Jamf
Receive Jamf Pro webhooks for enrollments, inventory and smart group changes as typed events. Use them to track device readiness, flag drift and lock lost devices with a sign-off.
Identity
Category
Events
Sync mode
p95 640 ms
Latency
6 min
Setup time
What it can do
- Computer enrolledWebhook
- Inventory updatedWebhook
- Smart group membership changedWebhook
- Mobile device enrolledWebhook
- Look up a computerRead
- Update inventory fieldsWrite
- Lock a computerWrite
- Erase a deviceWrite
Overview
The Jamf connector registers webhooks in Jamf Pro, so Tessel hears about device changes the moment Jamf records them. Each webhook arrives as a typed event with the serial number, user and device details, and it appears in the trace of the run it started.
Teams use it to mark onboarding done when a new hire's Mac enrolls, to open a Zendesk ticket when a device falls out of the encryption smart group, and to lock a lost laptop after Okta deactivates its owner.
Supported versions
Jamf Pro 10.49 and later, on Jamf Cloud or on-premises
macOS computers, plus iPhone and iPad as mobile devices
On-premises servers reachable over TLS from Tessel's static IPs
How webhooks work
Tessel creates one webhook per event type, each with a signing header unique to your workspace. Jamf posts JSON to a regional endpoint, and Tessel checks the header and the schema before starting a run. Repeated posts for the same event are matched by webhook ID and timestamp and dropped.
Remote commands
Lock and erase actions send MDM commands that cannot be undone. Tessel puts them behind an approval step by default, so a named person and a backup confirm before the command leaves.
Permissions needed
Create an API client in Jamf Pro with an API role that holds only the privileges below. The client uses client credentials, and Tessel refreshes its token before it expires.
Read ComputersandRead Mobile Devicesfor lookupsUpdate Computersfor inventory fieldsSend Computer Remote Lock CommandandSend Computer Remote Wipe Commandfor device actions
Four steps. About six minutes.
Most of the time goes into the API role. Tessel creates the webhooks once the client works.
- Create an API role with the listed privilegesJamf3 min
- Create an API client and copy its secretJamf1 min
- Paste your Jamf URL and client credentialsTessel2 min
- Run a recon on a test Mac and watch the eventVerify640 ms
Your fleet, in a workflow today.
Connect Jamf on the free plan. Up to three builders and 10,000 runs a month, no card required.