> ## Documentation Index
> Fetch the complete documentation index at: https://docs.neoagent.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Connecting OpenText Secure Cloud to Neo

> Generate a Secure Cloud API credential and refresh token, save them in Neo, and decide what each agent can do

You connect OpenText Secure Cloud once at the MSP level, then turn it on per agent. You need three values from Secure Cloud: a **Client ID**, a **Client secret** and a **Refresh token**.

## 1. Generate the credentials in Secure Cloud

<Steps>
  <Step title="Sign in as a partner administrator">
    Sign in to OpenText Secure Cloud with a user that has the partner administrator role. The user you authorize with in step 3 is the user Neo acts as.
  </Step>

  <Step title="Generate a Client ID and Client secret">
    Go to **Partner Services > Partner Integrations > API credentials management** and click **Generate credentials**. Copy the **Client ID** and the **Client secret**. Secure Cloud shows the secret only once. A partner can hold at most 20 credentials.
  </Step>

  <Step title="Authorize and copy the refresh token">
    On the same page, choose **Actions > Authorize with credentials** in your user's row. Enter the Client ID and the Client secret, choose **Secure Cloud IDP**, and click **Continue**. Copy the **Refresh token**.
  </Step>
</Steps>

<Warning>
  **Enter the refresh token in Neo only.** A Secure Cloud refresh token works once. Each time Neo connects, Secure Cloud returns a new token and Neo stores it in place of the old one. If another tool or script uses the same token, one of the two stops working, and you must authorize again in Secure Cloud.
</Warning>

## 2. Save the credentials in Neo

<Steps>
  <Step title="Open Integrations">
    In the Neo Dashboard, open [**Integrations** → **OpenText Secure Cloud**](https://dashboard.neoagent.io/integrations?open=opentext), under Cloud Marketplace.
  </Step>

  <Step title="Enter the values">
    Paste the **Client ID**, **Client Secret** and **Refresh Token**. To let agents reach your Webroot sites and endpoints, also enter the **GSM Keycode**: the parent keycode of your Webroot Global Site Manager console, from **Settings > Subscription** in the GSM console. Leave it blank if you do not use Webroot. Click **Save**.

    Neo exchanges the refresh token with Secure Cloud before it saves. A wrong Client ID or secret, or a token that was already used, is refused on the spot.
  </Step>
</Steps>

### Keep the connection alive

A refresh token expires after 14 days without use. Neo maps your Secure Cloud customers to PSA companies after each PSA sync, and that run renews the token, so an account whose PSA keeps syncing stays connected.

If Secure Cloud refuses the token, for example after 14 days without a sync or after someone used the same token elsewhere, Neo shows an action item in your inbox and emails your admin. Authorize again in Secure Cloud, as in **Authorize and copy the refresh token** above, and save the new refresh token in Neo.

<Note>
  The Webroot console areas need a Secure Cloud user with access to your GSM console. If the user has none, or loses it later, Neo keeps the Secure Cloud areas connected, and the Webroot areas return a `403`. Neo checks which areas the user can reach when you save the connection, so after you give the user more access, save the connection again.
</Note>

## 3. Turn OpenText Secure Cloud on per agent

Each agent decides whether it uses OpenText Secure Cloud and which areas it can touch. Open the agent, go to the Integrations section, and configure the OpenText Secure Cloud block.

### Pick an access profile

<CardGroup cols={2}>
  <Card title="Read Only" icon="magnifying-glass">
    Every area read only. The agent looks up customers, users, licences, charges and Webroot endpoints, and never changes anything.
  </Card>

  <Card title="Helpdesk" icon="headset">
    Customers & Users and Webroot Endpoints & Groups read and write, each change with technician approval. Everything else read only.
  </Card>

  <Card title="IT Admin" icon="user-gear">
    Every writable area read and write. The agent manages users, licences, orders, sites and endpoints on its own. Admins and roles, DNS Protection mappings and event subscriptions wait on a technician, as do the changes listed under Full Automation.
  </Card>

  <Card title="Full Automation" icon="bolt">
    Every supported write runs with no approval. Only admin and role changes, changing an endpoint's keycode, uninstalling or deactivating Webroot on endpoints, suspending or deactivating a site, and cancelling a product wait on a technician.
  </Card>
</CardGroup>

### Or set each area by hand

| Area | Access levels you can pick | Notes |
| - | - | - |
| **Customers & Users** | Disabled, Read Only, Read and Write | Creating a user, changing a user's details, and adding or removing a user's services and licences follow your approval setting. A create or update that sets a role, or makes a user a Microsoft 365 administrator, uses **Admins & Roles** instead. |
| **Subscriptions & Charges** | Disabled, Read Only | Subscriptions, seat counts, terms, charges and charge events. A seat quantity is changed in Secure Cloud. |
| **Orders & Trials** | Disabled, Read Only, Read and Write | Carts, orders and trials follow your approval setting. Cancelling a product always waits on a technician. |
| **Webroot Sites** | Disabled, Read Only, Read and Write | Creating, editing and resuming a site, and converting a trial site, follow your approval setting. Suspending or deactivating a site always waits on a technician. |
| **Webroot Endpoints & Groups** | Disabled, Read Only, Read and Write | Scans, cleanup, restart, isolation, moves, policies and groups follow your approval setting. Uninstalling or deactivating endpoints, and changing their keycode, always wait on a technician. |
| **DNS Protection** | Disabled, Read Only, Read and Write | A mapping change can allow traffic that was blocked, so consider approval here. |
| **Status & Reports** | Disabled, Read Only | Agent status, statistics, security awareness activity and usage reports. |
| **Admins & Roles** | Disabled, Read Only, Read and Write | Webroot console and site administrators, any Secure Cloud user create or update that sets a role, and making a user a Microsoft 365 administrator (or removing it). Each changes who holds admin access, so each always waits on a technician. |
| **Event Notifications** | Disabled, Read Only, Read and Write | A subscription sends events to the address it names, so consider approval here. |

## Safety controls

* **You set the approvals.** Each area has its own approval setting, so an agent can assign a licence or scan an endpoint on its own, or ask a technician first.
* **Admin access, keycode changes and removing protection always wait on a technician.** Every Admins & Roles change, changing an endpoint's keycode, uninstalling or deactivating Webroot on endpoints, suspending or deactivating a site, and cancelling a product need approval whatever the agent's automation level. This is not a setting you can turn off.
* **Seat quantities stay with you.** Neo refuses a change to a subscription's seat quantity. The agent tells the technician what to change in Secure Cloud.
* **Endpoint actions name their targets.** Webroot applies a site-level command, move, policy change or deactivation with an empty endpoint list to every endpoint of the site. Neo refuses one that does not list the endpoints.
* **Only documented operations.** Neo sends only the operations in the Unity API reference, each with its own method, and refuses any other call.
* **Console sign-in links stay in Webroot.** Neo never reads the console links that sign their holder in to the Webroot console.
* **Path safety.** Neo rejects suspicious URL paths (anything that contains `..`, for example) before they reach OpenText.

## If OpenText refuses Neo's requests

| What comes back | Cause | Fix |
| - | - | - |
| An inbox action item to reconnect | The refresh token expired or was used elsewhere | Authorize again in Secure Cloud and save the new refresh token in Neo. |
| `401` | The credentials lost access | Check that the user is still a partner administrator, then authorize again. |
| `403` with `insufficient_scope` | The user cannot reach that area, such as the Webroot console | Authorize with a user that has access to that area. |
| `403` | The user's role does not allow the operation | Give the user a role that allows it. |
| `429` | Too many requests | Wait, then try again. |

## Disconnecting OpenText Secure Cloud

<Steps>
  <Step title="Open the integration">
    In the Neo Dashboard, open **Integrations** and select the OpenText Secure Cloud card.
  </Step>

  <Step title="Disconnect">
    Click **Disconnect** and confirm. Neo removes the credentials from Key Vault and stops using its cached access token.
  </Step>
</Steps>

Neo keeps your Organization Mapping, including any mapping you set by hand, so a later reconnect continues from the same state. Agents that use OpenText Secure Cloud stop working until you connect it again.

## Security

* The Client secret and the refresh token are stored in Azure Key Vault, never in plaintext.
* All traffic to OpenText goes over HTTPS, to `unityapi.webrootcloudav.com` only.
* Write access is opt-in per agent.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.