> ## Documentation Index
> Fetch the complete documentation index at: https://docs.opal.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Wrike

> Learn how to connect Opal to Wrike to manage users, groups, and user types.

You can connect Wrike to Opal to manage and review access to users, groups, and user types.

## Supported resources

| Resource | Read | Grant and revoke access |
| - | - | - |
| Users | ✔️ | ✔️ |
| Groups | ✔️ | ✔️ |
| User types | ✔️ | Grant only |

With the Wrike integration, you can:

* Let people request access to Wrike groups and user types.
* Invite people to Wrike, reactivate users, and deactivate users or cancel pending invitations.
* Review group membership and user types in access reviews.

Opal does not buy Wrike seats. If Wrike has no free seat, an invitation or user type change fails and no seat is purchased.

## Requirements

Before you begin, you must:

* Be an Opal Admin.
* Have a Wrike account. The Wrike REST API is available on every plan, including Free.
* Have access to a durable Wrike admin account that can own the permanent API token. The token can perform any action that the account can perform.
* Know your Wrike host: `www.wrike.com`, `app-eu.wrike.com`, or `app-us2.wrike.com`. You can find the host at the beginning of the URL when you are signed in to Wrike.

<Warning>
  Deactivating a user is available on Wrike Pinnacle and Apex plans. On Free,
  Team, and Business plans, removing a user who has accepted their invitation
  fails. Canceling a pending invitation works on every plan.
</Warning>

## 1. Create a permanent API token in Wrike

Sign in with the Wrike admin account that will own the integration:

1. Select your profile image, then select **Apps & Integrations**.
2. Open the **API** tab.
3. Create an app, such as `Opal`, or open an existing app.
4. Under **Permanent access token**, select **Get token** or **Create token**.
5. Enter your Wrike password and copy the token. Wrike displays the token only once.

Create the token with a technical admin account instead of someone's everyday account. Wrike revokes the token if the account owner resets their password, is deactivated, or is accessed through **Log in as this user**. If synchronization fails with an authorization error, generate a new token and update the app in Opal.

## 2. Create the Wrike app in Opal

In Opal, go to **Inventory** > **+ App**, then select **Wrike**.

## 3. Enter your Wrike credentials

Complete the app form:

| Field | Value |
| - | - |
| App name | An identifiable name, such as `Wrike`. |
| App admin | The owner of this app in Opal. |
| Description | A short description shown to people who request access. |
| Visibility | Global, or restricted to specific groups. |
| Host | Your Wrike host: `www.wrike.com`, `app-eu.wrike.com`, or `app-us2.wrike.com`. Using the wrong host causes an invalid token error. |
| Permanent access token | The token you created in [step 1](#1-create-a-permanent-api-token-in-wrike). |

After you save the app, import Wrike groups and user types from **...** > **Import items**.

## What Opal syncs

* **Users:** Active people, matched by email. Pending invitations appear as users until they are accepted. Opal skips bots and does not list deactivated or deleted people.
* **Groups:** Every Wrike group, including My Team, as a flat list. Opal syncs membership for people who have accepted their invitation, but does not preserve parent and child relationships between nested groups.
* **User types:** Regular, External, Contributor, Viewer, and Collaborator, if the account still has that type. Owner and Admin are visible but cannot be granted. Opal omits Asset user types because they represent equipment rather than a person license.

Opal does not sync spaces, folders, item access roles, or job roles.

## Provisioning

### Users

Adding someone to the Wrike app sends one invitation to their email address. The invitation includes their name. Wrike assigns the account's default user type. After the person accepts, sync the app so Opal can link them to the Wrike user, then grant the required user type.

* If the email address belongs to a deactivated Wrike user, Opal reactivates them instead of sending another invitation.
* If the email address belongs to a deleted Wrike user, Opal does not send an invitation. Restore the user in Wrike, then retry.
* Adding someone who is already invited or active does not send another email.

Removing someone from the app deactivates an accepted user or cancels a pending invitation. Opal never permanently deletes a Wrike user, and deactivation does not free the seat. Account owners and people who belong to more than one Wrike account cannot be deactivated.

### User types

A Wrike user has exactly one user type. Granting a type replaces their current type. Granting the type they already have makes no change.

* You cannot grant Owner or Admin from Opal. Change these user types in Wrike.
* You cannot revoke a user type from someone who has accepted their invitation. Grant a replacement type or remove the person from the app.
* Revoking a user type from someone with a pending invitation cancels the invitation.
* A user type grant for someone with a pending invitation waits until they accept. After they accept, sync the app and retry the grant.

### Groups

Granting group access adds the person to that group. Revoking access removes them from that group without changing their other group memberships. Both actions apply only after the person accepts their invitation.

Opal does not create, delete, or nest Wrike groups.

## Limitations

The Wrike integration does not support:

* OAuth. The app uses a permanent token.
* SCIM, including direct user creation, profile editing, and permanent deletion.
* Sharing spaces, folders, and projects, or managing access roles on those items.
* Buying seats or deleting a user to free a seat.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.