Skip to content

Connect Autotask

Ledger reads your Autotask PSA client and configuration-item inventory over Autotask's own REST API. This read connection never installs an agent or changes any Autotask configuration — ticket creation, an entirely separate opt-in connection covered in section 6 below, is the only way this integration ever writes anything to Autotask.

1. Confirm the API license is provisioned

Autotask's REST API needs a separate, free API license type on your account, independent of the security level and tracking identifier below — easy to miss if a setup call focuses only on those two. Confirm with your Autotask administrator (or Datto/Kaseya support) that this license is provisioned before continuing.

2. Create an API-only user

Create (or reuse) a user with the API User (API-only) security level — this is the only Autotask security level that reaches the REST API at all.

3. Build a custom, View-only security level

No stock Autotask security level is read-only for the REST API — the two system levels are full-access and full-access-minus-costs. Build (or reuse) a custom API security level with View on, and Add/Edit/Delete off, scoped to the Companies, ConfigurationItems, and Contracts modules (Autotask supports up to 50 custom API security levels; Contracts also covers the contract-services and service-units data billing reconciliation reads, since Autotask manages all three together through this one module). Apply that level to the API-only user from step 2.

Verify that the level actually blocks writes before relying on it as your sole safeguard.

4. Generate a Custom (Internal Integration) tracking identifier

On that same API-only user, generate a tracking identifier from the Security tab. Autotask offers two kinds:

  • Custom (Internal Integration) — self-generated inside your own Autotask instance, with no request to Datto/Kaseya and no approval queue. Use this one.
  • Vendor-catalog — assigned to a registered Autotask integrations partner from a menu. Ledger does not use this path; never select a vendor-catalog identifier for a Ledger connection.

5. Add the connection in Ledger

From Connections → Add connection → Autotask, fill in:

Field Value
API username (UserName) The API-only user's username from step 2
Secret The API-only user's secret from step 2
Tracking identifier (integration code) The Custom (Internal Integration) tracking identifier from step 4

There is no host or region field to fill in: Ledger discovers your Autotask zone (the correct API host for your database) automatically from your username.

Ledger tests the connection immediately after you save it.

6. Ticket creation (off by default)

Ledger can create a ticket in Autotask for an exception, but only where your account has been enabled for it. It is switched off unless your account has been enabled, and until then the Add connection screen shows no ticket-creation option. You do not need to do anything for it now; in particular, do not create a ticket-creation credential in advance.

If it is enabled for you, a ticket-creation credential is always its own, separate connection with its own API-only user, never the read-only one from step 2. Even then, Ledger only creates a ticket from an exception you choose to act on and, where Autotask allows it, links the affected device's configuration item to it; it never closes or deletes a ticket, and never changes anything else in Autotask. Autotask has no concept of a "board": the ticket-creation dialog's Board list shows your Autotask queues instead. See Tickets.

What Ledger reads

Ledger lists your Autotask companies (clients) and every active configuration item registered against them — serial number, and, when an RMM integration is syncing into Autotask, a hostname and MAC address.

Autotask configuration items carry a serial number field but no operating-system field at all, and hostname is available only when a third-party RMM (for example Datto RMM) is integrated and syncing device-audit data into Autotask — a configuration item with no RMM integration is normal, not an error, and simply has no hostname in Ledger. Devices without an RMM-synced hostname or MAC address match your other sources on serial number alone, and only when the serial is long and distinctive enough to be reliable; otherwise they appear as separate devices until you confirm the match in the review queue.

Billing. Ledger reads your Recurring Service contracts (Contracts, contract services, and service units) and reconciles them against your device inventory. When a contract service's configuration items are linked to it, Ledger reconciles that service's billed quantity device-by-device against the specific devices those configuration items resolve to; when no configuration items are linked, Ledger falls back to matching invoice descriptions to devices and otherwise compares counts (billed quantity vs. managed-device count), the same fallback it uses for PSAs that carry no device-level link at all (see billing reconciliation). A contract stays in Ledger's billing view until its own end date passes, regardless of its status in Autotask.

Rotating credentials later

Generate a new secret for the API-only user in Autotask, then update it from the connection's Rotate credentials action in Ledger — this re-tests the connection with the new credentials and never leaves the old ones stored.