API for Sentinel One ClearPass Integration

Body

Renew the ClearPass SentinelOne API Token

Overview

The ClearPass service user in SentinelOne uses the Clear Pass Read-Only role. This role provides the minimum permissions required for the ClearPass integration.

The SentinelOne API token used by ClearPass expires after one year. A scheduled TeamDynamix ticket is created every 320 days. This provides a 45-day renewal buffer before the current token expires.

Use the following steps to regenerate the API token and update the token and expiration date in Password State.

SentinelOne Console

  1. Sign in to the SentinelOne console.
  2. Confirm that you are at the Account level.
  3. Go to Policies and Settings > User Management > Service Users.
  4. Locate the ClearPass service user.
  5. Select Actions > Regenerate API Token.
  6. Set Expiry to 1 Year.
  7. Regenerate the token.
  8. Copy the new API Token.
  9. Note the token’s expiration date.

Password State

  1. Sign in to Password State.
  2. Go to Automation > API Keys.
  3. Locate svc_ClearPass (cppm) for S1 API.
  4. Update the API token with the newly generated SentinelOne token.
  5. Update the expiration date to match the expiration date shown in SentinelOne.
  6. Save the changes.

Verification

After saving the new token, confirm that:

  • The API token in Password State is current.
  • The expiration date in Password State matches SentinelOne.
  • ClearPass can continue communicating with SentinelOne successfully.

Details

Details

Article ID: 172508
Created
Tue 8/11/26 12:55 PM
Modified
Tue 8/25/26 12:02 PM