Connect ConnectWise Automate
Ledger reads your ConnectWise Automate (LabTech) device and client inventory over Automate's REST API, from your own on-premise or self-hosted Automate instance. It never installs an agent or changes any Automate configuration.
1. Create an API-capable user
- Log into your Automate instance as an administrator.
- Create (or identify) a user account Ledger can authenticate as — a username and password.
ConnectWise does not currently document a restricted, least-privilege role specifically for Automate's REST API the way some other sources offer. Until that changes, use an account scoped as narrowly as your Automate instance allows for read access to computers and clients.
2. Add the connection in Ledger
From Connections → Add connection → ConnectWise Automate, fill in:
| Field | Value |
|---|---|
| Server | Your Automate server's address (host, or host:port) — no https:// prefix |
| Username | The username from step 1 |
| Password | The password from step 1 |
| CA bundle path (optional) | See "Self-signed certificates" below |
Ledger tests the connection immediately after you save it.
Self-signed certificates
On-premise ConnectWise Automate instances commonly use self-signed TLS certificates. Ledger never disables certificate verification globally. If your instance uses a self-signed or internally issued certificate, provide the CA bundle path field with the path to a CA bundle or pinned certificate file Ledger can use to verify your instance specifically — full verification stays on either way, scoped to your certificate rather than turned off.
What Ledger reads
Ledger lists your Automate clients and every computer under them (hostname, domain, serial number, MAC address, operating system, last known user, last-contact time, and local/router IP addresses), solely to reconcile them against what your other tools report for the same devices.
Rotating credentials later
Change the password on the account in Automate, then update it from the connection's Rotate credentials action in Ledger — this re-tests the connection with the new password and never leaves the old one stored.