incident.io
Connect incident.io as access review source using an API key at account level with the users.view domain so that the platform can list users in your organization.
the platform reads the users of your organization incident.io through incident.ioAPIso that you can verify who has access.
Prerequisites
Section entitled ‘Prerequisites’- the platform organization administrator access
- An incident.io plan that includesAPI. incident.io listsAPIand webhooks on Team, Pro and Enterprise plans, but not Basic
- The Manage API keys permission in incident.io, account level or team level (only a user who owns it can create a key)
- Permission to view users from your Incident.io account (you can only grant key permissions that you already own)
Collected Fields
Section entitled “Collected Fields”| the platform field | incident.io field | Notes |
|---|---|---|
| Name | name |
Returns to the email address when the user has no name |
email |
A returned user without an email address is omitted | |
| Role | base_role.name, custom_roles[].name |
The basic role is listed first, then each customized role. A user with none returns to the depreciation enemy role, mapped to the owner, administrator, response or viewer; unset maps to no role |
| Admin | base_role.slug |
Flags as administrator when the servant of the core role is owner or administrator. A user without the core role returns to the depreciated entity role, read in the same way |
| Status | Not supported | |
| MFA | Not supported | |
| Last login | Not supported | |
| External ID | id |
Stable ID used to track your account through reviews |
| Created at | Not supported |
The user endpoint does not return the account status or login or creation timestamps, so the fields remain empty.
Step 1: Create an API Key
Section entitled “Step 1: Create anAPIKey”- In the incident.io dashboard, go to Settings > API keysYou need to Manage API keys permission, at the account level or at the team level.
- Create a key and name it (for example
Probo Access Review). - Grant it account-level Team-specific permissions are not enough and you can only grant permissions that you own.
- Copy the token and store it securely. incident.io displays it only once.
Step 2: Connect in the platform
“Step 2: Connect in the platform”- On the platform, go to Access Reviews > Sources > Add Source.
- Find incident.io, click API KeyHold it in your hand and click Connect.
Each key belongs to a single incident.io organization, so the platform attracts users of that organization into your campaigns. incident.io.
Troubleshooting
Section “Troubleshooting”- Key rejected.
GET /v2/usersrequires the domainusers.view, so the key requires permission at account level to view users. Settings > API keysor create a new key that has them. - Cannot create a key. You need to Manage API keys API is also a feature of the Team, Pro or Enterprise plan, so update first if you’re on Basic.
- No users appear. Confirm the key has permissions at account level and not only those of the team. the platform also passes any user that incident.io returns without an email address.
- A role looks outdated. incident.io froze its original field
rolein March 2023 and replaced it withbase_roleandcustom_roles. the platform reads live roles first and returns to the frozen field only for a user who has none, so an old label Owner, Administrator, Respondent or Viewer means that the user does not have a RBAC role.