OneCLI connects AI agents to Navan through the Navan API. Agents can read travel bookings and expense transactions, and write ERP sync status, GL codes, tax mappings, and custom field values back to Navan. The gateway injects credentials into requests to api.navan.com, so your agent never sees them.Navan uses machine-to-machine OAuth 2.0 (the client credentials grant), not a browser sign-in. You create a Client ID and Secret Key in Navan, and OneCLI exchanges them for an access token. Tokens last 12 hours, and the gateway gets a new one automatically when the current one expires.
For expense endpoints: Navan must enable the Expense API for your company. Ask Navan support or your account team. Until it’s enabled, expense requests return 403 Forbidden. Booking endpoints work without it.
Sign in to Navan, click the Navan logo in the top left, and select Admin.
Open Integrations and start a new API credential.
1. In the left menu, go to Travel > Settings > Integrations.
2. In the Navan API credentials section, click Create new.
Name the credential and select the scopes your agents need.
1. Enter a Description, for example OneCLI. Leave Allowed IP Addresses empty.
2. Select the scopes your agents need:
Scope
Grants
Booking: Read Only
Read travel bookings
Expense: Read Only
Read expense transactions, receipts, and custom fields
Expense: Write
Update transactions, custom field options, GL codes, and tax mappings
3. Click Create.
Copy the Client ID and Secret Key before you close the dialog.
1. The Client ID. You’ll paste it into OneCLI next.
2. The Secret Key. Click Copy key to copy it on its own.
3. Click Save and Copy all to copy the Description, Client ID, and Secret Key together.
Navan shows the Secret Key only once. Save it before you close the dialog. If you lose it, delete the credential and create a new one.
2
Connect in OneCLI
Open the OneCLI dashboard, go to Connections, find Navan, and click Connect.
Enter the Navan credential in OneCLI. Region is under Advanced.
1. Paste the Client ID from Navan.
2. Paste the Secret Key from Navan.
3. Expand Advanced only if your company is hosted in Navan’s EU region, and set Region to eu. Leave it empty for US.
4. Click Connect Navan.
OneCLI exchanges the credentials for a token when you connect. If the credential is invalid or has no scopes selected, the connection fails with an error that explains why.
3
Grant the connection to an agent
Grant the Navan connection to each agent that needs it.
Set Region to eu (under Advanced in the connect window) if your company is hosted in Navan’s EU region. OneCLI then uses Navan’s EU token endpoint and adds the X-ta-region: EU header to every request. Navan answers EU requests without that header with 500 Internal Server Error, so your agent doesn’t need to add the header itself.
The bookings endpoint requires a complete date range: createdFrom/createdTo, updatedFrom/updatedTo, or startDateFrom/startDateTo. Without one, Navan returns 400 Bad Request.
The Expense API isn’t enabled for your company yet, or the credential lacks an Expense scope. Ask Navan support to enable the Expense API, and check the credential’s scopes in Travel > Settings > Integrations.
Connecting fails with 401
The Client ID or Secret Key is wrong, or the region doesn’t match your account. A US credential fails against the EU region and the other way around.
Connecting fails with "no scopes"
The credential was created without any scope selected. Delete it in Navan and create a new one with at least one scope.
Writes return 403 Forbidden
The credential doesn’t have the Expense: Write scope. Edit the credential in Navan to add it, then reconnect in OneCLI.
Access is per agent: grant the connection to each agent that needs it, choosing per tool what runs freely, what needs human approval, and what stays blocked. A read-only agent is a single grant. Organization rules add guardrails on top, like rate limits and blanket blocks. Everything is checked before credential injection, so a blocked request never reaches the Navan API.