Skip to main content

Capabilities

The Retool connector syncs the following resources: Notes:
  • Sync and group/page provisioning use a direct connection to the Retool Postgres database (the connection-string setting). The account lifecycle (Create and the enable/disable actions) additionally uses the Retool REST API and requires the retool-api-base-url and retool-api-token settings — sync-only deployments work without them.
  • Retool’s API does not expose a hard delete, so the connector does not offer account deletion. Deprovisioning is the disable_user action, which deactivates the account (blocks sign-in) while retaining the user and its group memberships; the enable_user action reactivates it.

Gather Retool credentials

Configuring the connector requires you to pass in credentials generated in Retool. Gather these credentials before you move on.
A user with the ability to create a new user in Retool must perform this task.

Create a Retool user and compose the connection string

1
Connect to the Retool database and create a new user. The connector will use this user to connect to the PostGreSQL database. Make sure to create and save a secure password:CREATE USER baton WITH PASSWORD 'secure-password';
2
Grant the new user the following privileges, which are required by the connector for inspecting Retool privileges:
3
Compose and save the Retool connection string you’ll use when setting up the connector. This string will be in this form:"user=baton password=secure-password host=localhost port=5432 dbname=hammerhead_production"

(Optional) Create a Retool API token for account provisioning

Account creation and the enable/disable user actions use the Retool REST API. Skip this section if you only need sync and group/page provisioning.
A Retool admin must perform this task, and your Retool plan must include REST API access.
1
In Retool, go to Settings > API and create a new API token.
2
Grant the token the users:read and users:write scopes (both are required to create, look up, and enable/disable users).
3
Copy and save the token, and note your Retool base URL (for example https://<your-org>.retool.com). You’ll provide both when configuring the connector.
Done. Next, move on to the connector configuration instructions.

Configure the Retool connector

To complete this task, you’ll need:
  • The Connector Administrator or Super Administrator role in C1
  • Access to the set of Retool credentials generated by following the instructions above
Follow these instructions to use a built-in, no-code connector hosted by C1.Cloud-hosted connector not currently available.
You can download the latest baton-retool release binaries from the ConductorOne download center.