Kandji
Purpose
Gathers Apple device inventory and blueprint assignments from Kandji.
tip
Secret fields below accept either an AWS Secrets Manager ARN or a value pasted directly into SubImage's managed vault. See Secrets for details.
important
If your Kandji tenant is restricted to private IPs, set tailscale_hostname and run the collector from a SubImage Outpost.
Required Fields
| Field | Secret? | Description |
|---|---|---|
kandji_base_uri |
No | Tenant base URI, e.g. https://example.api.kandji.io |
kandji_tenant_id |
No | Tenant ID displayed in your Kandji settings |
kandji_token |
Yes | Kandji API token |
tailscale_hostname |
No | (Optional) Internal hostname resolved via Outpost |
Setup Steps
- In Kandji → Settings → API Token, create a Read-Only token and copy it.
- In SubImage, fill in the fields above (use the token or its AWS Secret ARN for
kandji_token) and save the module.