jump to content

Segment

Connect Segment as an access review source using a Public API token and workspace region so the platform can list your workspace's members and roles.

View as Markdown

the platform reads your Segment workspace’s members through the Segment Public API so you can review who has access.

  • the platform organization administrator access
  • A Segment workspace on the Team or Business tier
  • The Workspace Owner role in Segment (only a Workspace Owner can create a Public API token)
  • The workspace’s Region, which the Connect dialog asks for alongside the token. Segment calls it the data processing region and sets it when the workspace is created; you cannot change it afterwards. New workspaces default to US, and EU data residency is a Business tier feature that a Segment account executive enables, so a Team workspace is always US
the platform fieldSegment fieldNotes
NamenameFalls back to the email address
Emailemail
Rolepermissions[].roleNameDeduplicated and sorted. A pending invitation carries no role
Adminpermissions[].roleNameFlagged as an administrator when one of the roles is Workspace Owner
StatusinvitesPending invitations are listed as inactive. The users endpoint carries no status for members who have accepted, so theirs is left unknown
MFANot supported
Last loginNot supported
External IDidStable identifier used to track the account across reviews. A pending invitation is keyed by its email address
Created atNot supported

Members who have been invited but have not yet accepted appear alongside accepted members, marked inactive.

  1. In the Segment app, signed in as a Workspace Owner, go to Settings > Workspace settings > Access Management > Tokens.
  2. Click + Create Token, choose a Public API token, write a description (e.g. Probo Access Review), and assign it Workspace Owner access.
  3. Click Create, copy the token somewhere secure, and click Done.
  1. In the platform, go to Access Reviews > Sources > Add Source.
  2. Find Segment, click API Key, paste the token, choose your Region, and click Connect.

the platform names the source after your workspace and pulls its members into your campaigns.

  • Token creation is unavailable. The Public API is a Team and Business tier feature, and only a Workspace Owner can create a token. On a Free workspace, upgrade the plan first.
  • Token rejected. Confirm it is a Public API token rather than a Config API token, that a Workspace Owner created it, and that the Region matches the workspace. Each region has its own host, and a token authenticates against its own workspace’s host.
  • Region unknown. Segment does not document a settings screen that shows an existing workspace’s region, but the URL you sign in with is a practical indicator: app.segment.com is the US app and eu1.app.segment.com the EU one.
  • No members appear. A token with only Workspace Member access may not be able to read the workspace’s users. Create one with Workspace Owner access instead.

Ultima actualizare: