---
title: "Adapter configuration guide"
description: "Find the app type, credentials, permissions, and verification steps for each Ankole identity and chat adapter."
url: "https://ankole.agentbull.com/en-US/docs/adapter-configuration/"
lang: "en-US"
---

> Documentation index for AI Agents: https://ankole.agentbull.com/en-US/llms.txt

# Adapter configuration guide

This page lists the enterprise identity and chat adapters included with Ankole. First determine whether a platform supplies an **Identity Provider (IdP)**, a **Channel Provider**, or both. Then consult the applicable configuration guide.

During first-run setup, `/setup` shows the login callback URL and a guide link for the selected IdP. After setup, manage identity settings under **Console → Identity Providers**. Bind chat applications to Agents under **Console → Signal Routing**.

## Identity Providers

An IdP supplies Console sign-in. It can also synchronize employees, departments, or groups when the platform supports this function. The built-in local password provider needs no external application: it is always listed in `/setup` and the Console, and it signs people in with an email address and a password that Ankole stores. Use it for the first administrator, for a small team without a directory, or for the accounts that consumer-IM users are mapped to. The credential names below match the Ankole form. Use the linked guide for the exact permissions, provider-console paths, and verification steps.

| Platform | External application | Main configuration | Detailed guide |
|---|---|---|---|
| Slack | Slack app created from scratch | Client ID and Client Secret; directory sync also needs a Bot Token and App Token | [Slack IdP guide](https://ankole.agentbull.com/en-US/docs/quickstart/index.md?idp=slack#identity-providers) |
| Microsoft Entra ID | Single-tenant app registration | Tenant ID, Client ID, Client Secret, and Microsoft Graph permissions | [Entra ID guide](https://ankole.agentbull.com/en-US/docs/quickstart/index.md?idp=entra-id#identity-providers) |
| Google Workspace | OAuth web client and a service account with domain-wide delegation | OAuth client, allowed domains, service-account JSON, and delegated administrator email | [Google Workspace guide](https://ankole.agentbull.com/en-US/docs/quickstart/index.md?idp=google-workspace#identity-providers) |
| Feishu / Lark | Enterprise self-built app or Custom App | App ID, App Secret, service region, and application availability | [Feishu / Lark IdP guide](https://ankole.agentbull.com/en-US/docs/quickstart/index.md?idp=lark#identity-providers) |
| DingTalk | Internal enterprise application | Client ID, Client Secret, Corp ID, and directory permissions | [DingTalk IdP guide](https://ankole.agentbull.com/en-US/docs/quickstart/index.md?idp=dingtalk#identity-providers) |
| WeCom | Self-built app with optional contacts synchronization | CorpID, AgentId, application Secret, contacts-sync Secret, and trusted IP addresses | [WeCom IdP guide](https://ankole.agentbull.com/en-US/docs/quickstart/index.md?idp=wecom#identity-providers) |

After you configure the provider, register the callback URL exactly as `/setup` shows it. Do not type it manually. Do not replace the browser-facing HTTPS origin with an internal container address. After sign-in succeeds, run one full directory sync and check the users, departments, or groups under **Principals and permission groups**.

## Channel Providers

A chat adapter receives messages and sends Agent replies. For production use, create separate applications for identity and chat, even when one platform supplies both. This separation keeps sign-in permissions, bot permissions, release scope, and credential rotation independent.

| Platform | External application | Connection and main configuration | Detailed guide |
|---|---|---|---|
| Slack | Slack app with a Bot User | Socket Mode; Bot Token, App Token, events, and Bot scopes | [Slack channel guide](https://ankole.agentbull.com/en-US/docs/quickstart/index.md?channel=slack#chat-channels) |
| Microsoft Teams | Azure Bot with its Entra application | Bot Framework; App ID, Client Secret, tenant, and messaging endpoint | [Teams channel guide](https://ankole.agentbull.com/en-US/docs/quickstart/index.md?channel=teams#chat-channels) |
| Feishu / Lark | Separate enterprise self-built app or Custom App | Long connection; App ID, App Secret, events, and bot permissions | [Feishu / Lark channel guide](https://ankole.agentbull.com/en-US/docs/quickstart/index.md?channel=lark#chat-channels) |
| DingTalk | Internal enterprise application with a bot | Stream mode; Client ID and Client Secret, with optional AI cards | [DingTalk channel guide](https://ankole.agentbull.com/en-US/docs/quickstart/index.md?channel=dingtalk#chat-channels) |
| WeCom | API-mode AI bot created by a super administrator | Long connection; Bot ID and bot Secret | [WeCom channel guide](https://ankole.agentbull.com/en-US/docs/quickstart/index.md?channel=wecom#chat-channels) |
| Telegram | Bot created with @BotFather | Long polling; Bot token, with group privacy mode off | [Telegram channel guide](https://ankole.agentbull.com/en-US/docs/quickstart/index.md?channel=telegram#chat-channels) |
| Discord | Application with a bot in the Developer Portal | Gateway WebSocket; Bot token, message content intent, and bot permissions | [Discord channel guide](https://ankole.agentbull.com/en-US/docs/quickstart/index.md?channel=discord#chat-channels) |
| LINE | Messaging API channel of an Official Account | Webhook; Channel ID, Channel secret, channel access token, and webhook URL | [LINE channel guide](https://ankole.agentbull.com/en-US/docs/quickstart/index.md?channel=line#chat-channels) |
| WhatsApp | Meta App with the WhatsApp product and a Business phone number | Cloud API webhook; App ID, App secret, verify token, Phone number ID, and System User token | [WhatsApp channel guide](https://ankole.agentbull.com/en-US/docs/quickstart/index.md?channel=whatsapp#chat-channels) |
| Email | A dedicated mailbox with IMAP and SMTP | IMAP and SMTP hosts and ports, login, password, and sender authentication | [Email channel guide](https://ankole.agentbull.com/en-US/docs/quickstart/index.md?channel=email#chat-channels) |

Telegram, Discord, LINE, and WhatsApp are consumer IMs. Their users have no employee record, so a new sender is mapped to an account under **Identity → Pending mappings** before the Agent serves them; WhatsApp maps a sender by itself when a known account already owns the phone number. An email sender is known only through an explicit email identity binding, which directory sync creates for employees and an administrator creates for everyone else. See [Signal routing rules](https://ankole.agentbull.com/en-US/docs/signal-bindings/index.md#choose-what-happens-to-unknown-senders).

After you prepare the external application, open **Console → Signal Routing → New routing rule**. Select the Agent and adapter, and enter the credentials. Use the same `platformSubjectNamespace` for the IdP and chat application only when both applications belong to the same enterprise organization. Do not share a namespace across organizations.

## Update a stored credential

When you edit an Identity Provider or signal routing rule, the Console only indicates that an encrypted credential is stored. It never returns tokens or secrets to the browser. Leave the credential field blank to keep the stored value. Enter and save a new value only when replacing it. Rotate or revoke old credentials in the external provider, as stored values cannot be retrieved from the Console.

## Verification order

1. Verify IdP sign-in and confirm that the first administrator can open the Console.
2. Run a full directory sync and check the Principals and permission groups.
3. Create the chat routing rule. Test it first with a direct message or an explicit mention.
4. Confirm that the Agent receives the message and sends a reply. Then enable advanced functions such as group observation, real-time directory sync, or cards.

If you change provider scopes, application permissions, or release scope, reinstall or republish the application when the provider requires this action. Update Ankole with each rotated credential.
