Skip to content

Scripted API ​

Scripted API Connectors are ICF connectors based on a proprietary connector named Scripted API. This generic connector provides utility functions that can be used in Groovy scripts to create specific ICF connectors. These connectors can then be easily customized to meet the business needs of each organization. Customization is facilitated through a graphical interface integrated within RAC/M Identity.

Prerequisites ​

  • RAC/M Identity 3.17 or later
  • A data repository accessible via an API (e.g., Workday)

Script creation ​

This step involves creating a Groovy script to be used by the Scripted API connector.

  1. In the menu bar, navigate to Configuration > Script Files.
  2. Select the script corresponding to the desired connector, starting with reference-scripts/scripted-api-.
    For example, to create a connector for Workday, select:
    reference-scripts/scripted-api-19.0.0.0/workday.groovy.
    Select the latest version.
    If the connector doesn't already exist, you can create one based on reference scripts.
  3. Click the Duplicate button at the bottom-right of the screen to create a copy of the script. This ensures the reference script remains intact.
  4. In the dialog that appears, give the script an appropriate name and click Duplicate.
  5. (If necessary) Edit the script to meet your specific needs. Be sure to save your changes regularly to avoid losing progress.
  6. Click Save to store the script.

Connector creation ​

This step involves creating a Scripted API connector that will use the script created earlier. Follow the steps for creating a connector as described in Configuring an ICF Connector. Select Scripted API as the connector type. Use the same version as the one used for the script.

Configuration as a Target System ​

The following parameters are required:

ConfigurationDescription
Script PathPath to the previously created Groovy script.
API URLURL of the API to connect to.
Preferred Authentication MethodAuthentication method to use (password, bearer, userToken, or oauth2).
Authentication URLURL for authentication.
Custom Config 1 to 5Custom configurations that can be used by the script.
UsernameUsername to use for authentication.
PasswordPassword to use for authentication.
User TokenUser token to use for authentication.
Bearer TokenBearer token to use for authentication.
Custom Secret 1 to 5Custom secrets that can be used by the script, securely encrypted and managed.

Advanced Configuration ​

The following parameters are required:

ConfigurationDescription
TimeoutTimeout in milliseconds.
Time between retriesTime to wait before retrying an HTTP request. Leave blank to use the default 500 ms.
Thread Pool SizeNumber of threads to use for concurrent operations. Leave blank to use all available threads.

Authentication (OAuth2) ​

The connector can use the OAuth2 protocol to authenticate with the API. This requires additional configuration properties to enable the authentication flow:

ConfigurationRequired Value
Custom Config 1The grant_type.
Custom Config 2The client_id.
Custom Secret 1The client_secret.
Preferred Authentication Methodoauth2
Authentication URLURL for authentication.

Authentification (saml2) ​

Le connecteur peut utilisé le protocole OAuth2 saml2 pour s'authentifier auprès de l'API. Cela implique que la configuration nécessite quelques propriétés supplémentaires afin de permettre au flux d'authentification de se dérouler correctement :

ConfigurationRequired Value
Script PathPath to the previously created Groovy script.
API URLscim https://<api?>.sapsf.com/rest/iam/scim/v2
Preferred Authentication Methodsaml2
Authentication URLL'URL servant à l'authentification.
Custom Config 1The grant_type urn:ietf:params:oauth:grant-type:saml2-bearer
Custom Config 2The client_id.
Custom Config 3The company_id
Custom Config 4The token_url https://<api?>.sapsf.com/oauth/token
UsernameThe user_id
Custom Secret 1The private_key

Authentication (Bearer) ​

ConfigurationRequired Value
Bearer TokenThe "Access Token".
API URLURL of the API to connect to.
Preferred Authentication MethodBearer.

Authentication (Password) ​

ConfigurationDescription
API URLURL of the API to connect to.
Authentication methodpassword.
UsernameUsername to connect to the API.
PasswordPassword to connect to the API.

Authentication (User Token) ​

ConfigurationDescription
Authentication methoduserToken.
User TokenUser token used to connect to the API.

Troubleshooting ​

In case of errors, ensure that the configuration is correct, the script is valid, and the API is accessible. You can also check logs for more details on the error (see Viewing Logs).

Technical Details ​

To better understand how the Scripted API connector works, refer to the reference scripts. These include comments explaining their functionality. It is recommended to develop a new connector based on these reference scripts.

Data Schema ​

The data schema used by Scripted API connectors is composed of ScriptedAPIObjectClass.
Each ScriptedAPIObjectClass contains ScriptedAPIAttribute used to represent object attributes. For instance, a Workday user is represented by a WorkerObjectClass containing attributes like EMPLOYEE_ID, FIRST_NAME, LAST_NAME, etc.

Functions ​

The Scripted API connector communicates with the Groovy script by calling certain functions by name.
The following functions must be implemented:

FunctionDescription
testTests the connection.
schemaReturns the data schema.
searchSearches for objects.
createCreates an object.
updateUpdates an object.
deleteDeletes an object.
addAttributeValuesAdds values to an object's attribute.
removeAttributeValuesRemoves values from an object's attribute.

Refer to the reference scripts for parameters and implementation examples for these functions.

Libraries ​

The following libraries are included in the Scripted API connector and can be used in scripts:

LibraryPurpose
connid-connector-frameworkICF Connector Framework
okhttpHTTP Requests
org.jsonJSON Manipulation

Threads ​

The Scrited API connector supports concurrent operations. To do this, it uses a thread pool. This allows multiple API calls to be made in parallel to increase performance. This is especially useful when importing a large number of users. The number of threads to use can be configured through the "Thread Pool Size" parameter. Leave this parameter empty to use all available threads.