Third-party login
Starting with TE3.1, AE Root users can bind third-party apps in the System Settings module to:
- Log in by scanning a QR code with the third-party app
- Log in to AE with one click from the third-party app's workbench
- Receive AE updates in the third-party app
Note: This guide doesn't apply to SaaS customers or customers who log in with LDAP authentication.
Follow the steps in this document to enable all of the features above.
Binding to WeCom, DingTalk, or Feishu apps is currently supported. See the relevant section to complete the app binding
1. Bind a third-party app
1.1 WeCom
Step 1: Create an app
A WeCom admin goes to the WeCom Admin Console and creates an app under App Management > Apps > Self-built
- Upload the app logo. To use the AE logo, download it here
- Enter the app name, such as AE Platform
- Enter the app description
- Select the visibility scope. You must add yourself to the visibility scope; only employees within the visibility scope can log in to the AE platform through WeCom authorization
Step 2: Set up access to the AE platform from the WeCom client
Click the app you created. In the Features section at the bottom of the page, click to set the Workbench App Homepage, and in the dialog, enter the app homepage URL: https://your-private-cluster-address/#/login (for example, https://ta.thinkingdata.cn/#/login)
Step 3: Get WeCom account information
At the bottom of the page, go to Developer API > Web Authorization and JS-SDK, click Set Trusted Domain, and enter the trusted domain (your private cluster address) in the dialog. If domain ownership verification is required, follow the prompts
Step 4: Enable WeCom QR code login
Go to Developer API > WeCom Authorized Login and click Settings
On the settings page, select Web > Set Authorization Callback Domain. Enter your private cluster address and click Save.
This completes the setup in the WeCom Admin Console. Complete the following configuration on the AE platform.
Step 5: Bind the WeCom app in AE System Settings
An AE Root user goes to System Settings > General Management > General Configuration, opens the Login Options tab, selects WeCom in the Third-party Application list, and clicks Enable.
- Corp ID: In the WeCom Admin Console, under My Company > Company Info
- AgentId&Secret: On the home page of the app you created
This completes the binding between AE and WeCom.
1.2 DingTalk
Step 1: Create an app
After logging in, a DingTalk organization admin goes to the DingTalk Open Platform and clicks Self-built App under Workbench
Select Enterprise Internal App
- App name: For example, AE Platform
- App description
- App icon: To use the AE logo, download it here
Step 2: Set up access to the AE platform from the DingTalk client workbench
On the details page of the micro app you created, select Development Management, edit the following, and save
- Dev Mode: Quick link
- App homepage URL: https://your-private-cluster-address/#/login, for example, https://ta.thinkingdata.cn/#/login
- PC homepage URL: https://your-private-cluster-address/#/login
Step 3: Get DingTalk login account information
On the current page, click Permission Management, set the permission scope, and add the Member Information Read Permission qyapi_get_member
Step 4: Set the app usage scope & publish the app
Select employees to authorize; only employees within the usage scope can log in to the AE platform through DingTalk authorization
Step 5: Enable DingTalk QR code login
In the Login and Sharing section of the left navigation bar, enter the callback domain
https://your-private-cluster-address/v1/sso/thirdLogin/callback
This completes the setup in the DingTalk admin console. The following steps are the corresponding settings on the AE platform.
Step 6: Bind the DingTalk app in AE System Settings
An AE Root user goes to System Settings > General Management > General Configuration, opens the Login Options tab, selects DingTalk in the Third-party Application list, and clicks Enable
- CorpID: Found on the home page of the DingTalk developer platform
The remaining information can be found in the app credentials
-
Scan login application authorization
- appID: The AppKey
- appSecret: The AppSecret
-
H5 micro app credentials (same as in the image)
- AgentId
- AppKey
- AppSecret
If your app is the new version, the display differs from the old version
-
Scan login application authorization
- appID: The Client ID
- appSecret: The Client Secret
-
H5 micro app credentials
- AgentId: The AgentId of the original enterprise internal app
- AppKey: The Client ID
- AppSecret: The Client Secret
This completes the binding between AE and DingTalk.
1.3 Feishu
Step 1: A Feishu admin goes to the Feishu Open Platform, selects Custom App, and clicks Create Custom App
- App type: Custom App
- App name: For example, AE Platform
- App subtitle
- App icon: To use the AE logo, download it here
Step 2: Set up access to the AE platform from the Feishu client workbench
Click the app you created, then click Features > Web App:
- Click to enable the web app
- Configure the desktop homepage: https://your-private-cluster-address/#/login. For example, https://ta.thinkingdata.cn/#/login
- Configure the mobile homepage: https://your-private-cluster-address/#/login
Step 3: Set up the URL allowlist for the login-free authorization code
Click Security Settings and configure the redirect URL: https://your-private-cluster-address/v1/sso/thirdLogin/callback
Step 4: Configure message receiving
Click Permissions & Scopes and add Obtain user ID (contact:user.employee_id:readonly), Send messages as an app (im:message:send_as_bot), and Send batch messages to multiple users (im:message:send_multi_users)
Click Features > Bot, then click Enable Bot
Step 5: Set the app visibility scope & publish the app
Select employees to authorize; only employees within the visibility scope can log in to the AE platform through Feishu authorization
Versions that involve changes to user permissions must be reviewed by a Feishu admin. A version takes effect only after it is approved and released.
This completes the app setup on the Feishu Open Platform. Complete the following configuration on the AE platform.
Step 6: Bind the Feishu app in AE System Settings
An AE Root user goes to System Settings > General Management > General Configuration, opens the Login Options tab, selects Feishu in the Third-party Application list, and clicks Enable.
- App ID & App Secret: View them in Credentials & Basic Info of the app you created
This completes the binding between AE and Feishu.
2. Bind an AE account
After a Root user binds the AE system to a third-party app, AE members can bind their personal accounts.
2.1 Bind an existing AE account
(1) After logging in, bind on the Account page
An AE member goes to the Account page and binds a personal account: Click Bind on the Account page and scan the QR code to bind the third-party account to the AE account.
- Note: Only members within the app's visibility scope can complete this binding
(2) Bind on the login page
On the AE login page, click the app login entry, scan the QR code, enter your AE account password, and click Bind
2.2 Get an AE account through a third-party app
After a Root user binds the third-party app in System Settings, users can create an AE account by scanning the QR code on the AE login page
- Note: Only members within the app's visibility scope can create an account this way
A newly created account has no project permissions by default. Contact an admin to add the account to a project in Project Settings and complete project authorization.
3. Unbind an account
A third-party account and an AE account are bound one-to-one. If you're told during binding that the account is already bound and you want to switch the binding, unbind the current account and then bind the new one:
(1) Scan the QR code to log in to the bound account
(2) Go to the Account page and remove the current binding
- After unbinding, the account can only be logged in to with the AE account and password. If you continue to use this account, make sure you remember the account name and password
(3) Log in to the AE account to be bound and complete the binding again

