Skip to main content
Cimento authenticates to Jamf Pro as an API Client using the client-credentials flow, uploads the agent package and configuration profile, scopes them to a computer group you choose, and tracks the install per Mac.

Prerequisites

  • Your Jamf Pro instance URL, for example https://yourcompany.jamfcloud.com.
  • A Jamf Pro administrator who can create API Roles and API Clients.
  • A smart or static computer group to use as the pilot target.
  • Macs with an assigned user in Jamf inventory. The profile uses Jamf’s $EMAIL variable to attribute each Mac, so Cimento never reads your directory.

Steps

1

Create an API Role

In Jamf Pro, open Settings › System › API roles and clients › API Roles and create a role named something like Cimento Agent Deployment. Grant exactly the privileges in the table below and leave every other privilege unselected.
2

Create an API Client bound to that role

On the API Clients tab, create a client, assign it the role, enable it, and generate a client secret. Jamf shows the secret once; copy it before closing the dialog.
3

Enter the credentials in Cimento

Under Admin → Integrations → AI agents → Jamf Pro, paste the instance URL, client ID and client secret. All three are stored encrypted per tenant and never shown again.
4

Verify

Cimento makes read-only calls to confirm the client can authenticate and to list your computer groups.
5

Deploy

Choose a computer group. Cimento uploads the signed .pkg as a Package and the .mobileconfig as a macOS Configuration Profile, creates a Policy scoped to the group, and triggers the install. Nothing is installed until you click Deploy. The page then tracks install status per Mac.

Privileges to grant and why

If a privilege is missing, Cimento names the specific one to add, so you can start with this set.

Why a dedicated API Role

A role scoped to this deployment can do only what the deployment needs, and you can revoke Cimento’s access by disabling one API Client.

Disconnecting

Disconnect in Cimento uninstalls the agent from the targeted Macs, removes the package, profile and policy Cimento created, and then deletes the stored credentials.