> ## Documentation Index
> Fetch the complete documentation index at: https://docs.neoagent.io/llms.txt
> Use this file to discover all available pages before exploring further.

# CyberQP API

> Verify end users, manage just-in-time admin accounts and read CyberQP customers, passwords and events from an agent

The CyberQP API tool gives Neo agents access to CyberQP (formerly Quickpass), your privileged access platform. The common uses are verifying a caller before a password reset, giving a technician temporary admin rights at a customer for one ticket, and handing the CyberQP install token and customer GUID to an RMM deployment script.

<Info>
  Automatically enabled when you configure CyberQP permissions in your agent workflow.
</Info>

## What It Does

* Find a customer in CyberQP, with its agent GUID, and read its user, admin, service and JIT accounts
* Send an end user an identity verification push; CyberQP adds the result to the PSA ticket
* Create a just-in-time (JIT) admin account under one of your JIT policies, enable it for a duration, disable it, or delete it
* Read a customer account's or a JIT account's password and a JIT account's OTP codes, for a technician who asks
* Read the agent install token, so your RMM can deploy the CyberQP agent
* Read CyberQP's audit events from the last three months

Neo never refreshes or revokes CyberQP tokens on request, never downloads the agent installer, and never saves an OTP secret on a JIT account: that secret would sit in the agent's run log.

## Permission Groups

| Group | Access levels | Covers |
| - | - | - |
| Customers & Accounts | Disabled, Read Only | Customers and their agent GUIDs, each customer's accounts and their counts, your company data |
| Agent Deployment | Disabled, Read Only | Your agent install token. It installs the agent for any of your customers |
| Identity Verification | Disabled, Read / Write | Send an end user an identity verification push |
| Just-In-Time Accounts | Disabled, Read Only, Read / Write | JIT accounts and policies; create, enable, disable and delete a JIT account |
| Passwords & OTP | Disabled, Read Only, Read / Write | Account and JIT account passwords, JIT OTP codes, and removing a JIT account's OTP secret |
| Events | Disabled, Read Only, Read / Write | Audit events; record an event on an account |

| Profile | What it does |
| - | - |
| Read Only | Reads customers, accounts, JIT accounts and events. The install token, passwords and identity verification stay off |
| Helpdesk | Sends identity verifications on its own. Every JIT account change asks a technician first; events are read-only |
| IT Admin | Identity verification, disabling or deleting a JIT account, and events on their own |
| Full Automation | Every supported call with no approval, except the calls below |

### Calls that always ask a technician

These calls wait for a technician's approval under every profile, whatever you set on the group:

* Creating a JIT admin account, and enabling one
* Reading a customer account's password, a JIT account's password or a JIT account's OTP codes
* Removing a JIT account's OTP secret

Each gives a person admin rights at a customer, hands over a live credential, or weakens an account's sign-in, so no setting runs them unattended. The agent sends the approval request with the customer, the account and the ticket.

Turn Passwords & OTP on only for agents that hand credentials to your team, such as an internal chat agent.

## Setup

See [Connecting CyberQP to Neo](/integrations/cyberqp/connecting-to-neo).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.