Endpoint Agent setup (through Auth Token)

Last updated: May 21, 2026

The Matters Endpoint Agent brings Data Security Posture Management (DSPM) directly to the endpoint. It continuously discovers, classifies, and contextualizes sensitive data at rest.

The agent provides robust identification of sensitive entities across all file formats, including documents, images, screenshots, structured files, and unstructured files. It uses advanced secret detection and LLM-based contextual classification.

By delivering real-time visibility, intelligent tagging, and policy-driven risk control, the agent enables proactive governance, insider risk mitigation, and prevention of data misuse or exfiltration before it occurs.

This guide explains how to download, install, configure, and run scans using the Endpoint Agent.

Step 1. Downloading the Endpoint Agent and Generating the Authentication Token

The Endpoint Agent can be downloaded and the Agent Authentication Token can be generated from two locations.

Before installing the agent, you must generate an authentication token. Authentication of the Agent will not be possible without this token.

Follow below simple steps to setup Endpoint Agent.

Option A: From Integrations → Endpoint

  1. Navigate to Integrations → Endpoint.

Link to Download Endpoint Agent from Integrations

  1. You will see a list of all supported Endpoint Agent types:

  • Windows

  • Mac

  • Linux


3. Select the appropriate agent based on your operating system and Click Download.


4. The installer file (for example, a .dmg file on Mac) will be downloaded.


5. Click on Get Agent Token.

  1. An Agent Auth Token will be generated.

  1. Save the token and use this token to authenticate the agent after installation.

Option B: From Endpoint → Agent Management

  1. Navigate to the Endpoint page:

Link to Download Endpoint Agent

  1. Click on Agent Management.

  1. A side drawer will open and you will see all supported Endpoint Agent versions.

  2. Select the appropriate version and click Download.


5. Click on Get Agent Token.


6. An Agent Authentication Token will be generated.

  1. Copy and use this token to log in to the Endpoint Agent after installation.

Step 2. Configuring Scan Boundaries

Before installing the agent, you must configure the scan boundaries.These boundaries apply to both full disk scans and automatic incremental scans.

Important:

Configure Scan Boundaries Before Running a Full Disk Scan

Before initiating a Full Disk Scan, you must first configure the Scan Boundaries (Folder Paths, Excluded Folders, File Types, and Scan Reconciliation Timeframe).

2.1: Open Scan Boundaries

  1. Go to the Dashboard → Endpoint Section.

  2. Click on Scan Boundaries.

2.2: Configure Folder Path to Scan

  • Enter the Folder Path to Scan.

  • The agent will monitor and scan all files within this Folder Path.

2.3: Configure Excluded Folders

  • Enter folder paths that should not be scanned.

  • These directories will be skipped during the scanning process.

2.4: Select File Types

  • Select the file types that should be included in scans.

  • The agent will identify sensitive entities only within the selected file formats.

2.5: Configure Scan Reconciliation Timeframe

Configure the Scan Reconciliation Timeframe.

  • The server agent scans all large files that were modified within the last 24 hours during this timeframe.

  • This ensures comprehensive coverage and prevents files from being missed.

  • Schedule this during off-peak hours to minimize performance impact.

After configuring all required settings, click Save.

Step 3. Configuring Full Disk Scan

  1. Click on Full Disk Scan.


2. Select the scans you want to run. Click on Run Scan.

Scan Options

When configuring a Full Disk Scan, you can select one of the following scan options based on your requirement:

  1. Quiet Hours

    This option allows the scan to run during a defined quiet period to minimize impact on system performance.

    A 6-hour window is recommended. The scan will execute only within the selected quiet hours.

  2. Run Immediately

    This option starts the scan as soon as it is configured.

    The scan will begin on all endpoints within 5 minutes of saving the configuration.

  3. Scheduled Time

    This option allows you to define a specific date and time for the scan to start.

    The scan will automatically begin at the scheduled time.

Important:

Once a Full Disk Scan is configured and saved, it cannot be modified or reconfigured until the current scan process is fully completed.

Step 4. Installing and Logging in to the Endpoint Agent

  1. Locate the installer file that was downloaded earlier.

    • Open the .dmg file, run the installer and complete the setup process.

    • Once installation is complete, launch the Endpoint Agent application.

  2. When the agent starts, you will be prompted to authenticate.

    • Paste the previously generated Agent Auth Token.

    • Click on Authenticate with Token.

After successful authentication, the agent will automatically begin scanning based on the configured settings on Dashboard Endpoint Agent Configuration.

Step 5. Viewing Scan Results

Once scanning begins, the agent will list all files that contain identified sensitive entities on Dashboard.

To view results from the dashboard:

  1. Navigate to the Dashboard Endpoint Agent Section.

Link to Dashboard Endpoint Section

  1. Click on the Agent.

  1. On the Overview screen, you can view a summary of Agent and Scan results.

  1. Go to the Sensitive page to see detailed information about identified sensitive data.

You will be able to review:

  • Files containing sensitive entities in File View Section.

  • List of Sensitive entities detected along with their file path and sample data

Step 6: Mark False Positives

If any detected entity is a false positive:

  1. Locate the entity in the Sensitive list.

  2. Click on the False Positive button. Give a proper Reason and click on Submit.

  3. The entity will be marked as a false positive.

Step 7: View False Positives

  1. Go to the Sensitive page.

  2. Click on Show False Positives toggle.

  3. Turn it ON to view all marked false positives.

  4. Turn it OFF to hide them.

This completes the Endpoint Agent installation, configuration, scanning, and result review process.