Skip to main content

Capabilities

Additional functionality:
  • Create and delete members.
  • Assign and unassign a base role (reader, writer, admin, no_access) on members. Unassign sets the member to no_access. Owner-role transfer is not exposed; it requires LaunchDarkly’s UI-only reauthentication flow.
  • Grant and revoke custom-role assignments on members.
  • Add and remove members from teams.
LaunchDarkly has no separate disabled or deactivated member state, so the connector maps a disable request to deletion. Provisioning through this connector isn’t supported on LaunchDarkly accounts that have SCIM provisioning enabled; manage LaunchDarkly members through your identity provider instead.

Gather LaunchDarkly configuration information

Configuring the connector requires you to pass in information from LaunchDarkly. Gather these configuration details before you move on. Here’s the information you’ll need:
  • API Access Token
  • Base URL (optional) — only needed for non-US tenants. Use https://app.eu.launchdarkly.com for EU tenants or https://app.launchdarkly.us for Federal tenants. Leave unset for US commercial tenants (defaults to https://app.launchdarkly.com). The value must be exactly one of those three URLs — LaunchDarkly’s regions are subdomains, not paths, so a form like https://app.launchdarkly.com/eu is rejected at startup rather than treated as a valid EU host.
See the LaunchDarkly docs for information on how to acquire credentials: View the documentation This connector requires an access token with one of the following permission sets:
  • Reader base role (sufficient for read-only sync). Note that syncing teams and custom roles additionally requires an Enterprise plan — see the warning below; no base role substitutes for it.
  • Admin base role, or a custom role granting createMember, deleteMember, updateRole, and updateCustomRole on member/* plus updateTeamMembers on team/*, is required to also create and delete members, assign base roles and custom roles, and change team membership.
This connector requires a LaunchDarkly Enterprise plan. A token’s base role cannot substitute for the plan.
  • Sync. Teams and custom roles are Enterprise-only features, so on the Developer and Foundation plans GET /api/v2/teams and GET /api/v2/roles return 403 Forbidden regardless of the access token’s role, and the sync fails.
  • Base-role deprovisioning. Unassigning a base role is performed by assigning the No access role, because LaunchDarkly members always hold exactly one base role and there is no removal operation. On a plan that does not offer No access, every base-role revoke fails with 400 {"message":"Invalid role: no_access"}.

Configure the LaunchDarkly connector

To complete this task, you’ll need:
  • The Connector Administrator or Super Administrator role in C1
  • Access to the set of LaunchDarkly configuration information gathered by following the instructions above
Follow these instructions to use a built-in, no-code connector hosted by C1.
1
In C1, navigate to Apps > Connectors and click Add connector.
2
Search for LaunchDarkly and click Add.
3
Choose where to add the connector: Create a new app, or Add to an existing app (then select the app).If you’re creating a new app, choose whether to link it to an application discovered from your identity provider: select Yes and pick the IdP application, or No to continue with just the connector.
4
Set the connector’s Name and, optionally, a Description.
5
Click the pencil icon next to Owners to choose who can configure and manage this connector.
6
Click Add. The connector is created and its configuration page opens.
7
Find the Settings area of the page and click Edit.
8
Enter the configuration information from the previous section.
9
Click Save.
10
The connector’s label changes to Syncing, followed by Connected. You can view the logs to ensure that information is syncing.
Done. Your LaunchDarkly connector is now pulling access data into C1.