Integrations
Kandji (now Iru)
Tidal Control's Kandji integration reads the device state from your Kandji tenant for compliance purposes. Kandji rebranded to Iru in October 2025; the platform and its API are unchanged, and the integration tile in Tidal Control is still labelled Kandji. It authenticates with an API token against your own Kandji API URL, and provides the device evidence that auditors ask for on endpoint encryption and mobile device management.
What this integration monitors
- FileVault encryption: Whether full-disk encryption is enabled on each Mac
- Data volume encryption: Whether the data volume itself is encrypted
- MDM enrolment: Whether each device is still actively enrolled
- Device supervision: Whether devices are supervised
- Recovery Lock: Whether recovery lock is set
Requirements
- Super User role in Tidal Control
- A Kandji tenant, and permission to manage API tokens
- Your Kandji API URL, which is specific to your tenant
Configuration step-by-step plan
We'll find your tenant's API URL, create an API token, then add the connection in Tidal Control.
Configuration steps:
- Find your API URL
- Create an API token
- Configure the integration in Tidal Control
Step 1: Find your API URL
- Sign in to your Kandji tenant
- Go to Settings → Access → API Token
- Copy the API URL shown there. It is specific to your tenant and looks like
https://yourtenant.api.kandji.io
The API URL must include the scheme. Tidal Control rejects a value that does not start with http, so enter the full https://... URL rather than a bare hostname.
Step 2: Create an API token
- On the same Settings → Access page, add a new API Token
- Grant it the device-read permissions, so it can list devices and their details
- Copy the token immediately: Kandji shows it only once
Step 3: Configure the integration in Tidal Control
- Go to Settings → Integrations in Tidal Control
- Click the plus icon next to Kandji
- Fill in the configuration:
- Name: A descriptive name, for example
Kandji - API URL: The tenant URL from step 1
- API key: The token from step 2
- Name: A descriptive name, for example
- Click "Create" to save the integration
Configuration fields explained
The integration dialog asks for the following values:
Name:
- A descriptive name for this connection
- For example:
Kandji
API URL:
- Your tenant's Kandji API URL, including
https:// - Required
API key:
- The API token from step 2
- Required, and stored as a secret
Verification
The integration is working when all of the following are true:
- Settings → Integrations shows Kandji under Configured Integrations
- Kandji tests are available in the Tests section
- Test refresh returns device results without authentication errors
Frequently asked questions
Why is the API URL tenant-specific? Kandji hosts each tenant on its own subdomain, so there is no single shared API host to default to. You have to copy yours from the tenant.
Does this cover devices other than Macs? The checks cover the Apple device estate Kandji manages. Devices Kandji does not manage cannot appear, so treat Kandji coverage as part of your device inventory review.
Does Tidal Control read anything from the devices themselves? No. It reads device records from the Kandji API, which reports management state rather than user files.
Common problems
"API URL is required" or "API URL must start with http"
- Enter the full URL including the scheme, for example
https://yourtenant.api.kandji.io
"API Key is required"
- The token was not pasted, or was lost after creation. Create a new token in Kandji
Device checks return no devices
- The token lacks device-read permission, or the API URL points at a different tenant
Still can't figure it out?
Send an email to support@tidalcontrol.com, and we'll get back to you as soon as possible.
Gather support info: Note which browser you're using, exact error messages, and which steps you've already tried. This speeds up the solution considerably.
- Previous
- Jira Cloud
- Next
- Linear