setup

Zendesk

Purpose

Collects one Zendesk Support account's staff users (admins and agents) and its legacy API token metadata, including who created each token and when it was last used.

tip

Secret fields below accept either an AWS Secrets Manager ARN or a value pasted directly into SubImage's managed vault. See Secrets for details.

Required Fields

Field Secret? Description
zendesk_subdomain No Subdomain only, e.g. acme for https://acme.zendesk.com
zendesk_oauth_token Yes OAuth access token with the read scope: its AWS Secrets Manager ARN, or the vault value

Required Permissions

The token's user must be an administrator, or an agent whose role has Manage APIs and can view team members. On Enterprise plans you can use a custom agent role instead of a full administrator. Manage APIs can also manage credentials, so treat this token as privileged.

Restrict the OAuth token to the read scope. The sync only issues GET requests to the Users and API Tokens endpoints.

Setup Steps

  1. In Zendesk Admin Center, go to Apps and integrations > APIs > OAuth Clients and add a client named SubImage.
  2. Using a dedicated user with the permissions above, obtain an access token for that client with the read scope. Zendesk's OAuth setup guide walks through the grant.
  3. In SubImage, enter your subdomain in zendesk_subdomain and the access token in zendesk_oauth_token.
  4. Save the module and run a sync.

Notes

  • The sync is read-only.
  • SubImage does not refresh the OAuth token. If the token expires or is revoked, issue a new one and update the module configuration.
  • The inventory lists legacy API tokens, not OAuth tokens. Zendesk has scheduled the API Tokens endpoint for removal on April 30, 2027.
  • If API token access is disabled on the account, the sync records no API tokens and still syncs users.

Troubleshooting

  • Zendesk subdomain invalid: enter the subdomain only, not a URL or custom hostname.
  • 401 Unauthorized: the token expired, was revoked, or was issued for a different Zendesk account.
  • 403 Forbidden: the token lacks the read scope, or its user cannot view team members. If only the API Tokens endpoint is forbidden, the sync logs a warning, skips tokens, and keeps the previous token inventory.