QUALTRICS_DATACENTER, QUALTRICS_CLIENT_ID, QUALTRICS_CLIENT_SECRET), or QUALTRICS_DATACENTER plus QUALTRICS_API_TOKEN if you use a token instead.
Scope of this integration today. ConfigView reads who has a Qualtrics account and on which user type, who is a Brand Administrator, when each person last logged in, who is allowed to use the Qualtrics API, your divisions and groups and who is in them, the brand’s license expiry and login statistics, the event subscriptions (webhooks) that push survey events to other systems, and the brand’s activity log of sign-ins and permission changes. ConfigView never reads surveys, questions, responses, contacts, mailing lists or dashboards, and never creates or changes anything.
Step 1: Open the Qualtrics page in ConfigView
Open ConfigView in a second browser tab and leave it open:https://{companyname}.configview.com/admin/integrations/qualtrics
Qualtrics shows the OAuth client secret once, when you create the client, so paste it straight into ConfigView.
Step 2: Find your datacenter ID
- Sign in to Qualtrics as a Brand Administrator
- Open the account menu (top right) → Account Settings → Qualtrics IDs
- In the User box, copy the Datacenter ID (for example
iad1,fra1,syd1) - Paste it into
QUALTRICS_DATACENTERin ConfigView and click the save icon
yourbrand.iad1.qualtrics.com) also works. Use your brand’s home datacenter: calls to another one are slower, and an OAuth client only gets tokens from the datacenter it was created in.
Step 3: Create a read-only OAuth client
Every list ConfigView reads is a Brand Administrator call, and an OAuth client acts as the user who creates it. So create it as a Brand Administrator, ideally a long-lived admin account rather than a person who might leave.- Still in Account Settings → Qualtrics IDs, open OAuth Client Manager (on some brands it is in the OAuth section) and click Create Client
- Name it
ConfigViewand add your IT contact email - Set the grant type to Client Credentials
- Add these scopes and nothing else:
- Click Create client and copy the Client ID and Client Secret. Qualtrics will not show the secret again
- Paste them into
QUALTRICS_CLIENT_IDandQUALTRICS_CLIENT_SECRETin ConfigView and click the save icon for each
manage:all.
Using an API token instead. If your brand cannot create OAuth clients, a Brand Administrator can use Account Settings → Qualtrics IDs → API → Generate Token and paste it into QUALTRICS_API_TOKEN. The token carries all of that admin’s rights, including changes, and generating a new one immediately breaks anything still using the old one. ConfigView ignores the token when the OAuth client ID and secret are set.
Activity log access. Reading the activity log also needs the admin’s account to have Qualtrics’ activity log (audit) access, which some licenses include and others add on. Without it, only the Activity Log collector skips.
To revoke ConfigView’s access, delete the client in OAuth Client Manager (or generate a new API token).
Step 4: Connect and verify
- Back on
https://{companyname}.configview.com/admin/integrations/qualtrics, confirm the credentials show as saved - Click Connect. ConfigView creates its tables and schedules every collector at your default run time. Stop any you don’t want under Collectors:
- Click Verify now. The health check confirms the secrets, gets a token, checks who the client is connected as and whether that is a Brand Administrator, reads a page of users, then reports groups, event subscriptions, the activity log and the brand details as ok or skipped.
- Token request fails with
invalid_client. The client ID or secret is wrong, or the client was created in a different datacenter thanQUALTRICS_DATACENTER. - Token request fails with
invalid_scopeonread:users. The client was created withoutread:users. Edit the client’s scopes or create a new one. /usersreturns 403. The client (or token) belongs to someone who is not a Brand Administrator. Recreate it as a Brand Administrator.- A collector is skipped with “not granted read:…”. That scope is missing from the client. Add it if you want that data.
- Activity Log skipped with 403. The admin’s license doesn’t include activity log access.
- 429. Qualtrics’ per-brand limit is spent for the moment, usually by a survey export or another integration. The next run will be fine.
Data Tables
Once the scripts run, these tables are created in your database. Each includes arun_at column. Snapshot tables keep only the newest run.
user_type is Qualtrics’ user type ID. Qualtrics’ built-in types get a name in user_type_name (for example UT_BRANDADMIN is Brand Administrator, UT_PARTICIPANT is Participant). Types your brand created have IDs like UT_4dSkJx0YwB2nQ1a. The API doesn’t return their names, so user_type_name is empty. Look the ID up under Admin → User Types.
api_access is 1 when the user’s Access API permission is on, so they can generate an API token. permissions_on lists every permission switched on for the user.
Things worth knowing
User Details refresh in rotation. The users list has no last-login date, so ConfigView reads one user at a time and refreshes up to 1,500 a run (QUALTRICS_DETAIL_LOOKUPS_PER_RUN), never-seen and stalest first. A 20,000-account university brand is fully refreshed every 14 runs. run_at on that table is when each person’s row was last refreshed, and people deleted from Qualtrics are removed from it.
The activity log is a permanent ledger. Qualtrics keeps activity logs for a limited time. ConfigView stores each event once and never prunes. The first run reaches back 30 days (QUALTRICS_ACTIVITY_BACKFILL_DAYS), and later runs continue from the newest stored event. By default it reads sign-ins, user changes, user and role permission changes, role membership changes and brand setting changes. API-call events (api_access) are left out because there is one per API call. Add them with QUALTRICS_ACTIVITY_TYPES if you want to see which accounts use the API.
API calls are shared with your other integrations. Qualtrics allows 3,000 calls a minute per brand across every integration, and fewer on some endpoints (groups 600, event subscriptions 120, brand details 5). ConfigView paces itself at a fraction of each.
Divisions come from your users and groups. Qualtrics has no “list divisions” call, so ConfigView reads the divisions your users and groups belong to. An empty division with no users or groups isn’t collected.
What isn’t collected
- Surveys, survey questions and flows, responses, response exports, files and quotas
- Contacts, mailing lists, XM Directory data, distributions and samples
- Dashboards, reports and tickets
- Full event subscription URLs (only the host is kept, since URLs can carry tokens)
- Password hashes and the sign-in URL from activity-log events; password change and reset events aren’t requested
- API tokens and OAuth secrets of any user