Hello, I’m Nora, your AI guide from Technology Last Stop. This guide covers Connect OneLogin application and role access. Read selected application assignments and returned role membership. Current availability: Read adapter implemented; company authorization and successful live sync required. Before you start. An authorized company administrator with Vendor licenses management permission and an approved provider data-use scope. The company’s protected integration vault. Use a dedicated provider application; never put credentials in a KB, video, chat or source file. Step 1. Create a dedicated OneLogin API credential pair with Read All scope. Record the organization URL, client ID and client secret. Step 2. Enter those values in the OneLogin form. Use the organization’s onelogin.com URL; the adapter exchanges the credential pair for a short-lived token during sync. Step 3. Optionally select up to twenty numeric app IDs. The reader fetches users filtered to each selected app and the role memberships returned by the roles API. Step 4. Save the encrypted connection in Companies > company > Vendor licenses. Choose Sync now in production after provider authorization. Dev and QA isolate external operations. Review the recorded sync result and compare the snapshot with the provider console. Step 5. Review role names as application-access groups, not administrator privileges. OneLogin status and state are separate indicators; this reader does not infer purchased seats from either one. Now verify the result. Compare selected-app users with the OneLogin app and role pages. Users from an unselected app must not be assigned to the selected product. A successful company sync is required before describing the connection as healthy; an available adapter alone is not a connected account. Check a second company and a view-only account: neither can change this company’s credentials or lifecycle state. Pause, Resume and Trash affect only the local connection. Resume waits for a separate Sync action; no vendor user or license is modified. If you get stuck. 401 or 403: check credential expiry, the selected provider organization and the exact required permissions. Do not grant broad write access merely to bypass a failed read. A failed or incomplete provider response preserves the last complete snapshot. Review the error, correct the connection and explicitly retry. On a 429 rate-limit response, wait for the provider’s retry window before another manual sync. Large inventories can require a separately designed scheduled export; the current bounded sync does not commit partial results. Use the current written guide for exact URLs, permission names, and provider documentation. Pause before entering credentials, and keep them in protected configuration. I’m Nora, your TLS guide.