Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
35 changes: 33 additions & 2 deletions baton/coupa.mdx
Original file line number Diff line number Diff line change
@@ -1,13 +1,13 @@
---
title: "Set up a Coupa connector"
og:title: "Set up a Coupa connector"

Check warning on line 3 in baton/coupa.mdx

View check run for this annotation

Mintlify / Mintlify Validation (conductorone) - vale-spellcheck

baton/coupa.mdx#L3

Did you really mean 'Coupa'?
description: "C1 provides identity governance for Coupa. Integrate your Coupa instance with C1 to run user access reviews (UARs) and enable just-in-time access requests."
og:description: "C1 provides identity governance for Coupa. Integrate your Coupa instance with C1 to run user access reviews (UARs) and enable just-in-time access requests."

Check warning on line 5 in baton/coupa.mdx

View check run for this annotation

Mintlify / Mintlify Validation (conductorone) - vale-spellcheck

baton/coupa.mdx#L5

Did you really mean 'Coupa'?

Check warning on line 5 in baton/coupa.mdx

View check run for this annotation

Mintlify / Mintlify Validation (conductorone) - vale-spellcheck

baton/coupa.mdx#L5

Did you really mean 'UARs'?
sidebarTitle: "Coupa"
---

<Tip>
**This is an updated and improved version of the Coupa connector!** If you're setting up Coupa with C1 for the first time, you're in the right place.

Check warning on line 10 in baton/coupa.mdx

View check run for this annotation

Mintlify / Mintlify Validation (conductorone) - vale-spellcheck

baton/coupa.mdx#L10

Did you really mean 'Coupa'?

Check warning on line 10 in baton/coupa.mdx

View check run for this annotation

Mintlify / Mintlify Validation (conductorone) - vale-spellcheck

baton/coupa.mdx#L10

Did you really mean 'Coupa'?
</Tip>

## Capabilities
Expand All @@ -21,61 +21,92 @@
| Roles | <Icon icon="square-check" iconType="solid" color="#c937ae"/> | <Icon icon="square-check" iconType="solid" color="#c937ae"/> |
| Licenses | <Icon icon="square-check" iconType="solid" color="#c937ae"/> | <Icon icon="square-check" iconType="solid" color="#c937ae"/> |

¹ Account Groups sync is opt-in. To enable it, select **Account Groups** in the resource types to sync when configuring the connector in C1, and ensure the `core.accounting.read` OAuth scope is added to your Coupa OAuth client.

Check warning on line 24 in baton/coupa.mdx

View check run for this annotation

Mintlify / Mintlify Validation (conductorone) - vale-spellcheck

baton/coupa.mdx#L24

Did you really mean 'Coupa'?

The **Licenses** resource surfaces each user's Coupa license assignments — such as Analytics, Purchasing, Sourcing, CLM Advanced, Navi AI Agent, and Intake — as license profiles, so they can be reviewed and provisioned through C1 License Management.

Check warning on line 26 in baton/coupa.mdx

View check run for this annotation

Mintlify / Mintlify Validation (conductorone) - vale-spellcheck

baton/coupa.mdx#L26

Did you really mean 'Coupa'?

Check warning on line 26 in baton/coupa.mdx

View check run for this annotation

Mintlify / Mintlify Validation (conductorone) - vale-spellcheck

baton/coupa.mdx#L26

Did you really mean 'Navi'?

### Account provisioning

C1 can create Coupa user accounts. When you configure account provisioning for the app, map these profile fields:

Check warning on line 30 in baton/coupa.mdx

View check run for this annotation

Mintlify / Mintlify Validation (conductorone) - vale-spellcheck

baton/coupa.mdx#L30

Did you really mean 'Coupa'?

| Field | Description |
|-------|-------------|
| First name | First name of the person who will own the Coupa user. |

Check warning on line 34 in baton/coupa.mdx

View check run for this annotation

Mintlify / Mintlify Validation (conductorone) - vale-spellcheck

baton/coupa.mdx#L34

Did you really mean 'Coupa'?
| Last name | Last name of the person who will own the Coupa user. |

Check warning on line 35 in baton/coupa.mdx

View check run for this annotation

Mintlify / Mintlify Validation (conductorone) - vale-spellcheck

baton/coupa.mdx#L35

Did you really mean 'Coupa'?
| Email | Email address of the Coupa user. Defaults to the C1 user's primary email. |

Check warning on line 36 in baton/coupa.mdx

View check run for this annotation

Mintlify / Mintlify Validation (conductorone) - vale-spellcheck

baton/coupa.mdx#L36

Did you really mean 'Coupa'?
| Login | Login for the Coupa user. Defaults to the C1 user's username. |

Check warning on line 37 in baton/coupa.mdx

View check run for this annotation

Mintlify / Mintlify Validation (conductorone) - vale-spellcheck

baton/coupa.mdx#L37

Did you really mean 'Coupa'?
| SSO identifier | Single sign-on identifier for the Coupa user. |
| Employee number | Employee number for the Coupa user. |

Check warning on line 39 in baton/coupa.mdx

View check run for this annotation

Mintlify / Mintlify Validation (conductorone) - vale-spellcheck

baton/coupa.mdx#L39

Did you really mean 'Coupa'?
| Manager login | Login of the user's manager in Coupa. |

Check warning on line 40 in baton/coupa.mdx

View check run for this annotation

Mintlify / Mintlify Validation (conductorone) - vale-spellcheck

baton/coupa.mdx#L40

Did you really mean 'Coupa'?
| Purchasing user | Assign a Purchasing license when the account is created. |
| Invoicing user | Assign an Invoicing license when the account is created. |
| Sourcing user | Assign a Sourcing license when the account is created. |
| Account security type | Numeric Coupa account security type. |

Check warning on line 44 in baton/coupa.mdx

View check run for this annotation

Mintlify / Mintlify Validation (conductorone) - vale-spellcheck

baton/coupa.mdx#L44

Did you really mean 'Coupa'?
| Authentication method | `coupa_credentials`, `ldap`, or `saml`; values are case-sensitive. |
| Authentication method | `coupa_credentials`, `ldap`, or `saml`; values are case-sensitive. Only the methods enabled on your Coupa instance are accepted. |

Check warning on line 45 in baton/coupa.mdx

View check run for this annotation

Mintlify / Mintlify Validation (conductorone) - vale-spellcheck

baton/coupa.mdx#L45

Did you really mean 'Coupa'?
| Default locale | Default locale, such as `en` or `en-GB`. |
| Default account type | Name of the user's default Coupa account type. |

Check warning on line 47 in baton/coupa.mdx

View check run for this annotation

Mintlify / Mintlify Validation (conductorone) - vale-spellcheck

baton/coupa.mdx#L47

Did you really mean 'Coupa'?
| Default currency | ISO currency code, such as `USD`. |
| Custom fields | Map of instance-specific Coupa user field names to values. |
| Custom fields | Map of your Coupa instance's custom user field names to values, for example `{"cost-center": "CC-100"}`. |

Check warning on line 49 in baton/coupa.mdx

View check run for this annotation

Mintlify / Mintlify Validation (conductorone) - vale-spellcheck

baton/coupa.mdx#L49

Did you really mean 'Coupa'?

Every field is optional to C1. Map **First name** and **Last name** regardless — Coupa has no other source for a new user's name.

Check warning on line 51 in baton/coupa.mdx

View check run for this annotation

Mintlify / Mintlify Validation (conductorone) - vale-spellcheck

baton/coupa.mdx#L51

Did you really mean 'Coupa'?

Accounts are created active. The connector does not set a password.

Custom fields are sent in Coupa's `custom-fields` namespace. License assignments can also be managed after account creation through C1 License Management.

Check warning on line 55 in baton/coupa.mdx

View check run for this annotation

Mintlify / Mintlify Validation (conductorone) - vale-spellcheck

baton/coupa.mdx#L55

Did you really mean 'Coupa's'?

Check warning on line 55 in baton/coupa.mdx

View check run for this annotation

Mintlify / Mintlify Validation (conductorone) - vale-spellcheck

baton/coupa.mdx#L55

Did you really mean 'namespace'?

The connector trims surrounding whitespace from **Email**, **Login**, **SSO identifier**, **Employee number**, **Manager login**, **Authentication method**, **Default locale**, **Default account type**, and **Default currency**. A value that is only whitespace counts as unmapped. **First name** and **Last name** are sent as-is.

**Purchasing user**, **Invoicing user**, and **Sourcing user** must be mapped to boolean values, and **Account security type** to a number. A value of any other type, such as the text `"false"`, is ignored and not sent to Coupa. Custom field values are sent with the type they are mapped with.

Check warning on line 59 in baton/coupa.mdx

View check run for this annotation

Mintlify / Mintlify Validation (conductorone) - vale-spellcheck

baton/coupa.mdx#L59

Did you really mean 'Coupa'?

<Note>
The extended attributes are set only when the account is created. The connector does not update SSO identifier, employee number, manager, security and authentication settings, locale, default account type, default currency, or custom fields on existing Coupa users. It also does not sync these attributes back into C1: synced Coupa accounts carry only login, email, name, and status.

Check warning on line 62 in baton/coupa.mdx

View check run for this annotation

Mintlify / Mintlify Validation (conductorone) - vale-spellcheck

baton/coupa.mdx#L62

Did you really mean 'Coupa'?

Check warning on line 62 in baton/coupa.mdx

View check run for this annotation

Mintlify / Mintlify Validation (conductorone) - vale-spellcheck

baton/coupa.mdx#L62

Did you really mean 'Coupa'?
</Note>

#### Mapping examples

Mappings in C1 are expressions. Wrap text constants in quotes; booleans and numbers take no quotes. The C1 user has no separate first and last name, so derive them from the display name.

Check warning on line 67 in baton/coupa.mdx

View check run for this annotation

Mintlify / Mintlify Validation (conductorone) - vale-spellcheck

baton/coupa.mdx#L67

Did you really mean 'booleans'?

| Field | Example mapping |
|-------|-----------------|
| First name | `subject.display_name.split(" ")[0]` |
| Last name | `subject.display_name.substring(subject.display_name.indexOf(" ") + 1)` |
| Email | `subject.email` |
| Login | `subject.username` |
| Employee number | A value unique per user, such as `subject.id`. Coupa requires employee numbers to be unique, so a constant fails from the second account on. |

Check warning on line 75 in baton/coupa.mdx

View check run for this annotation

Mintlify / Mintlify Validation (conductorone) - vale-spellcheck

baton/coupa.mdx#L75

Did you really mean 'Coupa'?
| Manager login | `"jane.manager"` |
| Purchasing user | `true` |
| Default currency | `"USD"` |
| Custom fields | `{"cost-center": "CC-100", "remote": true, "desk-number": 42}` |

#### How Coupa applies some values

Check warning on line 81 in baton/coupa.mdx

View check run for this annotation

Mintlify / Mintlify Validation (conductorone) - vale-spellcheck

baton/coupa.mdx#L81

Did you really mean 'Coupa'?

- **License flags.** If an account would be created with no license at all — for example, with **Purchasing user**, **Invoicing user**, and **Sourcing user** all mapped to `false` — Coupa assigns the Purchasing license anyway. To create a user without Purchasing, map at least one other license flag to `true`.

Check warning on line 83 in baton/coupa.mdx

View check run for this annotation

Mintlify / Mintlify Validation (conductorone) - vale-spellcheck

baton/coupa.mdx#L83

Did you really mean 'Coupa'?
- **Custom field names.** Coupa accepts either the hyphenated or the underscore form of a custom field name (for example `cost-center` or `cost_center`) and reports it in the hyphenated form. A name that doesn't match an existing custom user field is ignored without an error, so check the spelling against an existing user's `custom-fields` in the Coupa Users API.

Check warning on line 84 in baton/coupa.mdx

View check run for this annotation

Mintlify / Mintlify Validation (conductorone) - vale-spellcheck

baton/coupa.mdx#L84

Did you really mean 'Coupa'?

Check warning on line 84 in baton/coupa.mdx

View check run for this annotation

Mintlify / Mintlify Validation (conductorone) - vale-spellcheck

baton/coupa.mdx#L84

Did you really mean 'Coupa'?
- **Integer custom fields** are returned by Coupa as decimal strings, for example `"42.0"`.

Check warning on line 85 in baton/coupa.mdx

View check run for this annotation

Mintlify / Mintlify Validation (conductorone) - vale-spellcheck

baton/coupa.mdx#L85

Did you really mean 'Coupa'?
- **Rejected values.** If Coupa rejects a value — an authentication method your instance doesn't enable, or an account type, currency, or manager that doesn't exist — the account isn't created and the connector returns Coupa's error message, for example `Authentication Method must be one of Coupa Credentials`.

Check warning on line 86 in baton/coupa.mdx

View check run for this annotation

Mintlify / Mintlify Validation (conductorone) - vale-spellcheck

baton/coupa.mdx#L86

Did you really mean 'Coupa'?

Check warning on line 86 in baton/coupa.mdx

View check run for this annotation

Mintlify / Mintlify Validation (conductorone) - vale-spellcheck

baton/coupa.mdx#L86

Did you really mean 'Coupa's'?

### Connector actions

Connector actions are custom capabilities that extend C1 automations with app-specific operations. You can use connector actions in the [Perform connector action](/product/admin/automations-steps-reference#perform-connector-action) automation step.

Check warning on line 90 in baton/coupa.mdx

View check run for this annotation

Mintlify / Mintlify Validation (conductorone) - vale-spellcheck

baton/coupa.mdx#L90

Did you really mean 'automations'?

| Action name | Additional fields | Description |
|-------------|-------------------|-------------|
| enable_user | `user_id` (string, required) — the Coupa user's numeric ID, the `id` field on `/api/users` | Enables a disabled user account in Coupa, allowing them to access the system |

Check warning on line 94 in baton/coupa.mdx

View check run for this annotation

Mintlify / Mintlify Validation (conductorone) - vale-spellcheck

baton/coupa.mdx#L94

Did you really mean 'enable_user'?

Check warning on line 94 in baton/coupa.mdx

View check run for this annotation

Mintlify / Mintlify Validation (conductorone) - vale-spellcheck

baton/coupa.mdx#L94

Did you really mean 'Coupa'?

Check warning on line 94 in baton/coupa.mdx

View check run for this annotation

Mintlify / Mintlify Validation (conductorone) - vale-spellcheck

baton/coupa.mdx#L94

Did you really mean 'Coupa'?
| disable_user | `user_id` (string, required) — the Coupa user's numeric ID, the `id` field on `/api/users` | Disables an active user account in Coupa, preventing them from accessing the system |

Check warning on line 95 in baton/coupa.mdx

View check run for this annotation

Mintlify / Mintlify Validation (conductorone) - vale-spellcheck

baton/coupa.mdx#L95

Did you really mean 'disable_user'?

Check warning on line 95 in baton/coupa.mdx

View check run for this annotation

Mintlify / Mintlify Validation (conductorone) - vale-spellcheck

baton/coupa.mdx#L95

Did you really mean 'Coupa'?

Check warning on line 95 in baton/coupa.mdx

View check run for this annotation

Mintlify / Mintlify Validation (conductorone) - vale-spellcheck

baton/coupa.mdx#L95

Did you really mean 'Coupa'?

## Gather Coupa credentials

Check warning on line 97 in baton/coupa.mdx

View check run for this annotation

Mintlify / Mintlify Validation (conductorone) - vale-spellcheck

baton/coupa.mdx#L97

Did you really mean 'Coupa'?

Configuring the connector requires you to pass in credentials generated in Coupa. Gather these credentials before you move on.

Check warning on line 99 in baton/coupa.mdx

View check run for this annotation

Mintlify / Mintlify Validation (conductorone) - vale-spellcheck

baton/coupa.mdx#L99

Did you really mean 'Coupa'?

<Warning>
A user with **Admin** access in Coupa must perform this task.

Check warning on line 102 in baton/coupa.mdx

View check run for this annotation

Mintlify / Mintlify Validation (conductorone) - vale-spellcheck

baton/coupa.mdx#L102

Did you really mean 'Coupa'?
</Warning>

### Look up your Coupa domain

Check warning on line 105 in baton/coupa.mdx

View check run for this annotation

Mintlify / Mintlify Validation (conductorone) - vale-spellcheck

baton/coupa.mdx#L105

Did you really mean 'Coupa'?

<Steps>
<Step>
Log into your Coupa control panel and copy the URL from your browser.

Check warning on line 109 in baton/coupa.mdx

View check run for this annotation

Mintlify / Mintlify Validation (conductorone) - vale-spellcheck

baton/coupa.mdx#L109

Did you really mean 'Coupa'?
</Step>
</Steps>

Expand All @@ -83,7 +114,7 @@

<Steps>
<Step>
In the Coupa control panel, click **Setup**.

Check warning on line 117 in baton/coupa.mdx

View check run for this annotation

Mintlify / Mintlify Validation (conductorone) - vale-spellcheck

baton/coupa.mdx#L117

Did you really mean 'Coupa'?
</Step>
<Step>
Search for "OAuth" and click **OAuth2/OpenID Connect Clients**.
Expand All @@ -105,7 +136,7 @@
- core.user_group.read
- core.user.read
- login
- openid

Check warning on line 139 in baton/coupa.mdx

View check run for this annotation

Mintlify / Mintlify Validation (conductorone) - vale-spellcheck

baton/coupa.mdx#L139

Did you really mean 'openid'?
- profile

**If you also want to sync Account Groups, add:**
Expand All @@ -119,7 +150,7 @@
- core.user.read
- core.user.write
- login
- openid

Check warning on line 153 in baton/coupa.mdx

View check run for this annotation

Mintlify / Mintlify Validation (conductorone) - vale-spellcheck

baton/coupa.mdx#L153

Did you really mean 'openid'?
- profile

**If you also want to sync and provision Account Groups, add:**
Expand All @@ -146,13 +177,13 @@

**Done.** Next, move on to the connector configuration instructions.

## Configure the Coupa connector

Check warning on line 180 in baton/coupa.mdx

View check run for this annotation

Mintlify / Mintlify Validation (conductorone) - vale-spellcheck

baton/coupa.mdx#L180

Did you really mean 'Coupa'?

<Warning>
To complete this task, you'll need:

- The **Connector Administrator** or **Super Administrator** role in C1
- Access to the set of Coupa credentials generated by following the instructions above

Check warning on line 186 in baton/coupa.mdx

View check run for this annotation

Mintlify / Mintlify Validation (conductorone) - vale-spellcheck

baton/coupa.mdx#L186

Did you really mean 'Coupa'?
</Warning>

<Tabs>
Expand Down Expand Up @@ -185,7 +216,7 @@
Find the **Settings** area of the page and click **Edit**.
</Step>
<Step>
Enter your Coupa domain in the **Domain** field.

Check warning on line 219 in baton/coupa.mdx

View check run for this annotation

Mintlify / Mintlify Validation (conductorone) - vale-spellcheck

baton/coupa.mdx#L219

Did you really mean 'Coupa'?
</Step>
<Step>
Paste the client ID into the **Client ID** field.
Expand All @@ -201,12 +232,12 @@
</Step>
</Steps>

**Done.** Your Coupa connector is now pulling access data into C1.

Check warning on line 235 in baton/coupa.mdx

View check run for this annotation

Mintlify / Mintlify Validation (conductorone) - vale-spellcheck

baton/coupa.mdx#L235

Did you really mean 'Coupa'?

</Tab>
<Tab title="Self-hosted">

**Follow these instructions to use the Coupa connector, hosted and run in your own environment.**

Check warning on line 240 in baton/coupa.mdx

View check run for this annotation

Mintlify / Mintlify Validation (conductorone) - vale-spellcheck

baton/coupa.mdx#L240

Did you really mean 'Coupa'?

When running in service mode on Kubernetes, a self-hosted connector maintains an ongoing connection with C1, automatically syncing and uploading data at regular intervals. This data is immediately available in the C1 UI for access reviews and access requests.

Expand All @@ -216,7 +247,7 @@

* [GitHub repository](https://github.com/conductorone/baton-coupa): Access the source code, report issues, or contribute to the project.

### Step 1: Set up a new Coupa connector

Check warning on line 250 in baton/coupa.mdx

View check run for this annotation

Mintlify / Mintlify Validation (conductorone) - vale-spellcheck

baton/coupa.mdx#L250

Did you really mean 'Coupa'?

<Steps>
<Step>
Expand Down Expand Up @@ -251,7 +282,7 @@

### Step 2: Create Kubernetes configuration files

Create two Kubernetes manifest files for your Coupa connector deployment:

Check warning on line 285 in baton/coupa.mdx

View check run for this annotation

Mintlify / Mintlify Validation (conductorone) - vale-spellcheck

baton/coupa.mdx#L285

Did you really mean 'Coupa'?

#### Secrets configuration

Expand Down Expand Up @@ -315,14 +346,14 @@

<Steps>
<Step>
Create a namespace in which to run C1 connectors (if desired), then apply the secret config and deployment config files.

Check warning on line 349 in baton/coupa.mdx

View check run for this annotation

Mintlify / Mintlify Validation (conductorone) - vale-spellcheck

baton/coupa.mdx#L349

Did you really mean 'namespace'?
</Step>
<Step>
Check that the connector data uploaded correctly. In C1, click **Apps**. On the **Managed apps** tab, locate and click the name of the application you added the Coupa connector to. Coupa data should be found on the **Entitlements** and **Accounts** tabs.

Check warning on line 352 in baton/coupa.mdx

View check run for this annotation

Mintlify / Mintlify Validation (conductorone) - vale-spellcheck

baton/coupa.mdx#L352

Did you really mean 'Coupa'?

Check warning on line 352 in baton/coupa.mdx

View check run for this annotation

Mintlify / Mintlify Validation (conductorone) - vale-spellcheck

baton/coupa.mdx#L352

Did you really mean 'Coupa'?
</Step>
</Steps>

**Done.** Your Coupa connector is now pulling access data into C1.

Check warning on line 356 in baton/coupa.mdx

View check run for this annotation

Mintlify / Mintlify Validation (conductorone) - vale-spellcheck

baton/coupa.mdx#L356

Did you really mean 'Coupa'?

</Tab>
</Tabs>
Expand Down