Skip to main content

Iru Endpoint Management API

Iru Endpoint Management is a mobile device management (MDM) platform for administering Apple, Windows, and Android device fleets. Its REST API exposes devices, Blueprints, Library Items, users, threats, and vulnerabilities, and supports remote device actions such as lock, erase, and Lost Mode. Nexla uses this API to ingest endpoint and security data and to push device-management commands back to the platform.

Iru Endpoint Management API icon

Power end-to-end data operations for your Iru Endpoint Management API API with Nexla. Our bi-directional Iru Endpoint Management API connector is purpose-built for Iru Endpoint Management API, making it simple to ingest data, sync it across systems, and deliver it anywhere — all with no coding required. Nexla turns API-sourced data into ready-to-use, reusable data products and makes it easy to send data to Iru Endpoint Management API or any other destination. With comprehensive monitoring, lineage tracking, and access controls, Nexla keeps your Iru Endpoint Management API workflows fast, secure, and fully governed.

Features

Type: API

SourceDestination

  • Seamless API Integration: Connect to any endpoint as source or destination without coding, with automatic data product creation
  • Visual Composition & Chaining: Build complex integrations using visual templates, chain API calls, and compose workflows with data validation and filtering
  • API Proxy: Expose curated slices of your data securely with a secure and customizable API proxy that validates and transforms data on the fly
  • Request optimization with intelligent batching, retry, and caching to minimize API calls and costs

Prerequisites

Before creating an Iru Endpoint Management credential, you need two pieces of information from your Iru tenant:

  1. API token — Iru Endpoint Management authenticates every API request with a secret bearer token. Generate an API token from the API settings of your Iru admin console, and grant it the permissions required for the endpoints you plan to use (for example, device read, Library, and device-action permissions). Copy the token when it is displayed, as it may not be retrievable afterward.

  2. Tenant subdomain — Your API requests are made against your tenant-specific host, https://{sub}.api.iru.com, where {sub} is your Iru tenant subdomain. You can identify it from the URL you use to sign in to your Iru admin console.

Treat the API token as sensitive. If it is ever exposed, revoke it in your Iru admin console and generate a new one. For detailed information about authentication and available endpoints, refer to the Iru Endpoint Management API documentation.

Authenticate

Credentials required

FieldRequiredSecretDescription
API Key ValueYesYesAn encoded string value used as a secret token to authenticate API requests
Sub DomainYesNoYour Iru tenant subdomain, e.g. the {sub} in {sub}.api.iru.com

Create a credential in Nexla

  1. After selecting the data source/destination type, click the Add Credential tile to open the Add New Credential overlay.

  2. Enter a name for the credential in the Credential Name field and a short, meaningful description in the Credential Description field.

  3. Enter your API token in the API Key Value field. This token is sent as a bearer token in the Authorization header of every API request and must be kept confidential.

  4. Enter your Iru tenant subdomain in the Sub Domain field. This is the {sub} portion of your tenant host https://{sub}.api.iru.com and is used to construct the API endpoint URLs for your tenant.

    If your API token is compromised, revoke it in your Iru admin console and generate a new one. The token grants access to your device fleet and management actions, and should be treated as sensitive information.

  5. Click the Save button at the bottom of the overlay. The newly added credential will now appear in a tile on the Authenticate screen during data source/destination creation.

Use as a data source

To create a new data flow, navigate to the Integrate section, and click the New Data Flow button. Select the Iru Endpoint Management API connector tile, then select the credential that will be used to connect to the Iru tenant, and click Next; or, create a new Iru Endpoint Management credential for use in this flow.

Endpoint templates

Nexla provides pre-built templates that can be used to rapidly configure data sources to ingest data from common Iru Endpoint Management endpoints. Select the endpoint from which this source will fetch data from the Endpoint pulldown menu. Available endpoint templates are listed in the expandable boxes below.

[Rest API] List tenant admins (actors)

Retrieves a list of tenant admins. The ID of each admin can be mapped to an actor_id listed in audit events.

[Rest API] List ADE devices

Retrieves a list of Automated Device Enrollment (ADE) devices, including their Blueprint assignment and routing state.

[Rest API] Update ADE device

Updates a specific Automated Device Enrollment device's Blueprint assignment, assigned ADE Library Item, user assignment, and asset tag.

[Rest API] List Blueprints

Returns a list of Blueprints. Optional query parameters can be specified to filter the results.

[Rest API] Get Blueprint

Returns information about a specific Blueprint based on Blueprint ID.

[Rest API] Create Blueprint

Creates a new empty Blueprint or a new Blueprint from a template. The name and enrollment code activation keys are required, and the Blueprint name must be unique.

[Rest API] List Library Items

Retrieves a list of Library Items associated with a specific Blueprint (classic and maps). Requires the Blueprint ID as a path parameter.

[Rest API] Assign Library Item

Assigns a Library Item to a specific Blueprint (classic and maps). The response includes the list of Library Item IDs assigned to the Blueprint.

[Rest API] Enable Lost Mode

Sends an MDM command to remotely turn on Lost Mode on iOS and iPadOS. Optionally, a payload can set a lock message, phone number, and footnote.

[Rest API] Get Device Commands

Returns information about the commands sent to a given Apple device, including each command's MDM status.

[Rest API] Lock Device

Sends an MDM command to remotely lock an Apple or Android device. For macOS clients, an unlock PIN is created and returned in the response.

[Rest API] List Devices

Returns a list of devices in an Iru Endpoint Management tenant. Optional query parameters can filter the results. There is a hard upper limit of 300 results per request.

[Rest API] Get Device

Returns the high-level information for a specified Device ID. This is a polymorphic endpoint; if Windows or Android management is turned on, additional fields are returned.

[Rest API] Get Device Details

Returns the device details for a specified Device ID. This is a polymorphic endpoint whose response is tailored to the device platform.

[Rest API] Get Device Apps

Returns a list of all installed apps for a specified Device ID. For iPhone and iPad, preinstalled Apple apps are not reported.

[Rest API] Get Device Library Items

Returns all Library Items and their statuses for a specified Device ID.

[Rest API] Get Device Status

Returns the full status (parameters and Library Items) for a specified Device ID. Parameters are returned as a list of IDs that can be correlated with parameter definitions.

[Rest API] Update Device

Updates device information such as the assigned Blueprint, user, Asset Tag, and Tags for a specified Device ID. It is not required to include every attribute in a request.

[Rest API] List Custom Apps

Retrieves a list of Custom Apps from the Library.

[Rest API] List Custom Profiles

Retrieves a list of Custom Profiles from the Library.

[Rest API] List Custom Scripts

Retrieves a list of Custom Scripts from the Library.

[Rest API] Get Threat Details - v2

Returns threat details. This second version offers improved performance and access to newer features like severity, tags, and management state.

[Rest API] Get Behavioral Detections - v2

Returns behavioral detection events. This second version offers improved performance and access to newer features like severity, tags, and management state.

[Rest API] List Users

Retrieves a list of users from user directory integrations. A default of 25 records are returned per request, up to a maximum of 300 records per request.

[Rest API] List Detections

Retrieves a list of all vulnerability detections across the device fleet.

[Rest API] List Vulnerabilities

Retrieves a list of all vulnerabilities grouped by CVE.

Once the selected endpoint template has been configured, click the Test button to the right of the endpoint selection menu to retrieve a sample of the data that will be fetched. Sample data will be displayed in the Endpoint Test Result panel on the right, allowing you to verify that the source is configured correctly before saving.

Manual configuration

Iru Endpoint Management data sources can also be manually configured to ingest data from any valid Iru Endpoint Management API endpoint, including endpoints not covered by the pre-built templates, chained API calls, or custom request parameters. Select the Advanced tab at the top of the configuration screen, and follow the instructions in Connect to Any API to configure the API method, endpoint URL, date/time and lookup macros, path to data, metadata, and request headers.

Once all of the relevant settings have been configured, click the Create button in the upper right corner of the screen to save and create the new Iru Endpoint Management data source. Nexla will now begin ingesting data from the configured endpoint and will organize any data that it finds into one or more Nexsets.

Use as a destination

Click the + icon on the Nexset that will be sent to the Iru Endpoint Management destination, and select the Send to Destination option from the menu. Select the Iru Endpoint Management API connector from the list of available destination connectors, then select the credential that will be used to connect to the Iru tenant, and click Next; or, create a new Iru Endpoint Management credential for use in this flow.

Endpoint templates

Nexla provides pre-built templates that can be used to rapidly configure destinations to send data to common Iru Endpoint Management endpoints. Select the endpoint to which data will be sent from the Endpoint pulldown menu. Then, click on the template in the list below to expand it, and follow the instructions to configure additional endpoint settings.

[Rest API] Update Blueprint

Updates an existing Blueprint. Each record from the Nexset is sent as a PATCH request to update the Blueprint identified by its Blueprint ID.

[Rest API] Disable Lost Mode

Sends an MDM command to remotely turn off Lost Mode on the specified device.

[Rest API] Clear Passcode

Sends an MDM command to clear the passcode on the specified device.

[Rest API] Erase Device

Sends an MDM command to remotely erase the specified device.

Manual configuration

Iru Endpoint Management destinations can also be manually configured to send data to any valid Iru Endpoint Management API endpoint. Select the Advanced tab at the top of the configuration screen, and follow the instructions in Connect to Any API to configure the API method, data format, endpoint URL, request headers, attribute exclusions, record batching, and response webhooks.

Save & activate

Once all endpoint settings have been configured, click the Done button in the upper right corner of the screen to save and create the destination. To send the data to the configured Iru Endpoint Management endpoint, open the destination resource menu, and select Activate.

The Nexset data will not be sent to the Iru Endpoint Management endpoint until the destination is activated. Destinations can be activated immediately or at a later time, providing full control over data movement.