.png)
Delinea Integration Guide
Connect Delinea Secret Server and Delinea Platform services with enterprise applications through REST APIs, legacy SOAP services, controlled callbacks, and scheduled workflows.
Delinea integration options at a glance
Delinea integrations are product- and deployment-specific, with REST APIs as the primary approach for Secret Server and Delinea Platform services. APIs can read and manage Secrets, Folders, Secret Templates, Users, and Groups where the selected product and permissions allow. Secret Server also exposes legacy SOAP services for compatible deployments, while webhook-style notifications or callbacks may be available for selected operations and must be confirmed. Martini can authenticate with OAuth 2.0 and bearer tokens, orchestrate paginated API calls, map protected metadata, expose controlled APIs, and use scheduled polling when no suitable event mechanism exists.
| Integration point | Supported by Delinea? | Common use cases | How Martini supports it |
|---|---|---|---|
| REST APIs | Yes | Secret Server and Delinea Platform REST APIs can read or manage Secrets, Folders, Secret Templates, Users, Groups, and other product-specific resources. Exact paths and operations depend on the product and version. | Martini can consume Delinea REST endpoints, paginate responses, transform JSON, apply business rules, and expose controlled Martini APIs over selected operations. |
| SOAP APIs | Legacy | Secret Server has historically provided SOAP web services for existing deployments or operations not available through REST. | Martini can consume SOAP services and handle XML mappings where a legacy Secret Server operation is required. |
| Webhooks / outbound callbacks | Limited | Delinea products may provide event, notification, or callback capabilities for selected operations, but universal webhook coverage is not confirmed. | Martini can receive documented callbacks when available; otherwise it can use scheduled API polling with timestamps, identifiers, or audit checkpoints. |
| Bulk / async / batch APIs | Not confirmed | Bulk and asynchronous support is operation-specific and should not be assumed across Delinea resources. | Martini can implement controlled pagination, checkpointing, throttling, and workflow batching around available endpoints. |
| File / attachment APIs | Limited | Secret Server may expose attachment operations for selected Secret resources, subject to API version, Secret Template, and permissions. | Martini can transfer or transform supported attachments while enforcing size, access, logging, and error-handling policies. |
| Authentication | Yes | Applicable Secret Server and Delinea Platform APIs support OAuth 2.0 and bearer-token authentication; exact grants, scopes, and endpoints vary. | Martini can store client credentials in protected environment configuration, obtain tokens, add authorization headers, and handle expiry or permission failures. |
| Database / analytics access | No | Direct database access is not the standard supported integration path for Delinea Cloud or Secret Server SaaS deployments. | Martini should consume supported Delinea APIs rather than reading or writing product databases directly. |
How Delinea exposes data and business events
Delinea REST APIs
REST is the primary standards-based integration method for current Secret Server and Delinea Platform scenarios. Depending on the product and permissions, REST resources can support Secrets, Folders, Secret Templates, Users, Groups, audit data, and other product-specific operations.
Martini implementation pattern
Martini implementation pattern: Martini authenticates to the appropriate Delinea endpoint, invokes the required REST resources, validates responses, maps JSON into a canonical model, and coordinates downstream writes or controlled API responses.
Implementation sequence
Secret Server SOAP APIs
Secret Server has historically exposed SOAP web services for legacy deployments and compatibility scenarios. SOAP should generally be evaluated only when the required operation is unavailable through REST or an existing deployment depends on it.
Martini implementation pattern
Martini implementation pattern: Martini consumes the SOAP service, handles XML request and response structures, applies the same authorization, validation, mapping, and retry controls used for REST integrations, and isolates legacy mappings for maintainability.
Implementation sequence
Delinea callbacks and scheduled synchronization
Delinea event, notification, or callback capabilities may exist for selected products and operations, but universal webhook coverage is not confirmed. Scheduled API polling is an alternative when no suitable outbound event is available.
Martini implementation pattern
Martini implementation pattern: Martini receives a documented callback when supported, or starts a scheduled workflow that retrieves changed resources using timestamps, identifiers, audit data, pagination, and persisted checkpoints.
Implementation sequence
Common Delinea integration patterns
Pattern 1: Automate ServiceNow privileged-access requests
When to use this pattern
Use this pattern when an approved ServiceNow request must retrieve or provision a Delinea Secret and return status or audit information. It supports approval validation, controlled exposure, and duplicate prevention.
Integration direction
Example Mapping
| Delinea Field | Canonical Field | Target Field |
|---|---|---|
| requestId | externalRequestId | Secret or workflow correlation key |
| requestedFolder | folderIdentifier | Folder ID |
| requestedSecret | secretIdentifier | Secret ID or name |
| approvalStatus | approvalState | Workflow business rule |
Martini implementation pattern
A Martini API receives the approved request, validates requester, approver, Folder, and Secret permissions, then orchestrates Delinea calls. It returns only the permitted response, records correlation data, and uses the request ID as an idempotency key so retries do not create duplicate Secrets or repeat unsafe retrievals.
Martini capabilities used
- APIs
- workflows
- API consumption
- data mapping
- business rules
- secrets management
- error handling
Pattern 2: Reconcile Delinea access with Microsoft Entra ID
When to use this pattern
Use this pattern to align selected Delinea Users or Groups with approved Microsoft Entra ID identities and memberships. The workflow can report differences or apply governed updates where the product API permits.
Integration direction
Example Mapping
| Delinea Field | Canonical Field | Target Field |
|---|---|---|
| id | externalIdentityId | User ID |
| displayName | identityName | User or Group name |
| accountEnabled | activeState | User status |
| members | groupMemberships | Group membership |
Martini implementation pattern
A scheduled Martini workflow retrieves directory changes and Delinea Users or Groups, normalizes identifiers, applies disabled-user and privilege-escalation rules, and performs only supported updates. It checkpoints pages, records differences, and routes permission or conflict errors without broadening access automatically.
Martini capabilities used
- scheduled workflows
- API consumption
- data mapping
- business rules
- checkpointing
- error handling
Pattern 3: Publish a non-secret Delinea inventory
When to use this pattern
Use this pattern for compliance, operational, or SIEM reporting based on Secret, Folder, Secret Template, Site, and audit metadata. Secret values should be excluded unless explicitly required and authorized.
Integration direction
Example Mapping
| Delinea Field | Canonical Field | Target Field |
|---|---|---|
| secretId | objectId | object_id |
| folderId | containerId | folder_id |
| secretTemplate | templateName | template |
| lastModified | modifiedAt | event_time |
Martini implementation pattern
Martini pages through permitted Delinea resources, normalizes dates and identifiers, removes protected values, enriches records with source and execution metadata, and publishes them to Splunk or another approved destination. Checkpoints, bounded concurrency, and retry classification prevent full rescans and uncontrolled duplicate events.
Martini capabilities used
- scheduled workflows
- API consumption
- pagination
- data mapping
- JSON handling
- retry handling
- monitoring
Pattern 4: Expose a controlled DevOps secret retrieval API
When to use this pattern
Use this pattern when Ansible, Terraform, or another automation process needs a narrowly scoped credential without embedding it in code or playbooks. The exact Delinea product and machine-to-machine flow must be confirmed.
Integration direction
Example Mapping
| Delinea Field | Canonical Field | Target Field |
|---|---|---|
| workspace | executionContext | Authorization rule |
| environment | environmentName | Folder or Secret selection |
| secretReference | secretIdentifier | Secret ID |
| requestId | correlationId | Audit metadata |
Martini implementation pattern
Martini exposes an authenticated API façade, validates the calling context and requested environment, retrieves only the permitted Secret through Delinea, and returns a controlled response. It masks logs, applies short-lived token handling, limits retries for retrieval failures, and records audit metadata without storing the secret value unnecessarily.
Martini capabilities used
- API exposure
- API consumption
- authentication
- authorization
- data mapping
- business rules
- secure logging
- error handling
Applications commonly integrated with Delinea
Delinea commonly participates in privileged-access, identity, security monitoring, service-management, and DevOps workflows. The exact integration depends on the Delinea product, tenant, API version, and permissions available to the integration identity.
| Application | Scenario | Direction | Martini Pattern |
|---|---|---|---|
| ServiceNow | Automate privileged-access requests, approvals, credential checkout, ticket updates, and audit references. | ServiceNow → Martini → Delinea | Expose a Martini API for approved requests, validate requester and approval data, retrieve or provision the required Delinea Secret, and return a controlled status while retaining correlation and audit data. |
| Microsoft Entra ID | Synchronize approved users and groups, reconcile disabled identities, and align privileged access with directory membership. | Microsoft Entra ID → Martini → Delinea | Run a scheduled workflow that retrieves directory changes, maps identities and group memberships, applies permission and lifecycle rules, and updates supported Delinea objects idempotently. |
| Splunk | Send Delinea audit and privileged-access metadata to a SIEM for monitoring, investigation, and compliance reporting. | Delinea → Martini → Splunk | Page through supported Delinea audit or activity data, remove secret values, normalize events, and publish them to a Splunk ingestion endpoint with retry and checkpoint handling. |
| Microsoft Sentinel | Forward privileged-access activity and security metadata into Microsoft security monitoring and response workflows. | Delinea → Martini → Microsoft Sentinel | Use a scheduled or event-driven workflow to retrieve permitted Delinea activity, transform it to the target ingestion model, and submit it with bounded retries and correlation identifiers. |
| Ansible | Retrieve approved credentials during infrastructure automation without hard-coding them in playbooks. | Ansible → Martini → Delinea | Expose a narrowly scoped Martini API that validates the automation request, selects the permitted Secret, retrieves only the required value, masks operational logs, and returns a controlled response. |
| Terraform | Provide environment-specific credentials to infrastructure provisioning workflows while centralizing authorization and audit controls. | Terraform → Martini → Delinea | Use a Martini API façade to validate workspace and environment context, retrieve the authorized Delinea Secret, apply response and logging controls, and handle transient failures safely. |
| Jira | Associate privileged-access changes, remediation work, and approvals with issue records. | Jira → Martini → Delinea | Orchestrate issue and Delinea API calls, map request identifiers and statuses, enforce approval rules, and update both systems using idempotent workflow steps. |
| Microsoft Power BI | Create operational or compliance reports from non-secret Delinea inventory, audit, and access metadata. | Delinea → Martini → Microsoft Power BI | Extract permitted metadata on a schedule, normalize identifiers and timestamps, exclude protected values, and publish the result to an approved reporting dataset or ingestion endpoint. |
How to build a Delinea integration in Martini
Objective
Identify the Delinea product, tenant or base URL, deployment model, API version, and required permissions before configuring the integration.
Instructions in Martini
- Select the supported Delinea REST endpoint or required legacy SOAP service
- Create a least-privilege integration identity
- Configure OAuth 2.0 client credentials, bearer-token settings, or confirmed legacy authentication
- Store client secrets and tokens in Martini protected environment configuration
Objective
Select an event-driven, API-led, or scheduled execution model based on the confirmed Delinea capabilities for the target operation.
Instructions in Martini
- Use a Martini API for request-driven retrieval or provisioning
- Receive only documented Delinea callbacks for supported events
- Use a scheduler when event coverage is unavailable or incomplete
- Define the checkpoint and idempotency strategy before processing data
Objective
Call the appropriate Delinea resources and retrieve only the objects and fields required by the business process.
Instructions in Martini
- Invoke the product-specific REST or SOAP operation
- Follow documented pagination and filtering parameters
- Retrieve current resources after callback notifications when necessary
- Avoid requesting or logging Secret values unless explicitly authorized
Objective
Coordinate Delinea calls with approvals, identity systems, reporting destinations, or DevOps clients in a maintainable Martini workflow.
Instructions in Martini
- Validate the incoming request and caller context
- Apply permission, approval, and environment rules
- Branch on authentication, authorization, validation, conflict, throttling, and service failures
- Persist correlation identifiers and synchronization checkpoints
Objective
Convert Delinea-specific JSON or XML structures into a canonical model and target application format.
Instructions in Martini
- Map Secret, Folder, User, Group, Site, and Secret Template fields explicitly
- Normalize identifiers, timestamps, status values, and nulls
- Use metadata-only mappings for reporting and audit exports
- Keep product- and version-specific mappings isolated and reusable
Objective
Publish approved results to downstream systems or return a controlled response to the calling application.
Instructions in Martini
- Write only to targets authorized for the use case
- Use stable external IDs or request IDs for idempotent creates and updates
- Do not expose protected values in broad API responses
- Record target acknowledgements and Delinea object identifiers
Common Delinea data objects used in integrations
| Object | Typical Use | Common target systems | Martini handling |
|---|---|---|---|
| Secret | Retrieve, create, update, inventory, or securely reference privileged credentials and protected values. | ServiceNow, Ansible, Terraform, Splunk, Microsoft Sentinel | Martini restricts access by workflow identity and Delinea permissions, avoids logging values, maps permitted fields, and uses idempotency for writes. |
| Folder | Organize Secrets and apply access-control boundaries. | ServiceNow, Microsoft Entra ID, reporting datasets | Martini uses Folder identifiers and permissions when selecting Secrets, synchronizing access, or producing metadata reports. |
| User | Represent Delinea or Secret Server identities and support access or lifecycle reconciliation. | Microsoft Entra ID, ServiceNow, Jira | Martini maps identifiers and status fields, handles pagination and disabled users, and applies least-privilege update rules. |
| Group | Represent membership-based access control and approved privileged-access populations. | Microsoft Entra ID, ServiceNow, reporting systems | Martini compares memberships, applies reconciliation rules, records differences, and avoids unauthorized privilege expansion. |
| Site | Identify a Secret Server location or site in distributed deployments. | ServiceNow, inventory stores, reporting platforms | Martini preserves Site identifiers in canonical data and routes or filters operations according to deployment-specific rules. |
| Secret Template | Define the fields and structure used by Secrets. | ServiceNow, inventory stores, governance reports | Martini validates template-dependent fields, isolates version-specific mappings, and rejects unsupported or incomplete payloads. |
Authentication and security considerations
OAuth and bearer-token security
Applicable Delinea Platform and Secret Server APIs use OAuth 2.0 and bearer tokens, with exact grants, scopes, audiences, and endpoints varying by product and deployment. Martini stores client secrets and protected configuration in environment secrets rather than workflow definitions.
Least privilege and secret protection
- Use separate integration identities for inventory, retrieval, provisioning, and audit use cases where practical.
- Grant only the required Secret, Folder, User, Group, Site, and audit permissions.
- Do not log Secret values or return them in broad API responses.
- Handle token expiry, revoked clients, insufficient scopes, tenant mismatches, and clock skew explicitly.
Operational considerations for Delinea integrations
Product and schema differences
Secret Server, Delinea Platform, DevOps Secrets Vault, Privilege Manager, and other products can expose different resources, versions, and permission models. Confirm the product, tenant, deployment, base URL, API version, and integration identity before implementation.
Reliable synchronization
- Follow pagination and use bounded page sizes.
- Persist checkpoints for long-running inventory or audit workflows.
- Apply throttling and bounded retry backoff for rate limits, timeouts, and temporary service failures.
- Use stable request IDs, external IDs, or Secret and Folder keys to prevent duplicates.
- Test Folder, Secret Template, Site, User, Group, and audit permissions with the actual service account.
- Isolate version-specific mappings and monitor changes to identifiers, date formats, null handling, and error responses.
Why use Martini instead of scripts or point-to-point integrations?
Orchestration instead of isolated scripts
Martini provides a maintainable workflow layer for authenticating to Delinea, coordinating approvals and downstream applications, transforming JSON or XML, applying business rules, and exposing controlled APIs. This avoids duplicating authentication, retry, mapping, and audit logic across scripts.
Operational control
Workflows can combine API-led, scheduled, callback-based, and batch-oriented processing while preserving checkpoints, correlation identifiers, and error paths. Martini also supports reusable integration assets, protected configuration, monitoring, and controlled deployment as Delinea products and API versions evolve.
Frequently asked questions
Delinea can be integrated through Secret Server and Delinea Platform REST APIs, with legacy Secret Server SOAP services available for compatible deployments. Selected products or operations may provide callbacks or notifications, while scheduled API polling can support synchronization when event coverage is unavailable. OAuth 2.0, bearer tokens, permissions, pagination, and product-specific API versions must be confirmed.
Yes. Martini can consume Delinea REST APIs, use legacy Secret Server SOAP APIs where required, receive documented callbacks when available, expose controlled APIs for downstream applications, and orchestrate Delinea operations with identity, service-management, SIEM, and DevOps systems.
No. A dedicated Delinea connector is not required. Martini can use Delinea's confirmed native REST APIs, legacy SOAP services, authentication methods, and supported callbacks or notifications through API consumption and workflow orchestration.
Lonti does not charge an additional per-connector or per-vendor fee to integrate Delinea. The integration is subject to the provisioned capacity of the Martini environment. Separate costs may apply from Delinea, cloud infrastructure, or other third-party systems depending on subscriptions, usage, and deployment model.
REST APIs should generally be evaluated first for current Secret Server and Delinea Platform integrations. OAuth 2.0 and bearer tokens are documented for applicable services. SOAP is a legacy compatibility option, and callbacks should be used only after confirming support for the selected product and event.
No universal webhook coverage was confirmed. Delinea event, notification, or callback support is product- and operation-specific. Martini can receive documented callbacks where available, or run scheduled workflows that poll APIs using timestamps, identifiers, audit data, and checkpoints.
Martini can perform real-time request-driven processing, callback-based updates, or scheduled synchronization. Workflows can use pagination, updated timestamps, object IDs, audit information, and persisted checkpoints, while applying stable keys to avoid duplicate Secret creation or repeated updates.
Martini maps Delinea JSON or XML into canonical and target models, validates permissions and required fields, and applies business rules before writes. Workflows can separate authentication, authorization, validation, conflict, throttling, timeout, and service failures, with bounded retries for transient errors and idempotency controls for non-idempotent operations.
Related Martini documentation
API Integration
Workflows
Integrate Delinea with Martini
Use Martini to build secure, maintainable Delinea integrations across REST APIs, legacy SOAP services, controlled callbacks, scheduled synchronization, and enterprise workflows.