Skip to main content
You connect Domotz once at the MSP level, then turn it on per agent.

1. Create an API key

1

Open API Keys

Sign in to the Domotz Portal and open Settings, then Services, then API Keys.
2

Create a key for Neo

Create a key and name it so you know Neo uses it. The key sees every collector your Domotz account can see.
3

Copy the key and its endpoint

Copy the key, and the API endpoint shown next to it. The endpoint depends on your region, for example https://api-us-east-1-cell-1.domotz.com/public-api/v1/ in the US or https://api-eu-west-1-cell-1.domotz.com/public-api/v1/ in the EU. A key works only at the endpoint shown with it.

2. Add the key in Neo

1

Open Integrations

Open Integrations and find Domotz under Networking.
2

Save the key

Paste the endpoint into API endpoint and the key into API key, then click Save. The endpoint works with or without the /public-api/v1/ path. Neo lists your collectors with the key before it saves, so a refused key shows an error and is not saved. The Organization Mapping tab fills after the save, and again on each nightly PSA sync.

3. Turn Domotz on per agent

Open the agent, go to the Integrations section, and configure the Domotz block.

Pick an access profile

Read Only

Read collectors, devices, history, alerts and Organizations. Nothing is changed.

Helpdesk

Resolve alerts on its own. Every other change waits on a technician.

IT Admin

Change devices, run power actions, resolve alerts and manage Organizations on its own. Monitoring Coverage, Collector Settings and Users & Account changes wait on a technician.

Full Automation

Manage devices, monitoring, collector settings, Organizations, users, alerts and power actions without approval. Deleting a collector or an Organization still waits on a technician.

Or set each area by hand

Each area also has its own technician approval setting.

Example: a device is offline

Give an agent that runs on your Domotz alert tickets the Helpdesk profile and instructions like these:
For a device-offline ticket, find the device in Domotz and check the other devices on the same collector. If the whole site is down, say so on the ticket and stop. If only the device is down and it sits on a PoE switch port or PDU outlet, power cycle it. When the device is back, resolve the Domotz alert and add a note with what you did.
The power cycle waits on a technician’s approval. See Domotz API for what the agent can read and change.

Safety controls

  • You decide what waits on a technician. Each area has its own approval setting. Helpdesk asks before every change except resolving an alert; IT Admin asks before a Monitoring Coverage, Collector Settings or Users & Account change; Full Automation asks on nothing else.
  • Two deletions always wait on a technician. Deleting a collector, which removes the site and its whole history, and deleting an Organization both wait for approval, whatever the settings.
  • Changes that stop alerts have their own area. Hiding a device, setting it unmanaged, unbinding an alert rule or deleting a sensor all sit in Monitoring Coverage, so you can keep them behind approval.
  • No access links, secrets or images. Neo refuses these before it calls Domotz: opening a remote connection to a device or a collector VPN session, the text of stored device configurations, and camera snapshots. Neo removes SNMP community strings and keys from every Domotz response before an agent or a script sees it.
  • No unnamed bulk deletes. Neo refuses the bulk delete of a collector’s offline devices and the wipe of the account’s whole inventory.
  • Only Domotz hosts. Neo refuses an API endpoint whose host is not a Domotz API host.
  • Path safety. A URL path with a .. segment is rejected before it reaches Domotz.

Disconnecting Domotz

In the Neo Dashboard, open Integrations, select the Domotz card, click Disconnect and confirm. Neo removes the key from Key Vault. Agents that use Domotz stop working until you connect it again. Your Organization Mapping is kept, including any mapping you set by hand.

Security

  • The key lives in Azure Key Vault. It is never stored in plaintext.
  • All traffic goes over HTTPS to the Domotz API endpoint you saved.
  • Write access is opt in per agent and per area.