Connect NinjaOne
Ledger reads your organizations and devices from NinjaOne's v2 API over an OAuth2 client-credentials app. It never installs an agent, changes a policy, or writes anything back to NinjaOne.
1. Create an API client app in NinjaOne
- Log into your NinjaOne instance as an administrator.
- Go to Administration → Apps → API.
- Create a new API client application using the Client Credentials grant type (not Authorization Code — Ledger runs unattended, with no user in the loop).
- Grant the app the
monitoringscope only. It exposes the organizations and device inventory that Ledger reads. Do not grantmanagement: it allows changing data in NinjaOne and Ledger does not need it. - Copy the Client ID and Client secret NinjaOne generates — the secret is shown once.
2. Pick your region
NinjaOne runs separate regional instances. Use the same region your NinjaOne login URL uses:
| Region | API host |
|---|---|
| US | app.ninjarmm.com |
| US2 | us2.ninjarmm.com |
| EU | eu.ninjarmm.com |
| CA | ca.ninjarmm.com |
| OC | oc.ninjarmm.com |
If you're unsure, check the domain you use to log into the NinjaOne dashboard — it matches one of the hosts above.
3. Add the connection in Ledger
From Connections → Add connection → NinjaOne, fill in:
| Field | Value |
|---|---|
| Region | One of the five regions above |
| Client ID | The Client ID from step 1 |
| Client secret | The Client secret from step 1 |
Ledger exchanges these for an access token against
https://{region host}/ws/oauth/token and tests the connection
immediately. A healthy result means Ledger can list your organizations
and devices; a failure shows the reason NinjaOne gave (credentials are
never included in that message).
Rotating credentials later
If you need to rotate the client secret, generate a new one in NinjaOne and update it from the connection's Rotate credentials action in Ledger — this re-tests the connection with the new secret and never leaves the old one stored.