Skip to main content

About Jamf Protect

Jamf Protect is Jamf’s endpoint-security product for macOS - detection, visibility, and compliance for Mac fleets. Connecting it to Serval lets your team list and triage security alerts, look up enrolled computers, inspect plans and the analytics catalog, read tenant audit logs, and remove computer records - all through Serval workflows that call your tenant’s Jamf Protect GraphQL API on your behalf. Serval only ever sends authenticated requests to the exact Protect tenant you configure. Authentication: Jamf Protect API client. You create an API client in the Protect console and give Serval the Client ID and Password plus your tenant name. Serval stores the Client ID and an encrypted copy of the password, and exchanges them for short-lived access tokens against your own tenant on demand - no browser-based sign-in and no user-level consent. Data sync: On demand. There is no background sync - workflows call the Jamf Protect API when they run (subject to each workflow’s approval procedure).

What the Jamf Protect integration enables

Get your credentials

Serval authenticates with a Jamf Protect API client. See Jamf’s guide, Creating an API Client in Jamf Protect, for full details. Note that tenants are limited to five API clients.
1

Open API Clients

Log in to Jamf Protect and go to AdministrativeAPI Clients, then select Create API Client.
2

Assign a role

Name the client (e.g. “Serval Integration”) and assign a role. A read-only role covers the listing workflows; updating alert status and deleting computers need the matching write permissions. You can change the role later without reconnecting.
3

Copy the credentials

Copy the Client ID and the generated Password immediately - the password is shown only once.

Connect Jamf Protect to Serval

1

Open integrations

In Serval, go to SettingsIntegrations and select Jamf Protect.
2

Enter your tenant and credentials

Enter your Protect tenant (the first part of your tenant URL, e.g. your-tenant for https://your-tenant.protect.jamfcloud.com - pasting the full URL also works), the Client ID, and the Password.
3

Connect

Click connect. Healthchecks run immediately and verify the credentials can reach your tenant’s alerts, computers, and analytics.