Trellix EDR uses OAuth 2.0 client credentials plus a tenant-scoped API key. Collect the API key and client credentials from the Trellix Developer Portal, grant the required scopes when you create the credential, and copy the tenant ID from IAM Tenant Settings.

## Prerequisites

API access depends on **both** your Trellix license entitlements and the OAuth scopes on the client credential. Scopes alone do not unlock operations your tenant is not licensed for.

| License / product area | Operations available | Related scope(s) |
|  --- | --- | --- |
| **EPO** (endpoint management) | Query managed devices | `epo.device.r` |
| **Trellix EDR** | Query threat events and alerts; quarantine and unquarantine hosts; realtime searches | `soc.act.tg`, `soc.rts.c`, `soc.rts.r` |


A tenant licensed for **EPO only** can query devices. Threat, alert, remediation, and realtime search operations require a **Trellix EDR** license — **Trellix EDR Foundation (EDRF)** is the recommended minimum entitlement. Without EDR, those scopes may be unavailable in Client Credentials, and API calls for those operations return not authorized even if a scope is granted.

## 1. Collect credentials

You need four values: **API Key**, **Client ID**, **Client Secret**, and **Tenant ID**. The API key is tenant-scoped — it is not in the ePO or EDR product dashboard.

### Step 1: Copy the API key

1. Log in to the [Trellix Developer Portal](https://developer.manage.trellix.com) (the developer portal)
2. Click **Self Service**
3. Under **API Access Information**, click **Configure**
4. Copy the value under **API Key Information**


The same key also appears as **Trellix API Key** at the top of the Client Credentials page in the next step.

### Step 2: Create client credentials

1. On the API Access Information page, click **Generate Client Credentials**. This opens [Client Credentials Management](https://uam.ui.trellix.com/clientcreds.html)
2. Click **Add**
3. Give the credential a description
4. Select **all** required scopes listed under [scopes](#2-add-scopes) — scope selection is configured at credential creation
5. Click **Create**, then save the generated **Client ID** and **Client Secret**. The secret is shown once.


If a licensed product's scopes are missing from the list, request them from the Developer Portal first.

### Step 3: Copy the tenant ID

1. Log in to the [Trellix IAM dashboard](https://auth.ui.trellix.com/dashboard.html) (the tenant)
2. Click the profile icon in the top right and select **Tenant Settings**
3. Copy **Tenant Id** from **Tenant Information**


## 2. Add scopes

Grant **all** scopes in the table below on the client credential. Each scope maps to operations described in [Prerequisites](#prerequisites). Trellix checks license entitlements and scopes on every API call — missing either one causes that operation to be rejected as **not authorized**.

In **Client Credentials**, Trellix groups scopes by product area:

| Trellix console category | Scope(s) |
|  --- | --- |
| **Devices** | `epo.device.r` |
| **EDR Remediations** | `soc.act.tg` |
| **EDR Searches** | `soc.rts.c`, `soc.rts.r` |
| **EDR Threats** | `soc.act.tg` |


> **Note:** `soc.act.tg` appears under both **EDR Remediations** and **EDR Threats**. Grant it once.


### Required scopes

| Scope | Required for | Without this scope |
|  --- | --- | --- |
| `epo.device.r` | Querying managed endpoints | Cannot query endpoints; Trellix returns not authorized. |
| `soc.act.tg` | Querying threat events and alerts; quarantining and unquarantining hosts | Cannot query threat events or alerts; cannot quarantine or unquarantine hosts; Trellix returns not authorized. |
| `soc.rts.c` | Creating realtime searches | Cannot create realtime searches; Trellix returns not authorized. |
| `soc.rts.r` | Polling realtime search jobs and reading results | Cannot read realtime search results; Trellix returns not authorized. |


Realtime search scopes work as a pair
`soc.rts.c` and `soc.rts.r` are both required for any realtime search workflow — including quarantine verification on Windows, which uses a HostInfo search. If you grant `soc.rts.c` but omit `soc.rts.r`, the search can be created but reading results returns not authorized (`403`).

## 3. Configure the integration

**Client ID**: OAuth client ID from Client Credentials.

**Client Secret**: OAuth client secret from Client Credentials.

**Tenant ID**: Trellix tenant GUID from IAM **Tenant Settings** → **Tenant Information**.

**API Key**: Tenant-scoped Trellix API key from Developer Portal **Self Service** → **API Access Information**, or **Trellix API Key** on the Client Credentials page.

Trellix API requests also send `X-Tenant-Id`, `x-api-key`, and a bearer token from `https://iam.cloud.trellix.com/iam/v1.0/token`.