Prerequisites
- API access enabled on your Iru tenant. In the Iru sidebar, open the Account menu and choose Access. If there is no API tokens tab, ask your Iru Customer Success Manager to enable the Endpoint API first.
- Your organization API URL from the Access › API tokens tab. Iru shows it as a bare hostname such as
yourcompany.api.kandji.io(US) oryourcompany.api.eu.kandji.io(EU). The hostname still useskandji.io; use exactly what your console shows. - A blueprint to use as the pilot target.
- Macs with an assigned user. The profile uses the
$EMAILvariable to attribute each Mac, so Cimento never reads your directory.
Steps
1
Create an API token
On Access › API tokens, click Add Token, name it something like
Cimento Agent Deployment, and click Create. Iru shows the token once; copy it before closing the dialog.2
Grant only the listed permissions
On Manage API Permissions, click Configure. Expand the Blueprints, Library and Devices categories and enable exactly the endpoints in the table below. Leave everything else off and click Save. You can revisit this later by opening the token and clicking Edit.
3
Enter the credentials in Cimento
Under Admin → Integrations → AI agents → Iru, paste the API host with
https:// in front of it, and the token. Both are stored encrypted per tenant and never shown again.4
Verify
Cimento makes read-only calls to confirm the token can authenticate and to list your blueprints.
5
Deploy
Choose a blueprint. Cimento uploads the signed
.pkg as a Custom App and the .mobileconfig as a Custom Profile, assigns both to the blueprint, and triggers the install. Nothing is installed until you click Deploy. The page then tracks install status per Mac.