Skip to main content

About Freshservice

Iru reads tickets, changes (with approval status and implementation dates), incidents, problems, assets from the CMDB, and agents with their roles from the Freshservice API v2. Authentication uses your API key, found under Profile Settings. Requests target your account domain at https://YOUR_DOMAIN.freshservice.com/api/v2. The connector wizard collects Basic credentials first, then the domain.

How It Works

Freshservice uses HTTP Basic over HTTPS: the username is your API key and the password is any non-empty string, conventionally the literal X. Iru handles the encoding. Username-and-password Basic auth was deprecated on May 31, 2023 and now fails, so the API key is the only supported method. An API key carries exactly the permissions of the agent who generated it, and there are no per-endpoint scopes. A key from a limited-permission agent returns a partial view of tickets and changes. Use a dedicated admin-level service account so evidence stays complete. Official references: API v2 reference, Where to find your API key.

Prerequisites

  • Your domain (acme from https://acme.freshservice.com).
  • An admin-level agent account to generate the key from. A personal agent account ties evidence collection to one person’s permissions and breaks when they are offboarded.
  • Decide what is in scope. Freshservice lets you exclude ticket types, skip asset inventory, or filter by department. When underlying data is excluded, Iru marks affected controls as unable to verify.

Connect Freshservice to Iru

Complete this tab before you connect the source in Compliance.
1

Sign in to Freshservice

Sign in to https://YOUR_DOMAIN.freshservice.com as the admin-level agent whose permissions the integration should inherit.
2

Open Profile Settings

Select your profile avatar in the top right, then Profile Settings.
3

Copy your API key

Locate Your API Key on that page and copy it. Freshservice displays the key on the profile page rather than generating a new one each time, so you can return for it later.
4

Note the password convention

The password for Basic auth is the literal X. Enter it in Iru, not in Freshservice.
Continue on the Iru Compliance tab.

Troubleshooting

Check pop-up blocker settings for the Iru site and try again.
An email address and password were used instead of the API key. That method was removed on May 31, 2023. Use the key as the username.
Paste the full API key and confirm the password field contains a non-empty value such as X. An empty password fails.
The agent who generated the key lacks permission for changes, assets, or problems. Regenerate from an admin-level agent.
Either the CMDB is out of scope for this connection or the agent cannot read assets. Iru cannot tell those cases apart.
Fix the domain and reconnect. The domain is the subdomain only, not the full URL.

Sources Management

Browse and manage every Compliance source.

Freshsales

Connect Freshsales for CRM evidence.

Getting Started With Compliance

Frameworks, actions, and Artifacts.

Artifacts Management

Upload, review, and organize evidence from sources and actions.