Notion
Purpose
Collects one Notion workspace's people and bot connections, and optionally the metadata of pages published to the web.
tip
Secret fields below accept either an AWS Secrets Manager ARN or a value pasted directly into SubImage's managed vault. See Secrets for details.
Required Fields
| Field | Secret? | Description |
|---|---|---|
notion_api_token |
Yes | Access token of a Notion internal connection: its AWS Secrets Manager ARN, or the vault value |
notion_sync_public_pages |
No | Inventory pages published to the web that the connection can see. Defaults to false |
Required Permissions
| Capability | Purpose |
|---|---|
| Read user information including email addresses | Inventory workspace people and bot connections, and map people by email |
| Read content (optional) | Only needed when notion_sync_public_pages is enabled |
No insert, update, or comment capability is required.
Setup Steps
- In Notion, open Developer tools and select Connections.
- Select New connection, name it
SubImage, choose Access token, and select Create connection. - On the Configuration tab, select Read user information including email addresses.
- Disable Update content and Insert content, which may be enabled by default. Leave comment and agent capabilities disabled.
- Leave Read content disabled unless you plan to enable
notion_sync_public_pages. If you do, open the Content access tab, select Add pages & databases, and choose the pages to scan. Child pages inherit access. - Copy the Access token from the Integration token section.
- In SubImage, enter the token in
notion_api_token, save the module, and run a sync.
Notes
- The sync is read-only.
- Use a connection access token. Notion personal access tokens cannot list workspace users.
- Public page sync stores page metadata only (title, URLs, timestamps, parent, creator), never page body or comment content.
- Turning
notion_sync_public_pagesoff removes previously ingested pages on the next sync.
Troubleshooting
- Notion personal access token: replace the personal access token with a connection access token.
- 401 Unauthorized: the connection was deleted or its token was regenerated. Update the module with the current token.
- 403 Forbidden: enable Read user information including email addresses. If the error came from page search, grant Read content or disable
notion_sync_public_pages. - Notion search incomplete: Notion truncated the page search. Share fewer root pages with the connection, or disable
notion_sync_public_pages.