Enable API access
- In Datto RMM, go to Setup → Global Settings.
- Under Access Control, turn on Enable API Access. Keys are created per user. This switch has to be on first, or the API section won’t appear on the user page.

Create a Datto user
- Go to Setup → Users and click Create user. You can generate keys on an existing user instead. A dedicated user named
MSPilotis easier to revoke later. - Enter a Username and Email address. Leave User status set to Active.
- Under Security (this is for the Datto console, not the API keys):
- Leave Component level at the default Low (2) unless this user will log in and work in the Component Library.
- Set Security Levels to administrator.
- Set Default security level to administrator (the list only includes the levels you assigned).
- Click Create user.

Generate API keys
- Open Setup → Users and click the user you just created.
- In the API section, click Generate API Keys. The API fields are hidden until you do this.

- Set API security level to administrator (or another level that can manage sites, devices, and jobs).
- Set API Components level to Super (5). It defaults to Low (2). MSPilot needs a level that can run the enroll component.
- Copy API key, API Secret Key, and note the API URL to a password manager, then click Save User. Datto shows a notice that you cannot retrieve the secret again. Generating keys again invalidates the previous pair.

Connect Datto RMM
- In MSPilot, open Integrations and choose Datto RMM.
- Select the Platform that matches the URL you sign in to Datto RMM with. If your API URL is
https://vidal.rmm.datto.com/..., choose Vidal. - Paste API key and API secret.
- Click Connect Datto RMM.