Purpose
Purpose
Supported Versions
Supported Versions
Authentication
Authentication
Supported token types
Role and access considerations
- The user generating the token must be permitted to edit the selected runZero organization.
- Use an organization-scoped Export token for read-only AirMDR operations.
- Do not use a Download token because it cannot access inventory data.
- Avoid an Account API token unless there is a confirmed requirement for account-wide access.
- If using an Account API token, enter the organization’s unique ID in the AirMDR Organization ID field.
- Restrict API access through the runZero IP allowlist when AirMDR has known static egress addresses.
Pre-requisites
An active runZero organization access.Permission to edit the selected organization or request a token from a runZero administrator.
Setup Steps
Generate a runZero Export token
-
Sign in to the runZero Console.
- For the runZero cloud console, use: https://console.runzero.com
- For a self-hosted deployment, use your organization’s runZero Console URL.
- From the runZero navigation menu, select Organizations.
-
Select the organization that AirMDR must query.
Export tokens are limited to the organization from which they are generated.
- On the organization details page, select Edit organization.
- Scroll to the Export tokens section.
- Select the option to generate an Export token. If an Export token already exists, runZero may display an option to regenerate it.
- Copy the generated token.
- Store the token temporarily in an approved password manager or secrets-management system.
-
Do not include the token in tickets, screenshots, emails, chat messages, or documentation.
The token-type section of runZero’s identifies Export tokens with an
ETprefix, while some examples on the same page display anXTplaceholder.Select the token explicitly generated from the organization’s Export tokens section instead of validating it only by its prefix
Find the runZero Console URL
- Use the URL that your browser uses to access runZero.
- runZero Cloud: https://console.runzero.com
- Self-hosted runZero: https://runzero.example.com
- Enter only the base console URL. Do not add an API endpoint such as
/api/v1.0/export.
Example: Enterhttps://console.runzero.com, nothttps://console.runzero.com/api/v1.0/export/org/assets.json.
Find the Organization ID
- Sign in to the runZero Console.
- Select Organizations.
- Open the organization that AirMDR must query.
- Locate the unique organization ID on the organization information page.
- Copy the ID without adding spaces.
Leave the AirMDR Organization ID field empty when using an Export token unless the AirMDR connector validation specifically requires it.
Configure the API IP address allowlist
- Obtain the approved AirMDR egress IP addresses.
- In runZero, open Account settings.
- Locate API key IP address allowlist.
- Add the AirMDR egress IP addresses or CIDR ranges.
- Separate multiple values with commas.
- Save the account settings.
Example: 203.0.113.10/32, 203.0.113.11/32The allowlist applies to API requests across the runZero console. If AirMDR’s source address is not allowed, runZero rejects the request even when the token is valid. An empty allowlist disables this restriction.
runZero Credential Reference Table
Validate Connectivity
Use the following request to retrieve the organization’s sites:Sample Request
Sample Request
Sample Response
Sample Response
Configure runZero in AirMDR Integrations Dashboard
- Navigate to AirMDR, provide the credentials and click Login
- Navigate to the AirMDR Integrations Dashboard in the left navigation pane and select ADMIN → Integrations.
- Use the search option, enter the keyword “runZero”, select the Connections tab, and click + New Connection button.
- Use the following values in the AirMDR integration configuration screen:
- Set Verify SSL to
true. - Confirm that the API token belongs to the correct runZero organization.
- Select Save.
- Run the available connection test or a read-only skill to confirm that AirMDR can retrieve data.
Skills provided by this Integration
Inventory and Discovery
Inventory and Discovery
hostname or user_email to limit the result set.Issue Investigation and Response
Issue Investigation and Response
update_pluto_issue, assignee_emails and assignee_ids replace the existing assignee list. Use clear_assignees to remove all existing assignees.AI Agent Activity and Audit
AI Agent Activity and Audit
14d or less.Governance and Inventory Management
Governance and Inventory Management
risk_levelcan be updated only forbuilderandapplicationentity types.- Use
commentwhen updating other supported entity types. - Passing an empty
business_contextvalue clears the existing business-context field. - The business-context value is limited to 4,000 characters.
- The Pluto-managed
org_infofield is not modified by the business-context skill.
AI Add-on Security Scanning
AI Add-on Security Scanning
Additional Information
🛑 Security & Access Best Practices
🛑 Security & Access Best Practices
- Use an organization-scoped Export token.
- Follow least-privilege access principles.
- Keep Verify SSL enabled.
- Restrict API access to approved AirMDR egress addresses.
- Store tokens in an approved secrets-management system.
- Rotate tokens according to your security policy.
- Review API usage and integration failures regularly.
- Use separate tokens for production and non-production integrations.
- Revoke tokens when an integration is decommissioned.
- Sanitize logs and screenshots before sharing them.
- Using Account API tokens for read-only asset retrieval.
- Reusing one token across unrelated systems.
- Including tokens in documentation or support tickets.
- Storing tokens in source-control repositories.
- Sending tokens through email or chat.
- Disabling SSL verification in production.
- Regenerating a shared token without checking dependencies.
- Logging the
Authorizationheader. - Allowing unrestricted API access when static egress addresses are available.
👉 Support & Maintenance
👉 Support & Maintenance
- 📧 Contact AirMDR Support through your designated support channel.
- 🔁 Rotate credentials regularly. Recommended cadence: Every 90 days or as per internal security policy
- 🔄 Reconnect in AirMDR immediately when API Keys are changed.
🔄 Monitoring & Logs
🔄 Monitoring & Logs
- Connection-test results
- Authentication failures
- TLS certificate errors
- Request timeouts
- API rate-limit responses
- Skill execution status
- Response parsing failures
- API usage headers returned with API responses
- Account security settings
- Organization activity or audit information
- Self-hosted console and reverse-proxy logs
🛑 Data Flow & Security
🛑 Data Flow & Security
- Asset identifiers and names
- IP and MAC addresses
- Hostnames
- Operating-system and hardware details
- Discovered services
- Site information
- Scan information and timestamps
- Asset attributes, tags, and related inventory metadata
- The bearer token in the authorization header
- The requested API path
- Optional search or filtering parameters
- The Organization ID when an Account API token is used
- API communication should use HTTPS.
- Bearer tokens are transmitted in the HTTPS authorization header.
- Enable Verify SSL to validate the runZero server certificate.
- For self-hosted deployments, use a certificate signed by a trusted certificate authority.
🧰 Error Handling
🧰 Error Handling
Rate-limit recovery
runZero documents a limit of 2,000 requests per five minutes for each source IP address. It also applies a daily limit based on licensed assets.For an HTTP429 response:- Stop immediate retries.
- Read the API usage and remaining-limit headers.
- Apply exponential backoff.
- Reduce unnecessary requests.
- Resume after the applicable limit resets.

