Skip to content

Connect SentinelOne

Ledger reads your SentinelOne sites and agents over the management console's REST API. It never installs an agent, quarantines anything, or changes any SentinelOne policy.

SentinelOne's model: Account → Site → Group

SentinelOne organizes devices as Account → Site → Group. Ledger maps each Site onto one of your Ledger clients — this is the level MSPs usually bill and report at. Accounts exist in SentinelOne purely for display grouping (one console can host multiple accounts) and Ledger uses them only to label which account a site belongs to.

1. Generate an API token

  1. Log into your SentinelOne management console as an administrator and create a dedicated service user with the Viewer (read-only) role.
  2. Sign in as that service user, go to its Settings → API Token, and generate a new token. A token from an administrator login can change policy and quarantine devices; a Viewer token cannot, which keeps the credential you give Ledger read-only.
  3. Copy the token — SentinelOne shows it once.

2. Add the connection in Ledger

From Connections → Add connection → SentinelOne, fill in:

Field Value
Console URL Your management console's full URL, e.g. https://yourcompany.sentinelone.net
API token The token from step 1

The console URL must start with https:// and end in .sentinelone.net — Ledger validates this before making any request. Ledger sends the token as Authorization: ApiToken {token} on every request, and it is never logged.

What Ledger reads

Ledger lists every site on your console (mapped to a Ledger client) and every agent under those sites — hostname, OS, MAC addresses, and SentinelOne's own agent metadata — solely to reconcile them against what your other tools report for the same devices.

Rotating credentials later

Generate a new token in SentinelOne and update it from the connection's Rotate credentials action in Ledger — this re-tests the connection with the new token and never leaves the old one stored.