Secrets & Key Management · Integration
Delinea
Add Delinea to your product for your customers, and give your AI agents governed access to it.
Embed a Delinea integration, formerly Centrify, so your customers can work their own privileged accounts, secrets, and session records from inside your product under least-privilege access. Only the scopes required for the actions you enable are requested, each customer grants access to their own tenant, and every call is recorded so an access change can be traced to its source. fastn handles per-customer authorisation and API upkeep, so onboarding a tenant is configuration rather than a release.
In your product
Embedded for your customers. Per-tenant auth, no per-customer code, maintained by fastn.
Let customers connect their own Delinea tenant so your product works within their existing privileged access controls.
Retrieve a secret at runtime with scoped permissions instead of storing credentials in your product.
Read privileged account inventory and session records so access reviews happen where your users already work.
Trigger your product when a privileged account, permission, or session record changes.
For your AI agents
Governed, audited access for the agents you build, through the MCP server.
An agent lists who holds access to a privileged account before an access review.
An agent requests or revokes access within governed permissions, with every action audited.
An agent reacts to a session or permission change and raises it for review.
Example prompt
List privileged accounts whose access has not been reviewed in 90 days and show the current holders.
Set up Delinea in 4 steps
- 01Open the Delinea connector from your fastn dashboard.
- 02Have each customer authenticate their own tenant with least-privilege scopes.
- 03Map the accounts, secrets, and audit fields your product uses, then enable actions and triggers.
- 04Call them from your product, or expose them to an agent through the MCP server.
Why teams use the Delinea integration
What you get by embedding it with fastn instead of building it yourself.
- Ship a Delinea integration without building it. Your customers connect their own Delinea account inside your product and work their secrets, keys and certificates there, with no per-customer code on your side.
- Handle the part that actually costs time: an expired certificate or an unrotated key is an outage rather than a warning, and it arrives without notice. fastn owns the auth, token refresh, rate limits, pagination and breaking-change fixes, so a Delinea update is not your on-call problem.
- One integration serves your product and your agents. The same governed Delinea connection powers in-product features and gives AI agents scoped, audited access, so you fetch a credential at the point of use instead of storing it yourself without wiring it twice.
Used by these teams
Works well with
Often used alongside
Tools the same teams tend to run next to Delinea, across other categories.
Delinea integration FAQ
How do I add a Delinea integration to my product?
Enable the Delinea connector in your fastn dashboard, then let each customer authenticate their own Delinea account. fastn handles the OAuth flow, token storage and refresh per tenant, so there is no Delinea client code in your app and no per-customer branch in your codebase. Setup is 4 steps.
Do my customers each connect their own Delinea account?
Yes. Every connection is scoped to the individual customer, so each authorises their own Delinea account and only ever sees their own secrets, keys and certificates. That per-tenant isolation is the point of an embedded integration: you support the long tail of customer setups without maintaining an integration per customer.
Can AI agents use this Delinea integration?
Yes. The same connection is exposed to your agents through the fastn MCP gateway, with permissions scoped per tenant and every call audited. An agent lists who holds access to a privileged account before an access review.
Who maintains the Delinea integration?
fastn does. When Delinea changes an endpoint, deprecates a field or alters its auth, the fix lands in the connector rather than in your backlog, and your customers' connections keep working.
Does my product ever hold the customer's Delinea secret?
No longer than the call needs it. Values are fetched under the customer's own credentials at the point of use and never written into your database, and every read is logged per tenant so an access can be traced to what asked for it.
Can rotation and expiry be handled automatically?
Yes, within the permissions the customer grants, and audited. This matters more here than almost anywhere else: an expired certificate or an unrotated key takes something down rather than raising a warning first.
What can I build with the Delinea integration?
A common starting point: connect their own Delinea tenant so your product works within their existing privileged access controls. Teams also use it for the other use cases listed above, and expose it to agents for governed reads and writes.
How much does the Delinea integration cost?
It is included. Pricing is based on connected accounts, not on how many connectors you enable, so adding Delinea does not change your per-connector cost. You can start free with 3 connected accounts.
Add Delinea to your product
Start free with 3 connected accounts. No sales call required, and no per-customer integration code.