Skip to main content
Telara

Integrations / SailPoint Identity Security Cloud

SailPoint Identity Security Cloud logo

SailPoint Identity Security Cloud

SailPoint Identity Security Cloud identity governance data for identities, sources, access profiles, roles, entitlements, and account/source mappings.

OAuth 2.0
Indexes
Actions

What Telara does

Capability matrix

Before you connect

Prerequisites

A SailPoint Identity Security Cloud tenant you can administer.
Admin who can create a personal access token or OAuth client.

Vendor setup

Get the credential

1
Open API tokens
In Identity Security Cloud, click your avatar → Preferences → Personal Access Tokens (or Admin → API Management).
2
Create a token
Click New Token. Name it for Telara. Grant the permissions this page lists. Copy the token once. Also copy your tenant API host (the *.api.identitynow.com host).
3
Paste in Telara
Settings → Integrations → SailPoint Identity Security Cloud. Paste the token and the tenant API root Telara asks for.

In Telara

Connect in Telara

OAuth 2.0

SailPoint Identity Security Cloud client-credentials OAuth for a tenant API client. The customer supplies the tenant subdomain, API client ID and secret, and v2024 base URL. Browser authorization-code and refresh-token flows are documented by SailPoint but intentionally not exposed until tenant-aware callback routing is available.

In Telara, open Settings → Integrations, choose this connector, and click Connect. Telara sends you to the vendor to approve access, then returns you here. You do not create an OAuth app or paste a client secret.

Fields Telara asks for
  • Tenant
  • Base Url
API key

SailPoint bearer token. Store base_url as the tenant v2024 API root, for example https://tenant.api.identitynow.com/v2024.

In Telara, open Settings → Integrations, choose this connector, and paste the key into the fields Telara shows.

Fields Telara asks for
  • API token

Knowledge

What gets indexed

ResourceCoverage
IdentityPartial — not every record the vendor holds is synced
RolePartial — not every record the vendor holds is synced

Sync

Freshness & sync

ResourceLagDeletions
IdentityUp to 1 dayRemoved records disappear on the next full sync
RoleUp to 1 dayRemoved records disappear on the next full sync

Data handling

Permissions & data handling

Telara has not published a permission list for this connector yet. Treat the vendor consent screen as the source of truth until this page lists scopes.

Excluded from semantic search: Identity, Role.

After connect

Verify it worked

After you save, Telara runs a read-only check against the account. The integration shows as connected when that check succeeds.

Honesty

Known limitations

IdentityIQ on-prem is not this connector.
A token from a user who cannot read identities produces an empty directory.