Skip to content
All guidesSecurity & asset platforms

Connect runZero (network discovery)

runZero's read-only Export token brings every network-discovered device into Cybermatic — with end-of-life and missing-device findings.

  1. 1Part 1 — Confirm runZero has asset data. Before creating the token, make sure runZero has completed at least one discovery scan. 1. Sign in to the runZero Console. 2. In the upper-right organization selector, make sure you are working in the organization whose assets you want Cybermatic to ingest. runZero keeps assets, scans, sites, and related data isolated by organization. 3. Go to Inventory → Assets. 4. Confirm that you see devices/assets listed.
  2. 2Part 2 — Get the runZero Export token. This is the important runZero portion of the Cybermatic setup. Step 1 — Open Organizations: in runZero, go to Global Settings → Organizations. You should see your organizations listed by name, for example: Corporate IT Production Lab Choose the organization containing the assets you want Cybermatic to receive. Step 2 — Open the organization: click the organization name, for example Corporate IT. This opens the organization's detail page. Step 3 — Click Edit organization on the organization detail page. Do not go to the regular user API-key area. Cybermatic needs an Export token, not an Organization API token. Step 4 — Find Export tokens: scroll down until you find the Export tokens section. Step 5 — Generate an Export token: if no suitable token exists, select the option to Generate export token. Step 6 — Copy the token. A runZero Export token is identified by an ET prefix. It is tied to a specific organization and can only use runZero's Export API; it cannot access the read/write Organization API. It should resemble: ET****************************** (the characters follow ET directly). Do not paste the token into Teams, Slack, tickets, email, documentation, or source code. Put it temporarily in your organization's approved password manager/secrets vault until you enter it into Cybermatic.
  3. 3Part 3 — Connect runZero to Cybermatic. Now leave runZero and go to Cybermatic. 1. Sign in to Cybermatic. 2. Open Connections. 3. Find the Asset platforms section. 4. Select runZero. 5. Find the Export token field. 6. Paste the ET… token you copied. 7. Click Connect. Cybermatic only needs runZero's Export API for this type of inventory ingestion. This API gives read-only access to organization data such as assets, sites, and scans.
  4. 4What Cybermatic checks. • Removed at the source? Devices you delete in runZero disappear from Cybermatic automatically on the next scan. • Every discovered device joins your asset inventory — visible alongside cloud assets, filterable by source. • End-of-life operating systems (Windows 7, 8, 10, Server 2008/2012, and others past vendor support) — a High finding, since these receive no security updates and are common ransomware entry points. • Devices not seen by runZero in over 30 days — a Medium finding, since unaccounted-for hardware can hold company data outside your control. Device risk shows directly on the Assets page: High for end-of-life systems, Medium for missing devices, Low otherwise.
  5. 5Troubleshooting. "the Export token was rejected (401/403)" — the token was rotated or deleted in runZero; copy the current ET… token from Edit organization → Export tokens and use Connections → Update credentials. "Paste the runZero Export token — it starts with ET" — the pasted value isn't an Export token. Organization tokens (OT…) and Account tokens (CT…) are different credentials with broader rights; Cybermatic deliberately accepts only the read-only Export token. No devices appear — runZero exports what its scans have discovered; run a scan in runZero first (their Explorer must be deployed on the network you want mapped), then Scan now in Cybermatic. Asset counts look low — Cybermatic imports up to your plan's asset limit per scan; if your runZero inventory is larger, the highest-signal devices still surface in findings. Devices appear but no findings — that's a good result: nothing end-of-life and everything appearing in recent scans.

Tip: runZero's superpower is finding what nothing else can: the device with no agent, no login, and no owner. Its free Community Edition covers up to 256 assets — most small businesses can run it at no cost and feed Cybermatic a complete network picture.

More in Security & asset platforms