Your HaloPSA connection
Create the HaloPSA API application that QuantumOps signs in with, then change, test and repair the connection and its webhooks in Tenant settings.
Written By Chris Scaminaci
Last updated About 3 hours ago
QuantumOps reads your tickets from HaloPSA and writes back to them. It does this through an API application that you create in HaloPSA, and through webhooks that tell it when a ticket changes. This page is the one place that explains how to create that application. It then shows how to change the connection in Tenant settings, test it, re-register the webhooks and fix common problems.
Before you start:
- You need the Administrator role in QuantumOps.
- You need a HaloPSA login that can create API applications.
What QuantumOps uses the HaloPSA connection for
QuantumOps signs in to HaloPSA as the API application, with no person involved. It uses that access to:
- Read tickets, the actions on them (notes and replies), clients and users, so it can analyse tickets and build its dashboards.
- Write to HaloPSA when a feature does, for example a research note, an Agent Assist guide note, or a reply that a technician approves.
- Register webhooks, so that HaloPSA tells QuantumOps the moment a ticket is created, updated or closed.
- Serve Qubit's built-in HaloPSA look-ups and outside AI clients, which both read tickets through this connection. See What Qubit can use: tools and sources and Connecting external AI clients over MCP.
Create the HaloPSA API application
You do this in HaloPSA, not in QuantumOps.
- In HaloPSA, go to Configuration → Integrations → HaloPSA API → Applications.
- Create a new application and give it a name you will recognise, for example QuantumOps.
- Choose a sign-in method that uses a Client ID and a Client Secret, not a person's login. QuantumOps signs in as the application itself.
- Give the application full access to tickets, clients, users and actions.
- Save the application, then copy its Client ID and Client Secret.
HaloPSA shows the secret only once, when you create the application. If you lose it, generate a new one in HaloPSA. You can find the Client ID again later in the application's View Details. Keep the secret private.
You enter these values in QuantumOps in one of two places:
- The setup wizard, the first time you set up. See Setup wizard: HaloPSA and your organisation and Before you begin.
- Tenant settings, any time afterwards (next section).
This application is separate from the one that HaloPSA's native MCP source needs, which each technician signs in through. See HaloPSA's native MCP source.
Change the connection in Tenant settings
- Select the gear icon in the page header (its tooltip is Settings). The page is titled Tenant Configuration.
- Open the HaloPSA Integration section. Your saved values are shown, and the secret is masked.
- Change what you need.
QuantumOps signs in with the Agent URL, the Client ID and the Client Secret. Choose the region and version that match your HaloPSA.
- Select Test Connection. The button reads Testing... while QuantumOps signs in with the values on the screen. A message says "Connection successful!" or explains what failed. The test does not save your entries.
- Select Save at the top of the section. QuantumOps asks for the Agent URL, the Client ID and the Client Secret if one is missing. When the save works, a message confirms it.
Test first, then save. Test Connection proves the values work, and Save is what makes QuantumOps use them. A Save on this page stores every section except Communication Policy, so unsaved edits in the other sections are saved with it. See Save your changes.
Recreate the webhooks
HaloPSA tells QuantumOps about ticket changes through webhooks. QuantumOps creates them in your HaloPSA when setup finishes. HaloPSA signs each webhook, and QuantumOps checks the signature on every one it receives.
QuantumOps registers six webhooks, all named with the prefix QuantumOps:
What happens to a ticket after a webhook arrives is covered in How ticket analysis works.
To re-register them:
- Save any change you made to the connection first. Recreate Webhooks uses the credentials that are saved, not the ones typed on the screen.
- In HaloPSA Integration, select Recreate Webhooks.
- Wait for the message. On success it says the webhooks were created. If any webhook failed, an error message lists how many were created, updated, skipped and failed.
For each of the six webhooks, Recreate Webhooks works like this:
- A webhook that does not exist in HaloPSA is created.
- A webhook that exists and already points at your QuantumOps is left alone.
- A webhook that exists but points somewhere else is updated to point at your QuantumOps.
Use it when tickets stop arriving after someone removed or changed a webhook in HaloPSA, when you move to a different HaloPSA, or when the support team asks you to. It is safe to run again, because a webhook that already exists is not created a second time.
Fix common problems
Tickets are not arriving
- Look at the header. If it shows Paused, QuantumOps still receives webhooks but does not analyse tickets. See Pausing and resuming AI processing.
- Open HaloPSA Integration and select Test Connection. Fix any error first.
- Select Recreate Webhooks, in case a webhook was removed or edited in HaloPSA.
- Open Pipeline Health to see tickets that were received but failed or were skipped, and why.
The credentials stopped working
The message "Invalid credentials. Please check your Client ID and Client Secret." means HaloPSA refused the sign-in. The usual causes are a secret that was regenerated, an application that was deleted or disabled, or an application that lost its access. Open the application in HaloPSA, give it full access to tickets, clients, users and actions again, copy the Client ID and the Client Secret, enter them in QuantumOps, select Test Connection, then Save.
The Agent URL is wrong
If the test says "Connection timed out. Please check your HaloPSA URL and try again." or fails right away, check the
HaloPSA Agent URL. Use the address you open as an agent, without https://, and without a path after the host name.
If you leave the field empty, the form shows the reminder "Enter Halo Base URL - do not include https://".
Other integrations
QuantumOps connects to more than HaloPSA. Each of these has its own page:
- Documentation Hub: connect IT Glue, Hudu or SharePoint documentation so that Qubit and Sherlock research can cite it. Documentation sources and Connecting SharePoint documentation cover each source.
- HaloPSA's native MCP source: give Qubit the tools of HaloPSA's own MCP endpoint, with each technician signing in as themselves.
- StackJack and MCP sources: give Qubit tools from StackJack or any compatible server.
- Setting up the Slack app and Setting up the Teams bot: connect Qubit and the agent commands to Slack or Microsoft Teams.
Related pages
- Tenant settings: the rest of the Tenant Configuration page.
- How ticket analysis works: what happens after a webhook arrives.
- Pipeline Health: tickets that were received but not processed.
- Setup wizard: HaloPSA and your organisation: the same step during first setup.
- Before you begin: what to have ready before you set up QuantumOps.
Was this helpful?
Still need help? Ask the team