Skip to main content
ConfigView reads your monday.com account through the monday.com GraphQL API, using the personal API token of an account admin. You will end up with 1 secret in ConfigView (MONDAY_API_TOKEN) when setup is complete.
Scope of this integration today. ConfigView reads who is in your monday.com account: admins, members, viewers, guests (including people from outside your company), deactivated people and invites nobody has accepted, with each person’s last activity. It also reads teams and who owns them, workspaces and who can open each one, the account’s plan and paid seats, and its user roles. On the Enterprise plan it also reads the audit log: sign-ins, data exports, user type and security-setting changes, API tokens viewed or regenerated, and AI agent apps installed. It never reads boards, items, updates, docs or files, or their names. ConfigView only reads. It never creates, changes or deletes anything.

Step 1: Open the monday.com page in ConfigView

Open ConfigView in a second browser tab and leave it open: https://{companyname}.configview.com/admin/integrations/monday

Step 2: Copy an account admin’s API token

monday.com has no read-only or service-account key. A personal API token can do everything its user can do in the monday.com UI, and sees exactly what that user sees. It needs to belong to an account admin. A member’s token misses private (closed) workspaces, deactivated people and the audit log. We recommend a dedicated admin user for ConfigView (for example configview@yourcompany.com), so the token doesn’t stop working when a person leaves or regenerates their own token. That user takes a paid seat.
  1. Sign in to monday.com as an account admin
  2. Click your profile picture (top right) → Administration → Connections → Personal API token. You can also click your profile picture → Developers → API token → Show
  3. Copy the token
  4. Switch to the ConfigView tab, paste it into MONDAY_API_TOKEN under Credentials, and click the save icon
Paste the token on its own, without Bearer in front. Plan requirements. Users, teams, workspaces and the account work on every plan that includes API access. The audit log needs the Enterprise plan. Custom roles exist only on Enterprise. Elsewhere, the role list holds just the built-in roles.

Step 3: Connect and verify

  1. Back on https://{companyname}.configview.com/admin/integrations/monday, confirm the credential shows as saved
  2. Click Connect. ConfigView creates its tables and schedules every collector at your default run time. Stop any you don’t want under Collectors:
  1. Click Verify now. The health check confirms the token, signs in, checks that the token’s user is an account admin, then reads one record from each list.
If a check fails:
  • Auth fails with 401. The token was mistyped or regenerated, which kills the old token immediately. Or an admin restricted API access to certain IP addresses, so ConfigView’s server address needs to be allowed.
  • Auth fails with USER_ACCESS_DENIED. The token’s user can’t use the API. Viewers, guests, deactivated users and people who haven’t confirmed their email can’t.
  • “Token belongs to an account admin” warns. The token is a member’s. Collection still runs, but private workspaces, deactivated people and the audit log will be missing.
  • Audit log is skipped. Expected unless the account is on Enterprise and the token is an admin’s.
  • DAILY_LIMIT_EXCEEDED. monday.com caps API calls per account per day, and every integration and script on the account shares that budget. See Rate limits below.

Data Tables

Once the scripts run, these tables are created in your database. Each includes a run_at column for historical tracking, and a raw_json column holding the record as monday.com returned it, minus the fields listed under What isn’t collected. Every table keeps only the newest run, except monday_audit_logs, which keeps every event it has ever read.

Things worth knowing

User types and paid seats. kind is monday.com’s user type: admin, member, view_only or guest. Admins and members take paid seats. Viewers and guests don’t. status is ACTIVE, INACTIVE (deactivated) or PENDING (invited, not yet accepted). Pending invites count against seats. last_activity is monday.com’s own “last active” date, not a sign-in log. It’s the date the paid-seats question uses. On Enterprise, individual sign-ins are in the audit log (event = 'login'). “Outside the company” means a domain no admin uses. monday.com’s API has no list of your company’s email domains, so the catalog questions treat the domains your account admins use as the company’s. Anyone on another domain counts as external, whether a guest or not. The audit log is a growing history. The first run reads the last 90 days. After that, each run reads from the newest stored event, one day at a time and oldest first, so nothing is read twice and nothing is ever deleted. monday.com gives audit events no ID, so ConfigView identifies each one by a fingerprint of the whole event. Two identical events in the same second from the same person, IP address and browser are stored once. Installed apps come from the audit log. monday.com has no API that lists the marketplace apps installed on an account. ConfigView sees AI agent apps through ai-agent-app-installed, -updated and -uninstalled audit events, and these feed the connection map. Content is stripped from audit details. activity_metadata keeps IDs, roles, settings and formats. Any field that could hold a board, item, doc, file or dashboard name, or text someone typed, is dropped before it’s stored. Rate limits. monday.com counts API calls per account per day: 1,000 on Free, Basic and Standard, 10,000 on Pro and 25,000 on Enterprise. They reset at midnight UTC. Every integration and script on the account shares this budget. A daily ConfigView run uses about ten calls, plus one for every 200 users, one per team and one per workspace. ConfigView makes one request at a time and waits whenever monday.com asks it to slow down. API version. Every request pins API version 2026-07. In that version monday.com replaced the old user flags (is_admin, is_guest, is_pending, enabled) with kind and status, and ConfigView reads only the new fields.

What isn’t collected

  • Boards, items, sub-items, updates, docs, files, forms and dashboards, including their names
  • Workspace descriptions, team pictures, profile photos, phone numbers and birthdays
  • Board, item, doc and file names inside audit events
  • Token values of any kind
  • Marketplace apps installed on the account. monday.com’s app_installs API only answers an app’s own developers