> ## Documentation Index
> Fetch the complete documentation index at: https://docs.neoagent.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Connecting RoboShadow to Neo

> Copy a RoboShadow refresh token and save it in Neo

You connect RoboShadow once at the MSP level. Neo reaches every organisation the RoboShadow user behind the token can see, so connect it with a user who sees all the customers you want Neo to read.

## 1. Copy the refresh token

<Steps>
  <Step title="Open the API Token page">
    Sign in to the RoboShadow portal and open **Reports**, then **API Token**.
  </Step>

  <Step title="Copy the Refresh Token">
    The page shows an Organisation ID, a Bearer Token and a Refresh Token. Copy the **Refresh Token**. Neo uses it to get a new bearer token whenever the last one expires, so you never paste the short-lived bearer token.
  </Step>
</Steps>

<Warning>
  Neo reads only what the RoboShadow user behind the token can see. If that user loses access to an organisation, restore it in RoboShadow, or save a refresh token from another user who has it.
</Warning>

## 2. Add the token in Neo

<Steps>
  <Step title="Open Integrations">
    In the Neo Dashboard, open **Integrations** and find the RoboShadow card, under Security.
  </Step>

  <Step title="Save the token">
    Paste the refresh token and click **Save**. Neo checks it against RoboShadow before saving, so a wrong token is rejected straight away.
  </Step>
</Steps>

## 3. Turn RoboShadow on per agent

Open the agent, go to the Integrations section, and configure the RoboShadow block. The **Read Only** profile turns on every area. To leave an area out, set it to Disabled:

| Area | Access levels you can pick | Notes |
| - | - | - |
| **Organisations, Devices and Inventory** | Disabled, Read Only | Organisations, devices, applications, services, disks and hardware. |
| **Vulnerabilities and Updates** | Disabled, Read Only | CVEs, fixes, missing updates and remediation attempts. Needed to patch from the CVE report. |
| **Antivirus and Firewall** | Disabled, Read Only | Antivirus, threats, Windows Defender and firewall status. |
| **Users and MFA** | Disabled, Read Only | User accounts and profiles on each device, and the Microsoft MFA report. Device lists in the other areas still name the logged-on user. |
| **External Scans** | Disabled, Read Only | External vulnerability scans of your customers' internet-facing addresses. |

To let the agent patch what it finds, also give it your RMM's tools. See [RoboShadow API](/agents/tools/security/roboshadow-api) for what the agent can read.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.