.png)
Lansweeper Integration Guide
Integrate Lansweeper Cloud inventory and security context with enterprise systems through its GraphQL API, scheduled workflows, and selected webhook-style notifications.
Lansweeper integration options at a glance
Lansweeper Cloud’s primary documented integration mechanism is its GraphQL API, which can be used to query assets, users, locations, software, operating systems, and available vulnerability information. Martini can authenticate requests with a Lansweeper API credential stored in Secrets Management, submit parameterized queries, paginate through large inventories, and map results into target systems. Webhook-style notifications may be available for selected Lansweeper features or alert scenarios, but broad event coverage is not confirmed. A general-purpose REST API, bulk API, file API, and direct database access should not be assumed. Scheduled GraphQL polling is therefore the dependable default for synchronization.
Common Lansweeper integration patterns
Common Lansweeper data objects used in integrations
Authentication and security considerations
Credential protection
Lansweeper Cloud API access uses an API key or bearer-style credential. Store the credential in Martini Secrets Management and inject it into workflow requests rather than embedding it in query definitions or logs.
Least privilege
Use the least-privileged Lansweeper account or API credential available for the required queries. Confirm credential scope, tenant access, available fields, and authorization-header requirements before deployment.
Controlled exposure
If Martini exposes a normalized inventory API or receives a callback, restrict access through appropriate authentication and authorization controls. Do not expose unrestricted user, device, software, or vulnerability data.
- Use environment-specific secrets and rotate credentials according to organizational policy.
- Remove credentials and sensitive inventory fields from diagnostic logs.
- Apply target-specific filtering and privacy rules before forwarding data.
Operational considerations for Lansweeper integrations
Schema and pagination
Treat the active Lansweeper GraphQL schema as authoritative. Confirm field names, relationships, filters, query limits, pagination, and response behavior for the target tenant. Large inventories should be processed in deterministic pages rather than one large query.
Incremental synchronization
Prefer supported updated or last-seen timestamps, cursors, or change filters. When no reliable marker exists, compare stable asset identifiers and relevant values, and define whether missing assets become inactive, retired, quarantined, or deleted.
Reliability
Use bounded retries and exponential backoff for transient failures. GraphQL responses can contain both data and errors, so record affected pages and objects without logging credentials. Store checkpoints only after successful processing.
Testing and change management
Version-control query documents, test against a non-production tenant where possible, and review schema changes as deployment-impacting changes. Normalize time zones, software versions, operating-system labels, and locations before loading target systems.
Why use Martini instead of scripts or point-to-point integrations?
Orchestrate beyond a script
Martini coordinates Lansweeper extraction, pagination, transformation, validation, enrichment, target delivery, and synchronization state in maintainable workflows rather than concentrating all logic in a one-off script.
Control the data contract
Martini can expose a normalized REST API so downstream applications do not need to understand Lansweeper’s GraphQL schema or receive direct access to Lansweeper credentials.
Handle enterprise conditions
Reusable workflows can apply idempotency, reconciliation, privacy filtering, retries, partial-failure handling, and controlled checkpoints across multiple target systems.
- Keep credentials and environment settings separate from implementation logic.
- Reuse mappings and business rules across CMDB, service-management, reporting, and analytics flows.
- Monitor workflow outcomes and troubleshoot failed pages or records without replaying successful work unnecessarily.