> For the complete documentation index, see [llms.txt](https://cybrhawksoc.gitbook.io/cybrhawk-docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cybrhawksoc.gitbook.io/cybrhawk-docs/siem-integrations/sso-and-identity/onelogin.md).

# OneLogin

Cybrhawk integrates with **OneLogin** to collect authentication and identity activity logs for monitoring, threat detection, and incident response.

***

## Requirements

* Administrator access to the **OneLogin Admin Portal** (`<your_instance>.onelogin.com`)
* API credentials with read access

***

## Step 1. Create New API Credentials

1. Sign in to the **OneLogin Admin Portal**.
2. In the navigation menu, go to **Developers > API Credentials**.
3. Click **New Credential**.
4. In the *Create new API credential* dialog, configure the following:
   * **Name** — Enter a unique, descriptive name (e.g., *Cybrhawk Integration*).
   * **Read all** — Select the checkbox.
5. Click **Done**.
6. Copy the **Client ID** and **Client Secret** values and store them securely.

***

## Step 2. Provide Credentials to Cybrhawk

Send the following details to 📧 **<socv2@cybrhawk.com>**:

* **Account Name** (unique, descriptive identifier for this integration)
* **Region** (your OneLogin region)
* **Client ID** (from Step 1)
* **Client Secret** (from Step 1)
* **Credential Expiry** (optional, if applicable)
