All integrations

OneSignal

MARKETING · MARKETING

Push and email messages, apps, users, subscriptions, segments, and journeys in the account they connected.

Acts as the person, not as itself

Each user connects their own account. Every call carries both identities — the agent and the person it is acting for — so the agent can never reach past what that individual can already do.

Credentials never touch the agent

Tokens live in the vault and attach server-side at call time. The agent holds a session, not a secret, and revoking access does not mean rotating a key.

Every call on the record

Who asked, which agent acted, which action ran, and the verdict that let it through — one audit trail across every integration, not one per vendor.

What an agent can do

Each action is granted on its own. An agent allowed to read is not thereby allowed to write, and the scope beside each row is what the acting user must have connected for it to run at all.

onesignal_delete_apps_by_app_id_auth_tokens_by_token_idWRITE

Delete an API key via DELETE /apps/{app_id}/auth/tokens/{token_id}. Permanently delete an API key. Any client still authenticating with it starts failing at once. ORGANIZATION KEY: this route is organization-scoped and an App API key cannot reach it. Fill the Organization API key box on this connection (OneSignal dashboard -> Settings -> Organization settings -> Security -> Keys & IDs), which only an organization Admin can mint. DESTRUCTIVE: the resource is removed and there is no undo through this API. Read it first with the matching Get or List tool if you may need what it held.

api
onesignal_delete_apps_by_app_id_journeys_by_idWRITE

Delete a journey via DELETE /apps/{app_id}/journeys/{id}. Permanently delete a journey. Anyone currently inside it stops progressing and its statistics go with it. DESTRUCTIVE: the resource is removed and there is no undo through this API. Read it first with the matching Get or List tool if you may need what it held.

api
onesignal_delete_apps_by_app_id_segments_by_segment_idWRITE

Delete a segment via DELETE /apps/{app_id}/segments/{segment_id}. Permanently delete a segment. Messages and automations that target it by name stop matching anyone. DESTRUCTIVE: the resource is removed and there is no undo through this API. Read it first with the matching Get or List tool if you may need what it held.

api
onesignal_delete_apps_by_app_id_subscriptions_by_subscription_idWRITE

Delete a subscription via DELETE /apps/{app_id}/subscriptions/{subscription_id}. Permanently delete one subscription. That channel stops receiving messages; the user and its other subscriptions remain. IDENTITY VERIFICATION: if this app has OneSignal's Token Identity Verification (beta) switched on, this route stops accepting the App API key and requires an ES256 JWT minted per end user by the customer's own backend -- a short-lived per-user token, not a credential a connection can hold. With the toggle off (its default) the App API key is what it takes. DESTRUCTIVE: the resource is removed and there is no undo through this API. Read it first with the matching Get or List tool if you may need what it held.

api
onesignal_delete_apps_by_app_id_users_by_by_alias_label_by_alias_idWRITE

Delete a user via DELETE /apps/{app_id}/users/by/{alias_label}/{alias_id}. Permanently delete a user and every subscription attached to it. The person stops receiving messages on all channels and their history is gone. DESTRUCTIVE: the resource is removed and there is no undo through this API. Read it first with the matching Get or List tool if you may need what it held.

api
onesignal_delete_apps_by_app_id_users_by_by_alias_label_by_alias_id_identity_by_alias_label_to_deleteWRITE

Delete an alias via DELETE /apps/{app_id}/users/by/{alias_label}/{alias_id}/identity/{alias_label_to_delete}. Remove one alias label from a user. The user itself and its other aliases are untouched, but anything addressing it by the deleted label stops resolving. DESTRUCTIVE: the resource is removed and there is no undo through this API. Read it first with the matching Get or List tool if you may need what it held.

api
onesignal_delete_notifications_by_message_idWRITE

Cancel a message via DELETE /notifications/{message_id}. Cancel a scheduled message before it is sent. It only works while the message is still pending: once delivery has begun there is nothing to cancel and nothing here can recall what was already sent. `app_id` is REQUIRED and is a query parameter (the ledger records it at `path`, which its own path template contradicts; corrected from the sibling View message operation). DESTRUCTIVE: the resource is removed and there is no undo through this API. Read it first with the matching Get or List tool if you may need what it held.

api
onesignal_delete_templates_by_template_idWRITE

Delete a template via DELETE /templates/{template_id}. Permanently delete a template. Anything still referencing it by `template_id` -- scheduled messages, journeys, automations -- fails at send time rather than falling back. DESTRUCTIVE: the resource is removed and there is no undo through this API. Read it first with the matching Get or List tool if you may need what it held.

api
onesignal_get_appsREAD

View apps via GET /apps. List every app in the organization with its App ID, name and per-platform configuration (Apple, Firebase, web push, Huawei, SMS, email). This is how a caller discovers the `app_id` every other tool here needs. ORGANIZATION KEY: this route is organization-scoped and an App API key cannot reach it. Fill the Organization API key box on this connection (OneSignal dashboard -> Settings -> Organization settings -> Security -> Keys & IDs), which only an organization Admin can mint.

api
onesignal_get_apps_by_app_idREAD

View an app via GET /apps/{app_id}. Read one app's settings and channel configuration by App ID. The App ID is a public UUID and is explicitly not a secret.

api
onesignal_get_apps_by_app_id_auth_tokensREAD

View API keys via GET /apps/{app_id}/auth/tokens. List the app's API keys (Rich Authentication Tokens) with their ids, names, IP allowlists and creation times. The key VALUES are not returned here -- OneSignal shows a value only when it is created or rotated. ORGANIZATION KEY: this route is organization-scoped and an App API key cannot reach it. Fill the Organization API key box on this connection (OneSignal dashboard -> Settings -> Organization settings -> Security -> Keys & IDs), which only an organization Admin can mint.

api
onesignal_get_apps_by_app_id_email_analytics_delivery_metricsREAD

View email delivery metrics via GET /apps/{app_id}/email_analytics/delivery_metrics. Read the app's email bounce and spam-complaint rates over the last 24 hours and the last 30 days. These are the two numbers a sending reputation is judged on.

api
onesignal_get_apps_by_app_id_inboxREAD

View inbox broadcasts via GET /apps/{app_id}/inbox. List the app's inbox broadcasts. `last_broadcast_id` is the pagination cursor and `limit` caps the page size.

api
onesignal_get_apps_by_app_id_journeysREAD

View journeys via GET /apps/{app_id}/journeys. List the app's journeys with their status, schedule and re-entry rules.

api
onesignal_get_apps_by_app_id_journeys_by_idREAD

View a journey via GET /apps/{app_id}/journeys/{id}. Read one journey by id, with its full node graph.

api
onesignal_get_apps_by_app_id_journeys_by_id_statsREAD

View journey stats via GET /apps/{app_id}/journeys/{id}/stats. Read one journey's performance -- per node, per branch and per message -- over an optional time window.

api
onesignal_get_apps_by_app_id_outcomesREAD

View outcomes via GET /apps/{app_id}/outcomes. Read aggregated outcome counts for the app -- clicks, confirmed deliveries, session duration and any custom outcomes -- selected by `outcome_names` and narrowed by time range, platform and attribution model.

api
onesignal_get_apps_by_app_id_segmentsREAD

View segments via GET /apps/{app_id}/segments. List the app's segments with their ids, names and current subscription counts. Paged with `limit` and `offset`.

api
onesignal_get_apps_by_app_id_segments_by_segment_idREAD

View a segment via GET /apps/{app_id}/segments/{segment_id}. Read one segment by id, with the filters that define it.

api
onesignal_get_apps_by_app_id_subscriptions_by_subscription_id_user_identityREAD

View identity by subscription via GET /apps/{app_id}/subscriptions/{subscription_id}/user/identity. Read the alias map of whichever user owns this subscription. The reverse lookup: subscription id in, identity out. IDENTITY VERIFICATION: if this app has OneSignal's Token Identity Verification (beta) switched on, this route stops accepting the App API key and requires an ES256 JWT minted per end user by the customer's own backend -- a short-lived per-user token, not a credential a connection can hold. With the toggle off (its default) the App API key is what it takes.

api
onesignal_get_apps_by_app_id_users_by_by_alias_label_by_alias_idREAD

View a user via GET /apps/{app_id}/users/by/{alias_label}/{alias_id}. Read one user, addressed by any alias -- `external_id`, `onesignal_id` or a custom alias label -- with its identity, properties and every subscription attached to it.

api
onesignal_get_apps_by_app_id_users_by_by_alias_label_by_alias_id_identityREAD

View a user's aliases via GET /apps/{app_id}/users/by/{alias_label}/{alias_id}/identity. Read the full alias map for one user -- every label and id it can be addressed by, including the `onesignal_id` OneSignal assigned it.

api
onesignal_get_apps_by_app_id_users_by_by_alias_label_by_alias_id_inboxREAD

View a user's inbox messages via GET /apps/{app_id}/users/by/{alias_label}/{alias_id}/inbox. List one user's inbox messages with their read, opened and deleted state. OneSignal documents `last_message_id` as the pagination cursor and the ledger records it as REQUIRED, so pass the id you last saw (or the empty string to ask for the first page).

api
onesignal_get_apps_by_app_id_users_by_by_alias_label_by_alias_id_inbox_unread_countREAD

View a user's unread inbox count via GET /apps/{app_id}/users/by/{alias_label}/{alias_id}/inbox/unread_count. Return how many inbox messages this user has not read. The number an app badge is drawn from.

api
onesignal_get_notificationsREAD

View messages via GET /notifications. List the app's messages, newest first, with their delivery counts. `limit` and `offset` page through them (50 per page by default), `kind` selects dashboard / API / automated messages, `template_id` narrows to one template and `time_offset` shifts the window.

api
onesignal_get_notifications_by_message_idREAD

View a message via GET /notifications/{message_id}. Read one message by id with its full delivery breakdown -- successful, failed, errored, converted, remaining -- and optionally its outcome counts via `outcome_names`, `outcome_time_range`, `outcome_platforms` and `outcome_attribution`.

api
onesignal_get_organizations_by_organization_id_audit_logsREAD

List audit logs via GET /organizations/{organization_id}/audit_logs. Read the organization's audit log -- who did what and when, ordered by `occurred_at` ascending, filterable by app, action, actor, target, IP and time window. The array filters are capped by OneSignal (10 entries each, 20 for `actions`). ORGANIZATION KEY: this route is organization-scoped and an App API key cannot reach it. Fill the Organization API key box on this connection (OneSignal dashboard -> Settings -> Organization settings -> Security -> Keys & IDs), which only an organization Admin can mint.

api
onesignal_get_templatesREAD

View templates via GET /templates. List the app's message templates. `app_id` is required, `channel` narrows to one channel, and `limit`/`offset` page through the results.

api
onesignal_get_templates_by_template_idREAD

View a template via GET /templates/{template_id}. Read one template by id, with its contents and settings. `app_id` is required.

api
onesignal_patch_apps_by_app_id_auth_tokens_by_token_idWRITE

Update an API key via PATCH /apps/{app_id}/auth/tokens/{token_id}. Rename an API key or change its IP allowlist. The reply is an empty object; re-read with View API keys to see the change. ORGANIZATION KEY: this route is organization-scoped and an App API key cannot reach it. Fill the Organization API key box on this connection (OneSignal dashboard -> Settings -> Organization settings -> Security -> Keys & IDs), which only an organization Admin can mint.

api
onesignal_patch_apps_by_app_id_journeys_by_idWRITE

Update a journey via PATCH /apps/{app_id}/journeys/{id}. Update a journey's settings or its node graph. A `nodes` array in the body REPLACES the graph rather than merging into it, so read the journey first and send the whole graph back -- or use Update a journey node to change one node.

api
onesignal_patch_apps_by_app_id_journeys_by_id_nodes_by_node_idWRITE

Update a journey node via PATCH /apps/{app_id}/journeys/{id}/nodes/{node_id}. Update a single node inside a journey without resending the whole graph. The narrow edit to prefer over Update a journey.

api
onesignal_patch_apps_by_app_id_segments_by_segment_idWRITE

Update a segment via PATCH /apps/{app_id}/segments/{segment_id}. Rename a segment or replace the filters that define it. The filter array REPLACES the segment's definition rather than adding to it, so read the segment first if you mean to extend it.

api
onesignal_patch_apps_by_app_id_subscriptions_by_subscription_idWRITE

Update a subscription via PATCH /apps/{app_id}/subscriptions/{subscription_id}. Update one subscription by id: its token, enabled flag, notification types, session data and device metadata. Setting `enabled` to false is how a subscription is suppressed without deleting it. IDENTITY VERIFICATION: if this app has OneSignal's Token Identity Verification (beta) switched on, this route stops accepting the App API key and requires an ES256 JWT minted per end user by the customer's own backend -- a short-lived per-user token, not a credential a connection can hold. With the toggle off (its default) the App API key is what it takes.

api
onesignal_patch_apps_by_app_id_subscriptions_by_subscription_id_ownerWRITE

Transfer a subscription via PATCH /apps/{app_id}/subscriptions/{subscription_id}/owner. Move a subscription from its current user to another, named by alias. Used when a device or address changes hands between accounts. IDENTITY VERIFICATION: if this app has OneSignal's Token Identity Verification (beta) switched on, this route stops accepting the App API key and requires an ES256 JWT minted per end user by the customer's own backend -- a short-lived per-user token, not a credential a connection can hold. With the toggle off (its default) the App API key is what it takes.

api
onesignal_patch_apps_by_app_id_subscriptions_by_subscription_id_user_identityWRITE

Create an alias by subscription via PATCH /apps/{app_id}/subscriptions/{subscription_id}/user/identity. Add alias labels to the user that owns this subscription, without having to resolve that user first. IDENTITY VERIFICATION: if this app has OneSignal's Token Identity Verification (beta) switched on, this route stops accepting the App API key and requires an ES256 JWT minted per end user by the customer's own backend -- a short-lived per-user token, not a credential a connection can hold. With the toggle off (its default) the App API key is what it takes.

api
onesignal_patch_apps_by_app_id_subscriptions_by_token_by_token_type_by_tokenWRITE

Update a subscription by token via PATCH /apps/{app_id}/subscriptions_by_token/{token_type}/{token}. Update a subscription addressed by its TOKEN rather than its id -- the device push token, email address or phone number, with `token_type` naming which. The route for a caller that holds the token and not the subscription id.

api
onesignal_patch_apps_by_app_id_users_by_by_alias_label_by_alias_idWRITE

Update a user via PATCH /apps/{app_id}/users/by/{alias_label}/{alias_id}. Update a user's properties: tags, language, timezone, country, session counts and purchase records. Tags are MERGED, and a tag sent with an empty string value is how one is removed.

api
onesignal_patch_apps_by_app_id_users_by_by_alias_label_by_alias_id_identityWRITE

Create an alias via PATCH /apps/{app_id}/users/by/{alias_label}/{alias_id}/identity. Add one or more alias labels to an existing user, addressed by an alias it already has. Adding an alias that belongs to a different user is refused rather than moving it.

api
onesignal_patch_apps_by_app_id_users_by_by_alias_label_by_alias_id_inboxWRITE

Bulk update inbox message state via PATCH /apps/{app_id}/users/by/{alias_label}/{alias_id}/inbox. Mark EVERY matching inbox message for one user read, opened or deleted, up to `last_message_id`. `is_deleted: true` hides all of them from that user's inbox for good, and there is no per-message confirmation in the reply -- it answers 204 with no body.

api
onesignal_patch_apps_by_app_id_users_by_by_alias_label_by_alias_id_inbox_by_message_idWRITE

Update an inbox message state via PATCH /apps/{app_id}/users/by/{alias_label}/{alias_id}/inbox/{message_id}. Mark one of a user's inbox messages read, opened or deleted. `is_deleted` hides it from that user's inbox for good; the other two flags are ordinary state. Answers 204 with no body.

api
onesignal_patch_templates_by_template_idWRITE

Update a template via PATCH /templates/{template_id}. Update one template's name, contents or channel settings. Messages already scheduled against it pick up the change.

api
onesignal_post_appsWRITE

Create an app via POST /apps. Create a new OneSignal app and set its channel configuration in one call -- APNs key or certificate, Firebase service account, web push keys, Huawei, and the SMS and email sender settings. The response carries the new App ID. ORGANIZATION KEY: this route is organization-scoped and an App API key cannot reach it. Fill the Organization API key box on this connection (OneSignal dashboard -> Settings -> Organization settings -> Security -> Keys & IDs), which only an organization Admin can mint.

api
onesignal_post_apps_by_app_id_activities_activity_by_activity_typeWRITE

Start a Live Activity via POST /apps/{app_id}/activities/activity/{activity_type}. Start an iOS Live Activity of the named type for the targeted subscriptions, with its initial content state. iOS only.

api
onesignal_post_apps_by_app_id_auth_tokensWRITE

Create an API key via POST /apps/{app_id}/auth/tokens. Mint a new API key for the app, optionally restricted to an IP allowlist in CIDR notation. THE RESULT IS REDACTED: the reply carries the new key's value in `formatted_token`, and Agentic Fabriq replaces it before the reply reaches an agent. OneSignal shows that value once and cannot show it again, so mint keys in the dashboard when you need to read one. Note that an IP allowlist will block Agentic Fabriq's own egress unless its addresses are included. ORGANIZATION KEY: this route is organization-scoped and an App API key cannot reach it. Fill the Organization API key box on this connection (OneSignal dashboard -> Settings -> Organization settings -> Security -> Keys & IDs), which only an organization Admin can mint.

api
onesignal_post_apps_by_app_id_auth_tokens_by_token_id_rotateWRITE

Rotate an API key via POST /apps/{app_id}/auth/tokens/{token_id}/rotate. Issue a new value for an existing API key. THE PREVIOUS VALUE STOPS WORKING IMMEDIATELY, for every client still using it, including this connection if it is the key being rotated -- there is no grace period and no way to recover the old value. THE RESULT IS REDACTED: the reply carries the new value in `formatted_token` and Agentic Fabriq replaces it before the reply reaches an agent, so rotate in the dashboard when you need to read the new value. ORGANIZATION KEY: this route is organization-scoped and an App API key cannot reach it. Fill the Organization API key box on this connection (OneSignal dashboard -> Settings -> Organization settings -> Security -> Keys & IDs), which only an organization Admin can mint. DESTRUCTIVE: the resource is removed and there is no undo through this API. Read it first with the matching Get or List tool if you may need what it held.

api
onesignal_post_apps_by_app_id_custom_eventsWRITE

Create custom events via POST /apps/{app_id}/custom_events. Record up to a megabyte of custom events against users, each naming the user by External ID or OneSignal ID and carrying its own payload. Give each event an `idempotency_key` so a retry cannot double-count it. Partial success is normal: the 202 reply lists the events that failed and the rest were processed.

api
onesignal_post_apps_by_app_id_inboxWRITE

Create an inbox broadcast via POST /apps/{app_id}/inbox. Create an in-app inbox broadcast for the app, with its per-language contents, optional image and custom data. Returns the new broadcast's id.

api
onesignal_post_apps_by_app_id_journeysWRITE

Create a journey via POST /apps/{app_id}/journeys. Create a journey: its audience, trigger, schedule, re-entry rules, early-exit conditions and the whole node graph of messages, waits and branches.

api
onesignal_post_apps_by_app_id_journeys_by_id_duplicateWRITE

Duplicate a journey via POST /apps/{app_id}/journeys/{id}/duplicate. Copy a journey into a new, separate journey, optionally overriding its name and settings. The copy starts paused; nothing is sent by duplicating.

api
onesignal_post_apps_by_app_id_live_activities_by_activity_id_notificationsWRITE

Update a Live Activity via POST /apps/{app_id}/live_activities/{activity_id}/notifications. Push a new content state to a running iOS Live Activity, optionally with an alert, and optionally ending it (`event: end`). Ending one cannot be undone from here -- a new activity has to be started.

api
onesignal_post_apps_by_app_id_notifications_by_notification_id_unsubscribeWRITE

Unsubscribe with a token via POST /apps/{app_id}/notifications/{notification_id}/unsubscribe. Unsubscribe the recipient of one message, using the `token` from that message's own unsubscribe link. The token is per message and per recipient and is the argument that identifies them -- there is nothing to look up and no way to guess one.

api
onesignal_post_apps_by_app_id_segmentsWRITE

Create a segment via POST /apps/{app_id}/segments. Create a segment from a named list of filter conditions combined with `AND`/`OR` operators. The reply carries the new segment's id.

api
onesignal_post_apps_by_app_id_usersWRITE

Create a user via POST /apps/{app_id}/users. Create a user with its identity aliases, properties (tags, language, timezone, country) and any subscriptions to attach in the same call. Idempotent on the alias: creating a user whose alias already exists updates that user rather than making a second one. IDENTITY VERIFICATION: if this app has OneSignal's Token Identity Verification (beta) switched on, this route stops accepting the App API key and requires an ES256 JWT minted per end user by the customer's own backend -- a short-lived per-user token, not a credential a connection can hold. With the toggle off (its default) the App API key is what it takes.

api
onesignal_post_apps_by_app_id_users_by_by_alias_label_by_alias_id_subscriptionsWRITE

Create a subscription via POST /apps/{app_id}/users/by/{alias_label}/{alias_id}/subscriptions. Attach a new subscription -- an email address, a phone number or a push token -- to an existing user, addressed by one of its aliases.

api
onesignal_post_notifications_by_message_id_export_eventsREAD

Export message events as CSV via POST /notifications/{message_id}/export_events. Generate a CSV of one message's events and return a download URL. The file is produced asynchronously and the URL is valid for three days.

api
onesignal_post_notifications_by_message_id_historyREAD

Export message history via POST /notifications/{message_id}/history. Email a CSV of the subscriptions that were SENT or CLICKED one message, to the address in the body. The report is delivered by email rather than returned here, so the reply only confirms the request was accepted. Requires the Email Message Reporting add-on, and `sent` events are not recorded for messages targeting fewer than 1,000 recipients.

api
onesignal_post_notifications_count_unsavedREAD

Count message recipients via POST /notifications/count-unsaved. Return how many subscriptions a message's targeting WOULD reach, without creating or sending anything. Takes the same targeting fields as Create message. The safest way to check an audience before sending: it answers `count` plus whether a plan cap reduced it.

api
onesignal_post_notifications_emailWRITE

Create an email message via POST /notifications. Send or schedule an EMAIL message. The same Create message endpoint as the push and SMS tools; `target_channel` defaults to `email` here and `email_subject` plus `email_body` are required. Carries the email-only fields -- from name and address, reply-to, preheader, BCC, click tracking, sender domain and warm-up. THIS SENDS REAL EMAIL and cannot be recalled once delivery starts.

api
onesignal_post_notifications_pushWRITE

Create a push message via POST /notifications. Send or schedule a PUSH message. The channel is chosen by `target_channel` in the body, which defaults to `push` here. Targeting is one of segments (`included_segments`/`excluded_segments`), filters, aliases (`include_aliases`, which requires `target_channel`) or subscription ids; `contents` carries the per-language body and is required. Supports scheduling (`send_after`, `delayed_option`, `delivery_time_of_day`), per-platform assets, action buttons, and `idempotency_key` to make a retry safe. THIS SENDS REAL MESSAGES TO REAL PEOPLE and cannot be recalled once delivery starts.

api
onesignal_post_notifications_smsWRITE

Create an SMS message via POST /notifications. Send or schedule an SMS or MMS message. The same Create message endpoint as the push and email tools, with `target_channel` required and defaulting to `sms`; `sms_from` names the Messaging Service SID or number to send from and `sms_media_urls` attaches MMS media. THIS SENDS REAL, BILLABLE MESSAGES to real phone numbers and cannot be recalled once delivery starts.

api
onesignal_post_players_csv_exportREAD

Export subscriptions as CSV via POST /players/csv_export. Generate a CSV of the app's subscription records and return its download URL. `segment_name` limits it to one segment, `extra_fields` adds columns such as external user id, country and timezone, and `last_active_since` limits it by recency. The file is produced asynchronously -- the URL is returned at once and the object may take a few minutes to appear -- and is available for three days.

api
onesignal_post_templatesWRITE

Create a template via POST /templates. Create a reusable message template for a channel, with its per-language contents and channel-specific settings.

api
onesignal_post_templates_by_template_id_copy_to_appWRITE

Copy a template to another app via POST /templates/{template_id}/copy_to_app. Copy one template into a different app in the same organization. Two apps are involved, which is why this is the one template tool that needs the Organization API key. ORGANIZATION KEY: this route is organization-scoped and an App API key cannot reach it. Fill the Organization API key box on this connection (OneSignal dashboard -> Settings -> Organization settings -> Security -> Keys & IDs), which only an organization Admin can mint.

api
onesignal_put_apps_by_app_idWRITE

Update an app via PUT /apps/{app_id}. Update one app's name and channel configuration. Fields the body omits keep their current values; a field sent empty clears it, which for a platform credential silently stops that channel delivering. ORGANIZATION KEY: this route is organization-scoped and an App API key cannot reach it. Fill the Organization API key box on this connection (OneSignal dashboard -> Settings -> Organization settings -> Security -> Keys & IDs), which only an organization Admin can mint.

api

Put OneSignal behind one governed endpoint.

Same permissions, same audit trail, whatever else you connect next.