If your MDM has a dedicated guide (SimpleMDM, Jamf Pro, Intune, or Mosyle), use that instead for provider-specific instructions.
Prerequisites
- Admin access to your MDM solution
- Organization API key from Runlayer with MCP Watch Scan role
- Your MDM must support running shell scripts on managed devices
Creating an Organization API Key
Creating an Organization API Key
Organization API keys authenticate MDM-deployed scripts without per-device enrollment.
Configure the Key
- Name (required): Enter a descriptive name (e.g., “MDM MCP Watch”)
- Role: Select MCP Watch Scan
Deployment Steps
Generate the Script
Fill in your settings below to generate a deployment script.
DEVICE_NAME: Use your MDM’s variable for the device name or serial number (e.g.,$DEVICE_NAME,%DeviceName%). Leave empty to use the computer name.
Deploy the Script
Use your MDM’s script or command execution feature:
- Create a new script/command in your MDM console
- Paste the generated script contents
- Configure a recurring execution schedule (at least daily recommended)
- Assign to target devices
- Save and deploy
MDM scripts typically run as root. The generated script handles this by detecting and running operations as the logged-in user where needed.
Verification
Open a client application (e.g., Cursor) on a target device and confirm the synced MCP servers appear. If something went wrong, check/var/log/runlayer-sync.log on the device.