Skip to content

Connect Datto RMM

Ledger reads your Datto RMM device and site inventory over Datto's public API. It never installs an agent or changes any Datto RMM configuration.

1. Find your platform and create an API key

  1. Log into your Datto RMM console as an administrator.
  2. Note which of the seven Datto RMM platforms your account is hosted on — Datto (not Ledger) assigns this when your account is created. If you don't know it, check your console's URL or ask Datto support.
  3. Generate an API key and secret for your account (Datto calls these API_KEY and API_SECRET).

Datto does not currently document a restricted, least-privilege role specifically for this API. Until that changes, use credentials scoped as narrowly as your Datto RMM account allows for read access to devices and sites.

2. Add the connection in Ledger

From Connections → Add connection → Datto RMM, fill in:

Field Value
Platform Your Datto RMM platform, from step 1
API key The API_KEY from step 1
API secret The API_SECRET from step 1

Ledger tests the connection immediately after you save it.

What Ledger reads

Ledger lists your Datto RMM sites and every device under them (hostname, domain, operating system, last-seen time, last logged-in user, and internal/external IP addresses), solely to reconcile them against what your other tools report for the same devices.

Datto RMM's device list does not carry a hardware serial number, manufacturer, or model. Those details live in each device's separate audit record, which Ledger reads once a week for every device under a connected Datto RMM account (serial number, manufacturer, model and the MAC addresses of its network adapters), again only to reconcile the device against your other tools. Until a device's first audit read has run, it matches against your other sources on weaker signals than serial number.

Rotating credentials later

Generate a new API key/secret pair in Datto RMM, then update it from the connection's Rotate credentials action in Ledger — this re-tests the connection with the new credentials and never leaves the old ones stored.