PSA, RMM & Business Tool Integrations
Integration guide
These are separate from Custom Connectors: each of the 42 below is purpose-built for one specific vendor's real API, rather than a generic template you configure yourself. All 42 share the same interaction model:
- Integrations → [category] → Connect, and fill in that vendor's credential fields (below) — entered once, encrypted at rest, never shown again in plaintext.
- Test Connection calls the vendor's API right then and reports a real pass/fail — it does not just check that fields are non-empty.
- Sync Now pulls that vendor's data (tickets, devices, agents, incidents — whatever the category implies) into Graften, viewable under that integration's Data tab.
None of these use a browser redirect/consent screen — you're entering credentials you generate on the vendor's own side (an API key, a service account, an app registration), not signing in interactively. Two vendors need more than a simple key and are called out below.
PSA & Ticketing
| Vendor | Credential fields |
|---|
| Autotask | integration_code, api_username, api_secret, zone |
| ConnectWise | company_id, public_key, private_key, base_url |
| HaloPSA | subdomain, client_id, client_secret, scope |
| Freshservice | domain, api_key |
| ServiceNow | instance, username, password |
| Jira | domain, email, api_token |
| Zendesk | subdomain, email, api_token |
RMM
| Vendor | Credential fields |
|---|
| NinjaRMM | client_id, client_secret |
| Datto RMM | api_url, api_key, secret_key |
| Atera | api_key |
| N-central | server_url, api_key |
| Kaseya VSA | server_url, username, password |
NinjaRMM devices are attributed to clients through Client Mappings: map each Ninja organisation to a Graften client. A client with several Ninja organisations (for example one per site) can have them all mapped, and every one is synced. If one organisation fails to sync, the others still import, the sync is reported as partial, and the patch history snapshot is skipped rather than recorded from an incomplete device list.
Documentation & Asset Management
| Vendor | Credential fields |
|---|
| IT Glue | region, api_key |
| Hudu | base_url, api_key |
| SharePoint | tenant_id, client_id, client_secret (Azure AD app registration, not delegated user consent) |
| Confluence | base_url, email, api_token |
| Passportal | base_url, api_key |
| Liongard | base_url, access_key, access_secret |
Security & EDR
| Vendor | Credential fields |
|---|
| Huntress | api_key, api_secret |
| SentinelOne | console_url, api_token |
| Sophos Central | client_id, client_secret |
| CrowdStrike | client_id, client_secret, region |
Network & Firewall
| Vendor | Credential fields |
|---|
| Fortinet | base_url, api_token |
| SonicWall | base_url, username, password |
| Meraki | organization_id, api_key |
| WatchGuard | api_key, access_id, access_secret |
Remote Access
| Vendor | Credential fields |
|---|
| AnyDesk | license_id, api_key |
| Splashtop | api_key |
Incident & Monitoring
| Vendor | Credential fields |
|---|
| PagerDuty | api_key |
| Datadog | site, api_key, app_key |
Automation & Infrastructure-as-Code
| Vendor | Credential fields |
|---|
| Azure Automation | tenant_id, client_id, client_secret, subscription_id, resource_group, automation_account |
| Terraform (Cloud/Enterprise) | base_url, organization, api_token |
| AWS Automation (SSM) | access_key_id, secret_access_key, region, session_token (optional) |
HR
| Vendor | Credential fields |
|---|
| BambooHR | subdomain, api_key |
| Rippling | api_key |
| HiBob | service_user_id, token |
| Workday | base_url, token_url, client_id, client_secret |
| Oracle Fusion Cloud HCM | base_url, token_url, client_id, client_secret, scope |
| Cegid HR | base_url, client_id, client_secret |
| ServiceNow HR | instance, username, password |
Two HR connectors need more than the generic form above:
- ADP Workforce Now — OAuth2 client-credentials plus mandatory mutual TLS. Beyond client_id/client_secret you also need the SSL client certificate and private key ADP issues for your registered app — every call to ADP's API, including the token request, is rejected at the TLS layer without it.
- SAP SuccessFactors — OAuth2 SAML bearer assertion: a signed XML SAML 2.0 assertion is exchanged for a bearer token, which needs a certificate and private key from your SuccessFactors app registration, not just a key. Flagged honestly: this connector has not yet been validated against a live SuccessFactors tenant. A subtly wrong assertion fails signature validation with an opaque SAP error that looks identical to a bad credential — if setup doesn't work, that's the first thing to suspect, not a sign the integration is fundamentally broken.
What's not here
Xero and Microsoft 365 have their own guides above — both use real OAuth2 authorization-code flows with a consent screen, not this credential-form model. QuickBooks, Employment Hero and MYOB connect the same authorization-code way (not yet documented here). HubSpot, Salesforce and Microsoft Teams have their own dedicated route families (proposal push, posture sync, inbound webhooks) beyond a simple connect/test/sync — Teams is covered in its own guide above.
API
POST /api/v1/integrations/connect (body: {type, client_id, credentials}), POST /api/v1/integrations/{id}/test, POST /api/v1/integrations/{id}/sync, GET /api/v1/integrations/{id}/data, GET /api/v1/integrations, DELETE /api/v1/integrations/{id}.
Open in the interactive docs