# Kandji MCP for AI Agents AI Agent Connect

> Kandji MCP lets you manage your Apple device fleet through your AI agent. It connects directly to the Kandji MDM API so you can audit devices, check security settings, and manage blueprints without switching tabs. It's built for IT teams who need to handle macOS and iOS management at scale without the manual overhead of clicking through a web console. It's the fastest way to get fleet visibility.

## Overview
- **Category:** security-compliance
- **Price:** Free
- **Endpoint:** https://edge.vinkius.com/vk_preview_47dZOrq6axzqY7N6eKozgF7QiUAy4WTru8MRILv1/ai-agent-connect
- **Tags:** mdm, apple-device-management, fleet-security, it-automation, macos-management, ios-security

## Description

Kandji MCP lets you manage your Apple device fleet through your AI agent. It connects directly to the Kandji MDM API so you can audit devices, check security settings, and manage blueprints without switching tabs. It's built for IT teams who need to handle macOS and iOS management at scale without the manual overhead of clicking through a web console. Managing a fleet of Macs and iPhones is a headache when you're constantly jumping between browser tabs to check security statuses or verify software deployments. You need a way to pull that data into a single flow. This Connector gives your AI agent direct access to your Kandji environment. Instead of hunting for a specific device's security parameters or digging through logs to see who changed a policy, you just ask your agent to do it for you. It handles the heavy lifting of querying the API, whether you're looking for a list of all managed devices, checking on specific app deployments, or auditing recent administrative actions. You can see how your fleet is organized through blueprints and keep tabs on who's actually using the hardware. It's one of the many ways the Vinkius catalog makes it easy to bridge the gap between your management tools and your daily workflow. You'll get real-time status updates on your security posture and device health without the usual friction of a manual dashboard. This means you can spend less time on data entry and more time on actual security.

## Tools

### list_activity
Lists recent management activity logs. This is perfect for auditing who changed what and when.

### get_device
Pulls deep-dive auditing data for a single specific asset. Use this to check a device's health or specs instantly.

### get_organization
Retrieves your organization's identity details. It's the quickest way to verify your account connection.

### list_devices
Returns a full list of device names, IDs, and OS versions. Use this for a high-level fleet audit.

### list_parameters
Lists all library parameters and policies. It's the best way to see your current security controls.

### list_users
Lists all users tied to your managed devices. Use this to quickly identify who owns which piece of hardware.

### list_auto_apps
Lists all Kandji Auto Apps in your library. This helps you audit your standard software deployments.

### list_blueprints
Lists all device blueprints. Use this to see how your fleet is categorized and organized.

### list_commands
Lists recent MDM commands like Lock, Wipe, or Restart. It's essential for auditing remote actions.

### list_custom_apps
Lists all custom applications in your account. Use this to audit non-store software deployments.

## Prompt Examples

**Prompt:** 
```
How many Macs do we have on macOS 12 or older?
```

**Response:** 
```
| Device Name | OS Version | Status |
| :--- | :--- | :--- |
| Marketing-MacBook-04 | macOS 12.6 | Enrolled |
| Sales-MacBook-12 | macOS 12.7 | Enrolled |
| HR-MacBook-01 | macOS 12.5 | Enrolled |

**Total:** 3 devices found on older OS versions.
```

**Prompt:** 
```
Show me the last 5 commands sent to devices.
```

**Response:** 
```
Here are the last 5 MDM commands sent to your fleet:

* **Lock** - MacBook Pro (ID: 8821) - 10:45 AM
* **Restart** - iMac (ID: 4432) - 09:30 AM
* **Wipe** - iPhone 13 (ID: 1120) - 08:15 AM
* **Lock** - MacBook Pro (ID: 9901) - 07:50 AM
* **Restart** - MacBook Air (ID: 3321) - 07:20 AM
```

**Prompt:** 
```
Who are the users for our managed hardware?
```

**Response:** 
```
Here are the primary users associated with your managed devices:

* **Sarah Jenkins** (Marketing)
* **Mark Thompson** (Sales)
* **Elena Rodriguez** (HR)
* **James Chen** (Engineering)
```

## Capabilities

### Fetch device details
Get full specs and security data for any specific asset in your fleet.

### Audit management activity
See a history of recent administrative changes and system events.

### List all managed devices
Pull a complete inventory of every Apple device enrolled in your account.

### Inspect security parameters
View all library policies and security controls currently in use.

### Identify device owners
Retrieve a list of all users associated with your managed hardware.

### Review software libraries
See all Auto Apps and custom software deployments across the fleet.

### View device blueprints
Understand how your hardware is categorized and configured.

## Use Cases

### Security Audit
A security lead needs to check if all devices are using the latest security parameters. They ask the agent to list all parameters and highlight any that aren't updated.

### Rapid Inventory
An IT tech needs to know how many Macs are on a specific OS. They ask the agent to list all devices and filter by version.

### Troubleshooting
An admin wants to see what happened to a device that was wiped. They ask the agent to list recent commands and activity to find the specific action.

### Software Review
A manager wants to see every custom app currently in the library. They ask the agent to list custom apps and summarize the software types.

## Benefits

- Stop manual inventory: Use list_devices to get a full count of your fleet in seconds instead of scrolling through a web table.
- Faster security audits: Use list_parameters to quickly check your current policies and ensure they meet compliance standards.
- Clearer admin logs: Use list_activity to see exactly what changes were made to your environment without digging through nested menus.
- Easy owner identification: Use list_users to map hardware to people instantly, making it easier to manage permissions and hardware handoffs.
- Better app oversight: Use list_auto_apps and list_custom_apps to keep a clean eye on every piece of software you've deployed.

## How It Works

The bottom line is you get a direct line to your fleet data without the manual overhead of the web console.

1. Connect your Kandji API credentials to the Connector via the Vinkius dashboard.
2. Open your preferred AI client and point it toward the Kandji connection.
3. Ask your agent to perform tasks like listing all Macs with old OS versions or checking the last 10 admin actions.

## Frequently Asked Questions

**Can Kandji MCP help me audit my Apple devices?**
Yes, it allows your AI agent to pull a full list of your managed devices and check their specific status, OS version, and security parameters instantly.

**How do I see my Kandji blueprints with an AI agent?**
You can simply ask your agent to list your blueprints. It will retrieve the organization of your fleet so you can understand how devices are categorized.

**Can I check my Kandji security parameters using an AI?**
Yes, the Connector provides direct access to your library parameters. You can ask your agent to verify if your current security controls meet your company's requirements.

**How do I list all my managed Apple devices?**
Just ask your agent to list all managed devices. It will return a clean inventory of device names, IDs, and OS versions across your entire fleet.

**Can I see recent admin activity in Kandji through an agent?**
Yes, you can query the recent management activity. This helps you see who made changes to your environment and when those actions occurred.

**Does Kandji MCP support custom app auditing?**
It does. You can use your agent to list all custom applications in your library to keep track of non-store software deployments across your hardware.

**How do I get Kandji API credentials?**
Log in to your Kandji account, navigate to Settings > Access > API Token, and generate a new token. You also need your tenant's API URL.

**What is the API URL?**
The API URL is specific to your Kandji instance (e.g., https://yourtenant.api.kandji.io). You can find this in your Kandji API settings.

**Can I see remote commands?**
Yes, the list_commands tool allows you to retrieve a history of MDM commands sent to your managed devices.