Skip to content
Notifications
Clear all

How to automate user onboarding/deboarding via their API (Python script included)

3 Posts
3 Users
0 Reactions
12 Views
(@amelia2)
Reputable Member
Joined: 3 months ago
Posts: 261
Topic starter   [#25766]

Spent the weekend hacking NordLayer's API to automate team member onboarding/deboarding. Their docs are okay, but the real trick is handling the async nature of provisioning. Here's the core script.

You'll need:
* Service Account with API access (Admin role)
* Your organization's `tenantId`
* Python with `requests`

The script does:
* Adds user to organization
* Assigns them to a specific team (by teamId)
* Waits for license assignment to succeed
* Cleans up on deboarding (revoke license, remove user)

```python
import requests
import time

API_BASE = "https://app.nordlayer.com/api/v1"
API_KEY = "your_service_account_key"

headers = {"Authorization": f"Bearer {API_KEY}", "Content-Type": "application/json"}

def onboard_user(email, team_id):
# 1. Create user invite
invite_payload = {"email": email}
invite_resp = requests.post(f"{API_BASE}/organizations/users/invite", json=invite_payload, headers=headers)
invite_resp.raise_for_status()
user_id = invite_resp.json().get("id")

# 2. Add user to team
team_payload = {"userId": user_id}
requests.post(f"{API_BASE}/teams/{team_id}/users", json=team_payload, headers=headers).raise_for_status()

# 3. Poll for license assignment (simplified)
license_assigned = False
for _ in range(10):
user_data = requests.get(f"{API_BASE}/organizations/users/{user_id}", headers=headers).json()
if user_data.get("license", {}).get("assigned"):
license_assigned = True
break
time.sleep(3)
if not license_assigned:
print(f"Warning: License may not be assigned for {email}")

def deboard_user(user_id):
# Revoke license first
requests.post(f"{API_BASE}/organizations/users/{user_id}/license/revoke", headers=headers)
# Remove from organization
requests.delete(f"{API_BASE}/organizations/users/{user_id}", headers=headers)

# Example usage
# onboard_user("[email protected]", "your-team-id-here")
```

Pitfalls:
* The license assignment isn't instant. You must poll.
* Deleting a user requires revoking their license first.
* API rate limits exist, but are reasonable for batch operations.

Integrate this with your HR system or IdP (SCIM not supported last I checked). Makes offboarding seamless.

— a2


Ship it, but test it first


   
Quote
(@cloud_ops_amy)
Honorable Member
Joined: 7 months ago
Posts: 453
 

Nice work, especially handling the async licensing. I've hit similar timing issues with AWS SSO user provisioning.

Did you consider adding a retry with exponential backoff for the license poll? Their API can be flaky during peak hours. I usually wrap those calls in a small decorator that also logs to CloudWatch for audit trails.

Also, you might want to add a check for existing invites before sending a new one. I learned the hard way that sending duplicate invites triggers their rate limiting pretty fast.


Cloud cost nerd. No, I don't use Reserved Instances.


   
ReplyQuote
(@ci_cd_plumber_42)
Reputable Member
Joined: 4 months ago
Posts: 257
 

Good points. The duplicate invite check is critical - their rate limit is brutal and it locks the service account for an hour.

For backoff, I usually skip decorators and just use tenacity. Less code, handles most retry scenarios out of the box.



   
ReplyQuote