Paladin context scripts are currently in beta. Contact Opal support to enable them for your organization.
Context provider scripts fail open. If a script errors, times out, or adds nothing, Paladin simply makes its decision without that context. A broken script never blocks a review.
How it runs
- A request is routed to a Paladin agent that has the script added as a context source.
- When the agent starts its review, Opal runs each of the agent’s context scripts against the request. Scripts run in parallel.
- Every
actions.add_context(...)call the script makes becomes a context item that Paladin reads during the review. - The run is recorded on the OpalScript Runs page, like any other script run.
Write a context provider script
Read the request withcontext.get_request(), fetch what you need, and attach it with actions.add_context(...).
api_token must exist as a secret.
context module
Returns the request Paladin is reviewing. It is the same object documented for request review.actions module
Adds one item of context for Paladin to read. Call it as many times as you need. It returnsNone and does not end the script.
add_context accepts keyword arguments only. Passing a positional argument is an error.
string
required
A short, human-readable title for the item, such as
"Okta authn posture for alice@example.com". Must not be empty.any
required
The context itself: a dict, list, string, number, bool, or
None. It is serialized to JSON, so keep it to the fields that matter for the decision.string
Where the data came from, such as
"okta" or "jamf". Helps Paladin and reviewers attribute the context.…[truncated], so summarize rather than passing a whole API response through.
Available modules
Context provider scripts can use these utility modules:access,entity,requests,risk, andtimefor reading Opal datahttpandsecretsfor calling external APIs
notifications and tickets are not available, because a context provider script only reads.
Create a context provider script
- Navigate to Admin > OpalScript > Editor and select + above the script list.
- Choose Paladin context from the script type dropdown.
- Pick a template, or Blank script to start from scratch.
- Enter a name, then select Use template (or Create blank script).
Templates
Each template has constants at the top, such as the base URL of your Okta org, that you set before you use it. Create the secret it expects in Admin > OpalScript > Advanced > Secrets, and add the host to Allowed hosts.
Add the script to a Paladin agent
- Open the Paladin agent’s configuration.
- In the connector list, select the OpalScript row.
- Under Context scripts, pick the scripts this agent should run.
Test a context provider script
Use Test run in the editor, just as for a request review script. The Debug panel lists eachadd_context call with its label and source, so you can confirm what Paladin would receive. Nothing is sent to Paladin during a test run.
Limits
Because the timeout is 5 seconds, keep each script to a few fast API calls. A script that times out adds no context at all, even if it called
add_context before the timeout.