IT Glue: documents, passwords and renewals where your team works
IT Glue is where an MSP writes down how each partner's environment works: the documents, the passwords, the device configurations and the dates things run out. This connector puts that in front of your team where the work already happens in Current: on a service desk ticket, on the company record, on a PSA ticket and in the Device panel. Documents and the list of passwords are read from IT Glue when someone opens them. A password itself is fetched only when a person presses Reveal, shows for 30 seconds, and is never stored in Current.
Create the API key in IT Glue
IT Glue's API comes with its Enterprise plan, and only a user with IT Glue's Administrator role can create a key. One key reaches every organization in your IT Glue account. IT Glue has no read-only key, so Current's own rules decide what the key is used for: every request is checked against a short list of IT Glue addresses before it is sent, and the only thing Current ever writes is a new document, when a person reads a draft and presses Save (see Saving a fix to IT Glue below).
- 11 · Sign in to IT Glue as an AdministratorOpen Admin, then Settings, then API Keys. Some accounts label the tab Custom API Keys.
- 22 · Create the key and name it CurrentChoose Create API Key and give it a name a colleague will recognise, such as Current, so a future admin can tell which key belongs to what.
- 33 · Decide on Password AccessPassword Access is a setting on each key, and IT Glue returns password values through its API only when it is on. Turn it on if your team should be able to reveal passwords in Current. Leave it off and everything else still works (documents, the names of passwords, device configurations and renewals), and Reveal tells the person that the key can't read passwords.
- 44 · Copy the key nowIT Glue shows the key once, when you generate it, and never again. If the page closes before you copy it, revoke that key and create another.
Connect it in Current
- 1Open the IT Glue cardIn Current's left menu open Integrations (it sits under Workspace, so Tenant Admins have the link) and find IT Glue in the Documentation section.
- 2Paste the key, then pick your region and web addressChoose the region your IT Glue account lives in: US, EU or Australia. A key sent to the wrong region is refused, so the region is the first thing to check when a key is rejected. The web address is the one you sign in to IT Glue at, such as https://yourcompany.itglue.com (EU accounts end in .eu.itglue.com and Australian ones in .au.itglue.com). Current builds every Open in IT Glue link on that address, and accepts only an https address on itglue.com.
- 3Press Test connectionCurrent reads one page of your IT Glue organizations to prove the key works, and counts them. It never reads a password to test a key. On success the key is stored server-side only: the browser never sees it again, and it is never written into a web address, a status message or a log.
Matching IT Glue organizations to your companies
Each IT Glue organization is one partner. Every sync reads your organizations and links each one to the Current company with the same normalized name (lowercased, with punctuation and Inc/LLC/Ltd-style suffixes stripped) when exactly one company matches. When IT Glue's API also returns the PSA link it keeps on an organization (IT Glue keeps one when it syncs organizations from Autotask or ConnectWise PSA), Current can match on that PSA company ID as well. A name that fits two companies waits for you on the Unmapped tab rather than being paired on a guess.
- 1Let the automatic pass run firstThe clear matches link themselves on the first sync, and only the ambiguous ones need a hand. Press Sync now on the card to run the first sync straight away instead of waiting for the daily one.
- 2Open the mapping panelIntegrations → IT Glue → Manage → Customer mapping. It opens on the Unmapped tab, which lists every IT Glue organization the automatic pass could not place.
- 3Map an organization to its companyOn an unmapped row press Map, type a few letters of the company, and pick it. That organization's renewals attach right away, and its documents and passwords show on the company the next time someone opens them.
- 4Ignore internal or test organizationsFor an organization that should never map to a partner (your own internal documentation, a lab, a template) press Ignore. It moves to the Ignored tab and stops counting as unmapped.
- 5Fix a wrong match laterThe Mapped tab lists every link; Unmap corrects a bad automatic match, and Un-ignore brings a dismissed organization back. A mapping you set by hand is never overwritten by a later automatic match.
Where it shows up
- +A service desk ticket, where the service desk is switched on: the Docs and passwords panel for the ticket's company, the Assistant panel that answers questions from that company's documents, and Save this fix to IT Glue.
- +The company record: a Docs and passwords section, and the company's renewals (see Renewals below).
- +A PSA ticket opened in the drawer: a Docs and passwords section on its Overview, for the ticket's company. It stays folded until you open it, and nothing is read from IT Glue until then.
- +The Device panel on a service desk ticket with a device linked: the IT Glue configuration for that device, found by serial number within the company's organization and then by exact hostname. It shows the configuration's type, status and warranty date, how it was matched, and the passwords attached to it. When nothing matches, the panel says so.
The Documents group lists the documents in every folder, most recently updated first, with a search box once there are more than eight. Clicking one opens it in a reader beside the panel: headings, text and numbered steps show, and images stay in IT Glue, with a line in the reader saying so. The reader is a protected frame: nothing written into a document can run inside Current, and it cannot load anything from anywhere else. A link inside a document opens in a new browser tab. The Passwords group lists each password by name, username and category, except a restricted one, which shows its name only. Opening the list never reveals anything, and archived passwords are left out of it. If IT Glue answers the passwords but not the documents, the Documents group says the documents couldn't load and the passwords show as usual; try again in a minute.
Revealing a password
Press Reveal on a password row. Current asks IT Glue for that one password at that moment, runs the checks below, records the reveal, and only then shows it, under the row:
- +The username, with a Copy button.
- +The password, masked until you press Show, with its own Copy button.
- +The one-time code with a countdown, when the login has one and IT Glue provides it (see One-time codes below).
- +Open in IT Glue.
- +A line saying the reveal was recorded, and on a service desk ticket, that it was recorded on the ticket.
- +A thin bar that runs down over 30 seconds.
When the bar runs out, the password, the username and the code are cleared from the screen. They are also cleared when you press Hide, when the panel closes, and when the browser tab is hidden, for example when you switch to another tab. To see the password again, press Reveal again. That is a new reveal, and it is recorded too.
Who can reveal
Engineers, project managers and tenant admins. The rule names the roles that are allowed, so a role added to Current later is refused until someone decides otherwise. Account executives and sales managers can't open documents or reveal passwords, and Partner Viewers never see any of it. The company has to be in your own workspace, and the password has to belong to the IT Glue organization matched to that company: a password from any other organization is refused, even when someone sends its ID directly. A reveal from a service desk ticket also has to come from a ticket you can open, for that same company. Every one of these checks runs on Current's server for every request, not only in what the screen shows.
Limits on reveals, and support sessions
Each person can reveal 20 passwords in any 10 minutes and 200 in a day, and a workspace can reveal 1,000 in a day. Past a limit, Reveal says reveals are paused for you and to try again later or ask an admin, and nothing is shown. The first time someone in the workspace is paused on a given day, its tenant admins are notified. The limits count reveal attempts, including refused and paused ones; reading documents and the password list doesn't count toward them.
During a Current support session, when someone from Current support is signed in to your workspace to help, passwords can't be revealed and nothing can be saved to IT Glue. Reveal and Save each say so.
Restricted and archived passwords
IT Glue lets you restrict a password to named people or groups. The API key sees every password in the account, restricted ones included, so Current cannot tell whether you are one of the people allowed. It never reveals a restricted password, and it shows no more of one than its name: the row reads Restricted in IT Glue and offers Open in IT Glue, where IT Glue's own permissions decide, with no username or web address beside it. Current checks the password as IT Glue returns it at the moment of the reveal, not the list the page loaded earlier, so a password restricted a minute ago is already refused. An archived password is not revealed either.
One-time codes
IT Glue can hold a one-time code for a login, and its API documents the secret behind the code as something you can write but not read back. So Current shows a code only when IT Glue provides one. When IT Glue returns the secret with the password, Current works out the current six-digit code, shows it with the seconds it has left, and discards the secret; neither the code nor the secret is stored. When IT Glue doesn't return it, the reveal says the login also needs a one-time code and that you can see the code by opening the password in IT Glue.
The record of who looked
Every reveal is recorded before the value leaves Current's server. If the record cannot be written, the reveal stops and nothing is shown. The record holds who revealed the password, its name, the company, where it happened (a service desk ticket, a PSA ticket, the company page or the Device panel), when, whether a one-time code was shown, and the result. It never holds the value. A reveal Current refused or paused is recorded too, so the list also shows attempts that showed nothing: a restricted or archived password, one from another organization, a key without Password Access, a password IT Glue couldn't find, a support session, or a person past the reveal limits (listed at most once every 5 minutes while the pause lasts). On a service desk ticket, the ticket's Activity also gains a line naming who revealed which password from IT Glue.
IT Glue records a password read through its API against the API key, not against a person, so its own logs show Current's key and nobody behind it. IT Glue's Password Access workflow can notify you each time a password is read through the API, and that notification names the key too. Current's list is therefore the record of who looked. Tenant admins find it in Settings under Password reveals once IT Glue is connected: when, who, the company, the password, where, the result (Shown, a Refused line naming why, Paused: too many reveals, Failed, or Not finished) and whether a code was shown, with a CSV export. Records are kept for 365 days.
AI and your documents
The Assistant on a service desk ticket reads document text only when a person asks it something. It lists the company's document titles, picks up to four that look relevant, reads those (up to 12,000 characters of each), and answers in sentences that each cite the document they came from; a citation opens that document in the reader. When the documents don't cover the question, it says it couldn't find the answer rather than guessing. A person can ask 30 questions an hour, and a workspace 300 a day.
The desk's automatic triage of a new ticket sees the titles of the company's documents, up to 40 of them, and never their text.
Nothing from the Passwords group ever reaches an AI model: no password names, no values, no one-time codes and no notes. Current counts AI use for the usage meter and keeps neither the question nor the answer.
Saving a fix to IT Glue
- 1Open Save this fix to IT GlueIt sits at the foot of Docs and passwords on a service desk ticket.
- 2Draft with AI, or start blankDraft with AI writes a title and a body from the ticket's subject, its conversation and the close note when there is one. The draft is told never to include passwords, keys or codes, and to write "(see IT Glue password: name)" in their place.
- 3Read it and edit itChange the title and the body as you need; headings and lists are kept. Save only what the team should read, and link to the IT Glue password rather than pasting one.
- 4Press SaveCurrent creates a new document in the company's IT Glue organization, adds your text and publishes it. A confirmation offers a link to open it, and the ticket's Activity gains a line naming who saved which document.
Saving is the only thing Current ever writes to IT Glue, and it happens only when a person presses Save after reading the draft. Current never edits or deletes an existing document and never changes a password. A title can run to 200 characters and a body to 60,000.
Renewals
Once a day Current reads the renewal dates IT Glue tracks for each matched organization, from 30 days ago to 120 days ahead: SSL certificates, domains, warranties, licences and any date on a flexible asset that IT Glue tracks as an expiration. They show on the company record under Expiring soon, each with the item, its type and the date in words ("in 12 days", "expired 3 days ago"), dates already past in red and dates coming up soon in amber, and Open in IT Glue on every row. On the CRM company record a line counts the renewals due. A company with nothing in the window shows no list at all.
The company alert band carries a Documented renewals are due entry: a warning when something expires within the next 30 days, and critical when something expired in the last 30 days. It lists up to three of the items with their type and date.
An expiry date is not a secret, so renewals reach more people than documents do: engineers, project managers, tenant admins and sales leadership see them, and an account executive sees them on any company they can view. Partner Viewers never do. An item IT Glue stops returning drops off after a complete read without it.
When something looks wrong
| What you see | What it means |
|---|---|
| Test connection says IT Glue rejected the key | Check the region first, because a key sent to the wrong region is refused. Otherwise the key was mistyped, paused in IT Glue, or revoked, which IT Glue does on its own to a key unused for 90 days. Create a new key under Admin, Settings, API Keys and reconnect. |
| Reveal says the key can't read passwords | Password Access is off on the key. Turn it on for the key in IT Glue, or create a new key with it on and reconnect. Everything else keeps working meanwhile. |
| A password offers only Open in IT Glue | It is restricted in IT Glue. Current never reveals a restricted password, and IT Glue's own permissions decide who sees it there. |
| Reveal says the password is archived | It was archived in IT Glue. Restore it there if it is still in use. |
| Reveal says reveals are paused for you | You passed a reveal limit: 20 in any 10 minutes or 200 in a day for one person, or 1,000 in a day for the workspace. Try again later. Your tenant admins were notified the first time someone was paused that day, and the pause is on the Password reveals list as Paused, at most once every 5 minutes while it lasts. |
| Reveal or Save says it isn't available during a support session | Someone from Current support is signed in to your workspace to help. Revealing passwords and saving to IT Glue are off for the whole session. |
| IT Glue refused access to an item | IT Glue itself refused the API key access to that password, document or configuration. Check the item's access in IT Glue, or open it there. |
| The Documents group says the documents couldn't load | IT Glue answered the password list but not the documents. Try again in a minute; the passwords work meanwhile. |
| Reveal says it wasn't recorded | Current could not write the record of the reveal, so it showed nothing. Try again in a moment. |
| No one-time code, only a line about opening IT Glue | IT Glue didn't return the secret behind that login's code. Open the password in IT Glue to see the code. |
| Docs and passwords says the company isn't matched | Its IT Glue organization is not mapped yet. Check the Unmapped tab on the IT Glue card. |
| It says the company is matched to more than one organization | Two or more IT Glue organizations point at the same company. The panel shows one of them; unmap the others on the Mapped tab if the split is not deliberate. |
| IT Glue says it is busy | IT Glue allows 3,000 requests every five minutes, shared by every tool connected to your account. Current waits and tries once more, then asks you to try again shortly. |
| The Device panel finds no matching configuration | No configuration in the company's IT Glue organization carries the device's serial number or its exact hostname. Correct the record in IT Glue and it matches the next time the panel opens. |
| Saving says the workspace is read-only | The workspace's billing is frozen. Reading documents and revealing passwords still work, and saving to IT Glue waits until billing is sorted. |
| A renewal you expect is missing | Current reads 30 days back and 120 days ahead, for matched organizations, once a day. A date outside that window, on an organization that isn't matched, or not tracked as an expiration in IT Glue doesn't show. |
| Nothing from IT Glue shows on a company or a ticket | IT Glue isn't connected, or your role can't open it: documents and passwords are for engineers, project managers and tenant admins. |
