Security & Identity · Integration
Jamf
Add Jamf to your product for your customers, and give your AI agents governed access to it.
Embed a Jamf integration so your customers can see and act on their own managed Apple devices from inside your product. The blast radius of a device action is large, so each customer grants access to their own Jamf tenant, permissions are scoped to the actions you enable, and every call is recorded so a change can be traced to its source. fastn handles per-tenant authorisation, pagination, and API upkeep.
In your product
Embedded for your customers. Per-tenant auth, no per-customer code, maintained by fastn.
Let customers read their own device inventory and compliance state into your product, mapped to their fields.
Read group membership so your product can target actions the way the customer already organises devices.
Run an enabled device action, such as applying a policy, from your product within scoped permissions.
Trigger your product when a device enrols, drifts out of compliance, or is removed.
For your AI agents
Governed, audited access for the agents you build, through the MCP server.
An agent reads a device's inventory and compliance state before recommending a remediation.
An agent runs an approved device action within governed permissions, with every call audited.
An agent reacts to a device falling out of compliance and opens the right follow-up work.
Example prompt
List the managed devices that are out of compliance and show which group each one belongs to.
Set up Jamf in 4 steps
- 01Open the Jamf connector from your fastn dashboard.
- 02Have each customer authenticate their own Jamf tenant with least-privilege scopes.
- 03Map the device, group, and policy fields your product uses, then enable actions and triggers.
- 04Call them from your product, or expose them to an agent through the MCP server.
Why teams use the Jamf integration
What you get by embedding it with fastn instead of building it yourself.
- Ship a Jamf integration without building it. Your customers connect their own Jamf account inside your product and work their users, groups and roles there, with no per-customer code on your side.
- Handle the part that actually costs time: the blast radius of an error is large, so least-privilege and auditability are non-negotiable. fastn owns the auth, token refresh, rate limits, pagination and breaking-change fixes, so a Jamf update is not your on-call problem.
- One integration serves your product and your agents. The same governed Jamf connection powers in-product features and gives AI agents scoped, audited access, so you keep access and identity in step across a customer's estate without wiring it twice.
Used by these teams
Compare with
Works well with
Often used alongside
Tools the same teams tend to run next to Jamf, across other categories.
Jamf integration FAQ
How do I add a Jamf integration to my product?
Enable the Jamf connector in your fastn dashboard, then let each customer authenticate their own Jamf account. fastn handles the OAuth flow, token storage and refresh per tenant, so there is no Jamf client code in your app and no per-customer branch in your codebase. Setup is 4 steps.
Do my customers each connect their own Jamf account?
Yes. Every connection is scoped to the individual customer, so each authorises their own Jamf account and only ever sees their own users, groups and roles. That per-tenant isolation is the point of an embedded integration: you support the long tail of customer setups without maintaining an integration per customer.
Can AI agents use this Jamf integration?
Yes. The same connection is exposed to your agents through the fastn MCP gateway, with permissions scoped per tenant and every call audited. An agent reads a device's inventory and compliance state before recommending a remediation.
Who maintains the Jamf integration?
fastn does. When Jamf changes an endpoint, deprecates a field or alters its auth, the fix lands in the connector rather than in your backlog, and your customers' connections keep working.
What permissions does the Jamf integration need?
Only the scopes required for the actions you enable. Each customer grants access to their own Jamf tenant, permissions are scoped per tenant, and every call is recorded so an access change can be traced to its source.
Can access changes be automated safely?
Yes. Provisioning and deprovisioning can be driven from your product or an agent within governed permissions, with every action audited, which is what makes automated access changes reviewable after the fact.
What can I build with the Jamf integration?
A common starting point: read their own device inventory and compliance state into your product, mapped to their fields. Teams also use it for the other use cases listed above, and expose it to agents for governed reads and writes.
How much does the Jamf integration cost?
It is included. Pricing is based on connected accounts, not on how many connectors you enable, so adding Jamf does not change your per-connector cost. You can start free with 3 connected accounts.
Add Jamf to your product
Start free with 3 connected accounts. No sales call required, and no per-customer integration code.