MiscellaneousIntegrate Adyen

Integrate Adyen

Connecting Adyen with Scrut lets you pull user access data from your Adyen environment into Scrut and run automated compliance checks against your applicable frameworks.

What This Integration Does in Scrut

  • User Access Data: Fetches user details, roles, and permissions from Adyen for Access Reviews.
  • Automated Tests: Runs automated checks that continuously evaluate Adyen for security misconfigurations and compliance checks against your applicable compliance frameworks.

Prerequisites

  • An active Adyen account with admin access to the Adyen Customer Area.
  • Access to both your test and live Customer Areas if you intend to use this integration in a production environment.

Permissions and Access Requirements

For Adyen

The API credential you create must have the following roles assigned:

  • Management API: Account read
  • Management API: Users read and write

For Scrut

  • Admin access to Scrut, or Contributor access with permission to the Integrations module.

Limitations

The API key generated in your test Customer Area does not work on live endpoints. You must generate a separate API key in your live Customer Area when switching to a production environment.

Data Collected

Scrut fetches the following information to populate Access Review data:

  • User name: Full display name from Adyen
  • User email: Primary email on the Adyen account
  • User role: Roles assigned to the user in Adyen

Sync Frequency

Data is synced automatically once every 24 hours. You can also manually trigger a sync from the integration settings page.

Integration Setup

Step 1: Generate Credentials in Adyen

You need three credentials from Adyen: an API key, an HMAC key, and a live URL prefix. Follow the steps below to retrieve each one.

Note: Keep your API key, HMAC key, and live URL prefix stored securely. You need all three to complete the setup in Scrut.

API Key

  1. Log in to your Adyen Customer Area and select your Company account.

  2. Click Developers → API credentials on the left sidebar.

  3. Click Create new credential.

  4. Under Credential type, select Web service user.

  5. Optionally enter a description, such as Scrut Integration, and click Create credential.

  6. On the Configure API credentials page, go to Server settings → Authentication API key tab.

  7. Click Generate API key.

  8. Click the copy icon and save your API key securely. You cannot retrieve it again after leaving this page.

  9. Assign the following roles to this credential:

    • Management API: Accounts read
    • Management API: Accounts read and write
  10. Click Save changes.

HMAC Key

  1. Click Developers → Webhooks on the left sidebar.

  2. Create a new standard webhook or open an existing one.

  3. Scroll to the Security section of the webhook.

  4. Click Generate HMAC key, then copy and store it securely.

Live URL Prefix

  1. Log in to your Adyen live Customer Area at live.adyen.com.
  2. Click Developers → API URLs on the left sidebar.
  3. Copy the prefix shown for your live endpoint. It appears in a format similar to a1b2c3d4-yourcompany.

Step 2: Connect Adyen in Scrut

  1. Log in to Scrut and go to Integrations in the left navigation.

  2. Select the Integrations Library tab.

  3. In the left panel, select Miscellaneous under Categories, or search for Adyen using the search bar.

  4. Click Integrate on the Adyen card.

  5. On the Adyen integration page, enter the following:

    • API Key: Paste the API key you generated in Step 1.
    • HMAC Key: Paste the HMAC key from your Adyen webhook configuration.
    • Prefix: Enter the live endpoint prefix for your Adyen account.
  6. Click Submit.

What Happens Next?

Initial data sync

After you submit your credentials, Scrut initiates the first data sync automatically. You can monitor the status of the sync by selecting the Audit Log tab on the Adyen integration page in Scrut.

Review synced data

Once the sync completes, navigate to the following locations in Scrut to verify your data:

  • Navigate to People → Access Reviews module in Scrut to view the user records fetched from Adyen, including name, email address, license type, and activation status.
  • Navigate to Tests → Automated Tests to view the compliance checks that Scrut runs for Adyen.

Common Errors and Troubleshooting

Authentication failure

Possible solutions:

  • Check that the required roles (Management API - Account read and Management API - Accounts read and write) are assigned to the credential.
  • If you recently rotated your API key in Adyen, update it in Scrut by returning to the integration's Details tab and submitting the new key.

HMAC key invalid

Possible solutions:

  • Confirm that you copied the HMAC key from an active webhook configuration in Adyen.
  • Check that the webhook is enabled and not paused or deleted in Adyen.

FAQs

FAQ

Reach out to support@scrut.io or contact your CSM for further assistance.