Configure the Connection
- how-to
Set up a connection between Tableau and Enterprise Analytics using the Couchbase Tableau Connector.
Set Up the Connection
To set up a connection between Tableau and Enterprise Analytics:
-
Open Tableau Desktop.
-
Go to .
-
Select a Couchbase Tableau Connector. If there are multiple connectors installed, select the one that is compatible with Enterprise Analytics.
-
In the connection dialog, enter the following details:
Server The host and port details. The default HTTP port is
8095, while the default HTTPS/TLS port is18095.Scope (Optional) The scope to extract data from. You can leave this field blank or use
Defaultif your data is in the default scope.Authentication The authentication method to use for the connection.
Based on the authentication method you select, the required fields differ.
Authentication Method Required Fields Description Username and Password
Username, Password
Enter user credentials.
LDAP
Username, Password
Enter LDAP credentials.
Client Certificate
Client Certificate
Select the client certificate mode. You can select either
PEM Files (Certificate + Key)orKeystore (JKS/PKCS12).OAuth 2.0
OAuth Provider
Select the OAuth provider from the list. The list contains the default Keycloak configuration and any custom configurations you created. For more information, see Create a Custom Configuration File.
To use OAuth 2.0 authentication, you need:
-
Tableau Connector 2.0 or later
-
Enterprise Analytics 2.2 or later
-
An Identity Provider (IdP)
-
A custom XML configuration file
For more information, see OAuth 2.0 Authentication.
-
-
(Optional) Select the Require SSL option, if required.
To set up SSL support, see:
-
For advanced settings, click the Advanced tab. You can set the connection timeout and scan consistency mode. If you set the scan consistency to
Request plus, a dropdown appears to select the scan wait time. -
Click Sign In.
OAuth 2.0 Authentication
The Tableau Connector 2.0 supports OAuth 2.0 authentication for Enterprise Analytics 2.2 and later.
This authentication method uses an external Identity Provider (IdP) to issue an JSON Web Token (JWT). When you initiate a connection, the Tableau Connector opens a browser window for you to log in to the IdP. After you log in, the connector retrieves the access token and passes it to the JDBC driver to authenticate your connection.
Tableau manages token refreshing automatically, so you do not need to manually refresh the token.
To use OAuth 2.0 authentication, you need to:
Get IdP Details
The following table lists the IdP details you need to set up OAuth 2.0 authentication.
| Item | Description |
|---|---|
Identity Provider (IdP) |
An OIDC-compliant IdP must be running and accessible from Tableau. For example: |
Issuer URL |
The base OIDC discovery URL of your IdP realm. |
Public Client ID |
A public OIDC client registered on your IdP that:
|
Scopes |
The registered client must have at least the following scopes enabled:
You can add additional scopes as well. |
User Account |
A valid user account on the IdP and the same user must be registered as an external user on Couchbase. |
Once you’ve established these details, create a custom configuration file.
Create a Custom Configuration File
To connect Tableau to your IdP, you must provide your client ID, authentication endpoints, and other IdP settings. You can provide this information in a custom XML configuration file.
Once you add the file to the correct location, Tableau automatically loads it and displays your IdP in the authentication dropdown (see Set Up the Connection).
The Tableau Connector ZIP archive includes pre-filled templates for Keycloak, Okta, Azure AD and AuthO in the OAuthConfigs-templates/ directory.
You can use these templates to create your own custom configuration file.
| The Tableau Connector (.taco) file includes a default Keycloak configuration (displayed as Keycloak in the authentication dropdown), but with an empty client ID. To use it, you must provide your own client ID. |
Configure the XML File
Open a template file in a text editor and update the attributes using the following rules:
| If you do not follow these exactly, Tableau silently ignores the file and your configuration options do not appear in the connection dialog. |
-
Set the plugin class: Set
dbclasstoenterprise-analytics. This links the configuration to the correct connector and must match the exact plugin class of your taco. -
Prefix the configuration ID: The
oauthConfigIdattribute must start withcustom_. For example,custom_myidp. -
Format redirect URIs: Use a separate
<redirectUrisDesktop>element for each redirect URI. Do not combine multiple URIs in a single element. -
Use absolute URLs: Provide full, absolute URLs for the
authUriandtokenUrielements. Tableau does not support OIDC discovery in override files.For information about these endpoints, see your IdP documentation.
The following is an example of a complete XML file for a custom IdP.
<?xml version="1.0" encoding="utf-8"?>
<pluginOAuthConfig>
<dbclass>enterprise-analytics</dbclass>
<oauthConfigId>custom_myidp</oauthConfigId>
<configLabel>My IdP (my org)</configLabel>
<clientIdDesktop>YOUR_CLIENT_ID</clientIdDesktop>
<redirectUrisDesktop>http://localhost:55555/Callback</redirectUrisDesktop>
<redirectUrisDesktop>http://localhost:55556/Callback</redirectUrisDesktop>
<redirectUrisDesktop>http://localhost:55557/Callback</redirectUrisDesktop>
<redirectUrisDesktop>http://localhost:55558/Callback</redirectUrisDesktop>
<redirectUrisDesktop>http://localhost:55559/Callback</redirectUrisDesktop>
<authUri>https://YOUR_IDP_HOST/oauth2/authorize</authUri>
<tokenUri>https://YOUR_IDP_HOST/oauth2/token</tokenUri>
<scopes>openid</scopes>
<scopes>offline_access</scopes>
<capabilities>
<entry><key>OAUTH_CAP_REQUIRE_PKCE</key><value>true</value></entry>
<entry><key>OAUTH_CAP_PKCE_REQUIRES_CODE_CHALLENGE_METHOD</key><value>true</value></entry>
<entry><key>OAUTH_CAP_FIXED_PORT_IN_CALLBACK_URL</key><value>true</value></entry>
<entry><key>OAUTH_CAP_SUPPORTS_GET_USERINFO_FROM_ID_TOKEN</key><value>true</value></entry>
</capabilities>
<accessTokenResponseMaps>
<entry><key>ACCESSTOKEN</key><value>access_token</value></entry>
<entry><key>REFRESHTOKEN</key><value>refresh_token</value></entry>
<entry><key>access-token-expires-in</key><value>expires_in</value></entry>
<entry><key>id-token</key><value>id_token</value></entry>
</accessTokenResponseMaps>
<refreshTokenResponseMaps>
<entry><key>ACCESSTOKEN</key><value>access_token</value></entry>
<entry><key>REFRESHTOKEN</key><value>refresh_token</value></entry>
<entry><key>access-token-expires-in</key><value>expires_in</value></entry>
<entry><key>id-token</key><value>id_token</value></entry>
</refreshTokenResponseMaps>
</pluginOAuthConfig>
For more information about the XML, see Tableau OAuth Configuration and Usage.
Save the XML File
Name your XML file (for example, enterprise-analytics-okta.xml) and save it in one of the following locations.
-
Windows:
%USERPROFILE%\Documents\My Tableau Repository\OAuthConfigs\ -
macOS:
~/Documents/My Tableau Repository/OAuthConfigs/
After you save the XML file, restart Tableau.
Tableau loads all .xml files from these directories on startup.
When you open the connection dialog, your custom IdP configuration appears in the authentication dropdown.
Connect Tableau Desktop to Tableau Server
You can publish reports and dashboards created on Tableau Desktop to Tableau Server.
To configure your Tableau Server connection:
-
In Tableau Desktop, go to .
-
Sign in with your Tableau Server credentials.
After you sign in, the connection appears in the Server section.
| If you’re using an on-premise instance of Tableau Server, you need to configure SSL. You can do this by logging into the Tableau Services Manager UI and going to . |
For more information about configuring SSL on your Tableau Server, see Configuring SSL on Tableau Server.