LenelS2 NetBox
Integration Guide

This integration connects Sine with LenelS2 NetBox, allowing visitor and access data to flow directly between the two systems. By linking Sine to your NetBox access control system, you can streamline visitor credentialing and keep physical access permissions synchronized with visitor management records. This guide is intended for system integrators and IT administrators responsible for configuring and maintaining the connection between Sine and NetBox.
Overview
This integration connects Sine with LenelS2 NetBox to automatically provision and revoke visitor access credentials, with simplified connectivity for on-premise deployments via Sine Secure Bridge. It supports Sine QR Code credentials, which visitors can present on printed badges or receive via SMS, and Physical Assets credentials, such as HID proximity cards, which you manage in Sine and assign to visitors at check-in.
How It Works
Sine integrates with LenelS2 NetBox to synchronize visitor credentials with your access control system in real time. As visitors check in and out through Sine, the integration provisions and revokes their access permissions directly in LenelS2 NetBox, ensuring that physical access always reflects the current visit status.
Select your preferred check-in method below.
Visitors are issued a Sine QR Code credential that can be scanned at compatible readers, providing a contactless and fully digital access method for the duration of their visit.

Check-in Flow:
The visitor initiates check-in through Sine, using a kiosk, the mobile app, a web form, or a printed QR poster.
Sine provisions a unique QR code credential, scoped to the visitor's assigned access groups for the duration of their visit.
Once the visit is approved following security and compliance checks, Sine activates the QR code credential in LenelS2 NetBox.
Sine delivers the QR code to the visitor via SMS or displays it on their printed badge.
The visitor presents the QR code at a reader with QR/barcode scanning support, and the door unlocks.
Check-out Flow:
The visitor checks out through the Sine app or kiosk, by notifying their host, or automatically upon exiting the geofence area.
Sine revokes the QR code credential in LenelS2 NetBox, preventing any further entry attempts.
Requirements
Sine Requirements
- Integration enablement: Your Sine subscription must support the LenelS2 NetBox integration and have it enabled. Additional fees may apply.
LenelS2 NetBox Requirements
- NetBox server: You need an on-premise NetBox server with the NBAPI web services API enabled, reachable via the NBAPI XML endpoint through either external network access or the Sine Secure Bridge.
- API credentials: You need a NetBox user account whose role permits API access and the management of people, credentials, and access levels. Sine uses this user's username and password to authenticate with NetBox.
- QR Reader: If you plan to use QR codes for access, you need compatible QR access readers. Confirm compatible models with LenelS2 or your Access Control Integration Partner. A reader similar to this one is suggested.
- Credential pool: If you plan to use physical access cards, you need an available credential pool.
- Testing environment: You need a sandbox environment or a safe testing space to validate the integration before deploying it to production.
- Network connectivity: Determine how Sine will connect to your on-premise NetBox system.
- Direct API access: This method requires network firewall access to the NetBox API from outside your network.
- Sine Secure Bridge: This method requires installing the Sine Secure Bridge agent to establish a secure, managed tunnel between your on-premise NetBox system and Sine.
Configuration
LenelS2 NetBox Configuration
API and Access Level Setup
Enable the NBAPI — Ensure the NBAPI web services API is enabled on your NetBox system and that the API user's role grants API access. Roles such as Partition monitor do not have API access by default, so confirm the role you assign to the API user can use the API.
Visitor role — Create or identify the NetBox role you want Sine to assign to visitor person records, then enter its exact name in the Visitor Role field. Role names are configurable per system and per partition, so this name must match your NetBox configuration exactly.
Access levels — Create the access levels in NetBox that should be available for assignment to visitor credentials.
Card format — Confirm that the card format visitors will use is configured in NetBox, and note its card number capacity so you can set a compatible badge number range in Sine.
Visitor UDF fields (optional)
- Visit ID: Sine's unique identifier for the visit.
- Email: The email address the visitor entered at check-in, if available.
- Mobile: The mobile number the visitor entered at check-in, if available.
- Company: The visitor's company name, if provided at check-in.
Sine Configuration
General Setup
Admin permissions — Ensure you have Team or Site Admin permissions. These are required to configure integrations.
Log in — Log in to the Sine admin dashboard at https://dashboard.sine.co.
Select site — Navigate to the Locations tab and click on the site you want to configure the integration for.
Add integration — In the Site menu, click Integrations. Click the Add integration button and select LenelS2 NetBox from the list of available integrations. If the integration does not appear in the list, contact support.
Name integration — Enter a name for the integration. You can use any name, but choose something that helps you identify its purpose.
Connect to LenelS2 NetBox
Connection Method
There are two ways to establish network connectivity to your on-premise LenelS2 NetBox instance.
Select your preferred method below.
Sine Secure Bridge enables a secure, managed tunnel between Sine Cloud and your on-premise system's API.
Enable Secure Bridge — Switch Use Sine Secure Bridge on to display a dropdown list of your Secure Bridge tunnels. If you do not see the Sine Secure Bridge toggle, contact your Sine representative.
Documentation — For more information on installing and configuring a Sine Secure Bridge tunnel, visit the Secure Bridge Documentation.
Authentication
Credentials — Enter your LenelS2 NetBox API User's username and password.
Test Connection — Click the Test connection button to confirm that your configuration is correct. Once you have successfully verified that Sine can connect to your LenelS2 NetBox account, the Integration Settings section becomes available.
Integration Settings
Credential Configuration
Controls the type of access control credential that will be generated when the integration runs.
Select your preferred credential type below.
Generates and attaches a QR code to a visitor's pass. The integration runs when a pass is created or expired, or when the visitor checks out.
Provision credentials on invitation — By default, the visitor's credentials are provisioned on check-in. If this toggle is enabled, the QR code provided to the visitor in their invitation email is provisioned in LenelS2 NetBox and activated closer to the date of the visitor's invitation start time. This can be used to provide a more seamless experience by provisioning car parking access or access to secure areas prior to the visitor's arrival. Note: if this toggle is enabled and you also want to provision credentials on check-in, you must create a separate integration.
Badge number range — Specify the badge number range you want to use with QR code credentials. Sine randomly generates a new card number for visitors on check-in using the range you provide. The range must be supported by your access control card formats.
Badge Style — Select the style of printed badge to use when this integration runs. Some access control readers require a specially formatted Access badge style rather than the default name badge style.
Send QR Code by SMS — If the visitor's mobile number is available, send them a QR code credential to their phone. This can be a good backup to a badge printer.
Provision credential on check-in — Select one or more visitor types for which you want the integration to provision credentials in your access control system when they check in using Sine. Ensure the Host Selection Required checkbox is ticked for any visitor types used in access control integrations. Without this setting, visitors would be provided with access credentials without requiring approval from a host. You can review which of your visitor types have Host Approval Required in the General tab of your site settings.
Grace Period — A visitor may use Sine to check out before they leave the location and may still need to use their credentials to exit. You can set a grace period to ensure their access control credentials are not deprovisioned immediately after they are checked out in Sine.
Basic Configuration
Access Levels — Select one or more NetBox access levels to assign to visitor credentials. The list is populated automatically from your NetBox system, and access levels are assigned to the visitor's person record when they are provisioned.
Card Format — Select the card format to use when creating credentials in NetBox. The list is populated automatically from your NetBox system.
Visitor Role — Enter the NetBox role to assign to the person records Sine creates for visitors. This field is required and must match, exactly, the name of a role that exists in your NetBox system (for example, Partition monitor). Provisioning fails if the role does not exist in NetBox.
UDF Field Mapping
- Optionally map Sine values onto NetBox user-defined fields (UDF1 to UDF25) on the visitor's person record. NetBox does not expose custom UDF display labels through the API, so fields are referenced by their canonical keys (UDF1 to UDF25).
Visit ID field — Optionally select the NetBox UDF field to store the Sine visit ID on the visitor's person record.
Email field — Optionally select the NetBox UDF field to store the visitor's email address on the visitor's person record.
Mobile field — Optionally select the NetBox UDF field to store the visitor's mobile number on the visitor's person record.
Company field — Optionally select the NetBox UDF field to store the visitor's company name on the visitor's person record.
Messages
- Visitor failure message — Enter the message to display to the visitor if the access control integration fails.
Notifications
- Send integration failure notifications — If the integration fails, you can enter one or more email addresses to be notified of the failures and their corresponding details.
Testing
Create a test check-in — Create a test visitor check-in using a visitor type configured for the integration.
Verify credential provisioning — Verify that the visitor profile is created in the vendor system and that credentials are provisioned correctly.
Test credential access — Test the credential at a compatible reader to ensure access is granted.
Verify credential revocation — Check out the test visitor and verify that access credentials are revoked after the configured grace period.
Check failure notifications — Monitor the integration failure notifications to ensure they are working correctly.
Need help? Contact Sine Support at [email protected]

