Prerequisites
- Coupa administrator account with permission to manage OAuth2/OpenID Connect clients
- A Coupa instance URL (for example,
https://<instance>.coupahost.comfor customer tenants, orhttps://<instance>.coupacloud.comfor partner/demo tenants) - Admin access to the Oleria workspace
Standard integrations are configured with read-only permissions. Use a service account (and not an employee account) to create the OAuth2/OpenID Connect client, so the integration keeps working if the employee leaves or changes roles.
Create an OAuth2/OpenID Connect client in Coupa
1
Open OAuth2/OpenID Connect Clients
Log in to Coupa as an administrator, then select Setup -> Integrations -> OAuth2/OpenID Connect Clients.
Menu names can vary slightly by Coupa release. If you don’t see this option, ask your Coupa administrator or Coupa Support to enable it for your instance.
2
Create a new client
Select Create and name the client something recognizable, for example
Oleria Integration.3
Set the grant type
Set Grant Type to Client Credentials. This lets Oleria authenticate directly with Coupa without a user login step.
4
Grant read scopes
Grant the client read access to the following three scopes:
These three scopes are fixed defaults for the Oleria connector and do not depend on which Coupa modules you have licensed. Coupa does not expose a separate scope for roles.
5
Save the client credentials
Save the client. Coupa displays a Client ID and Client Secret - copy both now, since Coupa shows the secret only once.
If you lose the client secret, create a new OAuth2/OpenID Connect client and update the credentials in Oleria.
Connect Coupa to Oleria
1
Open the integration
Go to your Oleria workspace, select Integrations -> select Coupa.
2
Complete the connection form
Select Continue and provide the following:
3
Confirm the connection
Select Authenticate to validate the credentials. Find the newly connected Coupa instance in your Oleria workspace connected integrations.

