
Connecter Aikido Security à Lutril
Lutril connects to Aikido Security with an API client, using the OAuth client credentials flow. It reads your Aikido users with their role, their sign in method and their last activity, and it time boxes the admin role: a grant raises somebody's role for as long as the access lasts, then Lutril writes their previous role back at the deadline. Aikido's API cannot create or deactivate accounts, and Lutril never pretends otherwise. Accounts arrive through your source control sync or through SAML, and removing one stays a manual step in the Aikido console.
Accès demandés
- users:read (list the workspace users, and read one user's rights)
- users:write (raise a role for a time boxed grant, and restore the previous one at the deadline)
Étapes de configuration
- 1
Sign in to Aikido as an admin and open Settings, then Integrations, then API. You need the admin role to create a client.
Open Aikido API settings - 2
Select Create client, name it something like Lutril, and tick only the users:read and users:write scopes. Nothing else is needed: Lutril reads the roster and changes roles, and never touches your repositories, clouds or findings.
Aikido API authorization - 3
Copy the client ID and the client secret straight away. Aikido shows the secret once and will not display it again.
- 4
Note the region your workspace runs in. It is in the address you sign in to: app.aikido.dev for Europe, app.us.aikido.dev for the United States, app.au.aikido.dev for Australia, app.me.aikido.dev for the Middle East. A client created in one region is not accepted by another.
- 5
In Lutril, connect Aikido, paste the client ID and the client secret, then pick the matching data region.
- 6
To time box Aikido access, set the access levels on the Aikido app in your catalogue to admin, default and team_only. Those are Aikido's own role names, so what somebody requests is exactly what they get.
Roles and permissions in Aikido - 7
A grant only ever raises a role. Anyone who already holds the role they asked for, or a higher one, is left exactly as they were, so a deadline can never take away access that Lutril did not grant. Read only status and the individual permission flags are preserved untouched in both directions.
Où le créer
Documentation officielle
Connectez-vous à Lutril pour brancher Aikido Security, ou réservez une démo et nous le mettons en place avec vous. Sans slides.