Skip to main content
This guide explains how to retrieve your Netskope Tenant URL, generate an API Token, and enter these credentials in AirMDR.
Connect Netskope to AirMDR using your Tenant URL and API Token to enable supported security investigations and automated workflows.
Netskope provides two token creation workflows. Tenants with RBAC V3 enabled use Service Account under Administrators & Roles.The Settings → Tools → REST API v2 path shown in the AirMDR connection screen applies to the legacy workflow.After RBAC V3 activation, new tokens must use the service account workflow.
The connection requires two values:The token is included in each request using this HTTP header: Netskope-Api-Token: <generated-api-token>Netskope documents this header for REST API v2 requests.
Enter only the generated token in AirMDR’s API Token field. Do not include the header name, quotation marks, or a Bearer prefix.
Role-based access considerations
  • RBAC V3: A Tenant Admin manages administrators and roles. Assign the integration service account a role containing only the required permissions. Netskope Administrators RBAC V3
  • Legacy workflow: Configure access for individual endpoints when creating the token.
  • Grant read access for retrieval operations. Grant write access only where a supported skill changes Netskope data or configuration.
The following are endpoint examples, not a confirmed AirMDR permission list:Netskope documents these endpoint privileges in its API token scope reference. Use only those required by the integration.

Pre-requisites

An active Netskope tenant with access to the required API features.
Netskope administrator access to create API credentials and assign permissions.

Setup Steps

1

Retrieve the Tenant URL

  1. Open your organization’s Netskope administration console.
  2. Sign in with your administrator account.
  3. After authentication completes, select the browser address bar.
  4. Copy the HTTPS scheme and tenant hostname.
  5. Remove any page path, query parameters, or fragment.
    For example:
  6. Retain the exact hostname assigned to your tenant.
    Netskope assigns the Tenant URL when provisioning the tenant. You retrieve this value; you do not generate it. Do not append /api/v2, a login path, or an API endpoint to the AirMDR Tenant URL field.
2

Generate an API Token

Netskope uses different token generation methods depending on whether your tenant has Role-Based Access Control (RBAC) V3 enabled. Follow the method available in your tenant.
Complete only the applicable method. After RBAC V3 is enabled, use the Service Account method for new tokens. Both methods generate credentials for accessing Netskope REST API v2.
3

Generate an API Token — RBAC V3

RBAC V3 — Service Account

Use this procedure when your tenant provides the Service Account option.
Ask a Netskope Tenant Admin to complete account and role provisioning.
  1. Open Settings → Administration → Administrators & Roles.
  2. Ensure an appropriate integration role exists with the permissions required by the AirMDR skills. If not create a dedicated role.
    Create a role to define the permissions available to the AirMDR service account.
    Sign in to Netskope with the predefined Tenant Admin role.
    1. Navigate to Settings → Administration > Administrators & Roles.
    2. Select the Roles tab.
    3. Click New.
    4. Enter the role details:
    5. Select the functional areas required by the AirMDR skills you intend to use.
    6. Review the functions and permissions displayed below the selected areas. Netskope automatically selects associated permissions; adjust them to retain only the required access and dependencies.
    7. Click the information icon beside a permission set to check its associated API endpoints. Confirm that it includes the methods and endpoints required by your skills.
    8. If applicable, configure Scope and Obfuscation to control which records and fields the integration can access.
    9. If your organization requires IP restrictions, open IP Allowlist and add the approved outbound IP addresses used by AirMDR or its Remote Agent.
    10. Click Save.
    11. Confirm that AirMDR-Integration-Role appears in the Roles list.
  3. Select the Administrators tab.
  4. Click Service Account.
  5. Enter a descriptive service account name, such as: AirMDR-Integration-Role
  6. Select the approved role from the Role dropdown.
  7. Configure REST API token generation and enter the expiration period in days.
  8. Leave the option to generate the token later unselected.
  9. Click Create.
  10. Copy the generated API token immediately and store it in an approved secrets manager.
    The token is displayed only once.
    Copy and securely save the API Token in your designated Password Manager or Vault.

    It cannot be retrieved after the creation screen is closed.
4

Generate an API Token — Legacy Workflow

Legacy — REST API v2

Use this procedure only when token creation remains available under REST API v2.
  1. Open Settings > Tools > REST API v2.
  2. Check REST API Status.
  3. If disabled, click the pencil icon, enable REST API access, and click Save.
  4. Click New Token.
  5. Enter a token name, such as AirMDR-Integration.
  6. Select an expiration period aligned with your organization’s credential policy.
  7. Click Add Endpoint.
  8. Select the endpoints confirmed for the AirMDR integration.
  9. Assign the required privileges to each endpoint:
    • Read for supported retrieval operations.
    • Read + Write where modification operations are required.
  10. Click Save.
  11. On the confirmation page, click Copy Token.
  12. Store the token securely, then click OK.
    The token is displayed only once.
    Copy and securely save the API Token in your designated Password Manager or Vault.

    It cannot be retrieved after the creation screen is closed.

Netskope Credential Reference Table

The Tenant URL is assigned to your organization; it is not generated during integration setup. Copy and securely store the API token when it is displayed.Do not include BearerNetskope-Api-Token:, or quotation marks in the API Token field.

Validate Connectivity

Use a read-only endpoint that the token is permitted to access. The example below queries alert records through Netskope’s Datasearch API.
The token or service account role must permit GET /api/v2/events/datasearch/alert. Permission for a Dataexport endpoint does not automatically establish permission for this endpoint.
  1. Open a Bash terminal on an approved system.
  2. Run the following commands, replacing the example Tenant URL:
  3. Confirm that the HTTP status is 200 and the response reports status.execution as SUCCESS.
  4. Review any error message before retrying.

Configure Netskope in AirMDR Integrations Dashboard

  1. Navigate to AirMDR, provide the credentials and click Login
  2. Navigate to the AirMDR Integrations Dashboard in the left navigation pane and select ADMIN → Integrations.
  3. Use the search option, enter the keyword “Netskope”, select the Connections tab, and click + New Connection button.
  4. Use the following values in the AirMDR integration configuration screen:
    1. In Remote Agent, select an AirMDR Remote Agent when access to your Netskope tenant requires an approved proxy or controlled outbound network route. If Netskope IP allowlisting is enabled, ensure the selected runtime’s outbound IP address is permitted. Otherwise, leave this field unselected unless instructed by your AirMDR administrator.
    2. In Expiry, select the date on which AirMDR should treat the stored Netskope credentials as expired, according to your organization’s credential-rotation policy. Set this date no later than the API token’s expiration in Netskope.
    The Expiry setting in AirMDR does not extend, rotate, or revoke the Netskope API token. Before the token expires, generate a replacement using the applicable Netskope token-generation method, update the API Token in AirMDR, and validate the connection. Revoke the previous token after confirming that all integrations using it have been updated.
  5. Click Save.

Skills provided by this Integration

The Netskope integration provides investigation, device and application assessment, policy review, and event retrieval skills to help security teams investigate activity, assess potential impact, and review Netskope security information.
Search alerts, examine DLP incidents, review audit activity, and assess the potential impact of user activity.
PingID’s GetUserDetails operation is part of the User Management API and returns user status and device details.
Retrieve device status and application risk information to support investigation and assessment.
Review configured URL lists and Netskope Private Access policies.
Retrieve event records for analysis and use in AirMDR workflows.
To view the details of Input Parameters and Output for the respective skills
  • Go to AirMDR → Netskope Integration page.
  • Select the Skills tab and click on the required listed skills.

Required Permission Summary

Additional Information

✅ Do
  • Use a dedicated service account for AirMDR when your tenant supports RBAC V3.
  • Grant only the endpoint and role permissions required by the enabled skills.
  • Use the Tenant URL and API Token from the same Netskope tenant.
  • Store the API token in an approved secrets manager and restrict access to authorized administrators.
  • Use HTTPS and keep TLS certificate validation enabled.
  • If IP allowlisting is enabled, permit the approved outbound IP addresses used by AirMDR or the selected Remote Agent.
  • Track token expiration and rotate credentials according to your organization’s security policy.
  • During routine rotation, update the token in AirMDR and validate the connection before revoking the previous token.
  • Review integration failures, role changes, and access to sensitive DLP forensic information.
  • Revoke exposed tokens promptly and replace them in affected connections.
❌ Don’t
  • Do not share API tokens through email, Slack, or support tickets.
  • Do not expose tokens in screenshots, logs, source-control repositories, or configuration examples.
  • Do not assign Tenant Admin or broad write permissions unless explicitly required and verified.
  • Do not assume access to one event endpoint permits access to every event type.
  • Do not use an example Tenant URL without replacing it with your actual tenant address.
  • Do not send the API token in URL query parameters.
  • Do not disable TLS verification to bypass connection errors.
  • Do not assume the Expiry field in AirMDR extends, rotates, or revokes the token in Netskope.
  • Do not retain unused tokens or service accounts after the integration is retired.
  • 📧 Contact AirMDR Support through your designated support channel.
  • 🔁 Rotate credentials regularly. Recommended cadence: As per internal security policy
  • 🔄 Reconnect in AirMDR immediately when API Keys are changed.
    Revoke the previous credential after confirming all consumers have migrated.
    Legacy tokens retained after RBAC V3 activation continue until expiration but cannot be extended. Plan migration before they expire.
  • Use the Netskope Support portal for tenant access, API availability, or token provisioning issues.
Data flow
  1. An AirMDR skill initiates a request to the configured Netskope tenant.
  2. Netskope evaluates the supplied token and its associated permissions.
  3. Netskope returns the requested data or operation result.
  4. AirMDR uses the response in the calling workflow.
Depending on the configured skills, exchanged data may include alerts, events, user or device information, and action results. Confirm the actual data categories with the AirMDR Integration team.If Netskope IP restrictions are enabled, allow the actual outbound IP addresses of the integration runtime. Netskope specifically calls out REST API client IP allowlisting.
Where to checkNetskope documents the API Credential information on the Administrators page.Recommended loggingWhere configurable, use INFO for routine outcomes, WARN for retryable failures, and ERROR for failed operations. Enable DEBUG temporarily for troubleshooting and redact credentials and sensitive payloads.Illustrative log entries—not actual AirMDR or Netskope log formats:
Monitor repeated failures, overdue token rotation, and gaps in expected data.