Skip to main content
You can connect Wrike to Opal to manage and review access to users, groups, and user types.

Supported resources

With the Wrike integration, you can:
  • Let people request access to Wrike groups and user types.
  • Invite people to Wrike, reactivate users, and deactivate users or cancel pending invitations.
  • Review group membership and user types in access reviews.
Opal does not buy Wrike seats. If Wrike has no free seat, an invitation or user type change fails and no seat is purchased.

Requirements

Before you begin, you must:
  • Be an Opal Admin.
  • Have a Wrike account. The Wrike REST API is available on every plan, including Free.
  • Have access to a durable Wrike admin account that can own the permanent API token. The token can perform any action that the account can perform.
  • Know your Wrike host: www.wrike.com, app-eu.wrike.com, or app-us2.wrike.com. You can find the host at the beginning of the URL when you are signed in to Wrike.
Deactivating a user is available on Wrike Pinnacle and Apex plans. On Free, Team, and Business plans, removing a user who has accepted their invitation fails. Canceling a pending invitation works on every plan.

1. Create a permanent API token in Wrike

Sign in with the Wrike admin account that will own the integration:
  1. Select your profile image, then select Apps & Integrations.
  2. Open the API tab.
  3. Create an app, such as Opal, or open an existing app.
  4. Under Permanent access token, select Get token or Create token.
  5. Enter your Wrike password and copy the token. Wrike displays the token only once.
Create the token with a technical admin account instead of someone’s everyday account. Wrike revokes the token if the account owner resets their password, is deactivated, or is accessed through Log in as this user. If synchronization fails with an authorization error, generate a new token and update the app in Opal.

2. Create the Wrike app in Opal

In Opal, go to Inventory > + App, then select Wrike.

3. Enter your Wrike credentials

Complete the app form: After you save the app, import Wrike groups and user types from … > Import items.

What Opal syncs

  • Users: Active people, matched by email. Pending invitations appear as users until they are accepted. Opal skips bots and does not list deactivated or deleted people.
  • Groups: Every Wrike group, including My Team, as a flat list. Opal syncs membership for people who have accepted their invitation, but does not preserve parent and child relationships between nested groups.
  • User types: Regular, External, Contributor, Viewer, and Collaborator, if the account still has that type. Owner and Admin are visible but cannot be granted. Opal omits Asset user types because they represent equipment rather than a person license.
Opal does not sync spaces, folders, item access roles, or job roles.

Provisioning

Users

Adding someone to the Wrike app sends one invitation to their email address. The invitation includes their name. Wrike assigns the account’s default user type. After the person accepts, sync the app so Opal can link them to the Wrike user, then grant the required user type.
  • If the email address belongs to a deactivated Wrike user, Opal reactivates them instead of sending another invitation.
  • If the email address belongs to a deleted Wrike user, Opal does not send an invitation. Restore the user in Wrike, then retry.
  • Adding someone who is already invited or active does not send another email.
Removing someone from the app deactivates an accepted user or cancels a pending invitation. Opal never permanently deletes a Wrike user, and deactivation does not free the seat. Account owners and people who belong to more than one Wrike account cannot be deactivated.

User types

A Wrike user has exactly one user type. Granting a type replaces their current type. Granting the type they already have makes no change.
  • You cannot grant Owner or Admin from Opal. Change these user types in Wrike.
  • You cannot revoke a user type from someone who has accepted their invitation. Grant a replacement type or remove the person from the app.
  • Revoking a user type from someone with a pending invitation cancels the invitation.
  • A user type grant for someone with a pending invitation waits until they accept. After they accept, sync the app and retry the grant.

Groups

Granting group access adds the person to that group. Revoking access removes them from that group without changing their other group memberships. Both actions apply only after the person accepts their invitation. Opal does not create, delete, or nest Wrike groups.

Limitations

The Wrike integration does not support:
  • OAuth. The app uses a permanent token.
  • SCIM, including direct user creation, profile editing, and permanent deletion.
  • Sharing spaces, folders, and projects, or managing access roles on those items.
  • Buying seats or deleting a user to free a seat.
Last modified on October 1, 2026