Endpoint Agent setup (through Auth Token)
Last updated: May 21, 2026
The Matters Endpoint Agent brings Data Security Posture Management (DSPM) directly to the endpoint. It continuously discovers, classifies, and contextualizes sensitive data at rest.
The agent provides robust identification of sensitive entities across all file formats, including documents, images, screenshots, structured files, and unstructured files. It uses advanced secret detection and LLM-based contextual classification.
By delivering real-time visibility, intelligent tagging, and policy-driven risk control, the agent enables proactive governance, insider risk mitigation, and prevention of data misuse or exfiltration before it occurs.
This guide explains how to download, install, configure, and run scans using the Endpoint Agent.
Step 1. Downloading the Endpoint Agent and Generating the Authentication Token
The Endpoint Agent can be downloaded and the Agent Authentication Token can be generated from two locations.
Before installing the agent, you must generate an authentication token. Authentication of the Agent will not be possible without this token.
Follow below simple steps to setup Endpoint Agent.
Option A: From Integrations → Endpoint
Navigate to Integrations → Endpoint.
Link to Download Endpoint Agent from Integrations
You will see a list of all supported Endpoint Agent types:
Windows
Mac
Linux
3. Select the appropriate agent based on your operating system and Click Download.
4. The installer file (for example, a .dmg file on Mac) will be downloaded.
5. Click on Get Agent Token.
An Agent Auth Token will be generated.
Save the token and use this token to authenticate the agent after installation.
Option B: From Endpoint → Agent Management
Navigate to the Endpoint page:
Link to Download Endpoint Agent
Click on Agent Management.
A side drawer will open and you will see all supported Endpoint Agent versions.
Select the appropriate version and click Download.
5. Click on Get Agent Token.
6. An Agent Authentication Token will be generated.
Copy and use this token to log in to the Endpoint Agent after installation.
Step 2. Configuring Scan Boundaries
Before installing the agent, you must configure the scan boundaries.These boundaries apply to both full disk scans and automatic incremental scans.
Important:
Configure Scan Boundaries Before Running a Full Disk Scan
Before initiating a Full Disk Scan, you must first configure the Scan Boundaries (Folder Paths, Excluded Folders, File Types, and Scan Reconciliation Timeframe).
2.1: Open Scan Boundaries
Go to the Dashboard → Endpoint Section.
Click on Scan Boundaries.
2.2: Configure Folder Path to Scan
Enter the Folder Path to Scan.
The agent will monitor and scan all files within this Folder Path.
2.3: Configure Excluded Folders
Enter folder paths that should not be scanned.
These directories will be skipped during the scanning process.
2.4: Select File Types
Select the file types that should be included in scans.
The agent will identify sensitive entities only within the selected file formats.
2.5: Configure Scan Reconciliation Timeframe
Configure the Scan Reconciliation Timeframe.
The server agent scans all large files that were modified within the last 24 hours during this timeframe.
This ensures comprehensive coverage and prevents files from being missed.
Schedule this during off-peak hours to minimize performance impact.
After configuring all required settings, click Save.
Step 3. Configuring Full Disk Scan
Click on Full Disk Scan.
2. Select the scans you want to run. Click on Run Scan.
Scan Options
When configuring a Full Disk Scan, you can select one of the following scan options based on your requirement:
Quiet Hours
This option allows the scan to run during a defined quiet period to minimize impact on system performance.
A 6-hour window is recommended. The scan will execute only within the selected quiet hours.
Run Immediately
This option starts the scan as soon as it is configured.
The scan will begin on all endpoints within 5 minutes of saving the configuration.
Scheduled Time
This option allows you to define a specific date and time for the scan to start.
The scan will automatically begin at the scheduled time.
Important:
Once a Full Disk Scan is configured and saved, it cannot be modified or reconfigured until the current scan process is fully completed.
Step 4. Installing and Logging in to the Endpoint Agent
Locate the installer file that was downloaded earlier.
Open the .dmg file, run the installer and complete the setup process.
Once installation is complete, launch the Endpoint Agent application.
When the agent starts, you will be prompted to authenticate.
Paste the previously generated Agent Auth Token.
Click on Authenticate with Token.
After successful authentication, the agent will automatically begin scanning based on the configured settings on Dashboard Endpoint Agent Configuration.
Step 5. Viewing Scan Results
Once scanning begins, the agent will list all files that contain identified sensitive entities on Dashboard.
To view results from the dashboard:
Navigate to the Dashboard Endpoint Agent Section.
Link to Dashboard Endpoint Section
Click on the Agent.
On the Overview screen, you can view a summary of Agent and Scan results.
Go to the Sensitive page to see detailed information about identified sensitive data.
You will be able to review:
Files containing sensitive entities in File View Section.
List of Sensitive entities detected along with their file path and sample data
Step 6: Mark False Positives
If any detected entity is a false positive:
Locate the entity in the Sensitive list.
Click on the False Positive button. Give a proper Reason and click on Submit.
The entity will be marked as a false positive.
Step 7: View False Positives
Go to the Sensitive page.
Click on Show False Positives toggle.
Turn it ON to view all marked false positives.
Turn it OFF to hide them.
This completes the Endpoint Agent installation, configuration, scanning, and result review process.