> ## Documentation Index
> Fetch the complete documentation index at: https://docs.jesta.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Deploy integrations

> How a tripwire reaches your fleet.

A deploy integration **runs a tripwire's install command** on selected machines.
Each machine then self-enrolls and pulls its own unique honeytoken; the deploy
plugin never handles token content or secrets. External tooling decides which
machines are in scope - Thumper provides the command.

## Available integrations

| Integration | Status | Notes |
| - | - | - |
| **SSH (direct)** | Available | Runs the install command over SSH using your local ssh client and its key/agent auth. Good for servers and bastions. |
| **MDM (Jamf Pro)** | Coming soon | Upserts a Jamf Pro script + policy scoped to a smart group (recurring check-in trigger). **Jamf Pro only** - the scripts/policies/smart-groups API it uses doesn't exist in Jamf Now, Jamf School, or other MDMs. |
| **Your own** | - | Any MDM, CM tool, or workflow - \~30 lines. See below. |

<Note>
  Not on a supported MDM? You don't need a plugin at all - copy the install
  command from the tripwire and distribute it however you already manage
  endpoints (push via your MDM, run via Ansible, or paste on the box).
</Note>

## Roll your own

A deploy plugin receives an `AgentInstall` (carrying `tripwire_id`, `server_url`,
`enroll_token`, and the ready-to-run `command`) and runs that command on its
targets. That's the whole contract. See
[Writing a plugin](/thumper/writing-plugins) for the directory layout, manifest,
and the `DeployPlugin` class.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.