ThreatSabre Docs
OnboardingObtaining api info

Obtaining API credentials

Create read-only API administrators on FortiGate, FortiManager, or FortiManager Cloud so the ThreatSabre Agent can collect telemetry securely.

ThreatSabre uses read-only Fortinet API access. Provision the account that matches your deployment, then restrict it with trusted hosts to the Agent's IP when possible.

If you use…Follow
FortiGate (direct management)Create API User on FortiGate
FortiManager (on-prem or VM)Create API User on FortiManager
FortiManager CloudCreate API User on FortiManager Cloud

After the API user exists, you can use these credentials in the Onboarding wizard when you reach Step 3 — Agent Device to register your Agent Device. If you are not using the wizard, continue with device registration and Agent installation as described in Onboarding.