Skip to main content
With the Ramp integration, you can manage spend-platform access through Opal:
  • Let people request just-in-time access to Ramp roles and funds from the web and Slack
  • Provision and deprovision Ramp users
  • Delegate approvals to the right owners
  • Review who has each Ramp role or fund membership
Ramp departments and locations sync into Opal as groups for visibility. Membership comes from Ramp, so you cannot assign people to those groups in Opal.

Supported resources

Custom Ramp roles and People Groups are not available in Opal. People Groups have no Developer API.

Requirements

Before you begin, you must:
  • Be an Opal Admin.
  • Be a Ramp admin with access to Company > Developer.
  • Create a Ramp Developer app that uses the Client Credentials grant.
  • Have the Ramp integration enabled for your Opal organization. If you do not see Ramp under + App, contact your Opal admin or Opal support.
Guest User and Auditor (View-Only Admin) can require Ramp Plus. Ramp still lists those roles through the API when the business has the feature.

1. Create a Ramp Developer app

Opal authenticates with OAuth client credentials. No user login is required. In Ramp:
  1. Go to Company > Developer.
  2. Create a new app.
  3. Allow these scopes on the app:
  1. Copy the Client ID and Client Secret. Ramp shows the secret only once.
For more detail, see Ramp’s Quickstart and Authorization docs.

2. Create a Ramp app in Opal

In Opal, go to Inventory > + App, then select Ramp. Fill in the following fields and create the app.

3. Import Ramp resources

After creating the app, import users, roles, funds, departments, and locations from … > Import items. People can then request Ramp roles and funds through Opal.

User provisioning

When user provisioning is enabled:
  • New email: Opal creates the Ramp user as a Business User, and Ramp sends the invitation immediately.
  • Existing inactive user: Opal reactivates that user. The Ramp user ID, cards, organization, and role stay the same.
  • Existing draft: Opal sends the invitation now.
  • Already active: Opal links the existing Ramp user and does not send another invitation.
  • Remove from the connection: Opal deactivates the Ramp user. Cards freeze and history remains. Ramp’s API has no permanent delete.
Opal matches people by email. Opal does not update name, department, location, or manager from access requests. Change roles through the built-in role resources. Fund access is membership on the fund.

Ramp SCIM

Ramp SCIM is an identity provider integration, configured in Ramp for Okta, Microsoft Entra, or Rippling. Opal does not speak SCIM to Ramp. When SCIM is on, the identity provider overwrites name, email, department, location, manager, and role on its next sync, typically within minutes. When you answer Yes to Does your Ramp use SCIM?, Opal limits what it changes:
If the person is still assigned in the identity provider, SCIM can reactivate them after Opal deactivates them. Keep the identity provider assignment in sync with offboarding.
See Setting up SCIM and managing user provisioning in Ramp’s help center.

Additional information

Built-in roles

A Ramp user holds exactly one built-in role. Granting a role replaces the user’s current role. Revoking a role assigns Business User. Opal does not catalog or assign:
  • Owner (BUSINESS_OWNER). This role cannot be invited or assigned. Transfer ownership in Ramp.
  • Custom roles from Ramp’s custom roles API. Those roles can be listed, but they cannot be assigned to a user through Opal.
Manager is a Ramp add-on (is_manager), not a role in Opal.

Departments and locations

Departments and locations sync as groups so you can review who sits where. You cannot add or remove members in Opal. Changing a location’s legal entity in Ramp moves every user on that location.

Funds

Funds are optional. They require funds:read to import and funds:write to change membership. Funds stay requestable when Ramp SCIM is on.
Last modified on October 1, 2026