Simplifyd MDMMDM Docs
Using the console

API and webhooks

Letting your own systems read from Simplifyd MDM and hear about what happens.

Settings → API & webhooks connects your own tools: an asset register, a helpdesk, or a script.

Settings → API & webhooks, with an API key and a webhook.

API keys

An API key lets a tool call the API as a member of your organisation, with the role you give it. A key can't change accounts, billing, keys or webhooks, whatever its role.

  1. Select Create key and name it after what will use it, for example Helpdesk sync.
  2. Choose its role. Give it the least it needs: Auditor keys can only read. You can also limit it to some groups, as with a member.
  3. Copy the key. It won't be shown again, so store it where your tool keeps its secrets.

Send it as a bearer token:

curl -H "Authorization: Bearer $MDM_API_KEY" \
  https://api.mdm.simplifyd.com/api/v1/devices

Each key shows when it was last used. Revoke stops a key working at once.

Webhooks

A webhook sends a signed message to your URL the moment something happens.

  1. Select Add webhook, and enter a public https:// URL and a description.
  2. Tick the events you want:
EventWhen it is sent
device.enrolledA device enrolled.
device.compliance_changedA device became compliant, entered its grace period, or became non-compliant.
command.completedA device finished a command, whether it worked or not.
policy.publishedA policy was created, or a version of it was published, piloted, promoted or rolled back.
device.geofence_exitedA device was seen outside every place its policy says it belongs.
device.geofence_enteredA device that was outside its places is back inside one.
approval.requestedSomeone asked for a wipe that needs a second person's approval.
approval.decidedA wipe request was approved or rejected.
  1. Copy the signing secret. It won't be shown again.

Use Send test event to try it, and Deliveries to see what was sent and how your server answered. Webhooks cover your organisation and every organisation below it. You can pause, edit or delete a webhook from its menu.

Checking a delivery is genuine

Each delivery is a POST of a JSON event, with an X-MDM-Signature header of the form t=<unix time>,v1=<hex>. The v1 value is an HMAC-SHA256 of the timestamp, a full stop, and the raw request body, keyed with your signing secret. Compute the same and compare, and reject deliveries whose timestamp is more than a few minutes old.

The X-MDM-Event-Id header is the same on every retry of an event, so you can ignore one you have already handled.

Failures

Answer with any 2xx status within 10 seconds. Anything else is a failure, and the delivery is retried after 1 minute, 5 minutes, 30 minutes, 2 hours, 6 hours, 12 hours and 24 hours, about two days in all, before it is given up. The webhook's card shows its last error.

Managing keys and webhooks needs the Manage settings permission. Admins have it.

On this page