About Freshservice
Iru reads tickets, changes (with approval status and implementation dates), incidents, problems, assets from the CMDB, and agents with their roles from the Freshservice API v2. Authentication uses your API key, found under Profile Settings. Requests target your account domain athttps://YOUR_DOMAIN.freshservice.com/api/v2. The connector wizard collects Basic credentials first, then the domain.
How It Works
X. Iru handles the encoding. Username-and-password Basic auth was deprecated on May 31, 2023 and now fails, so the API key is the only supported method.
An API key carries exactly the permissions of the agent who generated it, and there are no per-endpoint scopes. A key from a limited-permission agent returns a partial view of tickets and changes. Use a dedicated admin-level service account so evidence stays complete.
Official references: API v2 reference, Where to find your API key.
Prerequisites
- Your domain (
acmefromhttps://acme.freshservice.com). - An admin-level agent account to generate the key from. A personal agent account ties evidence collection to one person’s permissions and breaks when they are offboarded.
- Decide what is in scope. Freshservice lets you exclude ticket types, skip asset inventory, or filter by department. When underlying data is excluded, Iru marks affected controls as unable to verify.
Connect Freshservice to Iru
- Freshservice
- Iru Compliance
Complete this tab before you connect the source in Compliance.
1
Sign in to Freshservice
Sign in to
https://YOUR_DOMAIN.freshservice.com as the admin-level agent whose permissions the integration should inherit.2
Open Profile Settings
Select your profile avatar in the top right, then Profile Settings.
3
Copy your API key
Locate Your API Key on that page and copy it. Freshservice displays the key on the profile page rather than generating a new one each time, so you can return for it later.
4
Note the password convention
The password for Basic auth is the literal
X. Enter it in Iru, not in Freshservice.Continue on the Iru Compliance tab.
Troubleshooting
Nothing opens when you turn the source on
Nothing opens when you turn the source on
Check pop-up blocker settings for the Iru site and try again.
401 with unsupported_authentication_type
401 with unsupported_authentication_type
An email address and password were used instead of the API key. That method was removed on May 31, 2023. Use the key as the username.
401 with no detail
401 with no detail
Paste the full API key and confirm the password field contains a non-empty value such as
X. An empty password fails.access_denied on some endpoints
access_denied on some endpoints
The agent who generated the key lacks permission for changes, assets, or problems. Regenerate from an admin-level agent.
Assets are missing
Assets are missing
Either the CMDB is out of scope for this connection or the agent cannot read assets. Iru cannot tell those cases apart.
The wizard reports an unreachable host
The wizard reports an unreachable host
Fix the domain and reconnect. The domain is the subdomain only, not the full URL.
Related Articles
Sources Management
Browse and manage every Compliance source.
Freshsales
Connect Freshsales for CRM evidence.
Getting Started With Compliance
Frameworks, actions, and Artifacts.
Artifacts Management
Upload, review, and organize evidence from sources and actions.
