Skip to content

Connect HaloPSA

Ledger reads your HaloPSA client and asset inventory over HaloPSA's own REST API. It never installs an agent or changes any HaloPSA configuration.

1. Create an API application

  1. Log into HaloPSA as an administrator and go to Configuration → Integrations → Halo API → New.
  2. Set Authentication Method to Client ID and Secret (Services).
  3. Set Login Type to Application identity — a dedicated machine identity with no impersonated Agent, for a cleaner audit trail.
  4. Grant permissions: role User + "Assets Read" (for asset/device inventory) and role Agent + "Customers Read" (for client and site inventory) — these are two different permission tiers, and both are needed. HaloPSA's own documentation does not name a specific permission for the recurring-invoice billing data Ledger reads, so there is no additional permission name to grant here; if billing sync fails with a permissions error, contact HaloPSA support.
  5. Note the generated Client ID and Client Secret, and your tenant's base address (for example https://support.haloservicedesk.com).

2. Add the connection in Ledger

From Connections → Add connection → HaloPSA, fill in:

Field Value
Base URL Your tenant's base address from step 1 — the bare host, the Resource Server URL, or the Authorisation Endpoint URL from Halo's own settings page all work, as long as it starts with https://
Tenant Usually left blank — see below
Scope Usually left blank — see below
Client ID The Client ID from step 1
Client secret The Client Secret from step 1

Tenant and Scope are both optional. HaloPSA's own worked client-credentials example omits both, even though its documentation says a hosted install needs a tenant query parameter. Leave both blank unless HaloPSA support tells you otherwise for your account.

Ledger tests the connection immediately after you save it.

What Ledger reads

Ledger lists your HaloPSA clients and every asset registered against them (MAC address and a handful of internal reference fields). Unlike every other connector Ledger supports, HaloPSA's asset record has no fixed serial number or hostname field at all — those live in per-tenant, admin-configurable custom fields whose names Ledger cannot know in advance. HaloPSA assets are visible in Ledger, but they match your other sources only on a MAC address — a weaker signal than serial number. A shared MAC address never merges a HaloPSA asset into another device automatically: it proposes a match for you to confirm in the review queue, so most HaloPSA assets will show up as their own device until you confirm a proposed match.

Ledger also reads your HaloPSA recurring-invoice billing lines, for count-based billing reconciliation (comparing how many devices you manage for a client against how many you bill them for). Device-level billing reconciliation — matching an individual billing line to the specific device it covers — through configuration links is not available for HaloPSA: HaloPSA's billing lines don't carry a usable device link the way Ledger's other supported PSAs' do. A HaloPSA client's billing is therefore matched by invoice description where enough lines name a device, and compared by count otherwise (see billing reconciliation).

Troubleshooting: 403 despite valid credentials

If your connection test fails with a 403, first confirm the permissions in step 4 above are actually granted; if it persists, contact support.

Rotating credentials later

Generate a new Client Secret from HaloPSA's Integrations page, then update it from the connection's Rotate credentials action in Ledger — this re-tests the connection with the new credentials and never leaves the old ones stored.