> ## Documentation Index
> Fetch the complete documentation index at: https://msprecapp.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Endpoint security integrations in MSP Recapp

> Connect endpoint protection and threat detection tools to sync agents, sites, and coverage data — and surface gaps across your client base.

Endpoint security integrations pull agent and coverage data from your protection platforms into MSP Recapp. Once synced, you can map which devices across your RMM or PSA have — or are missing — endpoint protection, helping you identify coverage gaps before they become incidents.

<Note>
  Endpoint security data in Recapp is used for coverage analysis. Recapp does not modify threat policies, quarantine files, or take any action inside your security platforms.
</Note>

## Available endpoint security integrations

<AccordionGroup>
  <Accordion title="SentinelOne">
    **Syncs:** Agents, Threats, Applications, Policies

    SentinelOne connects via a management console API token. Recapp syncs your SentinelOne sites and their associated agents to give you full visibility into endpoint coverage.

    **Required credentials**

    | Field        | Description                                                                           |
    | ------------ | ------------------------------------------------------------------------------------- |
    | Instance URL | Your SentinelOne management console URL, e.g. `https://usea1-xxx.sentinelone.net`     |
    | API Token    | Your SentinelOne API token — generated in **Settings → Users → API Token Generation** |
  </Accordion>

  <Accordion title="Huntress">
    **Syncs:** Organizations, Agents

    Huntress is a managed detection and response (MDR) platform. Recapp connects via the Huntress API using a key and secret pair to sync your organizations and their agents.

    **Required credentials**

    | Field      | Description                                                                              |
    | ---------- | ---------------------------------------------------------------------------------------- |
    | API Key    | Your Huntress API key, found in **Settings → API Credentials** in the Huntress dashboard |
    | API Secret | Your Huntress API secret from the same location                                          |
  </Accordion>

  <Accordion title="Sophos Central">
    **Syncs:** Tenants, Endpoints

    Sophos Central uses an OAuth 2.0 client credentials flow scoped to your MSP partner account. Recapp syncs your managed tenants and their associated endpoints.

    **Required credentials**

    | Field         | Description                                                                                                                                |
    | ------------- | ------------------------------------------------------------------------------------------------------------------------------------------ |
    | Client ID     | Your Sophos Central API Client ID — create API credentials under **Global Settings → API Credentials** in the Sophos Central admin console |
    | Client Secret | Your Sophos Central API Client Secret from the same location                                                                               |

    <Note>
      After a successful connection test, Recapp displays the detected account type, account ID, and data region. Confirm these match your Sophos Central partner account before saving.
    </Note>
  </Accordion>

  <Accordion title="Webroot">
    **Syncs:** Endpoints, Threats, Console Users

    Webroot connects via the Webroot Unity API, which requires five separate credentials: a login email, password, OAuth client ID, client secret, and a GSM keycode.

    **Required credentials**

    | Field             | Description                                                                    |
    | ----------------- | ------------------------------------------------------------------------------ |
    | Username (Email)  | Your Webroot GSM console login email                                           |
    | Password          | Your Webroot GSM console password                                              |
    | Client ID         | Your Webroot Unity API Client ID                                               |
    | Client Secret     | Your Webroot Unity API Client Secret                                           |
    | GSM Key (Keycode) | Your GSM keycode — found under **Account Settings** in the Webroot GSM Console |
  </Accordion>

  <Accordion title="ThreatLocker">
    **Syncs:** Agents, Sites, Policies

    ThreatLocker is a zero-trust endpoint security platform. Recapp connects via the ThreatLocker Portal API using an API token. You can optionally specify your portal instance to target the correct regional endpoint.

    **Required credentials**

    | Field           | Description                                                                                                                                         |
    | --------------- | --------------------------------------------------------------------------------------------------------------------------------------------------- |
    | Portal Instance | Your ThreatLocker instance letter (a–z), a hostname like `portalapi.b`, or a full Portal API URL. Leave blank to use the default failover endpoint. |
    | API Token       | Your ThreatLocker Portal API token — found in **ThreatLocker Portal → Settings → API**                                                              |

    <Tip>
      If you're unsure of your instance letter, check the URL you use to access the ThreatLocker portal. The instance letter appears in the subdomain, e.g. `portalapi.b.threatlocker.com`.
    </Tip>
  </Accordion>

  <Accordion title="Field Effect">
    **Syncs:** Accounts, Endpoints, Threats

    Field Effect is a managed security service. Recapp connects with a single API key to sync your accounts and their associated endpoints.

    **Required credentials**

    | Field   | Description                                                                        |
    | ------- | ---------------------------------------------------------------------------------- |
    | API Key | Your Field Effect API key — found in **Settings → API** in the Field Effect portal |
  </Accordion>

  <Accordion title="Datto EDR">
    **Syncs:** Locations, Agents

    Datto EDR (formerly Infocyte) is an endpoint detection and response platform. Recapp connects via the Datto EDR API using a URL and API key.

    **Required credentials**

    | Field   | Description                                                                                       |
    | ------- | ------------------------------------------------------------------------------------------------- |
    | API URL | Your Datto EDR API endpoint URL, including `/api` at the end, e.g. `https://api.dattoedr.com/api` |
    | API Key | Your Datto EDR API key                                                                            |

    <Note>
      The API URL varies by Datto EDR instance. If you are on a custom or regional instance (e.g. an `.infocyte.com` subdomain), use that instance's `/api` endpoint instead of the default.
    </Note>
  </Accordion>

  <Accordion title="Zorus">
    **Syncs:** Customers, Endpoints

    Zorus provides DNS filtering and web security for MSPs. Recapp connects via the Zorus API using a single API token to sync your customers and their associated endpoints.

    **Required credentials**

    | Field     | Description                                                      |
    | --------- | ---------------------------------------------------------------- |
    | API Token | Your Zorus API token — obtain it from the Zorus developer portal |
  </Accordion>
</AccordionGroup>

## Coverage gap detection

Once you have endpoint security integrations synced alongside your RMM or PSA, you can use Recapp's reconciliation view to identify devices that appear in your RMM but have no matching agent in your endpoint security platform — and vice versa. This highlights unprotected endpoints and orphaned agents before your next client review.
