Boot Tools turns your organisation's PXE/iPXE setup into something that reports back automatically: generate an API key, then either add a chain command to a network-boot menu you already run, or download ready-made boot media with that key already built in. Every health check and wipe certificate a device produces after booting from it is linked to your organisation without anyone entering a verification code afterward. This walks through building that boot media and who on your team can do which part.
Before you start
Sign in and open Boot Tools from the tool sidebar. It requires belonging to an organisation — an account with no organisation is redirected to a page offering to create one; joining an existing organisation instead takes an invite link from one of its administrators, not something you can do from that redirect alone.
From there, viewing the page and downloading boot media is open to every member of the organisation, but generating or revoking the API key itself is limited to an organisation administrator or a site admin. If you're not an administrator, the API Keys panel tells you so instead of listing keys — ask an administrator on your team to generate one and share it with you, or paste a key they've already shared into the field on the right yourself.
Building boot media step by step
- Sign in and open Boot Tools.
- If you're an organisation administrator: click "Generate New Key," name it, and copy the full key shown once — Boot Tools can fetch it again for you later, but it isn't printed a second time automatically.
- If you're not an administrator: get a key from one who is, then paste it into the API Key field under "Boot Media."
- Click "Apply" to build a Chain URL from that key, or pick ISO, USB, or EFI to download boot media with the key already embedded.
- Add the chain command to your existing PXE setup, or write the downloaded image to boot media, then boot a device from it.
- Check "View Wipe Certificates" or "View Health Reports" afterward — results from a device booted this way are linked to your organisation automatically.
Chain URL vs. downloaded boot media
Both options carry the same organisation key; picking one is about how your PXE setup already works. The interface labels the Chain URL the recommended option, since it needs no separate download.
- Chain URL — a line you add to an iPXE menu you already run, so an existing setup starts reporting to your organisation without replacing anything.
- ISO / USB / EFI download — a ready-made boot image for CD/DVD boot, a flash drive, or UEFI boot, for a site that doesn't already have its own PXE setup to add a line to.
Either path, once a device boots from it, its health checks and wipe certificates are linked to your organisation automatically.
Choosing who does what
Only an organisation administrator or a site admin can generate or revoke the API key — a deliberate limit, since anyone holding a valid key can produce boot media that reports into your organisation. Once a key exists, though, any member can use it: downloading boot media or building a Chain URL needs the key text, not an administrator role. A team that wants more than one person building boot media should have an administrator generate a key up front and share it, rather than routing every download through the administrator personally.
Between the two delivery options, the deciding factor is what you already run: use the Chain URL if you already maintain your own iPXE/PXE boot menu, and download the ISO, USB, or EFI image if you don't and need something to boot from directly.
When something looks wrong
- The API Keys panel just says administrators only, with no way to generate a key. That's what a non-administrator member sees — ask an organisation administrator or a site admin to generate one for you.
- The ISO, USB, and EFI download cards are greyed out. They're disabled until a key is entered in the API Key field above them.
- You see "You must belong to an organization to access Boot Tools." Your account isn't in an organisation yet — create one from the page you're sent to, or ask an existing organisation's administrator for an invite link if you mean to join theirs instead.
- You see "Only organization administrators can access this feature." You tried an admin-only action — generating or revoking a key — without being an organisation administrator or site admin.
Frequently asked questions
Who can download boot media — does it have to be an administrator?
No. Any signed-in member of the organisation can view Boot Tools and download boot media once a key exists. Generating or revoking the API key itself is the only part limited to an organisation administrator or a site admin.
What's the difference between the Chain URL and downloading boot media?
Both carry the same organisation key; the choice is about what you already run. The Chain URL is a line you add to an iPXE menu you already maintain, so an existing setup starts reporting to your organisation without replacing anything. The ISO, USB, or EFI download is a ready-made boot image for a site that doesn't already have its own PXE setup to add a line to.
Can I get back a key if I didn't copy it right away when it was generated?
If you're an organisation administrator, yes — click Select on that key in the API Keys list and Boot Tools fetches it again to fill in the API Key field. The "shown once" notice in the creation dialog just means it isn't printed a second time automatically, not that it's gone. If you're not an administrator, you never see the key list at all, and depend on an administrator to share the key with you directly.
If I revoke a key, does boot media built with it stop working?
Yes, immediately. Any chain URL or downloaded boot media still carrying a revoked key stops being accepted, so it no longer links a device's results to your organisation. Generate a new key and rebuild or re-share it if you still need that path working.
Do I need to belong to an organisation to use Boot Tools at all?
Yes — every part of this page, including just viewing it, requires signing in and belonging to an organisation; an account with no organisation is redirected to create or join one first. That's different from the bootable toolkit described in our Drive Health guide, which needs no account or organisation at all.
Try it
Generate an organisation API key and build a Chain URL or downloadable boot media that links results back to your organisation automatically.