Purpose
Purpose
Supported Versions
Supported Versions
Authentication
Authentication
X as the placeholder password. A normal Freshservice username and password should not be used for API v2 authentication.The key acts with the permissions of its Freshservice identity. Assign only the roles and workspace access needed for the AirMDR actions you intend to use. A successful authentication does not grant access to records outside that identity’s permissions.Credential reference
Credential reference
Pre-requisites
An active Freshservice tenant and its default Freshservice domain.Permission to create a Freshservice integration user, or access to an active agent’s API key.
Setup Steps
AirMDR can connect using the API key of a dedicated integration user or an existing agent. Both options use the same Domain and API Key fields in AirMDR. Choose the identity based on how your organization manages access.Refer Freshservice Dedicated integration user or Existing agent’s API key for better understanding
Refer Freshservice Dedicated integration user or Existing agent’s API key for better understanding
Create a dedicated Freshservice integration user
- Sign in to Freshservice with an administrator account authorized to manage integration users.
- Go to Global Settings → User Management → Integration Users.
- Select Create integration user.
- Enter a descriptive Display name, such as
AirMDR Integration, and a Description explaining its purpose. - Select Create.
- Open the new user and, on the Permissions tab, select Add to workspace.
- Choose each workspace AirMDR must access. Under Roles, select a role with the required permissions, then select Save.
- Add an account-wide admin role only if an approved AirMDR action specifically needs account-wide administrative access.
- On the user’s API key card, select Show, then Copy. Store the key securely until you enter it in AirMDR.
Alternative: Copy an existing agent’s API key
If your tenant does not offer integration users:- Sign in as the Freshservice agent whose permissions will be used for AirMDR.
- Select your profile icon in the upper-right corner.
- Select Profile settings.
- Find Your API Key on the right side of the page, below Delegate Approvals. Complete the verification prompt if one appears.
- Copy the key. Confirm that this agent is active and has the required roles and workspace access.
Identify the Freshservice domain
- In Freshservice, inspect the tenant address and identify its Freshservice hostname—for example,
acme.freshservice.com. - If your organization uses multiple requester portals or a branded URL, ask your Freshservice administrator for the default portal’s Freshservice URL.
- Record only the hostname for AirMDR’s Domain field:
https://acme.freshservice.com/support/home, a secondary portal URL, or api.freshservice.com as the tenant domain.Freshservice Credential Reference Table
Validate Connectivity
Use the following request to confirm a read-only API request: Run this optional check from an approved terminal that can reach the tenant. It lists tickets visible to the key’s Freshservice identity; a successful response may contain an empty list if no tickets are visible.Sample Request
Sample Request
acme.freshservice.com with your default Freshservice hostname. Avoid adding --verbose or sharing terminal output containing credentials. Freshservice’s API documentation shows the API-key-as-username pattern and the /api/v2/ticketsendpoint.Sample Response
Sample Response
Configure Freshservice in AirMDR Integrations Dashboard
- Navigate to AirMDR, provide the credentials and click Login
- Navigate to the AirMDR Integrations Dashboard in the left navigation pane and select ADMIN → Integrations.
- Use the search option, enter the keyword “Freshservice”, select the Connections tab, and click + New Connection button.
-
Use the following values in the AirMDR integration configuration screen:
Expand Advanced Configuration if required. (Optional)
- In Remote Agent, select an AirMDR Remote Agent only when requests to your Freshservice tenant must pass through an approved network route, proxy, or controlled environment. For a publicly accessible Freshservice tenant, leave this field unselected unless your AirMDR administrator instructs otherwise.
- In Expiry, select the date on which AirMDR should treat the stored Freshservice credentials as expired, according to your organization’s credential rotation policy.
The Expiry date applies to the connection in AirMDR. It does not automatically reset or revoke the API key in Freshservice.When rotating the key, reset it in Freshservice, update the AirMDR connection with the new key, and validate the connection. Resetting a Freshservice integration user’s key immediately breaks applications that still use the old key. - Click Save.
Skills provided by this Integration
Ticket retrieval
Ticket retrieval
Ticket creation and updates
Ticket creation and updates
Ticket communication
Ticket communication
Additional Information
🧰 Error Handling
🧰 Error Handling
🔄 Monitoring & Logs
🔄 Monitoring & Logs
- In AirMDR: Check the connection status and the execution history of the Freshservice skill or workflow that failed. Record the time, action, and HTTP status; keep the API key out of logs.
- In Freshservice: Inspect the affected record’s Activity where applicable. For integration users, Freshservice also documents Global Settings → Audit Log and the integration user’s Tickets tab for relevant activity. An audit log is not a guaranteed trace of every API request. support.freshservice.com
- Recommended logging: Keep routine successful requests at
INFO, transient failures atWARN, and failed authentication or authorization atERROR. Log a request identifier when available, while redacting credentials and sensitive record content.
🛑 Security & Access Best Practices
🛑 Security & Access Best Practices
- Use a dedicated Freshservice integration user for AirMDR when the feature is available.
- Assign only the ticket permissions and workspace roles required by the AirMDR skills you enable.
- Enter the API key only in AirMDR’s designated secret field or an approved secrets manager.
- Use the default portal’s Freshservice domain and connect over HTTPS.
- Keep production and non-production connections and credentials separate.
- Review ticket activity and available integration-user audit logs for unexpected actions.
- Rotate the API key according to your organization’s policy, then update and validate the AirMDR connection.
- Reset the key promptly if exposure is suspected; investigate actions performed by that identity.
- Share the API key through email, chat, tickets, screenshots, or documentation.
- Store the key in scripts, configuration files, or source-control repositories.
- Use an employee’s personal API key when a dedicated integration user is available.
- Grant account-wide administrator access solely to make the connection work; check the permission needed for the failing skill.
- Use a secondary portal or branded custom URL as the Freshservice API domain.
- Assume a successful connection test confirms permission for ticket creation, updates, and replies.
- Assume AirMDR’s Expiry field resets or revokes the Freshservice API key.
- Reset a key without updating dependent connections: Freshservice warns that applications using the previous key will stop working.
👉 Support & Maintenance
👉 Support & Maintenance
- 📧 Contact AirMDR Support through your designated support channel for connection or skill execution issues.
- 🔄 Rotate the Freshservice API key according to your organization’s security policy. If your policy specifies a 90-day cycle, schedule the AirMDR Expiry date to support that review.
- 🔁 Update the API Key in AirMDR immediately after resetting it in Freshservice, then validate the connection with a read-only action. Resetting an integration user’s key stops applications that use the previous key. support.freshservice.com
- 🛠️ For Freshservice API or tenant issues, use the Freshservice Support portal or contact
support@freshservice.com. Include the tenant domain, timestamp, affected action, and sanitized error details; never include the API key.
🛑 Data Flow & Security
🛑 Data Flow & Security
https://<domain>/api/v2/.... Freshservice returns the records or action results permitted for the API-key identity. The specific data exchanged—such as ticket fields, requester details, or updates—depends on the AirMDR skill invoked and its Freshservice endpoint. Review the enabled skills and their permissions before granting access.
