Skip to main content

Overview

OpalScript is Opal’s scripting language for automating access management workflows integrated deeply with Opal’s access management platform. Built on Starlark (a Python-like language), OpalScript enables you to write custom automation logic and scripts that evaluate conditions, query the access graph and take actions programmatically.

Use cases

OpalScript currently supports automated request review and delegation conditions, with more automation types planned:

How OpalScript works

Each OpalScript type has access to:
  1. Utility modules: Common functions available to all script types (e.g., access for access queries, notifications for sending notifications, http and secrets for calling external APIs)
  2. Context module: Script-type-specific data about what triggered the script
  3. Actions module: Script-type-specific operations the script can perform
This separation allows you to learn the core language and utility functions once, then apply them across different automation scenarios.

Create your first workflow

  1. In Opal, navigate to OpalScript > Editor and create a new script. Give it a name and select an owner. Opal provisions a service user behind the script, owned by the owner you select. This service user is the identity that runs the script.
  2. Enter your OpalScript in the editor. For example, to auto-approve all requests:
    See Request Review: Get started for the full context and actions API reference, and examples for ready-to-use scripts.
  3. Add the script’s service user as a reviewer on any resource or group. When a request is submitted, the script runs automatically.
For test runs, version history, triggers, and run monitoring, see Using the editor.
Last modified on September 21, 2026