Skip to main content

Jamf Pro

Jamf Pro is an Apple device management and security platform for administering macOS, iOS, iPadOS, and tvOS devices at scale. The Jamf Pro API provides programmatic access to inventory, enrollment, and configuration data, letting you read device records and manage prestage enrollment configurations. Connect Nexla to Jamf Pro to ingest computer inventory and to automate the creation and maintenance of prestage enrollments.

Jamf Pro icon

Power end-to-end data operations for your Jamf Pro API with Nexla. Our bi-directional Jamf Pro connector is purpose-built for Jamf Pro, making it simple to ingest data, sync it across systems, and deliver it anywhere — all with no coding required. Nexla turns API-sourced data into ready-to-use, reusable data products and makes it easy to send data to Jamf Pro or any other destination. With comprehensive monitoring, lineage tracking, and access controls, Nexla keeps your Jamf Pro workflows fast, secure, and fully governed.

Features

Type: API

SourceDestination

  • Seamless API Integration: Connect to any endpoint as source or destination without coding, with automatic data product creation
  • Visual Composition & Chaining: Build complex integrations using visual templates, chain API calls, and compose workflows with data validation and filtering
  • API Proxy: Expose curated slices of your data securely with a secure and customizable API proxy that validates and transforms data on the fly
  • Request optimization with intelligent batching, retry, and caching to minimize API calls and costs

Prerequisites

Before creating a Jamf Pro credential, you need the base URL of your Jamf Pro instance and a set of credentials that can be exchanged for a short-lived bearer token. The Jamf Pro API issues a bearer token that is valid for a limited time (typically 20 minutes); Nexla obtains and refreshes this token automatically using the credentials you provide.

Jamf Pro supports two ways to obtain a bearer token:

  1. API Roles and Clients (recommended) — In your Jamf Pro instance, navigate to Settings > System > API roles and clients. First create an API Role that grants the privileges your integration needs (for example, read access to computer inventory and read/write access to prestage enrollments). Then, on the API Clients tab, create an API Client, assign it the role you created, and generate a Client Secret. The client secret is shown only once at creation time, so store it securely.

  2. Standard user account — Alternatively, you can authenticate with the username and password of a Jamf Pro user account that has the required permissions. The account's privileges determine which API endpoints are accessible.

To connect Nexla to Jamf Pro, gather the following:

  • Your Jamf Pro base URL, in the form https://yourinstance.jamfcloud.com.
  • A username (or API Client ID / API Key) and its corresponding password (or client secret).

For full details on authentication, API roles, and available endpoints, see the Jamf Pro API documentation and the Client Credentials guide.

Authenticate

Credentials required

FieldRequiredSecretDescription
Username Or API KeyYesNoYour username or personal API Key
PasswordYesYesYour password
Jamf Pro Base URLYesNoThe full base URL of your Jamf Pro instance (e.g. https://yourinstance.jamfcloud.com).

Create a credential in Nexla

  1. After selecting the data source/destination type, click the Add Credential tile to open the Add New Credential overlay.

  2. Enter a name for the credential in the Credential Name field and a short, meaningful description in the Credential Description field.

  3. Enter your username, API Client ID, or personal API Key in the Username Or API Key field.

  4. Enter the corresponding password or client secret in the Password field. This value is stored securely and used to obtain a bearer token from Jamf Pro.

  5. Enter the full base URL of your Jamf Pro instance in the Jamf Pro Base URL field (e.g. https://yourinstance.jamfcloud.com).

    Jamf Pro bearer tokens are short-lived. Nexla obtains and refreshes the token automatically from the credentials you provide, so no manual token management is required.

    For detailed information about Jamf Pro authentication, API roles and clients, and available endpoints, see the Jamf Pro API documentation.

  6. Click the Save button at the bottom of the overlay. The newly added credential will now appear in a tile on the Authenticate screen during data source/destination creation.

Use as a data source

To create a new data flow, navigate to the Integrate section, and click the New Data Flow button. Select the Jamf Pro connector tile, then select the credential that will be used to connect to the Jamf Pro instance, and click Next; or, create a new Jamf Pro credential for use in this flow.

Endpoint templates

Nexla provides pre-built templates that can be used to rapidly configure data sources to ingest data from common Jamf Pro endpoints. Select the endpoint from which this source will fetch data from the Endpoint pulldown menu. Available endpoint templates are listed in the expandable boxes below.

[Rest API] List Computers Inventory

Returns a paginated list of computers in the Jamf Pro inventory. Use this template when you need to ingest managed computer records for analysis, reporting, or synchronization with other systems.

  • This endpoint automatically retrieves computers accessible to your credential. Nexla handles pagination for you, iterating through pages until all records have been fetched.

This endpoint returns computer inventory information from your Jamf Pro instance, including device identifiers, hardware details, and management status. Nexla will automatically follow pagination to fetch subsequent pages of data.

For detailed information about the response structure and available inventory data, see the Jamf Pro API documentation.

Once the selected endpoint template has been configured, click the Test button to the right of the endpoint selection menu to retrieve a sample of the data that will be fetched. Sample data will be displayed in the Endpoint Test Result panel on the right, allowing you to verify that the source is configured correctly before saving.

Manual configuration

Jamf Pro data sources can also be manually configured to ingest data from any valid Jamf Pro API endpoint, including endpoints not covered by the pre-built templates, chained API calls, or custom request parameters. Select the Advanced tab at the top of the configuration screen, and follow the instructions in Connect to Any API to configure the API method, endpoint URL, date/time and lookup macros, path to data, metadata, and request headers.

Once all of the relevant settings have been configured, click the Create button in the upper right corner of the screen to save and create the new Jamf Pro data source. Nexla will now begin ingesting data from the configured endpoint and will organize any data that it finds into one or more Nexsets.

Use as a destination

Click the + icon on the Nexset that will be sent to the Jamf Pro destination, and select the Send to Destination option from the menu. Select the Jamf Pro connector from the list of available destination connectors, then select the credential that will be used to connect to the Jamf Pro instance, and click Next; or, create a new Jamf Pro credential for use in this flow.

Endpoint templates

Nexla provides pre-built templates that can be used to rapidly configure destinations to send data to common Jamf Pro endpoints. Select the endpoint to which data will be sent from the Endpoint pulldown menu. Then, click on the template in the list below to expand it, and follow the instructions to configure additional endpoint settings.

[Rest API] Create Computer Prestage

Create a new computer prestage enrollment configuration in Jamf Pro. Use this template when you need to automatically provision computer prestage enrollments based on records from a Nexset.

  • This endpoint sends data as JSON in the request body. Each record from your Nexset is sent as a separate API request to create a new computer prestage. The request body must contain the prestage configuration in the format required by the Jamf Pro API.

The prestage structure must match the Jamf Pro API's expected format. Ensure your records include all required fields for computer prestage creation. For detailed information about the request body and available properties, see the Jamf Pro API documentation.

[Rest API] Update Computer Prestage

Update an existing computer prestage enrollment configuration in Jamf Pro. Use this template when you need to modify prestage settings based on records from a Nexset.

  • This endpoint sends data as JSON in the request body using the PUT method. The prestage to update is identified by its ID, which is supplied as part of the endpoint configuration. Each record from your Nexset is sent as a separate API request.

The prestage structure must match the Jamf Pro API's expected format, and the target prestage ID must reference an existing configuration. For detailed information about the request body and available properties, see the Jamf Pro API documentation.

[Rest API] Delete Computer Prestage

Delete a computer prestage enrollment configuration from Jamf Pro. Use this template when you need to remove prestage configurations based on records from a Nexset.

  • This endpoint issues a DELETE request. The prestage to delete is identified by its ID, which is supplied as part of the endpoint configuration. Each record from your Nexset triggers a separate API request.

Deleting a prestage is irreversible. Confirm that the target prestage ID references the intended configuration before activating the destination. For detailed information, see the Jamf Pro API documentation.

[Rest API] Create Mobile Device Prestage

Create a new mobile device prestage enrollment configuration in Jamf Pro. Use this template when you need to automatically provision mobile device prestage enrollments based on records from a Nexset.

  • This endpoint sends data as JSON in the request body. Each record from your Nexset is sent as a separate API request to create a new mobile device prestage. The request body must contain the prestage configuration in the format required by the Jamf Pro API.

The prestage structure must match the Jamf Pro API's expected format. Ensure your records include all required fields for mobile device prestage creation. For detailed information about the request body and available properties, see the Jamf Pro API documentation.

Manual configuration

Jamf Pro destinations can also be manually configured to send data to any valid Jamf Pro API endpoint. Select the Advanced tab at the top of the configuration screen, and follow the instructions in Connect to Any API to configure the API method, data format, endpoint URL, request headers, attribute exclusions, record batching, and response webhooks.

Jamf Pro APIs expect JSON format for most write operations. For update or delete operations, include the ID of the object to be modified at the end of the URL.

Save & activate

Once all endpoint settings have been configured, click the Done button in the upper right corner of the screen to save and create the destination. To send the data to the configured Jamf Pro endpoint, open the destination resource menu, and select Activate.

The Nexset data will not be sent to the Jamf Pro endpoint until the destination is activated. Destinations can be activated immediately or at a later time, providing full control over data movement.