jump to content

UpCloud

Connect UpCloud as your access review source using an API tokenfor the main account to review each account and subaccount in the UpCloud contract.

Show as Markdown

The platform reads the main account of your UpCloud contract and its subaccounts through UpCloudAPI so you can verify who has access.

  • the platform organization administrator access
  • Accesul la UpCloud main account (a subaccount only sees itself)
the platform field UpCloud field Notes
Name first_name, last_name From the account details. returns to username when the name is empty
Email email From account details
Role roles.role Orice technical, billing, aux_billing
Admin type Tagged as administrator for the main account (any type other than sub)
Status Not supported
MFA Not supported
Last login Not supported
External ID username Stable ID used to track your account through reviews
Created at Not supported

The UpCloud Control Panel displays a 2FA status column under People, but the API does not expose that field to any account endpoint, so the platform cannot collect it.

Creating an API token in the UpCloud Control Panel

  1. In the UpCloud Control PanelConnected as the main account, go to Account > API tokens.
  2. Click Add new API token and enter a name (for example Probo Access Review).
  3. Set ExpirationSource stops synchronization once the token expires, so choose the longest time that your policy allows and plan to spin the token before that date.
  4. Leave Allow this token to create other tokens The platform only reads accounts.
  5. For ZebraByte Cloud, keep Allows access from all IP addresses For a self-hosted implementation with fixed egress addresses, you can restrict the token to these addresses.
  6. Click Create API token, then copy the token (ucat_…) and save it securely.

Step 2: Connect in the platform

“Step 2: Connect in the platform”
  1. On the platform, go to Access Reviews > Sources > Add Source.
  2. Find UpCloud, click API KeyHold it in your hand and click Connect.

The platform names the source after the account to which the token belongs and draws the contract accounts into your campaigns.

  • Token rejected. Confirms that the token starts with ucat_ and has not expired. Allows access from all IP addressesA self-hosted implementation can use its fixed addresses egress. upcloud username and password will not work here.
  • Conturile contractului nu au trecut. Account listing is only available for the main account, so a token created under a sub-account is rejected and the source cannot list the contract.
  • One account lacks your name and email address. The token could not read the details of that account.

Ultima actualizare: