Skip to content

Connect NinjaOne

Ledger reads your organizations and devices from NinjaOne's v2 API over an OAuth2 client-credentials app. It never installs an agent, changes a policy, or writes anything back to NinjaOne.

1. Create an API client app in NinjaOne

  1. Log into your NinjaOne instance as an administrator.
  2. Go to Administration → Apps → API.
  3. Create a new API client application using the Client Credentials grant type (not Authorization Code — Ledger runs unattended, with no user in the loop).
  4. Grant the app the monitoring scope only. It exposes the organizations and device inventory that Ledger reads. Do not grant management: it allows changing data in NinjaOne and Ledger does not need it.
  5. Copy the Client ID and Client secret NinjaOne generates — the secret is shown once.

2. Pick your region

NinjaOne runs separate regional instances. Use the same region your NinjaOne login URL uses:

Region API host
US app.ninjarmm.com
US2 us2.ninjarmm.com
EU eu.ninjarmm.com
CA ca.ninjarmm.com
OC oc.ninjarmm.com

If you're unsure, check the domain you use to log into the NinjaOne dashboard — it matches one of the hosts above.

3. Add the connection in Ledger

From Connections → Add connection → NinjaOne, fill in:

Field Value
Region One of the five regions above
Client ID The Client ID from step 1
Client secret The Client secret from step 1

Ledger exchanges these for an access token against https://{region host}/ws/oauth/token and tests the connection immediately. A healthy result means Ledger can list your organizations and devices; a failure shows the reason NinjaOne gave (credentials are never included in that message).

Rotating credentials later

If you need to rotate the client secret, generate a new one in NinjaOne and update it from the connection's Rotate credentials action in Ledger — this re-tests the connection with the new secret and never leaves the old one stored.