Skip to main content
This guide walks you through connecting your Huntress account to Clarion. Huntress provides endpoint detection and response (EDR) data that Clarion uses to enrich alert triage with real endpoint intelligence.
Estimated time: 5 minutes. You will need Huntress Admin access.

Prerequisites

  • Access to your Huntress Dashboard as an admin
  • A Clarion workspace with the Huntress integration wizard open

Step 1 — Generate API Credentials in Huntress

  1. In the Huntress dashboard, click the menu button in the upper-right corner.
  1. Select API Credentials.
  2. In the User API Credentials section, click Add.
  1. Select the appropriate user and copy the generated API Key and API Secret
Copy the API Secret immediately — it will only be shown once. Store it securely.

Step 2 — Enter Credentials in Clarion

  1. In Clarion, open the Huntress integration from your workspace settings
  2. Paste the API Key and API Secret from Huntress
  3. Click Connect to activate the integration
Clarion checks the credentials against Huntress before saving them, so a mistyped key or secret is reported straight away instead of failing quietly later.

Step 3 — Choose the organization

Huntress only issues API credentials at the account level. If you are an MSP, that means a single key can read every client organization in your account — so Clarion asks which one this workspace represents.
  1. In the connected Huntress integration, find the Organization section.
  2. Open the picker and search by the client’s name as it appears in Huntress. The list is not ordered to match your Clarion workspace names, so searching is usually faster than scrolling.
  3. Select the organization and click Save.
Once an organization is set, Clarion restricts everything Huntress-related to that client: incident polling, webhook events, and the Huntress data available to triage agents.
If you are a direct Huntress customer rather than an MSP, leave this set to Entire account (all organizations) — the default.
Changing the organization restarts ingestion for the new scope, picking up its currently open incidents. Alerts already created for the previous organization are left untouched.

Step 4 — Set up webhook alerts (optional)

Webhooks let Huntress push Incident Reports and Escalations to Clarion in real time, where they become issues and flow through automated triage.
Configuring webhooks in Huntress requires the account admin role.
  1. In Clarion, open the connected Huntress integration and find the Webhook alerts section. Copy the Webhook URL.
  2. In the Huntress dashboard, go to Integrations → Add an Integration → Webhooks and click Add Endpoint.
  3. Paste the Clarion Webhook URL as the destination URL.
  4. Enable only the Incident Reports and Escalations categories.
  5. Open the endpoint’s menu and choose View Signing Secret. Copy it.
  6. Back in Clarion, paste the signing secret into the Signing secret field and click Save.
  7. In Huntress, use the endpoint’s Send Test option to confirm Clarion receives deliveries.

What happens next

Once configured, Clarion will (within the organization you selected):
  • Query Huntress for endpoint data during triage (e.g. matching IP addresses to known managed endpoints)
  • Use EDR context to validate or dismiss suspicious sign-in alerts from other integrations (e.g. Okta)
  • Provide agents with visibility into which devices are protected and their current status
  • Turn incoming Incident Report and Escalation webhooks into issues and run automated triage on them (if webhooks are configured)