Skip to main content
Tools Reference

Addigy Tools

Written By Christopher Scaminaci

Last updated 7 days ago

Addigy Tools

addigy_ · 255 tools · Free 119 · Pro 136 Static x-api-key (v2 token, granular per-token permissions); fixed base https://api.addigy.com/api/v2; org-scoped paths take organizationId; page/per_page (cap 500).

All connector tools · Addigy setup guide

Addigy tool groups

Devices

ToolPlanAccessSummary
addigy_assign_devices_to_policyProDestructiveAssign one or more devices to one or more policies.
addigy_delete_deviceProDestructiveRemove a single device from Addigy by its serial number.
addigy_get_device_benchmark_compliance_statusFreeRead-onlyGet a device's compliance statuses per security benchmark for a specific organization.
addigy_get_device_policy_assignmentsFreeRead-onlyGet the list of policy IDs assigned to a specific device.
addigy_get_managed_admin_passwordFreeRead-onlyReveal the current managed admin password for a specific account on a device.
addigy_get_mdm_device_detailsFreeRead-onlyGet MDM device details for a single device including enrollment profile, APN certificate, and last MDM response.
addigy_list_available_factsFreeRead-onlyList the available device facts for an organization.
addigy_list_device_managed_adminsFreeRead-onlyList the managed admin accounts associated with a specific device.
addigy_query_devices_compliance_statusFreeRead-onlyGet overall compliance status for a set of devices.
addigy_query_installed_apps_via_agentFreeRead-onlyQuery installed applications reported by the Addigy agent for one or more devices.
addigy_query_installed_apps_via_mdmFreeRead-onlyQuery installed applications reported via MDM for one or more devices.
addigy_query_mdm_certificatesFreeRead-onlyPaginated list of certificates installed on MDM devices.
addigy_rotate_managed_admin_passwordProDestructiveRotate the managed admin password for a specific account on a device.
addigy_search_devicesFreeRead-onlyUniversal device search: query for devices by any device fact (e.g. serial_number, hostname, model).
addigy_test_mdm_device_responseFreeRead-onlyTest the MDM response for a single device — probes whether the device responds to an MDM command, useful for diagnosing unresponsive or stale MDM enrollments.
addigy_unassign_devices_from_policyProDestructiveUnassign one or more devices from one or more policies.

[Addigy] Assign one or more devices to one or more policies. Required body fields: `agent_ids` (non-empty array of device agent IDs) and `policy_ids` (non-empty array of policy IDs). Requires organizationId (from addigy_list_child_organizations). Use addigy_get_device_policy_assignments to verify current assignments. Requires API token permission: Assign/Unassign Device Policies.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object with the assignment. Required: agent_ids (non-empty array of agent IDs), policy_ids (non-empty array of policy IDs).
organizationIdstringyesOrganization ID (from addigy_list_child_organizations).

[Addigy] Remove a single device from Addigy by its serial number. DESTRUCTIVE — the device is deleted from the organization. NOTE: this endpoint is not intended for bulk removal. Requires organizationId (from addigy_list_child_organizations) and the device's serial number (sn). Requires API token permission: Delete Devices.

ParamTypeRequiredDefaultDescription
organizationIdstringyesOrganization ID (from addigy_list_child_organizations).
snstringyesThe device's serial number.

[Addigy] Get a device's compliance statuses per security benchmark for a specific organization. Returns an array of benchmark compliance statuses for the given agent. Requires organizationId (from addigy_list_child_organizations) and the device's agentId. Requires API token permission: View Devices.

ParamTypeRequiredDefaultDescription
agentIdstringyesAgent ID of the device to check.
organizationIdstringyesOrganization ID (from addigy_list_child_organizations).

[Addigy] Get the list of policy IDs assigned to a specific device. Returns an array of policy id strings. Requires organizationId (from addigy_list_child_organizations) and the device's agentId. Use addigy_assign_devices_to_policy / addigy_unassign_devices_from_policy to change assignments. Requires API token permission: View Devices.

ParamTypeRequiredDefaultDescription
agentIdstringyesAgent ID of the device.
organizationIdstringyesOrganization ID (from addigy_list_child_organizations).

[Addigy] Reveal the current managed admin password for a specific account on a device. NOTE: revealing the password also schedules a rotation on the device in one hour. Requires organizationId (from addigy_list_child_organizations), the device's agentId, and the accountName (discover via addigy_list_device_managed_admins). Requires API token permission: View Managed Admin Password.

ParamTypeRequiredDefaultDescription
accountNamestringyesAccount name of the managed admin whose password to reveal.
agentIdstringyesAgent ID of the device.
organizationIdstringyesOrganization ID (from addigy_list_child_organizations).

[Addigy] Get MDM device details for a single device including enrollment profile, APN certificate, and last MDM response. The device UUID is the MDM device identifier (distinct from the agent_id used by /o/ device endpoints). Use addigy_search_devices to discover devices.

ParamTypeRequiredDefaultDescription
deviceUuidstringyesDevice UUID (MDM device identifier).

[Addigy] List the available device facts for an organization. Returns an array of fact definitions whose identifiers can be passed as desiredFactIdentifiers or used in filters for addigy_search_devices. Requires organizationId (from addigy_list_child_organizations).

ParamTypeRequiredDefaultDescription
organizationIdstringyesOrganization ID (from addigy_list_child_organizations).

[Addigy] List the managed admin accounts associated with a specific device. Returns managed-user records (account names and metadata). Requires organizationId (from addigy_list_child_organizations) and the device's agentId; optionally filter to a single accountName. Requires API token permission: View Mac Users.

ParamTypeRequiredDefaultDescription
accountNamestringnonullOptional account name to filter to a single managed admin. Omit for all managed admins on the device.
agentIdstringyesAgent ID of the device.
organizationIdstringyesOrganization ID (from addigy_list_child_organizations).

[Addigy] Get overall compliance status for a set of devices. Provide agent_ids in fieldsJson to scope the query (omit/empty for all devices). Returns an array of device compliance statuses. Aggregates across child organizations when multitenancy=true. Requires API token permission: View Devices.

ParamTypeRequiredDefaultDescription
childOrganizationsstringnonullComma-separated list of child organization IDs to include when aggregating. Omit for all.
fieldsJsonstringyesJSON object with the request. Optional: agent_ids (array of agent IDs to scope the query). Omit for all devices.
multitenancybooleannonullWhen true, aggregate across child organizations. Omit to scope to the API key's own organization.

[Addigy] Query installed applications reported by the Addigy agent for one or more devices. macOS only. Build the filter via queryJson — required key `agent_ids` (array of agent IDs), optional `names` (array of application names, e.g. ["Google Chrome","Firefox"]). sortField and sortDirection are required by the API: sortField is one of agent_id|name; sortDirection is asc|desc. Paginated; response metadata carries page_count/total. Aggregates across child organizations when multitenancy=true. Requires API token permission: View Devices.

ParamTypeRequiredDefaultDescription
childOrganizationsstringnonullComma-separated list of child organization IDs to include when aggregating. Omit for all.
multitenancybooleannonullWhen true, aggregate across child organizations. Omit to scope to the API key's own organization.
pageintegerno1Page number (default 1).
perPageintegerno50Results per page (default 50, max 100 — Addigy documents a 100 cap on this endpoint).
queryJsonstringyesJSON for the `query` object. Required: agent_ids (array of agent IDs); optional: names (array of application names).
sortDirectionstringyesSort direction: asc|desc (required by the API).
sortFieldstringyesField to sort by: agent_id|name (required by the API).

[Addigy] Query installed applications reported via MDM for one or more devices. Required body fields (all required by the API): `agent_ids` (array of agent IDs), `limit` (integer page size), `skip` (integer offset), `sort_field` (string, e.g. name), `sort_direction` (asc|desc). Uses skip/limit offset pagination rather than page numbers. Aggregates across child organizations when multitenancy=true. Requires API token permission: View Devices.

ParamTypeRequiredDefaultDescription
childOrganizationsstringnonullComma-separated list of child organization IDs to include when aggregating. Omit for all.
fieldsJsonstringyesJSON object with the request. Required: agent_ids (array), limit (integer), skip (integer), sort_field (string), sort_direction (asc|desc).
multitenancybooleannonullWhen true, aggregate across child organizations. Omit to scope to the API key's own organization.

[Addigy] Paginated list of certificates installed on MDM devices. Build the filter via queryJson — supported keys: `days_until_expiration` (integer; certs expiring within N days), `issuer_common_name` (string), and `devices` (array of device identifiers). Useful for auditing expiring certificates across the fleet. Paginated; response metadata carries page_count/total. Requires API token permission: View Devices.

ParamTypeRequiredDefaultDescription
pageintegerno1Page number (default 1).
perPageintegerno50Results per page (default 50, max 500).
queryJsonstringnonullJSON for the `query` object: { days_until_expiration, issuer_common_name, devices[] }. Omit for all certificates.

[Addigy] Rotate the managed admin password for a specific account on a device. Required body field: `accountName` (the managed admin account to rotate; discover via addigy_list_device_managed_admins). Requires organizationId (from addigy_list_child_organizations) and the device's agentId. Requires API token permission: Rotate Managed Admin Password.

ParamTypeRequiredDefaultDescription
agentIdstringyesAgent ID of the device.
fieldsJsonstringyesJSON object with the request body. Required: accountName (the managed admin account to rotate).
organizationIdstringyesOrganization ID (from addigy_list_child_organizations).

[Addigy] Universal device search: query for devices by any device fact (e.g. serial_number, hostname, model). Returns a paginated audit response of matching devices. Build the search via queryJson — supported keys: `search_any` (free-text across facts), `policy_id`, and `filters` (array of audit filters); pass `desiredFactIdentifiers` (comma-separated fact ids from addigy_list_available_facts) to control which facts come back. Paginated; response metadata carries page_count/total. Org-scoping: omit organizationId to search the API key's own organization, or pass an organizationId (from addigy_list_child_organizations) to target a specific child organization. Requires API token permission: View Devices.

ParamTypeRequiredDefaultDescription
desiredFactIdentifiersstringnonullComma-separated list of desired fact identifiers to include in each result (fact ids from addigy_list_available_facts). Omit for the default fact set.
organizationIdstringnonullOptional organization ID from addigy_list_child_organizations. Omit to search the API key's own organization.
pageintegerno1Page number (default 1).
perPageintegerno50Results per page (default 50, max 500).
queryJsonstringnonullJSON for the `query` object: { search_any, policy_id, filters[] }. Omit for an unfiltered search.
sortDirectionstringnonullSort direction: asc|desc. Omit for default ordering.
sortFieldstringnonullField to sort by, e.g. serial_number. Omit for default ordering.

[Addigy] Test the MDM response for a single device — probes whether the device responds to an MDM command, useful for diagnosing unresponsive or stale MDM enrollments. The device UUID is the MDM device identifier; discover it via addigy_search_devices or addigy_get_mdm_device_details.

ParamTypeRequiredDefaultDescription
deviceUuidstringyesDevice UUID (MDM device identifier).

[Addigy] Unassign one or more devices from one or more policies. Required body fields: `agent_ids` (non-empty array of device agent IDs) and `policy_ids` (non-empty array of policy IDs). Requires organizationId (from addigy_list_child_organizations). Use addigy_get_device_policy_assignments to verify current assignments. Requires API token permission: Assign/Unassign Device Policies.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object with the unassignment. Required: agent_ids (non-empty array of agent IDs), policy_ids (non-empty array of policy IDs).
organizationIdstringyesOrganization ID (from addigy_list_child_organizations).

Organization & Users

ToolPlanAccessSummary
addigy_create_userProWriteCreate a new organization user (admin).
addigy_delete_userProDestructiveRemove a user from the organization, identified by their email.
addigy_disable_beta_featureProDestructiveDisable a Beta Feature for the organization, identified by its feature_flag_key (discover keys with addigy_list_public_beta_features).
addigy_enable_beta_featureProWriteEnable a Beta Feature for the organization.
addigy_get_api_key_permissionsFreeRead-onlyGet the permission set granted to the API key currently in use.
addigy_get_billing_accountFreeRead-onlyGet the billing account record for a specific organization — contact, payment, and account-status details.
addigy_get_billing_dataFreeRead-onlyGet billing data (device counts, charges, and usage figures) for a specific organization.
addigy_get_whoamiFreeRead-onlyIdentify the organization the API token belongs to, via GET /configuration/whoami.
addigy_list_billing_invoicesFreeRead-onlyList the billing invoices for a specific organization.
addigy_list_child_organizationsFreeRead-onlyList the child organizations belonging to a parent organization (MSP multi-tenant view).
addigy_list_public_beta_featuresFreeRead-onlyList all Beta Features available to the organization, including each feature's flag key and whether it is currently enabled.
addigy_query_ade_token_policy_assignmentsFreeRead-onlyGet the list of Automatic Device Enrollment (ADE / DEP) tokens assigned to the given policies.
addigy_query_organization_usersFreeRead-onlyQuery the users (admins) belonging to a specific organization.
addigy_update_userProWriteUpdate an existing organization user, matched by email.

[Addigy] Create a new organization user (admin). Required body fields: email (string), role (e.g. admin). Optional: name, phone, policies (array of policy id strings). Returns the created user record. To change an existing user use addigy_update_user; to list users use addigy_query_organization_users. Requires API token permission: Create User.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object with the new user. Required: email, role (e.g. admin). Optional: name, phone, policies (array of policy id strings).

[Addigy] Remove a user from the organization, identified by their email. Discover existing users with addigy_query_organization_users. This is irreversible — re-add with addigy_create_user. Requires API token permission: Remove User.

ParamTypeRequiredDefaultDescription
emailstringyesEmail of the user to remove — from addigy_query_organization_users.

[Addigy] Disable a Beta Feature for the organization, identified by its feature_flag_key (discover keys with addigy_list_public_beta_features). To re-enable use addigy_enable_beta_feature. Requires API token permission: Toggle Feature Betas.

ParamTypeRequiredDefaultDescription
featureFlagKeystringyesBeta feature flag key to remove — from addigy_list_public_beta_features.

[Addigy] Enable a Beta Feature for the organization. Required body field: feature_flag_key (string) — discover available keys with addigy_list_public_beta_features. To turn a feature back off use addigy_disable_beta_feature. Requires API token permission: Toggle Feature Betas.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object with the feature to enable. Required: feature_flag_key (string) — from addigy_list_public_beta_features.

[Addigy] Get the permission set granted to the API key currently in use. Returns an array of Addigy permission identifiers (e.g. com.addigy.devices.view, com.addigy.policies.edit — verified live 2026-08-26) describing exactly what this token can do; each identifier corresponds to a labeled permission on Addigy's API-token creation screen. Use this first to confirm a tool you intend to call is authorized.

[Addigy] Get the billing account record for a specific organization — contact, payment, and account-status details. Requires organizationId from addigy_list_child_organizations (or the org's own id). For usage/charge figures use addigy_get_billing_data; for invoices use addigy_list_billing_invoices. Requires API token permission: View Billing.

ParamTypeRequiredDefaultDescription
organizationIdstringyesOrganization id — from addigy_list_child_organizations.

[Addigy] Get billing data (device counts, charges, and usage figures) for a specific organization. Requires organizationId from addigy_list_child_organizations (or the org's own id). For account contact details use addigy_get_billing_account; for invoices use addigy_list_billing_invoices. Requires API token permission: View Billing.

ParamTypeRequiredDefaultDescription
organizationIdstringyesOrganization id — from addigy_list_child_organizations.

[Addigy] Identify the organization the API token belongs to, via GET /configuration/whoami. Returns {organization_id, name}. This is the ONLY self-discovery of the token's own organization id — the o// tools need that id, and on a single-organization account nothing else reveals it. NOTE: the endpoint is absent from Addigy's published Swagger spec; it was verified live 2026-08-26 and may change without notice.

[Addigy] List the billing invoices for a specific organization. Returns an array of invoice records (id, period, amount, status). Requires organizationId from addigy_list_child_organizations (or the org's own id). For the live account/usage figures use addigy_get_billing_account / addigy_get_billing_data. Requires API token permission: View Billing.

ParamTypeRequiredDefaultDescription
organizationIdstringyesOrganization id — from addigy_list_child_organizations.

[Addigy] List the child organizations belonging to a parent organization (MSP multi-tenant view). Returns each child org's id, companyName, subdomain, and contact — the organizationId values needed by org-scoped tools (addigy_get_billing_account, addigy_query_organization_users, etc.). Supports searchString, sort, and a childOrganizationId filter to fetch one specific child. Paginated; response metadata has page/page_count/total.

ParamTypeRequiredDefaultDescription
childOrganizationIdstringnonullFilter result by orgid for a specific child organization.
organizationIdstringyesParent organization id to check for child organizations.
pageintegerno1Requested page (default 1).
perPageintegerno50Number of items in the response (default 50, max 500).
searchStringstringnonullSearch string for organization name.
sortDirectionstringnonullSort direction: asc|desc (default asc).
sortFieldstringnonullField used for sorting: companyName|email|firstName|lastName|subdomain (default companyName).

[Addigy] List all Beta Features available to the organization, including each feature's flag key and whether it is currently enabled. Use the returned feature_flag_key with addigy_enable_beta_feature / addigy_disable_beta_feature to toggle a feature. Paginated; response metadata has page/page_count/total. Requires API token permission: Toggle Feature Betas.

ParamTypeRequiredDefaultDescription
pageintegerno1Requested page (default 1).
perPageintegerno50Number of items in the response (default 50, max 500).

[Addigy] Get the list of Automatic Device Enrollment (ADE / DEP) tokens assigned to the given policies. Required body field: policy_ids (array of strings). Returns the matching ADE token records (server name, expiration, assigned policy). Spans child organizations when multitenancy=true.

ParamTypeRequiredDefaultDescription
childOrganizationsstringnonullComma-separated list of child organization ids to scope the aggregation to.
fieldsJsonstringyesJSON object with the policy ids to look up. Required: policy_ids (array of strings).
multitenancybooleannonullWhen true, aggregate results across child organizations (/oa/ scope).

[Addigy] Query the users (admins) belonging to a specific organization. Returns a paginated list with each user's email, name, role, and policies. Requires organizationId from addigy_list_child_organizations (or the org's own id). Pass an optional queryJson body for additional filter fields supported by the endpoint. Paginated; response metadata has page/page_count/total. Requires API token permission: View Users.

ParamTypeRequiredDefaultDescription
organizationIdstringyesOrganization id — from addigy_list_child_organizations.
pageintegerno1Requested page (default 1).
perPageintegerno50Number of items in the response (default 50, max 500).
queryJsonstringnonullOptional JSON object with additional query/filter fields to merge into the request body.
sortDirectionstringnonullSort direction: asc|desc.
sortFieldstringnonullField used for sorting (e.g. email).

[Addigy] Update an existing organization user, matched by email. Body fields: email (string, identifies the user to update), name, phone, role (e.g. admin). Discover existing users with addigy_query_organization_users. To create a new user use addigy_create_user; to remove one use addigy_delete_user. Requires API token permission: Edit User.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object with the user fields to update. Identify the user by email. Updatable: name, phone, email, role (e.g. admin).

Policies

ToolPlanAccessSummary
addigy_create_policyProWriteCreate a new policy within a specific organization.
addigy_create_policy_ruleProDestructiveAdd an automatic-assignment (Smart Software / custom filter) rule to a policy within an organization.
addigy_delete_policyProDestructivePermanently delete a policy from a specific organization.
addigy_delete_policy_parentProDestructiveDetach a policy from its parent, promoting it to a top-level policy within an organization.
addigy_delete_policy_ruleProDestructiveRemove an automatic-assignment rule from a policy within an organization.
addigy_get_policy_ruleFreeRead-onlyGet the automatic-assignment rule configured for a single policy within an organization.
addigy_list_mdm_profile_policy_assignmentsFreeRead-onlyList the MDM configuration profiles currently assigned to policies for the API key's own organization.
addigy_list_policy_rulesFreeRead-onlyList all automatic-assignment (custom filter) rules across every policy in an organization.
addigy_query_policiesFreeRead-onlyQuery an organization for all policies, or filter to specific policies, and return their full info.
addigy_update_policyProWriteUpdate an existing policy's editable attributes (name, color, icon) for a specific organization.
addigy_update_policy_parentProDestructiveRe-parent a policy, moving it under a different parent policy within an organization (changes the policy hierarchy).

[Addigy] Create a new policy within a specific organization. Required body field: `name`. Optional body fields: `color`, `icon` (fa fa-user|fa fa-users|fa fa-trophy|fa fa-university|fa fa-database|fa fa-desktop|fa fa-building-o|fa fa-lock|fa fa-dog|fa fa-mobile|fa fa-wrench|fa fa-user-graduate|fa fa-cog|fa fa-laptop|fa fa-box-open|fa fa-globe-americas), `parent_policy_id` (nest under an existing policy — discover via addigy_query_policies), `splashtop_settings` and `ssh_settings` (each an object with `enabled` and `require_user_permission` booleans). Requires organizationId from addigy_list_child_organizations. Requires API token permission: Create Policy.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object with the new policy. Required: name. Optional: color, icon, parent_policy_id, splashtop_settings ({enabled, require_user_permission}), ssh_settings ({enabled, require_user_permission}).
organizationIdstringyesOrganization ID. Discover via addigy_list_child_organizations.

[Addigy] Add an automatic-assignment (Smart Software / custom filter) rule to a policy within an organization. Devices matching the rule's filters are auto-assigned to the policy. Body fields: `policy_id` (target policy — discover via addigy_query_policies), `filters` (array of filter groups; each group is an array of correlation_engine.Filter conditions), `auto_remove` (bool — unassign devices that stop matching), `disabled` (bool). Requires organizationId from addigy_list_child_organizations. Requires API token permission: Automatic Policy Assignments.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object for the rule. Fields: policy_id, filters (array of arrays of filter conditions), auto_remove (bool), disabled (bool).
organizationIdstringyesOrganization ID. Discover via addigy_list_child_organizations.

[Addigy] Permanently delete a policy from a specific organization. Identify the policy with the `id` query parameter (the policy's ID — discover via addigy_query_policies). Requires organizationId from addigy_list_child_organizations. Requires API token permission: Delete Policy.

ParamTypeRequiredDefaultDescription
idstringyesPolicy ID to delete. Discover via addigy_query_policies.
organizationIdstringyesOrganization ID. Discover via addigy_list_child_organizations.

[Addigy] Detach a policy from its parent, promoting it to a top-level policy within an organization. Identify the policy with the `policy_id` query parameter (discover via addigy_query_policies). Requires organizationId from addigy_list_child_organizations. Requires API token permission: Edit Policy.

ParamTypeRequiredDefaultDescription
organizationIdstringyesOrganization ID. Discover via addigy_list_child_organizations.
policyIdstringyesPolicy ID whose parent link is removed. Discover via addigy_query_policies.

[Addigy] Remove an automatic-assignment rule from a policy within an organization. Identify the rule with both the `policy_id` and `rule_id` query parameters — discover them via addigy_get_policy_rule or addigy_list_policy_rules. Requires organizationId from addigy_list_child_organizations. Requires API token permission: Automatic Policy Assignments.

ParamTypeRequiredDefaultDescription
organizationIdstringyesOrganization ID. Discover via addigy_list_child_organizations.
policyIdstringyesPolicy ID the rule belongs to. Discover via addigy_query_policies.
ruleIdstringyesRule ID to remove. Discover via addigy_get_policy_rule or addigy_list_policy_rules.

[Addigy] Get the automatic-assignment rule configured for a single policy within an organization. Identify the policy with the `policy_id` query parameter (discover via addigy_query_policies). Use addigy_list_policy_rules to enumerate rules across all policies. Requires organizationId from addigy_list_child_organizations. Requires API token permission: Automatic Policy Assignments.

ParamTypeRequiredDefaultDescription
organizationIdstringyesOrganization ID. Discover via addigy_list_child_organizations.
policyIdstringyesPolicy ID whose assignment rule is returned. Discover via addigy_query_policies.

[Addigy] List the MDM configuration profiles currently assigned to policies for the API key's own organization. Returns each policy together with the MDM profiles attached to it. Use addigy_query_policies to discover policy IDs and names. Paginated via page/per_page (default 50, max 500); the response metadata envelope carries page/page_count/per_page/result_count/total.

ParamTypeRequiredDefaultDescription
pageintegerno1Page number to retrieve (default 1).
perPageintegerno50Results per page (default 50, max 500).

[Addigy] List all automatic-assignment (custom filter) rules across every policy in an organization. Returns each rule with its associated policy and filter conditions. Use addigy_get_policy_rule for a single policy's rule. Requires organizationId from addigy_list_child_organizations. Requires API token permission: Automatic Policy Assignments.

ParamTypeRequiredDefaultDescription
organizationIdstringyesOrganization ID. Discover via addigy_list_child_organizations.

[Addigy] Query an organization for all policies, or filter to specific policies, and return their full info. This is the primary discovery tool for policy IDs and names referenced by the other Policies tools. Optional body field: `policies` (array of policy ID strings to filter to; omit or pass an empty body to return all policies). Aggregates across child organizations when multitenancy=true; scope to specific children via childOrganizations.

ParamTypeRequiredDefaultDescription
childOrganizationsstringnonullComma-separated list of child organization IDs to scope the aggregate query to. Omit for all child organizations.
fieldsJsonstringyesJSON object for the query. Optional: policies (array of policy ID strings to filter to). Omit or pass to return all policies.
multitenancybooleannonullWhen true, aggregate across child organizations (the /oa/ multitenancy flag). Omit for the API key's own organization only.

[Addigy] Update an existing policy's editable attributes (name, color, icon) for a specific organization. Required body field: `policy_id` (the target policy's ID — discover via addigy_query_policies). Optional body fields: `name`, `color`, `icon` (one of: fa fa-user, fa fa-users, fa fa-trophy, fa fa-university, fa fa-database, fa fa-desktop, fa fa-building-o, fa fa-lock, fa fa-dog, fa fa-mobile, fa fa-wrench, fa fa-user-graduate, fa fa-cog, fa fa-laptop, fa fa-box-open, fa fa-globe-americas). Requires organizationId from addigy_list_child_organizations. Requires API token permission: Edit Policy.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object with the policy update. Required: policy_id. Optional: name, color, icon (fa fa-user|fa fa-users|fa fa-trophy|fa fa-university|fa fa-database|fa fa-desktop|fa fa-building-o|fa fa-lock|fa fa-dog|fa fa-mobile|fa fa-wrench|fa fa-user-graduate|fa fa-cog|fa fa-laptop|fa fa-box-open|fa fa-globe-americas).
organizationIdstringyesOrganization ID. Discover via addigy_list_child_organizations.

[Addigy] Re-parent a policy, moving it under a different parent policy within an organization (changes the policy hierarchy). Required body fields: `policy_id` (the policy being moved) and `parent_policy_id` (its new parent). Discover both IDs via addigy_query_policies. Requires organizationId from addigy_list_child_organizations. Requires API token permission: Edit Policy.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object for the re-parent. Required: policy_id (policy being moved), parent_policy_id (new parent). Discover IDs via addigy_query_policies.
organizationIdstringyesOrganization ID. Discover via addigy_list_child_organizations.

MDM Commands

ToolPlanAccessSummary
addigy_clear_passcodeProDestructiveIssue an MDM Clear Passcode command, removing the unlock passcode from a managed device.
addigy_clear_restrictions_passwordProDestructiveIssue an MDM Clear Restrictions Password command, removing the restrictions (Screen Time) passcode from a managed device.
addigy_delete_device_userProDestructiveIssue an MDM Delete User command, removing an active local user account from a managed device.
addigy_disable_lost_modeProDestructiveIssue an MDM command that disables Lost Mode on a managed device (re-enable with addigy_enable_lost_mode).
addigy_disable_remote_desktopProDestructiveIssue an MDM command that disables Remote Desktop (screen sharing) on a managed device (re-enable with addigy_enable_remote_desktop).
addigy_enable_lost_modeProDestructiveIssue an MDM command that puts a managed device into Lost Mode with an on-screen message, phone number, and footnote.
addigy_enable_remote_desktopProDestructiveIssue an MDM command that enables Remote Desktop (screen sharing) on a managed device (disable with addigy_disable_remote_desktop).
addigy_erase_deviceProDestructiveIssue an MDM Erase Device command, wiping a managed macOS/iOS/iPadOS/tvOS device.
addigy_get_command_outputFreeRead-onlyRetrieve the captured output (stdout/stderr/exit status) of a previously dispatched device command.
addigy_get_device_locationFreeRead-onlyIssue an MDM command asking a device in Lost Mode to report its current location (enable Lost Mode first with addigy_enable_lost_mode; read the last reported coordinates with…
addigy_get_last_device_locationFreeRead-onlyRead the last known location reported by a device while in Lost Mode (request a fresh report with addigy_get_device_location).
addigy_list_device_usersFreeRead-onlyIssue an MDM Request User List command, asking a managed device to report its local user accounts to Addigy (read the cached result afterward with addigy_list_mdm_device_users).
addigy_list_mdm_device_usersFreeRead-onlyReturn the list of known device users previously reported to Addigy via the Request User List command (addigy_list_device_users triggers that command).
addigy_lock_deviceProDestructiveIssue an MDM Device Lock command, rendering the device unusable until the passcode is entered.
addigy_play_lost_mode_soundProDestructiveIssue an MDM command that plays a sound on a device currently in Lost Mode (enable Lost Mode first with addigy_enable_lost_mode).
addigy_request_airplay_mirroringProDestructiveIssue an MDM command prompting the user to share their screen via AirPlay Mirroring to a destination device.
addigy_restart_deviceProDestructiveIssue an MDM command that immediately restarts a managed device.
addigy_rotate_filevault_keyProDestructiveIssue an MDM command that rotates the FileVault personal recovery key on a managed macOS device.
addigy_run_device_commandProDestructiveRun an arbitrary shell command on one or more devices within an organization.
addigy_shutdown_deviceProDestructiveIssue an MDM command that shuts down a managed device.
addigy_stop_airplay_mirroringProDestructiveIssue an MDM command that stops AirPlay screen mirroring on a managed device.
addigy_unlock_device_userProDestructiveIssue an MDM command that unlocks a locked-out local user account on a managed device.

[Addigy] Issue an MDM Clear Passcode command, removing the unlock passcode from a managed device. Identify the target by EITHER agentId OR deviceUuid (provide exactly one — agentId comes from addigy_list_devices, deviceUuid from addigy_get_mdm_device_details). Requires API token permission: Execute Commands. Returns the queued MDM command payload (command UUID + status).

ParamTypeRequiredDefaultDescription
agentIdstringnonullAgentID (required if deviceUuid is not provided).
deviceUuidstringnonullDevice UUID (required if agentId is not provided).

[Addigy] Issue an MDM Clear Restrictions Password command, removing the restrictions (Screen Time) passcode from a managed device. Identify the device by EITHER agentId OR deviceUuid (provide exactly one). Requires API token permission: Execute Commands. Returns the queued MDM command payload.

ParamTypeRequiredDefaultDescription
agentIdstringnonullAgentID (required if deviceUuid is not provided).
deviceUuidstringnonullDevice UUID (required if agentId is not provided).

[Addigy] Issue an MDM Delete User command, removing an active local user account from a managed device. Identify the device by EITHER agentId OR deviceUuid (provide exactly one). Required: username (the account to delete) and forceDeletion. Discover known device users with addigy_list_mdm_device_users. Requires API token permission: Execute Commands. Returns the queued MDM command payload.

ParamTypeRequiredDefaultDescription
agentIdstringnonullAgentID (required if deviceUuid is not provided).
deviceUuidstringnonullDevice UUID (required if agentId is not provided).
forceDeletionbooleanyesForce deletion of the user account even if it has unsynced data (pass false for a normal delete).
usernamestringyesUsername of the local account to delete.

[Addigy] Issue an MDM command that disables Lost Mode on a managed device (re-enable with addigy_enable_lost_mode). Provide a JSON body identifying the device by EXACTLY ONE of `agent_id` or `device_uuid`. Requires API token permission: Execute Commands. Returns the queued MDM command payload.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object. Property: agent_id (string). Provide exactly one of agent_id or device_uuid to target the device.

[Addigy] Issue an MDM command that disables Remote Desktop (screen sharing) on a managed device (re-enable with addigy_enable_remote_desktop). Provide a JSON body identifying the device by EXACTLY ONE of `agent_id` or `device_uuid`. Requires API token permission: Execute Commands. Returns the queued MDM command payload.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object. Property: agent_id (string). Provide exactly one of agent_id or device_uuid to target the device.

[Addigy] Issue an MDM command that puts a managed device into Lost Mode with an on-screen message, phone number, and footnote. A message OR phone number must be provided. Provide a JSON body identifying the device by EXACTLY ONE of `agent_id` or `device_uuid`. Body properties: message (string), phone_number (string), footnote (string), agent_id. Disable later with addigy_disable_lost_mode; locate with addigy_get_device_location. Requires API token permission: Execute Commands. Returns the queued MDM command payload.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object. Properties: footnote (string), phone_number (string), message (string), agent_id (string). A message or phone number must be provided. Provide exactly one of agent_id or device_uuid to target the device.

[Addigy] Issue an MDM command that enables Remote Desktop (screen sharing) on a managed device (disable with addigy_disable_remote_desktop). Provide a JSON body identifying the device by EXACTLY ONE of `agent_id` or `device_uuid`. Requires API token permission: Execute Commands. Returns the queued MDM command payload.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object. Property: agent_id (string). Provide exactly one of agent_id or device_uuid to target the device.

[Addigy] Issue an MDM Erase Device command, wiping a managed macOS/iOS/iPadOS/tvOS device. Provide a JSON body with required `device_uuid` (all OSes). macOS: `pin` (six-character Find My PIN, required for devices without Apple M1/T2 EACS support) and `obliteration_behavior` (DoNotObliterate|ObliterateWithWarning|Always|Default). iOS/iPadOS: `disallow_proximity_setup` (bool, default false) and `preserve_data_plan` (bool, default false). Requires API token permission: Execute Commands. This command does not require supervision. Returns the queued MDM command payload.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object. Required: device_uuid (string). Optional: pin (string, macOS six-character Find My PIN), obliteration_behavior (DoNotObliterate|ObliterateWithWarning|Always|Default), disallow_proximity_setup (bool, default false), preserve_data_plan (bool, default false).

[Addigy] Retrieve the captured output (stdout/stderr/exit status) of a previously dispatched device command. Requires organizationId (discover with addigy_list_child_organizations), agentId (from addigy_list_devices), and actionId (the command/action identifier returned by addigy_run_device_command). Returns the CommandOutput record.

ParamTypeRequiredDefaultDescription
actionIdstringyesAction id (command identifier) returned by addigy_run_device_command.
agentIdstringyesAgent id of the device. Discover with addigy_list_devices.
organizationIdstringyesOrganization id. Discover with addigy_list_child_organizations.

[Addigy] Issue an MDM command asking a device in Lost Mode to report its current location (enable Lost Mode first with addigy_enable_lost_mode; read the last reported coordinates with addigy_get_last_device_location). Provide a JSON body identifying the device by EXACTLY ONE of `agent_id` or `device_uuid`. Requires API token permission: Execute Commands. Returns the queued MDM command payload.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object. Property: agent_id (string). Provide exactly one of agent_id or device_uuid to target the device.

[Addigy] Read the last known location reported by a device while in Lost Mode (request a fresh report with addigy_get_device_location). Identify the device by EITHER agentId OR deviceUuid (provide exactly one). Requires API token permission: Execute Commands. Returns the cached LostMode location record.

ParamTypeRequiredDefaultDescription
agentIdstringnonullAgentID (required if deviceUuid is not provided).
deviceUuidstringnonullDevice UUID (required if agentId is not provided).

[Addigy] Issue an MDM Request User List command, asking a managed device to report its local user accounts to Addigy (read the cached result afterward with addigy_list_mdm_device_users). Provide a JSON body identifying the device by EXACTLY ONE of `agent_id` or `device_uuid`. Requires API token permission: Execute Commands. Returns the queued MDM command payload.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object. Property: agent_id (string). Provide exactly one of agent_id or device_uuid to target the device.

[Addigy] Return the list of known device users previously reported to Addigy via the Request User List command (addigy_list_device_users triggers that command). Identify the device by EITHER agentId OR deviceUuid (provide exactly one). Requires API token permission: Execute Commands. Returns an array of MdmDeviceUser records.

ParamTypeRequiredDefaultDescription
agentIdstringnonullAgentID (required if deviceUuid is not provided).
deviceUuidstringnonullDevice UUID (required if agentId is not provided).

[Addigy] Issue an MDM Device Lock command, rendering the device unusable until the passcode is entered. Provide a JSON body identifying the device by EXACTLY ONE of `agent_id` or `device_uuid`. Optional body properties: message and phone_number (shown on the lock screen) and pin (six-digit recovery PIN for macOS). Requires API token permission: Execute Commands. Returns the queued MDM command payload.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object. Properties: phone_number (string), message (string), pin (string), agent_id (string). Provide exactly one of agent_id or device_uuid to target the device.

[Addigy] Issue an MDM command that plays a sound on a device currently in Lost Mode (enable Lost Mode first with addigy_enable_lost_mode). Provide a JSON body identifying the device by EXACTLY ONE of `agent_id` or `device_uuid`. Requires API token permission: Execute Commands. Returns the queued MDM command payload.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object. Property: agent_id (string). Provide exactly one of agent_id or device_uuid to target the device.

[Addigy] Issue an MDM command prompting the user to share their screen via AirPlay Mirroring to a destination device. Provide a JSON body identifying the device by EXACTLY ONE of `agent_id` or `device_uuid`. Body properties: destination_device_id (e.g. "AA:BB:CC:DD:EE:FF"), destination_name (e.g. "My Apple TV"), scan_time (integer 10–300, e.g. 30), password (optional), agent_id. Requires API token permission: Execute Commands. Returns the queued MDM command payload.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object. Properties: destination_device_id (string), destination_name (string), scan_time (integer 10–300), password (string), agent_id (string). Provide exactly one of agent_id or device_uuid to target the device.

[Addigy] Issue an MDM command that immediately restarts a managed device. Provide a JSON body identifying the device by EXACTLY ONE of `agent_id` or `device_uuid`. Requires API token permission: Execute Commands. Returns the queued MDM command payload.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object. Property: agent_id (string). Provide exactly one of agent_id or device_uuid to target the device.

[Addigy] Issue an MDM command that rotates the FileVault personal recovery key on a managed macOS device. Provide a JSON body identifying the device by EXACTLY ONE of `agent_id` or `device_uuid`. Requires API token permission: Execute Commands. Returns the queued MDM command payload.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object. Property: agent_id (string). Provide exactly one of agent_id or device_uuid to target the device.

[Addigy] Run an arbitrary shell command on one or more devices within an organization. Requires organizationId (discover with addigy_list_child_organizations). Provide a JSON body with required `agent_ids` (non-empty array of agent IDs from addigy_list_devices) and `command` (the shell command text). Optional: `background` (bool), `run_as_client` (bool). Retrieve results afterward with addigy_get_command_output using the returned action id. Returns an array of Command records.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object. Required: agent_ids (non-empty array of strings), command (string). Optional: background (bool), run_as_client (bool).
organizationIdstringyesOrganization id. Discover with addigy_list_child_organizations.

[Addigy] Issue an MDM command that shuts down a managed device. Provide a JSON body identifying the device by EXACTLY ONE of `agent_id` or `device_uuid`. Requires API token permission: Execute Commands. Returns the queued MDM command payload.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object. Property: agent_id (string). Provide exactly one of agent_id or device_uuid to target the device.

[Addigy] Issue an MDM command that stops AirPlay screen mirroring on a managed device. Provide a JSON body identifying the device by EXACTLY ONE of `agent_id` or `device_uuid`. Requires API token permission: Execute Commands. Returns the queued MDM command payload.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object. Property: agent_id (string). Provide exactly one of agent_id or device_uuid to target the device.

[Addigy] Issue an MDM command that unlocks a locked-out local user account on a managed device. Provide a JSON body identifying the device by EXACTLY ONE of `agent_id` or `device_uuid`, plus `username` (the account to unlock). Discover known device users with addigy_list_mdm_device_users. Requires API token permission: Execute Commands. Returns the queued MDM command payload.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object. Properties: username (string), agent_id (string). Provide exactly one of agent_id or device_uuid to target the device.

MDM Profiles & Settings

ToolPlanAccessSummary
addigy_assign_mdm_profile_to_policiesProDestructiveAssign an MDM configuration profile to one or more policies.
addigy_create_custom_mdm_profileProWriteCreate a Custom MDM Profile by uploading a raw .mobileconfig file.
addigy_create_mdm_profileProWriteCreate an Addigy-native MDM profile (not a raw .mobileconfig — use addigy_create_custom_mdm_profile for that).
addigy_delete_mdm_profileProDestructivePermanently delete an MDM configuration profile by its payload group ID.
addigy_deploy_profile_to_devicesProDestructiveDeploy an MDM profile directly to a list of devices and/or managed users.
addigy_get_mdm_profileFreeRead-onlyGet a single MDM configuration profile by its payload group ID, including its configuration payloads.
addigy_get_mdm_profile_definitionFreeRead-onlyGet the MDM configuration profile DEFINITION (payload manifest / schema) for a single Addigy payload type.
addigy_install_mdm_enrollment_profileProDestructiveInstall an MDM enrollment profile on a device (via MDM if available, otherwise via the Addigy agent for macOS devices).
addigy_list_mdm_configuration_profilesFreeRead-onlyList all MDM configuration profiles in the organization, with their configuration payloads.
addigy_list_mdm_profile_definitionsFreeRead-onlyList all MDM configuration profile DEFINITIONS (payload manifests / schemas).
addigy_list_mdm_profilesFreeRead-onlyGet a list of MDM profiles (the profiles installed on / pushed via MDM).
addigy_list_policy_profiles_by_payload_typeFreeRead-onlyList the MDM profiles configured on a specific policy that match a given payload type.
addigy_query_mdm_payloadsFreeRead-onlyQuery MDM payload information and policy assignments for a specific organization.
addigy_set_app_analyticsProDestructiveSend an MDM command to enable/disable app analytics sharing with app developers.
addigy_set_bluetooth_stateProDestructiveSend an MDM command to enable/disable Bluetooth.
addigy_set_data_roamingProDestructiveSend an MDM command to enable/disable data roaming.
addigy_set_device_nameProDestructiveSend an MDM command to set a device's name.
addigy_set_diagnostic_submissionProDestructiveSend an MDM command to set the user preference for diagnostic submission.
addigy_set_personal_hotspotProDestructiveSend an MDM command to enable/disable Personal Hotspot.
addigy_set_voice_roamingProDestructiveSend an MDM command to enable/disable voice roaming.
addigy_set_wallpaperProDestructiveSend an MDM command to set a device's wallpaper (a one-time setting the user can later change).
addigy_unassign_mdm_profile_from_policiesProDestructiveUnassign (detach) an MDM configuration profile from one or more policies.
addigy_update_mdm_profile_payloadsProDestructiveUpdate (REPLACE) an MDM profile's payloads.

[Addigy] Assign an MDM configuration profile to one or more policies. Body fields: `groupId` (the profile's payload group ID, discover via addigy_list_mdm_configuration_profiles), `policyIds` (array of policy IDs to attach), and `channel` (delivery channel). Use addigy_unassign_mdm_profile_from_policies to reverse.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object. Fields: groupId (profile payload group ID), policyIds (array of policy ID strings), channel (string).

[Addigy] Create a Custom MDM Profile by uploading a raw .mobileconfig file. Provide the .mobileconfig XML as `profileContent` and an upload `fileName`. Optionally set minimum OS versions to scope which platforms receive it (leave a version empty/null to NOT target that platform). For Addigy-native (non-custom) payloads use addigy_create_mdm_profile instead. Requires API token permission: Create MDM Profiles.

ParamTypeRequiredDefaultDescription
fileNamestringyesUpload file name for the .mobileconfig (e.g. "profile.mobileconfig").
iosMinimumVersionstringnonulliOS minimum version. Leave empty/null to not support iOS devices. Default "4.0".
macosMinimumVersionstringnonullmacOS minimum version. Leave empty/null to not support macOS devices. Default "10.7".
profileContentstringyesRaw .mobileconfig profile content (XML plist text) to upload.
tvosMinimumVersionstringnonulltvOS minimum version. Leave empty/null to not support tvOS devices. Default "10.2".

[Addigy] Create an Addigy-native MDM profile (not a raw .mobileconfig — use addigy_create_custom_mdm_profile for that). Body fields include payload metadata plus a `payloads` array of MDM payload objects. Per-payload required keys: payload_display_name (1–160 chars), payload_type (Apple type string such as com.apple.airplay, must not be empty), payload_priority (integer, default 9). Profiles with multiple payloads are not supported. NOTE: payload key names use snake_case (e.g. allow_passcode_modification), not Apple camelCase. Use addigy_list_mdm_profile_definitions / addigy_get_mdm_profile_definition to learn each payload's required keys. Requires API token permission: Create MDM Profiles.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object for the new MDM profile. Includes profile metadata and a `payloads` array; each payload needs payload_display_name, payload_type, payload_priority and the type's required snake_case keys.

[Addigy] Permanently delete an MDM configuration profile by its payload group ID. The `payloadGroupId` identifies the profile to remove — discover it via addigy_list_mdm_configuration_profiles or addigy_get_mdm_profile. This removes the profile and is not reversible.

ParamTypeRequiredDefaultDescription
payloadGroupIdstringyesMDM payload group ID of the profile to delete. Discover via addigy_list_mdm_configuration_profiles.

[Addigy] Deploy an MDM profile directly to a list of devices and/or managed users. This is an ATOMIC request — if any single target errors, NO profile is deployed to ANY target. Body fields: `payloads_group_id` (profile payload group ID, discover via addigy_list_mdm_configuration_profiles), `devices_uuid` (array of device UUIDs), and `devices_user_ids` (object mapping device to managed-user ID arrays). Requires API token permissions: View Devices, Execute commands.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object. Fields: payloads_group_id (string), devices_uuid (array of device UUID strings), devices_user_ids (object mapping device IDs to arrays of managed-user ID strings).

[Addigy] Get a single MDM configuration profile by its payload group ID, including its configuration payloads. The `payloadGroupId` identifies the profile — discover it via addigy_list_mdm_configuration_profiles. Use addigy_update_mdm_profile_payloads to modify it or addigy_delete_mdm_profile to remove it.

ParamTypeRequiredDefaultDescription
payloadGroupIdstringyesMDM payload group ID of the profile to fetch. Discover via addigy_list_mdm_configuration_profiles.

[Addigy] Get the MDM configuration profile DEFINITION (payload manifest / schema) for a single Addigy payload type. Returns the field/key manifest describing what keys a payload of this type accepts — useful before building a body for addigy_create_mdm_profile. The `addigyPayloadType` is Addigy's payload-type identifier; use addigy_list_mdm_profile_definitions to discover all available payload types.

ParamTypeRequiredDefaultDescription
addigyPayloadTypestringyesAddigy's payload type of the MDM profile (e.g. com.apple.airplay). Discover values via addigy_list_mdm_profile_definitions.

[Addigy] Install an MDM enrollment profile on a device (via MDM if available, otherwise via the Addigy agent for macOS devices). Requires `organizationId` (the target organization — discover via addigy_list_child_organizations). Body field: `udid` (the device UDID to enroll).

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object. Field: udid (string) — the device UDID to enroll.
organizationIdstringyesOrganization ID owning the device. Discover via addigy_list_child_organizations.

[Addigy] List all MDM configuration profiles in the organization, with their configuration payloads. Use this to discover payload group IDs for addigy_get_mdm_profile, addigy_update_mdm_profile_payloads, addigy_delete_mdm_profile, and addigy_assign_mdm_profile_to_policies. For the lighter MDM-profile listing (vendor/Apple-pushed profiles) use addigy_list_mdm_profiles.

[Addigy] List all MDM configuration profile DEFINITIONS (payload manifests / schemas). Returns the array of every Addigy-supported payload type and its key manifest. Use this to discover valid `addigyPayloadType` values for addigy_get_mdm_profile_definition and to learn the fields required when building a body for addigy_create_mdm_profile.

[Addigy] Get a list of MDM profiles (the profiles installed on / pushed via MDM). For the richer configuration-profile listing with full payloads, use addigy_list_mdm_configuration_profiles instead.

[Addigy] List the MDM profiles configured on a specific policy that match a given payload type. Requires both a `policyId` and a `payloadType`. Use this to inspect which profiles of a particular type (e.g. com.apple.airplay) a policy already carries before editing. Discover payload types via addigy_list_mdm_profile_definitions.

ParamTypeRequiredDefaultDescription
payloadTypestringyesProfile payload type to filter by (e.g. com.apple.airplay). Discover via addigy_list_mdm_profile_definitions.
policyIdstringyesPolicy ID to inspect.

[Addigy] Query MDM payload information and policy assignments for a specific organization. Requires `organizationId` (discover via addigy_list_child_organizations). Optional body fields: `payload_group_ids` (array — restrict to these payload group IDs) and `excluded_payload_group_ids` (array — exclude these). Omit the body to query all. Use addigy_list_mdm_configuration_profiles to discover payload group IDs.

ParamTypeRequiredDefaultDescription
fieldsJsonstringnonullOptional JSON object. Fields: payload_group_ids (array of strings to include), excluded_payload_group_ids (array of strings to exclude). Omit to query all payloads.
organizationIdstringyesOrganization ID to query. Discover via addigy_list_child_organizations.

[Addigy] Send an MDM command to enable/disable app analytics sharing with app developers. Available in Shared iPad mode on iOS 9.3.2+. Body fields: `app_analytics` (boolean — true enables, false disables) and exactly one device target: `device_uuid` or `agent_id`. Requires API token permission: Execute Commands.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object. Fields: app_analytics (boolean). Provide EXACTLY ONE device target: device_uuid or agent_id.

[Addigy] Send an MDM command to enable/disable Bluetooth. Available in iOS 11.3+ on supervised devices and macOS 10.13.4+. Body fields: `bluetooth` (boolean — true enables, false disables) and exactly one device target: `device_uuid` or `agent_id`. Requires API token permission: Execute Commands.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object. Fields: bluetooth (boolean). Provide EXACTLY ONE device target: device_uuid or agent_id.

[Addigy] Send an MDM command to enable/disable data roaming. Enabling data roaming also enables voice roaming. Body fields: `data_roaming` (boolean — true enables, false disables) and exactly one device target: `device_uuid` or `agent_id`. Requires API token permission: Execute Commands.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object. Fields: data_roaming (boolean). Provide EXACTLY ONE device target: device_uuid or agent_id.

[Addigy] Send an MDM command to set a device's name. Available only on supervised devices or macOS 10.10+. On macOS this sets the computer name and local hostname. Body fields: `device_name` (string), `host_name` (string, macOS) and exactly one device target: `device_uuid` or `agent_id`. Requires API token permission: Execute Commands.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object. Fields: device_name (string), host_name (string). Provide EXACTLY ONE device target: device_uuid or agent_id.

[Addigy] Send an MDM command to set the user preference for diagnostic submission. Shared iPad mode only; available in iOS 9.3+. Body fields: `diagnostic_submission` (boolean — true enables, false disables) and exactly one device target: `device_uuid` or `agent_id`. Requires API token permission: Execute Commands.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object. Fields: diagnostic_submission (boolean). Provide EXACTLY ONE device target: device_uuid or agent_id.

[Addigy] Send an MDM command to enable/disable Personal Hotspot. Only available on certain carriers. Body fields: `personal-hotspot` (boolean — true enables, false disables) and exactly one device target: `device_uuid` or `agent_id`. Requires API token permission: Execute Commands.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object. Fields: personal-hotspot (boolean). Provide EXACTLY ONE device target: device_uuid or agent_id.

[Addigy] Send an MDM command to enable/disable voice roaming. Only available on certain carriers. Disabling voice roaming also disables data roaming. Body fields: `voice-roaming` (boolean — true enables, false disables) and exactly one device target: `device_uuid` or `agent_id`. Requires API token permission: Execute Commands.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object. Fields: voice-roaming (boolean). Provide EXACTLY ONE device target: device_uuid or agent_id.

[Addigy] Send an MDM command to set a device's wallpaper (a one-time setting the user can later change). Supervised mode only; iOS 8+. Body fields: `image` (Base64-encoded PNG or JPEG), `where` (integer: 1=Lock screen, 2=Home/icon-list screen, 3=Lock and Home screens) and exactly one device target: `device_uuid` or `agent_id`. Requires API token permission: Execute Commands.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object. Fields: image (Base64-encoded PNG/JPEG), where (integer: 1=Lock, 2=Home, 3=Lock+Home). Provide EXACTLY ONE device target: device_uuid or agent_id.

[Addigy] Unassign (detach) an MDM configuration profile from one or more policies. Body fields: `groupId` (the profile's payload group ID), `policyIds` (array of policy IDs to detach), and `channel` (delivery channel). This is the reverse of addigy_assign_mdm_profile_to_policies; it removes the profile from those policies.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object. Fields: groupId (profile payload group ID), policyIds (array of policy ID strings to detach), channel (string).

[Addigy] Update (REPLACE) an MDM profile's payloads. IMPORTANT: this is a full REPLACE — partial data is not supported; the existing payload is removed and recreated from exactly what you send, so provide the COMPLETE payload structure. Some keys must match the existing payload to identify what to replace (payload_identifier, payload_group_id, payload_uuid). Per-payload required keys: payload_display_name, payload_type, payload_priority, plus the type's required snake_case keys. For Custom Profiles, modify and base64-encode the `custom_profile_content` field. Discover the profile via addigy_get_mdm_profile. Requires API token permission: Edit MDM Profiles.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object with the COMPLETE replacement profile. Includes profile metadata and a `payloads` array; preserve payload_identifier/payload_group_id/payload_uuid to target the existing profile. Custom profiles: base64-encode custom_profile_content.

Custom Facts

ToolPlanAccessSummary
addigy_assign_custom_fact_to_policyProDestructiveAssign a custom fact to one or more policies.
addigy_create_custom_factProWriteCreate a custom fact.
addigy_delete_custom_factProDestructiveDelete a custom fact by its id.
addigy_get_custom_factFreeRead-onlyGet a single custom fact by id within a specific organization.
addigy_get_custom_fact_usageFreeRead-onlyGet the usage of a custom fact within a specific organization — where the fact is referenced (e.g. by policies).
addigy_list_custom_factsFreeRead-onlyGet all custom facts defined for the API key's own organization.
addigy_query_custom_factsFreeRead-onlyGet a paginated list of custom facts for the organization, filtered by id or name.
addigy_query_custom_facts_aggregateFreeRead-onlyGet a paginated list of custom facts aggregated across organizations.
addigy_unassign_custom_fact_from_policyProDestructiveUnassign a custom fact from a policy.
addigy_update_custom_factProWriteUpdate an existing custom fact.

[Addigy] Assign a custom fact to one or more policies. Body fields: `id` (the custom fact id, from addigy_list_custom_facts) and `policies` (array of policy ids). Acts on the API key's own organization by default; pass organizationId (from addigy_list_child_organizations) to act on a specific child organization. Use addigy_unassign_custom_fact_from_policy to remove an assignment.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object with the assignment. Properties: id (the custom fact id), policies (array of policy id strings).
organizationIdstringnonullOptional organization id to target a specific child organization (from addigy_list_child_organizations). Omit to act on the API key's own organization.

[Addigy] Create a custom fact. Body fields: `name`, `return_type`, `notes`, and `os_architectures` (object with `linux` and `macOS` architecture settings). Returns the new fact (including its id). Acts on the API key's own organization by default; pass organizationId (from addigy_list_child_organizations) to create the fact in a specific child organization.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object describing the new custom fact. Properties: name, return_type, notes, os_architectures ({ linux, macOS }).
organizationIdstringnonullOptional organization id to target a specific child organization (from addigy_list_child_organizations). Omit to act on the API key's own organization.

[Addigy] Delete a custom fact by its id. Discover ids with addigy_list_custom_facts or addigy_query_custom_facts. Acts on the API key's own organization by default; pass organizationId (from addigy_list_child_organizations) to delete the fact in a specific child organization instead. This permanently removes the fact definition.

ParamTypeRequiredDefaultDescription
idstringyesCustom Fact id to delete. Discover with addigy_list_custom_facts.
organizationIdstringnonullOptional organization id to target a specific child organization (from addigy_list_child_organizations). Omit to act on the API key's own organization.

[Addigy] Get a single custom fact by id within a specific organization. Returns the fact's id, name, return_type, notes, and os_architectures. Requires organizationId (from addigy_list_child_organizations) and the custom fact id (from addigy_list_custom_facts or addigy_query_custom_facts). Use addigy_get_custom_fact_usage to see where the fact is referenced.

ParamTypeRequiredDefaultDescription
idstringyesCustom fact identifier (from addigy_list_custom_facts or addigy_query_custom_facts).
organizationIdstringyesOrganization id that owns the custom fact (from addigy_list_child_organizations).

[Addigy] Get the usage of a custom fact within a specific organization — where the fact is referenced (e.g. by policies). Requires organizationId (from addigy_list_child_organizations) and the custom fact id (from addigy_list_custom_facts or addigy_query_custom_facts). Use addigy_get_custom_fact for the fact's own definition.

ParamTypeRequiredDefaultDescription
idstringyesCustom fact identifier (from addigy_list_custom_facts or addigy_query_custom_facts).
organizationIdstringyesOrganization id that owns the custom fact (from addigy_list_child_organizations).

[Addigy] Get all custom facts defined for the API key's own organization. Returns each custom fact's id, name, return_type, notes, and os_architectures. Use addigy_get_custom_fact (with organizationId from addigy_list_child_organizations) for one fact's full detail, or addigy_query_custom_facts to filter by id/name. Paginated; response metadata carries page/page_count/per_page/result_count/total.

ParamTypeRequiredDefaultDescription
pageintegerno1Requested page number (default 1).
perPageintegerno50Number of items in the response (default 50, max 500).

[Addigy] Get a paginated list of custom facts for the organization, filtered by id or name. Optional filter (via filtersJson) supports `id` (exact match) and `name_contains` (substring). Supports sort_field (e.g. name) and sort_direction (asc/desc). Returns the same fact shape as addigy_list_custom_facts. Paginated; response metadata carries page/page_count/per_page/result_count/total.

ParamTypeRequiredDefaultDescription
filtersJsonstringnonullOptional JSON filter object. Properties: id (exact match), name_contains (substring match).
pageintegerno1Requested page number (default 1).
perPageintegerno50Number of items per page (default 50, max 500).
sortDirectionstringnonullSort direction: asc or desc. Omit for default.
sortFieldstringnonullField to sort by (e.g. name). Omit for default ordering.

[Addigy] Get a paginated list of custom facts aggregated across organizations. Optional filter (via filtersJson) supports `name_contains` (substring) and `ids` (array of fact ids). Supports sort_field (e.g. name) and sort_direction (asc/desc). per_page is capped at 100 by the API. Spans child organizations when multitenancy=true; scope with childOrganizations. Requires API token permission: View custom facts. Paginated; response metadata carries page/page_count/per_page/result_count/total.

ParamTypeRequiredDefaultDescription
childOrganizationsstringnonullComma-separated list of child organization ids to scope the aggregate to. Omit for all.
filtersJsonstringnonullOptional JSON filter object. Properties: name_contains (substring match), ids (array of fact id strings).
multitenancybooleannonullWhen true, aggregate across child organizations. Omit for the API key's own organization only.
pageintegerno1Requested page number (default 1).
perPageintegerno50Number of items per page (default 50, max 100 — Addigy documents a 100 cap on this endpoint).
sortDirectionstringnonullSort direction: asc or desc. Omit for default.
sortFieldstringnonullField to sort by (e.g. name). Omit for default ordering.

[Addigy] Unassign a custom fact from a policy. Requires the custom fact `id` (from addigy_list_custom_facts) and the `policy_id`. Acts on the API key's own organization by default; pass organizationId (from addigy_list_child_organizations) to act on a specific child organization. Use addigy_assign_custom_fact_to_policy to reassign.

ParamTypeRequiredDefaultDescription
idstringyesCustom Fact id to unassign. Discover with addigy_list_custom_facts.
organizationIdstringnonullOptional organization id to target a specific child organization (from addigy_list_child_organizations). Omit to act on the API key's own organization.
policyIdstringyesPolicy id to unassign the custom fact from.

[Addigy] Update an existing custom fact. Body fields: `id` (required — the fact to update, from addigy_list_custom_facts), `name`, `return_type`, `notes`, and `os_architectures` (object with `linux` and `macOS` architecture settings). Acts on the API key's own organization by default; pass organizationId (from addigy_list_child_organizations) to update the fact in a specific child organization.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object describing the update. Properties: id (required), name, return_type, notes, os_architectures ({ linux, macOS }).
organizationIdstringnonullOptional organization id to target a specific child organization (from addigy_list_child_organizations). Omit to act on the API key's own organization.

End Users

ToolPlanAccessSummary
addigy_assign_device_to_end_userProWriteAssign a device (agent) to an end user.
addigy_delete_end_user_device_assignmentsProDestructiveRemove device assignments from an end user.
addigy_delete_end_user_scim_credentialsProDestructiveDelete one or more SCIM credentials by external id.
addigy_disable_end_user_scimProDestructiveDisable the SCIM integration that provisions end users for this organization.
addigy_enable_end_user_scimProWriteEnable a SCIM integration to provision end users for this organization.
addigy_get_end_userFreeRead-onlyGet a single end user by id.
addigy_get_end_user_scim_credentialsFreeRead-onlyGet the SCIM credentials for one SCIM integration by external id.
addigy_import_end_user_devicesProWriteBulk-import end users and their device assignments from an inventory file (multipart upload).
addigy_query_end_user_device_import_metadataFreeRead-onlyQuery metadata for prior end-user device imports (status, counts, errors per import file).
addigy_query_end_user_devicesFreeRead-onlyQuery device assignments for end users.
addigy_query_end_user_groupsFreeRead-onlyQuery end-user groups.
addigy_query_end_user_scim_credentialsFreeRead-onlyQuery SCIM credentials configured for end-user provisioning.
addigy_query_end_usersFreeRead-onlyQuery end users.
addigy_rotate_end_user_scim_tokenProDestructiveRotate (regenerate) the SCIM token for one integration.
addigy_update_end_user_scimProWriteUpdate an existing SCIM integration used to provision end users.

[Addigy] Assign a device (agent) to an end user. Required body fields: `end_user_id` (from addigy_query_end_users), `agent_id` (the device's agent id). Use addigy_query_end_user_devices to view existing assignments. Requires organizationId from addigy_list_child_organizations. Requires API token permission: Manage end users.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object for the assignment. Required: end_user_id (string), agent_id (string).
organizationIdstringyesOrganization id. Discover via addigy_list_child_organizations.

[Addigy] Remove device assignments from an end user. Required body field: `end_user_id` (from addigy_query_end_users). Optional `agent_ids` (array of device agent ids) — omit to remove all of the end user's device assignments, or supply specific ids to remove only those. Requires organizationId from addigy_list_child_organizations. Requires API token permission: Manage end users.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object identifying the assignments to remove. Required: end_user_id (string). Optional: agent_ids (array of strings); omit to remove all of the end user's device assignments.
organizationIdstringyesOrganization id. Discover via addigy_list_child_organizations.

[Addigy] Delete one or more SCIM credentials by external id. Required body field: `external_ids` (array of external id strings, at least one — discover via addigy_query_end_user_scim_credentials). Requires organizationId from addigy_list_child_organizations. Requires API token permission: Manage end users.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object identifying credentials to delete. Required: external_ids (array of external id strings, min 1 item).
organizationIdstringyesOrganization id. Discover via addigy_list_child_organizations.

[Addigy] Disable the SCIM integration that provisions end users for this organization. Stops SCIM-driven end-user sync. Re-enable with addigy_enable_end_user_scim. Requires organizationId from addigy_list_child_organizations. Requires API token permission: Manage end users.

ParamTypeRequiredDefaultDescription
organizationIdstringyesOrganization id. Discover via addigy_list_child_organizations.

[Addigy] Enable a SCIM integration to provision end users for this organization. Returns the new SCIM credentials (token/external id) needed by your identity provider. Required body field: `name` (display name, min length 1). Requires organizationId from addigy_list_child_organizations. Requires API token permission: Manage end users.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object to enable SCIM. Required: name (string, min length 1, e.g. "My SCIM Integration").
organizationIdstringyesOrganization id. Discover via addigy_list_child_organizations.

[Addigy] Get a single end user by id. Returns the end_user record (id, display name, email, active state, tenant/group associations). Requires organizationId (from addigy_list_child_organizations) and endUserId (discover ids via addigy_query_end_users). Requires API token permission: View end users.

ParamTypeRequiredDefaultDescription
endUserIdstringyesEnd user id. Discover via addigy_query_end_users.
organizationIdstringyesOrganization id. Discover via addigy_list_child_organizations.

[Addigy] Get the SCIM credentials for one SCIM integration by external id. Returns the integration's credential record. Requires externalId (discover via addigy_query_end_user_scim_credentials). Requires organizationId from addigy_list_child_organizations. Requires API token permission: Manage end users.

ParamTypeRequiredDefaultDescription
externalIdstringyesExternal ID of the SCIM credentials to retrieve. Discover via addigy_query_end_user_scim_credentials.
organizationIdstringyesOrganization id. Discover via addigy_list_child_organizations.

[Addigy] Bulk-import end users and their device assignments from an inventory file (multipart upload). Provide the file contents as text and a file name. Returns import metadata (file id, status) — poll progress with addigy_query_end_user_device_import_metadata. Requires organizationId from addigy_list_child_organizations. Requires API token permission: Manage end users.

ParamTypeRequiredDefaultDescription
fileContentstringyesEnd users inventory file contents (text).
fileNamestringyesFile name for the uploaded inventory file (e.g. end-users.csv).
organizationIdstringyesOrganization id. Discover via addigy_list_child_organizations.

[Addigy] Query metadata for prior end-user device imports (status, counts, errors per import file). Use this to monitor an import started by addigy_import_end_user_devices. Optional filter: file_ids (array of import file ids). Paginated; response metadata has page/page_count/total. Requires organizationId from addigy_list_child_organizations. Requires API token permission: View end users.

ParamTypeRequiredDefaultDescription
organizationIdstringyesOrganization id. Discover via addigy_list_child_organizations.
pageintegerno1Page number (default 1).
perPageintegerno50Results per page (default 50, max 100 — Addigy documents a 100 cap on this endpoint).
queryJsonstringnonullJSON filter object. Optional: file_ids (array of import file id strings).
sortDirectionstringnonullSort direction: asc|desc. Omit for default.
sortFieldstringnonullField to sort by (e.g. name). Omit for default order.

[Addigy] Query device assignments for end users. Returns end-user-to-device links. Optional filter: end_user_ids and/or agent_ids (arrays of ids). Use addigy_assign_device_to_end_user / addigy_delete_end_user_device_assignments to change assignments. Paginated; response metadata has page/page_count/total. Requires organizationId from addigy_list_child_organizations. Requires API token permission: View end users.

ParamTypeRequiredDefaultDescription
organizationIdstringyesOrganization id. Discover via addigy_list_child_organizations.
pageintegerno1Page number (default 1).
perPageintegerno50Results per page (default 50, max 100 — Addigy documents a 100 cap on this endpoint).
queryJsonstringnonullJSON filter object. Optional: end_user_ids (array of strings), agent_ids (array of strings).
sortDirectionstringnonullSort direction: asc|desc. Omit for default.
sortFieldstringnonullField to sort by (e.g. displayName). Omit for default order.

[Addigy] Query end-user groups. Returns groups with id, display name, and membership metadata. Optional filters: search (free-text), tenant_ids (array), ids (array of group ids). Use the returned group ids with addigy_query_end_users (group_ids filter) to list members. Paginated; response metadata has page/page_count/total. Requires organizationId from addigy_list_child_organizations. Requires API token permission: View end users.

ParamTypeRequiredDefaultDescription
organizationIdstringyesOrganization id. Discover via addigy_list_child_organizations.
pageintegerno1Page number (default 1).
perPageintegerno50Results per page (default 50, max 100 — Addigy documents a 100 cap on this endpoint).
queryJsonstringnonullJSON filter object. Optional: search (string), tenant_ids (array of strings), ids (array of group id strings).
sortDirectionstringnonullSort direction: asc|desc. Omit for default.
sortFieldstringnonullField to sort by (e.g. displayName). Omit for default order.

[Addigy] Query SCIM credentials configured for end-user provisioning. Returns credential records with external ids and display names. Optional filters: search (free-text), external_ids (array). Use the returned external ids with addigy_get_end_user_scim_credentials, addigy_update_end_user_scim, addigy_rotate_end_user_scim_token, or addigy_delete_end_user_scim_credentials. Paginated; response metadata has page/page_count/total. Requires organizationId from addigy_list_child_organizations. Requires API token permission: Manage end users.

ParamTypeRequiredDefaultDescription
organizationIdstringyesOrganization id. Discover via addigy_list_child_organizations.
pageintegerno1Page number (default 1).
perPageintegerno50Results per page (default 50, max 100 — Addigy documents a 100 cap on this endpoint).
queryJsonstringnonullJSON filter object. Optional: search (string), external_ids (array of strings).
sortDirectionstringnonullSort direction: asc|desc. Omit for default.
sortFieldstringnonullField to sort by (e.g. display_name). Omit for default order.

[Addigy] Query end users. Returns end-user records (id, display name, email, active state). Optional filters: group_ids (array — from addigy_query_end_user_groups), search (free-text), active (boolean), tenant_ids (array). Use addigy_get_end_user for a single full record. Paginated; response metadata has page/page_count/total. Requires organizationId from addigy_list_child_organizations. Requires API token permission: View end users.

ParamTypeRequiredDefaultDescription
organizationIdstringyesOrganization id. Discover via addigy_list_child_organizations.
pageintegerno1Page number (default 1).
perPageintegerno50Results per page (default 50, max 100 — Addigy documents a 100 cap on this endpoint).
queryJsonstringnonullJSON filter object. Optional: group_ids (array of strings), search (string), active (boolean), tenant_ids (array of strings).
sortDirectionstringnonullSort direction: asc|desc. Omit for default.
sortFieldstringnonullField to sort by (e.g. display_name). Omit for default order.

[Addigy] Rotate (regenerate) the SCIM token for one integration. Returns the new SCIM credentials — the old token is invalidated, so update your identity provider afterward. Requires externalId (discover via addigy_query_end_user_scim_credentials). Requires organizationId from addigy_list_child_organizations. Requires API token permission: Manage end users.

ParamTypeRequiredDefaultDescription
externalIdstringyesExternal ID of the SCIM credentials to rotate. Discover via addigy_query_end_user_scim_credentials.
organizationIdstringyesOrganization id. Discover via addigy_list_child_organizations.

[Addigy] Update an existing SCIM integration used to provision end users. Requires externalId (the SCIM integration's external id — discover via addigy_query_end_user_scim_credentials). Required body field: `name` (display name, min length 1). Requires organizationId from addigy_list_child_organizations. Requires API token permission: Manage end users.

ParamTypeRequiredDefaultDescription
externalIdstringyesExternal ID for the SCIM integration. Discover via addigy_query_end_user_scim_credentials.
fieldsJsonstringyesJSON object for the update. Required: name (string, min length 1, e.g. "My SCIM Integration").
organizationIdstringyesOrganization id. Discover via addigy_list_child_organizations.

Monitoring & Alerts

ToolPlanAccessSummary
addigy_act_on_received_alertsProDestructivePerform a bulk action on received alerts within a specific organization: mute, acknowledge, or resolve.
addigy_assign_monitoring_item_to_policyProDestructiveAssign a custom monitoring item to a policy so the check applies to that policy's devices.
addigy_create_monitoring_itemProWriteCreate a custom monitoring item (a fact-based check that raises alerts).
addigy_delete_monitoring_itemProDestructivePermanently delete a custom monitoring item by its id.
addigy_list_received_alertsFreeRead-onlyList received alerts (monitoring checks that have fired), optionally filtered by status.
addigy_query_alert_level_statsFreeRead-onlyAggregate received-alert counts grouped by alert level across organizations.
addigy_query_alert_name_statsFreeRead-onlyAggregate received-alert counts grouped by alert name across organizations.
addigy_query_alert_remediation_statsFreeRead-onlyAggregate received-alert counts grouped by remediation status across organizations.
addigy_query_alert_status_statsFreeRead-onlyAggregate received-alert counts grouped by alert status across organizations.
addigy_query_alert_user_statsFreeRead-onlyAggregate received-alert counts grouped by acknowledging/resolving user across organizations.
addigy_query_monitoring_itemsFreeRead-onlyList the organization's custom monitoring items, optionally filtered by id or a name-contains substring.
addigy_query_received_alertsFreeRead-onlyQuery received alerts across organizations with rich filtering and pagination.
addigy_query_system_eventsFreeRead-onlySearch the organization's system-events audit stream (who did what, when — e.g. policy edits, command runs, device enrollments) with optional keyword highlighting and time-bucketed aggregation.
addigy_search_system_eventsFreeRead-onlySearch the organization's system-events audit stream via the /system-events/search surface (alternate to addigy_query_system_events) with optional keyword highlighting and time-bucketed aggregation.
addigy_unassign_monitoring_item_from_policyProDestructiveRemove a custom monitoring item from a policy (reverses addigy_assign_monitoring_item_to_policy).
addigy_update_monitoring_itemProWriteUpdate an existing custom monitoring item.

[Addigy] Perform a bulk action on received alerts within a specific organization: mute, acknowledge, or resolve. Required: organizationId (from addigy_list_child_organizations), action (mute|acknowledge|resolve), and a body with alert_ids (non-empty array). For action=mute, optionally include days_to_mute (integer, e.g. 7). Discover alert ids with addigy_query_received_alerts.

ParamTypeRequiredDefaultDescription
actionstringyesAction to perform: mute|acknowledge|resolve.
fieldsJsonstringyesJSON object. Required: alert_ids (non-empty array of alert ids). Optional (mute only): days_to_mute (integer, e.g. 7).
organizationIdstringyesOrganization ID (from addigy_list_child_organizations).

[Addigy] Assign a custom monitoring item to a policy so the check applies to that policy's devices. Required body fields: alert_id (the monitoring item id from addigy_query_monitoring_items), policy_id (the target policy id). Use addigy_unassign_monitoring_item_from_policy to reverse this. Requires API token permission: Edit Policy Monitoring.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object. Required: alert_id (monitoring item id), policy_id (target policy id).

[Addigy] Create a custom monitoring item (a fact-based check that raises alerts). Common fields: name, category, type, level, fact / fact_identifier, value / value_type, min_value / max_value, selector, emails (array), send_ticket, remediation_enabled, remediation_time, has_script, script_id, instructions. Returns the created item id. Use addigy_query_monitoring_items to list existing items and addigy_assign_monitoring_item_to_policy to scope it to a policy. Requires API token permission: Create Custom Monitoring.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object describing the monitoring item. Common: name, category, type, level, fact, fact_identifier, value, value_type, min_value, max_value, selector, emails[], send_ticket, remediation_enabled, remediation_time, has_script, script_id, instructions, version, is_in_blueprint.

[Addigy] Permanently delete a custom monitoring item by its id. Discover monitoring item ids with addigy_query_monitoring_items. Requires API token permission: Delete Custom Monitoring.

ParamTypeRequiredDefaultDescription
idstringyesMonitoring item id.

[Addigy] List received alerts (monitoring checks that have fired), optionally filtered by status. Returns the alert schedule with per-alert status and timing. For richer filtering (statuses, categories, date ranges, agent ids) use addigy_query_received_alerts. Paginated; response metadata carries page/page_count/total.

ParamTypeRequiredDefaultDescription
pageintegerno1Page number (default 1).
perPageintegerno50Results per page (default 50, max 500).
statusstringnonullOptional status filter. Omit for all statuses.

[Addigy] Aggregate received-alert counts grouped by alert level across organizations. Optional filter body: statuses[], ids[], name_contains (e.g. "disk"), remediation_status (Pending|Done|Failed), category, start_date / end_date (YYYY-MM-DD), agent_ids[]. Spans child organizations when multitenancy=true (optionally scoped to a child-organizations csv list).

ParamTypeRequiredDefaultDescription
childOrganizationsstringnonullComma-separated list of child organization ids to scope the aggregation to. Omit for all.
fieldsJsonstringnonullJSON filter object. Optional: statuses[], ids[], name_contains, remediation_status (Pending|Done|Failed), category, start_date, end_date (YYYY-MM-DD), agent_ids[].
multitenancybooleannonullWhen true, aggregate across child organizations. Omit to scope to the API key's own organization.

[Addigy] Aggregate received-alert counts grouped by alert name across organizations. Optional filter body: statuses[], ids[], name_contains (e.g. "disk"), remediation_status (Pending|Done|Failed), category, start_date / end_date (YYYY-MM-DD), agent_ids[]. Spans child organizations when multitenancy=true (optionally scoped to a child-organizations csv list).

ParamTypeRequiredDefaultDescription
childOrganizationsstringnonullComma-separated list of child organization ids to scope the aggregation to. Omit for all.
fieldsJsonstringnonullJSON filter object. Optional: statuses[], ids[], name_contains, remediation_status (Pending|Done|Failed), category, start_date, end_date (YYYY-MM-DD), agent_ids[].
multitenancybooleannonullWhen true, aggregate across child organizations. Omit to scope to the API key's own organization.

[Addigy] Aggregate received-alert counts grouped by remediation status across organizations. Optional filter body: statuses[], ids[], name_contains (e.g. "disk"), remediation_status (Pending|Done|Failed), category, start_date / end_date (YYYY-MM-DD), agent_ids[]. Spans child organizations when multitenancy=true (optionally scoped to a child-organizations csv list).

ParamTypeRequiredDefaultDescription
childOrganizationsstringnonullComma-separated list of child organization ids to scope the aggregation to. Omit for all.
fieldsJsonstringnonullJSON filter object. Optional: statuses[], ids[], name_contains, remediation_status (Pending|Done|Failed), category, start_date, end_date (YYYY-MM-DD), agent_ids[].
multitenancybooleannonullWhen true, aggregate across child organizations. Omit to scope to the API key's own organization.

[Addigy] Aggregate received-alert counts grouped by alert status across organizations. Optional filter body: statuses[], ids[], name_contains (e.g. "disk"), remediation_status (Pending|Done|Failed), category, start_date / end_date (YYYY-MM-DD), agent_ids[]. Spans child organizations when multitenancy=true (optionally scoped to a child-organizations csv list).

ParamTypeRequiredDefaultDescription
childOrganizationsstringnonullComma-separated list of child organization ids to scope the aggregation to. Omit for all.
fieldsJsonstringnonullJSON filter object. Optional: statuses[], ids[], name_contains, remediation_status (Pending|Done|Failed), category, start_date, end_date (YYYY-MM-DD), agent_ids[].
multitenancybooleannonullWhen true, aggregate across child organizations. Omit to scope to the API key's own organization.

[Addigy] Aggregate received-alert counts grouped by acknowledging/resolving user across organizations. Optional filter body: statuses[], ids[], name_contains (e.g. "disk"), remediation_status (Pending|Done|Failed), category, start_date / end_date (YYYY-MM-DD), agent_ids[]. Spans child organizations when multitenancy=true (optionally scoped to a child-organizations csv list).

ParamTypeRequiredDefaultDescription
childOrganizationsstringnonullComma-separated list of child organization ids to scope the aggregation to. Omit for all.
fieldsJsonstringnonullJSON filter object. Optional: statuses[], ids[], name_contains, remediation_status (Pending|Done|Failed), category, start_date, end_date (YYYY-MM-DD), agent_ids[].
multitenancybooleannonullWhen true, aggregate across child organizations. Omit to scope to the API key's own organization.

[Addigy] List the organization's custom monitoring items, optionally filtered by id or a name-contains substring. Returns the item definitions (name, fact, thresholds, remediation settings). Use the returned ids with addigy_update_monitoring_item, addigy_delete_monitoring_item, or addigy_assign_monitoring_item_to_policy. Paginated; response metadata carries page/page_count/total.

ParamTypeRequiredDefaultDescription
pageintegerno1Page number (default 1).
perPageintegerno50Results per page (default 50, max 500).
queryJsonstringnonullJSON filter object. Optional: id (exact monitoring item id), name_contains (substring match on the item name).
sortDirectionstringnonullSort direction (e.g. asc|desc). Omit for default.
sortFieldstringnonullField to sort by. Omit for default order.

[Addigy] Query received alerts across organizations with rich filtering and pagination. The nested query filter accepts: statuses[], ids[], name_contains (e.g. "disk"), remediation_status (Pending|Done|Failed), category, start_date / end_date (YYYY-MM-DD), agent_ids[]. Prefer this over addigy_list_received_alerts for filtered triage. Paginated; response metadata carries page/page_count/total. Spans child organizations when multitenancy=true (optionally scoped to a child-organizations csv list).

ParamTypeRequiredDefaultDescription
childOrganizationsstringnonullComma-separated list of child organization ids to scope the query to. Omit for all.
multitenancybooleannonullWhen true, query across child organizations. Omit to scope to the API key's own organization.
pageintegerno1Page number (default 1).
perPageintegerno50Results per page (default 50, max 100 — Addigy documents a 100 cap on this endpoint).
queryJsonstringnonullJSON filter object for the nested query. Optional: statuses[], ids[], name_contains, remediation_status (Pending|Done|Failed), category, start_date, end_date (YYYY-MM-DD), agent_ids[].
sortDirectionstringnonullSort direction: asc|desc. Omit for default.
sortFieldstringnonullField to sort by (e.g. name). Omit for default order.

[Addigy] Search the organization's system-events audit stream (who did what, when — e.g. policy edits, command runs, device enrollments) with optional keyword highlighting and time-bucketed aggregation. Use addigy_search_system_events for the alternate /system-events/search surface. Paginated; response metadata carries page/page_count/total. Requires API token permission: View System Events.

ParamTypeRequiredDefaultDescription
pageintegerno1Page number (default 1).
perPageintegerno50Results per page (default 50, max 500).
queryJsonstringnonullJSON object with the remaining request fields. Optional: from_date_time / to_date_time (e.g. "2024-01-01T01:01:01Z"), search_after (integer cursor), queries (array of {query, fields[]} — fields example ["action_sender.type"]), options ({keywords:bool, highlight:bool, aggregation_interval_minutes:int}).
sortDirectionstringnonullSort direction for the event timeline: asc|desc.

[Addigy] Search the organization's system-events audit stream via the /system-events/search surface (alternate to addigy_query_system_events) with optional keyword highlighting and time-bucketed aggregation. Paginated; response metadata carries page/page_count/total. Requires API token permission: View System Events.

ParamTypeRequiredDefaultDescription
pageintegerno1Page number (default 1).
perPageintegerno50Results per page (default 50, max 500).
queryJsonstringnonullJSON object with the remaining request fields. Optional: from_date_time / to_date_time (e.g. "2024-01-01T01:01:01Z"), search_after (integer cursor), queries (array of {query, fields[]} — fields example ["action_sender.type"]), options ({keywords:bool, highlight:bool, aggregation_interval_minutes:int}).
sortDirectionstringnonullSort direction for the event timeline: asc|desc.

[Addigy] Remove a custom monitoring item from a policy (reverses addigy_assign_monitoring_item_to_policy). Both ids are required. Requires API token permission: Edit Policy Monitoring.

ParamTypeRequiredDefaultDescription
alertIdstringyesId of the monitoring item.
policyIdstringyesId of the policy.

[Addigy] Update an existing custom monitoring item. The body must include the item id plus the fields to change. Common fields: id, name, category, type, level, fact, fact_identifier, value, value_type, min_value, max_value, selector, emails[], send_ticket, remediation_enabled, remediation_time, has_script, script_id, instructions, version. Discover ids with addigy_query_monitoring_items. Requires API token permission: Edit Custom Monitoring.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object with the updated monitoring item. Must include id. Common: name, category, type, level, fact, fact_identifier, value, value_type, min_value, max_value, selector, emails[], send_ticket, remediation_enabled, remediation_time, has_script, script_id, instructions, version, is_in_blueprint.

Software

ToolPlanAccessSummary
addigy_assign_managed_app_configProDestructiveAssigns (or unassigns) a managed app configuration to an Apple Apps & Books (VPP) application.
addigy_assign_smart_software_to_policyProDestructiveAssigns a Smart Software item to a policy, given the organizationId, policyId and the Smart Software assetId.
addigy_create_managed_app_configProWriteCreates a managed app configuration for an Apps & Books (VPP) application.
addigy_create_smart_softwareProWriteCreates a new Smart Software item in an organization.
addigy_create_smart_software_versionProWriteCreates a new version of an existing Smart Software item.
addigy_delete_managed_app_configProDestructiveDeletes the managed app configuration for a single Apps & Books (VPP) application, identified by its locationId and the app's bundleId.
addigy_delete_smart_softwareProDestructiveDeletes a Smart Software item by id, scoped to an organization.
addigy_get_managed_app_configFreeRead-onlyGets the managed app configuration for a single Apps & Books (VPP) application, identified by its locationId (VPP/Apps-and-Books location) and the app's bundleId (e.g. com.microsoft.Outlook).
addigy_get_smart_softwareFreeRead-onlyGets a single Smart Software item by id, scoped to an organization.
addigy_query_smart_softwareFreeRead-onlyGets a paginated list of Smart Software items, optionally filtered.
addigy_query_vpp_token_policy_assignmentsFreeRead-onlyGets the list of Apps & Books (VPP) tokens assigned to a set of policies.
addigy_search_managed_app_configsFreeRead-onlyGets all managed app configurations for an Apps & Books (VPP) location.
addigy_unassign_smart_software_from_policyProDestructiveUnassigns a Smart Software item from a policy, given the organizationId, policyId and the Smart Software assetId.

[Addigy] Assigns (or unassigns) a managed app configuration to an Apple Apps & Books (VPP) application. Provide a JSON object. Properties: location_id (string), bundle_id (string), is_assigned (boolean — true to assign, false to unassign). Use addigy_get_managed_app_config to read the current assignment state.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object. Properties: location_id (string), bundle_id (string), is_assigned (bool).

[Addigy] Assigns a Smart Software item to a policy, given the organizationId, policyId and the Smart Software assetId. Discover organizationId via addigy_list_child_organizations, policy ids via the policies tools, and Smart Software asset ids via addigy_query_smart_software. Requires Addigy permission: Add Asset To Policy.

ParamTypeRequiredDefaultDescription
assetIdstringyesSmart Software ID (asset id, from addigy_query_smart_software).
organizationIdstringyesOrganization ID (from addigy_list_child_organizations).
policyIdstringyesPolicy ID to assign the Smart Software item to.

[Addigy] Creates a managed app configuration for an Apps & Books (VPP) application. Provide a JSON object. Properties: location_id (string), bundle_id (string), configuration (object map of key→Configuration), is_assigned (boolean), asset_id (string). Use addigy_get_managed_app_config / addigy_search_managed_app_configs afterward to read the stored config.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object for the managed app configuration. Properties: location_id, bundle_id, configuration (object), is_assigned (bool), asset_id.

[Addigy] Creates a new Smart Software item in an organization. Pass the organizationId (from addigy_list_child_organizations) and a JSON body matching CreateSmartSoftwareRequest, optionally with a profiles array of PPPC profile objects. Use addigy_query_smart_software afterward to discover the new item's id. Requires Addigy permission: Create Smart Software.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON body for the Smart Software item (CreateSmartSoftwareRequest fields, optional profiles array of PPPC profiles).
organizationIdstringyesOrganization ID (from addigy_list_child_organizations).

[Addigy] Creates a new version of an existing Smart Software item. Pass the organizationId (from addigy_list_child_organizations), the Smart Software id (from addigy_query_smart_software), and a JSON body matching UpdateSmartSoftwareRequest, optionally with a profiles array of PPPC profile objects. Returns the updated CustomSoftware definition. Requires Addigy permission: Create Smart Software.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON body for the new version (UpdateSmartSoftwareRequest fields, optional profiles array of PPPC profiles).
idstringyesSmart Software ID (from addigy_query_smart_software).
organizationIdstringyesOrganization ID (from addigy_list_child_organizations).

[Addigy] Deletes the managed app configuration for a single Apps & Books (VPP) application, identified by its locationId and the app's bundleId. Use addigy_search_managed_app_configs to confirm which configurations exist for a location before deleting.

ParamTypeRequiredDefaultDescription
bundleIdstringyesBundle ID of the app (e.g. com.microsoft.Outlook).
locationIdstringyesLocation ID (the Apps & Books / VPP location).

[Addigy] Deletes a Smart Software item by id, scoped to an organization. Pass the organizationId (from addigy_list_child_organizations) and the Smart Software id (from addigy_query_smart_software or addigy_get_smart_software). Requires Addigy permission: Delete Smart Software.

ParamTypeRequiredDefaultDescription
idstringyesSmart Software ID (from addigy_query_smart_software).
organizationIdstringyesOrganization ID (from addigy_list_child_organizations).

[Addigy] Gets the managed app configuration for a single Apps & Books (VPP) application, identified by its locationId (VPP/Apps-and-Books location) and the app's bundleId (e.g. com.microsoft.Outlook). Returns the configuration key/value payload plus assignment flag and asset id. Use addigy_search_managed_app_configs to enumerate every managed app configuration for a location and discover bundle ids.

ParamTypeRequiredDefaultDescription
bundleIdstringyesBundle ID of the app (e.g. com.microsoft.Outlook).
locationIdstringyesLocation ID (the Apps & Books / VPP location).

[Addigy] Gets a single Smart Software item by id, scoped to an organization. Pass the organizationId (from addigy_list_child_organizations) and the Smart Software id (from addigy_query_smart_software). Returns the full CustomSoftware definition. Requires Addigy permission: View Smart Software.

ParamTypeRequiredDefaultDescription
idstringyesSmart Software ID (from addigy_query_smart_software).
organizationIdstringyesOrganization ID (from addigy_list_child_organizations).

[Addigy] Gets a paginated list of Smart Software items, optionally filtered. Build the filter via queryJson — a JSON object supporting: archived (bool), name_contains (string), identifier (string — to fetch the versions of a specific software), ids (array), excluded_ids (array). Sort with sortField (default name) and sortDirection (asc|desc). Paginated; per_page max 100 per Addigy and response metadata carries page_count/total. Spans child organizations when multitenancy=true (optionally narrowed by childOrganizations). Use addigy_get_smart_software for full detail of a single item. Requires Addigy permission: View Smart Software.

ParamTypeRequiredDefaultDescription
childOrganizationsstringnonullComma-separated list of child organization ids to scope the aggregation to. Omit for all.
multitenancybooleannonullWhen true, aggregate results across child organizations. Omit for the API key's own organization.
pageintegerno1Page number (default 1).
perPageintegerno50Results per page (default 50, max 100 — Addigy documents a 100 cap on this endpoint).
queryJsonstringnonullJSON object with the smart_software filter. Optional properties: archived (bool), name_contains (string), identifier (string), ids (array), excluded_ids (array). Omit for no filter.
sortDirectionstringnonullSort direction: asc|desc (default asc).
sortFieldstringnonullField to sort by (default name).

[Addigy] Gets the list of Apps & Books (VPP) tokens assigned to a set of policies. Provide a JSON object with a policy_ids array (string policy ids). Returns an array of AppsAndBooksToken records. Spans child organizations when multitenancy=true (optionally narrowed by childOrganizations).

ParamTypeRequiredDefaultDescription
childOrganizationsstringnonullComma-separated list of child organization ids to scope the aggregation to. Omit for all.
fieldsJsonstringyesJSON object with the query. Property: policy_ids (array of policy id strings).
multitenancybooleannonullWhen true, aggregate results across child organizations. Omit for the API key's own organization.

[Addigy] Gets all managed app configurations for an Apps & Books (VPP) location. Returns an array of configurations, each with its bundle_id, configuration payload, assignment flag and asset id. Use this to discover bundle ids before calling addigy_get_managed_app_config, addigy_assign_managed_app_config or addigy_delete_managed_app_config.

ParamTypeRequiredDefaultDescription
locationIdstringyesLocation ID (the Apps & Books / VPP location).

[Addigy] Unassigns a Smart Software item from a policy, given the organizationId, policyId and the Smart Software assetId. Discover organizationId via addigy_list_child_organizations and Smart Software asset ids via addigy_query_smart_software. Requires Addigy permission: Remove Asset From Policy.

ParamTypeRequiredDefaultDescription
assetIdstringyesSmart Software ID (asset id, from addigy_query_smart_software).
organizationIdstringyesOrganization ID (from addigy_list_child_organizations).
policyIdstringyesPolicy ID to unassign the Smart Software item from.

Prebuilt Apps

ToolPlanAccessSummary
addigy_create_prebuilt_app_configProWriteAdds a Prebuilt App Configuration to a Policy — this is what actually deploys a Prebuilt App from the library to the Macs in a policy.
addigy_delete_prebuilt_app_configProDestructiveRemoves a Prebuilt App Configuration from a Policy — undeploys the Prebuilt App from that policy.
addigy_get_prebuilt_appFreeRead-onlyGets a single app from the Prebuilt App library by its app ID.
addigy_get_prebuilt_app_configFreeRead-onlyGets a single Prebuilt App Configuration by its configuration ID.
addigy_get_prebuilt_app_versionFreeRead-onlyGets a single app version from the Prebuilt App library by its version ID.
addigy_query_prebuilt_app_configsFreeRead-onlyQueries Prebuilt App Configurations across organizations.
addigy_query_prebuilt_app_versionsFreeRead-onlyQueries app versions in the Prebuilt App library to discover version ids (needed to pin a Prebuilt App Configuration via addigy_create_prebuilt_app_config).
addigy_query_prebuilt_appsFreeRead-onlyQueries the Prebuilt App library to discover available apps (and their app ids) for deployment via addigy_create_prebuilt_app_config.
addigy_update_prebuilt_app_configProWriteUpdates an existing Prebuilt App Configuration (e.g. pin a new prebuilt_app_version_id, change enforcement_days or auto_update).

[Addigy] Adds a Prebuilt App Configuration to a Policy — this is what actually deploys a Prebuilt App from the library to the Macs in a policy. Requires organizationId from addigy_list_child_organizations. Required body fields: policy_id (target policy), prebuilt_app_id (discover with addigy_query_prebuilt_apps), prebuilt_app_version_id (discover with addigy_query_prebuilt_app_versions), provider ("prebuilt-app" or "prebuilt-app-self-service"), enforcement_days (0-14, default 14). Optional: auto_update (default true), run_removal_script (default false), update_only (default false). Returns the created configuration. Requires API token permission: Add asset to policy.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object for the new Prebuilt App Configuration. Required: policy_id, prebuilt_app_id, prebuilt_app_version_id, provider (prebuilt-app|prebuilt-app-self-service), enforcement_days (0-14). Optional: auto_update (default true), run_removal_script (default false), update_only (default false).
organizationIdstringyesOrganization ID. Discover with addigy_list_child_organizations.

[Addigy] Removes a Prebuilt App Configuration from a Policy — undeploys the Prebuilt App from that policy. Requires organizationId from addigy_list_child_organizations and the configuration id (discover with addigy_query_prebuilt_app_configs). This is irreversible; re-add with addigy_create_prebuilt_app_config. Requires API token permission: Remove asset from policy.

ParamTypeRequiredDefaultDescription
idstringyesConfiguration ID. Discover with addigy_query_prebuilt_app_configs.
organizationIdstringyesOrganization ID. Discover with addigy_list_child_organizations.

[Addigy] Gets a single app from the Prebuilt App library by its app ID. Returns the app's name, provider, categories, published state, and metadata. Discover app ids with addigy_query_prebuilt_apps; list its versions with addigy_query_prebuilt_app_versions. Requires API token permission: View Prebuilt Apps.

ParamTypeRequiredDefaultDescription
idstringyesApp ID. Discover with addigy_query_prebuilt_apps.

[Addigy] Gets a single Prebuilt App Configuration by its configuration ID. Returns the configuration's policy_id, prebuilt_app_id, prebuilt_app_version_id, provider, enforcement_days, auto_update, and related deployment settings. Requires organizationId from addigy_list_child_organizations and the configuration id (discover with addigy_query_prebuilt_app_configs). Requires API token permission: View Prebuilt Apps Configurations.

ParamTypeRequiredDefaultDescription
idstringyesConfiguration ID. Discover with addigy_query_prebuilt_app_configs.
organizationIdstringyesOrganization ID. Discover with addigy_list_child_organizations.

[Addigy] Gets a single app version from the Prebuilt App library by its version ID. Returns the version's app_id, version string, published_date, and metadata. Discover version ids with addigy_query_prebuilt_app_versions; the version id is required to pin a Prebuilt App Configuration via addigy_create_prebuilt_app_config. Requires API token permission: View Prebuilt Apps.

ParamTypeRequiredDefaultDescription
idstringyesVersion ID. Discover with addigy_query_prebuilt_app_versions.

[Addigy] Queries Prebuilt App Configurations across organizations. Use this to discover configuration ids before addigy_get_prebuilt_app_config / addigy_update_prebuilt_app_config / addigy_delete_prebuilt_app_config. Pass a queryJson filter object to narrow results (any of: ids[], policy_ids[], prebuilt_app_ids[], prebuilt_app_version_ids[], provider (prebuilt-app|prebuilt-app-self-service), update_only, auto_update, assist_onboarding). Sort with sortField (id|policy_id|prebuilt_app_id|prebuilt_app_version_id) + sortDirection (asc|desc). Paginated; response metadata has page/page_count/total. Spans child organizations when multitenancy=true. Requires API token permission: View Prebuilt Apps Configurations.

ParamTypeRequiredDefaultDescription
childOrganizationsstringnonullComma-separated list of child organization IDs to scope the aggregate query. Discover with addigy_list_child_organizations.
multitenancybooleannonullSet true to aggregate Prebuilt App Configurations across child organizations.
pageintegerno1Page number (default 1).
perPageintegerno10Results per page (default 10, max 100 — Addigy documents a 100 cap on this endpoint).
queryJsonstringnonullOptional JSON filter object. Any of: ids[], policy_ids[], prebuilt_app_ids[], prebuilt_app_version_ids[], provider (prebuilt-app|prebuilt-app-self-service), update_only, auto_update, assist_onboarding. Omit for no filter.
sortDirectionstringno"asc"Sort direction: asc|desc (default asc).
sortFieldstringno"id"Field to sort by: id|policy_id|prebuilt_app_id|prebuilt_app_version_id (default id).

[Addigy] Queries app versions in the Prebuilt App library to discover version ids (needed to pin a Prebuilt App Configuration via addigy_create_prebuilt_app_config). Pass a queryJson filter object to narrow results (any of: ids[], app_ids[], policy_ids[], version). Sort with sortField (id|app_id|version|published_date) + sortDirection (asc|desc). Paginated; response metadata has page/page_count/total. Requires API token permission: View Prebuilt Apps.

ParamTypeRequiredDefaultDescription
pageintegerno1Page number (default 1).
perPageintegerno50Results per page (default 50, max 100 — Addigy documents a 100 cap on this endpoint).
queryJsonstringnonullOptional JSON filter object. Any of: ids[], app_ids[], policy_ids[], version. Omit for no filter.
sortDirectionstringnonullSort direction: asc|desc. Omit for default.
sortFieldstringnonullField to sort by: id|app_id|version|published_date. Omit for default order.

[Addigy] Queries the Prebuilt App library to discover available apps (and their app ids) for deployment via addigy_create_prebuilt_app_config. Pass a queryJson filter object to narrow results (any of: ids[], excluded_ids[], assigned_ids[], policy_ids[], categories[], name, provider (prebuilt-app|prebuilt-app-self-service), assist_onboarding, published, version_id). Sort with sortField + sortDirection (asc|desc). Paginated; response metadata has page/page_count/total. Requires API token permission: View Prebuilt Apps.

ParamTypeRequiredDefaultDescription
pageintegerno1Page number (default 1).
perPageintegerno50Results per page (default 50, max 100 — Addigy documents a 100 cap on this endpoint).
queryJsonstringnonullOptional JSON filter object. Any of: ids[], excluded_ids[], assigned_ids[], policy_ids[], categories[], name, provider (prebuilt-app|prebuilt-app-self-service), assist_onboarding, published, version_id. Omit for no filter.
sortDirectionstringnonullSort direction: asc|desc. Omit for default.
sortFieldstringnonullField to sort by. Omit for default order.

[Addigy] Updates an existing Prebuilt App Configuration (e.g. pin a new prebuilt_app_version_id, change enforcement_days or auto_update). Requires organizationId from addigy_list_child_organizations and the configuration id (discover with addigy_query_prebuilt_app_configs). Body fields (all optional): prebuilt_app_version_id, enforcement_days (0-14), auto_update, run_removal_script, update_only, assist_onboarding. Returns the updated configuration. Requires API token permission: Edit Prebuilt Apps Configurations.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object with the fields to update. All optional: prebuilt_app_version_id, enforcement_days (0-14), auto_update, run_removal_script, update_only, assist_onboarding.
idstringyesConfiguration ID. Discover with addigy_query_prebuilt_app_configs.
organizationIdstringyesOrganization ID. Discover with addigy_list_child_organizations.

Scripts & Maintenance

ToolPlanAccessSummary
addigy_assign_maintenance_item_to_policyProDestructiveAssign a scheduled maintenance item to a policy so devices in that policy run it.
addigy_assign_os_user_to_policyProDestructiveAssign an OS user asset to a policy.
addigy_cancel_temp_admin_sessionProDestructiveCancel a scheduled or active TempAdmin session for a Mac user account.
addigy_create_device_script_assignmentProDestructiveCreate a device script assignment — schedule a script (predefined command) to run on one or more devices in the organization.
addigy_create_maintenance_itemProWriteCreate a scheduled maintenance item (a recurring catalog maintenance task).
addigy_create_scriptsProWriteCreate one or more scripts (predefined commands) in an organization.
addigy_delete_device_script_assignmentProDestructiveDelete a device script assignment — unschedule a script (predefined command) from a single device.
addigy_delete_maintenance_itemProDestructiveDelete a scheduled maintenance item by its id (from addigy_query_maintenance_items).
addigy_delete_os_userProDestructiveDelete an OS User asset from an organization.
addigy_delete_scriptProDestructiveDelete a script (predefined command) by id from an organization.
addigy_list_device_script_assignmentsFreeRead-onlyList device script assignments available for the organization — the mapping of scripts (predefined commands) to the specific devices they are scheduled to run on.
addigy_query_maintenance_itemsFreeRead-onlyQuery the organization's scheduled maintenance items (recurring catalog maintenance — bundles of scripts run on a frequency).
addigy_query_scriptsFreeRead-onlyQuery the organization's scripts (predefined commands) and return a paginated list.
addigy_schedule_temp_admin_sessionProDestructiveSchedule (or update the schedule for) a TempAdmin session that temporarily promotes a Mac user account to admin.
addigy_unassign_maintenance_item_from_policyProDestructiveUnassign a scheduled maintenance item from a policy.
addigy_unassign_os_user_from_policyProDestructiveUnassign an OS user asset from a policy.
addigy_update_maintenance_itemProWriteUpdate an existing scheduled maintenance item.

[Addigy] Assign a scheduled maintenance item to a policy so devices in that policy run it. Required body fields: `maintenance_id` (from addigy_query_maintenance_items) and `policy_id` (the target policy). Requires API token permission: Edit Policy Maintenance. Use addigy_unassign_maintenance_item_from_policy to reverse.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object. Required: maintenance_id (string, from addigy_query_maintenance_items), policy_id (string, the target policy).

[Addigy] Assign an OS user asset to a policy. Requires organizationId (discover via addigy_list_child_organizations), the asset_id of the OS user, and the policy_id to assign it to. Requires API token permission: Add asset to policy. Use addigy_unassign_os_user_from_policy to reverse.

ParamTypeRequiredDefaultDescription
assetIdstringyesAsset ID of the OS user.
organizationIdstringyesOrganization ID. Discover via addigy_list_child_organizations.
policyIdstringyesPolicy ID to assign the OS user to.

[Addigy] Cancel a scheduled or active TempAdmin session for a Mac user account. Requires organizationId (discover via addigy_list_child_organizations), agent_id (the device's Agent ID), and account_name (the macOS account). Requires API token permission: Manage Mac Users Privileges. Use addigy_schedule_temp_admin_session to (re)schedule.

ParamTypeRequiredDefaultDescription
accountNamestringyesAccount name of the macOS user.
agentIdstringyesAgent ID of the device.
organizationIdstringyesOrganization ID. Discover via addigy_list_child_organizations.

[Addigy] Create a device script assignment — schedule a script (predefined command) to run on one or more devices in the organization. Required body fields: `script_id` (Script or Command ID from addigy_query_scripts) and `agent_ids` (array of Agent IDs of the target devices). Defaults to the API key's own organization; pass organizationId to target a specific child organization (discover IDs via addigy_list_child_organizations). Use addigy_list_device_script_assignments to confirm the assignment afterward.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object with the assignment. Required: script_id (string, Script or Command ID of the script to assign), agent_ids (array of strings, Agent IDs of the devices to assign).
organizationIdstringnonullOptional organization ID to target a specific child organization. Omit to act on the API key's own organization. Discover IDs via addigy_list_child_organizations.

[Addigy] Create a scheduled maintenance item (a recurring catalog maintenance task). Body properties include `name`, `description`, `frequency` (e.g. `Monthly`), `day` (e.g. `15`), `scheduled_time`, `enabled`, `local_time`, `prompt_user`, `timeout_seconds`, `max_try_count`, `expected_remediation_time`, `is_in_blueprint`, `version`, and `scripts` (array of {name, type, command_id, script}). Requires API token permission: Create Catalog Maintenance. Use addigy_query_maintenance_items to confirm afterward and addigy_assign_maintenance_item_to_policy to scope it to a policy.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object describing the maintenance item. Properties: name, description, frequency (e.g. Monthly), day (e.g. 15), scheduled_time, enabled, local_time, prompt_user, timeout_seconds, max_try_count, expected_remediation_time, is_in_blueprint, version, scripts (array of {name, type, command_id, script}).

[Addigy] Create one or more scripts (predefined commands) in an organization. Requires organizationId (discover via addigy_list_child_organizations). Body field `commands` is a required non-empty array of script objects; each script requires `name`, `text` (the script body), and `categories` (non-empty array of category names), with optional `description`, `created_date`, and `in_review`. Requires API token permission: Create Predefined Commands. Use addigy_query_scripts to discover the new script ids.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object. Required: commands (non-empty array of script objects). Each script requires name (string), text (string, the script body), categories (non-empty array of strings); optional description, created_date, in_review.
organizationIdstringyesOrganization ID. Discover via addigy_list_child_organizations.

[Addigy] Delete a device script assignment — unschedule a script (predefined command) from a single device. Requires both script_id (Script or Command ID from addigy_query_scripts) and agent_id (the device's Agent ID). Defaults to the API key's own organization; pass organizationId to target a specific child organization (discover IDs via addigy_list_child_organizations). Use addigy_list_device_script_assignments to find existing assignments.

ParamTypeRequiredDefaultDescription
agentIdstringyesAgent ID of the device.
organizationIdstringnonullOptional organization ID to target a specific child organization. Omit to act on the API key's own organization. Discover IDs via addigy_list_child_organizations.
scriptIdstringyesScript or Command ID of the script. Discover via addigy_query_scripts.

[Addigy] Delete a scheduled maintenance item by its id (from addigy_query_maintenance_items). Requires API token permission: Delete Catalog Maintenance.

ParamTypeRequiredDefaultDescription
idstringyesMaintenance id. Discover via addigy_query_maintenance_items.

[Addigy] Delete an OS User asset from an organization. Requires organizationId (discover via addigy_list_child_organizations) and the asset_id of the OS user. Requires API token permission: Delete OS Users.

ParamTypeRequiredDefaultDescription
assetIdstringyesAsset ID of the OS user to delete.
organizationIdstringyesOrganization ID. Discover via addigy_list_child_organizations.

[Addigy] Delete a script (predefined command) by id from an organization. Requires organizationId (discover via addigy_list_child_organizations) and the script id (discover via addigy_query_scripts). Requires API token permission: Delete Predefined Commands.

ParamTypeRequiredDefaultDescription
idstringyesScript id. Discover via addigy_query_scripts.
organizationIdstringyesOrganization ID. Discover via addigy_list_child_organizations.

[Addigy] List device script assignments available for the organization — the mapping of scripts (predefined commands) to the specific devices they are scheduled to run on. Returns an array of assignments keyed by script_id and agent_id. Optionally filter to a single script (script_id from addigy_query_scripts) or a single device (agent_id, the device's Agent ID). Acts on the API key's own organization. Use addigy_create_device_script_assignment to add an assignment and addigy_delete_device_script_assignment to remove one.

ParamTypeRequiredDefaultDescription
agentIdstringnonullAgent ID of the device to get device script assignments. Omit to list assignments across all devices.
scriptIdstringnonullScript or Command ID of the script to get device script assignments. Omit to list all assignments. Discover via addigy_query_scripts.

[Addigy] Query the organization's scheduled maintenance items (recurring catalog maintenance — bundles of scripts run on a frequency). Returns a paginated list. Optional filters via filtersJson: `id` (exact maintenance id) and `name_contains` (substring match on name). Optional sort_field (e.g. `frequency`) and sort_direction (`asc`/`desc`). Paginated; response metadata carries page/page_count/total. Use addigy_create_maintenance_item to add one and addigy_update_maintenance_item / addigy_delete_maintenance_item to manage existing items.

ParamTypeRequiredDefaultDescription
filtersJsonstringnonullOptional JSON filter object. Supported properties: id (string, exact maintenance id), name_contains (string, substring match on name).
pageintegerno1Page number (default 1).
perPageintegerno50Results per page (default 50, max 500).
sortDirectionstringnonullOptional sort direction: asc|desc. Omit for default ordering.
sortFieldstringnonullOptional sort field, e.g. `frequency`. Omit for default ordering.

[Addigy] Query the organization's scripts (predefined commands) and return a paginated list. Requires organizationId (discover via addigy_list_child_organizations). Optional filter via filtersJson: `ids` (array of script ids). Optional sort_field (e.g. `name`) and sort_order (`asc`/`desc`). Paginated (per_page max 100 upstream); response metadata carries page/page_count/total. Requires API token permission: View Predefined Commands. Use addigy_create_scripts to add scripts and addigy_delete_script to remove one.

ParamTypeRequiredDefaultDescription
filtersJsonstringnonullOptional JSON filter object. Supported property: ids (array of strings, script ids to fetch).
organizationIdstringyesOrganization ID. Discover via addigy_list_child_organizations.
pageintegerno1Page number (default 1).
perPageintegerno50Results per page (default 50, max 100 — Addigy documents a 100 cap on this endpoint).
sortFieldstringnonullOptional sort field, e.g. `name`. Omit for default ordering.
sortOrderstringnonullOptional sort order: asc|desc. Omit for default ordering.

[Addigy] Schedule (or update the schedule for) a TempAdmin session that temporarily promotes a Mac user account to admin. Requires organizationId (discover via addigy_list_child_organizations), agent_id (the device's Agent ID), and account_name (the macOS account to promote). Optional body fields: `start_time` and `end_time` (ISO8601, e.g. 2024-07-08T19:00:00Z), `device_local_time` (bool), and `reason` (e.g. 'Install Slack'). Requires API token permission: Manage Mac Users Privileges. Use addigy_cancel_temp_admin_session to cancel.

ParamTypeRequiredDefaultDescription
accountNamestringyesAccount name of the macOS user to promote.
agentIdstringyesAgent ID of the device.
fieldsJsonstringnonullOptional JSON object for the TempAdmin request. Properties: start_time (ISO8601, e.g. 2024-07-08T19:00:00Z), end_time (ISO8601), device_local_time (bool), reason (string, e.g. 'Install Slack'). Omit to use defaults.
organizationIdstringyesOrganization ID. Discover via addigy_list_child_organizations.

[Addigy] Unassign a scheduled maintenance item from a policy. Requires the maintenance id (from addigy_query_maintenance_items) and the policy_id. Requires API token permission: Edit Policy Maintenance. Use addigy_assign_maintenance_item_to_policy to re-assign.

ParamTypeRequiredDefaultDescription
idstringyesMaintenance id. Discover via addigy_query_maintenance_items.
policyIdstringyesPolicy id to unassign the maintenance item from.

[Addigy] Unassign an OS user asset from a policy. Requires organizationId (discover via addigy_list_child_organizations), the asset_id of the OS user, and the policy_id to unassign it from. Requires API token permission: Remove asset from policy. Use addigy_assign_os_user_to_policy to re-assign.

ParamTypeRequiredDefaultDescription
assetIdstringyesAsset ID of the OS user.
organizationIdstringyesOrganization ID. Discover via addigy_list_child_organizations.
policyIdstringyesPolicy ID to unassign the OS user from.

[Addigy] Update an existing scheduled maintenance item. Body must include `id` (the maintenance id from addigy_query_maintenance_items) plus the fields to change: `name`, `description`, `frequency`, `day`, `scheduled_time`, `enabled`, `local_time`, `prompt_user`, `timeout_seconds`, `max_try_count`, `expected_remediation_time`, `is_in_blueprint`, `version`, and `scripts` (array of {name, type, command_id, script}). Requires API token permission: Edit Catalog Maintenance.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object describing the maintenance item update. Must include id (the maintenance id). Properties: name, description, frequency, day, scheduled_time, enabled, local_time, prompt_user, timeout_seconds, max_try_count, expected_remediation_time, is_in_blueprint, version, scripts (array of {name, type, command_id, script}).

System Updates

ToolPlanAccessSummary
addigy_email_installed_updates_reportProDestructiveRequests that an installed-system-updates report for a policy's devices be generated and emailed to a recipient.
addigy_get_available_system_updates_statusFreeRead-onlyReturns the OS software updates reported as available for a single device, each annotated with its current installation status (e.g. scheduled, downloading, installing, installed, failed).
addigy_get_device_installed_updates_reportFreeRead-onlyReturns the history of OS software updates already installed on a single device, as reported via MDM.
addigy_get_system_updates_settingsFreeRead-onlyReturns the configured system-updates settings for a policy — the per-OS (macOS/iOS/iPadOS/tvOS) update enforcement rules and the optional daily-send schedule.
addigy_get_system_updates_statusFreeRead-onlyReturns the current system-updates statuses most recently reported for a single device (the live progress of in-flight OS updates).
addigy_list_available_system_updatesFreeRead-onlyReturns the OS software updates most recently reported as available for a single device.
addigy_request_available_system_updatesProDestructiveIssues an MDM command asking a device to report the OS software updates it currently has available.
addigy_request_system_updates_scanProDestructiveIssues an MDM command telling a device to scan for newly-available OS software updates, refreshing what addigy_list_available_system_updates / addigy_get_available_system_updates_status will return.
addigy_request_system_updates_scheduleProDestructiveIssues an MDM command scheduling a specific OS software update to install on a single device.
addigy_request_system_updates_statusProDestructiveIssues an MDM command asking a device to report its current system-updates statuses, refreshing what addigy_get_system_updates_status will return.
addigy_schedule_updates_for_devicesProDestructiveSends on-demand MDM system-update commands immediately to a specific list of devices, rather than waiting for the default daily 2AM UTC schedule.
addigy_schedule_updates_for_policyProDestructiveSends on-demand MDM system-update commands immediately to every device in a policy, rather than waiting for the default daily 2AM UTC schedule.
addigy_set_system_updates_settingsProDestructiveCreates or updates the system-updates settings for a policy, covering both MDM and Declarative Device Management (DDM) enforcement across macOS/iOS/iPadOS/tvOS, plus an optional send schedule.

[Addigy] Requests that an installed-system-updates report for a policy's devices be generated and emailed to a recipient. This is an asynchronous side-effecting action (it sends an email), not a synchronous data fetch — for inline data on one device use addigy_get_device_installed_updates_report. Body fields: `policy_id` (the Addigy policy whose devices to report on) and `email` (the recipient address). Requires API token permission: View System Updates Settings.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object for the request. Fields: email (recipient address), policy_id (the Addigy policy whose devices to report on).

[Addigy] Returns the OS software updates reported as available for a single device, each annotated with its current installation status (e.g. scheduled, downloading, installing, installed, failed). Combines the available-update list from addigy_list_available_system_updates with per-update progress. Requires the device's MDM UDID. Requires API token permission: View Device List, Execute Predefined Commands.

ParamTypeRequiredDefaultDescription
deviceUdidstringyesDevice UDID (the device's MDM UDID).

[Addigy] Returns the history of OS software updates already installed on a single device, as reported via MDM. Use this to audit patch level / confirm an update applied after scheduling it. Note: this endpoint keys off the device UUID (the Addigy device identifier), not the MDM UDID used by the request/status tools. For the same data across all devices in a policy delivered by email, use addigy_email_installed_updates_report. Requires API token permission: View System Updates Settings, View Device List.

ParamTypeRequiredDefaultDescription
deviceUuidstringyesDevice UUID (the Addigy device identifier).

[Addigy] Returns the configured system-updates settings for a policy — the per-OS (macOS/iOS/iPadOS/tvOS) update enforcement rules and the optional daily-send schedule. Use this to inspect current configuration before changing it with addigy_set_system_updates_settings. Requires the Addigy policy id. Requires API token permission: View System Updates Settings.

ParamTypeRequiredDefaultDescription
policyIdstringyesPolicy Id (the Addigy policy whose system-updates settings to fetch).

[Addigy] Returns the current system-updates statuses most recently reported for a single device (the live progress of in-flight OS updates). Reads the cached/last-reported statuses; to force the device to re-report, first call addigy_request_system_updates_status. Requires the device's MDM UDID. Requires API token permission: View Device List, Execute Predefined Commands.

ParamTypeRequiredDefaultDescription
deviceUdidstringyesDevice UDID (the device's MDM UDID).

[Addigy] Returns the OS software updates most recently reported as available for a single device. Reads the cached/last-reported list; to force the device to re-report, first call addigy_request_available_system_updates (or addigy_request_system_updates_scan). For each available update with its current install status, use addigy_get_available_system_updates_status instead. Requires the device's MDM UDID. Requires API token permission: View Device List.

ParamTypeRequiredDefaultDescription
deviceUdidstringyesDevice UDID (the device's MDM UDID).

[Addigy] Issues an MDM command asking a device to report the OS software updates it currently has available. This is a write/command action — it queues an MDM command rather than returning the cached list (use addigy_list_available_system_updates to read the previously-reported results, or addigy_get_available_system_updates_status to read results with their install statuses). Required body field: `device_udid` (the device's MDM UDID). Requires API token permission: View Device List, Execute Predefined Commands.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object for the request. Required: device_udid (the device's MDM UDID).

[Addigy] Issues an MDM command telling a device to scan for newly-available OS software updates, refreshing what addigy_list_available_system_updates / addigy_get_available_system_updates_status will return. Required body field: `device_udid` (the device's MDM UDID). Optional: `force` (boolean — bypass any cached scan result and force a fresh scan). Requires API token permission: View Device List, Execute Predefined Commands.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object for the request. Required: device_udid (the device's MDM UDID). Optional: force (boolean — force a fresh scan instead of returning a cached result).

[Addigy] Issues an MDM command scheduling a specific OS software update to install on a single device. Use this to push one known update (discovered via addigy_list_available_system_updates) with a chosen install behavior, rather than the bulk on-demand tools. Required body fields: `device_udid` (the device's MDM UDID), `product_key` (the update's product key from the available-updates list), and `install_action` (one of: Default, DownloadOnly, InstallASAP, NotifyOnly, InstallLater, InstallForceRestart). Optional: `product_version`, `description`. Requires API token permission: View Device List, Execute Predefined Commands.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object for the request. Required: device_udid (MDM UDID), product_key (the update product key from addigy_list_available_system_updates), install_action (Default|DownloadOnly|InstallASAP|NotifyOnly|InstallLater|InstallForceRestart). Optional: product_version, description.

[Addigy] Issues an MDM command asking a device to report its current system-updates statuses, refreshing what addigy_get_system_updates_status will return. This is a write/command action that queues an MDM command rather than returning the statuses inline. Required body field: `device_udid` (the device's MDM UDID). Requires API token permission: View Device List, Execute Predefined Commands.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object for the request. Required: device_udid (the device's MDM UDID).

[Addigy] Sends on-demand MDM system-update commands immediately to a specific list of devices, rather than waiting for the default daily 2AM UTC schedule. Body field: `device_uuids` (array of Addigy device UUIDs to update now). To target a whole policy instead, use addigy_schedule_updates_for_policy. Applies to MDM system updates only; the organization must have a monthly paid plan to use this feature. Requires API token permission: View System Updates Settings, Create System Updates Settings.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object for the request. Field: device_uuids (array of Addigy device UUIDs to send on-demand update commands to now).

[Addigy] Sends on-demand MDM system-update commands immediately to every device in a policy, rather than waiting for the default daily 2AM UTC schedule. Body field: `policy_id` (the Addigy policy whose devices to update now). To target a hand-picked device list instead, use addigy_schedule_updates_for_devices. Applies to MDM system updates only; the organization must have a monthly paid plan to use this feature. Requires API token permission: View System Updates Settings, Create System Updates Settings.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object for the request. Field: policy_id (the Addigy policy whose devices to send on-demand update commands to now).

[Addigy] Creates or updates the system-updates settings for a policy, covering both MDM and Declarative Device Management (DDM) enforcement across macOS/iOS/iPadOS/tvOS, plus an optional send schedule. MDM enforcement needs supervised devices on macOS 12+/iOS 9+/iPadOS 13+/tvOS 12+; DDM needs supervised macOS 14+/iOS 17+/iPadOS 17+. Body field `policy_id` selects the target policy; `macos_settings`/`ios_settings`/`ipados_settings`/`tvos_settings` carry the per-OS rules (e.g. keep_os_updated, install_action, max_user_deferrals, deferrals, automatic_actions, denied_period, allowed_days); `schedule` controls the optional non-default send window (set schedule.enabled=false to keep the daily 2AM UTC default; if enabled, all schedule fields are required and the org must have a monthly paid plan). Fetch the current shape with addigy_get_system_updates_settings first. Requires API token permission: Create System Updates Settings.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object with the full system-updates settings. Field policy_id selects the policy; macos_settings/ios_settings/ipados_settings/tvos_settings hold per-OS enforcement rules; schedule holds the optional send window (set schedule.enabled=false for the daily 2AM UTC default). Call addigy_get_system_updates_settings to see the exact current shape before editing.

Self Service

ToolPlanAccessSummary
addigy_create_self_service_configProWriteCreates a new Self Service configuration in the organization.
addigy_get_policy_self_service_configsFreeRead-onlyGet the Self Service configurations assigned by OS for a policy, aggregated across child organizations.
addigy_query_self_service_location_assetsFreeRead-onlyGets a list of available Self Service assets for the provided location IDs (token IDs), aggregated across child organizations.
addigy_update_self_service_configProWriteUpdates an existing Self Service configuration in the organization.

[Addigy] Creates a new Self Service configuration in the organization. Supply a JSON body describing the configuration — common fields include `name`, `label`, `description`, `os_type`, `display_mode`, `grace_period` (integer), home-screen branding (`home_screen_company_name`, `home_screen_email`, `home_screen_phone`, `home_screen_address`, `home_screen_description`, and their `home_screen_show_*` boolean toggles), prompt text fields (`maintenance_prompt_text`, `filevault_prompt_text`, `screenview_prompt_text`, `user_sentiment_prompt_text`, `ms_office_updates_prompt_text`), icon/logo file objects (`app_logo`, `dark_mode_app_logo`, `dock_icon`, `menubar_icon`), and behavior toggles (`show_support`, `hide_chat`, `restart_after_complete`, `show_complete_screen`, `beta_program_enabled`, `is_onboarding_config`, `policy_restricted`, `allow_location_tracking`, `integration_intune_enabled`, `instruction_id`). Use addigy_get_policy_self_service_configs to inspect existing assignments. Requires API token permission: Create Instruction.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object describing the Self Service configuration to create. Common fields: name, label, description, os_type, display_mode, grace_period (integer), home_screen_* branding, *_prompt_text strings, app_logo/dock_icon/menubar_icon file objects, and boolean toggles (show_support, hide_chat, restart_after_complete, beta_program_enabled, is_onboarding_config, etc.).

[Addigy] Get the Self Service configurations assigned by OS for a policy, aggregated across child organizations. Requires policyId. Returns the per-OS Self Service configuration assignments for that policy. Spans child organizations when multitenancy=true; use childOrganizations to target specific child org IDs.

ParamTypeRequiredDefaultDescription
childOrganizationsstringnonullComma-separated list of child organization IDs to scope the aggregation to. Omit to span all child organizations.
multitenancybooleannonullWhen true, aggregate results across the API key's child organizations. Omit for the key's own organization only.
policyIdstringyesPolicy id whose assigned Self Service configurations to retrieve.

[Addigy] Gets a list of available Self Service assets for the provided location IDs (token IDs), aggregated across child organizations. Supply a JSON body to scope the query — example fields: `location_ids` (array of location/token ID strings), `policy_ids` (array of policy ID strings — discover policy IDs via addigy_get_policy_self_service_configs and related policy tools), `device_family` (string), `is_onboarding` (boolean). Spans child organizations when multitenancy=true; use childOrganizations to target specific child org IDs.

ParamTypeRequiredDefaultDescription
childOrganizationsstringnonullComma-separated list of child organization IDs to scope the aggregation to. Omit to span all child organizations.
fieldsJsonstringyesJSON body scoping the asset query. Fields: location_ids (array of strings), policy_ids (array of strings), device_family (string), is_onboarding (boolean). All optional; pass an empty object for an unscoped query.
multitenancybooleannonullWhen true, aggregate results across the API key's child organizations. Omit for the key's own organization only.

[Addigy] Updates an existing Self Service configuration in the organization. Supply a JSON body with the updated configuration — same field set as addigy_create_self_service_config, including the target configuration's `instruction_id`. Common fields: `name`, `label`, `description`, `os_type`, `display_mode`, `grace_period` (integer), home-screen branding (`home_screen_`), prompt text fields (`_prompt_text`), icon/logo file objects (`app_logo`, `dark_mode_app_logo`, `dock_icon`, `menubar_icon`), and behavior toggles (`show_support`, `hide_chat`, `restart_after_complete`, `beta_program_enabled`, `is_onboarding_config`, etc.). Requires API token permission: Create Instruction.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object with the updated Self Service configuration. Include instruction_id identifying the configuration to update. Same field set as create: name, label, description, os_type, display_mode, grace_period, home_screen_* branding, *_prompt_text strings, icon/logo file objects, and boolean toggles.

Compliance & Benchmarks

ToolPlanAccessSummary
addigy_assign_benchmark_to_policyProDestructiveAssign a benchmark to a policy so the policy's devices are scored against it.
addigy_create_benchmarkProWriteCreate a new benchmark asset (a named OS-version + compliance-rule set used for device compliance scoring).
addigy_create_compliance_ruleProWriteCreate a compliance rule (an audit filter set, optionally with an auto-remediation script, that benchmarks reference for device compliance scoring).
addigy_delete_benchmarkProDestructiveDelete a benchmark asset by id.
addigy_delete_compliance_ruleProDestructiveDelete a compliance rule by id.
addigy_get_azure_ca_tenants_metadataFreeRead-onlyGet metadata for the unique, enabled Azure Conditional Access tenants.
addigy_get_compliance_rule_usageFreeRead-onlyGet usage details for a single compliance rule — which benchmarks reference it.
addigy_list_compliance_rules_using_scriptFreeRead-onlyList the compliance rules that reference a given remediation script.
addigy_query_azure_ca_account_statusFreeRead-onlyGet Azure Conditional Access status for accounts tied to the given policy ids.
addigy_query_azure_ca_accounts_metadataFreeRead-onlyGet Azure Conditional Access metadata for all accounts tied to the given policy ids.
addigy_query_benchmarksFreeRead-onlySearch/list benchmark assets for an organization.
addigy_query_compliance_rulesFreeRead-onlySearch/list compliance rules for an organization.
addigy_unassign_benchmark_from_policyProDestructiveRemove a benchmark from a policy so the policy's devices are no longer scored against it.
addigy_update_benchmarkProWriteUpdate an existing benchmark asset (the named OS-version + compliance-rule set used for device compliance scoring).
addigy_update_compliance_ruleProWriteUpdate an existing compliance rule.

[Addigy] Assign a benchmark to a policy so the policy's devices are scored against it. Body properties: policy_id, benchmark_id. Discover benchmark ids with addigy_query_benchmarks and policy ids via the Addigy policy tools. Requires organizationId from addigy_list_child_organizations. Requires API token permission: Edit Policy Benchmarks.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object linking a benchmark to a policy. Properties: policy_id, benchmark_id.
organizationIdstringyesOrganization id (from addigy_list_child_organizations).

[Addigy] Create a new benchmark asset (a named OS-version + compliance-rule set used for device compliance scoring). Returns the created benchmark including its id. Body properties: name, target_os, minimum_os_version, maximum_os_version, compliance_rules_ids (array of compliance-rule ids from addigy_query_compliance_rules). Requires organizationId from addigy_list_child_organizations. Requires API token permission: Create Benchmark.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object describing the new benchmark. Properties: name, target_os, minimum_os_version, maximum_os_version, compliance_rules_ids (array of strings).
organizationIdstringyesOrganization id (from addigy_list_child_organizations).

[Addigy] Create a compliance rule (an audit filter set, optionally with an auto-remediation script, that benchmarks reference for device compliance scoring). Returns the created rule including its id. Body properties: name, description, filter_sets (array of arrays of AuditFilter objects), remediation_enabled (boolean), agent_remediation_script_id (the script to run when non-compliant). Requires organizationId from addigy_list_child_organizations. Requires API token permission: Create Benchmark.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object describing the new compliance rule. Properties: name, description, filter_sets (array of arrays of AuditFilter), remediation_enabled (boolean), agent_remediation_script_id (string).
organizationIdstringyesOrganization id (from addigy_list_child_organizations).

[Addigy] Delete a benchmark asset by id. Discover benchmark ids with addigy_query_benchmarks. Requires organizationId from addigy_list_child_organizations. Requires API token permission: Delete Benchmark.

ParamTypeRequiredDefaultDescription
idstringyesBenchmark id to delete (from addigy_query_benchmarks).
organizationIdstringyesOrganization id (from addigy_list_child_organizations).

[Addigy] Delete a compliance rule by id. Check whether a rule is still in use first with addigy_get_compliance_rule_usage. Discover compliance-rule ids with addigy_query_compliance_rules. Requires organizationId from addigy_list_child_organizations. Requires API token permission: Delete Benchmark.

ParamTypeRequiredDefaultDescription
idstringyesCompliance rule id to delete (from addigy_query_compliance_rules).
organizationIdstringyesOrganization id (from addigy_list_child_organizations).

[Addigy] Get metadata for the unique, enabled Azure Conditional Access tenants. Returns an array of account-metadata objects (one per distinct tenant). Use this to discover the policy ids and tenants to feed into addigy_query_azure_ca_accounts_metadata and addigy_query_azure_ca_account_status. Spans child organizations when multitenancy=true.

ParamTypeRequiredDefaultDescription
childOrganizationsstringnonullComma-separated list of child organization ids to scope the aggregate query. Used with multitenancy=true.
multitenancybooleannonullSet true to aggregate across child organizations (/oa/ scope). Omit for the API key's own organization.

[Addigy] Get usage details for a single compliance rule — which benchmarks reference it. Use this before deleting a rule with addigy_delete_compliance_rule to confirm nothing depends on it. Discover compliance-rule ids with addigy_query_compliance_rules. Spans child organizations when multitenancy=true. Requires API token permission: View Benchmarks.

ParamTypeRequiredDefaultDescription
childOrganizationsstringnonullComma-separated list of child organization ids to scope the aggregate query. Used with multitenancy=true.
idstringyesCompliance rule id (from addigy_query_compliance_rules).
multitenancybooleannonullSet true to aggregate across child organizations (/oa/ scope). Omit for the API key's own organization.

[Addigy] List the compliance rules that reference a given remediation script. Use this before deleting or editing a script to see which compliance rules depend on it. Discover script ids via the Addigy scripts/maintenance tools. Requires organizationId from addigy_list_child_organizations. Requires API token permission: View Benchmarks.

ParamTypeRequiredDefaultDescription
agentRemediationScriptIdstringyesRemediation script id. Returns every compliance rule whose agent_remediation_script_id matches this value.
organizationIdstringyesOrganization id (from addigy_list_child_organizations).

[Addigy] Get Azure Conditional Access status for accounts tied to the given policy ids. If a global account exists, its status is always returned. Body property: policy_ids (array of strings). Spans child organizations when multitenancy=true.

ParamTypeRequiredDefaultDescription
childOrganizationsstringnonullComma-separated list of child organization ids to scope the aggregate query. Used with multitenancy=true.
fieldsJsonstringyesJSON object with the policy ids to look up. Property: policy_ids (array of strings).
multitenancybooleannonullSet true to aggregate across child organizations (/oa/ scope). Omit for the API key's own organization.

[Addigy] Get Azure Conditional Access metadata for all accounts tied to the given policy ids. Body property: policy_ids (array of strings). Discover Azure CA tenant metadata with addigy_get_azure_ca_tenants_metadata. Spans child organizations when multitenancy=true.

ParamTypeRequiredDefaultDescription
childOrganizationsstringnonullComma-separated list of child organization ids to scope the aggregate query. Used with multitenancy=true.
fieldsJsonstringyesJSON object with the policy ids to look up. Property: policy_ids (array of strings).
multitenancybooleannonullSet true to aggregate across child organizations (/oa/ scope). Omit for the API key's own organization.

[Addigy] Search/list benchmark assets for an organization. This is the primary discovery tool for benchmark ids used by addigy_update_benchmark, addigy_delete_benchmark, and addigy_assign_benchmark_to_policy. Optional query filter (queryJson) supports name_contains, ids (array), and excluded_ids (array). Paginated; response metadata carries page/page_count/per_page/total. Spans child organizations when multitenancy=true. Requires API token permission: View Benchmarks.

ParamTypeRequiredDefaultDescription
childOrganizationsstringnonullComma-separated list of child organization ids to scope the aggregate query. Used with multitenancy=true.
multitenancybooleannonullSet true to aggregate across child organizations (/oa/ scope). Omit for the API key's own organization.
pageintegerno1Page number (default 1).
perPageintegerno50Results per page (default 50, max 500).
queryJsonstringnonullOptional JSON filter object. Supported properties: name_contains (string), ids (array of strings), excluded_ids (array of strings). Omit to return all benchmarks.
sortDirectionstringnonullSort direction: asc|desc. Omit for default order.
sortFieldstringnonullField to sort by, e.g. "name". Omit for default order.

[Addigy] Search/list compliance rules for an organization. This is the primary discovery tool for compliance-rule ids used by addigy_create_benchmark, addigy_update_benchmark, addigy_update_compliance_rule, and addigy_delete_compliance_rule. Optional query filter (queryJson) supports name_contains, ids (array), and excluded_ids (array). Paginated; response metadata carries page/page_count/per_page/total. Spans child organizations when multitenancy=true. Requires API token permission: View Benchmarks.

ParamTypeRequiredDefaultDescription
childOrganizationsstringnonullComma-separated list of child organization ids to scope the aggregate query. Used with multitenancy=true.
multitenancybooleannonullSet true to aggregate across child organizations (/oa/ scope). Omit for the API key's own organization.
pageintegerno1Page number (default 1).
perPageintegerno50Results per page (default 50, max 500).
queryJsonstringnonullOptional JSON filter object. Supported properties: name_contains (string), ids (array of strings), excluded_ids (array of strings). Omit to return all compliance rules.
sortDirectionstringnonullSort direction: asc|desc. Omit for default order.
sortFieldstringnonullField to sort by, e.g. "name". Omit for default order.

[Addigy] Remove a benchmark from a policy so the policy's devices are no longer scored against it. Discover benchmark ids with addigy_query_benchmarks and policy ids via the Addigy policy tools. Requires organizationId from addigy_list_child_organizations. Requires API token permission: Edit Policy Benchmarks.

ParamTypeRequiredDefaultDescription
benchmarkIdstringyesBenchmark id to unassign (from addigy_query_benchmarks).
organizationIdstringyesOrganization id (from addigy_list_child_organizations).
policyIdstringyesPolicy id the benchmark is currently assigned to.

[Addigy] Update an existing benchmark asset (the named OS-version + compliance-rule set used for device compliance scoring). Pass the full benchmark object — the body's `id` field identifies which benchmark to update. Body properties: id (required, the benchmark id from addigy_query_benchmarks), name, target_os, minimum_os_version, maximum_os_version, compliance_rules_ids (array of compliance-rule ids from addigy_query_compliance_rules). Requires organizationId from addigy_list_child_organizations. Requires API token permission: Edit Benchmark.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object describing the benchmark to update. Required: id. Optional: name, target_os, minimum_os_version, maximum_os_version, compliance_rules_ids (array of strings).
organizationIdstringyesOrganization id (from addigy_list_child_organizations).

[Addigy] Update an existing compliance rule. The body's `id` field identifies which rule to update. Body properties: id (required, from addigy_query_compliance_rules), name, description, filter_sets (array of arrays of AuditFilter objects), remediation_enabled (boolean), agent_remediation_script_id. Requires organizationId from addigy_list_child_organizations. Requires API token permission: Edit Benchmark.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object describing the compliance rule to update. Required: id. Optional: name, description, filter_sets (array of arrays of AuditFilter), remediation_enabled (boolean), agent_remediation_script_id (string).
organizationIdstringyesOrganization id (from addigy_list_child_organizations).

Integrations

ToolPlanAccessSummary
addigy_assign_mbov_site_to_policyProDestructiveAssigns a MalwareBytes OneView (MBOV) site to a policy.
addigy_close_device_ticketProDestructiveCloses a single device ticket.
addigy_create_ticket_noteProWriteAdds an organization note to a ticket.
addigy_disable_mbov_integrationProDestructiveDisables the MalwareBytes OneView (MBOV) integration for an organization.
addigy_enable_mbov_integrationProWriteEnables the MalwareBytes OneView (MBOV) integration for an organization, creating a new MBOV account.
addigy_get_autotask_accountFreeRead-onlyRetrieves a single Autotask PSA account (company) by its account_id.
addigy_get_connectwise_accountFreeRead-onlyRetrieves a single ConnectWise PSA account (company) by its account_id.
addigy_get_mbov_account_statusFreeRead-onlyReturns the MalwareBytes OneView (MBOV) account status for an organization (whether the integration is enabled and its provisioning state).
addigy_get_mbov_account_usageFreeRead-onlyReturns MalwareBytes OneView (MBOV) catalog-code usage for an organization across a date window.
addigy_list_autotask_accountsFreeRead-onlyLists the Autotask PSA accounts (companies) available to the Autotask integration for an organization.
addigy_list_connectwise_accountsFreeRead-onlyLists the ConnectWise PSA accounts (companies) available to the ConnectWise integration for an organization.
addigy_list_device_ticketsFreeRead-onlyLists all support tickets attached to a single device within an organization.
addigy_list_mbov_policy_sitesFreeRead-onlyLists the MalwareBytes OneView (MBOV) sites assigned to a specific policy.
addigy_list_mbov_sitesFreeRead-onlyLists the MalwareBytes OneView (MBOV) sites available to an organization's MBOV account.
addigy_list_ticket_notesFreeRead-onlyLists the notes (conversation entries) on a ticket.
addigy_sync_autotask_policy_devicesProDestructiveTriggers a sync of a policy's devices with their mapped Autotask configurations.
addigy_sync_connectwise_policy_devicesProDestructiveTriggers a sync of a policy's devices with their mapped ConnectWise configurations.
addigy_unassign_mbov_site_from_policyProDestructiveRemoves a MalwareBytes OneView (MBOV) site from a policy.

[Addigy] Assigns a MalwareBytes OneView (MBOV) site to a policy. Optional body fields: mbov_site_id (discover via addigy_list_mbov_sites), policy_id (the Addigy policy identifier). Requires the organizationId (discover via addigy_list_child_organizations). Use addigy_list_mbov_policy_sites to verify the assignment and addigy_unassign_mbov_site_from_policy to reverse it.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object describing the assignment. Optional: mbov_site_id (discover via addigy_list_mbov_sites), policy_id (string).
organizationIdstringyesThe organization id. Discover via addigy_list_child_organizations.

[Addigy] Closes a single device ticket. Idempotent — closing an already-closed ticket is a no-op. Requires the organizationId (discover via addigy_list_child_organizations), the device agent_id, and the ticket_id (discover via addigy_list_device_tickets). Requires API token permission: Edit Tickets.

ParamTypeRequiredDefaultDescription
agentIdstringyesAgent id — the device's Addigy agent identifier.
organizationIdstringyesOrganization id. Discover via addigy_list_child_organizations.
ticketIdstringyesTicket id. Discover via addigy_list_device_tickets.

[Addigy] Adds an organization note to a ticket. Returns the created TicketNote. Required body field: `message` (string). Requires the organizationId (discover via addigy_list_child_organizations) and the ticket_id (discover via addigy_list_device_tickets). Use addigy_list_ticket_notes to read existing notes.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object for the note. Required: message (string).
organizationIdstringyesOrganization id. Discover via addigy_list_child_organizations.
ticketIdstringyesTicket id. Discover via addigy_list_device_tickets.

[Addigy] Disables the MalwareBytes OneView (MBOV) integration for an organization. Destructive — tears down the MBOV account linkage. Requires the organizationId (discover via addigy_list_child_organizations). Use addigy_enable_mbov_integration to re-enable.

ParamTypeRequiredDefaultDescription
organizationIdstringyesThe organization id. Discover via addigy_list_child_organizations.

[Addigy] Enables the MalwareBytes OneView (MBOV) integration for an organization, creating a new MBOV account. Returns the resulting AccountStatus. Optional body fields: email, billing_street, billing_city, billing_state, billing_zip_code, billing_country (all strings). Requires the organizationId (discover via addigy_list_child_organizations). Use addigy_get_mbov_account_status to check the resulting account state and addigy_disable_mbov_integration to reverse this.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object with MBOV enrollment details. Optional: email, billing_street, billing_city, billing_state, billing_zip_code, billing_country (all strings).
organizationIdstringyesThe organization id. Discover via addigy_list_child_organizations.

[Addigy] Retrieves a single Autotask PSA account (company) by its account_id. Returns the Account object. Requires the organizationId (discover via addigy_list_child_organizations) and the account_id (discover via addigy_list_autotask_accounts).

ParamTypeRequiredDefaultDescription
accountIdstringyesAccount id. Discover via addigy_list_autotask_accounts.
organizationIdstringyesOrganization id. Discover via addigy_list_child_organizations.

[Addigy] Retrieves a single ConnectWise PSA account (company) by its account_id. Returns the Account object. Requires the organizationId (discover via addigy_list_child_organizations) and the account_id (discover via addigy_list_connectwise_accounts).

ParamTypeRequiredDefaultDescription
accountIdstringyesAccount id. Discover via addigy_list_connectwise_accounts.
organizationIdstringyesOrganization id. Discover via addigy_list_child_organizations.

[Addigy] Returns the MalwareBytes OneView (MBOV) account status for an organization (whether the integration is enabled and its provisioning state). Requires the organizationId (discover via addigy_list_child_organizations). Use addigy_get_mbov_account_usage for catalog-code usage figures.

ParamTypeRequiredDefaultDescription
organizationIdstringyesThe organization id. Discover via addigy_list_child_organizations.

[Addigy] Returns MalwareBytes OneView (MBOV) catalog-code usage for an organization across a date window. Both start_date and end_date are required in YYYY-MM-DD format (passed through verbatim). Requires the organizationId (discover via addigy_list_child_organizations). Use addigy_get_mbov_account_status for the integration's enabled/provisioning state.

ParamTypeRequiredDefaultDescription
endDatestringyesEnd date in the format YYYY-MM-DD.
organizationIdstringyesThe organization id. Discover via addigy_list_child_organizations.
startDatestringyesStart date in the format YYYY-MM-DD.

[Addigy] Lists the Autotask PSA accounts (companies) available to the Autotask integration for an organization. Returns an array of Account objects. Optionally narrow results with a free-text search phrase. Requires the organizationId (discover via addigy_list_child_organizations). Use addigy_get_autotask_account for a single account's detail.

ParamTypeRequiredDefaultDescription
organizationIdstringyesOrganization id. Discover via addigy_list_child_organizations.
phrasestringnonullSearch phrase for account. Omit to return all accounts.

[Addigy] Lists the ConnectWise PSA accounts (companies) available to the ConnectWise integration for an organization. Returns an array of Account objects. Optionally narrow results with a free-text search phrase. Requires the organizationId (discover via addigy_list_child_organizations). Use addigy_get_connectwise_account for a single account's detail.

ParamTypeRequiredDefaultDescription
organizationIdstringyesOrganization id. Discover via addigy_list_child_organizations.
phrasestringnonullSearch phrase for account. Omit to return all accounts.

[Addigy] Lists all support tickets attached to a single device within an organization. Returns an array of Ticket objects (id, status, subject, timestamps). Requires the organizationId (discover via addigy_list_child_organizations) and the device agent_id (the device's Addigy agent identifier, discoverable via the device-listing tools). Use addigy_list_ticket_notes to read a ticket's conversation and addigy_close_device_ticket to close one.

ParamTypeRequiredDefaultDescription
agentIdstringyesAgent id — the device's Addigy agent identifier.
organizationIdstringyesOrganization id. Discover via addigy_list_child_organizations.

[Addigy] Lists the MalwareBytes OneView (MBOV) sites assigned to a specific policy. Returns an array of Site objects. Requires the organizationId (discover via addigy_list_child_organizations) and the policy_id (the Addigy policy identifier). Use addigy_list_mbov_sites for the full site catalog and addigy_assign_mbov_site_to_policy / addigy_unassign_mbov_site_from_policy to change assignments.

ParamTypeRequiredDefaultDescription
organizationIdstringyesThe organization id. Discover via addigy_list_child_organizations.
policyIdstringyesThe policy id — the Addigy policy identifier.

[Addigy] Lists the MalwareBytes OneView (MBOV) sites available to an organization's MBOV account. Returns an array of Site objects. Requires the organizationId (discover via addigy_list_child_organizations). Use addigy_list_mbov_policy_sites to see which sites are assigned to a specific policy and addigy_assign_mbov_site_to_policy to assign one.

ParamTypeRequiredDefaultDescription
organizationIdstringyesThe organization id. Discover via addigy_list_child_organizations.

[Addigy] Lists the notes (conversation entries) on a ticket. Returns an array of TicketNote objects. The required include_internal flag controls whether internal-only notes are returned (true) or only customer-visible notes (false). Requires the organizationId (discover via addigy_list_child_organizations) and the ticket_id (discover via addigy_list_device_tickets). Use addigy_create_ticket_note to add an organization note.

ParamTypeRequiredDefaultDescription
includeInternalbooleanyesInclude internal notes. true returns internal-only notes alongside customer-visible ones; false returns only customer-visible notes.
organizationIdstringyesOrganization id. Discover via addigy_list_child_organizations.
ticketIdstringyesTicket id. Discover via addigy_list_device_tickets.

[Addigy] Triggers a sync of a policy's devices with their mapped Autotask configurations. Required body field: `policy_id` (string). Requires the organizationId (discover via addigy_list_child_organizations). Requires API token permission: Edit Integration.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object for the Autotask sync request. Required: policy_id (string).
organizationIdstringyesOrganization id. Discover via addigy_list_child_organizations.

[Addigy] Triggers a sync of a policy's devices with their mapped ConnectWise configurations. Required body field: `policy_id` (string). Requires the organizationId (discover via addigy_list_child_organizations). Requires API token permission: Edit Integration.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object for the ConnectWise sync request. Required: policy_id (string).
organizationIdstringyesOrganization id. Discover via addigy_list_child_organizations.

[Addigy] Removes a MalwareBytes OneView (MBOV) site from a policy. Destructive — unlinks the site from the policy. Requires the organizationId (discover via addigy_list_child_organizations) and the policy_id. Use addigy_assign_mbov_site_to_policy to re-assign and addigy_list_mbov_policy_sites to inspect current assignments.

ParamTypeRequiredDefaultDescription
organizationIdstringyesThe organization id. Discover via addigy_list_child_organizations.
policyIdstringyesThe policy id — the Addigy policy identifier.

Variables & Static Fields

ToolPlanAccessSummary
addigy_assign_static_field_to_devicesProWriteAssign a static field value to one or more devices.
addigy_assign_variable_policy_valueProDestructiveAssign a policy-specific override value to a variable, so devices in that policy resolve the variable to this value instead of the organization default.
addigy_create_static_fieldsProWriteCreate a new static field for the organization.
addigy_create_variableProWriteCreate a new organization variable.
addigy_delete_static_fieldProDestructiveRemove a static field from the organization by its id.
addigy_delete_variableProDestructiveDelete an organization variable by its key.
addigy_get_variable_policy_valueFreeRead-onlyList policy-level override values for variables in an organization.
addigy_get_variable_usageFreeRead-onlyList where a variable is referenced across the organization (the assets/objects that consume it).
addigy_get_variable_valueFreeRead-onlyResolve a variable's organization-default value (ignoring any policy overrides).
addigy_get_variable_value_by_policyFreeRead-onlyResolve a single variable's value as it applies within a specific policy (returns the policy override if one exists, otherwise the organization default).
addigy_list_device_static_field_valuesFreeRead-onlyList static field values assigned to devices across the organization (each record pairs a device/agent with a static field and its value).
addigy_list_static_fieldsFreeRead-onlyList all static fields defined for the organization (each with its id and name).
addigy_query_variablesFreeRead-onlySearch/list organization variables.
addigy_unassign_variable_policy_valueProDestructiveRemove a policy-level override value from a variable, reverting that policy to the variable's organization default.
addigy_update_static_fieldProWriteUpdate (rename) an existing static field for the organization.
addigy_update_variableProWriteUpdate an existing organization variable's default value.

[Addigy] Assign a static field value to one or more devices. Required body fields: `static_field_id` (from addigy_list_static_fields), `agent_ids` (array of device/agent ids), and `value` (the value to set on those devices). Example: {"static_field_id":"sf_123","agent_ids":["agent1","agent2"],"value":"Floor 3"}. Verify assignments afterward with addigy_list_device_static_field_values. Requires API token permission: View Devices.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object for the assignment. Required: static_field_id, agent_ids (array of strings), value.

[Addigy] Assign a policy-specific override value to a variable, so devices in that policy resolve the variable to this value instead of the organization default. Required body fields: `policy_id`, `variable_key`, and `value` (the override). Example: {"policy_id":"abc123","variable_key":"company_name","value":"Acme West"}. Requires organizationId from addigy_list_child_organizations; discover policies with addigy_list_policies and keys with addigy_query_variables. Requires API token permission: Edit Policy.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object for the policy override. Required: policy_id, variable_key, value.
organizationIdstringyesOrganization id. Obtain from addigy_list_child_organizations.

[Addigy] Create a new static field for the organization. Required body field: `name` (the field name). Example: {"name":"Asset Tag"}. Returns the created field id, which you then assign to devices via addigy_assign_static_field_to_devices. List existing fields with addigy_list_static_fields. Requires API token permission: View Devices.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object for the new static field. Required: name.

[Addigy] Create a new organization variable. Required body fields: `key` (variable name) and `type` ("string" or "secret"; secret values are masked). Optional: `default_value` (organization-wide default). Example: {"key":"api_endpoint","type":"string","default_value":"https://example.com"}. Requires organizationId from addigy_list_child_organizations. Returns the created variable. Requires API token permission: Create Variable.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object for the new variable. Required: key, type (string|secret). Optional: default_value.
organizationIdstringyesOrganization id. Obtain from addigy_list_child_organizations.

[Addigy] Remove a static field from the organization by its id. Permanently deletes the field and its per-device values. Required: `id` (from addigy_list_static_fields). Requires API token permission: View Devices.

ParamTypeRequiredDefaultDescription
idstringyesStatic field id to delete. Obtain from addigy_list_static_fields.

[Addigy] Delete an organization variable by its key. Permanently removes the variable and any policy-level overrides assigned to it (discover overrides first with addigy_get_variable_policy_value). Requires organizationId from addigy_list_child_organizations and the variable `key` from addigy_query_variables. Requires API token permission: Delete Variable.

ParamTypeRequiredDefaultDescription
keystringyesVariable key to delete.
organizationIdstringyesOrganization id. Obtain from addigy_list_child_organizations.

[Addigy] List policy-level override values for variables in an organization. Returns an array of variable-policy associations (each with policy id, variable key, and the override value). Requires organizationId from addigy_list_child_organizations. Optionally filter by `policyId` (from addigy_list_policies) and/or `variableKey` (from addigy_query_variables); omit both to list all overrides. To read a single resolved value use addigy_get_variable_value_by_policy. Requires API token permission: Edit Policy.

ParamTypeRequiredDefaultDescription
organizationIdstringyesOrganization id. Obtain from addigy_list_child_organizations.
policyIdstringnonullOptional policy id to filter overrides. Omit for all policies.
variableKeystringnonullOptional variable key to filter overrides. Omit for all variables.

[Addigy] List where a variable is referenced across the organization (the assets/objects that consume it). Returns an array of usage records for the given variable key. Required: `variableKey` (from addigy_query_variables) and organizationId from addigy_list_child_organizations. Useful before addigy_delete_variable to assess impact. Requires API token permission: View Variable.

ParamTypeRequiredDefaultDescription
organizationIdstringyesOrganization id. Obtain from addigy_list_child_organizations.
variableKeystringyesVariable key to look up usage for.

[Addigy] Resolve a variable's organization-default value (ignoring any policy overrides). Required: `variableKey` (from addigy_query_variables) and organizationId from addigy_list_child_organizations. For the policy-scoped value use addigy_get_variable_value_by_policy. Requires API token permission: View Variable.

ParamTypeRequiredDefaultDescription
organizationIdstringyesOrganization id. Obtain from addigy_list_child_organizations.
variableKeystringyesVariable key to resolve.

[Addigy] Resolve a single variable's value as it applies within a specific policy (returns the policy override if one exists, otherwise the organization default). Required: `variableKey` (from addigy_query_variables), `policyId` (from addigy_list_policies), and organizationId from addigy_list_child_organizations. For the organization-default value (ignoring policy) use addigy_get_variable_value. Requires API token permission: View Variable.

ParamTypeRequiredDefaultDescription
organizationIdstringyesOrganization id. Obtain from addigy_list_child_organizations.
policyIdstringyesPolicy id within which to resolve the value.
variableKeystringyesVariable key to resolve.

[Addigy] List static field values assigned to devices across the organization (each record pairs a device/agent with a static field and its value). Paginated; response metadata has page_count/total. Discover field ids with addigy_list_static_fields; assign new values with addigy_assign_static_field_to_devices. Requires API token permission: View Devices.

ParamTypeRequiredDefaultDescription
pageintegerno1Page number (default 1).
perPageintegerno50Number of items in the response (default 50, max 500).

[Addigy] List all static fields defined for the organization (each with its id and name). Paginated; response metadata has page_count/total. Use the returned field id with addigy_assign_static_field_to_devices, addigy_update_static_field, or addigy_delete_static_field. To see which devices have values assigned, use addigy_list_device_static_field_values. Requires API token permission: View Devices.

ParamTypeRequiredDefaultDescription
pageintegerno1Page number (default 1).
perPageintegerno50Number of items in the response (default 50, max 500).

[Addigy] Search/list organization variables. POST-based query: optionally filter via queryJson with `keys` (array of exact keys) and/or `key_contains` (substring), e.g. {"key_contains":"company"}. Paginated; response metadata has page_count/total. Sort with sortField/sortDirection. Spans child organizations when multitenancy=true (use childOrganizations to scope to specific child org ids). This is the discovery tool for variable keys consumed by addigy_get_variable_value, addigy_update_variable, and addigy_delete_variable. Requires API token permission: View Variables.

ParamTypeRequiredDefaultDescription
childOrganizationsstringnonullComma-separated list of child organization ids to scope the aggregation. Omit for all.
multitenancybooleannonullWhen true, aggregates variables across child organizations.
pageintegerno1Page number (default 1).
perPageintegerno50Results per page (default 50, max 100 — Addigy documents a 100 cap on this endpoint).
queryJsonstringnonullOptional JSON filter object. Supports: keys (array of strings), key_contains (string). Omit to list all variables.
sortDirectionstringnonullOptional sort direction.
sortFieldstringnonullOptional field to sort by.

[Addigy] Remove a policy-level override value from a variable, reverting that policy to the variable's organization default. Requires organizationId from addigy_list_child_organizations, `policyId` (from addigy_list_policies), and `variableKey` (from addigy_query_variables). Inspect current overrides first with addigy_get_variable_policy_value. Requires API token permission: Edit Policy.

ParamTypeRequiredDefaultDescription
organizationIdstringyesOrganization id. Obtain from addigy_list_child_organizations.
policyIdstringyesPolicy id whose override should be removed.
variableKeystringyesVariable key to unassign from the policy.

[Addigy] Update (rename) an existing static field for the organization. Required body fields: `id` (static field id from addigy_list_static_fields) and `name` (the new field name). Example: {"id":"sf_123","name":"Asset Tag"}. Static fields are custom name/value attributes you can assign to devices via addigy_assign_static_field_to_devices. Requires API token permission: View Devices.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object for the static field update. Required: id, name.

[Addigy] Update an existing organization variable's default value. Required body field: `key` (the variable to update). Optional: `default_value` (the new organization-wide default). Example: {"key":"company_name","default_value":"Acme Inc"}. Requires organizationId from addigy_list_child_organizations; discover keys with addigy_query_variables. Returns the updated variable. Requires API token permission: Edit Variable.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object for the variable update. Required: key. Optional: default_value.
organizationIdstringyesOrganization id. Obtain from addigy_list_child_organizations.

Files, Exports & Reports

ToolPlanAccessSummary
addigy_delete_fileProDestructiveDelete a file from an organization, identified by its file_id.
addigy_download_export_sourceFreeRead-onlyExport the raw data of a source over a date range.
addigy_get_file_metadataFreeRead-onlyGet an organization file's metadata by its id — name, md5_hash, size, upload date, and related fields.
addigy_get_reportFreeRead-onlyGet a generated report by its report_id.
addigy_list_available_reportsFreeRead-onlyGet the list of reports available to be requested.
addigy_list_export_sourcesFreeRead-onlyList the data sources available to be exported.
addigy_query_filesFreeRead-onlyGet a paginated list of organization files.
addigy_query_report_statusesFreeRead-onlyGet the status of one or more reports.
addigy_request_reportProWriteRequest a report be generated for an organization.

[Addigy] Delete a file from an organization, identified by its file_id. Requires organizationId (from addigy_list_child_organizations, or the org's own id) and the fileId — discover file ids with addigy_query_files or addigy_get_file_metadata. This permanently removes the file. Requires API token permission: Delete Files.

ParamTypeRequiredDefaultDescription
fileIdstringyesFile id to delete. Discover with addigy_query_files or addigy_get_file_metadata.
organizationIdstringyesOrganization id — from addigy_list_child_organizations.

[Addigy] Export the raw data of a source over a date range. These sources often contain a daily snapshot of data for every day between date_start and date_end. Discover sourceId with addigy_list_export_sources. This endpoint is not paginated and can return a large amount of data — keep the date range narrow for best results. dateStart/dateEnd must be formatted as YYYY-MM-DD (e.g. 2024-12-01). Spans child organizations when multitenancy=true. Requires API token permission: Export Report Data.

ParamTypeRequiredDefaultDescription
childOrganizationsstringnonullComma-separated list of child organization ids to scope the aggregation to.
dateEndstringyesLast date to get data from. Must be formatted as YYYY-MM-DD, for example 2024-12-01 for December 1st, 2024.
dateStartstringyesFirst date to get data from. Must be formatted as YYYY-MM-DD, for example 2024-12-01 for December 1st, 2024.
multitenancybooleannonullWhen true, aggregate results across child organizations (/oa/ scope).
policyIdsstringnonullOptional comma-separated list of policy ids to filter the data by.
sourceIdstringyesThe ID of the source to get the data from. Find it in the response of addigy_list_export_sources.

[Addigy] Get an organization file's metadata by its id — name, md5_hash, size, upload date, and related fields. Discover file ids with addigy_query_files. Spans child organizations when multitenancy=true. Requires API token permission: View Files.

ParamTypeRequiredDefaultDescription
childOrganizationsstringnonullComma-separated list of child organization ids to scope the aggregation to.
fileIdstringyesFile id to fetch metadata for. Discover with addigy_query_files.
multitenancybooleannonullWhen true, aggregate results across child organizations (/oa/ scope).

[Addigy] Get a generated report by its report_id. Discover report ids from the response of addigy_request_report or by checking addigy_query_report_statuses. Spans child organizations when multitenancy=true.

ParamTypeRequiredDefaultDescription
childOrganizationsstringnonullComma-separated list of child organization ids to scope the aggregation to.
multitenancybooleannonullWhen true, aggregate results across child organizations (/oa/ scope).
reportIdstringyesReport id to fetch — from addigy_request_report or addigy_query_report_statuses.

[Addigy] Get the list of reports available to be requested. Returns an array of report definitions (type, name, supported formats). Use a returned type with addigy_request_report to generate that report. Spans child organizations when multitenancy=true.

ParamTypeRequiredDefaultDescription
childOrganizationsstringnonullComma-separated list of child organization ids to scope the aggregation to.
multitenancybooleannonullWhen true, aggregate results across child organizations (/oa/ scope).

[Addigy] List the data sources available to be exported. A source is the raw data for a specific entity within Addigy. Returns each source's id and metadata — use the id with addigy_download_export_source to download that source's raw data over a date range. Spans child organizations when multitenancy=true. Requires API token permission: Export Report Data.

ParamTypeRequiredDefaultDescription
childOrganizationsstringnonullComma-separated list of child organization ids to scope the aggregation to.
multitenancybooleannonullWhen true, aggregate results across child organizations (/oa/ scope).

[Addigy] Get a paginated list of organization files. All body fields are optional filters: ids (array of file id strings), search_term (string), md5_hash (array of hash strings), plus pagination (page, per_page) and sorting (sort_field, sort_direction). For one file's full metadata use addigy_get_file_metadata. Paginated; response metadata has page/page_count/total. Spans child organizations when multitenancy=true. Requires API token permission: View Files.

ParamTypeRequiredDefaultDescription
childOrganizationsstringnonullComma-separated list of child organization ids to scope the aggregation to.
multitenancybooleannonullWhen true, aggregate results across child organizations (/oa/ scope).
pageintegerno1Requested page (default 1).
perPageintegerno50Number of items in the response (default 50, max 500).
queryJsonstringnonullOptional JSON object with additional filter fields to merge into the request body: ids (array of strings), search_term (string), md5_hash (array of strings).
sortDirectionstringnonullSort direction: asc|desc.
sortFieldstringnonullField used for sorting.

[Addigy] Get the status of one or more reports. Required body field: report_ids (array of strings, at least one — from addigy_request_report). Returns each report's status so you can tell when it is ready to fetch with addigy_get_report. Spans child organizations when multitenancy=true.

ParamTypeRequiredDefaultDescription
childOrganizationsstringnonullComma-separated list of child organization ids to scope the aggregation to.
fieldsJsonstringyesJSON object with the report ids to look up. Required: report_ids (array of strings, at least one — from addigy_request_report).
multitenancybooleannonullWhen true, aggregate results across child organizations (/oa/ scope).

[Addigy] Request a report be generated for an organization. Only one report of each type can be requested at a time. Requires organizationId (from addigy_list_child_organizations, or the org's own id). Required body field: type (string — the report type; discover available types with addigy_list_available_reports). Optional body fields: format (csv|json), payload (object of report-specific parameters), email_settings (object with recipients and cc_recipients string arrays). Returns the report status — poll with addigy_query_report_statuses and fetch the finished report with addigy_get_report.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object describing the report request. Required: type (string — from addigy_list_available_reports). Optional: format (csv|json), payload (object), email_settings (object with recipients, cc_recipients string arrays).
organizationIdstringyesOrganization id — from addigy_list_child_organizations.

Community

ToolPlanAccessSummary
addigy_get_community_factFreeRead-onlyGet a single community-shared custom fact by its id.
addigy_get_community_scriptFreeRead-onlyGet a single community-shared script by its id.
addigy_list_featured_community_factsFreeRead-onlyGet featured community facts — the highest rated, most voted, most copied, and newest community-shared facts.
addigy_list_featured_community_scriptsFreeRead-onlyGet featured community scripts — the highest rated, most voted, most copied, and newest community-shared scripts.
addigy_query_community_factsFreeRead-onlyGet a paginated list of community-shared facts.
addigy_query_community_scriptsFreeRead-onlyGet a paginated list of community-shared scripts.
addigy_report_community_contentProWriteReport a community fact or command to Addigy for review (e.g. inappropriate or broken content).

[Addigy] Get a single community-shared custom fact by its id. Returns the community fact's full detail. Discover fact ids with addigy_query_community_facts or addigy_list_featured_community_facts. Spans child organizations when multitenancy=true; scope with childOrganizations.

ParamTypeRequiredDefaultDescription
childOrganizationsstringnonullComma-separated list of child organization ids to scope to. Omit for all.
idstringyesThe community fact id (from addigy_query_community_facts or addigy_list_featured_community_facts).
multitenancybooleannonullWhen true, resolve across child organizations. Omit for the API key's own organization only.

[Addigy] Get a single community-shared script by its id. Returns the community script's full detail. Discover script ids with addigy_query_community_scripts or addigy_list_featured_community_scripts. Spans child organizations when multitenancy=true; scope with childOrganizations.

ParamTypeRequiredDefaultDescription
childOrganizationsstringnonullComma-separated list of child organization ids to scope to. Omit for all.
idstringyesThe community script id (from addigy_query_community_scripts or addigy_list_featured_community_scripts).
multitenancybooleannonullWhen true, resolve across child organizations. Omit for the API key's own organization only.

[Addigy] Get a paginated list of community-shared facts. Optional filter (via queryJson) supports `fact_id_author`, `submitter_emails` (array of strings), `search_text` (substring), and `ids` (array of fact ids). Supports sort_fields (via sortFieldsJson — JSON array of field names) and sort_direction (asc/desc). per_page is capped at 100 by the API. Use addigy_get_community_fact for one fact's detail. Spans child organizations when multitenancy=true; scope with childOrganizations. Paginated; pass page to walk results.

ParamTypeRequiredDefaultDescription
childOrganizationsstringnonullComma-separated list of child organization ids to scope to. Omit for all.
multitenancybooleannonullWhen true, query across child organizations. Omit for the API key's own organization only.
pageintegerno1Requested page number (default 1).
perPageintegerno50Number of items per page (default 50, max 100 — Addigy documents a 100 cap on this endpoint).
queryJsonstringnonullOptional JSON filter object. Properties: fact_id_author (string), submitter_emails (array of strings), search_text (substring), ids (array of fact id strings).
sortDirectionstringnonullSort direction: asc or desc. Omit for default.
sortFieldsJsonstringnonullJSON array of field names to sort by (e.g. ["name"]). Omit for default ordering.

[Addigy] Get a paginated list of community-shared scripts. Optional filter (via queryJson) supports `script_id_author`, `submitter_emails` (array of strings), `search_text` (substring), and `ids` (array of script ids). Supports sort_fields (via sortFieldsJson — JSON array of field names) and sort_direction (asc/desc). per_page is capped at 100 by the API. Use addigy_get_community_script for one script's detail. Spans child organizations when multitenancy=true; scope with childOrganizations. Paginated; pass page to walk results.

ParamTypeRequiredDefaultDescription
childOrganizationsstringnonullComma-separated list of child organization ids to scope to. Omit for all.
multitenancybooleannonullWhen true, query across child organizations. Omit for the API key's own organization only.
pageintegerno1Requested page number (default 1).
perPageintegerno50Number of items per page (default 50, max 100 — Addigy documents a 100 cap on this endpoint).
queryJsonstringnonullOptional JSON filter object. Properties: script_id_author (string), submitter_emails (array of strings), search_text (substring), ids (array of script id strings).
sortDirectionstringnonullSort direction: asc or desc. Omit for default.
sortFieldsJsonstringnonullJSON array of field names to sort by (e.g. ["name"]). Omit for default ordering.

[Addigy] Report a community fact or command to Addigy for review (e.g. inappropriate or broken content). Requires organizationId (from addigy_list_child_organizations). Body fields (all required): `id` (the community fact or command id — discover facts with addigy_query_community_facts / addigy_get_community_fact and scripts with addigy_query_community_scripts / addigy_get_community_script), `report_reason` (free-text reason), and `type` (one of `custom-fact` | `predefined-command`).

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object describing the report. Required: id (the community fact/command id), report_reason (free-text reason), type (custom-fact | predefined-command).
organizationIdstringyesOrganization id whose context the report is filed under (from addigy_list_child_organizations).

Webhooks

ToolPlanAccessSummary
addigy_create_webhookProWriteCreate a webhook for an organization.
addigy_delete_webhookProDestructiveDelete a webhook from an organization, identified by its webhook id.
addigy_delete_webhook_scheduleProDestructiveDelete the delivery schedule of a webhook, identified by its webhook id — clears the pending (queued) events waiting to be sent for that webhook.
addigy_get_webhook_event_countProWriteReturns the count of events resolved (already sent) and/or pending (waiting to be sent) for specific webhooks.
addigy_query_webhook_statusesFreeRead-onlyGet the delivery statuses of webhooks.
addigy_query_webhooksFreeRead-onlyGet the list of webhooks configured for an organization.
addigy_update_webhookProWriteUpdate an existing webhook, matched by its id.

[Addigy] Create a webhook for an organization. Required body field: name (string). Optional: action (object with required url — the endpoint Addigy POSTs events to), trigger (object describing which events fire it: sender_type, sender_name, sender_identifier, receiver_type, receiver_name, receiver_identifier, action_name, action_entity_type, action_entity_name, action_entity_identifier, result_status, level), disabled (boolean). Returns the created Webhook record (including its id). Requires organizationId from addigy_list_child_organizations (or the org's own id). To change an existing webhook use addigy_update_webhook; to list them use addigy_query_webhooks.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object for the new webhook. Required: name (string). Optional: action (), trigger (sender_type, sender_name, sender_identifier, receiver_type, receiver_name, receiver_identifier, action_name, action_entity_type, action_entity_name, action_entity_identifier, result_status, level), disabled (bool).
organizationIdstringyesOrganization id — from addigy_list_child_organizations.

[Addigy] Delete a webhook from an organization, identified by its webhook id. Discover existing webhook ids with addigy_query_webhooks. This permanently removes the webhook subscription — to re-create one use addigy_create_webhook. Requires organizationId from addigy_list_child_organizations (or the org's own id).

ParamTypeRequiredDefaultDescription
idstringyesWebhook id to delete — from addigy_query_webhooks.
organizationIdstringyesOrganization id — from addigy_list_child_organizations.

[Addigy] Delete the delivery schedule of a webhook, identified by its webhook id — clears the pending (queued) events waiting to be sent for that webhook. Discover webhook ids with addigy_query_webhooks; check pending/resolved event counts with addigy_get_webhook_event_count first. This does not delete the webhook itself (use addigy_delete_webhook for that). Requires organizationId from addigy_list_child_organizations (or the org's own id).

ParamTypeRequiredDefaultDescription
idstringyesWebhook id whose schedule to delete — from addigy_query_webhooks.
organizationIdstringyesOrganization id — from addigy_list_child_organizations.

[Addigy] Returns the count of events resolved (already sent) and/or pending (waiting to be sent) for specific webhooks. Required body field: webhook_ids (array of strings) — discover ids with addigy_query_webhooks. Optional: statuses (array) limiting the count to particular states: "resolved" (event successfully sent) and/or "pending" (event awaiting dispatch). Use addigy_delete_webhook_schedule to clear pending events. Spans child organizations when multitenancy=true.

ParamTypeRequiredDefaultDescription
childOrganizationsstringnonullComma-separated list of child organization ids to scope the aggregation to.
fieldsJsonstringyesJSON object for the count request. Required: webhook_ids (array of strings from addigy_query_webhooks). Optional: statuses (array of "resolved" and/or "pending").
multitenancybooleannonullWhen true, aggregate results across child organizations (/oa/ scope).

[Addigy] Get the delivery statuses of webhooks. Returns an array of WebhookStatus records describing the current health/state of each webhook's deliveries. Pass an optional JSON body to narrow the result: webhook_ids (array of strings) restricts to specific webhook ids — discover them with addigy_query_webhooks. For raw pending/resolved event tallies use addigy_get_webhook_event_count. Spans child organizations when multitenancy=true.

ParamTypeRequiredDefaultDescription
childOrganizationsstringnonullComma-separated list of child organization ids to scope the aggregation to.
fieldsJsonstringnonullOptional JSON object to filter the result. Properties: webhook_ids (array of webhook id strings from addigy_query_webhooks). Omit or pass for all.
multitenancybooleannonullWhen true, aggregate results across child organizations (/oa/ scope).

[Addigy] Get the list of webhooks configured for an organization. Returns an array of Webhook records (id, name, action url, trigger, disabled). Pass an optional JSON body to narrow the result: ids (array of strings) restricts to specific webhook ids. Omit the body (or pass an empty object) to return all webhooks. These ids are what addigy_get_webhook_event_count, addigy_query_webhook_statuses, addigy_update_webhook, and addigy_delete_webhook consume. Spans child organizations when multitenancy=true.

ParamTypeRequiredDefaultDescription
childOrganizationsstringnonullComma-separated list of child organization ids to scope the aggregation to.
fieldsJsonstringnonullOptional JSON object to filter the result. Properties: ids (array of webhook id strings). Omit or pass for all webhooks.
multitenancybooleannonullWhen true, aggregate results across child organizations (/oa/ scope).

[Addigy] Update an existing webhook, matched by its id. Required body fields: id (string, identifies the webhook to update — from addigy_query_webhooks) and name (string). Optional: action (object with required url), trigger (sender_type, sender_name, sender_identifier, receiver_type, receiver_name, receiver_identifier, action_name, action_entity_type, action_entity_name, action_entity_identifier, result_status, level), disabled (boolean). Returns the updated Webhook record. Requires organizationId from addigy_list_child_organizations (or the org's own id). To create a webhook use addigy_create_webhook; to remove one use addigy_delete_webhook.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object with the webhook fields to update. Required: id (from addigy_query_webhooks), name. Optional: action (), trigger (sender_type, sender_name, sender_identifier, receiver_type, receiver_name, receiver_identifier, action_name, action_entity_type, action_entity_name, action_entity_identifier, result_status, level), disabled (bool).
organizationIdstringyesOrganization id — from addigy_list_child_organizations.