Skip to content
All guidesSecurity & asset platforms

Connecting Rapid7 to Cybermatic

Generate an Organization Admin Key, identify your Data Storage Region, and connect — scanned hosts and CVE findings flow into Cybermatic.

  1. 1Step 1 — Sign in to Rapid7. Go to the Rapid7 Command/Insight Platform and sign in with your account. Once logged in, make sure you are at the main Platform Home rather than inside only the InsightVM Security Console.
  2. 2Step 2 — Open API Key Management. From the Rapid7 Platform Home: Left navigation → Administration → API Key Management Rapid7 currently documents this exact navigation path. You should see areas for Organization Keys and User API Keys.
  3. 3Step 3 — Generate the Organization Key. Go to: API Key Management → Organization Keys Then select: Generate New Admin Key → Organization Admin Key Rapid7 will open a panel asking you for the organization and key name. Select the Rapid7 organization containing the InsightVM data that Cybermatic needs to retrieve. For the name, enter: Cybermatic Scanner Then select Generate.
  4. 4Step 4 — Copy the key immediately. Rapid7 will display the generated API key. Copy it immediately. Rapid7 specifically warns that once you close or navigate away from that window, you cannot retrieve the actual key again. Store it directly in your approved secrets system. Do not put the key into email, Teams/Slack, ServiceNow/Jira tickets, documentation, or chat messages. If the key is lost, revoke it and generate a replacement.
  5. 5Step 5 — Find your Rapid7 region. Don't rely only on whether the login URL has a prefix. Rapid7 provides a more reliable way. Return to the Platform Home. If necessary, on the upper-left, click on the settings image and then choose Company Settings. Click on Organizational Settings. Look for: Data Storage Region Rapid7 documents that this identifies the data center assigned to your organization. Use this mapping: United States - 1 → us United States - 2 → us2 United States - 3 → us3 Europe → eu Canada → ca Australia → au Japan → ap
  6. 6Step 6 — Enter the information in Cybermatic. Now you should have exactly two pieces of information: API Key: the Cybermatic Scanner key you just generated Region: for example us, us2, us3, eu, etc. In Cybermatic: Connections → Security & asset platforms → Rapid7 InsightVM Enter: Insight Platform API key: your newly generated key Region: the Rapid7 region code you identified Then select Connect. The first scan starts immediately.
  7. 7What Cybermatic checks. • Removed at the source? Devices you delete in InsightVM disappear from Cybermatic automatically on the next scan. • Every InsightVM-scanned host joins your asset inventory, risk-rated from its vulnerability counts (any critical → Critical, any severe → High, any moderate → Medium). • Vulnerability findings grouped by CVE with severity, CVSS score, affected hosts, and InsightVM's solution summary where available. • Volume control: Medium severity and above, capped to the highest-severity 300. Vulnerabilities are owned by their source: each closes automatically when InsightVM no longer reports it — typically after patching.
  8. 8Troubleshooting. "the API key was rejected (401/403)" — the key was revoked or isn't an Insight Platform key. Platform keys come from insight.rapid7.com → Settings → API Keys — not from the InsightVM Security Console's local users. "endpoint not found (404) — this usually means the region is wrong" — re-check the region prefix in your console URL and update it via Connections → Update credentials. No assets appear — the API returns what InsightVM's scans have assessed; run a scan in InsightVM first, then Scan now in Cybermatic. Vulnerabilities without affected-host names — some InsightVM data shapes report findings without per-asset linkage; the finding still lists severity, CVSS, and solution, marked "Reported across scanned assets".

Tip: The Organization Key isn't tied to a person, so it survives staff changes. And the Data Storage Region page beats guessing from URLs — a wrong region is the most common cause of a 404 at connect time.

More in Security & asset platforms