Skip to main content
To connect AirMDR to runZero to retrieve organization-scoped asset, site, and scan information through the runZero Export API.
runZero states that the Export API provides read-only access to organization data. Organization API access requires a Professional or Platform license, while Account API access requires a Platform license.
Use an Export token unless AirMDR explicitly requires organization-level write operations.
runZero APIs use bearer-token authentication.

Supported token types

Role and access considerations

  • The user generating the token must be permitted to edit the selected runZero organization.
  • Use an organization-scoped Export token for read-only AirMDR operations.
  • Do not use a Download token because it cannot access inventory data.
  • Avoid an Account API token unless there is a confirmed requirement for account-wide access.
  • If using an Account API token, enter the organization’s unique ID in the AirMDR Organization ID field.
  • Restrict API access through the runZero IP allowlist when AirMDR has known static egress addresses.

Pre-requisites

An active runZero organization access.
Permission to edit the selected organization or request a token from a runZero administrator.

Setup Steps

1

Generate a runZero Export token

  1. Sign in to the runZero Console.
    • For the runZero cloud console, use: https://console.runzero.com
    • For a self-hosted deployment, use your organization’s runZero Console URL.
  2. From the runZero navigation menu, select Organizations.
  3. Select the organization that AirMDR must query.
    Export tokens are limited to the organization from which they are generated.
  4. On the organization details page, select Edit organization.
  5. Scroll to the Export tokens section.
  6. Select the option to generate an Export token. If an Export token already exists, runZero may display an option to regenerate it.
    Regenerating a token can invalidate the credential used by existing integrations. Confirm its current usage before regenerating it.
  7. Copy the generated token.
  8. Store the token temporarily in an approved password manager or secrets-management system.
  9. Do not include the token in tickets, screenshots, emails, chat messages, or documentation.
    The token-type section of runZero’s identifies Export tokens with an ET prefix, while some examples on the same page display an XT placeholder.
    Select the token explicitly generated from the organization’s Export tokens section instead of validating it only by its prefix
2

Find the runZero Console URL

  1. Use the URL that your browser uses to access runZero.
  2. Enter only the base console URL. Do not add an API endpoint such as /api/v1.0/export.
    Example: Enter https://console.runzero.com, not https://console.runzero.com/api/v1.0/export/org/assets.json.
3

Find the Organization ID

The Organization ID is normally unnecessary when using an organization-scoped Export token or Organization API token because the organization is encoded in the credential.The Organization ID is required when using an Account API token.To locate it:
  1. Sign in to the runZero Console.
  2. Select Organizations.
  3. Open the organization that AirMDR must query.
  4. Locate the unique organization ID on the organization information page.
  5. Copy the ID without adding spaces.
    Leave the AirMDR Organization ID field empty when using an Export token unless the AirMDR connector validation specifically requires it.
4

Configure the API IP address allowlist

Complete these steps only when the runZero API allowlist is enabled.
  1. Obtain the approved AirMDR egress IP addresses.
  2. In runZero, open Account settings.
  3. Locate API key IP address allowlist.
  4. Add the AirMDR egress IP addresses or CIDR ranges.
  5. Separate multiple values with commas.
  6. Save the account settings.
    Example: 203.0.113.10/32, 203.0.113.11/32
    The allowlist applies to API requests across the runZero console. If AirMDR’s source address is not allowed, runZero rejects the request even when the token is valid. An empty allowlist disables this restriction.

runZero Credential Reference Table

Use an organization-scoped Export token for the AirMDR integration because it provides read-only access to the selected runZero organization. Leave Organization ID empty unless you are using an Account API token or AirMDR validation explicitly requires it.

Validate Connectivity

Use the following request to retrieve the organization’s sites:
Do not run commands containing production tokens on shared systems. Clear the environment variable after testing.

Configure runZero in AirMDR Integrations Dashboard

  1. Navigate to AirMDR, provide the credentials and click Login
  2. Navigate to the AirMDR Integrations Dashboard in the left navigation pane and select ADMIN → Integrations.
  3. Use the search option, enter the keyword “runZero”, select the Connections tab, and click + New Connection button.
  4. Use the following values in the AirMDR integration configuration screen:
  5. Set Verify SSL to true.
  6. Confirm that the API token belongs to the correct runZero organization.
  7. Select Save.
  8. Run the available connection test or a read-only skill to confirm that AirMDR can retrieve data.
    Keep Verify SSL enabled for production connections. Disable certificate validation only for controlled troubleshooting and restore it immediately afterward.

Skills provided by this Integration

These read-only skills retrieve AI asset inventories, discovered tools, and web-domain activity.
When retrieving inventory for a specific system or user, provide hostname or user_email to limit the result set.
These skills retrieve Pluto security issues and write investigation outcomes back to Pluto.
In update_pluto_issue, assignee_emails and assignee_ids replace the existing assignee list. Use clear_assignees to remove all existing assignees.
These read-only skills support investigation of AI coding-agent activity and organization-level audit events.
Pluto rejects Claude Code session-event and agentic-hook queries with a time window greater than 14 days. Use a duration of 14d or less.
These skills manage approval tags, inventory metadata, and organization-level business context.
Pluto returns 403 Forbidden when tagging is disabled for the organization. IDE-extension tags are managed by Pluto and cannot be changed through the API.
Inventory metadata limitations
  • risk_level can be updated only for builder and application entity types.
  • Use comment when updating other supported entity types.
  • Passing an empty business_context value clears the existing business-context field.
  • The business-context value is limited to 4,000 characters.
  • The Pluto-managed org_info field is not modified by the business-context skill.
These skills submit MCP servers or agent skills for scanning and retrieve their results.
To view the details of Input Parameters and Output for the respective skills
  • Go to AirMDR → runZero Integration page.
  • Select the Skills tab and click on the required listed skills.

Additional Information

✅ Do
  • Use an organization-scoped Export token.
  • Follow least-privilege access principles.
  • Keep Verify SSL enabled.
  • Restrict API access to approved AirMDR egress addresses.
  • Store tokens in an approved secrets-management system.
  • Rotate tokens according to your security policy.
  • Review API usage and integration failures regularly.
  • Use separate tokens for production and non-production integrations.
  • Revoke tokens when an integration is decommissioned.
  • Sanitize logs and screenshots before sharing them.
❌ Don’t
  • Using Account API tokens for read-only asset retrieval.
  • Reusing one token across unrelated systems.
  • Including tokens in documentation or support tickets.
  • Storing tokens in source-control repositories.
  • Sending tokens through email or chat.
  • Disabling SSL verification in production.
  • Regenerating a shared token without checking dependencies.
  • Logging the Authorization header.
  • Allowing unrestricted API access when static egress addresses are available.
  • 📧 Contact AirMDR Support through your designated support channel.
  • 🔁 Rotate credentials regularly. Recommended cadence: Every 90 days or as per internal security policy
  • 🔄 Reconnect in AirMDR immediately when API Keys are changed.
AirMDR monitoringReview the AirMDR integration or skill-execution logs for:
  • Connection-test results
  • Authentication failures
  • TLS certificate errors
  • Request timeouts
  • API rate-limit responses
  • Skill execution status
  • Response parsing failures
runZero monitoringDepending on the deployment and permissions, review:
  • API usage headers returned with API responses
  • Account security settings
  • Organization activity or audit information
  • Self-hosted console and reverse-proxy logs
runZero returns the following rate-limit headers:
Illustrative log entriesThe following entries are examples for documentation and may not match the exact AirMDR log format:
Recommended log levels
Never record the API token or complete authorization header in logs.
Data exchangedDepending on the AirMDR skill and requested endpoint, runZero can return:
  • Asset identifiers and names
  • IP and MAC addresses
  • Hostnames
  • Operating-system and hardware details
  • Discovered services
  • Site information
  • Scan information and timestamps
  • Asset attributes, tags, and related inventory metadata
For the standard read-only integration, AirMDR sends:
  • The bearer token in the authorization header
  • The requested API path
  • Optional search or filtering parameters
  • The Organization ID when an Account API token is used
Encryption in transit
  • API communication should use HTTPS.
  • Bearer tokens are transmitted in the HTTPS authorization header.
  • Enable Verify SSL to validate the runZero server certificate.
  • For self-hosted deployments, use a certificate signed by a trusted certificate authority.
Encryption at restThe referenced API guide does not specify a particular encryption-at-rest algorithm for integration data or credentials. Confirm the applicable AirMDR and runZero security controls for your deployment before documenting a specific algorithm.Ports and endpointsCommon Export API endpoints include:
If a self-hosted console uses a non-standard HTTPS port, permit that configured port instead of TCP 443.

Rate-limit recovery

runZero documents a limit of 2,000 requests per five minutes for each source IP address. It also applies a daily limit based on licensed assets.For an HTTP 429 response:
  1. Stop immediate retries.
  2. Read the API usage and remaining-limit headers.
  3. Apply exponential backoff.
  4. Reduce unnecessary requests.
  5. Resume after the applicable limit resets.
Example retry schedule: