Ellipse Gradient for Header

Delinea Integration Guide

Connect Delinea Secret Server and Delinea Platform services with enterprise applications through REST APIs, legacy SOAP services, controlled callbacks, and scheduled workflows.

Delinea integration options at a glance

Delinea integrations are product- and deployment-specific, with REST APIs as the primary approach for Secret Server and Delinea Platform services. APIs can read and manage Secrets, Folders, Secret Templates, Users, and Groups where the selected product and permissions allow. Secret Server also exposes legacy SOAP services for compatible deployments, while webhook-style notifications or callbacks may be available for selected operations and must be confirmed. Martini can authenticate with OAuth 2.0 and bearer tokens, orchestrate paginated API calls, map protected metadata, expose controlled APIs, and use scheduled polling when no suitable event mechanism exists.

Integration pointSupported by Delinea?Common use casesHow Martini supports it
REST APIsYesSecret Server and Delinea Platform REST APIs can read or manage Secrets, Folders, Secret Templates, Users, Groups, and other product-specific resources. Exact paths and operations depend on the product and version.Martini can consume Delinea REST endpoints, paginate responses, transform JSON, apply business rules, and expose controlled Martini APIs over selected operations.
SOAP APIsLegacySecret Server has historically provided SOAP web services for existing deployments or operations not available through REST.Martini can consume SOAP services and handle XML mappings where a legacy Secret Server operation is required.
Webhooks / outbound callbacksLimitedDelinea products may provide event, notification, or callback capabilities for selected operations, but universal webhook coverage is not confirmed.Martini can receive documented callbacks when available; otherwise it can use scheduled API polling with timestamps, identifiers, or audit checkpoints.
Bulk / async / batch APIsNot confirmedBulk and asynchronous support is operation-specific and should not be assumed across Delinea resources.Martini can implement controlled pagination, checkpointing, throttling, and workflow batching around available endpoints.
File / attachment APIsLimitedSecret Server may expose attachment operations for selected Secret resources, subject to API version, Secret Template, and permissions.Martini can transfer or transform supported attachments while enforcing size, access, logging, and error-handling policies.
AuthenticationYesApplicable Secret Server and Delinea Platform APIs support OAuth 2.0 and bearer-token authentication; exact grants, scopes, and endpoints vary.Martini can store client credentials in protected environment configuration, obtain tokens, add authorization headers, and handle expiry or permission failures.
Database / analytics accessNoDirect database access is not the standard supported integration path for Delinea Cloud or Secret Server SaaS deployments.Martini should consume supported Delinea APIs rather than reading or writing product databases directly.

How Delinea exposes data and business events

Delinea REST APIs

REST is the primary standards-based integration method for current Secret Server and Delinea Platform scenarios. Depending on the product and permissions, REST resources can support Secrets, Folders, Secret Templates, Users, Groups, audit data, and other product-specific operations.

Martini implementation pattern

Martini implementation pattern: Martini authenticates to the appropriate Delinea endpoint, invokes the required REST resources, validates responses, maps JSON into a canonical model, and coordinates downstream writes or controlled API responses.

Implementation sequence

Authenticate with the configured OAuth 2.0 or bearer-token flow
Call the product-specific Delinea REST resource
Follow pagination and retain a synchronization checkpoint
Validate permissions, identifiers, and response fields
Map the result to the target system model
Write the result and record correlation data

Secret Server SOAP APIs

Secret Server has historically exposed SOAP web services for legacy deployments and compatibility scenarios. SOAP should generally be evaluated only when the required operation is unavailable through REST or an existing deployment depends on it.

Martini implementation pattern

Martini implementation pattern: Martini consumes the SOAP service, handles XML request and response structures, applies the same authorization, validation, mapping, and retry controls used for REST integrations, and isolates legacy mappings for maintainability.

Implementation sequence

Authenticate to the Secret Server SOAP service
Build the required XML request
Invoke the legacy web service operation
Validate the SOAP response and fault details
Transform XML data into the canonical model
Apply controlled retry and error routing

Delinea callbacks and scheduled synchronization

Delinea event, notification, or callback capabilities may exist for selected products and operations, but universal webhook coverage is not confirmed. Scheduled API polling is an alternative when no suitable outbound event is available.

Martini implementation pattern

Martini implementation pattern: Martini receives a documented callback when supported, or starts a scheduled workflow that retrieves changed resources using timestamps, identifiers, audit data, pagination, and persisted checkpoints.

Implementation sequence

Receive the documented callback or start the scheduled workflow
Validate the event or load the saved synchronization checkpoint
Retrieve the current Delinea resource or changed-resource page
Filter already processed identifiers and versions
Map metadata without exposing protected values
Persist the checkpoint and route failures for retry

Common Delinea integration patterns

Pattern 1: Automate ServiceNow privileged-access requests

When to use this pattern

Use this pattern when an approved ServiceNow request must retrieve or provision a Delinea Secret and return status or audit information. It supports approval validation, controlled exposure, and duplicate prevention.

Integration direction
ServiceNow
Martini
Delinea
Example Mapping
Delinea FieldCanonical FieldTarget Field
requestIdexternalRequestIdSecret or workflow correlation key
requestedFolderfolderIdentifierFolder ID
requestedSecretsecretIdentifierSecret ID or name
approvalStatusapprovalStateWorkflow business rule
Martini implementation pattern

A Martini API receives the approved request, validates requester, approver, Folder, and Secret permissions, then orchestrates Delinea calls. It returns only the permitted response, records correlation data, and uses the request ID as an idempotency key so retries do not create duplicate Secrets or repeat unsafe retrievals.

Martini capabilities used
  • APIs
  • workflows
  • API consumption
  • data mapping
  • business rules
  • secrets management
  • error handling

Pattern 2: Reconcile Delinea access with Microsoft Entra ID

When to use this pattern

Use this pattern to align selected Delinea Users or Groups with approved Microsoft Entra ID identities and memberships. The workflow can report differences or apply governed updates where the product API permits.

Integration direction
Microsoft Entra ID
Martini
Delinea
Example Mapping
Delinea FieldCanonical FieldTarget Field
idexternalIdentityIdUser ID
displayNameidentityNameUser or Group name
accountEnabledactiveStateUser status
membersgroupMembershipsGroup membership
Martini implementation pattern

A scheduled Martini workflow retrieves directory changes and Delinea Users or Groups, normalizes identifiers, applies disabled-user and privilege-escalation rules, and performs only supported updates. It checkpoints pages, records differences, and routes permission or conflict errors without broadening access automatically.

Martini capabilities used
  • scheduled workflows
  • API consumption
  • data mapping
  • business rules
  • checkpointing
  • error handling

Pattern 3: Publish a non-secret Delinea inventory

When to use this pattern

Use this pattern for compliance, operational, or SIEM reporting based on Secret, Folder, Secret Template, Site, and audit metadata. Secret values should be excluded unless explicitly required and authorized.

Integration direction
Delinea
Martini
Splunk
Example Mapping
Delinea FieldCanonical FieldTarget Field
secretIdobjectIdobject_id
folderIdcontainerIdfolder_id
secretTemplatetemplateNametemplate
lastModifiedmodifiedAtevent_time
Martini implementation pattern

Martini pages through permitted Delinea resources, normalizes dates and identifiers, removes protected values, enriches records with source and execution metadata, and publishes them to Splunk or another approved destination. Checkpoints, bounded concurrency, and retry classification prevent full rescans and uncontrolled duplicate events.

Martini capabilities used
  • scheduled workflows
  • API consumption
  • pagination
  • data mapping
  • JSON handling
  • retry handling
  • monitoring

Pattern 4: Expose a controlled DevOps secret retrieval API

When to use this pattern

Use this pattern when Ansible, Terraform, or another automation process needs a narrowly scoped credential without embedding it in code or playbooks. The exact Delinea product and machine-to-machine flow must be confirmed.

Integration direction
Terraform
Martini
Delinea
Example Mapping
Delinea FieldCanonical FieldTarget Field
workspaceexecutionContextAuthorization rule
environmentenvironmentNameFolder or Secret selection
secretReferencesecretIdentifierSecret ID
requestIdcorrelationIdAudit metadata
Martini implementation pattern

Martini exposes an authenticated API façade, validates the calling context and requested environment, retrieves only the permitted Secret through Delinea, and returns a controlled response. It masks logs, applies short-lived token handling, limits retries for retrieval failures, and records audit metadata without storing the secret value unnecessarily.

Martini capabilities used
  • API exposure
  • API consumption
  • authentication
  • authorization
  • data mapping
  • business rules
  • secure logging
  • error handling

Applications commonly integrated with Delinea

Delinea commonly participates in privileged-access, identity, security monitoring, service-management, and DevOps workflows. The exact integration depends on the Delinea product, tenant, API version, and permissions available to the integration identity.

Application Scenario Direction Martini Pattern
ServiceNow Automate privileged-access requests, approvals, credential checkout, ticket updates, and audit references. ServiceNow → Martini → Delinea Expose a Martini API for approved requests, validate requester and approval data, retrieve or provision the required Delinea Secret, and return a controlled status while retaining correlation and audit data.
Microsoft Entra ID Synchronize approved users and groups, reconcile disabled identities, and align privileged access with directory membership. Microsoft Entra ID → Martini → Delinea Run a scheduled workflow that retrieves directory changes, maps identities and group memberships, applies permission and lifecycle rules, and updates supported Delinea objects idempotently.
Splunk Send Delinea audit and privileged-access metadata to a SIEM for monitoring, investigation, and compliance reporting. Delinea → Martini → Splunk Page through supported Delinea audit or activity data, remove secret values, normalize events, and publish them to a Splunk ingestion endpoint with retry and checkpoint handling.
Microsoft Sentinel Forward privileged-access activity and security metadata into Microsoft security monitoring and response workflows. Delinea → Martini → Microsoft Sentinel Use a scheduled or event-driven workflow to retrieve permitted Delinea activity, transform it to the target ingestion model, and submit it with bounded retries and correlation identifiers.
Ansible Retrieve approved credentials during infrastructure automation without hard-coding them in playbooks. Ansible → Martini → Delinea Expose a narrowly scoped Martini API that validates the automation request, selects the permitted Secret, retrieves only the required value, masks operational logs, and returns a controlled response.
Terraform Provide environment-specific credentials to infrastructure provisioning workflows while centralizing authorization and audit controls. Terraform → Martini → Delinea Use a Martini API façade to validate workspace and environment context, retrieve the authorized Delinea Secret, apply response and logging controls, and handle transient failures safely.
Jira Associate privileged-access changes, remediation work, and approvals with issue records. Jira → Martini → Delinea Orchestrate issue and Delinea API calls, map request identifiers and statuses, enforce approval rules, and update both systems using idempotent workflow steps.
Microsoft Power BI Create operational or compliance reports from non-secret Delinea inventory, audit, and access metadata. Delinea → Martini → Microsoft Power BI Extract permitted metadata on a schedule, normalize identifiers and timestamps, exclude protected values, and publish the result to an approved reporting dataset or ingestion endpoint.

How to build a Delinea integration in Martini

Objective

Identify the Delinea product, tenant or base URL, deployment model, API version, and required permissions before configuring the integration.

Instructions in Martini

  • Select the supported Delinea REST endpoint or required legacy SOAP service
  • Create a least-privilege integration identity
  • Configure OAuth 2.0 client credentials, bearer-token settings, or confirmed legacy authentication
  • Store client secrets and tokens in Martini protected environment configuration

Objective

Select an event-driven, API-led, or scheduled execution model based on the confirmed Delinea capabilities for the target operation.

Instructions in Martini

  • Use a Martini API for request-driven retrieval or provisioning
  • Receive only documented Delinea callbacks for supported events
  • Use a scheduler when event coverage is unavailable or incomplete
  • Define the checkpoint and idempotency strategy before processing data

Objective

Call the appropriate Delinea resources and retrieve only the objects and fields required by the business process.

Instructions in Martini

  • Invoke the product-specific REST or SOAP operation
  • Follow documented pagination and filtering parameters
  • Retrieve current resources after callback notifications when necessary
  • Avoid requesting or logging Secret values unless explicitly authorized

Objective

Coordinate Delinea calls with approvals, identity systems, reporting destinations, or DevOps clients in a maintainable Martini workflow.

Instructions in Martini

  • Validate the incoming request and caller context
  • Apply permission, approval, and environment rules
  • Branch on authentication, authorization, validation, conflict, throttling, and service failures
  • Persist correlation identifiers and synchronization checkpoints

Objective

Convert Delinea-specific JSON or XML structures into a canonical model and target application format.

Instructions in Martini

  • Map Secret, Folder, User, Group, Site, and Secret Template fields explicitly
  • Normalize identifiers, timestamps, status values, and nulls
  • Use metadata-only mappings for reporting and audit exports
  • Keep product- and version-specific mappings isolated and reusable

Objective

Publish approved results to downstream systems or return a controlled response to the calling application.

Instructions in Martini

  • Write only to targets authorized for the use case
  • Use stable external IDs or request IDs for idempotent creates and updates
  • Do not expose protected values in broad API responses
  • Record target acknowledgements and Delinea object identifiers

Common Delinea data objects used in integrations

ObjectTypical UseCommon target systemsMartini handling
SecretRetrieve, create, update, inventory, or securely reference privileged credentials and protected values.ServiceNow, Ansible, Terraform, Splunk, Microsoft SentinelMartini restricts access by workflow identity and Delinea permissions, avoids logging values, maps permitted fields, and uses idempotency for writes.
FolderOrganize Secrets and apply access-control boundaries.ServiceNow, Microsoft Entra ID, reporting datasetsMartini uses Folder identifiers and permissions when selecting Secrets, synchronizing access, or producing metadata reports.
UserRepresent Delinea or Secret Server identities and support access or lifecycle reconciliation.Microsoft Entra ID, ServiceNow, JiraMartini maps identifiers and status fields, handles pagination and disabled users, and applies least-privilege update rules.
GroupRepresent membership-based access control and approved privileged-access populations.Microsoft Entra ID, ServiceNow, reporting systemsMartini compares memberships, applies reconciliation rules, records differences, and avoids unauthorized privilege expansion.
SiteIdentify a Secret Server location or site in distributed deployments.ServiceNow, inventory stores, reporting platformsMartini preserves Site identifiers in canonical data and routes or filters operations according to deployment-specific rules.
Secret TemplateDefine the fields and structure used by Secrets.ServiceNow, inventory stores, governance reportsMartini validates template-dependent fields, isolates version-specific mappings, and rejects unsupported or incomplete payloads.

Authentication and security considerations

OAuth and bearer-token security

Applicable Delinea Platform and Secret Server APIs use OAuth 2.0 and bearer tokens, with exact grants, scopes, audiences, and endpoints varying by product and deployment. Martini stores client secrets and protected configuration in environment secrets rather than workflow definitions.

Least privilege and secret protection

  • Use separate integration identities for inventory, retrieval, provisioning, and audit use cases where practical.
  • Grant only the required Secret, Folder, User, Group, Site, and audit permissions.
  • Do not log Secret values or return them in broad API responses.
  • Handle token expiry, revoked clients, insufficient scopes, tenant mismatches, and clock skew explicitly.

Operational considerations for Delinea integrations

Product and schema differences

Secret Server, Delinea Platform, DevOps Secrets Vault, Privilege Manager, and other products can expose different resources, versions, and permission models. Confirm the product, tenant, deployment, base URL, API version, and integration identity before implementation.

Reliable synchronization

  • Follow pagination and use bounded page sizes.
  • Persist checkpoints for long-running inventory or audit workflows.
  • Apply throttling and bounded retry backoff for rate limits, timeouts, and temporary service failures.
  • Use stable request IDs, external IDs, or Secret and Folder keys to prevent duplicates.
  • Test Folder, Secret Template, Site, User, Group, and audit permissions with the actual service account.
  • Isolate version-specific mappings and monitor changes to identifiers, date formats, null handling, and error responses.

Why use Martini instead of scripts or point-to-point integrations?

Orchestration instead of isolated scripts

Martini provides a maintainable workflow layer for authenticating to Delinea, coordinating approvals and downstream applications, transforming JSON or XML, applying business rules, and exposing controlled APIs. This avoids duplicating authentication, retry, mapping, and audit logic across scripts.

Operational control

Workflows can combine API-led, scheduled, callback-based, and batch-oriented processing while preserving checkpoints, correlation identifiers, and error paths. Martini also supports reusable integration assets, protected configuration, monitoring, and controlled deployment as Delinea products and API versions evolve.

Frequently asked questions

How can Delinea be integrated with enterprise systems?

Delinea can be integrated through Secret Server and Delinea Platform REST APIs, with legacy Secret Server SOAP services available for compatible deployments. Selected products or operations may provide callbacks or notifications, while scheduled API polling can support synchronization when event coverage is unavailable. OAuth 2.0, bearer tokens, permissions, pagination, and product-specific API versions must be confirmed.

Can Martini integrate with Delinea?

Yes. Martini can consume Delinea REST APIs, use legacy Secret Server SOAP APIs where required, receive documented callbacks when available, expose controlled APIs for downstream applications, and orchestrate Delinea operations with identity, service-management, SIEM, and DevOps systems.

Do I need a connector to integrate Delinea with Martini?

No. A dedicated Delinea connector is not required. Martini can use Delinea's confirmed native REST APIs, legacy SOAP services, authentication methods, and supported callbacks or notifications through API consumption and workflow orchestration.

Is there any extra Lonti cost to integrate Delinea with Martini?

Lonti does not charge an additional per-connector or per-vendor fee to integrate Delinea. The integration is subject to the provisioned capacity of the Martini environment. Separate costs may apply from Delinea, cloud infrastructure, or other third-party systems depending on subscriptions, usage, and deployment model.

Which Delinea integration method should new projects use?

REST APIs should generally be evaluated first for current Secret Server and Delinea Platform integrations. OAuth 2.0 and bearer tokens are documented for applicable services. SOAP is a legacy compatibility option, and callbacks should be used only after confirming support for the selected product and event.

Does Delinea provide webhooks for every event?

No universal webhook coverage was confirmed. Delinea event, notification, or callback support is product- and operation-specific. Martini can receive documented callbacks where available, or run scheduled workflows that poll APIs using timestamps, identifiers, audit data, and checkpoints.

How does Martini synchronize Delinea data?

Martini can perform real-time request-driven processing, callback-based updates, or scheduled synchronization. Workflows can use pagination, updated timestamps, object IDs, audit information, and persisted checkpoints, while applying stable keys to avoid duplicate Secret creation or repeated updates.

How does Martini handle Delinea mapping, errors, and retries?

Martini maps Delinea JSON or XML into canonical and target models, validates permissions and required fields, and applies business rules before writes. Workflows can separate authentication, authorization, validation, conflict, throttling, timeout, and service failures, with bounded retries for transient errors and idempotency controls for non-idempotent operations.