Skip to main content

Capabilities

The Lucidchart connector syncs the following resources: Additional functionality: The Lucidchart connector supports automatic account provisioning. Account provisioning includes Create* and Delete†. Notes:
  • *Account provisioning is only available on Lucidchart accounts with Enterprise licenses. When creating an account with no roles specified, Lucid assigns its server-side default role.
  • †Delete and the account actions require a Lucid Enterprise SCIM bearer token (lucid-scim-token). Without it, sync and account creation still work, but these capabilities are unavailable. See Create a SCIM token for how to generate one.
When a new account is created by C1, the account’s password will be sent to a vault.

Connector actions

Connector actions are custom capabilities that extend C1 automations with app-specific operations. You can use connector actions in the Perform connector action automation step. Each one needs the lucid-scim-token described above (see Create a SCIM token): update_user accepts roles either as SCIM names (AccountAdmin, BillingAdmin, Developer, DocumentAdmin, EnterpriseShieldAdmin, TemplateAdmin) or as the kebab-case names account creation takes (team-admin, billing-admin, developer, document-admin, enterprise-shield-admin, template-admin), which are translated for you. The remaining creation-time roles — account-owner, group-admin, organizational-group-admin and team-manager — have no SCIM equivalent and cannot be changed after the account exists.

The two SCIM integrations

Lucid runs two separate SCIM integrations, and both are served from the same base URL, https://users.lucid.app/scim/v2. Nothing in the URL tells them apart — the bearer token alone decides which integration a call reaches, so each needs its own token. lucid-content-access-scim-token extends Delete; it does not replace lucid-scim-token. With it configured, a Delete removes the user from admin management first and from content access second. If the first succeeds and the second fails, the connector reports a partial-deprovisioning error rather than a success — the user is gone from admin management but may still hold team content access, and that shouldn’t look like a completed offboarding.

FedRAMP and GovSuite tenants

The scim-base-url setting defaults to https://users.lucid.app/scim/v2, which is correct for all commercial Lucid accounts. Leave it empty unless you’re on FedRAMP/GovSuite. Lucid publishes no fixed FedRAMP SCIM hostname. Unlike the REST API, which simply swaps api.lucid.co for api.lucidgov.app, the SCIM base URL for a GovSuite account is generated per account in your own GovSuite admin panel. Copy it from there and paste it into scim-base-url. It applies to both SCIM tokens, since both integrations share the one base URL. Both SCIM bearer tokens are sent to whatever host scim-base-url names, so the connector rejects a value that isn’t an absolute https:// URL — cleartext would put the tokens on the wire in the clear. The hostname itself is not restricted, because a GovSuite hostname is account-specific and Lucid publishes no list to check it against. A rejected value disables the SCIM surface — actions, deprovisioning and delete — and logs the problem at debug level. Syncing is unaffected, since it runs against the REST API under base-url and never reads this setting. If SCIM operations fail with an error naming scim-base-url, correct the value rather than the tokens.

Gather Lucidchart credentials

Each setup method requires you to pass in credentials generated in Lucidchart. Gather these credentials before you move on.
A user with access to the developer tools in Lucidchart must perform this task.

Create an API key

1
In the Lucidchart developer portal, navigate to API Keys.
2
Click + Create API Key.
3
Give the new key a name, such as “C1” and set an expiration, if desired.
4
Give the key the relevant set of grants:
  • To give C1 sync-only (READ) access: Documents - View and Folders - View
  • To give C1 provisioning (READ/WRITE) access: Documents - Edit and Folders - Edit
5
Click Generate API key. The new key is created.
6
Carefully copy and save the API key.

Create an OAuth2 client

1
Navigate to https://lucid.app/developer#/packages and click Create Application.
2
Give the new app a name, then click Create.
3
Select the new app’s OAuth 2.0 tab.
4
Enter https://accounts.conductor.one/oauth/callback in the Redirect URI field.
5
Click Create OAuth 2.0 client.
6
Carefully copy and save the OAuth client ID and client secret.

Create a SCIM token

This token is optional. Sync, folder and document provisioning, and account creation all work without it. You only need it if you want C1 to delete accounts or to run the enable_user, disable_user and update_user actions, which go through Lucid’s SCIM surface.
SCIM is only available on Lucidchart accounts with Enterprise licenses, and Lucid support must enable it for your account before the page below appears. This task is performed by an account administrator in the Lucid admin panel — not in the developer portal.
1
In the Lucid admin panel, navigate to Admin > App Integration > SCIM.Don’t see the SCIM page? Contact Lucid support to have SCIM enabled for your account.
2
Generate a SCIM bearer token.The same page lists the SCIM base URL (https://users.lucid.app/scim/v2), which the connector uses by default.
3
Carefully copy and save the SCIM token.

Self-hosted only: Create an OAuth refresh token

If you’re setting up a self-hosted Lucidchart connector, you’ll also need a refresh token for the Lucidchart OAuth client.
1
Follow the Lucidchart OAuth2 access token documentation to create an access token.
2
If you want to use the Lucidchart connector to provision accounts, give the token the account.user scope.Account provisioning is only available on Lucidchart accounts with Enterprise licenses.If you also want C1 to transfer a deleted user’s documents to another user before removing the account, add the account.user.transfercontent scope. Without it, Delete calls to POST /v1/transferUserContent will return 403.Note: if the user’s REST record can’t be read at deletion time (a 403 or an undocumented 404), C1 probes SCIM to confirm they’re actually gone before deleting, refusing with FailedPrecondition if SCIM says the user is still present — grant account.user:readonly so the email can be read. A SCIM 409 (account owner or default document owner) also surfaces as FailedPrecondition.
3
Carefully copy and save the refresh token included in the token response.
That’s it! Next, move on to the connector configuration instructions.

Configure the Lucidchart connector

To complete this task, you’ll need:
  • The Connector Administrator or Super Administrator role in C1
  • Access to the set of Lucidchart credentials generated by following the instructions above
Follow these instructions to use a built-in, no-code connector hosted by C1.
1
In C1, navigate to Apps > Connectors and click Add connector.
2
Search for Lucidchart and click Add.Don’t see the Lucidchart connector? Reach out to support@conductorone.com to add Lucidchart to your Connectors page.
3
Choose where to add the connector: Create a new app, or Add to an existing app (then select the app).If you’re creating a new app, choose whether to link it to an application discovered from your identity provider: select Yes and pick the IdP application, or No to continue with just the connector.
4
Set the connector’s Name and, optionally, a Description.
5
Click the pencil icon next to Owners to choose who can configure and manage this connector.
6
Click Add. The connector is created and its configuration page opens.
7
Find the Settings area of the page and click Edit.
8
Paste the API key in the Lucidchart API key field.
9
Paste the client ID and client secret into the relevant fields.
10
Optional. Paste the SCIM token in the Lucidchart SCIM Token field. Leave it empty if you skipped Create a SCIM token; account delete and the three account actions are then unavailable.If you also use Lucid’s second SCIM integration, SCIM for content access (which syncs to teams), paste its token into the Lucidchart content access SCIM token field. When it’s set, deleting a user also removes them from that integration.
11
FedRAMP/GovSuite only. Enter your account-specific SCIM base URL in the Lucidchart SCIM base URL field. Leave it empty on commercial accounts — it defaults to https://users.lucid.app/scim/v2.
12
Optional. To have C1 transfer a deleted user’s documents to another user instead of removing them along with the account, enter that user’s email address in the Content Transfer User Email field.
13
Optional. By default, the connector syncs Lucidchart documents and folders that are shortcuts. If you prefer not to sync shortcuts (because they don’t grant effective permissions or might return 403/404 errors from the API), click to enable Exclude shortcuts.
14
Click Save.
15
Click Login with OAuth.
16
Log into Lucidchart and authorize C1.
17
After authorizing, you’ll be redirected back to the C1 integrations page, where an “Authorized as” message is now printed.
18
The connector’s label changes to Syncing, followed by Connected. You can view the logs to ensure that information is syncing.
That’s it! Your Lucidchart connector is now pulling access data into C1.