> ## Documentation Index
> Fetch the complete documentation index at: https://docs.opal.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Ramp

> Learn how to connect Opal to Ramp to manage users, roles, and funds.

With the Ramp integration, you can manage spend-platform access through Opal:

* Let people request just-in-time access to Ramp roles and funds from the web and Slack
* Provision and deprovision Ramp users
* Delegate approvals to the right owners
* Review who has each Ramp role or fund membership

Ramp departments and locations sync into Opal as groups for visibility. Membership comes from Ramp, so you cannot assign people to those groups in Opal.

## Supported resources

| Resource | Read | Grant and revoke access | Notes |
| - | - | - | - |
| Users | ✔️ | ✔️ | Active users only. Opal invites on create and deactivates on remove. Opal never permanently deletes a Ramp user. |
| Built-in roles | ✔️ | ✔️ | Business User, Business Admin, Bookkeeper, Auditor, Guest, and IT Admin. A user has exactly one role. Revoking a role assigns Business User. Owner cannot be assigned through the API. |
| Funds | ✔️ | ✔️ | Spend budgets. Add or remove fund members. |
| Departments | ✔️ | | Synced as groups. Membership comes from Ramp and cannot be edited in Opal. |
| Locations | ✔️ | | Synced as groups. Membership comes from Ramp and cannot be edited in Opal. |

Custom Ramp roles and People Groups are not available in Opal. People Groups have no Developer API.

## Requirements

Before you begin, you must:

* Be an Opal Admin.
* Be a Ramp admin with access to **Company** > **Developer**.
* Create a Ramp Developer app that uses the **Client Credentials** grant.
* Have the Ramp integration enabled for your Opal organization. If you do not see Ramp under **+ App**, contact your Opal admin or Opal support.

<Note>
  Guest User and Auditor (View-Only Admin) can require [Ramp Plus](https://support.ramp.com/user-roles-overview). Ramp still lists those roles through the API when the business has the feature.
</Note>

## 1. Create a Ramp Developer app

Opal authenticates with OAuth client credentials. No user login is required.

In Ramp:

1. Go to **Company** > **Developer**.
2. Create a new app.
3. Allow these scopes on the app:

| Scope | What it unlocks |
| - | - |
| `users:read` | List Ramp users |
| `departments:read` | Sync departments |
| `locations:read` | Sync locations |
| `funds:read` | Sync funds as entitlements |
| `entities:read` | Required for sync and user lifecycle actions. Opal does not import legal entities. |
| `users:write` | Invite, deactivate, reactivate, and change a built-in role |
| `funds:write` | Add or remove fund members |

4. Copy the **Client ID** and **Client Secret**. Ramp shows the secret only once.

For more detail, see Ramp's [Quickstart](https://docs.ramp.com/developer-api/v1/getting-started) and [Authorization](https://docs.ramp.com/developer-api/v1/authorization) docs.

## 2. Create a Ramp app in Opal

In Opal, go to **Inventory** > **+ App**, then select **Ramp**.

Fill in the following fields and create the app.

| Field | Value |
| - | - |
| App name | An identifiable name for this Ramp connection. |
| App admin | The team or user that should own the Ramp app in Opal. |
| Description | Let requesters know what they are requesting access to. |
| Visibility | Global, or restricted to specific groups. |
| Does your Ramp use SCIM? | **Yes** if an identity provider already provisions Ramp (Okta, Entra, or Rippling). **No** otherwise. See [Ramp SCIM](#ramp-scim). |
| Client ID | The Client ID from [step 1](#1-create-a-ramp-developer-app). |
| Client secret | The Client Secret from [step 1](#1-create-a-ramp-developer-app). |

## 3. Import Ramp resources

After creating the app, import users, roles, funds, departments, and locations from **...** > **Import items**. People can then request Ramp roles and funds through Opal.

## User provisioning

When user provisioning is enabled:

* **New email:** Opal creates the Ramp user as a Business User, and Ramp sends the invitation immediately.
* **Existing inactive user:** Opal reactivates that user. The Ramp user ID, cards, organization, and role stay the same.
* **Existing draft:** Opal sends the invitation now.
* **Already active:** Opal links the existing Ramp user and does not send another invitation.
* **Remove from the connection:** Opal deactivates the Ramp user. Cards freeze and history remains. Ramp's API has no permanent delete.

Opal matches people by email.

Opal does not update name, department, location, or manager from access requests. Change roles through the built-in role resources. Fund access is membership on the fund.

## Ramp SCIM

Ramp SCIM is an identity provider integration, configured in Ramp for Okta, Microsoft Entra, or Rippling. Opal does not speak SCIM to Ramp. When SCIM is on, the identity provider overwrites name, email, department, location, manager, and role on its next sync, typically within minutes.

When you answer **Yes** to **Does your Ramp use SCIM?**, Opal limits what it changes:

| Opal action | Allowed? |
| - | - |
| Create a new Ramp user | No |
| Grant or revoke a built-in role | No |
| Invite an existing draft, reactivate, or link someone already in Ramp | Yes |
| Deactivate | Yes |
| Fund membership | Yes |

<Warning>
  If the person is still assigned in the identity provider, SCIM can reactivate them after Opal deactivates them. Keep the identity provider assignment in sync with offboarding.
</Warning>

See [Setting up SCIM and managing user provisioning](https://support.ramp.com/setting-up-scim-and-managing-user-provisioning) in Ramp's help center.

## Additional information

### Built-in roles

A Ramp user holds exactly one built-in role. Granting a role replaces the user's current role. Revoking a role assigns **Business User**.

Opal does not catalog or assign:

* **Owner** (`BUSINESS_OWNER`). This role cannot be invited or assigned. Transfer ownership in Ramp.
* **Custom roles** from Ramp's custom roles API. Those roles can be listed, but they cannot be assigned to a user through Opal.

Manager is a Ramp add-on (`is_manager`), not a role in Opal.

### Departments and locations

Departments and locations sync as groups so you can review who sits where. You cannot add or remove members in Opal. Changing a location's legal entity in Ramp moves every user on that location.

### Funds

Funds are optional. They require `funds:read` to import and `funds:write` to change membership. Funds stay requestable when Ramp SCIM is on.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.