> For the complete documentation index, see [llms.txt](https://www.cakewalk.security/docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://www.cakewalk.security/docs/human-access/connections-and-integrations/integration-guides/pagerduty.md).

# PagerDuty

Set up PagerDuty Auto Provisioning with a REST API key and your account's service region, plus Access Sync for users, roles and teams.

### :sparkles: Auto Provisioning

| **Authentication method** | API key. See details [here](#how-can-i-create-an-api-key).                                                      |
| ------------------------- | --------------------------------------------------------------------------------------------------------------- |
| **Required permissions**  | `Admin` or `Account Owner`                                                                                      |
| **Required metadata**     | `Service Region`. Pick `EU` if your PagerDuty web address is `<company>.eu.pagerduty.com`, otherwise pick `USA` |
| **MFA**                   | Not applicable. The API key authenticates, not a user account                                                   |

Agent Cake creates the user in your PagerDuty account at the permission level you mapped, and deletes the user when access is revoked. PagerDuty emails the new user an invitation to accept, choose a password and set up their profile.

Available permission levels: `Admin`, `User`, `Limited User`, `Stakeholder`, `Observer`, `Restricted Access` and `Limited Stakeholder`.

{% hint style="info" %}
Which of these your account offers depends on your PagerDuty plan. `Observer`, `Restricted Access` and `Limited Stakeholder` exist only on accounts with Advanced Permissions enabled. Map only to roles your account actually has.
{% endhint %}

PagerDuty refuses to delete a user who is still on call, now or in the future, on a schedule or an escalation policy, or who has an open incident assigned. Move those assignments first, otherwise deprovisioning fails.

If your PagerDuty account restricts email domains, the new user's domain has to be on the `Email Domain Allow List` in PagerDuty account settings. Provisioning fails with a clear error when it is not.

<details>

<summary><strong>How can I create an API key?</strong></summary>

1. Sign in to PagerDuty as an `Admin` or `Account Owner`.

![](https://colony-recorder.s3.us-west-1.amazonaws.com/files/2026-08-24/54cf6898-eab2-4d67-8eb3-69f401fe3376/action-a25124664d58415a8358231247bb97f5_57f74764b2f641498d50d191e6f670e6_text_export.jpeg)

2. Click `Integrations`.

![](https://colony-recorder.s3.us-west-1.amazonaws.com/files/2026-08-24/ef359b9e-5f48-4540-bf53-9fb1de93ed71/action-cd90dc3a6f2a4ec486335445bbf9c48b_ee4d80d5f1fa4cabb57e5ecb797c9de2_text_export.jpeg)

3. Under `Developer Tools`, click `API Access Keys`.

![](https://colony-recorder.s3.us-west-1.amazonaws.com/files/2026-08-24/a7a63b79-19b7-40b2-b766-2effd2b8b93e/action-539891ce816a494db49b0181367df680_22ad9c3d8a434ae3a0dde851246bdf3b_text_export.jpeg)

4. Click `Create New API Key`.

![](https://colony-recorder.s3.us-west-1.amazonaws.com/files/2026-08-24/223c8a59-859e-4cc3-af21-8d8af1c041c7/action-6027dba1b846446095499ff18d6769ba_853380dc6e604cfcb2bcc312d58a6a7b_text_export.jpeg)

5. Enter a recognizable name in the `Description` field, for example `Agent Cake`. Leave `Read-only API Key` unchecked. A read only key can only read data, so it cannot create or delete users.

![](https://colony-recorder.s3.us-west-1.amazonaws.com/files/2026-08-24/7a322c29-a974-4992-be7a-7bb6c9e1f96d/action-0c0b007855b54632a3803a8a8f62f54f_840b1848f98f471686ebf32f9af8480f_text_export.jpeg)

6. Click `Create Key`.

![](https://colony-recorder.s3.us-west-1.amazonaws.com/files/2026-08-24/4fc63e42-84cd-436a-9f8f-e04297f8fb6e/action-4f1f69b00f404c6f8e568a03daf28381_ce7226d550904be8978e26fbb523ad1d_text_export.jpeg)

7. Copy the key and paste it into the `API Key` field in Cakewalk.

![](https://colony-recorder.s3.us-west-1.amazonaws.com/files/2026-08-24/0f37ff38-c6e2-4b81-844b-a5e6764a92a8/user_cropped_screenshot_4ff7f76c64b14f52949b9a1e7d1bd461_text_export.jpeg)

8. Click `Close`.

![](https://colony-recorder.s3.us-west-1.amazonaws.com/files/2026-08-24/d3c8a0b7-095e-49f6-bc93-a98db164fccc/user_cropped_screenshot_559d094795c04a3d8d5f970c9788d1a7_text_export.jpeg)

Copy the key before you close the dialog. PagerDuty shows it in full once and cannot display it again. If you lose it, delete the key and create a new one.

</details>

### :arrows\_counterclockwise: Access Sync

Access Sync for PagerDuty allows you to automatically synchronize user data with Cakewalk, including roles and team memberships.

| **Authentication method**  | OAuth. Connect and approve, no API key needed                  |
| -------------------------- | -------------------------------------------------------------- |
| **Synced user attributes** | Email, Name, Role and Teams                                    |
| **Non-human identities**   | Supported. Service integrations and webhook subscriptions      |
| **Required permissions**   | A PagerDuty `Admin` or `Account Owner` approves the connection |

### PagerDuty + Cakewalk Integration Benefits

* See every PagerDuty user with their role and team memberships in one unified directory, next to the rest of the company's apps.
* Include PagerDuty in access review campaigns and export audit evidence for SOC 2 and ISO 27001 audits.
* Discover non-human identities in PagerDuty: service integrations and webhook subscriptions appear alongside human accounts.

### How It Works

Cakewalk connects to PagerDuty through a read-only OAuth app, so there is no API key to create or store. Once a PagerDuty admin approves the connection, Cakewalk runs a scheduled sync that reads users with their roles and teams, service integrations and webhook subscriptions. Synced accounts are matched to existing identities in the Cakewalk directory. The integration never writes to PagerDuty and never reads incident data. Access tokens are stored encrypted by Cakewalk's embedded integration platform; Cakewalk never stores PagerDuty credentials.

### Requirements

* A Cakewalk workspace.
* A PagerDuty user with the `Admin` or `Account Owner` role to approve the connection. The connection acts with the access of the person who approves it.

### Integration Walkthrough

**In Cakewalk**

1. Sign in to Cakewalk and open **Integrations**.
2. Select **PagerDuty** and click **Connect**.

**In PagerDuty**

3. Sign in with an `Admin` or `Account Owner` account when prompted.
4. Review the requested read-only access and approve the connection.
5. Back in Cakewalk, the connection shows as active. The first sync starts automatically.

### How to Uninstall

1. In Cakewalk, open **Integrations**, select **PagerDuty** and disconnect the integration.
2. Optionally, revoke the app's access in PagerDuty under **My Profile** > **User Settings** > **Authorized Applications**.

### Support

For questions or issues with this integration, contact the Cakewalk team at <service@getcakewalk.io>.

#### Learn more

* [PagerDuty: General Access REST API Keys](https://support.pagerduty.com/main/docs/api-access-keys)
* [PagerDuty: User roles](https://support.pagerduty.com/main/docs/user-roles)
* [PagerDuty: Advanced Permissions](https://support.pagerduty.com/main/docs/advanced-permissions)
* [PagerDuty: Manage users](https://support.pagerduty.com/main/docs/manage-users)
* [PagerDuty: OAuth functionality](https://developer.pagerduty.com/docs/oauth-functionality)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://www.cakewalk.security/docs/human-access/connections-and-integrations/integration-guides/pagerduty.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
