Your monitoring, your IPAM, your IdP. rConfig plugs into all of them.
Device inventory from Zabbix, NetBox or Nautobot. Credentials from HashiCorp Vault. Sign in through the identity platform your team already uses. No duplicate data entry, no glue scripts holding the whole thing together.
DEVICE SYNC4 Hosts & inventory, upstreamZabbixNetBoxNautobotStatseekerSECRETS1 Credentials externalisedHashiCorp VaultIDENTITY1 Sign in through your IdPSAML / OIDC SSO
Three jobs handled by your existing tools. rConfig just uses them.
Your source of truth stays your source of truth
rConfig reads from Zabbix, NetBox, Nautobot or Statseeker and keeps its device list in lockstep. Add a device upstream, it appears in rConfig on the next sync. Retire one and the staging table flags it for review before anything breaks.
Credentials live in Vault, not our database
rConfig asks HashiCorp Vault for credentials when it needs them, uses them for the job at hand, and forgets them. Nothing sensitive stored on our side. Works with AppRole, Kubernetes auth and token auth.
Sign in the way your team already signs in
SAML and OIDC through Azure AD, Okta, Google Workspace, Keycloak and Authentik. MFA, group based RBAC and provisioning at login come with the territory.
Hosts and inventory, upstream
Read the device list from the system that already owns it. rConfig keeps its managed estate in lockstep, no CSV exports.
Zabbix
If Zabbix already knows every host on your network, rConfig doesn't ask twice. Hosts flow in on the schedule you set, new ones pick themselves up, and the integration is featured in Zabbix's own directory at zabbix.com/integrations/rconfig.
- Monitoring
- Official partner
NetBox
Treat NetBox as authoritative and let rConfig consume it. Scope the sync by site, tenant, role, platform or tag. Whatever NetBox says the network is, rConfig backs up.
- DCIM · IPAM
Nautobot
Tag driven sync that respects Nautobot's API model. Runs alongside Golden Config if you want both, or stands in as a complete alternative if your team isn't ready to own Jinja, Nornir and GraphQL.
- DCIM · IPAM
Statseeker
Statseeker watches the network. rConfig captures what's on it. Statseeker hosts now sync straight into rConfig as managed devices, no CSV exports required.
- Monitoring
- New in V8.2.0
AKIPS
Sync AKIPS devices into rConfig over the REST API for automated backup, change tracking and NIS2 / DORA evidence. 250+ enterprises trust AKIPS, now part of Tufin.
- Monitoring
Checkmk
Treat Checkmk as your inventory source of truth. rConfig backs up monitored devices and generates NIS2/DORA evidence over the REST API. Raw, Cloud, MSP and Enterprise editions supported.
- Monitoring
Paessler PRTG
Pair PRTG with rConfig for automated configuration backup, change tracking and compliance evidence. Devices sync over the REST API, no custom sensors required. Network Monitor, Enterprise Monitor and Hosted Monitor supported.
- Monitoring
OpsMill Infrahub
Consume the Infrahub GraphQL API as your network source of truth. rConfig keeps the managed estate in lockstep with Infrahub schemas and branches, no CSV exports required.
- Source of truth
Your monitoring tool?
LibreNMS, Observium and similar NMS systems are on the short list for Q2 2026. Most customer requested sync connectors ship through rConfig Automate without waiting for the next major release, so tell us what you run.
- Customer request
- Tell us
Credentials externalised
Pulled at the moment of use, never written to rConfig's database. AppRole, Kubernetes and token auth supported.
HashiCorp Vault
Pull device credentials at the moment of use. rConfig never writes secrets to its own database. Supports AppRole, Kubernetes and token authentication.
- Secrets
CyberArk
Privileged access management with credential vaulting. Short lived device credentials pulled at the moment of use.
- Enterprise PAM
- On the bench
Delinea (Thycotic)
Secret Server integration for privileged credential storage alongside the existing Vault path.
- Secret Server
- On the bench
Sign in through your IdP
Standard SAML and OIDC. MFA, group based RBAC and provisioning at login come with the territory.
SAML & OIDC SSO
The umbrella: standards based sign in that plugs into whatever IdP your team already runs. MFA, group based RBAC and provisioning at login come with it.
- Identity
Azure AD / Entra ID
Tenant wide sign in with group based RBAC and provisioning at login via OIDC or SAML.
- Microsoft
Okta
OIDC or SAML sign in with Okta group mapping to rConfig roles. SCIM provisioning on the short list.
- Identity cloud
Google Workspace
Google as the IdP with domain verification and organisational unit mapping to role groups.
- OIDC
SAML 2.0
Any standards compliant IdP: ADFS, Authentik, Duo, OneLogin, JumpCloud, PingFederate.
- Protocol
More IdPs coming
Running something that isn't listed? Tell us, most customer requested IdPs are a configuration away, not a release away.
- Customer request
- Please request
Alerts where your team reads them
Backup, compliance and change events land in chat or fan out as webhooks to the downstream systems you run.
Microsoft Teams
ChatOps notifications for backup failures, compliance drift and unauthorised changes, with click through to the offending device.
- ChatOps
Slack
Backup, compliance and change alerts in the channel your team already lives in. Threaded per device so noise stays manageable.
- ChatOps
Webhooks
Fire JSON payloads into any downstream system when rConfig detects a change. Fan out to SIEM, CMDB, or your own automation.
- Automation
One network, three teams, one source of truth each.
Here’s the honest version. Monitoring tells you the network is up. DCIM tells you what the network is supposed to look like. Neither one answers the 2am question: who changed the core switch ACL, and can we put it back. That’s the gap rConfig fills, and we fill it without asking you to rip out the tools you already trust.
Running rConfig alongside Zabbix, NetBox or Nautobot means inventory stays in one place (theirs) and configuration intelligence lives where it belongs (ours). The NOC, the security team and the auditor end up looking at the same network from the angle each of them needs. Every integration on this page is included in V8 Pro, Enterprise and Vector. No per connector licences, no extra modules, no consulting engagement required to turn them on.
Government networks, global telcos, and the lab down the hall.
rConfig ships into regulated estates, ISP backbones, and solo engineer setups alike. The only thing that changes is the shape of the integration list. Used in 120+ countries, from regional networks of a few hundred devices to global estates well north of 100,000.
On the bench, not the backlog.
Targets for the next two releases. If the connector your team needs isn't on the list, ask.
AI assisted operations
Natural language interrogation of config history, drift explanations and remediation suggestions, surfaced through rConfig Automate.
ServiceNow
CMDB sync plus automated change tickets when rConfig detects an unauthorised configuration change.
Customer requested connectors
If the tool your team needs isn't on this page, talk to us. Most customer requested sync integrations ship through rConfig Automate without waiting for the next major release.
Run rConfig alongside what you've already got
Book a 30 minute session with an rConfig engineer. We'll run inventory sync against a slice of your real network, back up a sample of devices, and show you what compliance reporting looks like against policies that actually matter to your team. Tell us your rough go-live date and we'll tailor the walk-through.
Building a custom connector? Explore the rConfig developer platform