> ## Documentation Index
> Fetch the complete documentation index at: https://conductorone-paul-querna-mcp-sources-docs.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Set up LaunchDarkly connector

> C1 provides identity governance for LaunchDarkly. Integrate your LaunchDarkly instance with C1 for unified visibility and governance over user access.

## Capabilities

| Resource  | Sync                                                          | Provision                                                     |
| :-------- | :------------------------------------------------------------ | :------------------------------------------------------------ |
| Member    | <Icon icon="square-check" iconType="solid" color="#c937ae" /> | <Icon icon="square-check" iconType="solid" color="#c937ae" /> |
| Base role | <Icon icon="square-check" iconType="solid" color="#c937ae" /> | <Icon icon="square-check" iconType="solid" color="#c937ae" /> |
| Role      | <Icon icon="square-check" iconType="solid" color="#c937ae" /> | <Icon icon="square-check" iconType="solid" color="#c937ae" /> |
| Team      | <Icon icon="square-check" iconType="solid" color="#c937ae" /> | <Icon icon="square-check" iconType="solid" color="#c937ae" /> |

**Additional functionality:**

* Create and delete members.
* Assign and unassign a base role (`reader`, `writer`, `admin`, `no_access`) on members. Unassign sets the member to `no_access`. Owner-role transfer is not exposed; it requires LaunchDarkly's UI-only reauthentication flow.
* Grant and revoke custom-role assignments on members.
* Add and remove members from teams.

LaunchDarkly has no separate disabled or deactivated member state, so the connector maps a disable request to deletion. Provisioning through this connector isn't supported on LaunchDarkly accounts that have SCIM provisioning enabled; manage LaunchDarkly members through your identity provider instead.

## Gather LaunchDarkly configuration information

Configuring the connector requires you to pass in information from LaunchDarkly. Gather these configuration details before you move on.

Here's the information you'll need:

* API Access Token
* Base URL (optional) — only needed for non-US tenants. Use `https://app.eu.launchdarkly.com` for EU tenants or `https://app.launchdarkly.us` for Federal tenants. Leave unset for US commercial tenants (defaults to `https://app.launchdarkly.com`). The value must be exactly one of those three URLs — LaunchDarkly's regions are subdomains, not paths, so a form like `https://app.launchdarkly.com/eu` is rejected at startup rather than treated as a valid EU host.

See the LaunchDarkly docs for information on how to acquire credentials: [View the documentation](https://launchdarkly.com/docs/home/account/api-create#create-access-tokens)

This connector requires an access token with one of the following permission sets:

* **Reader** base role (sufficient for read-only sync). Note that syncing teams and custom roles additionally requires an Enterprise plan — see the warning below; no base role substitutes for it.
* **Admin** base role, or a custom role granting `createMember`, `deleteMember`, `updateRole`, and `updateCustomRole` on `member/*` plus `updateTeamMembers` on `team/*`, is required to also create and delete members, assign base roles and custom roles, and change team membership.

<Warning>
  This connector requires a LaunchDarkly **Enterprise** plan. A token's base role cannot substitute for the plan.

  * **Sync.** Teams and custom roles are Enterprise-only features, so on the Developer and Foundation plans `GET /api/v2/teams` and `GET /api/v2/roles` return `403 Forbidden` regardless of the access token's role, and the sync fails.
  * **Base-role deprovisioning.** Unassigning a base role is performed by assigning the **No access** role, because LaunchDarkly members always hold exactly one base role and there is no removal operation. On a plan that does not offer No access, every base-role revoke fails with `400 {"message":"Invalid role: no_access"}`.
</Warning>

## Configure the LaunchDarkly connector

<Warning>
  To complete this task, you'll need:

  * The **Connector Administrator** or **Super Administrator** role in C1
  * Access to the set of LaunchDarkly configuration information gathered by following the instructions above
</Warning>

<Tabs>
  <Tab title="Cloud-hosted">
    **Follow these instructions to use a built-in, no-code connector hosted by C1.**

    <Steps>
      <Step>
        In C1, navigate to **Apps** > **Connectors** and click **Add connector**.
      </Step>

      <Step>
        Search for **LaunchDarkly** and click **Add**.
      </Step>

      <Step>
        Choose where to add the connector: **Create a new app**, or **Add to an existing app** (then select the app).

        If you're creating a new app, choose whether to link it to an application discovered from your identity provider: select **Yes** and pick the IdP application, or **No** to continue with just the connector.
      </Step>

      <Step>
        Set the connector's **Name** and, optionally, a **Description**.
      </Step>

      <Step>
        Click the pencil icon next to **Owners** to choose who can configure and manage this connector.
      </Step>

      <Step>
        Click **Add**. The connector is created and its configuration page opens.
      </Step>

      <Step>
        Find the **Settings** area of the page and click **Edit**.
      </Step>

      <Step>
        Enter the configuration information from the previous section.
      </Step>

      <Step>
        Click **Save**.
      </Step>

      <Step>
        The connector's label changes to **Syncing**, followed by **Connected**. You can view the logs to ensure that information is syncing.
      </Step>
    </Steps>

    **Done.** Your LaunchDarkly connector is now pulling access data into C1.
  </Tab>

  <Tab title="Self-hosted">
    **Follow these instructions to use the LaunchDarkly connector, hosted and run in your own environment.**

    When running in service mode on Kubernetes, a self-hosted connector maintains an ongoing connection with C1, automatically syncing and uploading data at regular intervals. This data is immediately available in the C1 UI for access reviews and access requests.

    ### Resources

    [Contact C1's support team](mailto:support@conductorone.com) to download the latest version of the connector.

    ### Step 1: Set up a new LaunchDarkly connector

    <Steps>
      <Step>
        In C1, navigate to **Apps** > **Connectors** and click **Add connector**.
      </Step>

      <Step>
        Search for **Baton** and click **Add**.
      </Step>

      <Step>
        Choose where to add the connector: **Create a new app**, or **Add to an existing app** (then select the app).

        If you're creating a new app, choose whether to link it to an application discovered from your identity provider: select **Yes** and pick the IdP application, or **No** to continue with just the connector.
      </Step>

      <Step>
        Set the connector's **Name** and, optionally, a **Description**.
      </Step>

      <Step>
        Click the pencil icon next to **Owners** to choose who can configure and manage this connector.
      </Step>

      <Step>
        Click **Add**. The connector is created and its configuration page opens.
      </Step>

      <Step>
        In the **Settings** area of the page, click **Edit**.
      </Step>

      <Step>
        Click **Rotate** to generate a new Client ID and Secret.

        Carefully copy and save these credentials. We'll use them in Step 2.
      </Step>
    </Steps>

    ### Step 2: Create Kubernetes configuration files

    Create two Kubernetes manifest files for your LaunchDarkly connector deployment:

    #### Secrets configuration

    ```yaml expandable theme={null}
    # baton-launchdarkly-secrets.yaml
    apiVersion: v1
    kind: Secret
    metadata:
      name: baton-launchdarkly-secrets
    type: Opaque
    stringData:
      # C1 credentials
      BATON_CLIENT_ID: <C1 client ID>
      BATON_CLIENT_SECRET: <C1 client secret>

      # LaunchDarkly config
      BATON_LAUNCHDARKLY_API_TOKEN: <LaunchDarkly API Access Token>
      # Optional: set for EU or Federal tenants; omit for US commercial
      BATON_LAUNCHDARKLY_BASE_URL: <EU or Federal base URL>

    ```

    See the connector's README or run `--help` to see all available configuration flags and environment variables.

    #### Deployment configuration

    ```yaml expandable theme={null}
    # baton-launchdarkly.yaml
    apiVersion: apps/v1
    kind: Deployment
    metadata:
      name: baton-launchdarkly
      labels:
        app: baton-launchdarkly
    spec:
      selector:
        matchLabels:
          app: baton-launchdarkly
      template:
        metadata:
          labels:
            app: baton-launchdarkly
            baton: true
            baton-app: launchdarkly
        spec:
          containers:
          - name: baton-launchdarkly
            image: public.ecr.aws/conductorone/baton-launchdarkly:latest
            imagePullPolicy: IfNotPresent
            env:
            - name: BATON_HOST_ID
              value: baton-launchdarkly
            envFrom:
            - secretRef:
                name: baton-launchdarkly-secrets
    ```

    ### Step 3: Deploy the connector

    <Steps>
      <Step>
        Create a namespace in which to run C1 connectors (if desired), then apply the secret config and deployment config files.
      </Step>

      <Step>
        Check that the connector data uploaded correctly. In C1, click **Apps**. On the **Managed apps** tab, locate and click the name of the application you added the launchdarkly connector to. launchdarkly data should be found on the **Entitlements** and **Accounts** tabs.
      </Step>
    </Steps>

    **Done.** Your LaunchDarkly connector is now pulling access data into C1.
  </Tab>
</Tabs>
