ThreatSabre Docs
OnboardingObtaining api info

Create API User on FortiManager

How to obtain an API key for FortiManager

To allow ThreatSabre to retrieve telemetry and posture data for your managed FortiGate devices via FortiManager, you must provision a REST API administrator. This administrative account facilitates secure access to the FortiManager.

You may restrict the API user to only certain ADOMs. This can be used in multi-tenanted FortiManagers where you want to align ADOMs in your FortiManager with Organizations in ThreatSabre.


Method 1: Graphical User Interface (GUI)

Follow these steps to generate an API key for the ThreatSabre Agent.

Step 1: Create a Read-Only Admin Profile

  1. Navigate to System Settings > Admin > Profile.

  2. Click Create New.

  3. Profile Name: ThreatSabre_FMG_RO.

  4. Type: Set to System Admin.

  5. Set the Device Manager > Retrieve Configuration from Devices permissions to Read. Set all other permissions to None.

  6. Click OK.

FortiManager Admin Profile

Step 2: Create the REST API User

  1. Navigate to System Settings > Admin > Administrator.

  2. Click Create New and select REST API Admin.

  3. User Name: TS_FMG_Audit.

  4. Admin Profile: Select ThreatSabre_FMG_RO.

  5. Trusted Hosts: Add the IP of your ThreatSabre Agent host to ensure the API can only be called from your Agent Virtual Machine. (e.g., 10.x.x.x/255.255.255.255).

  6. Click OK.

FortiManager Admin User

  1. Copy the Token: A pop-up window will display the API Key.

In some cases this pop-up will not appear. After creating the user, edit the newly created user and click the Regenerate option under Regenerate API Key.

FortiManager will never show this key again. If you lose it, you must regenerate it.


Method 2: Command Line Interface (CLI)

Use these commands to deploy the read-only system profile and REST API User. Replace <Agent_IP> in the user configuration with the IP address of your ThreatSabre Agent host.

1. Create the Profile

# Enter the administrator profile configuration
config system admin profile
    edit "ThreatSabre_FMG_RO"
        
        # Profile Identity
        set type system                   # Define as a system-wide profile
        set scope global                  # Grant visibility across all ADOM
        
        # Device Manager & Operations
        set device-manager read           # Base Device Manager access
        set device-config read            # View managed device configs
    next
end

Running the get command within the profile context is the best way to verify that every attribute has been registered by the FortiManager.

config system admin profile
    edit "ThreatSabre_FMG_RO"
    get

FortiManager Admin Profile (CLI)

2. Create the User & Assign Trusted Host

# Enter the system administrator user configuration context
config system admin user
    # Create or edit the specific audit service account
    edit "TS_FMG_Audit"
        # Identify this account as a REST API type (disables GUI/Console login)
        set user_type api
        
        # Link the user to the granular read-only profile created previously
        set profileid "ThreatSabre_FMG_RO"
        
        # Grant visibility to all Administrative Domains (ADOMs)
        set adom-access all
        
        # Set the JSON-RPC permission level to 'read'
        set rpc-permit read
        
        # Security: Restrict API access to the ThreatSabre Agent host IP
        set trusthost1 <Agent_IP> 255.255.255.255
    next
end

Running the get command within the user context is the best way to verify that every attribute has been registered by the FortiManager.

config system admin user
    edit "TS_FMG_Audit"
    get

FortiManager Admin User (CLI)

3. Generate the API Token

You must manually trigger the key generation to retrieve it via CLI:

execute api-user generate-key TS_FMG_Audit

On this page