> ## Documentation Index
> Fetch the complete documentation index at: https://help.dsalta.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Hex

> Analytics notebooks — members & access

<Tabs>
  <Tab title="Overview">
    Connect Hex with a workspace token to sync workspace members and projects, and run access reviews. Read-only; the token is held by Nango, and DSALTA keeps only a connection reference.

    <Info>
      **Read-only access.** DSALTA only reads data from this integration. It never creates, modifies, or deletes anything in your environment, and every remediation step is performed by your team directly in the third-party product.
    </Info>

    <Info>
      **What you'll see.** The Access page lists the **users** of your Hex workspace with their name, email and workspace role. Users whose role Hex reports as a guest or anonymous role are left out. Hex reports no account status, join date or MFA state, so every user is shown as **Active** with MFA **Unknown**, and each row is stamped with the date of the sync.
    </Info>

    <Note>
      **A Team plan is required.** Hex's API is not available on the free Community plan, so there is nothing for DSALTA to read on that plan.
    </Note>

    <Note>
      DSALTA collects this integration's data when you connect it — you can refresh it at any time with **Sync from integrations** on the **Integrations** page. The compliance checks below re-run once a day at 02:00 America/New\_York.
    </Note>

    ## What DSALTA reads

    DSALTA reads the Hex workspace user roster — names, emails and roles — which appears on your **Access** page; and your Hex **projects**, which appear on your **Inventory** page with their type, whether they are archived, their all-time app views, their owner and when they were last edited. Notebook contents and data connections are never read.

    It calls these Hex endpoints, through Nango's proxy, on `app.hex.tech`:

    * `/api/v1/projects`
    * `/api/v1/users`

    Every request is a read. DSALTA has no code path that creates, modifies, or deletes anything in your Hex environment.

    ## Troubleshooting

    <AccordionGroup>
      <Accordion title="The connection is rejected">
        DSALTA checks the token as soon as Nango reports the connection, by reading your Hex projects. An expired or revoked token, or a workspace on the Community plan, is rejected there and the integration never reaches the **Connected** tab. Create a fresh workspace token and connect again.
      </Accordion>

      <Accordion title="The connection succeeds but the first sync fails">
        A token that can read projects but not **Users** passes the connect-time check, because that check reads projects. It fails at the first sync instead. Open **Manage → Status** on the Hex card: if it reads **Connection issues detected**, disconnect and connect again with a token that also has read access to Users.
      </Accordion>

      <Accordion title="The connection stopped working">
        Hex tokens can carry an expiry of 7 to 120 days. When the token expires the sync fails with an authentication error; create a new token from the **API keys** page, then disconnect and connect again. Note that disconnecting permanently deletes the data already collected from Hex.
      </Accordion>
    </AccordionGroup>

    <AccordionGroup>
      <Accordion title="How do I check whether the connection is healthy?">
        Open **Integrations** in the DSALTA sidebar, stay on the **Connected** tab, and click **Manage** on the integration's card. Open the **Status** tab: it shows either **Connected and working properly** or **Connection issues detected**.

        Use the **Status** tab, not **Overview** — Overview always reports **Connected** regardless of the real state.
      </Accordion>

      <Accordion title="A check shows Failed and nothing changed on my side">
        On an integration-powered check, **Failed** normally means DSALTA was blocked rather than that you are non-compliant. Open the test, go to **Source Data**, and read the result code: **403** is a missing permission, **428** is a setting DSALTA still needs, **500** is a failure on DSALTA's side.

        A real compliance gap shows **207** and leaves the test looking **Completed**. See [Understanding Test Results](/guides/compliance/test-results).
      </Accordion>

      <Accordion title="Data looks out of date">
        Compliance checks re-run once a day at 02:00 America/New\_York. To refresh sooner, open **Integrations → Connected** and click **Sync from integrations** at the top right — it refreshes every connected integration at once.
      </Accordion>

      <Accordion title="How do I repair a broken connection?">
        There is no Reconnect, Repair or Refresh Token button. The only repair available is to disconnect and connect again.

        <Warning>
          **Disconnecting is destructive and cannot be undone.** DSALTA removes the access records, inventory, vulnerabilities, code changes, incidents and device records collected from this integration, and deletes the test results tied to the connection. Export anything you still need as audit evidence first — see [Integration errors](/troubleshooting/integration-errors).
        </Warning>
      </Accordion>

      <Accordion title="Configure scope will not let me change anything">
        That is expected. **Configure scope** is read-only — it shows what DSALTA is permitted to read, and has no Save action. To change what DSALTA can see, change the permissions on the credential in the third-party product, then disconnect and connect again.
      </Accordion>
    </AccordionGroup>
  </Tab>

  <Tab title="How to connect">
    Connect Hex by entering your workspace token in a secure Nango window. The token is stored by Nango — DSALTA only keeps a connection reference.

    **Before you begin**

    * A Hex workspace on the **Team** plan, or an active Team trial. The free Community plan has no API access.
    * The **Admin** role in that workspace, which is required to create a workspace token.

    You will need:

    | Field               | Where to find it                             | Example                                           |
    | ------------------- | -------------------------------------------- | ------------------------------------------------- |
    | **Workspace token** | **API keys** in Hex settings → **New Token** | `hxtw_…` (a personal token, `hxtp_…`, also works) |

    <Steps>
      <Step title="Start in DSALTA">
        Open **Integrations** in the DSALTA sidebar, find **Hex**, and click **Connect** to open the connect panel. Leave it open — the steps below are listed there too.
      </Step>

      <Step title="Check your Hex plan">
        The Hex API requires the Team plan or an active Team trial. On the Community plan the token cannot be created, and a connection would have nothing to read.
      </Step>

      <Step title="Create a workspace token">
        In Hex, open the **API keys** page in settings (Hex documents it under **User settings → API keys**, in the Account section) and click **New Token** to create a **workspace token**. Only an Admin can create one. Give it the **Read projects** scope and read access to **Users**, and pick an expiry — 7 to 120 days, or **no expiry**. Copy the token: workspace tokens start with `hxtw_`.

        <Info>
          A workspace token mirrors the workspace's admin permissions within the scopes you pick, and any Admin can revoke it. A **personal** access token (`hxtp_`) created by an Admin also works, but it carries that person's full permissions and stops working if they leave — prefer the workspace token.
        </Info>
      </Step>

      <Step title="Connect Hex">
        Return to the connect panel and click **Connect**. A secure Nango window opens — paste the workspace token there. The token is stored by Nango; DSALTA keeps only a connection reference and never stores it directly.
      </Step>
    </Steps>

    <Check>
      Once Nango confirms the connection to DSALTA, DSALTA creates this integration's checks, runs them, and starts the first sync. The integration moves to the **Connected** tab, and **Manage → Status** reads **Connected and working properly** once the first sync has succeeded.
    </Check>

    <Warning>
      **If the connection is rejected.** An expired or revoked token, a token that cannot read projects, or a workspace on the Community plan. The Nango window itself does not test the token — DSALTA validates it when Nango reports the connection, by reading your projects. A token that can read projects but not **Users** connects successfully and then fails at the first sync.

      The on-screen message is generic — see [Connection error messages](/troubleshooting/connection-error-messages).
    </Warning>
  </Tab>

  <Tab title="Automated checks">
    Each check below re-runs once a day, at 02:00 America/New\_York, while this integration is connected. Click any check for step-by-step remediation guidance.

    | Check                                                                                                              | Severity | What it verifies                                                               |
    | ------------------------------------------------------------------------------------------------------------------ | -------- | ------------------------------------------------------------------------------ |
    | [User access to Critical System should be valid](/integrations/hex/user-access-to-critical-system-should-be-valid) | Info     | Checks that everyone with Hex access is an active employee on the People page. |
    | [Offboarded users should not have active access](/integrations/hex/offboarded-users-should-not-have-active-access) | High     | Checks that offboarded employees no longer have active Hex access.             |
  </Tab>

  <Tab title="Useful links">
    | Topic   | Link                                                                    |
    | ------- | ----------------------------------------------------------------------- |
    | Setup   | [Hex API overview](https://learn.hex.tech/docs/api/api-overview)        |
    | General | [Hex](https://hex.tech)                                                 |
    | DSALTA  | [Connection error messages](/troubleshooting/connection-error-messages) |
  </Tab>
</Tabs>
