Skip to content
Ankole

Adapter configuration guide

For AI Agents: the Markdown version of this page is at https://ankole.agentbull.com/en-US/docs/adapter-configuration/index.md. The documentation index is at https://ankole.agentbull.com/en-US/llms.txt.

This page lists the enterprise identity and chat adapters included with Ankole. First determine whether a platform supplies an Identity Provider (IdP), a Channel Provider, or both. Then consult the applicable configuration guide.

During first-run setup, /setup shows the login callback URL and a guide link for the selected IdP. After setup, manage identity settings under Console → Identity Providers. Bind chat applications to Agents under Console → Signal Routing.

Identity Providers

An IdP supplies Console sign-in. It can also synchronize employees, departments, or groups when the platform supports this function. The built-in local password provider needs no external application: it is always listed in /setup and the Console, and it signs people in with an email address and a password that Ankole stores. Use it for the first administrator, for a small team without a directory, or for the accounts that consumer-IM users are mapped to. The credential names below match the Ankole form. Use the linked guide for the exact permissions, provider-console paths, and verification steps.

Platform External application Main configuration Detailed guide
Slack Slack app created from scratch Client ID and Client Secret; directory sync also needs a Bot Token and App Token Slack IdP guide
Microsoft Entra ID Single-tenant app registration Tenant ID, Client ID, Client Secret, and Microsoft Graph permissions Entra ID guide
Google Workspace OAuth web client and a service account with domain-wide delegation OAuth client, allowed domains, service-account JSON, and delegated administrator email Google Workspace guide
Feishu / Lark Enterprise self-built app or Custom App App ID, App Secret, service region, and application availability Feishu / Lark IdP guide
DingTalk Internal enterprise application Client ID, Client Secret, Corp ID, and directory permissions DingTalk IdP guide
WeCom Self-built app with optional contacts synchronization CorpID, AgentId, application Secret, contacts-sync Secret, and trusted IP addresses WeCom IdP guide

After you configure the provider, register the callback URL exactly as /setup shows it. Do not type it manually. Do not replace the browser-facing HTTPS origin with an internal container address. After sign-in succeeds, run one full directory sync and check the users, departments, or groups under Principals and permission groups.

Channel Providers

A chat adapter receives messages and sends Agent replies. For production use, create separate applications for identity and chat, even when one platform supplies both. This separation keeps sign-in permissions, bot permissions, release scope, and credential rotation independent.

Platform External application Connection and main configuration Detailed guide
Slack Slack app with a Bot User Socket Mode; Bot Token, App Token, events, and Bot scopes Slack channel guide
Microsoft Teams Azure Bot with its Entra application Bot Framework; App ID, Client Secret, tenant, and messaging endpoint Teams channel guide
Feishu / Lark Separate enterprise self-built app or Custom App Long connection; App ID, App Secret, events, and bot permissions Feishu / Lark channel guide
DingTalk Internal enterprise application with a bot Stream mode; Client ID and Client Secret, with optional AI cards DingTalk channel guide
WeCom API-mode AI bot created by a super administrator Long connection; Bot ID and bot Secret WeCom channel guide
Telegram Bot created with @BotFather Long polling; Bot token, with group privacy mode off Telegram channel guide
Discord Application with a bot in the Developer Portal Gateway WebSocket; Bot token, message content intent, and bot permissions Discord channel guide
LINE Messaging API channel of an Official Account Webhook; Channel ID, Channel secret, channel access token, and webhook URL LINE channel guide
WhatsApp Meta App with the WhatsApp product and a Business phone number Cloud API webhook; App ID, App secret, verify token, Phone number ID, and System User token WhatsApp channel guide
Email A dedicated mailbox with IMAP and SMTP IMAP and SMTP hosts and ports, login, password, and sender authentication Email channel guide

Telegram, Discord, LINE, and WhatsApp are consumer IMs. Their users have no employee record, so a new sender is mapped to an account under Identity → Pending mappings before the Agent serves them; WhatsApp maps a sender by itself when a known account already owns the phone number. An email sender is known only through an explicit email identity binding, which directory sync creates for employees and an administrator creates for everyone else. See Signal routing rules.

After you prepare the external application, open Console → Signal Routing → New routing rule. Select the Agent and adapter, and enter the credentials. Use the same platformSubjectNamespace for the IdP and chat application only when both applications belong to the same enterprise organization. Do not share a namespace across organizations.

Update a stored credential

When you edit an Identity Provider or signal routing rule, the Console only indicates that an encrypted credential is stored. It never returns tokens or secrets to the browser. Leave the credential field blank to keep the stored value. Enter and save a new value only when replacing it. Rotate or revoke old credentials in the external provider, as stored values cannot be retrieved from the Console.

Verification order

  1. Verify IdP sign-in and confirm that the first administrator can open the Console.
  2. Run a full directory sync and check the Principals and permission groups.
  3. Create the chat routing rule. Test it first with a direct message or an explicit mention.
  4. Confirm that the Agent receives the message and sends a reply. Then enable advanced functions such as group observation, real-time directory sync, or cards.

If you change provider scopes, application permissions, or release scope, reinstall or republish the application when the provider requires this action. Update Ankole with each rotated credential.