Connect Sigil
1
Sign in to Sigil Platform
Open Sigil Platform and sign in as an administrator.
2
Create a credential
Open Manage Credentials and create a credential with the permissions your workflows need. Copy the secret when it is shown; Sigil displays it only once.
3
Connect Sigil in Serval
Add the Sigil integration in Serval and enter the API Credential Secret.
4
Run the health checks
Run Validate API connection, followed by the health checks for the resources your workflows use.
https://sigil.app/api. Workflow code does not need the secret. The integration is marked Beta.
Permissions
The connection check calls/api/users/me, which requires authentication without additional permissions. Other health checks verify access separately:
Grant write permissions only when your workflows need them. A connection can pass authentication while a resource health check fails because its credential lacks permission.
Workflow operations
The Sigil API request action supports listing, creating, updating, and deleting users and groups; listing, adding, removing, and checking group membership; and reading apps and effective app access. To grant application access, read the app’sassignmentGroupId and add the user to that group. To revoke a direct assignment, remove the matching membership. Nested groups can also grant access: inspect /api/apps/access and its groupPath before concluding that removing a direct membership removed all access.
List endpoints use limit (maximum 1000), offset, and total. Increase offset by the number of returned records to read another page. Exact-match filters use is:; for example, email: "is:person@example.com" or groupId: "is:<group UUID>".
For PATCH requests, omit fields you want to preserve. Sending null clears a nullable field. Creating users, groups, and memberships requires a Sigil tenantId; membership creation also requires groupId and the appropriate memberUserId or memberGroupId.
This connector covers identity and application access. Device, session, audit-log, credential, token, tenant, and app-configuration administration are outside its current typed API.
Rotate the credential
Create a replacement credential in Sigil, update the connection secret in Serval, and run the health checks before revoking the old credential. Leaving the secret unchanged or blank when editing preserves the stored credential. A401 indicates an invalid or expired credential. A 403 indicates a missing permission. The membership-check endpoint returns 404 when the user or group is not a member.
