You entered a full URL instead of just the subdomain. For acme.api.eu.kandji.io, enter only acme.
Kandji Integration
Connect Kandji to Ploy to gain visibility into your managed Apple devices and who they are assigned to.
Alpha / limited availability notice: The Kandji integration is currently in alpha testing and is not yet generally available. When you open it in the Ploy integrations catalog you will see an "Alpha Notice" banner stating that the integration does not work right now and that you should only continue if instructed to do so by Ploy staff. Please do not connect Kandji unless a member of the Ploy team has asked you to — if you are interested in this integration, contact Ploy support and we will let you know when it is available for your organisation.
Overview
Kandji is an Apple device management (MDM) platform that helps organizations deploy, secure, and manage Mac, iPhone, iPad, and Apple TV devices. By connecting Kandji to Ploy, you can see which devices are managed, their status, and who they are assigned to — giving you better visibility into your device fleet and access patterns.
What Ploy syncs
Once the integration is enabled for your organisation, Ploy reads your Kandji device inventory and records:
Devices — platform, model, OS version, serial number, UDID, blueprint name, agent version, last check-in time, and status (active, or archived when Kandji marks the device as removed)
Device assignments — the user each managed device is assigned to in Kandji (the directory-assigned user shown on the device record; local macOS system accounts are not synced)
Device state flags — whether MDM is enabled, whether the Kandji agent is installed, and whether the device is marked missing or removed
Ploy reads devices only. It does not make any changes in Kandji.
Before you begin
The integration must have been enabled for your organisation by Ploy staff (see the alpha notice above).
You need a Kandji API token created from your Kandji admin console, with the Device list and Device details permissions.
You need to know your Kandji subdomain and the region (US or EU) your Kandji tenant is hosted in.
Set up the integration
Create a Kandji API token
Log in to your Kandji admin console.
Go to Settings → Access.
Click Add API Token.
Enable the following permissions:
Device list — required to scan your device inventory
Device details — required to retrieve device attributes and assigned users
Copy the token — you will need it for setup in Ploy.
For more detail, see Kandji's own guide: https://support.kandji.io/kb/kandji-api.
Connect Kandji to Ploy
In Ploy, navigate to Integrations.
Find and select Kandji from the catalog. You will see the Alpha Notice at the top of the setup form — only continue if Ploy staff have asked you to.
Enter your Kandji subdomain — use only the subdomain, not the full URL. For example, if your Kandji URL is
acme.api.eu.kandji.io, enteracme. You can find your API URL in Kandji under Settings → Access.Select your region: US or EU (defaults to US).
Paste your API token.
Click Connect.
Ploy tests the connection by requesting your device list from Kandji. If the test succeeds and the integration has been enabled for your organisation, Ploy starts syncing your Kandji device inventory. After each full sync, Ploy waits at least 2 hours before re-scanning devices.
Troubleshooting
Enter only your subdomain, not the full URL
API token does not have sufficient permissions — ensure Device list is enabled
Your API token is missing the Device list permission. Go to Kandji Settings → Access, edit the token, enable Device list, save, and try again.
Failed to authenticate with Kandji — check your subdomain and API token
Double-check your subdomain and API token for typos, and make sure the region you selected (US or EU) matches your Kandji tenant.
API endpoint not found — check your subdomain
The subdomain may be incorrect. Verify your actual Kandji subdomain from your Kandji admin console URL and re-enter it.
Could not reach Kandji — check your subdomain and region
This usually means the region is wrong. If your Kandji tenant is in the EU but you selected US (or vice versa), the connection will fail. Switch the region and try again.
Invalid API token
The token was not recognised by Kandji. Re-copy the token from Kandji Settings → Access and paste it again, making sure no extra spaces were included.
The setup form shows an "Alpha Notice" and says the integration does not work right now
This is expected: the Kandji integration is in alpha. Only continue if Ploy staff have instructed you to; otherwise contact Ploy support to register your interest.