# Sophos API Connection

Useroam uses the Sophos Firewall API to create and remove hotspot user sessions automatically. This page shows how to create the API user and grant the API permission on the Sophos side.

> **When do I need this?** Complete these steps after the **Sophos Integration Guide**, whenever Useroam has to manage users over the API.

---

### Creating a new profile

In Sophos, go to **Profile &gt; Device Access** in the left menu and create a new profile. Grant all permissions.

[![Creating a device access profile in Sophos](https://help.useroam.com/uploads/images/gallery/2026-07/scaled-1680-/screenshot-2026-07-24-at-13-32-08.png)](https://help.useroam.com/uploads/images/gallery/2026-07/screenshot-2026-07-24-at-13-32-08.png)

---

### Creating the API user

In Sophos, go to **Authentication &gt; Users &gt; New user** in the left menu and create a new user. For **User Profile**, select the profile you created in the previous step.

[![Creating the API user in Sophos](https://help.useroam.com/uploads/images/gallery/2026-07/scaled-1680-/screenshot-2026-07-24-at-13-32-30.png)](https://help.useroam.com/uploads/images/gallery/2026-07/screenshot-2026-07-24-at-13-32-30.png)

---

### Granting the API permission

In Sophos, open **Backup &amp; Firmware** from the left menu, switch to the **API** tab, add the entry below to the **API Configuration** field and click **+**.

[![Sophos API configuration](https://help.useroam.com/uploads/images/gallery/2026-07/scaled-1680-/screenshot-2026-07-24-at-13-32-39.png)](https://help.useroam.com/uploads/images/gallery/2026-07/screenshot-2026-07-24-at-13-32-39.png)

> **Tip:** the API user's credentials must match the ones entered on the device record in the Useroam panel. If you change the password later, update it in the panel as well.