Workday
Connect Workday to Cakewalk as an identity source: an integration system user, a security group and an API client, in about 30 minutes.
Workday connects to Cakewalk with an API client backed by a dedicated integration system user (ISU). Expect about 30 minutes of setup in the Workday console; for the shared flow, see Connecting an HRIS.
✅ Before You Start
You need to be an admin of your company's Workday account.
To check: log in to Workday and search for "View API Clients". If the menu item does not appear, ask your Workday admin to grant your account sufficient permissions or to take over the setup.
🛠 Connect
In Cakewalk, go to Settings → Data Sources → Users and select Workday.
Find your service URL: search for "View API Clients", open the task and copy the Workday REST API Endpoint (it follows
https://{domain}/ccx/api/v1/{tenant}).Create the integration user: search for "Create Integration System User", enter a username and a secure password. Workday recommends checking Do Not Allow UI Sessions.
Create a security group for it: search for "Create Security Group", pick the type Integration System Security Group (Unconstrained), name it after the integration user and add that user to Integration System Users.
Grant the group its permissions: search for "Maintain Permission for Security Group", select Maintain, pick your group and add the permissions under Domain Security Policy Permissions. The connection flow shows the exact list to enter.
Activate the changes: search for "Activate Pending Security Policy Changes", add a comment, check Confirm and select OK. Without this task, none of the permission changes take effect.
Create the API client: search for "Register API Client for Integrations", enter a client name, turn on Non-Expiring Refresh Tokens and enter the Scope (Functional Areas) values the connection flow shows.
Copy the Client ID and Client Secret, then, still on the same page, open API Client → Manage Refresh Tokens for Integrations, enter your integration user, check Generate New Refresh Token and copy the refresh token.
Enter the service URL, Client ID, Client Secret and refresh token in the connection flow and finish.
The first sync starts immediately. Sync details and cadence: Connecting an HRIS.
📚 Related
Last updated
Was this helpful?