> ## Documentation Index
> Fetch the complete documentation index at: https://docs.neoagent.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Connecting Datto BCDR to Neo

> Create a Datto Partner Portal API key and save it in Neo

You connect Datto BCDR once at the MSP level.

## 1. Create an API key

<Steps>
  <Step title="Open API Keys">
    Sign in to the Datto Partner Portal and open **Admin** > **Integrations** > **API Keys**.
  </Step>

  <Step title="Create the key">
    Click **Create API Key**. Leave the **Client** and **Vendor** fields blank, so the key sees the appliances of every client. Copy the **Public Key** and the **Secret Key**.
  </Step>
</Steps>

<Note>
  Datto allows two API keys per partner organization. If both are already in use by other tools, delete or regenerate one of them first.
</Note>

## 2. Add the key in Neo

<Steps>
  <Step title="Open Integrations">
    In the Neo Dashboard, open **Integrations** and find the Datto BCDR card, under Backup & Recovery.
  </Step>

  <Step title="Save the key">
    Paste the Public Key and the Secret Key and click **Save**. Neo checks them against Datto before saving, so a wrong or deactivated key is rejected straight away.
  </Step>
</Steps>

## 3. Turn Datto BCDR on per agent

Open the agent, go to the Integrations section, and configure the Datto BCDR block. Pick a profile, or set each area:

| Area | Access levels you can pick | Notes |
| - | - | - |
| **BCDR Appliances** | Disabled, Read Only | Appliances, their agents and shares, backups, screenshot verification and alerts. This is the area a Datto alert agent needs. |
| **Endpoint Backup** | Disabled, Read Only, Read / Write | Endpoint Backup for PCs and Direct-to-Cloud agents. Read / Write lets the agent set an agent's bandwidth limit. |
| **Activity Log** | Disabled, Read Only | The Partner Portal activity log. |
| **SaaS Protection** | Disabled, Read Only, Read / Write | Microsoft 365 and Google Workspace customers, seats and backups. Read / Write lets the agent license, pause or unlicense seats. |

| Profile | Bandwidth limit change | License a SaaS Protection seat | Pause or unlicense a seat |
| - | - | - | - |
| **Read Only** | Not allowed | Not allowed | Not allowed |
| **Helpdesk** | Asks a technician | Asks a technician | Asks a technician |
| **IT Admin** | Asks a technician | Runs on its own | Asks a technician |
| **Full Automation** | Runs on its own | Runs on its own | Asks a technician |

## Example: close Datto alerts that have recovered

Give an agent that runs on your Datto alert tickets the **Read Only** profile and instructions like these:

> For a Datto alert ticket, take the appliance serial from the title and check the appliance in Datto BCDR. For a backup or screenshot alert, read the last backups of the machine named in the ticket. If a backup newer than the alert succeeded and its screenshot verification passed, add a note with the backup time and both results, and close the ticket. For Device Not Seen, close it if the appliance has checked in since the alert. Otherwise, assign the ticket to the backup queue with the error and the time of the last good backup.

See [Datto BCDR API](/agents/tools/backup/datto-bcdr-api) for what the agent can read.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.