> ## Documentation Index
> Fetch the complete documentation index at: https://help.dsalta.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Uptrace

> OpenTelemetry observability — members, MFA & access

<Tabs>
  <Tab title="Overview">
    Connect Uptrace with a user auth token to sync organization members with their two-factor status, projects, monitors, dashboards, and notification channels, and run access and MFA reviews. Read-only. Data feeds into your Access accounts and Inventory pages.

    <Info>
      **Read-only access.** DSALTA only reads data from this integration. It never creates, modifies, or deletes anything in your environment, and every remediation step is performed by your team directly in the third-party product.
    </Info>

    <Info>
      **What you'll see.** The Access page lists the members of every Uptrace **organization** the token can see, one row per email address, with their name (or their email address when Uptrace has no name for them), their email and their organization roles (for example **Owner**, **Admin**, **Member**, **Viewer**, **Billing Manager** or **Collaborator**, joined on one row when a person belongs to several organizations, or **Member** when none is reported). An address that still has a pending invitation in that organization is left out. Uptrace's roster has no status field, so every member is shown as **Active** and stamped with the date of the sync. Uptrace does report per-user MFA, so the **MFA** column shows **Yes** or **No**, and is blank (a dash) for a user whose record carries no value. A person in several organizations shows **No** as soon as any one of them reports two-factor authentication off.
    </Info>

    <Note>
      DSALTA collects this integration's data when you connect it — you can refresh it at any time with **Sync from integrations** on the **Integrations** page. The compliance checks below re-run once a day at 02:00 America/New\_York.
    </Note>

    ## What DSALTA reads

    DSALTA reads the Uptrace organization member roster — names, emails, roles and two-factor flags — together with each organization's pending invitations, so that invited addresses can be left out; the roster appears on your **Access** page. It also reads your Uptrace **projects** (with their organization, whether they are suspended and their sampling mode), and, for each project, its **monitors** (type, status, number of unresolved alerts, number of channels and whether they are paused), **dashboards** (whether they are pinned) and **notification channels** (name, type and state — never a channel's webhook URL or token), which appear on your **Inventory** page. Monitors, dashboards and channels appear once a project has them. Teams, alerts and the telemetry itself — spans, metrics and logs — are not read, and neither are members' last-login times.

    It calls these Uptrace endpoints on `api.uptrace.dev`:

    * `/internal/v1/orgs`
    * `/internal/v1/orgs/{org}/users`
    * `/internal/v1/orgs/{org}/invites`
    * `/internal/v1/orgs/{org}/projects`
    * `/internal/v1/monitors/{project}`
    * `/internal/v1/dashboards/{project}`
    * `/internal/v1/projects/{project}/notification-channels`

    Every request is a read. DSALTA has no code path that creates, modifies, or deletes anything in your Uptrace environment.

    ## Troubleshooting

    <AccordionGroup>
      <Accordion title="The connection is rejected">
        The token is not a **user auth token** from your Uptrace profile page: a project token (DSN) only sends telemetry and cannot read the organization, and a token created from an account that signs in through Google or Okta SSO does not work with the API. Otherwise the token can see no organization, or one of its organizations returns no members, which means the token cannot read that organization's roster. Create the token from an owner or admin account that signs in with email and password, then connect again.
      </Accordion>

      <Accordion title="The Access page shows fewer members than expected">
        The token inherits the role of the user who created it, and a member or viewer token may return an incomplete member list. Create the token from an organization owner or admin, then disconnect and connect again. Note that disconnecting permanently deletes the data already collected from Uptrace.
      </Accordion>

      <Accordion title="The sync fails with a message naming an /internal/v1/ path">
        Uptrace's organization and project endpoints live under its beta `/internal/v1/` prefix, and a path that Uptrace re-shapes answers 404. The error names the path so the change can be reported. Projects, monitors, dashboards and notification channels are read best-effort after the roster, so a failure on one of them only leaves that part of the Inventory page empty; only the organization list and the member roster can fail the sync.
      </Accordion>
    </AccordionGroup>

    <AccordionGroup>
      <Accordion title="How do I check whether the connection is healthy?">
        Open **Integrations** in the DSALTA sidebar, stay on the **Connected** tab, and click **Manage** on the integration's card. Open the **Status** tab: it shows either **Connected and working properly** or **Connection issues detected**.

        Use the **Status** tab, not **Overview** — Overview always reports **Connected** regardless of the real state.
      </Accordion>

      <Accordion title="A check shows Failed and nothing changed on my side">
        On an integration-powered check, **Failed** normally means DSALTA was blocked rather than that you are non-compliant. Open the test, go to **Source Data**, and read the result code: **403** is a missing permission, **428** is a setting DSALTA still needs, **500** is a failure on DSALTA's side.

        A real compliance gap shows **207** and leaves the test looking **Completed**. See [Understanding Test Results](/guides/compliance/test-results).
      </Accordion>

      <Accordion title="Data looks out of date">
        Compliance checks re-run once a day at 02:00 America/New\_York. To refresh sooner, open **Integrations → Connected** and click **Sync from integrations** at the top right — it refreshes every connected integration at once.
      </Accordion>

      <Accordion title="How do I repair a broken connection?">
        There is no Reconnect, Repair or Refresh Token button. The only repair available is to disconnect and connect again.

        <Warning>
          **Disconnecting is destructive and cannot be undone.** DSALTA removes the access records, inventory, vulnerabilities, code changes, incidents and device records collected from this integration, and deletes the test results tied to the connection. Export anything you still need as audit evidence first — see [Integration errors](/troubleshooting/integration-errors).
        </Warning>
      </Accordion>

      <Accordion title="Configure scope will not let me change anything">
        That is expected. **Configure scope** is read-only — it shows what DSALTA is permitted to read, and has no Save action. To change what DSALTA can see, change the permissions on the credential in the third-party product, then disconnect and connect again.
      </Accordion>
    </AccordionGroup>
  </Tab>

  <Tab title="How to connect">
    An Uptrace user auth token from an organization owner or admin. Organizations and projects are detected automatically. Read-only.

    **Before you begin**

    * An Uptrace organization owner or admin account that signs in with email and password — an account created through Google or Okta SSO cannot create a working token.

    You will need:

    | Field | Where to find it | Example |
    | - | - | - |
    | **User auth token** | Your user profile page → create an authentication token | `Uptrace user auth token` |

    <Steps>
      <Step title="Start in DSALTA">
        Open **Integrations** in the DSALTA sidebar, find **Uptrace**, and click **Connect** to open the connect panel.
      </Step>

      <Step title="Sign in as an organization owner or admin">
        Sign in at [app.uptrace.dev](https://app.uptrace.dev) with an email and password account that is an owner or admin of the organization.

        <Note>
          An account created through Google or Okta SSO cannot create a working token — Uptrace states that user auth tokens do not work with single sign-on. If your organization uses SSO, create a separate email and password account and grant it access directly. A member or viewer token may return an incomplete member list.
        </Note>
      </Step>

      <Step title="Create an authentication token">
        Open your user profile page and create an authentication token. It carries the same permissions as your user account.

        <Warning>
          **Do not use a project token (DSN).** A project token only sends telemetry and cannot read the organization's members, and DSALTA rejects it at connect time.
        </Warning>
      </Step>

      <Step title="Connect Uptrace">
        Return to the connect panel, paste the user auth token, and click **Connect**.
      </Step>
    </Steps>

    <Check>
      DSALTA validates the token when you click **Connect**, by listing the organizations it can see and then listing the members of every one of them. On success the integration moves to the **Connected** tab, and **Manage → Status** reads **Connected and working properly**. Checks begin reporting after the first sync.
    </Check>

    <Warning>
      **If the connection is rejected.** An invalid token, a project token instead of a user auth token, a token from an SSO-created account, a token that can see no organization, or an organization whose member list comes back empty.

      The on-screen message is generic — see [Connection error messages](/troubleshooting/connection-error-messages).
    </Warning>
  </Tab>

  <Tab title="Automated checks">
    Each check below re-runs once a day, at 02:00 America/New\_York, while this integration is connected. Click any check for step-by-step remediation guidance.

    | Check | Severity | What it verifies |
    | - | - | - |
    | [User access to Critical System should be valid](/integrations/uptrace/user-access-to-critical-system-should-be-valid) | Info | Checks that everyone with Uptrace access is an active employee on the People page. |
    | [Offboarded users should not have active access](/integrations/uptrace/offboarded-users-should-not-have-active-access) | High | Checks that offboarded employees no longer have active Uptrace access. |
    | [MFA should be enabled for all users](/integrations/uptrace/mfa-enabled-for-all-users) | High | Checks that every Uptrace organization member has two-factor authentication enabled. |
  </Tab>

  <Tab title="Useful links">
    | Topic | Link |
    | - | - |
    | Setup | [Uptrace API reference](https://developers.uptrace.dev/) |
    | General | [Uptrace console](https://app.uptrace.dev) |
    | DSALTA | [Connection error messages](/troubleshooting/connection-error-messages) |
  </Tab>
</Tabs>
