> ## Documentation Index
> Fetch the complete documentation index at: https://help.dsalta.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Twingate

> Zero-trust network access — users & access

<Tabs>
  <Tab title="Overview">
    Connect Twingate with your network name and an Admin Console API token to sync users and protected resources, and run access reviews. Read-only.

    <Info>
      **Read-only access.** DSALTA only reads data from this integration. It never creates, modifies, or deletes anything in your environment, and every remediation step is performed by your team directly in the third-party product.
    </Info>

    <Info>
      **What you'll see.** The Access page lists every **user** of your Twingate network with their name, email, Admin Console role and the date they were created, and respects Twingate's own user state — a user Twingate reports as anything other than active (for example **Pending** or **Disabled**) is shown as **Inactive**. Twingate reports no MFA state through this query, so the **MFA** column shows **Unknown**. Devices are not synced.
    </Info>

    <Note>
      DSALTA collects this integration's data when you connect it — you can refresh it at any time with **Sync from integrations** on the **Integrations** page. The compliance checks below re-run once a day at 02:00 America/New\_York.
    </Note>

    ## What DSALTA reads

    DSALTA reads the Twingate user roster — names, emails, roles, state and creation dates — which appears on your **Access** page; and your Twingate **Resources**, which appear on your **Inventory** page with their address and whether they are active.

    It sends these GraphQL queries to `https://<network>.twingate.com/api/graphql/`:

    * `users { … }`
    * `resources { … }`

    Every request is a read. DSALTA has no code path that creates, modifies, or deletes anything in your Twingate environment.

    ## Troubleshooting

    <AccordionGroup>
      <Accordion title="The connection is rejected">
        The **Network name** must be the subdomain of your Admin Console URL — for `acme.twingate.com` enter `acme` — and the token must come from **Settings → API** in that network's Admin Console. A token from another network, or a deleted token, is rejected the same way.
      </Accordion>

      <Accordion title="Users synced from an identity provider">
        When Twingate is connected to an identity provider, users are synchronised from it and cannot be edited in the Admin Console. Remediation for those users happens in the identity provider; the Access page still shows them with the state Twingate reports.
      </Accordion>
    </AccordionGroup>

    <AccordionGroup>
      <Accordion title="How do I check whether the connection is healthy?">
        Open **Integrations** in the DSALTA sidebar, stay on the **Connected** tab, and click **Manage** on the integration's card. Open the **Status** tab: it shows either **Connected and working properly** or **Connection issues detected**.

        Use the **Status** tab, not **Overview** — Overview always reports **Connected** regardless of the real state.
      </Accordion>

      <Accordion title="A check shows Failed and nothing changed on my side">
        On an integration-powered check, **Failed** normally means DSALTA was blocked rather than that you are non-compliant. Open the test, go to **Source Data**, and read the result code: **403** is a missing permission, **428** is a setting DSALTA still needs, **500** is a failure on DSALTA's side.

        A real compliance gap shows **207** and leaves the test looking **Completed**. See [Understanding Test Results](/guides/compliance/test-results).
      </Accordion>

      <Accordion title="Data looks out of date">
        Compliance checks re-run once a day at 02:00 America/New\_York. To refresh sooner, open **Integrations → Connected** and click **Sync from integrations** at the top right — it refreshes every connected integration at once.
      </Accordion>

      <Accordion title="How do I repair a broken connection?">
        There is no Reconnect, Repair or Refresh Token button. The only repair available is to disconnect and connect again.

        <Warning>
          **Disconnecting is destructive and cannot be undone.** DSALTA removes the access records, inventory, vulnerabilities, code changes, incidents and device records collected from this integration, and deletes the test results tied to the connection. Export anything you still need as audit evidence first — see [Integration errors](/troubleshooting/integration-errors).
        </Warning>
      </Accordion>

      <Accordion title="Configure scope will not let me change anything">
        That is expected. **Configure scope** is read-only — it shows what DSALTA is permitted to read, and has no Save action. To change what DSALTA can see, change the permissions on the credential in the third-party product, then disconnect and connect again.
      </Accordion>
    </AccordionGroup>
  </Tab>

  <Tab title="How to connect">
    Your Twingate network name plus an API token from the admin console. Read-only.

    **Before you begin**

    * A Twingate network and **Admin** access to its Admin Console — API tokens are generated under **Settings → API**.
    * Your network name: the subdomain of the Admin Console URL, `<network>.twingate.com`.

    You will need:

    | Field            | Where to find it                                    | Example                      |
    | ---------------- | --------------------------------------------------- | ---------------------------- |
    | **Network name** | The Admin Console URL                               | `acme` for acme.twingate.com |
    | **API Token**    | Admin Console → **Settings → API → Generate Token** | Shown at creation            |

    <Steps>
      <Step title="Start in DSALTA">
        Open **Integrations** in the DSALTA sidebar, find **Twingate**, and click **Connect** to open the connect panel.
      </Step>

      <Step title="Generate an API token">
        In the Twingate Admin Console, open **Settings → API** and click **Generate Token**. Give it a name and choose the **Read only** permission level, then copy the token.

        <Tip>
          Twingate lets you pick **Read only**, **Read & Write** or **Read, Write & Provision**, and recommends the lowest level a token needs. DSALTA only reads, so **Read only** is sufficient and keeps the token harmless if it leaks.
        </Tip>
      </Step>

      <Step title="Find your network name">
        Look at the Admin Console address bar: the URL is `https://<network>.twingate.com`. Copy the `<network>` part only — DSALTA accepts the full hostname too and trims it.
      </Step>

      <Step title="Connect Twingate">
        Return to the connect panel, paste the network name and the API token, and click **Connect**.
      </Step>
    </Steps>

    <Check>
      DSALTA validates the pair when you click **Connect**, by listing the network's users. On success the integration moves to the **Connected** tab, and **Manage → Status** reads **Connected and working properly**. Checks begin reporting after the first sync.
    </Check>

    <Warning>
      **If the connection is rejected.** Wrong network name, a token from a different network, or a deleted token.

      The on-screen message is generic — see [Connection error messages](/troubleshooting/connection-error-messages).
    </Warning>
  </Tab>

  <Tab title="Automated checks">
    Each check below re-runs once a day, at 02:00 America/New\_York, while this integration is connected. Click any check for step-by-step remediation guidance.

    | Check                                                                                                                   | Severity | What it verifies                                                                    |
    | ----------------------------------------------------------------------------------------------------------------------- | -------- | ----------------------------------------------------------------------------------- |
    | [User access to Critical System should be valid](/integrations/twingate/user-access-to-critical-system-should-be-valid) | Info     | Checks that everyone with Twingate access is an active employee on the People page. |
    | [Offboarded users should not have active access](/integrations/twingate/offboarded-users-should-not-have-active-access) | High     | Checks that offboarded employees no longer have active Twingate access.             |
  </Tab>

  <Tab title="Useful links">
    | Topic       | Link                                                                    |
    | ----------- | ----------------------------------------------------------------------- |
    | Setup       | [Twingate API overview](https://www.twingate.com/docs/api-overview)     |
    | Remediation | [Users in the Admin Console](https://www.twingate.com/docs/users)       |
    | General     | [Twingate](https://www.twingate.com)                                    |
    | DSALTA      | [Connection error messages](/troubleshooting/connection-error-messages) |
  </Tab>
</Tabs>
