Connect Rewst
Rewst is the automation platform many MSPs run their onboarding, offboarding, ticket handling and billing clean-up on. An MSP's Rewst account is a parent organization with one child organization per…
Written By Christopher Scaminaci
Last updated About 3 hours ago
Rewst is the automation platform many MSPs run their onboarding, offboarding, ticket handling and billing clean-up on. An MSP's Rewst account is a parent organization with one child organization per customer, and every workflow runs for one of those organizations, acting in your PSA, your RMM and Microsoft 365 on that customer's behalf.
Connecting Rewst to StackJack gives your AI assistant a family of rewst_ MCP tools. MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:
- Answer the morning question - which automations failed overnight, for which customer, and why. Executions, their task logs and their context are all readable, across your whole customer tree
- Report the value of automation - time saved per workflow, per customer and per day, and the counts of tasks and executions by state, ready for a quarterly business review
- Start and stop automation - run a workflow for a customer, submit a form, fire a trigger or a webhook, and stop an execution that has gone wrong
- Map your customers - the organization tree, who manages whom, the variables each organization carries, and the users, invites and permissions in it
- Inventory what is armed - workflows, triggers, completion listeners and which organizations each trigger is switched on for
- Check your integrations - which integration packs are installed, how they are configured for each organization, and which bundles they belong to
- Author and change - create and edit workflows, triggers, forms, templates, tags, organizations, organization variables, integration configurations and App Builder sites, pages and components, and a user's display preferences and favorite actions
- Look things up - actions, crates, forms, tags, sensor types, Microsoft CSP customers and the feature previews switched on for an organization, and the link a person opens to authorize an integration
StackJack covers Rewst Classic. The newer Rewst platform at app.rewst.ai is a different product with its own sign-in and is not part of this connection.
What you need
A Rewst Classic account, and a Rewst API client: a Client ID and a Client Secret that you create inside Rewst. There is no sign-in prompt and nothing to renew by hand. StackJack exchanges the pair for a short-lived access token before it calls Rewst and renews the token on its own.
A Rewst API client acts as a Rewst user. Rewst decides what it may do from that user's roles, field by field, so the roles on that user are the real limit on what an AI can do. Read access is enough for everything the AI reports on; give the user the roles that create, edit, run or delete things only where you want an agent to do that.
Your region
Rewst Classic runs four separate regions, each with its own sign-in and its own API, and an API client works only in the region where it was created. Choose the one that matches the address you sign in to Rewst at:
- United States if your address is
app.rewst.io - United Kingdom if your address is
app.eu.rewst.io - Germany if your address is
app.rewst.eu - Australia if your address is
app.rewst.asia
Go by the full address rather than the letters in it: Rewst's own United Kingdom region lives at an address containing eu.rewst.io, and its Germany region at rewst.eu. There is no default. A client sent to the wrong region is refused in a way that looks exactly like a wrong secret, so a region mistake reads as a credential problem and can send you off rotating a perfectly good secret.
Creating the API client
- Find your region from the address above.
- Create an API client in Rewst. Rewst's public help center does not describe API clients, so the exact place depends on your account. In Rewst Classic they are managed under Configuration, in API Clients, and Rewst may need to switch the feature on for your account first. If you cannot find it, ask Rewst support to enable API clients. Create the client in your own (parent) organization and give it a name that identifies StackJack.
- Choose who the client acts as, and give that user the roles you want an AI to have.
- Copy the Client ID and the Client Secret. Rewst shows the secret once, when the client is created. If you lose it, replace it.
- Open Connectors in StackJack, choose Rewst, pick your region, and paste the Client ID and the Client Secret.
- Run a Test Connection. StackJack signs in and asks Rewst who the API client is, which needs nothing more than a valid client in the right region.
StackJack asks for the Client ID and the Client Secret again whenever you edit the connection, because the secret cannot be read back from storage. That is deliberate: asking for both is what stops an edit from quietly blanking one of them.
What has not been confirmed
Two things about Rewst's API are not documented by Rewst, and StackJack has not been able to confirm either against a live Rewst account. Both are the first things to check if something does not work.
The sign-in audience. To get an access token for your region, StackJack names the Rewst API address of that region. Rewst does not publish that value, so StackJack uses the documented best choice. If connecting fails with a message about the API audience, nothing is wrong with your Client ID or your Client Secret, so do not rotate them. Tell StackJack support which region you chose and the time of the failure.
Parent and child organizations. Whether an API client created in a parent organization can reach the customer organizations beneath it is not documented either. If a customer organization's data does not come back, create the API client in that organization, or ask Rewst. Listing the customers you manage works from the parent and is a good first check.
What to know before you let an AI loose on it
Several tools start or stop real automation. Running a workflow, submitting a form, firing a trigger, calling a webhook and killing an execution all take effect immediately, with real side effects in the tools those workflows are connected to, and Rewst Classic has no dry run for them. Creating or editing a trigger, a completion listener or a trigger instance arms automation that then runs on its own, and one call can switch a trigger on for every customer you manage. A workflow or an App Builder page created or edited with triggers inside it does the same, so those are labeled too, and so are publishing an App Builder site, moving its address, and replacing the tag set of a form, an organization or a workflow. StackJack labels all of these as changes that need approval, so an assistant that honors the label shows you the action and waits for you to confirm it. The confirmation belongs to the assistant, not to StackJack.
Starting automation returns an execution id, not a result. Running a workflow, firing a trigger instance and testing an integration configuration each answer with an id. Your AI reads what happened afterwards, from the execution and its task logs. Submitting a form is different: Rewst documents only that it submits the form data and starts the workflow bound to it, and does not say what it answers, so your AI finds that run among the organization's executions and reads it there before it reports success.
Some tools read or write stored credentials. Integration configurations hold the keys Rewst uses to act in your other tools, and organization variables can hold secrets. StackJack asks Rewst for the variables it holds exactly as Rewst chooses to return them, which for secret variables means Rewst's own masking applies, and it never asks Rewst to unmask them. The tools that read these values are on StackJack's sensitive list, so their results are never recorded for later and an oversized result is refused rather than stored. The tools that write them are labeled as changes that need approval, and they answer with identifiers only: the credential you send is not echoed back.
Creating an organization adds a customer organization. Rewst prices per client organization on the platform, so creating one spends money, and it is labeled as a change that needs approval for that reason.
Deleting is final. Rewst says a deleted organization cannot be brought back, even by Rewst support. Deleting a workflow, a trigger, a form, a variable or an integration configuration is labeled as a change that needs approval and Rewst documents no undo for it.
Some answers leave fields out on purpose. Each tool answers with a fixed set of the record's ordinary fields, and the fields that hold a webhook trigger's secret, a workflow's stored task inputs or an execution's raw task results are left out. Execution context is the exception: it is the one tool that returns the whole variable set of a run, and because it can include values pulled from variables and integrations it is on the sensitive list.
What comes back
Rewst answers with its own GraphQL response and StackJack passes it through unchanged: a data object, and errors when Rewst reports any. Lists come back as plain arrays with no total, so an AI keeps paging until a page comes back short.
Page sizes
Lists page by a limit and an offset. StackJack always sends a limit, because Rewst counts an omitted one against its own cap, and it caps the page size, lower for the large tables (workflow executions and task logs). Rewst publishes no maximum of its own, so these caps are StackJack's, and each tool says what it accepts.
Three tables need a scope
Rewst times out queries on its largest tables unless they are narrowed. So listing workflow executions needs the organization, listing task logs needs the execution, and listing organizations needs either the managing organization or a filter. The tools refuse the call without it and say what to add. Searching executions by a recent creation date narrows the scan a great deal.
Two more reads need a scope for other reasons. Rewst requires the organization on every user lookup, so reading users takes the organization. Listing integration configurations takes a filter, because an unscoped call would answer with the stored credentials of every organization the API client can see in one result.
Filters
Every list takes two filters, and they are not interchangeable. The first matches fields exactly and accepts only the fields Rewst lists for it. The second takes comparison operators such as contains, greater-than or in-a-list, and reaches fields the first cannot. Each tool names the fields its filters accept.
Authorization failures
Rewst answers an authorization failure with a normal success status and the error inside the response. StackJack reads the response and treats it as the failure it is: a connection whose client was deleted, or whose secret was replaced, is reported as needing attention rather than as healthy.
Plans and limits
Read tools are available on the Free tier. Every change needs Pro. The Business plan is a higher monthly call allowance on the same tools.
See the generated Rewst tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.
Rewst publishes no rate limit for its API. StackJack paces its requests conservatively for your StackJack organization, across all your Rewst customer organizations, and backs off when Rewst asks it to. Rewst does publish a limit for webhook triggers, 50 calls a second and 1,000 a minute for each trigger, and the webhook tool stays inside it.
Webhook triggers
A webhook trigger starts one workflow when something posts to its address. The webhook tool builds that address for you from your region, the trigger and the organization, and posts the payload you give it. If the trigger has a Secret key set, give that key as well: Rewst answers the call with a refusal without it, and StackJack never writes the key into an address or a log. A trigger set to wait for results answers with a redirect instead of a body; StackJack does not follow it and reports that the run was accepted.
Several customers
One API client reaches one Rewst account. If you hold more than one Rewst account, add one connection per account from the connector's card, name it after the account, and your AI names it on each call. Inside one account the customer organizations are an ordinary argument on the tools, not separate connections.
Troubleshooting
"Rewst's sign-in service refused this API client" - check the region first. A client created in one region and sent to another fails exactly like a bad secret. If the region is right, the secret was replaced or the client was deleted in Rewst: copy the new Client ID and Client Secret and save them again.
"Rewst did not authorize this request" on every tool - the API client was deleted, its secret was replaced, or the Rewst user it acts as was deactivated. Repair the client in Rewst and save its Client ID and Client Secret again.
"Rewst did not authorize this request" on some tools only - the Rewst user the client acts as lacks the role for that area. Rewst answers a missing permission and a refused credential with the same code, and checks permissions field by field. Give the user the role, or ask for something narrower.
A message about the API audience - see "What has not been confirmed" above. It is not a problem with your credentials.
A list is refused and asks for an organization - add the scope the message names. Rewst times out an unscoped query on its largest tables.
A query is slow or times out - narrow it: give the organization, a recent creation date for executions, and a smaller page size.
Everything works for the parent and nothing comes back for a customer organization - see "Parent and child organizations" above.
Rewst tools
rewst_ · 172 tools · Free 97 · Pro 75
Workflow runs and execution health
Run and stop automation
Workflows
Workflow authoring
Triggers
Organizations
Organization variables
Users and permissions
Integrations
Forms
Actions, crates, templates and tags
App Builder
Platform
Was this helpful?
More in Connector guides
Connect Acronis Cyber Protect CloudConnect Action1Connect AddigyConnect AlertOpsStill need help? Ask the team