> ## Documentation Index
> Fetch the complete documentation index at: https://docs.neoagent.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Connecting Domotz to Neo

> Save a Domotz API key and its endpoint in Neo, and decide what each agent can do

You connect Domotz once at the MSP level, then turn it on per agent.

## 1. Create an API key

<Steps>
  <Step title="Open API Keys">
    Sign in to the Domotz Portal and open **Settings**, then **Services**, then **API Keys**.
  </Step>

  <Step title="Create a key for Neo">
    Create a key and name it so you know Neo uses it. The key sees every collector your Domotz account can see.
  </Step>

  <Step title="Copy the key and its endpoint">
    Copy the key, and the API endpoint shown next to it. The endpoint depends on your region, for example `https://api-us-east-1-cell-1.domotz.com/public-api/v1/` in the US or `https://api-eu-west-1-cell-1.domotz.com/public-api/v1/` in the EU. A key works only at the endpoint shown with it.
  </Step>
</Steps>

## 2. Add the key in Neo

<Steps>
  <Step title="Open Integrations">
    Open [**Integrations**](https://dashboard.neoagent.io/integrations?open=domotz) and find **Domotz** under **Networking**.
  </Step>

  <Step title="Save the key">
    Paste the endpoint into **API endpoint** and the key into **API key**, then click **Save**. The endpoint works with or without the `/public-api/v1/` path. Neo lists your collectors with the key before it saves, so a refused key shows an error and is not saved. The **Organization Mapping** tab fills after the save, and again on each nightly PSA sync.
  </Step>
</Steps>

## 3. Turn Domotz on per agent

Open the agent, go to the Integrations section, and configure the Domotz block.

### Pick an access profile

<CardGroup cols={2}>
  <Card title="Read Only" icon="magnifying-glass">
    Read collectors, devices, history, alerts and Organizations. Nothing is changed.
  </Card>

  <Card title="Helpdesk" icon="headset">
    Resolve alerts on its own. Every other change waits on a technician.
  </Card>

  <Card title="IT Admin" icon="user-gear">
    Change devices, run power actions, resolve alerts and manage Organizations on its own. Monitoring Coverage, Collector Settings and Users & Account changes wait on a technician.
  </Card>

  <Card title="Full Automation" icon="bolt">
    Manage devices, monitoring, collector settings, Organizations, users, alerts and power actions without approval. Deleting a collector or an Organization still waits on a technician.
  </Card>
</CardGroup>

### Or set each area by hand

| Area | Access levels you can pick | Notes |
| - | - | - |
| **Collectors & Devices** | Disabled, Read Only, Read/Write | Collectors and their devices, with status, history, metrics, sensors and device profiles. Write edits a device's details and inventory values, tags it, adds a sensor or an external host, sets device credentials and SNMP settings, applies a device profile, and starts a configuration backup. |
| **Collector Settings** | Disabled, Read Only, Read/Write | Scan and interface policies, DHCP discovery, routed networks, service ports, the collector's default SNMP credentials, VPN sessions (list and close), moving a collector to another team, and deleting a collector. A collector deletion always waits on a technician. |
| **Monitoring Coverage** | Disabled, Read Only, Read/Write | Alert rules and their bindings to collectors, devices and contact channels, alert profile bindings, excluded and hidden devices, monitoring state, and deleting a device, sensor or trigger. These writes can stop an alert. |
| **Alerts** | Disabled, Read Only, Read/Write | Alert events, rules, profiles and contact channels. Write resolves an alert. |
| **Device Actions** | Disabled, Read Only, Read/Write | Power on, off or cycle through a PoE switch port or PDU outlet, software reboot, outlet actions, running and binding custom drivers. |
| **Organizations** | Disabled, Read Only, Read/Write | The Domotz Organizations, which collectors belong to each, and their contacts. Write creates, changes and deletes them. An Organization deletion always waits on a technician. |
| **Users & Account** | Disabled, Read Only, Read/Write | Domotz users, user groups and roles, areas and teams, and the account's tag and inventory field definitions. |

Each area also has its own technician approval setting.

## Example: a device is offline

Give an agent that runs on your Domotz alert tickets the **Helpdesk** profile and instructions like these:

> For a device-offline ticket, find the device in Domotz and check the other devices on the same collector. If the whole site is down, say so on the ticket and stop. If only the device is down and it sits on a PoE switch port or PDU outlet, power cycle it. When the device is back, resolve the Domotz alert and add a note with what you did.

The power cycle waits on a technician's approval. See [Domotz API](/agents/tools/networking/domotz-api) for what the agent can read and change.

## Safety controls

* **You decide what waits on a technician.** Each area has its own approval setting. Helpdesk asks before every change except resolving an alert; IT Admin asks before a Monitoring Coverage, Collector Settings or Users & Account change; Full Automation asks on nothing else.
* **Two deletions always wait on a technician.** Deleting a collector, which removes the site and its whole history, and deleting an Organization both wait for approval, whatever the settings.
* **Changes that stop alerts have their own area.** Hiding a device, setting it unmanaged, unbinding an alert rule or deleting a sensor all sit in Monitoring Coverage, so you can keep them behind approval.
* **No access links, secrets or images.** Neo refuses these before it calls Domotz: opening a remote connection to a device or a collector VPN session, the text of stored device configurations, and camera snapshots. Neo removes SNMP community strings and keys from every Domotz response before an agent or a script sees it.
* **No unnamed bulk deletes.** Neo refuses the bulk delete of a collector's offline devices and the wipe of the account's whole inventory.
* **Only Domotz hosts.** Neo refuses an API endpoint whose host is not a Domotz API host.
* **Path safety.** A URL path with a `..` segment is rejected before it reaches Domotz.

## Disconnecting Domotz

In the Neo Dashboard, open **Integrations**, select the Domotz card, click **Disconnect** and confirm. Neo removes the key from Key Vault. Agents that use Domotz stop working until you connect it again. Your Organization Mapping is kept, including any mapping you set by hand.

## Security

* The key lives in Azure Key Vault. It is never stored in plaintext.
* All traffic goes over HTTPS to the Domotz API endpoint you saved.
* Write access is opt in per agent and per area.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.