> ## Documentation Index
> Fetch the complete documentation index at: https://support.configview.com/llms.txt
> Use this file to discover all available pages before exploring further.

# monday.com setup

ConfigView reads your monday.com account through the monday.com GraphQL API, using the **personal API token of an account admin**.

You will end up with **1 secret** in ConfigView (`MONDAY_API_TOKEN`) when setup is complete.

> **Scope of this integration today.** ConfigView reads who is in your monday.com account: admins, members, viewers, guests (including people from outside your company), deactivated people and invites nobody has accepted, with each person's last activity. It also reads teams and who owns them, workspaces and who can open each one, the account's plan and paid seats, and its user roles. On the Enterprise plan it also reads the audit log: sign-ins, data exports, user type and security-setting changes, API tokens viewed or regenerated, and AI agent apps installed. It never reads boards, items, updates, docs or files, or their names. ConfigView only reads. It never creates, changes or deletes anything.

***

## Step 1: Open the monday.com page in ConfigView

Open ConfigView in a second browser tab and leave it open:

`https://{companyname}.configview.com/admin/integrations/monday`

***

## Step 2: Copy an account admin's API token

monday.com has no read-only or service-account key. A personal API token can do everything its user can do in the monday.com UI, and sees exactly what that user sees. It needs to belong to an **account admin**. A member's token misses private (closed) workspaces, deactivated people and the audit log.

We recommend a dedicated admin user for ConfigView (for example `configview@yourcompany.com`), so the token doesn't stop working when a person leaves or regenerates their own token. That user takes a paid seat.

1. Sign in to monday.com as an **account admin**
2. Click your profile picture (top right) → **Administration** → **Connections** → **Personal API token**. You can also click your profile picture → **Developers** → **API token** → **Show**
3. Copy the token
4. Switch to the ConfigView tab, paste it into `MONDAY_API_TOKEN` under **Credentials**, and click the save icon

Paste the token on its own, without `Bearer` in front.

**Plan requirements.** Users, teams, workspaces and the account work on every plan that includes API access. The audit log needs the **Enterprise** plan. Custom roles exist only on Enterprise. Elsewhere, the role list holds just the built-in roles.

***

## Step 3: Connect and verify

1. Back on `https://{companyname}.configview.com/admin/integrations/monday`, confirm the credential shows as saved
2. Click **Connect**. ConfigView creates its tables and schedules every collector at your default run time. Stop any you don't want under **Collectors**:

| Script | Notes |
| - | - |
| **Account and Plan** | The account itself: name, URL slug, plan tier and billing period, the number of seats it pays for, how many active members it has, whether it's on a trial, and which monday products (Work Management, CRM, Dev, Service) it runs. |
| **Users** | Everyone in the account, including deactivated people and invites nobody has accepted. Each row has the person's user type (admin, member, viewer, guest), status, when they joined, when they were last active, how they were added (invite, SSO, SCIM, domain sign-up) and which teams they're in. |
| **Teams** | Teams in the account: name, whether it's a guest team, when it was created, and who owns it. |
| **Team Members** | Who belongs to each team and who owns it, with each person's user type and status. |
| **Workspaces** | Every workspace, whether active, archived or deleted. Each row has the name, whether it's open to the whole account or closed (members only), which monday product it belongs to, and when it was created. Workspace descriptions and the boards inside are never read. |
| **Workspace Members** | Who can open each active workspace and how: people and teams, each as an owner or a subscriber, with the person's user type and status. |
| **Account Roles** | The user roles on the account: the built-in admin, member, viewer and guest roles, plus custom roles on Enterprise. It turns each person's role ID into a name. |
| **Audit Log** | The account's audit log (Enterprise, admin token): sign-ins and failed sign-ins, data exports, file downloads, people invited, deactivated or given a new user type, team and workspace changes, security and AI settings, API tokens viewed or regenerated, and AI agent apps installed. Each event records who did it, when, and from which IP address and device. Board and item names are never stored. Kept as a growing history. |

3. Click **Verify now**. The health check confirms the token, signs in, checks that the token's user is an account admin, then reads one record from each list.

If a check fails:

* **Auth fails with 401.** The token was mistyped or regenerated, which kills the old token immediately. Or an admin restricted API access to certain IP addresses, so ConfigView's server address needs to be allowed.
* **Auth fails with `USER_ACCESS_DENIED`.** The token's user can't use the API. Viewers, guests, deactivated users and people who haven't confirmed their email can't.
* **"Token belongs to an account admin" warns.** The token is a member's. Collection still runs, but private workspaces, deactivated people and the audit log will be missing.
* **Audit log is skipped.** Expected unless the account is on Enterprise and the token is an admin's.
* **`DAILY_LIMIT_EXCEEDED`.** monday.com caps API calls per account per day, and every integration and script on the account shares that budget. See *Rate limits* below.

***

## Data Tables

Once the scripts run, these tables are created in your database. Each includes a `run_at` column for historical tracking, and a `raw_json` column holding the record as monday.com returned it, minus the fields listed under *What isn't collected*. Every table keeps only the newest run, except `monday_audit_logs`, which keeps every event it has ever read.

| Table | Source (GraphQL) | Key Columns |
| - | - | - |
| `monday_account` | `account`, `apps_monetization_info` | account\_id, name, slug, tier, plan\_tier, plan\_period, plan\_version, plan\_max\_users, seats\_count, active\_members\_count, is\_during\_trial, is\_trial\_expired, products, product\_count, country\_code, created\_at |
| `monday_users` | `users` (status ACTIVE, INACTIVE, PENDING) | user\_id, name, email, email\_domain, kind, status, is\_admin, is\_guest, is\_view\_only, is\_active, is\_pending, is\_deleted, is\_email\_confirmed, invitation\_method, role\_id, created\_at, became\_active\_at, last\_activity, country\_code, time\_zone, team\_ids, team\_count |
| `monday_teams` | `teams` | team\_id, name, is\_guest\_team, created\_at, owner\_ids, owner\_count |
| `monday_team_members` | `teams { users owners }` | team\_id, team\_name, user\_id, user\_email, user\_kind, user\_status, is\_member, is\_owner |
| `monday_workspaces` | `workspaces` (state all) | workspace\_id, name, kind, state, is\_default\_workspace, product\_id, product\_kind, created\_at |
| `monday_workspace_members` | `workspaces { owners_subscribers users_subscribers team_owners_subscribers teams_subscribers }` | workspace\_id, workspace\_name, workspace\_kind, member\_type, member\_id, user\_email, team\_name, user\_kind, user\_status, role |
| `monday_account_roles` | `account_roles` | role\_id, name, role\_type |
| `monday_audit_logs` | `audit_logs` | event\_key, event\_time, event, user\_id, user\_name, user\_email, ip\_address, user\_agent, client\_name, client\_version, os\_name, os\_version, device\_name, device\_type, account\_slug, app\_name, activity\_metadata |

***

## Things worth knowing

**User types and paid seats.** `kind` is monday.com's user type: `admin`, `member`, `view_only` or `guest`. Admins and members take paid seats. Viewers and guests don't. `status` is `ACTIVE`, `INACTIVE` (deactivated) or `PENDING` (invited, not yet accepted). Pending invites count against seats.

**`last_activity` is monday.com's own "last active" date,** not a sign-in log. It's the date the paid-seats question uses. On Enterprise, individual sign-ins are in the audit log (`event = 'login'`).

**"Outside the company" means a domain no admin uses.** monday.com's API has no list of your company's email domains, so the catalog questions treat the domains your account admins use as the company's. Anyone on another domain counts as external, whether a guest or not.

**The audit log is a growing history.** The first run reads the last 90 days. After that, each run reads from the newest stored event, one day at a time and oldest first, so nothing is read twice and nothing is ever deleted. monday.com gives audit events no ID, so ConfigView identifies each one by a fingerprint of the whole event. Two identical events in the same second from the same person, IP address and browser are stored once.

**Installed apps come from the audit log.** monday.com has no API that lists the marketplace apps installed on an account. ConfigView sees AI agent apps through `ai-agent-app-installed`, `-updated` and `-uninstalled` audit events, and these feed the connection map.

**Content is stripped from audit details.** `activity_metadata` keeps IDs, roles, settings and formats. Any field that could hold a board, item, doc, file or dashboard name, or text someone typed, is dropped before it's stored.

**Rate limits.** monday.com counts API calls per account per day: 1,000 on Free, Basic and Standard, 10,000 on Pro and 25,000 on Enterprise. They reset at midnight UTC. Every integration and script on the account shares this budget. A daily ConfigView run uses about ten calls, plus one for every 200 users, one per team and one per workspace. ConfigView makes one request at a time and waits whenever monday.com asks it to slow down.

**API version.** Every request pins API version `2026-07`. In that version monday.com replaced the old user flags (`is_admin`, `is_guest`, `is_pending`, `enabled`) with `kind` and `status`, and ConfigView reads only the new fields.

## What isn't collected

* Boards, items, sub-items, updates, docs, files, forms and dashboards, including their names
* Workspace descriptions, team pictures, profile photos, phone numbers and birthdays
* Board, item, doc and file names inside audit events
* Token values of any kind
* Marketplace apps installed on the account. monday.com's `app_installs` API only answers an app's own developers


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.