Supported resources
With the Wrike integration, you can:
- Let people request access to Wrike groups and user types.
- Invite people to Wrike, reactivate users, and deactivate users or cancel pending invitations.
- Review group membership and user types in access reviews.
Requirements
Before you begin, you must:- Be an Opal Admin.
- Have a Wrike account. The Wrike REST API is available on every plan, including Free.
- Have access to a durable Wrike admin account that can own the permanent API token. The token can perform any action that the account can perform.
- Know your Wrike host:
www.wrike.com,app-eu.wrike.com, orapp-us2.wrike.com. You can find the host at the beginning of the URL when you are signed in to Wrike.
1. Create a permanent API token in Wrike
Sign in with the Wrike admin account that will own the integration:- Select your profile image, then select Apps & Integrations.
- Open the API tab.
- Create an app, such as
Opal, or open an existing app. - Under Permanent access token, select Get token or Create token.
- Enter your Wrike password and copy the token. Wrike displays the token only once.
2. Create the Wrike app in Opal
In Opal, go to Inventory > + App, then select Wrike.3. Enter your Wrike credentials
Complete the app form:
After you save the app, import Wrike groups and user types from … > Import items.
What Opal syncs
- Users: Active people, matched by email. Pending invitations appear as users until they are accepted. Opal skips bots and does not list deactivated or deleted people.
- Groups: Every Wrike group, including My Team, as a flat list. Opal syncs membership for people who have accepted their invitation, but does not preserve parent and child relationships between nested groups.
- User types: Regular, External, Contributor, Viewer, and Collaborator, if the account still has that type. Owner and Admin are visible but cannot be granted. Opal omits Asset user types because they represent equipment rather than a person license.
Provisioning
Users
Adding someone to the Wrike app sends one invitation to their email address. The invitation includes their name. Wrike assigns the account’s default user type. After the person accepts, sync the app so Opal can link them to the Wrike user, then grant the required user type.- If the email address belongs to a deactivated Wrike user, Opal reactivates them instead of sending another invitation.
- If the email address belongs to a deleted Wrike user, Opal does not send an invitation. Restore the user in Wrike, then retry.
- Adding someone who is already invited or active does not send another email.
User types
A Wrike user has exactly one user type. Granting a type replaces their current type. Granting the type they already have makes no change.- You cannot grant Owner or Admin from Opal. Change these user types in Wrike.
- You cannot revoke a user type from someone who has accepted their invitation. Grant a replacement type or remove the person from the app.
- Revoking a user type from someone with a pending invitation cancels the invitation.
- A user type grant for someone with a pending invitation waits until they accept. After they accept, sync the app and retry the grant.
Groups
Granting group access adds the person to that group. Revoking access removes them from that group without changing their other group memberships. Both actions apply only after the person accepts their invitation. Opal does not create, delete, or nest Wrike groups.Limitations
The Wrike integration does not support:- OAuth. The app uses a permanent token.
- SCIM, including direct user creation, profile editing, and permanent deletion.
- Sharing spaces, folders, and projects, or managing access roles on those items.
- Buying seats or deleting a user to free a seat.