> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://help.moveworks.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://help.moveworks.com/_mcp/server.

# Genesys Access Requirements

Moveworks integrates with Genesys Cloud so that your employees can chat with a live Genesys agent without leaving the Moveworks AI Assistant. This page covers everything required before configuring the handoff in Moveworks: all Genesys-side setup, the Moveworks credentials, and the Genesys Connector. Once these steps are complete, the connection between Moveworks and Genesys is established, and you can continue with [Configure Genesys Live Agent Message Brokering](/service-management/live-agent-handoff-assistant/live-agent-message-brokering-assistant/live-agent-genesys).

## Prerequisites

* A **Genesys Cloud** organization. The integration uses the Genesys Cloud **Open Messaging** capability, which is not available on Genesys Engage, Genesys Multicloud CX, or PureConnect.
* A Genesys Cloud license that includes Open Messaging. Per Genesys documentation, this is one of: **Genesys Cloud CX 4, Genesys Cloud CX 2 Digital, Genesys Cloud CX 3 Digital, or Genesys Cloud CX 1 with the Digital Add-on II**.
* Administrator access to the Genesys Cloud Admin console and Architect, with the following permissions:
  * **Messaging > Integration > All** (to create the Open Messaging integration)
  * **Process Automation > Trigger** permissions (to create the event triggers used for agent notifications). The Genesys requirements article lists trigger support for CX 1, CX 2, and CX 3 licenses and does not mention CX 4, so CX 4 customers should confirm trigger entitlement with Genesys.
  * **Architect > Flow** Add / Edit / View (to update your message flow and create notification workflows)
  * **Integrations > Integration** Edit / View and **Integrations > Action** Add / Edit / Execute / View (to create the data actions used for agent notifications)
  * **OAuth > Client > Add** (to create the OAuth client in Step 3). Genesys only lets you grant an OAuth client roles that are already assigned to your own profile.
* A working contact center to hand conversations to: at least one queue with assigned agents (see the Genesys article [Create and configure queues](https://help.genesys.cloud/articles/create-queues/)), and an Architect inbound message flow to receive Moveworks conversations. Step 4 can attach the integration to an existing flow, or you can create a dedicated one.

There is no Genesys platform version requirement. Genesys Cloud is continuously delivered and its Platform API has a single supported version (v2).

## Moveworks webhook URL

Several of the steps below use the Moveworks webhook URL. It is **specific to the Moveworks data center hosting your organization**, and the same region-specific URL is used in two places: as the **Outbound Notification Webhook URL** of the Open Messaging integration (Step 1) and as the **Request URL** of the two notification data actions (Step 6). Do not copy the United States URL unless your organization is hosted there:

| Moveworks Data Center    | Webhook URL                                                                               |
| :----------------------- | :---------------------------------------------------------------------------------------- |
| United States (default)  | `https://api.moveworks.ai/rest/LiveAgentService/GenesysSendMessageToUser`                 |
| US Prod 3                | `https://api.prod3.us.moveworks.com/rest/LiveAgentService/GenesysSendMessageToUser`       |
| US Prod 4                | `https://api.prod4.us.moveworks.com/rest/LiveAgentService/GenesysSendMessageToUser`       |
| Canada                   | `https://api.am-ca-central.moveworks.ai/rest/LiveAgentService/GenesysSendMessageToUser`   |
| EU                       | `https://api.am-eu-central.moveworks.ai/rest/LiveAgentService/GenesysSendMessageToUser`   |
| UK                       | `https://api.uk.moveworks.com/rest/LiveAgentService/GenesysSendMessageToUser`             |
| Japan                    | `https://api.jp.moveworks.com/rest/LiveAgentService/GenesysSendMessageToUser`             |
| Australia / Asia Pacific | `https://api.am-ap-southeast.moveworks.ai/rest/LiveAgentService/GenesysSendMessageToUser` |
| Government Secure Cloud  | `https://api.moveworksgov.ai/rest/LiveAgentService/GenesysSendMessageToUser`              |

You can identify your data center from your organization's Moveworks login domain: for example, a login domain of `acme.moveworks.com` means the United States data center (use `api.moveworks.ai`), while `acme.uk.moveworks.com` means UK (use `api.uk.moveworks.com`). If you are still unsure, confirm the URL with Moveworks support.

# Step 1: Create the Open Messaging integration in Genesys

This step produces two values that the Moveworks credentials in Step 2 need: a **webhook signature secret** that you generate, and the **integration ID** that Genesys generates when you save the integration.

1. Generate a webhook signature secret. This is a strong random secret of your choosing, at least 32 characters long. Any standard method works, for example running `openssl rand -base64 32` in a terminal or using your password manager's password generator. Treat it like a password and store it securely. You will enter this exact value in two places: in Genesys in this step, and in Moveworks in Step 2.
2. In Genesys Cloud Admin, go to **Admin > Message > Platforms** (in the newer navigation, **Menu > Digital and Telephony > Message > Platform Integrations**) and select **Create New Integration > Open Messaging**.
3. Configure:
   * **Name**: a recognizable name, for example `Moveworks_Integration`. No later step uses this name.
   * **Outbound Notification Webhook URL**: the Moveworks webhook URL for your data center (table above).
   * **Outbound Notification Webhook Signature Secret Token**: the webhook signature secret you generated above. Genesys hides this value after you save it, which is why you generated and stored it first.
   * **Supported Content Profile**: `default`, or a profile matching your attachment policy.
   * The remaining fields (for example **Platform Config** and **Engagement Source**) can be left at their defaults.
4. Save the integration and record its **integration ID** (the UUID visible in the page URL, or via the Genesys API). You will need it twice: in the Moveworks credentials in Step 2, and in the Live Agent Handoff configuration in the [configuration guide](/service-management/live-agent-handoff-assistant/live-agent-message-brokering-assistant/live-agent-genesys).

![Open Messaging integration: name, Moveworks webhook URL, signature secret token, and content profile](https://fdr-prod-docs-files-public.s3.us-east-1.amazonaws.com/moveworks.docs.buildwithfern.com/79c5af0174730233048b4a45d8a86144c407a8cde80d08fd55045ff2cd635edc/docs/assets/images/genesys-01-open-messaging-integration.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Content-Sha256=UNSIGNED-PAYLOAD&X-Amz-Credential=AKIA6KXJSKKNFOCF7G4B%2F20260824%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20260824T222801Z&X-Amz-Expires=604800&X-Amz-Signature=3e2f949f1bfcfec04eb7f27bb0716852070992200bb106fd81098f3009af6f9b&X-Amz-SignedHeaders=host&x-amz-checksum-mode=ENABLED&x-id=GetObject)

# Step 2: Create the credentials in Moveworks

In Moveworks Setup, under **HTTP Connectors > Credentials**, create the two credentials below.

1. A **Live Agent Webhook Symmetric Signature** credential, which lets Moveworks verify that webhook calls come from your Genesys organization (Genesys signs every webhook request with an `X-Hub-Signature-256` HMAC header):

   * **Webhook Secret** = the Open Messaging **integration ID** from Step 1.
   * **Webhook Symmetric Key** = the webhook signature secret you generated in Step 1. Enter the exact same value here.

   ![Live Agent Webhook Symmetric Signature credential: the Webhook Secret holds the integration ID and the Webhook Symmetric Key holds the signature secret (example values shown)](https://fdr-prod-docs-files-public.s3.us-east-1.amazonaws.com/moveworks.docs.buildwithfern.com/62fd8b1b47038a0f3c5572dc2cfe2d863af6c9c666da544c31f8d5ff4287b0e9/docs/assets/images/genesys-mw-02-symmetric-credential-form.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Content-Sha256=UNSIGNED-PAYLOAD&X-Amz-Credential=AKIA6KXJSKKNFOCF7G4B%2F20260824%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20260824T222801Z&X-Amz-Expires=604800&X-Amz-Signature=8a2583d7fbc6d82966607e0b61bc5b0ca1f3ae3c436e42b1baf34e3ad547003d&X-Amz-SignedHeaders=host&x-amz-checksum-mode=ENABLED&x-id=GetObject)

   ![Saving the credential shows a confirmation](https://fdr-prod-docs-files-public.s3.us-east-1.amazonaws.com/moveworks.docs.buildwithfern.com/919ba92798ce9155af0db4f62ffa99a0c460bac7a5f628ca076f063d36ed6d5e/docs/assets/images/genesys-mw-03-symmetric-credential-saved.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Content-Sha256=UNSIGNED-PAYLOAD&X-Amz-Credential=AKIA6KXJSKKNFOCF7G4B%2F20260824%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20260824T222801Z&X-Amz-Expires=604800&X-Amz-Signature=8c52b8bb8ff54e7b930ee7ff7667f97275a9680a74cdd5f992d6e1f897870ca5&X-Amz-SignedHeaders=host&x-amz-checksum-mode=ENABLED&x-id=GetObject)

2. An **OAuth 2.0 Client** credential. Moveworks generates the client ID and client secret when you create it. Store them securely when they are shown. Genesys uses this credential to authenticate the agent-accept and agent-disconnect notifications built in Step 6, exchanging it for an access token at the Moveworks token endpoint:

   ```
   POST https://api.moveworks.ai/oauth/v1/token
   ```

   Replace the host with your data center's API host from the table above, matching the host in your webhook URL. The request body (JSON or form-encoded) carries `grant_type=client_credentials`, `client_id`, and `client_secret`. Access tokens are valid for 1 hour, and the Genesys credential configuration in Step 6 refreshes them automatically.

   ![OAuth 2.0 Client credential: a name and the credential type are all that is needed before publishing](https://fdr-prod-docs-files-public.s3.us-east-1.amazonaws.com/moveworks.docs.buildwithfern.com/bac316595ec84e339b209553d7a720c799ea1dd8c55f27a3e6ad9d77f63ff5ae/docs/assets/images/genesys-mw-04-oauth-credential-form.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Content-Sha256=UNSIGNED-PAYLOAD&X-Amz-Credential=AKIA6KXJSKKNFOCF7G4B%2F20260824%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20260824T222801Z&X-Amz-Expires=604800&X-Amz-Signature=39bb9c345422fbd586b0f9ac42ed67b5a701a13bfab11c368689107b78d763f3&X-Amz-SignedHeaders=host&x-amz-checksum-mode=ENABLED&x-id=GetObject)

   ![The generated client ID and client secret are shown once after saving. Store them securely.](https://fdr-prod-docs-files-public.s3.us-east-1.amazonaws.com/moveworks.docs.buildwithfern.com/b101bf4e100c56924919b76cd370450979f4cc961082e706ca72634a34b20113/docs/assets/images/genesys-mw-05-oauth-credential-saved.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Content-Sha256=UNSIGNED-PAYLOAD&X-Amz-Credential=AKIA6KXJSKKNFOCF7G4B%2F20260824%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20260824T222801Z&X-Amz-Expires=604800&X-Amz-Signature=cd7bfc8b0d5ca3adca7d4b92c65ceb6ca140f6d1aeec18fcb5b4ca20f46c2e7d&X-Amz-SignedHeaders=host&x-amz-checksum-mode=ENABLED&x-id=GetObject)

# Step 3: Create a Genesys OAuth client for Moveworks

Moveworks starts conversations and relays employee messages into Genesys through the Genesys Cloud API, authenticating with credentials you create.

1. In Genesys Cloud Admin, go to **Admin > Integrations > OAuth** (in the newer navigation, **Menu > IT and Integrations > OAuth**) and add a client using the **Client Credentials** grant type. See the Genesys article [Create an OAuth client](https://help.genesys.cloud/articles/create-an-oauth-client/).
2. Assign a role to the client. Client Credentials clients have no scope setting in Genesys Cloud, so the assigned role's permissions determine what the token can do. Create a dedicated role with the following permissions and assign it to the client:

   * **Conversation > Message > Receive** (`conversation:message:receive`), which authorizes starting conversations, relaying employee messages, and delivery receipts
   * **Conversation > Communication > Disconnect** (`conversation:communication:disconnect`), which authorizes ending the conversation when the employee leaves the chat
   * **Conversation > Message > Create** (`conversation:message:create`), **Conversation > Message > View** (`conversation:message:view`), and **Analytics > Conversation Detail > View** (`analytics:conversationDetail:view`), which cover related conversation reads and message operations

   The first two permissions are required by the Moveworks calls. The remaining three are recommended so the role also covers adjacent conversation lookups without needing a role change later.
3. Store the client ID and client secret securely, along with your Genesys Cloud region. Your region is visible in your Genesys Cloud login domain: for example, logging in at `apps.usw2.pure.cloud` means the region host `usw2.pure.cloud`, which is the value the Genesys Connector's region dropdown expects. You will enter all three in the Genesys Connector in Step 7.

# Step 4: Route the integration to a message flow in Genesys

1. In Genesys Cloud Admin, go to **Admin > Routing > Message Routing** and select **Attach New Addresses to a Flow** (labeled **Attach New Addresses** in some versions of the Genesys Admin UI).
2. Select the Architect **inbound message flow** that should receive Moveworks conversations and attach the Open Messaging integration as its address.

You can attach the integration to an existing chat flow (many organizations reuse their service desk chat flow) or create a dedicated flow for Moveworks. To create a dedicated one, see the Genesys article [Add an inbound message flow](https://help.genesys.cloud/articles/add-inbound-message-flow/).

![Message Routing: the Open Messaging integration attached as the address of the inbound message flow](https://fdr-prod-docs-files-public.s3.us-east-1.amazonaws.com/moveworks.docs.buildwithfern.com/272485af074e18e9c9a5fea3462da6788b98194887c304f67fc9e3cffd056f74/docs/assets/images/genesys-02-message-routing-configure-addresses.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Content-Sha256=UNSIGNED-PAYLOAD&X-Amz-Credential=AKIA6KXJSKKNFOCF7G4B%2F20260824%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20260824T222801Z&X-Amz-Expires=604800&X-Amz-Signature=ea24b97a36a22b68c18c0d6653c4345500f0044812da21970bccd1a6f9308062&X-Amz-SignedHeaders=host&x-amz-checksum-mode=ENABLED&x-id=GetObject)

# Step 5: Handle Moveworks conversations in the Genesys flow

Open the flow in Architect and make sure it does three things for Moveworks traffic:

1. **Detect Open Messaging conversations.** If the flow is shared with other channels, branch on the message type. A Decision step with the expression `Message.Message.type == "open"` identifies conversations arriving through Open Messaging.
2. **Read the employee identity.** Moveworks sends the employee's email address as the message sender. Capture it with `Message.Message.senderAddress` and set whatever participant data your agents rely on with the Architect **Set Participant Data** action (for example a display name derived from the address, and a marker attribute identifying the Moveworks channel).
3. **Send an automated greeting from the flow.** This step is required. Moveworks treats the first automated (bot-originated) message coming back from your flow as the signal that the handoff session is active. A flow that stays silent until an agent replies will never activate the session. A simple welcome message such as "Connecting you with the service desk…" is enough (the Architect **Send Response** action), and it also gives the employee immediate feedback.

After that, route to your queue with the Architect **Transfer to ACD** action (see the Genesys article [Transfer to ACD action](https://help.genesys.cloud/articles/transfer-acd-action/)). Moveworks sends the employee's full request text, so you can either transfer directly to a single queue or add intent-based routing (see the optional section at the end of this page). When you finish editing, save and **publish** the flow. Changes do not take effect until the flow is published.

![Flow start: Get Participant Data, then a Decision on Message.Message.type detects Open Messaging conversations](https://fdr-prod-docs-files-public.s3.us-east-1.amazonaws.com/moveworks.docs.buildwithfern.com/0b338c0ddebb424932e1b7c172ca4b814ea1bf01b99188b599e7f86012e6a167/docs/assets/images/genesys-03-flow-ss-start-detection.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Content-Sha256=UNSIGNED-PAYLOAD&X-Amz-Credential=AKIA6KXJSKKNFOCF7G4B%2F20260824%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20260824T222801Z&X-Amz-Expires=604800&X-Amz-Signature=05fadf69ca5873e5ef9d9d6a3a9fb916ba04a5c30950b99ad38419042f7294be&X-Amz-SignedHeaders=host&x-amz-checksum-mode=ENABLED&x-id=GetObject)

![Example: deriving the display name from the employee's email address](https://fdr-prod-docs-files-public.s3.us-east-1.amazonaws.com/moveworks.docs.buildwithfern.com/a3d82e2d986ec1a37a1d2ad85b6b082964c8d4693dad42ed73fe6682c69d12ee/docs/assets/images/genesys-04-flow-name-derivation.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Content-Sha256=UNSIGNED-PAYLOAD&X-Amz-Credential=AKIA6KXJSKKNFOCF7G4B%2F20260824%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20260824T222801Z&X-Amz-Expires=604800&X-Amz-Signature=d8997ce97d5d787eff21326ba340f99bb04c18936f83276aea025f9596a2dc22&X-Amz-SignedHeaders=host&x-amz-checksum-mode=ENABLED&x-id=GetObject)

# Step 6: Set up agent-accept and agent-disconnect notifications in Genesys

The Open Messaging webhook does not include agent details, and it does not tell Moveworks when the agent leaves. You provide both with two notifications built from standard Genesys Cloud features: event triggers invoke workflows, and the workflows call data actions that notify Moveworks.

This is the longest step, but each part is a small, standard Genesys object:

| You will create                         | Purpose                                                           |
| :-------------------------------------- | :---------------------------------------------------------------- |
| 1 Web Services Data Actions integration | Lets Genesys authenticate to Moveworks with the Step 2 credential |
| 2 notification data actions             | Send the agent-accept and agent-disconnect events to Moveworks    |
| 1 conversation-lookup data action       | Fetches the name of the agent who joined                          |
| 2 workflows                             | Look up the agent name and call the notification actions          |
| 2 event triggers                        | Run the workflows when an agent joins or leaves a conversation    |

Build them in the order below. Each subsection uses what the previous one created.

## 6a. Create the web services data actions integration

In **Admin > Integrations**, add a **Web Services Data Actions** integration (see the Genesys article [Add a data actions integration](https://help.genesys.cloud/articles/add-a-data-actions-integration/)). Then configure its credential so Genesys can authenticate to Moveworks:

1. On the integration's **Configuration > Credentials** tab, select the **User Defined (OAuth)** credential type and add three fields holding the values from Step 2: `clientId`, `clientSecret`, and `tokenUrl`. Field names in this credential type are your choice, and these three names are referenced below.

2. Genesys automatically creates a **custom auth action** for the integration. Open it from the Credentials page (**Custom Auth Action**) and configure it to call the Moveworks token endpoint: Request URL Template `${credentials.tokenUrl}`, Request Type `POST`, a `Content-Type: application/x-www-form-urlencoded` header, and this request body template:

   ```
   grant_type=client_credentials&client_id=${credentials.clientId}&client_secret=${credentials.clientSecret}
   ```

3. The fields of the token response become available to your data actions as `${authResponse.access_token}`. For details, see the Genesys articles [How to use the User Defined (OAuth) credential type](https://help.genesys.cloud/articles/how-to-use-the-user-defined-oauth-credential-type/) and [Workflow for the User Defined (OAuth) credential type](https://help.genesys.cloud/articles/workflow-for-the-user-defined-oauth-credential-type/).

![Web Services Data Actions integration with a User Defined (OAuth) credential](https://fdr-prod-docs-files-public.s3.us-east-1.amazonaws.com/moveworks.docs.buildwithfern.com/13bfec800e169906fba32fc321b2993cb4b108fa6e26f4338eea1238afdcb7fe/docs/assets/images/genesys-05-web-services-integration-credentials.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Content-Sha256=UNSIGNED-PAYLOAD&X-Amz-Credential=AKIA6KXJSKKNFOCF7G4B%2F20260824%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20260824T222801Z&X-Amz-Expires=604800&X-Amz-Signature=e20f136f87aa82ca790f6e664f96e947c7ecda6ca774d74cef41eafcd363ce7c&X-Amz-SignedHeaders=host&x-amz-checksum-mode=ENABLED&x-id=GetObject)

## 6b. Create the two notification data actions

Create both under the Web Services Data Actions integration in **Admin > Integrations > Actions > Add Action**, and publish them when done (see the Genesys article [Create a custom action](https://help.genesys.cloud/articles/create-custom-action-integrations/)). Configure both with:

* **HTTP Method**: `POST`
* **Request URL**: the Moveworks webhook URL from the table above, the same region-specific URL used in the Open Messaging integration (Step 1)
* **Headers**: `Content-Type: application/json`, plus `Authorization: Bearer ${authResponse.access_token}` (the access token from the integration credential configured above)
* **Execution Timeout**: 60 seconds
* **Input contract and request body template**:

Agent accepted (input contract: `conversationId` required, `userName`):

```json
{
  "conversationId": "${input.conversationId}",
  "userName": "${input.userName}",
  "event": "agent_accepts"
}
```

Agent disconnected (input contract: `conversationId` required):

```json
{
  "conversationId": "${input.conversationId}",
  "event": "agent_disconnect"
}
```

The `event` value is what Moveworks reads. `agent_accepts` updates the agent name shown to the employee, and `agent_disconnect` ends the Moveworks handoff session. Additional fields are ignored, so contracts that also pass `addressFrom` or `disconnectType` work unchanged.

![Agent-accepted data action input contract](https://fdr-prod-docs-files-public.s3.us-east-1.amazonaws.com/moveworks.docs.buildwithfern.com/949b879bbda5de08d2cf2a87e8d234239148fb322e814e5cc314d3c802b340b9/docs/assets/images/genesys-07-accept-action-contract.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Content-Sha256=UNSIGNED-PAYLOAD&X-Amz-Credential=AKIA6KXJSKKNFOCF7G4B%2F20260824%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20260824T222801Z&X-Amz-Expires=604800&X-Amz-Signature=4f6eacb74455842d7e83aae681f53e543ca826dc0ee457f28dd28a0228331101&X-Amz-SignedHeaders=host&x-amz-checksum-mode=ENABLED&x-id=GetObject)

![Agent-accepted data action configuration: POST to the Moveworks webhook URL with the Bearer authorization header and JSON body template](https://fdr-prod-docs-files-public.s3.us-east-1.amazonaws.com/moveworks.docs.buildwithfern.com/d4cd03cb4545ba194cb1b43eebe49615485d02352e22000f803d0b1288014a0b/docs/assets/images/genesys-08-accept-action-configuration.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Content-Sha256=UNSIGNED-PAYLOAD&X-Amz-Credential=AKIA6KXJSKKNFOCF7G4B%2F20260824%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20260824T222801Z&X-Amz-Expires=604800&X-Amz-Signature=b7e91863ad35ac00c41d2b2bfa308ab87df8eb379afe054e893970bdfe26b823&X-Amz-SignedHeaders=host&x-amz-checksum-mode=ENABLED&x-id=GetObject)

![Agent-disconnected data action configuration](https://fdr-prod-docs-files-public.s3.us-east-1.amazonaws.com/moveworks.docs.buildwithfern.com/7dfdb0144793de76fef7c471dc2def70accdb0e1a723190a3a375ef211d79c8e/docs/assets/images/genesys-09-disconnect-action-configuration.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Content-Sha256=UNSIGNED-PAYLOAD&X-Amz-Credential=AKIA6KXJSKKNFOCF7G4B%2F20260824%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20260824T222801Z&X-Amz-Expires=604800&X-Amz-Signature=2857c038fb28db5979290b601ba8d0416d5e41ee48b8a6dc631cf6594f16c993&X-Amz-SignedHeaders=host&x-amz-checksum-mode=ENABLED&x-id=GetObject)

![The two custom data actions in the Actions list](https://fdr-prod-docs-files-public.s3.us-east-1.amazonaws.com/moveworks.docs.buildwithfern.com/a0368003f800ba4ae469c4e743d1bd07943fe044c6460535aae65ff29b05d75a/docs/assets/images/genesys-06-data-actions-list.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Content-Sha256=UNSIGNED-PAYLOAD&X-Amz-Credential=AKIA6KXJSKKNFOCF7G4B%2F20260824%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20260824T222801Z&X-Amz-Expires=604800&X-Amz-Signature=cb03409288772a836bce478a8fd30de03e5c347da340e8828cc86ffc861f001b&X-Amz-SignedHeaders=host&x-amz-checksum-mode=ENABLED&x-id=GetObject)

## 6c. Create the conversation-lookup data action

Add a **Genesys Cloud Data Actions** integration (if you don't already have one). This integration authenticates with its own Genesys OAuth client, and that client's role must include the **Conversation > Communication > View** permission. On it, create a data action that calls `GET /api/v2/conversations/{conversationId}`, with a `conversationId` input and a Request URL template of `/api/v2/conversations/${input.conversationId}`. The response's `participants` array carries each participant's `purpose` and `name`, which the accept workflow reads to look up the name of the agent who joined.

## 6d. Create the two workflows

* **Accept workflow**: call the conversation-lookup data action with the conversation ID, find the participant whose `purpose` is `"agent"` and take its `name` as the agent's display name, then call the agent-accepted data action with the conversation ID and the agent name.
* **Disconnect workflow**: call the agent-disconnected data action with the conversation ID.

Create the workflows in Architect under the **Workflow** flow type (see the Genesys article [Work with workflows](https://help.genesys.cloud/articles/work-with-workflows/)). The triggers below deliver the event's fields (`conversationId`, `participantId`, `sessionId`, `disconnectType`, and others) directly as workflow variables when the trigger's Data Format is set to `TopLevelPrimitives`, so no extra lookups are needed for the conversation ID. For this to work, each workflow must declare an **input variable** for every event field it uses (at minimum `conversationId`): when creating the variable in Architect, mark it as an input on its **Data** tab. Event fields without a matching input variable are not passed in.

![Accept workflow: the conversation-lookup data action fetches conversation details](https://fdr-prod-docs-files-public.s3.us-east-1.amazonaws.com/moveworks.docs.buildwithfern.com/33f43f4027aa14625a709dc41db3d62aaa678ea750d85fb25c3731ce1f248e3d/docs/assets/images/genesys-10-accept-workflow-lookup.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Content-Sha256=UNSIGNED-PAYLOAD&X-Amz-Credential=AKIA6KXJSKKNFOCF7G4B%2F20260824%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20260824T222801Z&X-Amz-Expires=604800&X-Amz-Signature=1e44b07a5562889ba395ab36e4ab272fd90984ea9a5c3b910b1cd156742a30a6&X-Amz-SignedHeaders=host&x-amz-checksum-mode=ENABLED&x-id=GetObject)

![Accept workflow: loop over participants selecting the one whose purpose is agent](https://fdr-prod-docs-files-public.s3.us-east-1.amazonaws.com/moveworks.docs.buildwithfern.com/6651a6cf629e9984c0dfbb7e00f0f49a981cf0b6e8727aa626024a29c3063a83/docs/assets/images/genesys-11-accept-workflow-participant-loop.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Content-Sha256=UNSIGNED-PAYLOAD&X-Amz-Credential=AKIA6KXJSKKNFOCF7G4B%2F20260824%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20260824T222801Z&X-Amz-Expires=604800&X-Amz-Signature=233762d4e41c9c37a81c3a3d034fc2210f6fe2bdcd9894fb2758b94591b15f2e&X-Amz-SignedHeaders=host&x-amz-checksum-mode=ENABLED&x-id=GetObject)

![Accept workflow: the agent-accepted data action call with its input mappings](https://fdr-prod-docs-files-public.s3.us-east-1.amazonaws.com/moveworks.docs.buildwithfern.com/5c9077a43c1d42df5ce213574a5287ebbd8eaffcc9628e34ac8e7296723eeaa6/docs/assets/images/genesys-12-accept-workflow-notify-inputs.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Content-Sha256=UNSIGNED-PAYLOAD&X-Amz-Credential=AKIA6KXJSKKNFOCF7G4B%2F20260824%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20260824T222801Z&X-Amz-Expires=604800&X-Amz-Signature=35ea6e900f522c33f8e63c8c4130049d72c6dd846e9f3db72b5485762a092888&X-Amz-SignedHeaders=host&x-amz-checksum-mode=ENABLED&x-id=GetObject)

## 6e. Create the two event triggers

In **Admin > Architect > Triggers**, on the **Event Based Triggers** tab (see the Genesys article [Create a trigger](https://help.genesys.cloud/articles/create-a-trigger/)), create:

| Trigger      | Topic                                           | Invokes             |
| :----------- | :---------------------------------------------- | :------------------ |
| Agent joined | `v2.detail.events.conversation.{id}.user.start` | Accept workflow     |
| Agent left   | `v2.detail.events.conversation.{id}.user.end`   | Disconnect workflow |

Configure both triggers with **Data Format: `TopLevelPrimitives`** and add match conditions so they fire only for Open Messaging conversations:

* `mediaType` Equals `"MESSAGE"`
* `messageType` Equals `"OPEN"`

On the **agent-left trigger only**, add a third condition so that transfers do not end the session. The goal is to exclude every transfer-type disconnect value:

* `disconnectType` **Not In** `["TRANSFER", "CONFERENCE_TRANSFER", "CONSULT_TRANSFER", "FORWARD_TRANSFER", "NO_ANSWER_TRANSFER", "NOT_AVAILABLE_TRANSFER", "DND_TRANSFER"]`

Both topics are built into Genesys Cloud, so you select them from the topic list when creating the trigger. The `user.start` event also fires when a chat is auto-answered. New triggers are created in an Inactive state, so activate both after configuring them.

![Event Based Triggers list with the user.start and user.end triggers active](https://fdr-prod-docs-files-public.s3.us-east-1.amazonaws.com/moveworks.docs.buildwithfern.com/c5dec3eb137b34baf91382d452df2375378ef83a569f2c3e2b4b46d91c8b6071/docs/assets/images/genesys-13-triggers-list.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Content-Sha256=UNSIGNED-PAYLOAD&X-Amz-Credential=AKIA6KXJSKKNFOCF7G4B%2F20260824%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20260824T222801Z&X-Amz-Expires=604800&X-Amz-Signature=1deb7f20fe01f294e86dd6d6c46b381acee49bd055c8b53cb1f51e6a71c48a7c&X-Amz-SignedHeaders=host&x-amz-checksum-mode=ENABLED&x-id=GetObject)

![Agent-joined trigger: topic, workflow target, TopLevelPrimitives data format, and match conditions](https://fdr-prod-docs-files-public.s3.us-east-1.amazonaws.com/moveworks.docs.buildwithfern.com/fea22ac8537c43ed91a899fd316a48fcefb61713e5caac6fe6c6464e69e8835a/docs/assets/images/genesys-14-trigger-user-start-detail.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Content-Sha256=UNSIGNED-PAYLOAD&X-Amz-Credential=AKIA6KXJSKKNFOCF7G4B%2F20260824%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20260824T222801Z&X-Amz-Expires=604800&X-Amz-Signature=6134e6344a8740e29b5f153c8269407e56a84956cefcb88a988abd3f81114423&X-Amz-SignedHeaders=host&x-amz-checksum-mode=ENABLED&x-id=GetObject)

![Agent-left trigger: the disconnectType Not In transfer exclusion](https://fdr-prod-docs-files-public.s3.us-east-1.amazonaws.com/moveworks.docs.buildwithfern.com/dcda00d602b700fee6e4413a6bc6b62e066e696300ca0fc87ddc21c31642d940/docs/assets/images/genesys-15-trigger-user-end-detail.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Content-Sha256=UNSIGNED-PAYLOAD&X-Amz-Credential=AKIA6KXJSKKNFOCF7G4B%2F20260824%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20260824T222801Z&X-Amz-Expires=604800&X-Amz-Signature=408e39077539b36866cfc01f3a11fe8e8d6c8c591eb91cef51fcd11f878d3d54&X-Amz-SignedHeaders=host&x-amz-checksum-mode=ENABLED&x-id=GetObject)

#### Supervisor Live Monitoring

Genesys fires `user.start` for any agent-side participant who joins the conversation, including a supervisor who starts Live Monitoring. Without a filter, a monitoring session re-runs the accept workflow and the employee sees the supervisor's name instead of the agent's. Add match conditions to your accept trigger or workflow to exclude monitoring participants. The reference filter configuration is still being validated, so confirm the exact conditions with Moveworks support.

# Step 7: Create the Genesys Connector in Moveworks

In Moveworks Setup, go to **Connectors > Built-in Connectors**, select **Genesys**, and configure the connector with your **Genesys Cloud region** and the **OAuth client ID and secret** created in Step 3. This is what lets Moveworks call the Genesys Cloud API in your region.

![Built-in Connectors: select Genesys as the system to connect to](https://fdr-prod-docs-files-public.s3.us-east-1.amazonaws.com/moveworks.docs.buildwithfern.com/791ba5825221dcdd27384aabd09fe975bd7341f946be23b3ecd71dc4e725c200/docs/assets/images/genesys-mw-06-connector-select-genesys.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Content-Sha256=UNSIGNED-PAYLOAD&X-Amz-Credential=AKIA6KXJSKKNFOCF7G4B%2F20260824%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20260824T222801Z&X-Amz-Expires=604800&X-Amz-Signature=01170f11b26144974db6162cee5bf0d56dd7bd86f713f16d0ac63e5a933b15fb&X-Amz-SignedHeaders=host&x-amz-checksum-mode=ENABLED&x-id=GetObject)

![The Customer Region dropdown lists the Genesys Cloud regional hosts](https://fdr-prod-docs-files-public.s3.us-east-1.amazonaws.com/moveworks.docs.buildwithfern.com/e27502e45b0680c8799cd65b62d169216cd15e4b47698f756dee5b811c6e5914/docs/assets/images/genesys-mw-07-connector-region-dropdown.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Content-Sha256=UNSIGNED-PAYLOAD&X-Amz-Credential=AKIA6KXJSKKNFOCF7G4B%2F20260824%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20260824T222801Z&X-Amz-Expires=604800&X-Amz-Signature=4c7218a9207a2818d21455682c09c36a59909063e4325439e453d0a8f18480a4&X-Amz-SignedHeaders=host&x-amz-checksum-mode=ENABLED&x-id=GetObject)

![Connector credential details: region, client ID, and client secret (example values shown)](https://fdr-prod-docs-files-public.s3.us-east-1.amazonaws.com/moveworks.docs.buildwithfern.com/29b1a2889951812de992db31710478706a9c15995c7714a67d99a9fdffce06bc/docs/assets/images/genesys-mw-08-connector-details-filled.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Content-Sha256=UNSIGNED-PAYLOAD&X-Amz-Credential=AKIA6KXJSKKNFOCF7G4B%2F20260824%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20260824T222801Z&X-Amz-Expires=604800&X-Amz-Signature=8064691b87f4cfc3639934bfd2b1a5456513aeed6e5123b93d5a91b502e99364&X-Amz-SignedHeaders=host&x-amz-checksum-mode=ENABLED&x-id=GetObject)

With this step, the connection between Moveworks and Genesys is established. Continue with [Configure Genesys Live Agent Message Brokering](/service-management/live-agent-handoff-assistant/live-agent-message-brokering-assistant/live-agent-genesys), keeping the **Open Messaging integration ID** from Step 1 at hand.

# Optional: intent-based queue routing

Moveworks sends the employee's request as free text (for example "my VPN keeps disconnecting"), not a menu selection. If you route different issue types to different queues, add a **Digital Bot Flow** in front of the queue transfer:

* Pass `Message.Message.body` (the employee's text) as the bot input.
* Classify it to intents. A common approach is a slot with **List** slot-type values whose synonym lists cover your issue vocabulary (for example a telephony intent matching "ringing" or "calls dropping", and a software intent matching "VPN", "Citrix", or "Outlook"), with a fallback intent for everything else.
* Route each intent to its queue.

This is optional. If all live chats go to one queue, transfer directly and skip the bot. Genesys prices bot flows separately (usage-based), independent of the Moveworks integration.

![Digital bot flow: Ask for Slot maps the employee's text to an intent value with fallbacks](https://fdr-prod-docs-files-public.s3.us-east-1.amazonaws.com/moveworks.docs.buildwithfern.com/7251b6d0cfab13afd2ca392dd9f789605f77f5802603e3f407322a6dc2458d64/docs/assets/images/genesys-16-bot-flow-canvas.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Content-Sha256=UNSIGNED-PAYLOAD&X-Amz-Credential=AKIA6KXJSKKNFOCF7G4B%2F20260824%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20260824T222801Z&X-Amz-Expires=604800&X-Amz-Signature=acd3cf9e0b04bc76865019adf416ed8954608c86b17ec31033efa240faf9b849&X-Amz-SignedHeaders=host&x-amz-checksum-mode=ENABLED&x-id=GetObject)

![List slot type: values act as intents, each with a synonym list](https://fdr-prod-docs-files-public.s3.us-east-1.amazonaws.com/moveworks.docs.buildwithfern.com/7225b4b783ffca318471b3ecedf14204a8a90481448552e22438debb2853b336/docs/assets/images/genesys-17-slot-type-menuoptions.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Content-Sha256=UNSIGNED-PAYLOAD&X-Amz-Credential=AKIA6KXJSKKNFOCF7G4B%2F20260824%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20260824T222801Z&X-Amz-Expires=604800&X-Amz-Signature=76b4ea4c1887024bba767ba40ec396395e1333ee7d99b0eb3c08c0ffe13fee13&X-Amz-SignedHeaders=host&x-amz-checksum-mode=ENABLED&x-id=GetObject)

# Next step

With the access requirements complete, continue with [Configure Genesys Live Agent Message Brokering](/service-management/live-agent-handoff-assistant/live-agent-message-brokering-assistant/live-agent-genesys), keeping the Open Messaging integration ID from Step 1 at hand.