# Primo Documentation ## Docs - [Welcome to Primo](https://docs.getprimo.com/index.md): Everything you need to manage your company's IT — devices, MDM, procurement, and SaaS — all in one place. - [Glossary](https://docs.getprimo.com/introduction/glossary.md): A reference for the IT and product terminology you'll encounter throughout the Primo Help Center. - [Set up HR Sync](https://docs.getprimo.com/employees/set-up-hr-sync.md): Connect your HR system to Primo to automatically sync employee data, trigger onboarding and offboarding workflows, and keep your employee directory up to date. If you don't use an HR system, you can import employees via CSV. - [Automate your onboardings](https://docs.getprimo.com/employees/automate-onboardings.md): Configure Primo to automatically handle the full onboarding journey — employee creation, email provisioning, SaaS access, and device enrollment — so every new hire starts on day one with everything they need. - [Track onboardings as tickets](https://docs.getprimo.com/employees/track-onboardings-as-tickets.md): Follow and resolve every employee onboarding from a single ticket, where each onboarding step appears as a task you can configure, schedule, or skip. - [Automate your offboardings](https://docs.getprimo.com/employees/automated-offboardings.md): Configure Primo to automatically handle the full offboarding journey — SaaS deprovisioning, email suspension, and equipment retrieval — triggered by departure dates from your HR system. - [Slack for ticketing](https://docs.getprimo.com/tickets/slack.md): Connect your Slack workspace to create tickets from Slack and keep a ticket and its Slack thread in sync. - [Platform support](https://docs.getprimo.com/mdm/get-started/supported-platforms.md): Primo supports macOS, Windows, Linux, iOS, Android, and ChromeOS — enroll any device, apply policies, and manage your entire fleet from a single platform. - [Apple](https://docs.getprimo.com/mdm/get-started/set-up-apn-certificate.md): Learn how to set up MDM for your Apple devices below. - [Windows](https://docs.getprimo.com/mdm/get-started/initial-setup-windows.md): Learn how to set up MDM for your Windows devices below. - [Linux](https://docs.getprimo.com/mdm/get-started/initial-setup-linux.md): Learn how to set up MDM for your Linux devices below. - [Android](https://docs.getprimo.com/mdm/get-started/initial-setup-android.md): Learn how to set up MDM for your Android devices below. - [Enrollment methods](https://docs.getprimo.com/mdm/rollout/enrollment-methods.md): Compare the available methods for enrolling devices into Primo and choose the right approach for your organisation, based on your existing setup, platform mix, and whether you want the process to be admin-driven or employee-driven. - [Zero Touch for Apple](https://docs.getprimo.com/mdm/zero-touch/zero-touch-macs.md): Connect Apple Business to automatically enroll, preconfigure, and secure Apple devices purchased through authorized resellers. - [Zero-touch for Windows](https://docs.getprimo.com/mdm/zero-touch/zero-touch-windows.md): Windows Autopilot gives new Windows devices an out-of-the-box setup experience. When an employee powers on a device for the first time, they sign in with their Microsoft credentials, and Autopilot applies all company apps, settings, and security policies automatically — no IT intervention required. - [Employee enrollment](https://docs.getprimo.com/mdm/rollout/invite-employees.md): Employee enrollment is the standard method for enrolling devices where the employee installs the Primo MDM agent themselves. It works on all supported platforms and requires no prior infrastructure. - [Account-driven device enrollment](https://docs.getprimo.com/mdm/rollout/account-driven-enrollment.md): Enroll iOS, iPadOS, and macOS devices using Account-driven Device Enrollment — a privacy-preserving method where employees sign in with their Managed Apple ID to enroll their device. - [Silent agent deployment](https://docs.getprimo.com/mdm/rollout/silent-agent-deployment.md): Deploy the Primo MDM agent centrally and silently — using an existing MDM, Active Directory with GPO, or any package deployment system. - [Migrate Macs using Apple Business](https://docs.getprimo.com/mdm/rollout/migrating-macs-using-abm.md): Reassign Macs from a previous MDM to Primo via Apple Business — no device wipe, no data loss. - [Communication resources](https://docs.getprimo.com/mdm/rollout/mdm-rollout-resources.md): Email and Slack templates to communicate your MDM rollout to employees. We recommend giving clear deadlines to drive a quick, efficient rollout. - [Employee guide & FAQ](https://docs.getprimo.com/mdm/rollout/employee-enrollment-guide.md): Step-by-step instructions for employees to install the Primo MDM agent on their device, with answers to common questions. - [Wiping devices](https://docs.getprimo.com/mdm/guides/wiping-devices.md): Remotely erase a managed Mac, Windows, Linux, iOS, iPadOS, or Android device from the Primo cockpit. This is critical when a device is lost, stolen, or being reassigned. Understand the wipe options available per platform and when to use each. - [Locking devices](https://docs.getprimo.com/mdm/guides/locking-devices.md): Remotely lock a managed Mac, Windows, Linux, iOS, iPadOS, or Android device from the dashboard to prevent unauthorized access when a device is lost or an employee is offboarded. - [Clear passcode](https://docs.getprimo.com/mdm/guides/clear-passcode.md): Remotely remove the lock screen passcode on a managed Android device so an employee who forgot their PIN, pattern, or password can regain access and set a new one. - [Activation Lock bypass code escrow](https://docs.getprimo.com/mdm/guides/activation-lock-bypass.md): Rules for ensuring Activation Lock bypass codes are escrowed via MDM so devices can be recovered after a wipe or reassignment. - [Script library](https://docs.getprimo.com/mdm/scripts/script-library.md): Add, edit, download, and delete shell, Python, and PowerShell scripts you can run on macOS, Linux, and Windows devices. - [Enforce OS updates](https://docs.getprimo.com/mdm/policies/enforce-minimum-os-version.md): Require devices to run a minimum operating system version to ensure security patches and app compatibility are maintained across your fleet. - [Automatic app and OS updates](https://docs.getprimo.com/mdm/policies/automatic-updates.md): Configure automatic update settings for macOS devices to keep apps and the operating system up to date in the background. - [Disk encryption](https://docs.getprimo.com/mdm/policies/disk-encryption.md): Enforce full-disk encryption across your fleet and automatically escrow recovery keys so IT can always regain access without relying on employee credentials. - [Admin management](https://docs.getprimo.com/mdm/policies/manage-admin-accounts.md): Deploy and manage local administrator accounts across your fleet — with per-device random passwords, privilege management, and full visibility from the Primo cockpit. - [Admin password rotation](https://docs.getprimo.com/mdm/policies/admin-password-rotation.md): Automatically rotate and securely back up local administrator account passwords on a scheduled basis to reduce the risk of credential reuse and unauthorized access. - [Generate settings via AI](https://docs.getprimo.com/mdm/policies/generate-settings-via-ai.md): Use Primo's AI engine to create tailored MDM configuration profiles for Apple devices in seconds by describing the settings you need in plain language. - [Custom file](https://docs.getprimo.com/mdm/policies/custom-file.md): Import a custom configuration profile to apply settings not covered by Primo's built-in controls, with support for native profile formats on macOS, iOS/iPadOS, Windows, and Android. - [App blocking](https://docs.getprimo.com/mdm/policies/app-blocking.md): Control which applications can run on macOS devices using Monitor, Lockdown, or Standalone enforcement modes. Powered by Santa, an open-source macOS security agent developed by Google. - [AirDrop restriction](https://docs.getprimo.com/mdm/policies/airdrop-restriction.md): Control AirDrop discoverability on macOS devices to prevent unauthorized file sharing. - [Device naming](https://docs.getprimo.com/mdm/policies/device-naming.md): Use AI to automatically generate and enforce consistent device names across your macOS, Windows, and Linux fleet based on employee and device attributes. - [Firewall](https://docs.getprimo.com/mdm/policies/firewall.md): Enable the built-in operating system firewall on macOS and Windows devices to block unauthorized inbound network connections. - [Google Chrome](https://docs.getprimo.com/mdm/policies/google-chrome.md): Deploy managed Chrome settings, extensions, and homepage across macOS and Windows devices. - [Lock MDM profiles pane](https://docs.getprimo.com/mdm/policies/lock-mdm-profiles-pane.md): Block users from modifying the Profiles section in macOS System Settings, preventing them from viewing or removing MDM profiles. - [Screen capture blocking](https://docs.getprimo.com/mdm/policies/screen-capture-blocking.md): Block screenshots and screen recording on macOS devices to protect sensitive content. - [Platform SSO with Entra](https://docs.getprimo.com/mdm/policies/mac-login-entra.md): Replace local macOS logins with Microsoft Entra ID single sign-on so employees use their corporate credentials to unlock their Mac. - [Platform SSO with Okta](https://docs.getprimo.com/mdm/policies/set-up-okta.md): Integrate Okta as the authentication provider for managed Mac devices using Apple's Platform Single Sign-On so employees log in with their Okta credentials and SSO propagates to all Okta-connected apps. - [Desktop SSO with Okta](https://docs.getprimo.com/mdm/policies/okta-windows.md): Configure Okta Device Access on managed Windows devices so employees authenticate with Okta Verify at the Windows login screen and gain SSO access to Okta-connected apps without re-authenticating. - [Password and screenlock](https://docs.getprimo.com/mdm/policies/password-policy.md): Set password rules and screen lock preferences to keep devices secure. - [recoveryOS protection](https://docs.getprimo.com/mdm/policies/recoveros-protection.md): Configure recoveryOS settings on macOS devices to prevent unauthorized access to recovery tools. - [Remote access](https://docs.getprimo.com/mdm/policies/remote-management.md): Deploy RustDesk to enable encrypted remote access and screen sharing on managed devices. - [USB storage blocking](https://docs.getprimo.com/mdm/policies/usb-storage-blocking.md): Prevent USB keys, SD cards, and other removable storage from connecting to managed devices. - [WiFi](https://docs.getprimo.com/mdm/policies/wifi.md): Push WiFi settings to managed devices so employees connect to company networks automatically without entering credentials manually. - [Device groups](https://docs.getprimo.com/mdm/device-groups.md): Organize your fleet into device groups to apply MDM profiles and controls to specific sets of devices. - [Custom fields](https://docs.getprimo.com/mdm/custom-fields.md): Define your own data attributes on devices to capture company-specific information, segment your fleet, power Device Group rules, and report on the data you need. - [Software types & capabilities](https://docs.getprimo.com/mdm/software-types.md): Primo supports several software types across platforms, each with different deployment and management capabilities. Use this page to choose the right approach for your fleet. - [Fleet-maintained software](https://docs.getprimo.com/mdm/policies/fleet-maintained-software.md): Deploy popular apps from a curated, pre-packaged catalog maintained by Fleet — no installer management required. - [Custom software](https://docs.getprimo.com/mdm/policies/custom-software.md): Deploy your own installer packages — internal tools, enterprise builds, or any app not in the Fleet catalog. - [App Store apps](https://docs.getprimo.com/mdm/policies/app-store-apps.md): Deploy Apple App Store apps to macOS and iOS/iPadOS devices using Apple's Volume Purchase Program (VPP). - [Google Play Store apps](https://docs.getprimo.com/mdm/policies/google-play-store.md): Deploy managed apps to Android devices through Android Enterprise and the Google Play Store. - [Find the right program name for Automatic Install](https://docs.getprimo.com/mdm/guides/find-program-name.md): How to identify the exact software name to use in your auto-install detection query on Windows and Linux. - [Compliance overview](https://docs.getprimo.com/mdm/compliance/overview.md): Continuously audit every managed device against your security and IT policies, surface deviations, and decide which device states should count as a violation. - [Configure compliance alert rules](https://docs.getprimo.com/mdm/compliance/alert-rules.md): Choose which device statuses count as a violation so the alerts list reflects your organization's risk posture. - [Monitor compliance alerts](https://docs.getprimo.com/mdm/compliance/alerts.md): Triage devices that currently violate your compliance rules from a single live list. - [Change a local session password](https://docs.getprimo.com/mdm/policies/change-local-password.md): To update a local session password from the Primo cockpit, ensure you are an administrator, that the device is enrolled and online, then navigate to the Users tab, modify the session password, and monitor the change status in the Logs tab for successful sign-in with the new credentials. - [SecureToken rules](https://docs.getprimo.com/mdm/policies/secure-token.md): The secure token is a critical security identifier in macOS that enables actions like changing passwords and creating user accounts, ensuring compliance with Apple's security standards and proper user management through Primo. - [Audit logs](https://docs.getprimo.com/mdm/audit-logs.md): Track all administrative actions taken on devices and MDM settings in Primo — including policy changes, remote commands, and enrollment events. - [Network whitelisting](https://docs.getprimo.com/mdm/network-requirements.md): Which Primo MDM and Apple endpoints must be reachable for enrollment, policy delivery, and push notifications to work when devices are behind a firewall or proxy. - [Settings](https://docs.getprimo.com/mdm/settings.md): Configure your Primo MDM instance — integrations, enrollment behavior, notifications, and more. - [ThreatDown](https://docs.getprimo.com/mdm/endpoint-protection/threatdown.md): Deploy ThreatDown (by Malwarebytes) automatically to protect your device fleet against security threats. - [SentinelOne](https://docs.getprimo.com/mdm/endpoint-protection/sentinelone.md): Connect your SentinelOne instance to Primo and deploy the agent automatically on macOS, Windows, and Linux devices. - [CrowdStrike Falcon](https://docs.getprimo.com/mdm/endpoint-protection/crowdstrike-falcon.md): Deploy the CrowdStrike Falcon agent on macOS and Windows devices. - [Bitdefender](https://docs.getprimo.com/mdm/endpoint-protection/bitdefender.md): Deploy the Bitdefender GravityZone agent on macOS and Windows devices using Primo MDM. - [Primo AI](https://docs.getprimo.com/ai/primo-ai.md): Chat with Primo AI, a context-aware assistant that helps you search, understand, and act across the platform. - [Knowledge base items](https://docs.getprimo.com/ai/knowledge-base-items.md): Teach Primo AI your company's knowledge, policies, and reusable tasks by creating and publishing knowledge base items. - [Connectors](https://docs.getprimo.com/ai/connectors.md): Connect external tools to Primo AI by registering Model Context Protocol (MCP) servers. - [Connect your email provider](https://docs.getprimo.com/saas/get-started/connect-email-provider.md): Connect Google Workspace or Microsoft Entra ID to Primo to enable SaaS discovery, automated provisioning, and identity management across your organization. - [Activate SaaS Discovery](https://docs.getprimo.com/saas/get-started/activate-saas-discovery.md): Discover all SaaS applications used across your organization by activating SaaS Mapping via Google Workspace or the Primo Chrome Extension. - [Connect your apps](https://docs.getprimo.com/saas/connect-apps.md): Connect your applications for secure, centralized access management, following the outlined steps to configure Single Sign-On (SSO), SCIM provisioning, or API-based integrations effectively. - [Connected SaaS and properties](https://docs.getprimo.com/saas/connected-saas-properties.md): Explore the various connected SaaS applications available, detailing their required plans, user provisioning, group and roles management, license management, and the necessity of single sign-on (SSO) for efficient integration and management. - [Manage tracked applications](https://docs.getprimo.com/saas/manage-tracked-apps.md): Tracked applications allow for manual recording and monitoring of employee accounts, with designated owners responsible for managing account changes during onboarding or offboarding processes, ensuring centralized and updated tracking of account information. - [Configure SSO with Primo as the identity provider](https://docs.getprimo.com/saas/configure-sso.md): Configure Single Sign-On (SSO) with Primo as the identity provider by retrieving the necessary SSO details and entering your service provider's information to enable user authentication for third-party applications. - [Cost management](https://docs.getprimo.com/saas/cost-management.md): Track and optimize your SaaS spending in Primo — monitor licence costs, identify unused seats, and reduce waste across your software stack. - [Identities](https://docs.getprimo.com/saas/identities.md): View and manage all employee identities and their SaaS application access from one place in Primo. - [Set up licence provisioning](https://docs.getprimo.com/saas/licence-provisioning.md): Set up provisioning to automate user account creation and updates in applications like Zendesk, ensuring employees have appropriate access roles based on defined rules without manual management. - [SaaS audit logs](https://docs.getprimo.com/saas/audit-logs.md): Track all administrative actions taken in Identity & SaaS Management — including provisioning events, rule changes, and app connection updates. - [SaaS settings](https://docs.getprimo.com/saas/settings.md): Configure your Identity & SaaS Management settings in Primo — manage integrations, provisioning defaults, and notification preferences. - [Get started with Global Purchasing](https://docs.getprimo.com/procurement/get-started.md): Everything you need to start ordering IT equipment through Primo — set up your catalog, configure billing profiles, and enable procurement in the countries you operate in. - [Equipment policy](https://docs.getprimo.com/procurement/equipment-policy.md): An AI-powered policy that defines which devices and accessories your employees can order based on their profile, and curates the catalog automatically. - [Create and manage your catalog](https://docs.getprimo.com/procurement/add-products-catalog.md): Primo uses per-country catalog management. Each country must be added individually in Orders & Shipments > Settings before you can order products for that country. - [Delivery countries](https://docs.getprimo.com/procurement/shipping-countries.md): Current shipping coverage and how to request additional countries. - [Open a new country](https://docs.getprimo.com/procurement/open-new-country.md): Request procurement access for a new country where your employees are located. Learn what's needed to enable ordering and shipping in a new region. - [Set up zero-touch deployment on your catalog](https://docs.getprimo.com/mdm/zero-touch/setup-zero-touch-catalog.md): Configure Apple Business Manager and Microsoft Entra so Primo enrolls ordered devices automatically with zero-touch deployment. - [Setup AppleCare for Enterprise](https://docs.getprimo.com/procurement/setup-applecare-enterprise.md): Set up AppleCare Enterprise (ACE), activate your MSA ID, and add ACE to your Primo orders. - [Keyboard layouts & localization](https://docs.getprimo.com/mdm/zero-touch/keyboard-layouts-localization.md): Understand how keyboard layout selection affects Zero-Touch Deployment (ZTD) eligibility when ordering devices. - [Track your order](https://docs.getprimo.com/procurement/track-your-order.md): Understand order statuses in Primo and track the progress of your device and accessory orders from placement to delivery. - [Modify or cancel an order](https://docs.getprimo.com/procurement/modify-or-cancel-order.md): Learn when you can cancel an order, why orders can't be modified once placed, and what happens if an ordered item is out of stock. - [Create a shipment](https://docs.getprimo.com/procurement/create-shipment.md): Generate a shipping label and create a return shipment in Primo — either from the offboarding flow or manually from the cockpit. - [Track a shipment](https://docs.getprimo.com/procurement/track-shipment.md): Follow the progress of equipment return shipments in Primo — understand shipment statuses and access carrier tracking. - [Customs & international shipments](https://docs.getprimo.com/procurement/customs-international-shipments.md): Understand when customs duties and clearance apply to shipments between the EU, the United Kingdom, and the rest of the world. - [Damaged in transit](https://docs.getprimo.com/procurement/damaged-parcel.md): What to do if a device or accessory is damaged during shipping, from refusing a visibly damaged parcel at delivery to opening a claim with Primo. - [Wrong or defective item received](https://docs.getprimo.com/procurement/wrong-or-defective-item.md): What to do if you receive the wrong device, a duplicate shipment, or a product that is defective on arrival, outside of transport damage. - [Return & exchange conditions](https://docs.getprimo.com/procurement/return-conditions.md): General eligibility conditions for returns and exchanges, and where to go for transport damage, wrong items, or defects. - [Repairs & warranty claims](https://docs.getprimo.com/procurement/repairs-warranty-claims.md): Standard warranty coverage, return policy, and how to handle accidental damage or theft for devices purchased through Primo. - [Repair partners](https://docs.getprimo.com/procurement/local-partners-repair.md): Repair partners available through Primo by country — submit a repair request directly from the device panel in your cockpit. - [Buyback partners](https://docs.getprimo.com/procurement/local-partners-resell.md): Resell your used IT equipment through Primo's trusted partners — one row per partner with coverage, supported devices, and contact details. - [Deal with lost passwords](https://docs.getprimo.com/guides/device-management/resolve-login-issue.md): To resolve a password-related login issue, verify the user's password entry and keyboard layout, check the applied password policy, and choose the appropriate recovery option while implementing preventive measures for future incidents. - [Navigate FleetDM](https://docs.getprimo.com/guides/device-management/fleetdm-guide.md): Get started with FleetDM by exploring its main tabs: Hosts, Controls, Queries, and Policies. - [Data erasure](https://docs.getprimo.com/guides/compliance/data-erasure.md): How Primo erases managed device data, which erasure standards apply, and how this maps to SOC 2, ISO 27001, and NIS2 compliance frameworks. - [Maintenances](https://docs.getprimo.com/maintenance/overview.md): Scheduled and past maintenance windows for the Primo platform, with scope and expected impact. - [Database migration](https://docs.getprimo.com/maintenance/database-migration.md): Scheduled database migration affecting Primo MDM features on June 23, 2026. - [July](https://docs.getprimo.com/changelog/2026/july.md): Product updates from July 2026 - [April](https://docs.getprimo.com/changelog/2026/april.md): Product updates from April 2026 - [March](https://docs.getprimo.com/changelog/2026/march.md): Product updates from March 2026 - [February](https://docs.getprimo.com/changelog/2026/february.md): Product updates from February 2026 - [December](https://docs.getprimo.com/changelog/2025/december.md): Product updates from December 2025 - [November](https://docs.getprimo.com/changelog/2025/november.md): Product updates from November 2025 - [September](https://docs.getprimo.com/changelog/2025/september.md): Product updates from September 2025 - [August](https://docs.getprimo.com/changelog/2025/august.md): Product updates from August 2025 - [July](https://docs.getprimo.com/changelog/2025/july.md): Product updates from July 2025 - [June](https://docs.getprimo.com/changelog/2025/june.md): Product updates from June 2025 - [May](https://docs.getprimo.com/changelog/2025/may.md): Product updates from May 2025 - [April](https://docs.getprimo.com/changelog/2025/april.md): Product updates from April 2025 - [March](https://docs.getprimo.com/changelog/2025/march.md): Product updates from March 2025 - [February](https://docs.getprimo.com/changelog/2025/february.md): Product updates from February 2025 - [January](https://docs.getprimo.com/changelog/2025/january.md): Product updates from January 2025 - [Create API keys for Primo](https://docs.getprimo.com/api/create-primo-api-key.md): Generate a Primo API key to authenticate requests to the Primo REST API. - [Create API keys for Fleet](https://docs.getprimo.com/api/create-fleet-api-key.md): Generate a FleetDM API key to authenticate direct requests to your Fleet instance. - [Connect to our MCP](https://docs.getprimo.com/get-started/primo-mcp-server.md): Learn how to connect ChatGPT, Claude, Cursor, and other AI assistants to Primo using the MCP (Model Context Protocol) server to manage your IT fleet in natural language. - [Get all admins](https://docs.getprimo.com/api-reference/admins/get-all-admins.md): Return the list of admin users for your company. Each entry is either an employee (with an id) or an external user (identified by email only). - [Get the authenticated company](https://docs.getprimo.com/api-reference/company/get-the-authenticated-company.md): Return the company associated with the API key. Only accessible with a Company API key. - [List custom fields](https://docs.getprimo.com/api-reference/customfields/list-custom-fields.md): Return a paginated list of custom field definitions for your company — definitions only, without the values stored on entities. To read or write the values on a specific entity, use `getDeviceCustomFields`/`getDevicesCustomFields` (devices) or `getAccessoryCustomFields` (accessories). Defaults to AC… - [Create a custom field](https://docs.getprimo.com/api-reference/customfields/create-a-custom-field.md): Create a new custom field definition. Labels are not constrained to be unique. Options are only allowed for SELECT and MULTI_SELECT field types. - [Get a custom field by ID](https://docs.getprimo.com/api-reference/customfields/get-a-custom-field-by-id.md): Return the custom field definition for the given custom field ID — the definition only, not the values stored on entities. To read or write values, use the per-entity endpoints (`getDeviceCustomFields`, `getAccessoryCustomFields`, …). - [Update a custom field](https://docs.getprimo.com/api-reference/customfields/update-a-custom-field.md): Update label, applyTo (widen-only), optionsToAdd, or optionsToRename on a custom field. At least one field must be provided. Archived fields cannot be updated. - [Archive a custom field](https://docs.getprimo.com/api-reference/customfields/archive-a-custom-field.md): Archive a custom field definition. Archived fields are no longer offered for new values but remain readable. Returns 409 if the field has active consumers (related entities must be cleared first). - [Get all companies in the workspace](https://docs.getprimo.com/api-reference/workspace/get-all-companies-in-the-workspace.md): Return the list of companies in your workspace. Only accessible with a Workspace API key. - [Get a company by ID](https://docs.getprimo.com/api-reference/workspace/get-a-company-by-id.md): Return the company details for the given company ID. Only accessible with a Workspace API key. - [Get all devices (deprecated)](https://docs.getprimo.com/api-reference/devices/get-all-devices-deprecated.md): **Deprecated** — use `getDevices` (`POST /devices/search`) instead, which returns the same device objects and additionally accepts a filter and a free-text search. This route will be removed on 2026-11-01. Return the paginated list of devices for your company, retired ones excluded, as JSON. - [Create a device](https://docs.getprimo.com/api-reference/devices/create-a-device.md): Create a new device in your company. - [Update several devices](https://docs.getprimo.com/api-reference/devices/update-several-devices.md): Update the inventory data of MULTIPLE devices in one call — the batch form of `updateDevice`, with the same fields and the same rules per device. Provide a list of `items`, each targeting one `deviceId` (up to 100 per call, each device at most once). Writes are independent and best-effort: the call… - [Export devices as CSV](https://docs.getprimo.com/api-reference/devices/export-devices-as-csv.md): Export the devices of your company as a paginated CSV (one row per device, first line is the header, up to 1000 devices per page). Each row contains the device attributes, its latest code of each type (recovery key, iCloud bypass code, unlock PIN, recovery OS password — see `getDeviceCodeHistory` fo… - [Get a device by ID](https://docs.getprimo.com/api-reference/devices/get-a-device-by-id.md): Return the device details for the given device ID. This device can have custom fields (see `getDeviceCustomFields`) and code history (see `getDeviceCodeHistory`). This device can also have local user accounts (see `getDeviceUsers`). - [Delete a device](https://docs.getprimo.com/api-reference/devices/delete-a-device.md): Permanently delete a device from your company. The device must not be enrolled. - [Update a device](https://docs.getprimo.com/api-reference/devices/update-a-device.md): Update the inventory data of one device: its assignee, its identity and specs, and its purchase data. Only the fields present in the body are changed — each field documents its own constraints. Fields that MDM reports for an enrolled device can only be set while the device is not enrolled; changing… - [Lock a device](https://docs.getprimo.com/api-reference/devices/lock-a-device.md): Lock the device for the given device ID. - [Unlock a device](https://docs.getprimo.com/api-reference/devices/unlock-a-device.md): Unlock the device for the given device ID. - [Wipe a device](https://docs.getprimo.com/api-reference/devices/wipe-a-device.md): Wipe the device for the given device ID. - [Run a script on one device](https://docs.getprimo.com/api-reference/devices/run-a-script-on-one-device.md): Run a script on the device for the given device ID. Pass `{ "scriptId": 12 }` to run a saved script (see `getScripts`), or `{ "contents": "..." }` to send the source inline. - [List a device's script history](https://docs.getprimo.com/api-reference/devices/list-a-devices-script-history.md): Return the paginated script executions that reached this device, newest first — across every run, including company-wide and device-group runs launched elsewhere. Each entry carries the script that ran plus its status, output, exit code and runtime. Use this to answer "what has been run on this mach… - [Retire a device](https://docs.getprimo.com/api-reference/devices/retire-a-device.md): Retire a device from your company. Optionally specify a data action (wipe/lock), physical condition, and notes. - [Reboot a device](https://docs.getprimo.com/api-reference/devices/reboot-a-device.md): Trigger a reboot on the device. The command is sent the next time the device comes online. - [Disenroll a device](https://docs.getprimo.com/api-reference/devices/disenroll-a-device.md): Disenroll the device from MDM. The device will no longer be managed after this operation. - [Move a device to stock](https://docs.getprimo.com/api-reference/devices/move-a-device-to-stock.md): Move the device to stock (unassign it from any employee). - [Move a device to in-use](https://docs.getprimo.com/api-reference/devices/move-a-device-to-in-use.md): Move the device from stock back to in-use status. - [Put a device back in stock](https://docs.getprimo.com/api-reference/devices/put-a-device-back-in-stock.md): Cancel a pending retirement and return the device to stock. - [Update a device owner](https://docs.getprimo.com/api-reference/devices/update-a-device-owner.md): Assign or unassign a device to an employee. Pass null to unassign. - [Update device tags](https://docs.getprimo.com/api-reference/devices/update-device-tags.md): Replace the tags on a device with the provided list. - [Get device events](https://docs.getprimo.com/api-reference/devices/get-device-events.md): Return the list of lifecycle events recorded by Primo for the given device (lock, wipe, reboot, disenroll, etc.) in reverse chronological order. For the MDM activity feed reported by the MDM layer, use `getDeviceActivities`; for raw MDM protocol commands and their delivery status, use `getDeviceComm… - [List local user accounts on a device](https://docs.getprimo.com/api-reference/devices/list-local-user-accounts-on-a-device.md): Return the local user accounts provisioned on ONE device, each with its privilege level (`rights`: ADMIN / USER / UNKNOWN). Use this to find which accounts hold local administrator or standard user rights on a machine. For many devices at once, use `getDevicesUsers` instead of calling this endpoint… - [List local user accounts on multiple devices](https://docs.getprimo.com/api-reference/devices/list-local-user-accounts-on-multiple-devices.md): Return the local user accounts provisioned on MULTIPLE devices in one call, grouped by device id, each account with its privilege level (`rights`: ADMIN / USER / UNKNOWN). Use this to answer fleet-wide questions such as "which users hold local administrator rights on their machine": list the devices… - [Get device code history](https://docs.getprimo.com/api-reference/devices/get-device-code-history.md): Return the decrypted code history for ONE device (recovery key, iCloud bypass code, unlock PIN, recovery OS password), newest first. Optionally filter by `type`. For many devices at once, use `getDevicesCodeHistory` instead of calling this endpoint in a loop. - [Get code history for multiple devices](https://docs.getprimo.com/api-reference/devices/get-code-history-for-multiple-devices.md): Return the decrypted code history (recovery key, iCloud bypass code, unlock PIN, recovery OS password) for MULTIPLE devices in one call, grouped by device id, each newest first. Provide a list of `deviceIds` (up to 200 per call), optionally filtered by `type`. Devices that do not exist, or that do n… - [Get device custom fields](https://docs.getprimo.com/api-reference/devices/get-device-custom-fields.md): Return all Active custom field definitions for ONE device, each paired with the current stored value (or null when unset). For SELECT / MULTI_SELECT fields the `options` catalog is included so you can map option ids to labels. For many devices at once, use `getDevicesCustomFields` instead of calling… - [Get custom fields for multiple devices](https://docs.getprimo.com/api-reference/devices/get-custom-fields-for-multiple-devices.md): Return all Active custom field definitions for MULTIPLE devices in one call, each paired with the current stored value (or null when unset), grouped by device id. Provide a list of `deviceIds` (up to 500 per call). Prefer this over calling `getDeviceCustomFields` once per device. - [Set a device custom field value](https://docs.getprimo.com/api-reference/devices/set-a-device-custom-field-value.md): Set or overwrite a custom field value on a device. Idempotent. Returns the updated field (definition + value). For SELECT supply the option id (string); for MULTI_SELECT supply an array of option ids. Option ids can be read from the `getDeviceCustomFields` endpoint. - [Clear a device custom field value](https://docs.getprimo.com/api-reference/devices/clear-a-device-custom-field-value.md): Remove the stored value for a custom field on a device. Returns the updated field (value reset to null). - [Get devices, optionally narrowed by a filter](https://docs.getprimo.com/api-reference/devices/get-devices-optionally-narrowed-by-a-filter.md): Return the devices of your company as a paginated JSON list of full device objects — THE tool to look up, filter, count or answer any question about devices. Send an empty body to list everything; add a `filter` to narrow it. Every `filter` entry is keyed by a `key` from `getDeviceFilterCatalog` (`G… - [Get the device search filter catalog](https://docs.getprimo.com/api-reference/devices/get-the-device-search-filter-catalog.md): Return every criterion a device filter accepts — each with its `key`, `valueType`, allowed operations and live company values — plus the custom fields defined for devices. This is the vocabulary for `getDevices`: use a criterion's `key` as the filter key and one of its `values` inside the clause (`{… - [Set device custom field values in batch](https://docs.getprimo.com/api-reference/devices/set-device-custom-field-values-in-batch.md): Set, overwrite, or clear custom field values across many devices in one call. Provide a list of `items`, each targeting one (deviceId, customFieldId) pair with the `value` to write (null clears it). Each pair must be unique within the batch (duplicates are rejected with 400). Up to 100 items per cal… - [List software on a device](https://docs.getprimo.com/api-reference/devices/list-software-on-a-device.md): Return the paginated list of software installed on ONE device. Supports filtering by vulnerability status, CVSS score range, install availability, and more. For the company-wide catalog of software titles managed by your company (not tied to one device), use `getSoftwares` instead. - [List past activities for a device](https://docs.getprimo.com/api-reference/devices/list-past-activities-for-a-device.md): Return the paginated list of past MDM activities for a device, as reported by the MDM layer. The `details` field is a polymorphic passthrough whose shape varies by activity type. For device lifecycle events recorded by Primo (lock, wipe, retire…), use `getDeviceEvents` instead. - [List upcoming activities for a device](https://docs.getprimo.com/api-reference/devices/list-upcoming-activities-for-a-device.md): Return the paginated list of upcoming (queued) MDM activities for a device. The `details` field is a polymorphic passthrough whose shape varies by activity type. - [List MDM commands for a device](https://docs.getprimo.com/api-reference/devices/list-mdm-commands-for-a-device.md): Return the paginated list of raw MDM protocol commands sent to a device, including their status (ran, pending, failed). Use `getDeviceCommandResults` for the execution results of one command. For a higher-level history, use `getDeviceActivities` (MDM activity feed) or `getDeviceEvents` (Primo lifecy… - [Get results for an MDM command](https://docs.getprimo.com/api-reference/devices/get-results-for-an-mdm-command.md): Return the execution results for a specific MDM command on a device. - [List the saved scripts](https://docs.getprimo.com/api-reference/scripts/list-the-saved-scripts.md): Return your company's saved scripts as JSON — id, name, and the platforms each one can run on. Use this to discover a `scriptId` before calling `runScript` or `runDeviceScript`. - [List script runs](https://docs.getprimo.com/api-reference/scripts/list-script-runs.md): Return the paginated history of script runs, newest first — what was run, on which target, by whom, and how many devices are in each execution status. Use this to answer "what scripts have been run recently?". - [Run a script on a target](https://docs.getprimo.com/api-reference/scripts/run-a-script-on-a-target.md): Run a script on all devices, on one or more device groups, or on an explicit list of devices — intersected with the given platforms. Pass `{ "scriptId": 12 }` to run a saved script (see `getScripts`), or `{ "contents": "..." }` to send the source inline. An inline run may only target a single device… - [Count the devices a script run would reach](https://docs.getprimo.com/api-reference/scripts/count-the-devices-a-script-run-would-reach.md): Return how many devices a run with this target and these platforms would resolve to, using exactly the same resolution as `runScript`. Nothing is executed. Call this before `runScript` to check the blast radius, especially with `target.type = "all"`. - [List the per-device results of a script run](https://docs.getprimo.com/api-reference/scripts/list-the-per-device-results-of-a-script-run.md): Return the paginated executions of one script run — one per targeted device, each with its status, output, exit code and runtime. Use this to see which devices succeeded and read the script output. - [Get a script run](https://docs.getprimo.com/api-reference/scripts/get-a-script-run.md): Return one script run: the script as executed (including its source), the resolved target, and the count of executions in each status. This is the endpoint to poll after `runScript` to follow progress. - [Get a saved script and its source](https://docs.getprimo.com/api-reference/scripts/get-a-saved-script-and-its-source.md): Return one saved script with its full source. Use this to review what a script does before running it. To list the available scripts, use `getScripts`. - [Get all device groups](https://docs.getprimo.com/api-reference/devicegroups/get-all-device-groups.md): Return the list of device groups for your company (id, name). - [Create a device group](https://docs.getprimo.com/api-reference/devicegroups/create-a-device-group.md): Create a device group with a `name` and a `target` filter. `name` must be unique per company — always `GET /device-groups` first to list existing groups and avoid a duplicate (a conflicting name is rejected with 409). Check the target with `validateDeviceGroupTarget` (`POST /device-groups/validate-t… - [Get what uses a device group](https://docs.getprimo.com/api-reference/devicegroups/get-what-uses-a-device-group.md): List the softwares and MDM controls that target this device group. A group can only be deleted once both lists are empty — call this before DELETE to discover (and then remove) what still references it, or to explain a 409. - [Get the device group filter catalog](https://docs.getprimo.com/api-reference/devicegroups/get-the-device-group-filter-catalog.md): Return every criterion (native device attributes plus custom fields) that may target a device group, with its live company values inline. Use this to build a valid device-group target. This is a deliberately narrower set than the device **search** catalog (`getDeviceFilterCatalog`): a group targetin… - [Get a device group by ID](https://docs.getprimo.com/api-reference/devicegroups/get-a-device-group-by-id.md): Return the device group: its `target` filter (the same shape create/update accept) plus the device IDs that filter currently resolves to. Read the `target` here before a PUT to change one field while preserving the rest of the targeting. - [Update a device group](https://docs.getprimo.com/api-reference/devicegroups/update-a-device-group.md): Replace a device group's `name` and `target` filter. Both fields are required — send the full desired state, not a partial patch. `name` must be unique per company (a conflicting name is rejected with 409). Build the `target` from the `GET /device-groups/filters-options` catalog and check it with `v… - [Delete a device group](https://docs.getprimo.com/api-reference/devicegroups/delete-a-device-group.md): Delete a device group by ID. A group that is still targeted by an MDM control or a software is rejected with 409 — call `GET /device-groups/:deviceGroupId/relations` to see what references it and remove those first. An unknown ID returns 404; deleting an already-deleted group is a no-op that still r… - [Check a device group target before creating the group](https://docs.getprimo.com/api-reference/devicegroups/check-a-device-group-target-before-creating-the-group.md): Validate a device group `target` without persisting anything: it reports whether the target is well-formed, whether every criterion is device-group-targetable (build it from `getDeviceGroupFiltersOptions`), and how many devices it currently matches — so a target that is valid but matches nothing is… - [Get all employees](https://docs.getprimo.com/api-reference/employees/get-all-employees.md): Return the list of employees for your company. - [Create an employee](https://docs.getprimo.com/api-reference/employees/create-an-employee.md): Create a new employee in your company. - [Get an employee by ID](https://docs.getprimo.com/api-reference/employees/get-an-employee-by-id.md): Return the employee details for the given employee ID. - [Update an employee](https://docs.getprimo.com/api-reference/employees/update-an-employee.md): Update an employee. Only the provided fields are changed; omitted fields are left untouched. - [Get employee custom fields](https://docs.getprimo.com/api-reference/employees/get-employee-custom-fields.md): Return all Active custom field definitions for the employee, each paired with the current stored value (or null when unset). For SELECT / MULTI_SELECT fields the `options` catalog is included so you can map option ids to labels. - [Hide an employee](https://docs.getprimo.com/api-reference/employees/hide-an-employee.md): Hide an employee from the company directory. Their onboarding and offboarding records are removed. - [Set an employee custom field value](https://docs.getprimo.com/api-reference/employees/set-an-employee-custom-field-value.md): Set or overwrite a custom field value on an employee. Idempotent. Returns the updated field (definition + value). For SELECT supply the option id (string); for MULTI_SELECT supply an array of option ids. Option ids can be read from the `getEmployeeCustomFields` endpoint. - [Clear an employee custom field value](https://docs.getprimo.com/api-reference/employees/clear-an-employee-custom-field-value.md): Remove the stored value for a custom field on an employee. Returns the updated field (value reset to null). - [Unhide an employee](https://docs.getprimo.com/api-reference/employees/unhide-an-employee.md): Make a previously hidden employee visible again in the company directory. - [Send an MDM enrollment request to an employee](https://docs.getprimo.com/api-reference/employees/send-an-mdm-enrollment-request-to-an-employee.md): Trigger the Primo-branded MDM enrollment invitation for the employee. By default it is sent to their work email; set `sendToPersonalEmail` to send it to their personal email instead. - [Get the equipment policy](https://docs.getprimo.com/api-reference/equipmentpolicy/get-the-equipment-policy.md): Return the company equipment policy: the editable draft text, the published text (what the agent sees at runtime, or null if never published), and the publication status. Read this before updating so you can re-send the full, edited body and diff draft against published. - [Get the computed equipment policy result](https://docs.getprimo.com/api-reference/equipmentpolicy/get-the-computed-equipment-policy-result.md): Return the computed equipment policy result: the recommended device and accessory product IDs per country, each country compute status (computing / ready / failed), and whether a policy is set up. The compute is asynchronous and fanned out per country, so a country can be `computing` while others ar… - [Get the purchasing policy](https://docs.getprimo.com/api-reference/purchasingpolicy/get-the-purchasing-policy.md): Return the company purchasing policy: the editable draft text, the published text (what the agent sees at runtime, or null if never published), and the publication status. Read this before updating so you can re-send the full, edited body and diff draft against published. - [Get all accessories](https://docs.getprimo.com/api-reference/accessories/get-all-accessories.md): Return the list of accessories for your company. An accessory can have custom fields (see `getAccessoryCustomFields`). - [Create an accessory](https://docs.getprimo.com/api-reference/accessories/create-an-accessory.md): Create an accessory for your company. - [Get an accessory by ID](https://docs.getprimo.com/api-reference/accessories/get-an-accessory-by-id.md): Return the accessory details for the given accessory ID. - [Update an accessory](https://docs.getprimo.com/api-reference/accessories/update-an-accessory.md): Update an existing accessory for your company. - [Get accessory custom fields](https://docs.getprimo.com/api-reference/accessories/get-accessory-custom-fields.md): Return all Active custom field definitions for the accessory, each paired with the current stored value (or null when unset). For SELECT / MULTI_SELECT fields the `options` catalog is included so you can map option ids to labels. - [Set an accessory custom field value](https://docs.getprimo.com/api-reference/accessories/set-an-accessory-custom-field-value.md): Set or overwrite a custom field value on an accessory. Idempotent. Returns the updated field (definition + value). For SELECT supply the option id (string); for MULTI_SELECT supply an array of option ids. Option ids can be read from the `getAccessoryCustomFields` endpoint. - [Clear an accessory custom field value](https://docs.getprimo.com/api-reference/accessories/clear-an-accessory-custom-field-value.md): Remove the stored value for a custom field on an accessory. Returns the updated field (value reset to null). - [Assign an accessory to an employee](https://docs.getprimo.com/api-reference/accessories/assign-an-accessory-to-an-employee.md): Assign an accessory to an employee. Pass ownerId as null to unassign the current owner. - [Archive an accessory](https://docs.getprimo.com/api-reference/accessories/archive-an-accessory.md): Archive (soft-delete) an accessory. The accessory is unassigned from its current owner and marked as deleted. - [Get all active compliance alerts](https://docs.getprimo.com/api-reference/compliance/get-all-active-compliance-alerts.md): Return the paginated list of active compliance alerts — one per (device, compliance rule) pair currently in a non-compliant status (e.g. not enrolled, offline, disk not encrypted). Each alert carries its device (`deviceId`, `deviceName`, `devicePlatform`, `owner`), its rule (`complianceRuleId`, `rul… - [Get compliance alerts, optionally narrowed by a filter](https://docs.getprimo.com/api-reference/compliance/get-compliance-alerts-optionally-narrowed-by-a-filter.md): Return the paginated list of active compliance alerts, narrowed by a `filter` — THE tool to answer any targeted question about non-compliance ("which macOS devices are not encrypted", "who owns the offline devices"). Send an empty body to list everything. Every `filter` entry is keyed by a `key` fro… - [Get the compliance alert filter catalog](https://docs.getprimo.com/api-reference/compliance/get-the-compliance-alert-filter-catalog.md): Return every criterion a compliance alert filter accepts — each with its `key`, `valueType`, allowed operations and live company values (the devices, platforms and owners that currently have an alert). This is the vocabulary for `searchComplianceAlerts`: use a criterion `key` as the filter key and o… - [Get all compliance alert rules](https://docs.getprimo.com/api-reference/compliance/get-all-compliance-alert-rules.md): Return the list of compliance alert rules configured for your company. Each rule defines which non-compliant device statuses trigger alerts for one compliance type (e.g. MDM_ENROLLMENT, MDM_ONLINE, MDM_CONTROL_ENCRYPTION). To list the devices currently alerting under these rules, use `getComplianceA… - [Create or upsert a compliance alert rule](https://docs.getprimo.com/api-reference/compliance/create-or-upsert-a-compliance-alert-rule.md): Create a compliance alert rule for the given type. Each (company, type) pair is unique — calling this for an existing type overwrites the rule with the provided non-compliant statuses. - [Update a compliance alert rule](https://docs.getprimo.com/api-reference/compliance/update-a-compliance-alert-rule.md): Update the non-compliant statuses of an existing compliance alert rule. Pass an empty array to disable alerts for this rule. - [Get all tasks](https://docs.getprimo.com/api-reference/tasks/get-all-tasks.md): Return a paginated list of tasks (child tickets) for your company. Pass a task id to getTicket to fetch that single task. - [Create a task](https://docs.getprimo.com/api-reference/tasks/create-a-task.md): Create a manual task on an existing ticket. Tasks cannot be added to onboarding tickets (whose tasks are managed automatically). - [Update task status](https://docs.getprimo.com/api-reference/tasks/update-task-status.md): Mark a task as COMPLETED or CANCELLED. Refused on tasks of an onboarding ticket unless the task is a manual SaaS provisioning task — an onboarding step closes by doing its work, not by marking its task done. For the Equipment task of an onboarding, use `executeOnboardingEquipment` instead: it places… - [Update task assignee](https://docs.getprimo.com/api-reference/tasks/update-task-assignee.md): Assign a task to an employee. Provide the parent ticketId in the body. - [Get all tickets](https://docs.getprimo.com/api-reference/tickets/get-all-tickets.md): Return a paginated list of tickets for your company. - [Create a ticket](https://docs.getprimo.com/api-reference/tickets/create-a-ticket.md): Create a ticket for your company. - [Get a ticket by ID](https://docs.getprimo.com/api-reference/tickets/get-a-ticket-by-id.md): Return details for a specific ticket. A task is a child ticket — pass a task id here to fetch a single task. - [Update a ticket](https://docs.getprimo.com/api-reference/tickets/update-a-ticket.md): Partially update a ticket. Only the provided fields are changed (title, description, priority, dueDate, assignee, tags). Use updateTicketStatus to change the status. - [Update ticket status](https://docs.getprimo.com/api-reference/tickets/update-ticket-status.md): Update the status of an existing ticket. - [Update ticket assignee](https://docs.getprimo.com/api-reference/tickets/update-ticket-assignee.md): Assign a ticket to an employee. - [Update ticket priority](https://docs.getprimo.com/api-reference/tickets/update-ticket-priority.md): Update the priority of an existing ticket. - [Create a ticket comment](https://docs.getprimo.com/api-reference/tickets/create-a-ticket-comment.md): Create a comment on a ticket. Comments are INTERNAL by default (team-only, never shown to the requester); pass visibility PUBLIC to post a requester-facing reply. Set taskId to reference the ticket task the comment concerns, and mention people in the text with @[Display Name](employee:)… - [Link a related object to a ticket](https://docs.getprimo.com/api-reference/tickets/link-a-related-object-to-a-ticket.md): Attach a device, employee, identity, order or shipment to the ticket. - [Unlink a related object from a ticket](https://docs.getprimo.com/api-reference/tickets/unlink-a-related-object-from-a-ticket.md): Detach a previously linked object from the ticket, using the linkId returned when listing or linking. - [List subscribers of a ticket](https://docs.getprimo.com/api-reference/tickets/list-subscribers-of-a-ticket.md): Return all subscribers for a specific ticket. - [Add subscribers to a ticket](https://docs.getprimo.com/api-reference/tickets/add-subscribers-to-a-ticket.md): Add one or more subscribers to an existing ticket. - [Remove a subscriber from a ticket](https://docs.getprimo.com/api-reference/tickets/remove-a-subscriber-from-a-ticket.md): Remove a subscriber from an existing ticket. - [List ticket tags](https://docs.getprimo.com/api-reference/tickettags/list-ticket-tags.md): Return all ticket tags defined for your company. Use their ids to tag a ticket or task. - [Create a ticket tag](https://docs.getprimo.com/api-reference/tickettags/create-a-ticket-tag.md): Create a new ticket tag for your company. - [Delete a ticket tag](https://docs.getprimo.com/api-reference/tickettags/delete-a-ticket-tag.md): Delete a ticket tag. It is removed from every ticket and task that carried it. - [Update a ticket tag](https://docs.getprimo.com/api-reference/tickettags/update-a-ticket-tag.md): Rename an existing ticket tag. - [Get all softwares](https://docs.getprimo.com/api-reference/softwares/get-all-softwares.md): Return the list of software titles managed or distributed by your company (the company-wide catalog) with id, name, platform, source, installation type, and target method. To list the software actually installed on a specific device, use `getDeviceSoftware` instead. - [List vulnerabilities](https://docs.getprimo.com/api-reference/softwares/list-vulnerabilities.md): Return the paginated list of CVE vulnerabilities detected across your fleet, with CVSS scores, EPSS probabilities, and host counts. Use `getVulnerability` for one CVE's full details. To list the vulnerable software installed on a single device, use `getDeviceSoftware` with its `vulnerable` filter. - [Get a vulnerability by CVE](https://docs.getprimo.com/api-reference/softwares/get-a-vulnerability-by-cve.md): Return full details for a single CVE vulnerability including affected OS versions and software titles. - [Get a software by ID](https://docs.getprimo.com/api-reference/softwares/get-a-software-by-id.md): Return software details for the given software ID, including targeting details. - [Get all MDM controls](https://docs.getprimo.com/api-reference/mdmcontrols/get-all-mdm-controls.md): Return the list of MDM controls configured for your company — the device policies deployed to your fleet (disk encryption, screen lock, OS restrictions, installed profiles…) — with id, name, type, platform, tags, enabled, and target method. Use `getMdmControl` for one control's full configuration an… - [Create an MDM control](https://docs.getprimo.com/api-reference/mdmcontrols/create-an-mdm-control.md): Create a new MDM control of the given `type` with its `configurationPayload` and targeting. Discover creatable types and their config JSON Schema via GET /mdm-controls/catalog. `name` is optional — when omitted, the catalog default name for the type is used; supply a name to create several controls… - [Get the MDM control type catalog](https://docs.getprimo.com/api-reference/mdmcontrols/get-the-mdm-control-type-catalog.md): Return the catalog of all creatable MDM control types with their name, description, platform, category, activation status, and JSON Schema for the configuration payload. Intended for AI/MCP agents to discover which control types exist and how to configure them. - [Get an MDM control by ID](https://docs.getprimo.com/api-reference/mdmcontrols/get-an-mdm-control-by-id.md): Return MDM control details for the given control ID, including target details and configuration payload. - [Delete an MDM control](https://docs.getprimo.com/api-reference/mdmcontrols/delete-an-mdm-control.md): Delete an MDM control by ID. Removing the control undeploys it from every targeted device. An unknown ID returns 404. Demo companies are not allowed to delete MDM controls (403). - [Update an MDM control](https://docs.getprimo.com/api-reference/mdmcontrols/update-an-mdm-control.md): Partially update an existing MDM control by ID. Send only the fields you want to change — any omitted field is left unchanged. `type` is required and must match the control (it selects the config schema). Editable fields: `name`, `enabled`, `configurationPayload`, and targeting. `configurationPayloa… - [Update an MDM control's tags](https://docs.getprimo.com/api-reference/mdmcontrols/update-an-mdm-controls-tags.md): Replace the full set of tags on an MDM control. Send the complete desired tag list — any existing tag not included is removed. An unknown control ID returns 404. - [Get all billing profiles](https://docs.getprimo.com/api-reference/billingprofiles/get-all-billing-profiles.md): Return the company billing profiles. Use an eligible profile id when creating an order. - [Get all orders](https://docs.getprimo.com/api-reference/orders/get-all-orders.md): Return the list of orders for your company. - [Create an order](https://docs.getprimo.com/api-reference/orders/create-an-order.md): Create a catalog order (V2) for your company — stock replenishment, or equipment bought outside an onboarding. To equip a joiner and close the Equipment step of their onboarding, use `executeOnboardingEquipment` instead: this endpoint places the order without touching the onboarding or its ticket. - [Get an order by ID](https://docs.getprimo.com/api-reference/orders/get-an-order-by-id.md): Return the order details for the given order ID. - [Get order custom fields](https://docs.getprimo.com/api-reference/orders/get-order-custom-fields.md): Return all Active custom field definitions for the order, each paired with the current stored value (or null when unset). For SELECT / MULTI_SELECT fields the `options` catalog is included so you can map option ids to labels. - [Set an order custom field value](https://docs.getprimo.com/api-reference/orders/set-an-order-custom-field-value.md): Set or overwrite a custom field value on an order. Idempotent. Returns the updated field (definition + value). For SELECT supply the option id (string); for MULTI_SELECT supply an array of option ids. Option ids can be read from the `getOrderCustomFields` endpoint. - [Clear an order custom field value](https://docs.getprimo.com/api-reference/orders/clear-an-order-custom-field-value.md): Remove the stored value for a custom field on an order. Returns the updated field (value reset to null). - [Get all SaaS](https://docs.getprimo.com/api-reference/saas/get-all-saas.md): Return the list of SaaS applications for your company, regardless of their approval status. - [Get a SaaS by ID](https://docs.getprimo.com/api-reference/saas/get-a-saas-by-id.md): Return the SaaS details for the given company SaaS application ID. - [Get the issues flagged for a SaaS](https://docs.getprimo.com/api-reference/saas/get-the-issues-flagged-for-a-saas.md): Return the list of provisioning issues currently flagged by the rule on the given SaaS, including missing access, unexpected access, missing/extra group/role/license assignments and orphaned identities. - [Update a SaaS contract](https://docs.getprimo.com/api-reference/saas/update-a-saas-contract.md): Replace the contract configuration for the given SaaS. All prices must be expressed for one billing period defined by `billingFrequency` (not annualized). - [Update a SaaS rule](https://docs.getprimo.com/api-reference/saas/update-a-saas-rule.md): Update the natural-language prompt and/or the lifecycle status of the SaaS rule. Both fields are optional but at least one must be provided. - [Provision a SaaS identity](https://docs.getprimo.com/api-reference/saas/provision-a-saas-identity.md): Provision an employee on a SaaS application with optional group, role, license, and organization unit assignments. - [Deprovision a SaaS identity](https://docs.getprimo.com/api-reference/saas/deprovision-a-saas-identity.md): Remove an employee's identity from a SaaS application. - [Update the owner of a SaaS](https://docs.getprimo.com/api-reference/saas/update-the-owner-of-a-saas.md): Set the owning employee of the given SaaS application. `ownerId` is the ID of an employee in your company. - [Update the approval status of a SaaS](https://docs.getprimo.com/api-reference/saas/update-the-approval-status-of-a-saas.md): Update the approval status of the given SaaS application. - [Add a license to a SaaS](https://docs.getprimo.com/api-reference/saas/add-a-license-to-a-saas.md): Add a new license to the SaaS catalog. Only allowed when the SaaS license capability is set to MANUAL (i.e. a manually-provisioned SaaS). Returns 409 otherwise. - [Rename a license of a SaaS](https://docs.getprimo.com/api-reference/saas/rename-a-license-of-a-saas.md): Rename an existing license. `remoteId` is the entitlement ID returned by `getSaasById`. Only allowed when the SaaS license capability is set to MANUAL (i.e. a manually-provisioned SaaS). Returns 409 otherwise. - [Remove a license from a SaaS](https://docs.getprimo.com/api-reference/saas/remove-a-license-from-a-saas.md): Remove an existing license. `remoteId` is the entitlement ID returned by `getSaasById`. Only allowed when the SaaS license capability is set to MANUAL (i.e. a manually-provisioned SaaS). Returns 409 otherwise. - [Add a role to a SaaS](https://docs.getprimo.com/api-reference/saas/add-a-role-to-a-saas.md): Add a new role to the SaaS catalog. Only allowed when the SaaS role capability is set to MANUAL (i.e. a manually-provisioned SaaS). Returns 409 otherwise. - [Rename a role of a SaaS](https://docs.getprimo.com/api-reference/saas/rename-a-role-of-a-saas.md): Rename an existing role. `remoteId` is the entitlement ID returned by `getSaasById`. Only allowed when the SaaS role capability is set to MANUAL (i.e. a manually-provisioned SaaS). Returns 409 otherwise. - [Remove a role from a SaaS](https://docs.getprimo.com/api-reference/saas/remove-a-role-from-a-saas.md): Remove an existing role. `remoteId` is the entitlement ID returned by `getSaasById`. Only allowed when the SaaS role capability is set to MANUAL (i.e. a manually-provisioned SaaS). Returns 409 otherwise. - [Add a group to a SaaS](https://docs.getprimo.com/api-reference/saas/add-a-group-to-a-saas.md): Add a new group to the SaaS catalog. Only allowed when the SaaS group capability is set to MANUAL (i.e. a manually-provisioned SaaS). Returns 409 otherwise. - [Rename a group of a SaaS](https://docs.getprimo.com/api-reference/saas/rename-a-group-of-a-saas.md): Rename an existing group. `remoteId` is the entitlement ID returned by `getSaasById`. Only allowed when the SaaS group capability is set to MANUAL (i.e. a manually-provisioned SaaS). Returns 409 otherwise. - [Remove a group from a SaaS](https://docs.getprimo.com/api-reference/saas/remove-a-group-from-a-saas.md): Remove an existing group. `remoteId` is the entitlement ID returned by `getSaasById`. Only allowed when the SaaS group capability is set to MANUAL (i.e. a manually-provisioned SaaS). Returns 409 otherwise. - [Add an organization unit to a SaaS](https://docs.getprimo.com/api-reference/saas/add-an-organization-unit-to-a-saas.md): Add a new organization unit to the SaaS catalog. Only allowed when the SaaS organization unit capability is set to MANUAL (i.e. a manually-provisioned SaaS). Returns 409 otherwise. - [Rename an organization unit of a SaaS](https://docs.getprimo.com/api-reference/saas/rename-an-organization-unit-of-a-saas.md): Rename an existing organization unit. `remoteId` is the entitlement ID returned by `getSaasById`. Only allowed when the SaaS organization unit capability is set to MANUAL (i.e. a manually-provisioned SaaS). Returns 409 otherwise. - [Remove an organization unit from a SaaS](https://docs.getprimo.com/api-reference/saas/remove-an-organization-unit-from-a-saas.md): Remove an existing organization unit. `remoteId` is the entitlement ID returned by `getSaasById`. Only allowed when the SaaS organization unit capability is set to MANUAL (i.e. a manually-provisioned SaaS). Returns 409 otherwise. - [Archive a SaaS application user](https://docs.getprimo.com/api-reference/saas/archive-a-saas-application-user.md): Archive (soft-delete) a SaaS application user. The user is removed from active listings but kept for historical reporting. - [Permanently delete a SaaS application user](https://docs.getprimo.com/api-reference/saas/permanently-delete-a-saas-application-user.md): Permanently delete a SaaS application user and its activity history. This is irreversible — prefer `archiveSaasApplicationUser` unless a hard delete is required. - [List catalog countries](https://docs.getprimo.com/api-reference/catalog/list-catalog-countries.md): Return the list of catalog country codes available to your company. - [Search catalog products](https://docs.getprimo.com/api-reference/catalog/search-catalog-products.md): Search the product catalog for a given country. Supports free-text search and filtering by product type, brand, zero-touch deployment support, and stock availability in that country. Variant details are not included — use the get product endpoint for those. - [Get catalog filter options](https://docs.getprimo.com/api-reference/catalog/get-catalog-filter-options.md): Return the available filter option values (brands, ram, storage, screen size, processor, resolution, position) for a country, optionally narrowed to specific product types. - [Get a catalog product](https://docs.getprimo.com/api-reference/catalog/get-a-catalog-product.md): Return the full details of a catalog product for a country, including its variants and per-supplier stock information. - [List shipping countries](https://docs.getprimo.com/api-reference/catalog/list-shipping-countries.md): Return your company's shipping countries with their enablement status. - [List company addresses for a shipping country](https://docs.getprimo.com/api-reference/catalog/list-company-addresses-for-a-shipping-country.md): Return the company's saved addresses in the given shipping country. Use one of these as the shipping address when creating an order. - [Get all shipments](https://docs.getprimo.com/api-reference/shipments/get-all-shipments.md): Return the list of shipments for your company. - [Create a shipment](https://docs.getprimo.com/api-reference/shipments/create-a-shipment.md): Create a new shipment for your company. - [Get a shipment by ID](https://docs.getprimo.com/api-reference/shipments/get-a-shipment-by-id.md): Return the shipment details for the given shipment ID. - [List the company knowledge base items](https://docs.getprimo.com/api-reference/knowledgebaseitems/list-the-company-knowledge-base-items.md): List every knowledge base item (e.g. Skills — reusable instruction packages) owned by the company, with their draft, published text and publication status. Call this to find an item's id before reading, editing or publishing it. Does not include the Equipment or Purchasing policy — use their dedicat… - [Get a knowledge base item](https://docs.getprimo.com/api-reference/knowledgebaseitems/get-a-knowledge-base-item.md): Return a single knowledge base item by id: its editable draft, the published text the agent sees at runtime (or null if never published), and its publication status. Read this before updating so you can show the user the current text. - [Get all onboardings](https://docs.getprimo.com/api-reference/onboardings/get-all-onboardings.md): Return the list of employee onboardings for your company. - [Get an onboarding by ID](https://docs.getprimo.com/api-reference/onboardings/get-an-onboarding-by-id.md): Return the onboarding details for the given onboarding ID. - [Complete onboardings in bulk](https://docs.getprimo.com/api-reference/onboardings/complete-onboardings-in-bulk.md): Close many onboardings for employees already in post in one call. Each one creates the employee from the connected HRIS data if needed and marks the employee active, without executing the remaining onboarding actions (no equipment ordered, no SaaS provisioned). Best-effort and independent: the call… - [Complete an onboarding](https://docs.getprimo.com/api-reference/onboardings/complete-an-onboarding.md): Close an onboarding for an employee already in post: creates the employee from the connected HRIS data if needed and marks the employee active, without executing the remaining onboarding actions (no equipment ordered, no SaaS provisioned). - [Ignore onboardings in bulk](https://docs.getprimo.com/api-reference/onboardings/ignore-onboardings-in-bulk.md): Discard many pending onboardings in one call — cancels each without creating the employee. Best-effort and independent: the call returns 200 with a per-id `results` manifest (`ok` / `error`) — always inspect `results` rather than the HTTP status to detect partial failures. Up to 100 ids per call. - [Ignore an onboarding](https://docs.getprimo.com/api-reference/onboardings/ignore-an-onboarding.md): Discard a pending onboarding: cancels it without creating the employee (the opposite of completeOnboarding, which keeps the employee active). Only pending onboardings can be ignored. - [Execute the equipment step of an onboarding](https://docs.getprimo.com/api-reference/onboardings/execute-the-equipment-step-of-an-onboarding.md): Equip a joiner and close the Equipment step of their onboarding in one call: places the catalog order when `order` is provided, assigns devices and accessories from existing stock when `assignedFromInventory` is provided, then moves the step and its onboarding-ticket task to done and links the order… - [Get all offboardings](https://docs.getprimo.com/api-reference/offboardings/get-all-offboardings.md): Return the list of employee offboardings for your company. - [Get an offboarding by ID](https://docs.getprimo.com/api-reference/offboardings/get-an-offboarding-by-id.md): Return the offboarding details for the given offboarding ID. ## OpenAPI Specs - [openapi](https://docs.getprimo.com/api-reference/openapi.json)