> ## Documentation Index
> Fetch the complete documentation index at: https://docs.neoagent.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Connecting WatchGuard to Neo

> Enable API access in WatchGuard Cloud and save the credential in Neo

You connect WatchGuard once at the MSP level, with the API credential of your own WatchGuard Cloud account: the region, your account ID, an Access ID with its password, and the API key.

## 1. Enable API access in WatchGuard Cloud

<Steps>
  <Step title="Open your own account">
    Sign in to WatchGuard Cloud with the Owner or Administrator role. As a Service Provider, switch to **Subscriber view** for your own account, not a customer's.
  </Step>

  <Step title="Note your account ID and region">
    Open **Administration** > **My Account**. The **Details** section shows your account ID (it starts with `ACC-` or `WGC-`) and your data zone.
  </Step>

  <Step title="Enable API access">
    Open **Administration** > **Managed Access** and click **Enable API Access**. Set a read-write password and a read-only password (at least 12 characters, with a lowercase and an uppercase letter, a number and a symbol), accept the license agreement and click **Save**.
  </Step>

  <Step title="Copy the credential">
    Copy the **Access ID (Read-write)**, the read-write password you set, and the **API Key**. The **API URL** shows your region: `usa`, `deu` or `jpn`.
  </Step>
</Steps>

<Note>
  The read-only Access ID also connects, but it cannot make changes in WatchGuard Cloud.
</Note>

<Warning>
  Do not change the API passwords or disable API access in WatchGuard Cloud after you connect. Neo loses access until you save the new values here.
</Warning>

## 2. Add the credential in Neo

<Steps>
  <Step title="Open Integrations">
    In the Neo Dashboard, open [**Integrations** → **WatchGuard**](https://dashboard.neoagent.io/integrations?open=watchguard), under Networking.
  </Step>

  <Step title="Save the credential">
    Pick the region, then paste your account ID, the Access ID, its password and the API key, and click **Save settings**. Neo checks them against WatchGuard Cloud before saving, so a wrong value is rejected straight away.
  </Step>
</Steps>

## 3. Turn WatchGuard on per agent

<Steps>
  <Step title="Open the agent's integrations">
    Open the agent in the Neo Dashboard and go to its **Integrations** tab.
  </Step>

  <Step title="Pick an access profile">
    Under **WatchGuard**, pick an access profile, or set each permission group by hand.

    | Profile | What it does |
    | - | - |
    | **Read Only** | Checks Fireboxes, access points, endpoints, incidents and licences; changes nothing |
    | **Helpdesk** | Also makes Firebox, endpoint, incident, account and AuthPoint changes, each with technician approval |
    | **IT Admin** | Isolates and scans endpoints and contains threats on its own; exceptions, Firebox configuration and account changes, and the changes Full Automation also asks about, ask a technician |
    | **Full Automation** | Every supported write without approval, except FireCloud allow exceptions, policy, VPN, certificate and template changes, disabling global exceptions, deployments, protection uninstalls, moving devices to another security configuration, undoing a containment, operator changes, deallocations, purchase orders and contract suspends or cancels |

    | Group | Covers |
    | - | - |
    | Firebox Devices and Reports | Status, offline since, uptime and reports of Fireboxes and access points (read-only) |
    | Firebox Exceptions | Blocked sites, WebBlocker, botnet, file, IPS, geolocation and HTTPS exceptions |
    | Firebox Configuration | Firewall policies, BOVPN tunnels, certificates, templates and deployments |
    | Endpoint Security | Devices, protection, security events; isolate, reboot and scan |
    | ThreatSync and NDR | Incidents, actions and comments; NDR assets and Smart Alerts |
    | Accounts and Licensing | Managed accounts, operators, licences, allocations and contracts |
    | AuthPoint Authentication | Test push and its result, the authentication policy for a user |

    With the read-only Access ID saved, every write fails in WatchGuard Cloud whatever the profile says. See [WatchGuard API](/agents/tools/networking/watchguard-api).
  </Step>

  <Step title="Tell the agent what to do">
    Add an instruction, for example: "When WatchGuard Cloud reports a Firebox offline, check the Firebox in WatchGuard, and write in an internal note whether it is back online and since when it was down."
  </Step>
</Steps>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.