All Products
Search
Document Center

Secure Access Service Edge:Connect to a Lark identity provider

Last Updated:Mar 31, 2026

Secure Access Service Edge (SASE) enforces identity-driven security policies. If your enterprise uses Lark as an identity provider (IdP) to manage its organizational structure, connect the Lark IdP to SASE so that employees can log in to the SASE app using their existing Lark accounts—without reconfiguring user identity information.

Limits

  • Up to five data sources can be enabled at a time.

  • Only one custom data source can be enabled at a time.

If you reach the quota, disable an existing data source before enabling a new one.

Prerequisites

Before you begin, ensure that you have:

  • A self-built application created on the Lark Open Platform, with the App ID and App Secret available

  • (Optional) Access to the Address Book Synchronization page in the Lark Open Platform, if you plan to configure event subscription for real-time org structure sync

Connect a Lark data source

Step 1: Get credentials from the Lark Open Platform

Before configuring SASE, retrieve the following values from the Lark Open Platform:

ValueWhere to find it
App IDIn the Lark Open Platform, open your self-built application.
App SecretIn the same self-built application.
Encrypt Key (optional)On the Address Book Synchronization page on the Lark Open Platform. Required only if you enable event subscription.
Verification Token (optional)On the Address Book Synchronization page of your application on the Lark Open Platform. Required only if you enable event subscription.

Step 2: Configure the Lark data source in SASE

  1. Log in to the SASE console.

  2. In the left navigation pane, choose Identity Authentication > Identity Access.

  3. On the Identity synchronization tab, click Create IdP.

  4. In the Create IdP panel, select Lark, click Configure, and complete the configuration wizard.

  5. In the Basic Configurations step, set the following parameters:

    ParameterDescription
    IdP NameA name for the Lark data source. Must be 2–100 characters and can include Chinese characters, letters, digits, hyphens (-), and underscores (_).
    DescriptionA description displayed on the SASE client as the logon title. This helps employees identify the data source when logging in.
    IdP StatusThe initial status of the identity source: Enabled or Closed.
    Important

    If you disable an identity source, end users cannot use the SASE app to access internal applications. Proceed with caution.

    App IDThe ID of your self-built application on the Lark platform.
    App SecretThe password of your self-built application on the Lark platform.
    Redirect URLStatic value: https://login.aliyuncsas.com/open-dev/feishu. Copy this value and configure it in the Lark Open Platform under Developer Console > Enterprise-built Application > Security Settings.
    Automatic SynchronizationEnable to let SASE automatically sync the org structure from Lark on a schedule. If disabled, you must trigger syncs manually.
    Synchronize User InformationEnable to automatically sync employee information based on the Automatic Synchronization Cycle. Has no effect if Automatic Synchronization is disabled.
    Automatic Synchronization CycleThe sync interval. Valid values: 1 hour to 24 hours.

    (Optional) Advanced Settings — Event subscription

    Configure event subscription to push real-time org changes (such as employee resignations or department restructuring) to SASE immediately, instead of waiting for the next scheduled sync.

    ParameterDescription
    Encrypt KeyObtained from the Address Book Synchronization page on the Lark Open Platform.
    Verification TokenObtained from the Address Book Synchronization page of your application on the Lark Open Platform.
    Request URLThis value is used to configure the redirection URL on the Lark Open Platform.

    Subscribed events: Department Created, Department Deleted, Department Information Changed, Employee Resigned, and Employee Information Changed.

  6. Click Connectivity Test. After the test succeeds, click Next.

    If the Connection Failed message appears, check whether the specified information is correct.
  7. In the Synchronization Settings step, configure the sync scope and field mappings, then click OK.

    ParameterDescription
    Organizational Structure SynchronizationSynchronize All: syncs the entire org structure from Lark to SASE. Partially Synchronize: select specific parts of the org structure to sync.
    Field Synchronization MappingMaps Lark org structure fields to SASE fields. If the built-in Local Field After Mapping options don't meet your needs, click View Extended Fields in the upper-right corner to add, edit, or delete extension fields.

After completing the wizard, the Lark data source appears on the Identity synchronization tab.

View synchronization records

  1. On the Identity synchronization tab, find the identity source and click Synchronize Records in the Actions column.

  2. On the Synchronize Records page, review the sync history for the identity source.

  3. In the Synchronization Task area on the left, click a specific sync task to view its details on the right.

    image

  4. Click Details in the Actions column to compare field values from the third-party data source and the SASE data source for that sync.

Manual synchronization

If you did not enable Automatic Synchronization, or if your org structure has changed and you need an immediate sync, click Create Synchronization Task and then click OK. Wait for the task to complete before reviewing the records.

After a successful sync, view the updated org structure and employee information under Identity Authentication > Identity Access > Employee Center. For more information, see Employee Center.

Disable automatic synchronization

Use either of the following methods:

  • On the Identity synchronization tab, find the identity source and turn off the switch in the Automatic Synchronization column.

  • In the Edit IdP panel, turn off the automatic synchronization switch.

More operations

OperationSteps
Edit a Lark data sourceOn the Identity synchronization tab, find the Lark data source and click Edit in the Actions column.
Disable a Lark data sourceOn the Identity synchronization tab, find the Lark data source and turn off the switch in the IdP Status column.
Delete a Lark data sourceOn the Identity synchronization tab, find the Lark data source and click Delete in the Actions column.

What's next