The Enhanced eBuy integration lets GovDash sync opportunity data and solicitation attachments directly from a customer-authorized GSA eBuy account, so a team can review and manage those records inside GovDash instead of monitoring eBuy by hand. This article is for the GovDash and eBuy administrators and security reviewers who approve and configure it. It covers how setup works, what access GovDash uses, how data is handled across its lifecycle, and the controls you have over it. For the functional walkthrough, see the eBuy integration docs.
Set Up in 6 Steps
Setup involves two roles. Confirm both are available before you start:
GovDash Team Admin: needs the Manage Team Integrations permission and performs the configuration inside GovDash.
GSA eBuy / FAS ID account holder or admin: authorized to add GovDash's generated email address to the customer's eBuy account.
Once both are in place, complete these six steps:
In GovDash, go to the eBuy integration settings page.
Click Request Access if the eBuy integration has not been created yet.
Click Enable Advanced Integration, review the disclosures, confirm authorization, and enter the initial eBuy password for the integration account.
Copy the generated GovDash eBuy email address, formatted like ebuy+[identifier]@integrations.govdash.com.
In GSA eBuy / FAS ID, add that address as an authorized user or contact for the relevant eBuy account. This works the same as the non-enhanced integration; see the standard setup steps.
GovDash completes account setup, receives the MFA verification emails, and begins syncing eBuy contracts, RFx records, details, and attachments for the authorized account.
Permissions and Scoping
Enhanced eBuy is optional and off by default. It is customer-authorized access, not an official GSA-endorsed integration. GSA eBuy does not offer OAuth-style granular scopes for this workflow, so access is bounded by the permissions, contracts, and RFx visibility of the eBuy/FAS ID account the customer authorizes GovDash to use.
eBuy / GSA Access
GovDash signs in to eBuy through the authorized FAS ID account and uses that session for the following:
Access | Why GovDash Requests It |
MFA email access | Completes FAS ID authentication during setup and scheduled syncs, using the generated GovDash eBuy address. |
Seller contract list | Identifies the contracts available to the authorized eBuy account. |
RFx / notification access | Discovers RFQs, RFIs, and related opportunity records available to the account. |
RFx detail access | Populates opportunity metadata in GovDash: title, description, due and issue dates, place of performance, agency, office, buyer contact, contract type, award method, and delivery information. |
RFx attachment download | Retrieves solicitation documents and makes them available inside GovDash. |
GovDash does not submit quotes, edit RFx records in eBuy, award work, message buyers, or make procurement decisions through this integration.
GovDash Permissions Required
GovDash Permission | Why Required |
Read in Discover | View synced eBuy opportunities, contracts, and related records. |
Manage Team Integrations | Create the integration, grant or revoke enhanced consent, update the integration password, and manage connected contract labels. |
GovDash Admin Access | Lets internal GovDash administrators view integration health and configure the generated eBuy identifier when needed. |
CUI Handling
eBuy opportunities and attachments may contain CUI, procurement-sensitive information, or other customer-restricted data. GovDash treats all enhanced eBuy data as team-scoped customer data classified as CUI. Records are scoped to the customer team and are never shared with other teams.
Data ingress
Data enters GovDash through two paths:
eBuy / FAS ID emails sent to the generated GovDash integration address, such as onboarding emails, MFA verification codes, and eBuy notification emails.
Authenticated HTTPS requests from GovDash to GSA eBuy after the customer explicitly enables enhanced access.
Through these paths GovDash ingests contract lists, RFx identifiers, RFx details, buyer and contact information, due dates, agency and office details, place of performance, descriptions, and solicitation attachments available to the authorized account.
Data in transit
GovDash communicates with GSA eBuy and FAS ID over HTTPS/TLS. Authentication, RFx retrieval, contract retrieval, and attachment downloads are all performed over encrypted transport. Inbound email processing and customer access to the application are also encrypted in transit, and users reach the synced data only through authenticated GovDash sessions.
Data at rest
Synced RFx metadata is stored in the GovDash database and scoped to the customer team. Solicitation attachments are stored in GovDash-managed object storage and linked back to the team-scoped records.
The eBuy password is encrypted before storage. Temporary workflow secrets such as session cookies, state tokens, access tokens, and redirect URLs are encrypted while carried through workflow execution. MFA codes are retained only long enough to complete the authentication flow and are cleared when enhanced consent is revoked.
Access controls
Synced eBuy data is not shared across GovDash teams. Access is enforced through GovDash authentication, team scoping, and role-based permissions, so a user needs the appropriate GovDash permissions to view Discover data or manage the integration.
Revocation
When enhanced consent is revoked, GovDash clears the stored enhanced-authentication material, including the encrypted password and MFA fields, and stops using enhanced eBuy access for that team. The standard eBuy email-forwarding integration remains available separately. Previously synced records may remain in GovDash unless they are removed under the customer's own retention or deletion process.
Data Shared with GovDash
The enhanced integration shares the following with GovDash:
The integration email address and encrypted eBuy password.
MFA verification codes.
Contract and RFx identifiers, titles, and descriptions.
Issue and close dates, and RFx status.
Buyer, agency, office, and contact details.
Place of performance and related contract metadata.
Solicitation attachments.
All data in the enhanced eBuy integration is treated as CUI, and every document is tagged as CUI automatically.
Data Flow Diagram

Operational Notes
Enhanced eBuy sync runs on a scheduled workflow for integrations that are marked healthy and have consent recorded. Integration status can be PENDING, HEALTHY, or UNHEALTHY. The standard eBuy email-forwarding workflow stays available even if enhanced consent is revoked.
Rotate the integration password periodically. GovDash surfaces the last password update date and marks passwords older than 90 days as expired.
This integration is provided “as is” and “as available,” without warranties of any kind, express or implied. By following the setup instructions and enabling it, you accept responsibility for configuring, testing, and maintaining it in your own environment. Use is at your own risk, and GovDash disclaims liability for errors, service interruptions, data loss, security issues, or other damages arising from its installation, configuration, or use.