> ## Documentation Index
> Fetch the complete documentation index at: https://docs.serval.com/llms.txt
> Use this file to discover all available pages before exploring further.

# ManageEngine Endpoint Central (On-Premises)

> Connect Serval to your self-hosted ManageEngine Endpoint Central server so workflows can look up managed computers, read inventory and patch status, and, when you allow it, deploy patches.

## About ManageEngine Endpoint Central (On-Premises)

ManageEngine Endpoint Central (formerly Desktop Central) manages Windows, macOS, and Linux endpoints: it inventories hardware and software, scans for missing patches and vulnerabilities, and deploys patches and software. This integration connects Serval to an Endpoint Central server you host yourself. If you use Endpoint Central Cloud, use the [ManageEngine Endpoint Central](/sections/integrations/manageengine-endpoint-central) integration instead; the two share the same API but authenticate differently. The integration is marked **Beta** in the connect screen, so its capabilities may still change.

**Authentication:** An Endpoint Central authentication key for a dedicated console user. Serval sends it to your server on each request, and workflows never handle it.

**Access level:** You choose what Serval may do when you connect, and Serval enforces it server-side on every request:

* **Read-only** reads computers, inventory, patches, vulnerabilities, custom fields, and reports.
* **Full** adds approving and deploying patches, scanning computers, managing agents, and editing custom fields.

The key's Endpoint Central role applies on top of the access level: Serval can never do more than that user can.

**Data sync:** None. Serval calls your server only when a workflow or health check runs.

## What the Endpoint Central (On-Premises) integration enables

| Capability | Description |
| - | - |
| Endpoint Central API request | A generic workflow action that can call the Endpoint Central REST API (`/api/1.4` and `/dcapi` paths): Scope of Management computers and agents, inventory (hardware, software, licenses, prohibited software), patch management (patches, systems, approval, deployment, and automated patch deployment tasks), vulnerabilities and misconfigurations, BitLocker reports, custom groups, custom fields, and query reports. |

<Note>
  The read-only access level is enforced by Serval, not just documented: with it selected, Serval refuses any request to your server that isn't a read, so workflows can't deploy patches, change agents, or edit custom fields.
</Note>

## Before you connect

<AccordionGroup>
  <Accordion title="Serval must be able to reach the server over the network">
    Most Endpoint Central servers sit on an internal network that Serval's cloud can't reach. Three deployments are possible:

    * **Server reachable from the internet**: connect normally, nothing extra needed.
    * **Self-hosted Serval deployment**: works when your deployment is configured to allow internal targets.
    * **Serval cloud with a self-hosted worker**: Enable **Run on self-hosted workers** for the connection. Requests then run from your network; the worker must be able to reach the server on its HTTPS port (8383 by default). A read-only connection also needs an up-to-date worker: on an older worker every request fails with a message asking you to upgrade it, because the older worker cannot enforce the read-only boundary per request.
  </Accordion>

  <Accordion title="The server's TLS certificate must be trusted">
    Serval always connects over HTTPS and verifies the server's certificate. Endpoint Central installs with a self-signed certificate, which fails verification. Either replace it with a certificate from a CA Serval trusts, or, when connecting through a self-hosted worker, pass your internal CA chain to the worker with `--ca-certificate` when you install or upgrade it. Serval never skips certificate verification.
  </Accordion>
</AccordionGroup>

## Get your credentials

<Steps>
  <Step title="Create a dedicated user and role">
    In the Endpoint Central console, go to **Admin**, then **User Administration**, and create a user such as `svc-serval`. Give it a role that grants only the modules your workflows need, for example read access to Scope of Management, Inventory, and Patch Management. For a Full connection, add write access to the modules workflows will change. Make sure the role allows API access.
  </Step>

  <Step title="Generate an authentication key">
    Sign in as that user, go to **Admin**, then **Integrations**, then **API Explorer**, and open **Authentication**. Choose **Local Authentication** or **AD Authentication** to match the account, enter its credentials, and run the login. If two-factor authentication is enabled, complete the one-time-password step. Copy the `auth_token` value from the response; this is the authentication key.
  </Step>

  <Step title="Note your server host">
    Use the hostname or IP address you use to open the Endpoint Central console, without the "https\://" prefix, for example `endpointcentral.example.com`. The server listens on port 8383 for HTTPS unless your installation changed it.
  </Step>
</Steps>

## Connect in Serval

<Steps>
  <Step title="Open the integration">
    In Serval, go to the integrations page and select **ManageEngine Endpoint Central (On-Premises)** (marked Beta).
  </Step>

  <Step title="Enter the Endpoint Central Server Host">
    Enter the hostname or IP address of your server, for example `endpointcentral.example.com`. Port 8383 is assumed; add a port only if your server uses a different one.
  </Step>

  <Step title="Enter the Authentication Key">
    Paste the key from the previous section. It's stored encrypted and shown masked after saving.
  </Step>

  <Step title="Choose the Access Level">
    Select **Read-only** unless workflows need to deploy patches, manage agents, or edit custom fields. You can change it later in the integration settings.
  </Step>

  <Step title="Save, then run the health checks">
    Saving validates the format of what you entered but doesn't call your server, because the connect screen can't reach an internal network even when workflows can. Run the health checks afterward to confirm the key works.
  </Step>
</Steps>

## Verifying the connection

| Health check | What it proves |
| - | - |
| Test Endpoint Central Connection | The server is reachable and the authentication key is accepted. |
| List Endpoint Central Managed Computers | The user's role can read Scope of Management. |
| List Endpoint Central Inventory Computers | The user's role can read Inventory. |
| Read Endpoint Central Patch Summary | The user's role can read Patch Management. |

If the connection test passes but a module check fails, the key is valid and the user's role lacks that module.

## Gotchas and troubleshooting

<AccordionGroup>
  <Accordion title="The key is invalid after the user changes">
    The authentication key belongs to the user that generated it. Deleting or disabling that user, or generating a new key for it, invalidates the stored key and requests fail with an authentication error. Generate a new key and update it in the integration settings.
  </Accordion>

  <Accordion title="Results are scoped to the user's permissions">
    Endpoint Central returns only the computers and data the key's user can see. When a workflow can't find a computer you know is managed, check the user's role and scope before suspecting the connection.
  </Accordion>

  <Accordion title="IPv6 addresses are not supported">
    Enter a hostname or an IPv4 address for the server. IPv6 addresses are rejected when you save the connection, because the self-hosted worker's network rules support IPv4 only.
  </Accordion>

  <Accordion title="Endpoint Central MSP is not supported">
    Endpoint Central MSP uses a different API version and isn't covered by this integration.
  </Accordion>

  <Accordion title="Deploying patches changes endpoints">
    With the Full access level, a workflow can approve and install patches, which can reboot the targeted computers depending on the deployment policy. Scope such workflows to explicit resource IDs, and test them against a small custom group first.
  </Accordion>

  <Accordion title="This integration is in Beta">
    The connect tile is marked Beta, so the available actions may still change.
  </Accordion>
</AccordionGroup>

***

Need help? Contact **[support@serval.com](mailto:support@serval.com)** for assistance with your ManageEngine Endpoint Central integration.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.