Connect Lansweeper (asset inventory)
A read-only Personal Access Token brings your on-prem device inventory into Cybermatic — with end-of-life and missing-device findings.
- 1Part 1 — Confirm you are in the correct Lansweeper environment. Go to the Lansweeper Platform/Cloud site and sign in with the account that has access to the site containing the devices you want Cybermatic to assess. Before creating anything, open the Lansweeper site and confirm you can actually see the servers, workstations, printers, network devices, etc. that you expect Cybermatic to ingest.
- 2Part 2 — Open Developer Tools. After signing in: 1. Click your profile/account icon. 2. Click on Account Settings. 3. Select Developer Tools. 4. Look for All API Clients or API Clients. 5. Click Create API client.
- 3Part 3 — Select the correct API client type. On the Add new API client screen: 1. Choose Personal Access Token (PAT). 2. Click Continue.
- 4Part 4 — Name the API client. For Name, enter: Cybermatic Scanner For Integration, choose: Other For Custom Integration Name, enter: Cybermatic For the description, we recommend: Read-only inventory access for Cybermatic security posture scanning. The description is primarily administrative — it helps someone looking at Lansweeper later understand why the token exists. Then click Continue.
- 5Part 5 — Choose the token expiration. Lansweeper will ask you how long the Personal Access Token should remain valid. You may choose Specific Day (subject to the maximum period allowed by your company policy) or No Expiration. If you use an expiring token, record the expiration date in your credential/secrets-management system, because Cybermatic will stop retrieving Lansweeper data after the token expires.
- 6Part 6 — This is the critical step: grant access to the Lansweeper site. You should now see the Lansweeper sites your account can access, for example: ☐ Production ☐ Corporate IT ☐ Lab ☐ Acquired Companies Check the site (or sites) containing the inventory you want Cybermatic to assess, for example: ☑ Corporate IT Move the checked sites from Available to Selected. (The Add all button moves every site — use it only if Cybermatic should access all of them.) Lansweeper explicitly requires you to choose which sites the Personal Access Token can access during token creation. Do not skip this step. A valid token without authorization to the intended Lansweeper site can still produce an access/authorization failure.
- 7Part 7 — Finish creating the token. After choosing the site or sites: 1. Click Create. 2. Lansweeper will generate the API Token / Personal Access Token. 3. Copy it immediately. This is important: Lansweeper states that the generated API token will not be shown again after you leave the screen. It will look like a long credential string.
- 8Part 8 — Store the token securely. Put the PAT into your organization's approved: • password manager, • privileged credential manager, • secrets vault, or • enterprise secrets-management platform. Treat it like a password.
- 9Part 9 — Record the exact Lansweeper site name. Before leaving Lansweeper, write down the exact site name you selected. For example: Corporate IT Pay attention to capitalization, spaces, hyphens, etc. If you gave Cybermatic's token access to only one site, the Site name field can remain blank. If you authorized multiple Lansweeper sites, we recommend explicitly entering the intended site name in Cybermatic rather than relying on "first available site".
- 10Part 10 — Connect Lansweeper in Cybermatic. 1. Sign in to Cybermatic. 2. Open Connections. 3. Find Asset platforms. 4. Select Lansweeper. 5. In Personal Access Token, paste the Lansweeper PAT. 6. For Site name: If the PAT has access to one Lansweeper site, leave it blank. If the PAT has access to multiple sites, enter the exact Lansweeper site name you recorded earlier. 7. Click Connect.
- 11Part 11 — Verify the connection. After clicking Connect, go to: Cybermatic → Assets. You should start seeing Lansweeper-discovered devices. Look for: Server Workstation Printer Network Device Other discovered assets and confirm that the source/tag is: Lansweeper
- 12What Cybermatic checks. • Removed at the source? Devices you delete in Lansweeper disappear from Cybermatic automatically on the next scan. • Every discovered device joins your asset inventory — visible alongside cloud assets, filterable by source. • End-of-life operating systems (Windows 7, 8, 10, Server 2008/2012, and others past vendor support) — a High finding, since these receive no security updates and are common ransomware entry points. • Devices not seen by Lansweeper in over 30 days — a Medium finding, since unaccounted-for hardware can hold company data outside your control. Device risk shows directly on the Assets page: High for end-of-life systems, Medium for missing devices, Low otherwise.
- 13Troubleshooting. "the Personal Access Token was rejected (401/403)" — the token expired or was revoked; create a new one under Settings → Developer tools and use Connections → Update credentials. "the token isn't authorized for this site" — when the API client was created, the site wasn't granted. Edit the client in Developer tools and check the site under its access grants. "no authorized site named …" — the site name entered in Cybermatic doesn't match any site the token can access; the error lists the sites it can see. Match the name exactly, or leave the field blank. Asset counts look low — Cybermatic imports up to your plan's asset limit per scan; if your Lansweeper inventory is larger, the highest-signal devices still surface in findings. Upgrade for a higher asset ceiling. Devices appear but no findings — that's a good result: nothing end-of-life and everything reporting recently.
Tip: Part 6 is where nearly every failed setup goes wrong: the token is valid but was never granted the site. If the connection errors with an authorization failure, come back to the API client and check its site grants first.