> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cimento.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Deploy Agent Hub with Iru

> Create a least-privilege Iru (formerly Kandji) API token so Cimento can deploy the endpoint agent to a blueprint, with every endpoint permission explained.

Cimento authenticates to Iru (the platform formerly known as Kandji) with a bearer API token, uploads the agent package as a Custom App and the configuration profile as a Custom Profile, assigns both to a blueprint you choose, and tracks the install per Mac.

## Prerequisites

* API access enabled on your Iru tenant. In the Iru sidebar, open the **Account** menu and choose **Access**. If there is no **API tokens** tab, ask your Iru Customer Success Manager to enable the Endpoint API first.
* Your organization API URL from the **Access › API tokens** tab. Iru shows it as a bare hostname such as `yourcompany.api.kandji.io` (US) or `yourcompany.api.eu.kandji.io` (EU). The hostname still uses `kandji.io`; use exactly what your console shows.
* A blueprint to use as the pilot target.
* Macs with an assigned user. The profile uses the `$EMAIL` variable to attribute each Mac, so Cimento never reads your directory.

## Steps

<Steps>
  <Step title="Create an API token">
    On **Access › API tokens**, click **Add Token**, name it something like `Cimento Agent Deployment`, and click **Create**. Iru shows the token once; copy it before closing the dialog.
  </Step>

  <Step title="Grant only the listed permissions">
    On **Manage API Permissions**, click **Configure**. Expand the **Blueprints**, **Library** and **Devices** categories and enable exactly the endpoints in the table below. Leave everything else off and click **Save**. You can revisit this later by opening the token and clicking **Edit**.
  </Step>

  <Step title="Enter the credentials in Cimento">
    Under **Admin → Integrations → AI agents → Iru**, paste the API host with `https://` in front of it, and the token. Both are stored encrypted per tenant and never shown again.
  </Step>

  <Step title="Verify">
    Cimento makes read-only calls to confirm the token can authenticate and to list your blueprints.
  </Step>

  <Step title="Deploy">
    Choose a blueprint. Cimento uploads the signed `.pkg` as a Custom App and the `.mobileconfig` as a Custom Profile, assigns both to the blueprint, and triggers the install. Nothing is installed until you click **Deploy**. The page then tracks install status per Mac.
  </Step>
</Steps>

## Permissions to enable and why

Iru labels these by endpoint under a category heading, so the wording in your console may differ slightly from the paths below.

### Blueprints

| Endpoint | Purpose |
| - | - |
| `GET /blueprints` | Lists the blueprints you pick a deployment target from. |
| `GET /blueprints/{id}/list-library-items` | Checks that the agent's app and profile are still attached to the blueprint, so the deployment can report whether it is live. |
| `POST /blueprints/{id}/assign-library-item` | Attaches the agent's app and profile to the blueprint. |
| `POST /blueprints/{id}/remove-library-item` | Detaches them when you change the deployment target, and when you disconnect. |

### Library

| Endpoint | Purpose |
| - | - |
| `POST /library/custom-apps/upload` | Uploads the agent package to your library. |
| `POST /library/custom-apps` | Creates the Custom App that installs the agent. |
| `PATCH /library/custom-apps/{id}` | Updates that Custom App in place on each new release, instead of adding another copy. |
| `POST /library/custom-profiles` | Creates the Custom Profile carrying the agent's configuration. |
| `PATCH /library/custom-profiles/{id}` | Updates that profile in place on later releases. |
| `GET /library/library-items/{id}/status` | Reads how many Macs in the blueprint have the agent installed. |

### Devices

| Endpoint | Purpose |
| - | - |
| `GET /devices` | Lists the Macs in the target blueprint so install progress can be shown per device. |

### Needed only to disconnect

| Endpoint | Purpose |
| - | - |
| `GET /library/custom-scripts` | Finds an uninstall script Cimento created previously. |
| `POST /library/custom-scripts` | Creates the script that uninstalls the agent. |
| `PATCH /library/custom-scripts/{id}` | Updates that uninstall script when one already exists. |
| `DELETE /library/custom-apps/{id}` | Removes the Custom App Cimento created. |
| `DELETE /library/custom-profiles/{id}` | Removes the Custom Profile Cimento created. |
| `DELETE /library/custom-scripts/{id}` | Removes the uninstall script once it has run. |
| `POST /devices/{id}/action/dailycheckin` | Asks a Mac to check in now rather than waiting for its next daily check-in. |

## Why a dedicated token

A token scoped to this deployment can do only what the deployment needs, and you can revoke Cimento's access by deleting one token.

## Disconnecting

**Disconnect** in Cimento runs the uninstall script on the targeted Macs, removes the Custom App, Custom Profile and script Cimento created, and then deletes the stored credentials.
