Configuration Hub Tenant Connection PAT error

I followed the instructions here to set up a tenant connection between my clients SB and Prod. When clicking “create new” I receive this response “The PAT Associated with this connection is invalid”. I have already tried creating a brand new PAT, and confirmed that the PAT has the correct scope (all). Any idea why I’m getting this error message?

Trace ID: fa60f3d673044be78f01875f1ab7456c Details: An error occurred. Please contact your administrator. The PAT Associated with this connection is invalid

Per the instructions here, make sure your PAT has the required scope of sp:config:backup-connection. The all scope will not work.

1 Like

Hey Pat - I tried making a new PAT with only sp:config:backup-connection scope and am still seeing the same failure message.

Weird. I did the same thing you did with the all scope initially then found that other scope in the doc then it worked. For the Tenant Name field, you are just putting the tenant name right? Not the full IDN URL? i.e. tenant123 vs tenant123.identitynow.com

And the PAT you created is in Prod right, not SB? Assuming you are trying to hook SB to Prod.

I’d tried both the full URL vs. just the host before and just tried that again and got the same issue.

Hmm I created the PAT IN SB and I’m making the connection in Prod, back to SB. That’s the right direction yea?

that seems the correct direction. it is a ‘pull’ of a backup config from source tenant to the target tenant which you would like to deploy it. i.e.: if you want to migrate configs from sb to prod, you need to provide access to sb, i.e. create connection from prod using PAT that was created in sb.
i see that you did use the correct scope - if this is still an issue, and the two tenants are in the same region, can you please create a support ticket and provide the tenants names and we can check logs for errors.

Seems like this is due to network access:
please check that the User Identity Profile which has block offNetwork traffic set to true.
also check on your sandbox if it allows traffic from prod admin > global > system settings > network settings

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.