Overview
Torii integrates with CrowdStrike Falcon and syncs:
- Console users — the people who log into the Falcon platform
- Each user's role
- Each user's creation date and last login
Torii does not sync devices or endpoints protected by Falcon — only the people who have access to the Falcon console.
You can constantly stay updated with application information from our Integrations Page >> Integration Capabilities button >> Integration Capabilities table.
Requirements
Accounts & Permissions
- An administrator-level account in your CrowdStrike Falcon console, to create an API client.
Scopes
- User Management: Read. This is the only scope Torii needs.
Required keys
- Region, Client ID, Client Secret.
How to Generate the Required Values
Step 1: Find your CrowdStrike region
Check the address you already use to log into Falcon:
| If you log into Falcon at… | Select this Region in Torii |
|---|---|
| falcon.crowdstrike.com | US-1 |
| falcon.us-2.crowdstrike.com | US-2 |
| falcon.eu-1.crowdstrike.com | EU-1 |
| A GovCloud environment | US-GOV-1 or US-GOV-2 — confirm which with CrowdStrike support if you are unsure |
Step 2: Create an API client with the minimum scope
- Log in to the Falcon console as an administrator.
- Open the Falcon menu (top left) and go to Support and resources > API Clients and Keys.
- Click Add new API client.
- Enter a Client Name (for example, "Torii") and, optionally, a Description.
- Under API Scopes, find User Management and check only the READ box. Do not check WRITE — Torii does not need it.
- Click Add.
Important
Copy your Client ID and Client Secret immediately. CrowdStrike shows the Client Secret only once and you cannot retrieve it later — if you lose it you will need to reset it, which generates a new secret.
An API client with more scopes, or an existing admin-level client, will also work — but it grants Torii more access than it needs. We recommend a client with only User Management: Read.
How to Connect the Integration
Step 3: Connect in Torii
- Go to the Integrations page in Torii.
- Search for CrowdStrike Falcon and click Connect.
- Select your Region, then enter the Client ID and Client Secret.
- Click Connect.
Q&A
Q: Does Torii sync devices or endpoints protected by Falcon?
A: No. This integration syncs only Falcon console users — the people who can log into the Falcon platform — not devices, sensors, or endpoints.
Q: What does the user's status show in Torii?
A: Torii shows each user's status exactly as CrowdStrike reports it, in an "external status" field. Torii doesn't interpret or act on this value — it's a direct passthrough of what CrowdStrike sends.
Q: I manage more than one Falcon tenant. How do I connect them?
A: One Torii connection covers one Falcon tenant. Connect each tenant separately, using the API client created in that tenant.
For any further questions, please contact Torii Support.