An RMM with an API you can actually use
Most RMMs treat the API as an enterprise upsell, a support ticket, or a PDF from 2019. RFF ships a documented REST API on every plan, including the free one, because a tool that can’t talk to the rest of your stack isn’t really managing your fleet - it’s just another console to check.
Start free → · 100 endpoints · API included
What people build with it
- CMDB sync. Push live hardware, OS, and installed-software inventory into ITGlue, Hudu, or your own database - so your documentation is generated, not maintained by hand.
- Dashboards. Feed Grafana or a client-facing status page with patch compliance, disk health, and check state.
- Compliance evidence. Export BitLocker, Secure Boot, firewall, and local-admin posture on a schedule, ready for an auditor.
- Ticket enrichment. When a ticket arrives, pull that machine’s inventory, recent changes, and open alerts into the ticket automatically.
- Onboarding automation. Create deployment jobs from whatever already triggers your onboarding process.
Authentication in one line
Keys are minted in Settings → API keys and sent as a header:
curl https://api.getrff.com/api/targets \
-H "X-Api-Key: rff_live_xxxxxxxxxxxxxxxx"
That’s it. No OAuth dance, no token refresh, no SDK required.
Built with the blast radius in mind
An API key for a fleet-management tool is a serious credential, and we designed it as one rather than bolting it on:
- Read-only by default. Write access - which includes creating jobs, and a job runs code as SYSTEM on the machines it targets - is a separate, deliberate opt-in with a plain warning at creation. Most integrations only ever need to read.
- We tell you what a read key exposes. It can’t change anything, but it can read your full inventory: hostnames, installed software, unpatched vulnerabilities, local admins. That’s a useful map to an attacker, and the UI says so instead of calling read-only “safe.”
- Every action is attributed. A job created by an integration is stamped with which key created it in the audit log, so it’s never mistaken for a human operator. Same treatment we give impersonated and partner-delegated actions.
- Expiry is enforced, not decorative. Set a key to expire in 90 days and the server refuses it on day 91.
- Revocation is instant, and revoked keys are kept - so an audit entry from six months ago still resolves to the integration that caused it.
- Keys are stored hashed. We can’t show you the key again, because we don’t have it.
Pricing
Included on every tier, free included. Rate limits scale with your plan (60/120/600 requests per key per minute for Free/Starter/MSP); access doesn’t. We charge for the number of machines you manage, not for the ability to connect RFF to your own systems.
Reference
Full endpoint documentation, request and response schemas, and a live try-it console:
Questions
Is the API on the free tier? Yes. Every operational feature is free to 100 endpoints, and the API is an operational feature.
Do you have a ConnectWise / Autotask / Halo integration? Not a prebuilt one. We publish a documented REST API instead, so you (or your PSA’s automation layer) can wire the two together. If a specific integration keeps coming up, tell us - that’s how it gets built.
Is there a webhook / push option? Check alerts already POST to a webhook of your choice (Slack, Teams, or your own endpoint). Broader event webhooks are on the roadmap.
Rate limits?
Per key, per minute, scaled by plan: 60 on Free, 120 on Starter, 600 on MSP. Every response carries X-RateLimit-Limit and X-RateLimit-Remaining; exceed it and you get a clear 429 with a Retry-After header and a JSON body, never a silent drop. Access is identical on every tier - only the ceiling moves.