Skip to main content

Read and export Radar data

Radar's API provides discovered app and device data for a connected Intune tenant. Use it for an inventory report or to investigate which devices have a particular app version installed. The requests in this guide read existing Radar data.

The virtual API user needs See / read information for the target tenant. Review Authentication and permissions, including the warning about the current all-users permission workaround, before granting access.

Select the tenant​

Set ROBOPACK_API_KEY, then list the tenants returned by GET /v1/tenant:

if ([string]::IsNullOrWhiteSpace($env:ROBOPACK_API_KEY)) {
throw 'Set ROBOPACK_API_KEY to your API key.'
}

$headers = @{ 'X-API-Key' = $env:ROBOPACK_API_KEY; Accept = 'application/json' }
$tenants = @(Invoke-RestMethod -Method Get -Headers $headers -ErrorAction Stop `
-Uri 'https://api.robopack.com/v1/tenant')

$tenants | Select-Object id, displayName, defaultDomain, adminConsentGranted |
Format-Table -AutoSize

$tenantId = Read-Host 'Enter the id of the tenant you want to report on'

Use the id returned by Robopack, and review displayName and defaultDomain to select the intended tenant. See the tenant list reference.

List discovered apps​

In the same session, search for an app and include both managed apps and modern apps explicitly:

$search = [uri]::EscapeDataString('7zip')
$uri = "https://api.robopack.com/v1/tenant/$tenantId/radar?Search=$search&IncludeManaged=true&IncludeModernApps=true&DisablePaging=false&ItemsPerPage=50"
$radarApps = @(Invoke-RestMethod -Method Get -Uri $uri -Headers $headers -ErrorAction Stop)

$radarApps | Select-Object name, publisher, matched, robopackManaged, deviceCount |
Format-Table -AutoSize

The response groups discovered apps and provides their version entries in entries. matched indicates whether an app is matched, and robopackManaged identifies apps already managed by Robopack. The query also accepts Matched=true or Matched=false if you need only matched or unmatched results.

This request uses the server's default page with a size of 50. For a complete report, plan your paging strategy or deliberately use DisablePaging=true. See all filters in the Radar app list reference.

For curl, set ROBOPACK_TENANT_ID to the selected tenant UUID:

: "${ROBOPACK_API_KEY:?Set ROBOPACK_API_KEY to your API key}"
: "${ROBOPACK_TENANT_ID:?Set ROBOPACK_TENANT_ID to the selected tenant id}"

curl --fail --silent --show-error --get \
"https://api.robopack.com/v1/tenant/${ROBOPACK_TENANT_ID}/radar" \
--header "X-API-Key: ${ROBOPACK_API_KEY}" \
--header 'Accept: application/json' \
--data-urlencode 'Search=7zip' \
--data-urlencode 'IncludeManaged=true' \
--data-urlencode 'IncludeModernApps=true' \
--data-urlencode 'DisablePaging=false' \
--data-urlencode 'ItemsPerPage=50'

Select a version entry​

Display the version entries from the PowerShell results:

$entries = foreach ($app in $radarApps) {
foreach ($entry in $app.entries) {
[pscustomobject]@{
EntryId = $entry.id
AppName = $app.name
Publisher = $app.publisher
Version = $entry.version
DeviceCount = $entry.deviceCount
}
}
}

$entries | Format-Table -AutoSize
$entryId = Read-Host 'Enter the non-empty EntryId for the app version you reviewed'

Use the version entry's id for the next call, and keep the same tenant ID. Entry IDs are nullable in the schema, so skip entries without an ID.

Read devices and export a CSV​

GET /v1/tenant/{tenantId}/radar/entry/{entryId}/devices returns devices that have the selected version installed:

$devices = @(Invoke-RestMethod -Method Get -Headers $headers -ErrorAction Stop `
-Uri "https://api.robopack.com/v1/tenant/$tenantId/radar/entry/$entryId/devices")

$devices | Select-Object deviceId, deviceName, userEmail, radarEntryId |
Format-Table -AutoSize

$devices | Select-Object deviceId, deviceName, userEmail, radarEntryId |
Export-Csv -Path './radar-devices.csv' -NoTypeInformation -Encoding UTF8

The device fields are nullable, so a missing user email or device name should not cause your report to fail. The CSV contains device and user information; store it in an appropriate location for your organisation.

See the version-entry device reference for the response model. There is also an app-level device endpoint for all versions of a Radar app. Its path requires a Radar app UUID; confirm that identifier before using it, since the app list model exposes both id and appId without documenting their relationship to that parameter.

Interpret the results​

Radar reads Intune's Discovered Apps data and refreshes every 24 hours. These read calls do not request a new scan, so a report can lag behind an installation or update. An empty result can also reflect your filters, permissions, or the tenant's available inventory.

If the report is empty unexpectedly, check the selected tenant, remove restrictive search filters, and review the Radar connection requirements. For scan troubleshooting, follow Radar troubleshooting.

Reading inventory is separate from enabling Radar Tracking. Custom-uploaded apps cannot use Radar Tracking, and existing app-specific limitations still apply. Review the Radar feature overview and Known Limitations before using inventory to plan patching.