Skip to content
← Back to documentation
Technical Reference

CyberArk

Manage users, groups, and access controls in CyberArk Privileged Access Management

CategoryProductivity
Authenticationcustom
Version0.1.7
Published scopes0 published scopes
Last updatedSeptember 29, 2026

Overview

Connect CyberArk with Flows360

Manage users, groups, and access controls in CyberArk Privileged Access Management

Use the CyberArk connector to include its declared actions and events in Flows360 workflows without duplicating the integration logic inside each consuming system. This pinned connector version currently exposes 17 actions and no declared triggers.

Available actions

  • Create User
  • Update User
  • Delete User
  • Activate User
  • Enable User
  • Disable User
  • Find User
  • Add Member to Group
  • Plus 9 additional declared actions.

Available triggers

  • No triggers are declared in this pinned package.

The capability list above is generated from the exact reviewed connector package so the public description stays aligned with the version Flows360 operates.

Technical guide

Technical reference

Package identity

  • Connector: CyberArk
  • Package: @activepieces/piece-cyberark@0.1.7
  • Exact artifact digest: sha256:454251669408efa4c29052bd651880723d48f73ef59df3faef401757e96eee3d
  • Runtime: Activepieces-compatible deterministic worker
  • Source: the exact reviewed Activepieces source

Authentication

CUSTOM AUTH. Connection values are tenant-specific and remain in the consuming Studio instance; CDK stores definitions and field metadata, not customer credential values.

Action contracts

  • Create User (create_user), Creates a new user in the CyberArk Vault Classification: read.
  • Update User (update_user), Updates an existing Vault user (except Master and Batch built-in users) Classification: read.
  • Delete User (delete_user), Deletes a specific user in the Vault (requires Add/Update Users authorization) Classification: read.
  • Activate User (activate_user), Activates an existing user who was suspended after entering incorrect credentials multiple times Classification: read.
  • Enable User (enable_user), Enables a specific user in the Vault Classification: read.
  • Disable User (disable_user), Disables a specific user in the Vault Classification: read.
  • Find User (find_user), Returns a list of existing users in the Vault based on filter criteria (requires Audit users permissions) Classification: read.
  • Add Member to Group (add_member_to_group), Adds a user as a member to an existing Vault group (requires Add/Update users permissions) Classification: read.
  • Remove Member from Group (remove_member_from_group), Removes a specific user from a user group in the Vault Classification: read.
  • Get Password Value (get_password_value), Retrieves the password or SSH key of an existing account identified by its Account ID Classification: read.
  • Retrieve Private SSH Key (retrieve_private_ssh_key), Retrieves a private SSH key file from an existing account identified by its Account ID Classification: read.
  • Change Credentials in the Vault (change_credentials_in_vault), Sets account credentials and changes them in the Vault. This will not affect credentials on the target device. Classification: read.
  • Verify Credentials in Bulk (verify_credentials_bulk), Marks multiple accounts for verification by the CPM Classification: read.
  • Change Credentials Immediately in Bulk (change_credentials_bulk), Marks multiple accounts for an immediate credentials change by the CPM to a new random value Classification: read.
  • Set Next Password in Bulk (set_next_password_bulk), Sets multiple accounts' credentials to use for the next CPM change Classification: read.
  • Change Credentials in the Vault in Bulk (change_credentials_in_vault_bulk), Sets credentials for multiple accounts and changes them in the Vault. This does not affect credentials on the target device. Classification: read.
  • Reconcile Credentials in Bulk (reconcile_credentials_bulk), Marks multiple accounts for automatic reconciliation by the CPM Classification: read.

Trigger contracts

  • No trigger delivery contracts are declared.

Verification

Runtime execution evidence is managed separately from package metadata.

Capability summary

Authenticationcustom
Supported objects17
Supported actions17
TriggersNone published

Authentication

Authentication method: custom

Authentication profiles

connection · custom
  • PVWA Server URL Required
  • Username Required
  • Password Required · protected credential

Supported objects

ObjectReadWriteNotes
Create User Yes No Creates a new user in the CyberArk Vault
Update User Yes No Updates an existing Vault user (except Master and Batch built-in users)
Delete User Yes No Deletes a specific user in the Vault (requires Add/Update Users authorization)
Activate User Yes No Activates an existing user who was suspended after entering incorrect credentials multiple times
Enable User Yes No Enables a specific user in the Vault
Disable User Yes No Disables a specific user in the Vault
Find User Yes No Returns a list of existing users in the Vault based on filter criteria (requires Audit users permissions)
Add Member to Group Yes No Adds a user as a member to an existing Vault group (requires Add/Update users permissions)
Remove Member from Group Yes No Removes a specific user from a user group in the Vault
Get Password Value Yes No Retrieves the password or SSH key of an existing account identified by its Account ID
Retrieve Private SSH Key Yes No Retrieves a private SSH key file from an existing account identified by its Account ID
Change Credentials in the Vault Yes No Sets account credentials and changes them in the Vault. This will not affect credentials on the target device.
Verify Credentials in Bulk Yes No Marks multiple accounts for verification by the CPM
Change Credentials Immediately in Bulk Yes No Marks multiple accounts for an immediate credentials change by the CPM to a new random value
Set Next Password in Bulk Yes No Sets multiple accounts' credentials to use for the next CPM change
Change Credentials in the Vault in Bulk Yes No Sets credentials for multiple accounts and changes them in the Vault. This does not affect credentials on the target device.
Reconcile Credentials in Bulk Yes No Marks multiple accounts for automatic reconciliation by the CPM

Supported actions

Create User · Read

Creates a new user in the CyberArk Vault

create_user · Risk: low · Retry: safe

Inputs

  • username · string · Required, The name of the user (max 128 characters)
  • userType · string · Optional, The user type according to license
  • initialPassword · string · Optional, Password for first-time login (max 39 characters)
  • authenticationMethod · string · Optional, The authentication method for login
  • allowedAuthenticationMethods · array · Optional, Non-Vault authentication methods the user can use
  • location · string · Optional, Vault location for user creation (must start with \)
  • enableUser · boolean · Optional, Whether the user will be enabled upon creation
  • changePassOnNextLogon · boolean · Optional, User must change password on next login
  • passwordNeverExpires · boolean · Optional, Password will not expire unless user changes it
  • description · string · Optional, Notes and comments (max 99 characters)
  • vaultAuthorization · array · Optional, User permissions
  • firstName · string · Optional, First name (max 29 characters)
  • middleName · string · Optional, Middle name (max 29 characters)
  • lastName · string · Optional, Last name (max 29 characters)
  • homeEmail · string · Optional, Home email address (max 319 characters)
  • businessEmail · string · Optional, Business email address (max 319 characters)
  • homeNumber · string · Optional, Home phone number (max 24 characters)
  • businessNumber · string · Optional, Business phone number (max 24 characters)
  • cellularNumber · string · Optional, Cellular phone number (max 24 characters)
  • faxNumber · string · Optional, Fax number (max 24 characters)
  • pagerNumber · string · Optional, Pager number (max 24 characters)
  • expiryDate · string · Optional, Date when the user expires
  • unAuthorizedInterfaces · array · Optional, Interfaces the user cannot access
  • workStreet · string · Optional, Business street address (max 29 characters)
  • workCity · string · Optional, Business city (max 19 characters)
  • workState · string · Optional, Business state (max 19 characters)
  • workZip · string · Optional, Business ZIP code (max 19 characters)
  • workCountry · string · Optional, Business country (max 19 characters)
  • street · string · Optional, Home street address (max 29 characters)
  • city · string · Optional, Home city (max 19 characters)
  • state · string · Optional, Home state (max 19 characters)
  • zip · string · Optional, Home ZIP code (max 19 characters)
  • country · string · Optional, Home country (max 19 characters)
  • title · string · Optional, Professional title (max 49 characters)
  • organization · string · Optional, Organization name (max 49 characters)
  • department · string · Optional, Department (max 49 characters)
  • profession · string · Optional, Profession (max 49 characters)
  • homePage · string · Optional, Personal website (max 319 characters)
  • otherEmail · string · Optional, Additional email address (max 319 characters)
Update User · Read

Updates an existing Vault user (except Master and Batch built-in users)

update_user · Risk: low · Retry: safe

Inputs

  • userId · string · Required, Select a user from the Vault (shows username, ID, type, and status)
  • username · string · Required, The name of the user (max 128 characters)
  • userType · string · Optional, The user type according to license
  • enableUser · boolean · Optional, Whether the user is enabled
  • changePassOnNextLogon · boolean · Optional, User must change password on next login
  • passwordNeverExpires · boolean · Optional, Password will not expire unless user changes it
  • suspended · boolean · Optional, Whether the user is suspended
  • expiryDate · string · Optional, Date when the user expires
  • userActivityLogRetentionDays · number · Optional, Days to retain user activity records (default: 90)
  • authenticationMethod · string · Optional, The authentication method for login
  • allowedAuthenticationMethods · array · Optional, Non-Vault authentication methods the user can use
  • unAuthorizedInterfaces · array · Optional, CyberArk interfaces this user cannot access
  • location · string · Optional, Vault location (must start with \)
  • distinguishedName · string · Optional, Distinguished name for PKI authentication
  • password · string · Optional, New password for the user (max 39 characters)
  • description · string · Optional, Notes and comments (max 99 characters)
  • vaultAuthorization · array · Optional, User permissions
  • firstName · string · Optional, First name (max 29 characters)
  • middleName · string · Optional, Middle name (max 29 characters)
  • lastName · string · Optional, Last name (max 29 characters)
  • title · string · Optional, Title (max 49 characters)
  • organization · string · Optional, Organization (max 49 characters)
  • department · string · Optional, Department (max 49 characters)
  • profession · string · Optional, Profession (max 49 characters)
  • street · string · Optional, Street address (max 29 characters)
  • city · string · Optional, City (max 19 characters)
  • state · string · Optional, State (max 19 characters)
  • zip · string · Optional, ZIP code (max 19 characters)
  • country · string · Optional, Country (max 19 characters)
  • workStreet · string · Optional, Work street address (max 29 characters)
  • workCity · string · Optional, Work city (max 19 characters)
  • workState · string · Optional, Work state (max 19 characters)
  • workZip · string · Optional, Work ZIP code (max 19 characters)
  • workCountry · string · Optional, Work country (max 19 characters)
  • homePage · string · Optional, Home page URL (max 319 characters)
  • homeEmail · string · Optional, Home email address (max 319 characters)
  • businessEmail · string · Optional, Business email address (max 319 characters)
  • otherEmail · string · Optional, Other email address (max 319 characters)
  • homeNumber · string · Optional, Home phone number (max 24 characters)
  • businessNumber · string · Optional, Business phone number (max 24 characters)
  • cellularNumber · string · Optional, Cellular phone number (max 24 characters)
  • faxNumber · string · Optional, Fax number (max 24 characters)
  • pagerNumber · string · Optional, Pager number (max 24 characters)
  • loginFromHour · string · Optional, Starting time when user can log in
  • loginToHour · string · Optional, Ending time when user can log in
Delete User · Read

Deletes a specific user in the Vault (requires Add/Update Users authorization)

delete_user · Risk: low · Retry: safe

Inputs

  • userId · string · Required, Select a user from the Vault (shows username, ID, type, and status)
  • confirmDeletion · boolean · Required, Check this box to confirm you want to delete the selected user. This action cannot be undone.
Activate User · Read

Activates an existing user who was suspended after entering incorrect credentials multiple times

activate_user · Risk: low · Retry: safe

Inputs

  • userId · string · Required, Select a user from the Vault (shows username, ID, type, and status)
Enable User · Read

Enables a specific user in the Vault

enable_user · Risk: low · Retry: safe

Inputs

  • userId · string · Required, Select a user from the Vault (shows username, ID, type, and status)
Disable User · Read

Disables a specific user in the Vault

disable_user · Risk: low · Retry: safe

Inputs

  • userId · string · Required, Select a user from the Vault (shows username, ID, type, and status)
Find User · Read

Returns a list of existing users in the Vault based on filter criteria (requires Audit users permissions)

find_user · Risk: low · Retry: safe

Inputs

  • filter · string · Optional, Filter users by userType, componentUser, or userName
  • search · string · Optional, Search by username, firstname, or lastname
  • sort · string · Optional, Sort by property (username, source, userType, location, lastname, firstname, middlename) followed by asc/desc
  • extendedDetails · boolean · Optional, Returns additional user details including groups and userDN for LDAP users
  • pageOffset · number · Optional, Offset the first user returned in results
  • pageSize · number · Optional, Maximum number of users to return (used with offset)
  • componentUser · boolean · Optional, Filter to show only component users
  • userType · string · Optional, Filter by specific user type
Add Member to Group · Read

Adds a user as a member to an existing Vault group (requires Add/Update users permissions)

add_member_to_group · Risk: low · Retry: safe

Inputs

  • groupId · string · Required, Select a group from the Vault
  • memberId · string · Required, Select a Vault user or enter LDAP group name to add to the group
  • memberType · string · Required, The type of user being added to the Vault group
  • domainName · string · Optional, The DNS address of the domain (required if memberType is domain)
Remove Member from Group · Read

Removes a specific user from a user group in the Vault

remove_member_from_group · Risk: low · Retry: safe

Inputs

  • groupId · string · Required, Select a group from the Vault
  • memberId · string · Required, Select a Vault user or enter LDAP group name to add to the group
Get Password Value · Read

Retrieves the password or SSH key of an existing account identified by its Account ID

get_password_value · Risk: low · Retry: safe

Inputs

  • accountId · string · Required, Select an account from the Vault
  • reason · string · Optional, The reason for retrieving the password/SSH key
  • ticketingSystemName · string · Optional, The name of the Ticketing System
  • ticketId · string · Optional, The ticket ID of the ticketing system
  • version · number · Optional, The version number of the required password. If there are no previous versions, the current password/key version is returned.
  • actionType · string · Optional, The action this password will be used for
  • isUse · boolean · Optional, Internal parameter (for PSM for SSH only)
  • machine · string · Optional, The address of the remote machine to connect to
Retrieve Private SSH Key · Read

Retrieves a private SSH key file from an existing account identified by its Account ID

retrieve_private_ssh_key · Risk: low · Retry: safe

Inputs

  • accountId · string · Required, Select an account from the Vault
  • reason · string · Optional, The reason for retrieving the private SSH key
  • ticketingSystemName · string · Optional, The name of the ticketing system
  • ticketId · string · Optional, The ticket ID defined in the ticketing system
  • version · number · Optional, The version number of the required SSH key. Must be a positive number. If left empty or the value does not exist, the current SSH key version is returned.
  • actionType · string · Optional, The action this SSH key is used for
  • isUse · boolean · Optional, Internal parameter (for use of PSMP only)
  • machine · string · Optional, The address of the remote machine to connect to using the SSH key
Change Credentials in the Vault · Read

Sets account credentials and changes them in the Vault. This will not affect credentials on the target device.

change_credentials_in_vault · Risk: low · Retry: safe

Inputs

  • accountId · string · Required, Select an account from the Vault
  • newCredentials · string · Required, The new account credentials that will be allocated to the account in the Vault. Leading and trailing white spaces will be automatically removed.
Verify Credentials in Bulk · Read

Marks multiple accounts for verification by the CPM

verify_credentials_bulk · Risk: low · Retry: safe

Inputs

  • accountIds · array · Required, List of unique account IDs to verify
Change Credentials Immediately in Bulk · Read

Marks multiple accounts for an immediate credentials change by the CPM to a new random value

change_credentials_bulk · Risk: low · Retry: safe

Inputs

  • accountIds · array · Required, List of unique account IDs to change credentials for
  • changeEntireGroup · boolean · Optional, Whether the CPM changes the credentials for all accounts in the same account group. Only applies to accounts that belong to an account group.
Set Next Password in Bulk · Read

Sets multiple accounts' credentials to use for the next CPM change

set_next_password_bulk · Risk: low · Retry: safe

Inputs

  • bulkItems · array · Required, List of account items. Each item should be a JSON object with accountId (required), changeImmediately (optional), and newCredentials (optional).
Change Credentials in the Vault in Bulk · Read

Sets credentials for multiple accounts and changes them in the Vault. This does not affect credentials on the target device.

change_credentials_in_vault_bulk · Risk: low · Retry: safe

Inputs

  • bulkItems · array · Required, List of account items. Each item should be a JSON object with accountId (required) and newCredentials (optional).
Reconcile Credentials in Bulk · Read

Marks multiple accounts for automatic reconciliation by the CPM

reconcile_credentials_bulk · Risk: low · Retry: safe

Inputs

  • accountIds · array · Required, List of unique account IDs to reconcile

Setup

Setup

  1. Add the CyberArk connector to the workflow in the target Flows360 Studio instance.
  2. Create or select the tenant-specific connection required by the connector. Connection secrets remain in the Studio connection boundary and are not copied into CDK documentation.
  3. Provide the connection fields declared by the pinned package:
  • PVWA Server URL (serverUrl), required.
  • Username (username), required.
  • Password (password), required; stored as a sensitive connection value.
  1. Select the required action or trigger and complete its declared input fields. Required and optional inputs are defined by the exact package schema.
  2. Test the workflow in the appropriate environment before enabling production scheduling or event delivery.

Limitations

Limitations and operational notes

  • This content describes @activepieces/piece-cyberark@0.1.7; provider behaviour can change independently and should be revalidated when the provider or connector version changes.
  • Only the 17 actions and 0 triggers declared by this pinned package are represented here.
  • Tenant credentials and connection values are not stored in the public connector record.
  • Provider-side permissions, account entitlements, quotas and rate limits remain subject to the connected provider account and are not inferred when the package does not declare them.
  • Runtime execution evidence is managed separately from package metadata.

Troubleshooting

Why canu2019t the connector authenticate?

Check the tenant connection in Studio and confirm every required CyberArk connection field is present. Re-authorise OAuth-based connections if the provider token or consent has expired. Do not place credential values in CDK content or logs.

Why is an action or trigger unavailable?

Confirm that the workflow is using @activepieces/piece-cyberark@0.1.7 and compare the requested capability with the declared action and trigger list for this version. A capability that is not declared by the pinned package should not be presented as supported.

What should I check after a provider-side change?

Revalidate authentication, required fields, action/trigger behaviour and provider documentation before publishing refreshed connector content or moving a new package version into production.