Skip to main content
This guide walks you through connecting your Huntress account to Clarion. Huntress provides endpoint detection and response (EDR) data that Clarion uses to enrich alert triage with real endpoint intelligence.
Estimated time: 5 minutes. You will need Huntress Admin access.

Prerequisites

  • Access to your Huntress Dashboard as an admin
  • A Clarion workspace with the Huntress integration wizard open

Step 1 — Generate API Credentials in Huntress

  1. In the Huntress dashboard, click the menu button in the upper-right corner.
  1. Select API Credentials.
  2. In the User API Credentials section, click Add.
  1. Select the appropriate user and copy the generated API Key and API Secret
Copy the API Secret immediately — it will only be shown once. Store it securely.

Step 2 — Enter Credentials in Clarion

  1. In Clarion, open the Huntress integration from your workspace settings
  2. Paste the API Key and API Secret from Huntress
  3. Click Save to activate the integration

Step 3 — Set up webhook alerts (optional)

Webhooks let Huntress push Incident Reports and Escalations to Clarion in real time, where they become alerts and flow through automated triage.
Configuring webhooks in Huntress requires the account admin role.
  1. In Clarion, open the connected Huntress integration and find the Webhook alerts section. Copy the Webhook URL.
  2. In the Huntress dashboard, go to Integrations → Add an Integration → Webhooks and click Add Endpoint.
  3. Paste the Clarion Webhook URL as the destination URL.
  4. Enable only the Incident Reports and Escalations categories.
  5. Open the endpoint’s menu and choose View Signing Secret. Copy it.
  6. Back in Clarion, paste the signing secret into the Signing secret field and click Save.
  7. In Huntress, use the endpoint’s Send Test option to confirm Clarion receives deliveries.

What happens next

Once configured, Clarion will:
  • Query Huntress for endpoint data during alert triage (e.g. matching IP addresses to known managed endpoints)
  • Use EDR context to validate or dismiss suspicious sign-in alerts from other integrations (e.g. Okta)
  • Provide agents with visibility into which devices are protected and their current status
  • Turn incoming Incident Report and Escalation webhooks into alerts and run automated triage on them (if webhooks are configured)