This is a Discovery Integration.
This integration currently only detects desktop app launches.
This integration collects 30 days of history by default upon first connection.
Collect Required Information from Vendor
Follow the steps to create an OAuth client and assign it the appropriate credentials.
Log in to your CrowdStrike Falcon console.
Go to Support and resources > Resources and tools > API Clients and Keys.
.png?sv=2026-02-06&spr=https&st=2026-07-25T21%3A51%3A56Z&se=2026-07-25T22%3A02%3A56Z&sr=c&sp=r&sig=HLXi%2Bt115cBpQUf1raRE7Jz093SD0Fg8yoc8jNVYzyQ%3D)
In the API client and Secrets window, select Add new API Client.
.png?sv=2026-02-06&spr=https&st=2026-07-25T21%3A51%3A56Z&se=2026-07-25T22%3A02%3A56Z&sr=c&sp=r&sig=HLXi%2Bt115cBpQUf1raRE7Jz093SD0Fg8yoc8jNVYzyQ%3D)
Create a new client by selecting the check box next to the following API Scopes:
Alerts: Read
App Logs: Read
Apps: Read
Hosts: Read
Assets: Read
IOC Management: Write
Expand for more information about Scopes.
Scope
Requirement
API
Purpose and reasoning
Apps: Read
Hosts: Read
Assets: Read
Mandatory
GET /discover/queries/applications/v1
All three scopes are collectively required to call the Falcon Discover applications endpoint. This single call retrieves installed and launched application data across the fleet and is the sole source of data for SaaS discovery.
IOC Management: Write
Alerts: Read
Optional
POST /iocs/entities/indicators/v1GET /alerts/entities/alerts/v2
For URL fetching only. CrowdStrike suggested creating IOC indicators for known SaaS URLs (IOC Management: Write), then querying the resulting alerts and logs to detect when those URLs are interacted with (Alerts: Read, App Logs: Read). This approach is being validated and hence can be skipped — the connector works fully today without them.
Copy/save the following fields for use when onboarding this integration:
Client ID
Client Secret
Base URL
.png?sv=2026-02-06&spr=https&st=2026-07-25T21%3A51%3A56Z&se=2026-07-25T22%3A02%3A56Z&sr=c&sp=r&sig=HLXi%2Bt115cBpQUf1raRE7Jz093SD0Fg8yoc8jNVYzyQ%3D)
Select the Base URL for your region using the options below:
All other regions — https://api.crowdstrike.com
Your CrowdStrike OAuth client is now created.
Onboard This Discovery Integration
Go to SaaS Management > Applications.
Select Add Integration.
Select the Discovery Apps tab, then select the card with the vendor's name.
From the API tab, enter the field(s) you copy/saved above.
Select the Authorize button.
SUCCESS!
You will now be redirected to the Integrations page in Calero.com, where the data sync will continue in the background, and you can monitor progress.
SUGGESTION:
Access Help through your Calero.com instance if links between articles return errors or if there are fewer sections in the Help menu than expected. Doing so will ensure you see all Help articles.