# Aikido Security + Lutril: setup guide

> Lutril connects to Aikido Security with an API client, using the OAuth client credentials flow. It reads your Aikido users with their role, their sign in method and their last activity, and it time boxes the admin role: a grant raises somebody's role for as long as the access lasts, then Lutril writes their previous role back at the deadline. Aikido's API cannot create or deactivate accounts, and Lutril never pretends otherwise. Accounts arrive through your source control sync or through SAML, and removing one stays a manual step in the Aikido console.

Source: https://www.lutril.com/integrations/aikido
Category: Security
Auth: oauth
Last verified: 2026-10-01

---

## Setup

1. [object Object]
2. [object Object]
3. Copy the client ID and the client secret straight away. Aikido shows the secret once and will not display it again.
4. Note the region your workspace runs in. It is in the address you sign in to: app.aikido.dev for Europe, app.us.aikido.dev for the United States, app.au.aikido.dev for Australia, app.me.aikido.dev for the Middle East. A client created in one region is not accepted by another.
5. In Lutril, connect Aikido, paste the client ID and the client secret, then pick the matching data region.
6. [object Object]
7. A grant only ever raises a role. Anyone who already holds the role they asked for, or a higher one, is left exactly as they were, so a deadline can never take away access that Lutril did not grant. Read only status and the individual permission flags are preserved untouched in both directions.

## Access requested

- users:read (list the workspace users, and read one user's rights)
- users:write (raise a role for a time boxed grant, and restore the previous one at the deadline)

## References

- [Aikido Security documentation](https://apidocs.aikido.dev/reference/authorization)
- [Aikido Security console](https://app.aikido.dev/settings/integrations/api/aikido/rest)
- [Aikido API authorization](https://apidocs.aikido.dev/reference/authorization)
- [List users endpoint](https://apidocs.aikido.dev/reference/listusers)
- [Update user rights endpoint](https://apidocs.aikido.dev/reference/updateuserrights)
- [Roles and permissions in Aikido](https://help.aikido.dev/getting-started/automated-user-management/setting-roles-and-permissions)
