setup

Kandji

Purpose

Gathers Apple device inventory and blueprint assignments from Kandji.

tip

Secret fields below accept either an AWS Secrets Manager ARN or a value pasted directly into SubImage's managed vault. See Secrets for details.

important

If your Kandji tenant is restricted to private IPs, set tailscale_hostname and run the collector from a SubImage Outpost.

Required Fields

Field Secret? Description
kandji_base_uri No Tenant base URI, e.g. https://example.api.kandji.io
kandji_tenant_id No Tenant ID displayed in your Kandji settings
kandji_token Yes Kandji API token
tailscale_hostname No (Optional) Internal hostname resolved via Outpost

Setup Steps

  1. In Kandji → Settings → API Token, create a Read-Only token and copy it.
  2. In SubImage, fill in the fields above (use the token or its AWS Secret ARN for kandji_token) and save the module.