> ## Documentation Index
> Fetch the complete documentation index at: https://help.dsalta.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Labelbox

> Data labeling platform — members & access

<Tabs>
  <Tab title="Overview">
    Connect Labelbox with an Admin API key to sync workspace members, projects, and datasets, and run access reviews. Read-only. Data feeds into your Access accounts and Inventory pages.

    <Info>
      **Read-only access.** DSALTA only reads data from this integration. It never creates, modifies, or deletes anything in your environment, and every remediation step is performed by your team directly in the third-party product.
    </Info>

    <Info>
      **What you'll see.** The Access page lists the members of the Labelbox **workspace** the key belongs to, with their display name (falling back to their handle, then their email address), their email, their workspace role exactly as Labelbox names it (for example **Admin**, **Team Manager** or **Labeler**; **Project-based** for a member whose workspace role is Labelbox's "None", and **Member** when the role could not be read) and the date their account was created. External labeling-service users, members whose role starts with **Workforce**, and members Labelbox has removed are left out; pending invitations never appear, because Labelbox keeps them apart from members. Labelbox reports no per-member account status, so every member is shown as **Active**. Labelbox reports no per-user MFA state — its multi-factor authentication is a single workspace-wide setting — so the **MFA** column is blank (shown as a dash).
    </Info>

    <Note>
      DSALTA collects this integration's data when you connect it — you can refresh it at any time with **Sync from integrations** on the **Integrations** page. The compliance checks below re-run once a day at 02:00 America/New\_York.
    </Note>

    ## What DSALTA reads

    DSALTA reads the Labelbox workspace member roster — display names, handles, emails, workspace roles and creation dates — which appears on your **Access** page; and your Labelbox **projects** and **datasets**, which appear on your **Inventory** page with their creation and last-update dates. Workspace roles are looked up member by member, best-effort: if the lookup fails, every member is shown as **Member** without failing the sync. Projects and datasets are read best-effort too, and a fresh workspace has none — they appear once you create one. Members' last-login times are not shown, and seat usage, API keys, models and ontologies are not read.

    Labelbox exposes a single GraphQL endpoint, `POST https://api.labelbox.com/graphql`, and DSALTA sends these queries to it:

    * `user { … } organization { … }` — the key's own user and workspace, used to validate
    * `organization { users { … } }` — the member roster
    * `user(where: {id}) { orgRole { … } }` — each member's workspace role
    * `projects(where: {deleted: false}) { … }`
    * `datasets(where: {deleted: false}) { … }`

    Every request is a read. DSALTA has no code path that creates, modifies, or deletes anything in your Labelbox environment.

    ## Troubleshooting

    <AccordionGroup>
      <Accordion title="The connection is rejected">
        Labelbox did not accept the key, or the key was not created with the **Admin** role. Only Admin can both use the API and view workspace members; a key created as Labeler, Reviewer, Data Admin or Read-only Admin cannot list the roster, and DSALTA rejects a key that cannot. Create a new key with the Admin role and connect again.
      </Accordion>

      <Accordion title="The connection stopped working">
        A Labelbox API key is valid for at most 6 months — there is no non-expiring option — and it is disabled together with its owner's account. When the key lapses or its owner is disabled, every sync fails until you create a new key and reconnect. Create the new key from an Admin account that will stay, then disconnect and connect again. Note that disconnecting permanently deletes the data already collected from Labelbox.
      </Accordion>

      <Accordion title="Inventory is empty while Access works">
        A fresh Labelbox workspace has no projects and no datasets, so Inventory stays empty until you create one. Projects and datasets are also read best-effort after the roster: a failure on either query leaves that part of the page empty, without failing the sync, until the next successful sync. Click **Sync from integrations** on the **Integrations** page to retry.
      </Accordion>
    </AccordionGroup>

    <AccordionGroup>
      <Accordion title="How do I check whether the connection is healthy?">
        Open **Integrations** in the DSALTA sidebar, stay on the **Connected** tab, and click **Manage** on the integration's card. Open the **Status** tab: it shows either **Connected and working properly** or **Connection issues detected**.

        Use the **Status** tab, not **Overview** — Overview always reports **Connected** regardless of the real state.
      </Accordion>

      <Accordion title="A check shows Failed and nothing changed on my side">
        On an integration-powered check, **Failed** normally means DSALTA was blocked rather than that you are non-compliant. Open the test, go to **Source Data**, and read the result code: **403** is a missing permission, **428** is a setting DSALTA still needs, **500** is a failure on DSALTA's side.

        A real compliance gap shows **207** and leaves the test looking **Completed**. See [Understanding Test Results](/guides/compliance/test-results).
      </Accordion>

      <Accordion title="Data looks out of date">
        Compliance checks re-run once a day at 02:00 America/New\_York. To refresh sooner, open **Integrations → Connected** and click **Sync from integrations** at the top right — it refreshes every connected integration at once.
      </Accordion>

      <Accordion title="How do I repair a broken connection?">
        There is no Reconnect, Repair or Refresh Token button. The only repair available is to disconnect and connect again.

        <Warning>
          **Disconnecting is destructive and cannot be undone.** DSALTA removes the access records, inventory, vulnerabilities, code changes, incidents and device records collected from this integration, and deletes the test results tied to the connection. Export anything you still need as audit evidence first — see [Integration errors](/troubleshooting/integration-errors).
        </Warning>
      </Accordion>

      <Accordion title="Configure scope will not let me change anything">
        That is expected. **Configure scope** is read-only — it shows what DSALTA is permitted to read, and has no Save action. To change what DSALTA can see, change the permissions on the credential in the third-party product, then disconnect and connect again.
      </Accordion>
    </AccordionGroup>
  </Tab>

  <Tab title="How to connect">
    A Labelbox API key created with the Admin role. The workspace is detected automatically. Read-only.

    **Before you begin**

    * A Labelbox workspace.
    * A durable **Admin** account to own the key — keys are disabled together with their owner's account.

    You will need:

    | Field | Where to find it | Example |
    | - | - | - |
    | **API key** | Labelbox home page → **Create API key**, role **Admin** | Shown once |

    <Steps>
      <Step title="Start in DSALTA">
        Open **Integrations** in the DSALTA sidebar, find **Labelbox**, and click **Connect** to open the connect panel.
      </Step>

      <Step title="Sign in with a durable Admin account">
        Sign in at [app.labelbox.com](https://app.labelbox.com/home) with an **Admin** account that will not be offboarded: API keys are disabled together with their owner's account.
      </Step>

      <Step title="Create an Admin API key">
        On the home page click **Create API key**. Enter a name, set the validity to the maximum (6 months is the hard cap, there is no non-expiring option, so note the renewal date), and choose the role **Admin**.

        <Warning>
          **The role you pick is the whole integration.** Only Admin can both use the API and view workspace members. A key created as Labeler, Reviewer, Data Admin or Read-only Admin connects to Labelbox and then fails to list members, so DSALTA rejects it.
        </Warning>
      </Step>

      <Step title="Copy the key and connect">
        Click **Create**, copy the key from the confirmation prompt — it is shown once — and click **Done**. Return to the connect panel, paste the key, and click **Connect**.
      </Step>
    </Steps>

    <Check>
      DSALTA validates the key when you click **Connect**, by asking Labelbox for the key's own user and workspace and then listing the workspace's members. On success the integration moves to the **Connected** tab, and **Manage → Status** reads **Connected and working properly**. Checks begin reporting after the first sync.
    </Check>

    <Warning>
      **If the connection is rejected.** A key Labelbox does not accept — invalid, expired, or disabled with its owner's account — or a key that was not created with the Admin role.

      The on-screen message is generic — see [Connection error messages](/troubleshooting/connection-error-messages).
    </Warning>
  </Tab>

  <Tab title="Automated checks">
    Each check below re-runs once a day, at 02:00 America/New\_York, while this integration is connected. Click any check for step-by-step remediation guidance.

    | Check | Severity | What it verifies |
    | - | - | - |
    | [User access to Critical System should be valid](/integrations/labelbox/user-access-to-critical-system-should-be-valid) | Info | Checks that everyone with Labelbox access is an active employee on the People page. |
    | [Offboarded users should not have active access](/integrations/labelbox/offboarded-users-should-not-have-active-access) | High | Checks that offboarded employees no longer have active Labelbox access. |
  </Tab>

  <Tab title="Useful links">
    | Topic | Link |
    | - | - |
    | Setup | [Create a Labelbox API key](https://docs.labelbox.com/reference/create-api-key) |
    | Remediation | [Manage members and groups](https://docs.labelbox.com/docs/manage-members-and-groups) · [Roles and permissions](https://docs.labelbox.com/docs/roles-and-permissions) |
    | General | [Labelbox](https://app.labelbox.com/home) |
    | DSALTA | [Connection error messages](/troubleshooting/connection-error-messages) |
  </Tab>
</Tabs>
