> ## Documentation Index
> Fetch the complete documentation index at: https://docs.getprimo.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Bastion

> Connect Bastion to Primo with a read-only Primo API key so it can check the security settings of your Mac, Windows, and Linux devices.

## Platform compatibility

| macOS | Windows | Linux | iOS / iPadOS | Android |
| - | - | - | - | - |
| ✅ | ✅ | ✅ | | |

<Info>
  **Data flow: one-way, read by Bastion**

  Bastion reads your device data through the Primo API with a read-only key. Primo pushes nothing to Bastion, and no Bastion data appears in the cockpit.
</Info>

Bastion surfaces the security settings of your Mac, Windows, and Linux devices for its compliance checks. The integration is configured in Bastion, not in the cockpit. On the Primo side, you only create the API key Bastion uses to read your devices.

Which settings Bastion checks, how often it collects them, and how it maps them to its controls is documented by Bastion.

## Prerequisites

* A Primo MDM plan with device management configured.
* Access to **Settings > Developers** in the cockpit, to create the key.
* Administrator access to your Bastion account.

## Create a read-only Primo API key

<Steps>
  <Step title="Open the Developers settings">
    Go to **Settings > Developers** and click **Create key**.
  </Step>

  <Step title="Configure the key">
    * **Key name** — for example `Bastion`.
    * **Access level** — **Read-only**. Bastion only reads data, so it never needs write access.
    * **Expiration (days)** — leave empty for a key that never expires, or set a number of days and plan to rotate the key in Bastion before then.
  </Step>

  <Step title="Copy the secret">
    Click **Create key**, then **Copy secret**. The secret is shown only once.
  </Step>
</Steps>

<Warning>
  Treat the secret as a password. Anyone who holds it can read your Primo data through the API.
</Warning>

## Connect the key in Bastion

In your Bastion account, open the Primo integration, choose the Primo API key mode, and paste the secret. Complete the connection there. Bastion then collects your device data on its own schedule.

To check that Bastion is reading data, open **Recent Primo API logs** in **Settings > Developers**: its requests appear with the last characters of the key.

## Disconnect Bastion

Go to **Settings > Developers**, find the key in **Primo API keys**, and click **Revoke**. Bastion loses access immediately, and the key cannot be restored. To reconnect, create a new key and paste it in Bastion.

## Troubleshooting

**Bastion stopped receiving device data**

* In **Primo API keys**, check the key's **Status** and **Expires** columns. A revoked or expired key stops working at once.
* Create a new key and update it in Bastion.

**A device is missing in Bastion**

* Check its platform. Bastion covers macOS, Windows, and Linux devices.
* Check that the device is enrolled and reports to the cockpit. Bastion only sees devices Primo knows about.

## Related articles

* [Create API keys for Primo](/api/create-primo-api-key)
* [Vanta](/mdm/integrations/vanta)
* [Compliance overview](/mdm/compliance/overview)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.