Purpose
Purpose
Supported Versions
Supported Versions
pluto_ prefix.Authentication
Authentication
API key access
According to the AirMDR configuration guidance, the Pluto API key:- Authenticates requests to Pluto read endpoints.
- Authorizes supported issue-triage operations.
- Authorizes supported tagging operations.
- Authorizes supported add-on scanning operations.
- Attributes supported write operations to the API key in the Pluto audit log.
Role-based access considerations
Role-based access considerations
- Use a Pluto account authorized to access Integrations and manage API keys.
- Restrict API-key generation to approved administrators.
- If Pluto supports configurable key permissions, enable only the permissions required by the AirMDR integration.
- Do not generate the key from a personal account that may be disabled or removed unexpectedly.
- Review all write actions associated with the API key through the Pluto audit log.
Pre-requisites
An active Pluto Security tenant and access the Integrations page in the Pluto console.Determine whether your organization uses the US or EU Pluto tenant.
Setup Steps
Generate an API token in Pluto Security
- Sign in to your organization’s Pluto Security console.
- Open the Integrations page.
- Locate the Pluto API section.
- Select the available option to create a new API key.
The exact create-key button label may vary between Pluto UI versions.
- If prompted, enter a recognizable name for the key, such as:
AirMDR-Production. - Create the API key.
- Copy the generated key and store it temporarily in an approved secrets-management system.
- Verify that the key begins with the required prefix:
pluto_. - Record the key owner, purpose, creation date, and planned rotation date.
Determine the Base URL
- Sign in to Pluto Security.
- Check the hostname displayed in the browser address bar.
- If the hostname is
app.eu.pluto.security, use: https://app.eu.pluto.security. - If your organization uses the default US tenant, leave the Base URL field empty in AirMDR.
If your organization uses a custom or different hostname, contact Pluto Support or your Pluto administrator before proceeding.
Pluto Credential Reference Table
Validate Connectivity
Use the following request to confirm a read-only Pluto API endpoint to confirm that the Base URL and API token can access the tenant:Sample Request
Sample Request
Sample Response
Sample Response
Configure Pluto in AirMDR Integrations Dashboard
- Navigate to AirMDR, provide the credentials and click Login
- Navigate to the AirMDR Integrations Dashboard in the left navigation pane and select ADMIN → Integrations.
- Use the search option, enter the keyword “Pluto”, select the Connections tab, and click + New Connection button.
-
Use the following values in the AirMDR integration configuration screen:
Expand Advanced Configuration if required. (Optional)
- In Remote Agent, select an AirMDR Remote Agent only when the Pluto tenant must be accessed through an approved private network route, proxy, or controlled network environment. For publicly accessible Pluto SaaS tenants, leave this field unselected unless instructed otherwise by your AirMDR administrator.
- In Expiry, select the date on which AirMDR should treat the stored Pluto credentials as expired, according to your organization’s credential-rotation policy.
The Expiry date controls credential validity in AirMDR. It does not automatically rotate or revoke the API key in Pluto Security. Generate a replacement key in Pluto, update the AirMDR connection, validate it, and then revoke the previous key. - Click Save.
Skills provided by this Integration
Inventory and Discovery
Inventory and Discovery
hostname or user_email to limit the result set.Issue Investigation and Response
Issue Investigation and Response
update_pluto_issue, assignee_emails and assignee_ids replace the existing assignee list. Use clear_assignees to remove all existing assignees.AI Agent Activity and Audit
AI Agent Activity and Audit
14d or less.Governance and Inventory Management
Governance and Inventory Management
risk_levelcan be updated only forbuilderandapplicationentity types.- Use
commentwhen updating other supported entity types. - Passing an empty
business_contextvalue clears the existing business-context field. - The business-context value is limited to 4,000 characters.
- The Pluto-managed
org_infofield is not modified by the business-context skill.
AI Add-on Security Scanning
AI Add-on Security Scanning
Permission Summary
Additional Information
🧰 Error Handling
🧰 Error Handling
Recovery procedure
- Confirm the Pluto tenant region.
- Verify that the API token begins with
pluto_. - Confirm that the token has not been revoked or rotated.
- Review the AirMDR connection configuration.
- Test a read-only operation.
- Review AirMDR execution details and the Pluto audit log.
- Generate a replacement key if the existing key cannot be validated.
- Contact support if the issue continues.
🔄 Monitoring & Logs
🔄 Monitoring & Logs
- Issue-triage activity.
- Tagging operations.
- Add-on scanning requests.
- Identity or API key associated with the action.
- Timestamp and action status, where available.
- Connection-test results.
- Skill execution status.
- Request failures.
- Authentication errors.
- Response codes.
- Retry attempts.
🛑 Security & Access Best Practices
🛑 Security & Access Best Practices
- Use a dedicated API key for AirMDR.
- Apply least-privilege access wherever Pluto supports configurable permissions.
- Store the key in an approved secrets-management system.
- Rotate the API key according to your organization’s security policy.
- Monitor write operations through the Pluto audit log.
- Restrict integration administration to authorized users.
- Test configuration changes with a read-only action first.
- Revoke the API key immediately if exposure is suspected.
- Keep production and non-production credentials separate.
- Review integration access after administrator or employee changes.
- Sharing the API key through email, Slack, tickets, or documents.
- Storing the token in scripts or source-control repositories.
- Reusing a key assigned to another integration.
- Entering the public
https://pluto.securitywebsite as the API Base URL. - Using the EU Base URL for a default US tenant.
- Capturing the API token in screenshots or logs.
- Disabling TLS certificate validation.
- Leaving unused or former integration keys active.
👉 Support & Maintenance
👉 Support & Maintenance
- 📧 Contact AirMDR Support through your designated support channel.
- 🔁 Rotate credentials regularly. Recommended cadence: Every 90 days or as per internal security policy
- 🔄 Reconnect in AirMDR immediately when API Keys are changed.
- Use the official Pluto Security contact page, Pluto also identifies
info@pluto.securityas a contact address in its published terms.
🛑 Data Flow & Security
🛑 Data Flow & Security
- Requests for supported Pluto security information.
- Issue and finding identifiers.
- Issue-triage instructions.
- Tags and tag updates.
- Add-on scanning requests.
- Status information and API responses.
- Error codes and troubleshooting details.

