Jamf Pro
Jamf Pro is an Apple device management and security platform for administering macOS, iOS, iPadOS, and tvOS devices at scale. The Jamf Pro API provides programmatic access to inventory, enrollment, and configuration data, letting you read device records and manage prestage enrollment configurations. Connect Nexla to Jamf Pro to ingest computer inventory and to automate the creation and maintenance of prestage enrollments.
Power end-to-end data operations for your Jamf Pro API with Nexla. Our bi-directional Jamf Pro connector is purpose-built for Jamf Pro, making it simple to ingest data, sync it across systems, and deliver it anywhere — all with no coding required. Nexla turns API-sourced data into ready-to-use, reusable data products and makes it easy to send data to Jamf Pro or any other destination. With comprehensive monitoring, lineage tracking, and access controls, Nexla keeps your Jamf Pro workflows fast, secure, and fully governed.
Features
Type: API
- Seamless API Integration: Connect to any endpoint as source or destination without coding, with automatic data product creation
- Visual Composition & Chaining: Build complex integrations using visual templates, chain API calls, and compose workflows with data validation and filtering
- API Proxy: Expose curated slices of your data securely with a secure and customizable API proxy that validates and transforms data on the fly
- Request optimization with intelligent batching, retry, and caching to minimize API calls and costs
Prerequisites
Before creating a Jamf Pro credential, you need the base URL of your Jamf Pro instance and a set of credentials that can be exchanged for a short-lived bearer token. The Jamf Pro API issues a bearer token that is valid for a limited time (typically 20 minutes); Nexla obtains and refreshes this token automatically using the credentials you provide.
Jamf Pro supports two ways to obtain a bearer token:
-
API Roles and Clients (recommended) — In your Jamf Pro instance, navigate to Settings > System > API roles and clients. First create an API Role that grants the privileges your integration needs (for example, read access to computer inventory and read/write access to prestage enrollments). Then, on the API Clients tab, create an API Client, assign it the role you created, and generate a Client Secret. The client secret is shown only once at creation time, so store it securely.
-
Standard user account — Alternatively, you can authenticate with the username and password of a Jamf Pro user account that has the required permissions. The account's privileges determine which API endpoints are accessible.
To connect Nexla to Jamf Pro, gather the following:
- Your Jamf Pro base URL, in the form
https://yourinstance.jamfcloud.com. - A username (or API Client ID / API Key) and its corresponding password (or client secret).
For full details on authentication, API roles, and available endpoints, see the Jamf Pro API documentation and the Client Credentials guide.
Authenticate
Credentials required
| Field | Required | Secret | Description |
|---|---|---|---|
| Username Or API Key | Yes | No | Your username or personal API Key |
| Password | Yes | Yes | Your password |
| Jamf Pro Base URL | Yes | No | The full base URL of your Jamf Pro instance (e.g. https://yourinstance.jamfcloud.com). |
Create a credential in Nexla
-
After selecting the data source/destination type, click the Add Credential tile to open the Add New Credential overlay.
-
Enter a name for the credential in the Credential Name field and a short, meaningful description in the Credential Description field.
-
Enter your username, API Client ID, or personal API Key in the Username Or API Key field.
-
Enter the corresponding password or client secret in the Password field. This value is stored securely and used to obtain a bearer token from Jamf Pro.
-
Enter the full base URL of your Jamf Pro instance in the Jamf Pro Base URL field (e.g.
https://yourinstance.jamfcloud.com).Jamf Pro bearer tokens are short-lived. Nexla obtains and refreshes the token automatically from the credentials you provide, so no manual token management is required.
For detailed information about Jamf Pro authentication, API roles and clients, and available endpoints, see the Jamf Pro API documentation.
-
Click the Save button at the bottom of the overlay. The newly added credential will now appear in a tile on the Authenticate screen during data source/destination creation.
Use as a data source
To create a new data flow, navigate to the Integrate section, and click the New Data Flow button. Select the Jamf Pro connector tile, then select the credential that will be used to connect to the Jamf Pro instance, and click Next; or, create a new Jamf Pro credential for use in this flow.
Endpoint templates
Nexla provides pre-built templates that can be used to rapidly configure data sources to ingest data from common Jamf Pro endpoints. Select the endpoint from which this source will fetch data from the Endpoint pulldown menu. Available endpoint templates are listed in the expandable boxes below.
Once the selected endpoint template has been configured, click the Test button to the right of the endpoint selection menu to retrieve a sample of the data that will be fetched. Sample data will be displayed in the Endpoint Test Result panel on the right, allowing you to verify that the source is configured correctly before saving.
Manual configuration
Jamf Pro data sources can also be manually configured to ingest data from any valid Jamf Pro API endpoint, including endpoints not covered by the pre-built templates, chained API calls, or custom request parameters. Select the Advanced tab at the top of the configuration screen, and follow the instructions in Connect to Any API to configure the API method, endpoint URL, date/time and lookup macros, path to data, metadata, and request headers.
Once all of the relevant settings have been configured, click the Create button in the upper right corner of the screen to save and create the new Jamf Pro data source. Nexla will now begin ingesting data from the configured endpoint and will organize any data that it finds into one or more Nexsets.
Use as a destination
Click the + icon on the Nexset that will be sent to the Jamf Pro destination, and select the Send to Destination option from the menu. Select the Jamf Pro connector from the list of available destination connectors, then select the credential that will be used to connect to the Jamf Pro instance, and click Next; or, create a new Jamf Pro credential for use in this flow.
Endpoint templates
Nexla provides pre-built templates that can be used to rapidly configure destinations to send data to common Jamf Pro endpoints. Select the endpoint to which data will be sent from the Endpoint pulldown menu. Then, click on the template in the list below to expand it, and follow the instructions to configure additional endpoint settings.
Manual configuration
Jamf Pro destinations can also be manually configured to send data to any valid Jamf Pro API endpoint. Select the Advanced tab at the top of the configuration screen, and follow the instructions in Connect to Any API to configure the API method, data format, endpoint URL, request headers, attribute exclusions, record batching, and response webhooks.
Jamf Pro APIs expect JSON format for most write operations. For update or delete operations, include the ID of the object to be modified at the end of the URL.
Save & activate
Once all endpoint settings have been configured, click the Done button in the upper right corner of the screen to save and create the destination. To send the data to the configured Jamf Pro endpoint, open the destination resource menu, and select Activate.
The Nexset data will not be sent to the Jamf Pro endpoint until the destination is activated. Destinations can be activated immediately or at a later time, providing full control over data movement.