About OneLogin
OneLogin is an identity and access management (IdP) platform. Serval connects to your OneLogin account using an API credentials pair scoped to your OneLogin subdomain and works against the OneLogin API v2. Once connected, Serval keeps your user directory, application catalog, and roles (including who belongs to each role) in sync, and can grant or revoke access by adding or removing users from OneLogin roles. Authentication: OAuth 2.0 client credentials - you paste a Subdomain, Client ID, and Client Secret from a OneLogin API credentials pair. There is no browser sign-in step. Data sync: Background syncs pull users every 4 hours, and applications and roles every 48 hours (role and membership changes are also picked up by a faster 4-hour delta sync between full role syncs). Access changes run on demand from workflows.What the OneLogin integration enables
Get your credentials
Serval authenticates with an API credentials pair (Client ID and Client Secret) created in your OneLogin admin console. See OneLogin’s guide to working with API credentials for full details.Log in to your OneLogin admin console
Navigate to Developers > API Credentials
Click New Credential
Click Save
Copy the Client ID and Client Secret
Connect in Serval
Open the OneLogin integration in Serval
Subdomain (required)
acme.onelogin.com. Do not include https://.” Leaving it blank shows “This field is required”.Client ID (required)
Client Secret (required)
Submit
Verifying the connection
The integration ships four health checks you can run from the integration’s page in Serval. Test OneLogin Connection - verifies the integration is configured correctly and can authenticate against the OneLogin API with a minimal read-only call.- Success: “Successfully authenticated with OneLogin”
- Failure: “Unable to connect to OneLogin.” followed by a hint - “The OneLogin client credentials are invalid or expired. Verify the client ID and client secret in the integration settings.” (bad credentials), “The OneLogin API credential lacks the required scope. Use ‘Read all’ for sync-only, or ‘Manage all’ if access management is needed.” (insufficient scope), or “OneLogin returned a server error. This is likely a temporary issue with OneLogin’s API - please try again later.” (OneLogin-side errors). Other errors show the base message alone.
Gotchas and troubleshooting
OneLogin Roles are groups; OneLogin Groups are not synced
OneLogin Roles are groups; OneLogin Groups are not synced
Permissions come from the credential's scope, not from Serval
Permissions come from the credential's scope, not from Serval
The Subdomain is your full onelogin.com domain
The Subdomain is your full onelogin.com domain
acme.onelogin.com) without https://. Serval only attaches credentials to requests going to a domain of the form yoursubdomain.onelogin.com, so a custom branded domain outside onelogin.com will not work. Authentication is also performed against this value, so a wrong Subdomain breaks the connection entirely - “not found” hints on health checks often indicate an incorrect Subdomain.Adding or removing access requires a unique email match
Adding or removing access requires a unique email match
Updating credentials: blank fields keep their saved values
Updating credentials: blank fields keep their saved values
Rate limits and temporary errors are retried automatically
Rate limits and temporary errors are retried automatically
Paginating OneLogin results in custom workflows
Paginating OneLogin results in custom workflows
Need help? Contact support@serval.com for assistance with your OneLogin integration.

