Liongard Tools
Written By Christopher Scaminaci
Last updated 7 days ago
Liongard Tools
liongard_ · 77 tools · Free 44 · Pro 33
IT environment discovery, documentation and change detection. The credential is a Liongard access key and secret key. Both the v1 and v2 endpoints are covered, and the v1 tools carry a _v1 suffix in their names. Page size stops at 2000. Searches are POSTs that only read. The v1 report downloads return a short-lived link to the stored file.
All connector tools · Liongard setup guide
Liongard tool groups
- Environments — 10 tools
- Environment Groups — 4 tools
- Agents — 3 tools
- Asset Inventory — Identities — 4 tools
- Asset Inventory — Devices — 4 tools
- Metrics — 4 tools
- Timeline & Detections — 2 tools
- Dataprints — 1 tool
- Webhooks — 6 tools
- Inspectors (v1) — 3 tools
- Systems (v1) — 3 tools
- Launchpoints (v1) — 6 tools
- Users (v1) — 5 tools
- Service Providers (v1) — 2 tools
- Reports (v1) — 4 tools
- Alerts (v1) — 3 tools
- Tags (v1) — 5 tools
- Notes (v1) — 5 tools
- Roles (v1) — 2 tools
- Audit Log (v1) — 1 tool
Environments
liongard_count_environments details
liongard_count_environments details
[Liongard] Returns the total number of environments visible to the API key. Useful as a cheap health check or to size pagination loops before calling liongard_list_environments.
liongard_create_environment details
liongard_create_environment details
[Liongard] Create a new environment. Body requires Name, Description, Parent (nullable), ShortName, and Tier (must be 'Core' or 'Essentials'). Returns the created environment with its assigned ID.
liongard_create_environments_bulk details
liongard_create_environments_bulk details
[Liongard] Create multiple environments in one call. Body must be a JSON array of environment-create objects (same shape as liongard_create_environment).
liongard_delete_environment details
liongard_delete_environment details
[Liongard] WARNING: Permanently delete an environment. Setting relatedEntities=true also deletes child agents, launchpoints, and integration mappings — non-reversible. Use liongard_get_environment_related_entities first to understand the blast radius.
liongard_get_environment details
liongard_get_environment details
[Liongard] Get a single environment by ID. Returns full environment metadata including parent, short name, tier, creation date, and IDs of associated launchpoints/agents. Use liongard_list_environments to discover IDs.
liongard_get_environment_related_entities details
liongard_get_environment_related_entities details
liongard_list_environments details
liongard_list_environments details
[Liongard] List environments (top-level customer/site containers). Each environment groups inspectors, agents, launchpoints, and asset inventory. Returns paginated array with environment IDs, names, descriptions, and tier (Core or Essentials). Takes the FLAT parameters page/pageSize/columns/orderBy only — this is a GET, not a POST-for-search; a nested / object is NOT accepted (the stackjack_run_* dispatchers reject unknown arguments; a direct call silently ignores them). Liongard offers no server-side name filter on this endpoint: to find an environment by name, page through with orderBy='Name' and match client-side. Use liongard_get_environment for full details and liongard_get_environment_related_entities to fetch dependent objects.
liongard_query_environment_dashboard details
liongard_query_environment_dashboard details
[Liongard] Run dashboard-metric queries against a single environment. Body must contain a queryIdentifiers array of dashboard metric names (e.g. 'm365TotalUsers', 'workstationOsVersionPct', 'winServerEDRSoftware', 'macOSPctEncryptedAtRest'). See Liongard's UI dashboard for the full enum (60+ values). Use this for posture-snapshot reports.
liongard_update_environment details
liongard_update_environment details
[Liongard] Update a single environment by ID. Body uses the same shape as create (Name/Description/Parent/ShortName/Tier). Use liongard_list_environments to find IDs.
liongard_update_environments_bulk details
liongard_update_environments_bulk details
[Liongard] Update multiple environments in one call. Body must be a JSON array of {EnvironmentId, Name, Description, Parent, ShortName, Tier} objects.
Environment Groups
liongard_create_environment_group details
liongard_create_environment_group details
[Liongard] Create an environment group. Body requires AutoAddNewEnvironments (bool), Description, Environments (int[]), Name, Users (array of {UserID, GroupID}).
liongard_delete_environment_groups details
liongard_delete_environment_groups details
[Liongard] WARNING: Permanently delete one or more environment groups. Liongard quirk: this is a DELETE with a JSON BODY (not a path-based delete). Body shape: {"EnvironmentGroupIDs": [1, 2, 3]}. Environments inside the groups are NOT deleted — only the group association.
liongard_list_environment_groups details
liongard_list_environment_groups details
[Liongard] List environment groups. Each group bundles environment IDs and user permission assignments. Use to discover group IDs before applying group-level permissions.
liongard_update_environment_group details
liongard_update_environment_group details
[Liongard] Update a single environment group. Body shape matches liongard_create_environment_group. Use liongard_list_environment_groups to find IDs.
Agents
liongard_delete_agents details
liongard_delete_agents details
[Liongard] WARNING: Permanently delete one or more agents. Liongard quirk: this is a DELETE with a JSON BODY (not path-based). Body shape: {"AgentIDs": [1,2,3]}. Optional disableLaunchpoints flag also disables every launchpoint that pointed at the deleted agents. Use liongard_list_agents first to confirm IDs.
liongard_generate_agent_installer details
liongard_generate_agent_installer details
[Liongard] Generate a one-time installer download URL for a new agent in a specific environment. Body requires os ('windows', 'mac', or 'linux') and environmentID. Returns an installer URL or installer artifact metadata.
liongard_list_agents details
liongard_list_agents details
[Liongard] List agents (Liongard collectors deployed in customer networks). Liongard quirk: this is a POST-for-search endpoint at /view/agents. Body envelope: {Filters, Sorting, Pagination}. Liongard requires empty arrays even when not filtering — this tool sends defaults automatically when bodyJson is null. Optional flags excludeSummary/excludeAgents/excludeManaged trim the response shape.
Asset Inventory — Identities
liongard_get_identity details
liongard_get_identity details
[Liongard] Get a single identity by UUID. Returns full identity details including type, status, location, manual-curation flag.
liongard_list_identities details
liongard_list_identities details
[Liongard] Query identities (users, service accounts, admins, guests, etc.) within an environment's asset inventory. POST-for-search: body requires Environment (int, REQUIRED) and Filters/Pagination/Sorting (Liongard requires empty arrays even when unused). Returns identity records with type, status, location, inventory state, and isManual flag.
liongard_update_identities_bulk details
liongard_update_identities_bulk details
[Liongard] Bulk-update inventory state, status, and type across many identities. Liongard quirk: this is a POST-for-update (not a PUT), per the bulk-mutate convention. Body: {"Environment": N, "IDs": ["uuid1","uuid2"], "InventoryState": "Archive", "Status": "inactive", "Type": "user"}.
liongard_update_identity details
liongard_update_identity details
[Liongard] Update a single identity's classification (type, status, location, inventoryState, isManual). Type values: service|user|admin|guest|shared|system|application. Status values: suspended|active|inactive|expired|deactivated|deleted|pending-activation. InventoryState: Inventory|Archive|Discovery.
Asset Inventory — Devices
liongard_get_device details
liongard_get_device details
[Liongard] Get a single device profile by UUID. Returns full device metadata: alias, class, status, category, type, role, location, host info, asset tag, purchase date, warranty/EOL dates, environment.
liongard_list_devices details
liongard_list_devices details
[Liongard] Query device profiles within an environment's asset inventory. POST-for-search: body requires Environment, Filters, Pagination, Sorting (empty arrays required). Returns devices with class, status, category, type, role, location, and asset metadata.
liongard_update_device details
liongard_update_device details
[Liongard] Update a device's classification or asset metadata. Many enum fields: Class (critical|standar — Liongard spec typo, pass through as 'standar'), Status (active|inactive|idle|standby), Category (compute|network|iot-printer|storage), Type (server|host|desktop|laptop|smartphone|tablet), Role (15 values incl. domain-directory|vm-host|vm-guest|pbx|voip|dns|sql|backup|user-device). See Liongard docs for the full enum tree.
liongard_update_devices_bulk details
liongard_update_devices_bulk details
[Liongard] Bulk-update inventory state, status, and type across many device profiles. Liongard quirk: POST-for-update. Body: {"Environment": N, "IDs": ["uuid1","uuid2"], "InventoryState": "Archive", "Status": "inactive", "Type": "server"}.
Metrics
liongard_evaluate_metrics details
liongard_evaluate_metrics details
[Liongard] Evaluate one or more metrics across systems and return the values. WARNING: this endpoint has a STRICTER rate limit (100 req/min vs the platform-wide 2000 req/5min). Batch metric IDs into a single call rather than firing per-metric. Body: {"Metrics": [<int or UUID>], "Filters": [{"Field":"EnvironmentID","Op":"equal_to","Values":[1]}], "Sorting": [], "Pagination": {"Page":1,"PageSize":25}}. Filters/Sorting empty arrays required even when unused.
liongard_evaluate_metrics_by_system details
liongard_evaluate_metrics_by_system details
[Liongard] Evaluate ALL enabled metrics for a list of system IDs. Returns metric values per system. Useful when you want a posture snapshot for specific systems rather than a metric-first view. Body: {"Systems": [N1, N2], "Filters": [], "Sorting": [], "Pagination": }.
liongard_get_metric_related_environments details
liongard_get_metric_related_environments details
liongard_list_metrics details
liongard_list_metrics details
[Liongard] List defined metrics. Liongard quirk: this endpoint uses UPPERCASE Page/PageSize query params (most other endpoints use lowercase). Filters/Sorting are passed as repeated form params with JSON-string values, e.g. Filters[]={"FilterBy":"Name","Op":"contains","Value":"Active Directory"}.
Timeline & Detections
liongard_list_detections details
liongard_list_detections details
[Liongard] List detection events (alert-style records derived from inspector runs). POST-for-search body: {Pagination, Filters, Sorting, StartDate, EndDate}. StartDate/EndDate use ISO 8601 with Z (e.g. '2026-04-01T00:00:00.000Z'); Filters/Sorting may be empty arrays. Filter entries use {"FilterBy","Op","Value"} — NOT the {Field,Op,Values} shape in Liongard's own OAS, which the live validator rejects. FilterBy is one of 'name' | 'change-detection' (Op: contains, does_not_contain, matches_exactly, starts_with, ends_with, is_empty, is_not_empty; Value MUST be a string, even for numbers) or 'date' (Op: between_two_date_times/not_between_two_date_times with From/To, or exactly_on_date_time/from_a_date_time_forward/up_to_certain_date_time with Value). Broad queries can take 30-50s on large instances.
liongard_query_timeline details
liongard_query_timeline details
[Liongard] Query timeline entries (inspector runs). Each entry includes Status (queued/running/completed/failed), AdHoc, SystemID, SystemDetailID (presence indicates a dataprint exists), ChangeDetections, ScheduledAt/RunningAt/FinishedAt timestamps, ExitCode, ExitMessage. KNOWN VENDOR LIMITATIONS: Liongard's validator rejects every documented Filters shape on this endpoint (400 'Invalid request body' — do NOT send Filters entries), an empty Sorting array triggers a vendor 500 (StackJack strips empty Filters/Sorting automatically), and the query runs unfiltered — on instances with large timelines it may exceed the 2-minute budget and time out. For filtered change history use liongard_list_detections instead.
Dataprints
liongard_evaluate_dataprint details
liongard_evaluate_dataprint details
[Liongard] Run a JMESPath query against a system's inspection dataprint and return the matched values. JMESPath is a JSON query language (https://jmespath.org). Use liongard_get_inspector_schema_v1 to discover property paths for a given inspector. Body: {"QueryPath": "<jmespath expression>", "Pagination": {"Page":1,"PageSize":25}}.
Webhooks
liongard_create_webhook details
liongard_create_webhook details
[Liongard] Register a new webhook. WARNING: Liongard validates the URL is reachable at create time — returns 404 if the destination URL refuses the verification ping. Make sure the receiver is deployed and accepting requests before calling this. Body: {"Description": "...", "Url": "https://...", "Events": ["alert.created"]}. Currently only 'alert.created' is supported.
liongard_delete_webhook details
liongard_delete_webhook details
liongard_generate_webhook_signing_key details
liongard_generate_webhook_signing_key details
[Liongard] WARNING: DESTRUCTIVE. Generates a new global signing key used for HMAC-SHA256 signing of ALL webhook payloads. Calling this immediately invalidates HMAC verification for ALL existing webhook receivers — every receiver must be updated with the new key before the next event arrives. Use ONLY when rotating a compromised key. Returns the new signing key in the response (one-time visibility).
liongard_get_webhook details
liongard_get_webhook details
liongard_list_webhooks details
liongard_list_webhooks details
[Liongard] List configured webhooks. Each webhook has ID (UUID), URL, Description, Events (array; currently only 'alert.created' is published), Active flag, Health, CreatedOn, CreatedBy.
liongard_update_webhook details
liongard_update_webhook details
[Liongard] Update a single webhook. Adds Active toggle vs. create. Body: {"Description": "...", "Url": "https://...", "Events": ["alert.created"], "Active": true}.
Inspectors (v1)
liongard_get_inspector_schema_v1 details
liongard_get_inspector_schema_v1 details
[Liongard v1] Returns the JSON schema for an inspector's dataprint output, including all property paths (JMESPath-compatible). Pair with liongard_evaluate_dataprint (v2) to query specific values from a system's inspection.
liongard_get_inspector_v1 details
liongard_get_inspector_v1 details
[Liongard v1] Get a single inspector's metadata: name, version, description, inspection schedule, configuration schema. Use liongard_list_inspectors_v1 to discover IDs.
liongard_list_inspectors_v1 details
liongard_list_inspectors_v1 details
[Liongard v1] List all inspectors available in this tenant. Each inspector is a data source definition (e.g. 'Microsoft 365 Inspector'). Use to discover available data sources before chaining to liongard_get_inspector_schema_v1 for property paths usable in dataprint queries.
Systems (v1)
liongard_get_system_details_v1 details
liongard_get_system_details_v1 details
[Liongard v1] Get the most recent inspection details (dataprint snapshot) for a system. Returns the full inspector output. For targeted queries against this output, use liongard_evaluate_dataprint (v2) with the SystemDetailID.
liongard_get_system_v1 details
liongard_get_system_v1 details
liongard_list_systems_v1 details
liongard_list_systems_v1 details
[Liongard v1] List inspector instances (systems). v1 filter quirk: each filter is a JSON object inside a bracket-array query param, e.g. conditions[]={"path":"Name","op":"equals","value":"Contoso"}. Allowed path names are endpoint-specific and not published by Liongard — an unsupported path returns 400 'must be equal to constant'; known-good ops include equals, is, contains.
Launchpoints (v1)
liongard_create_launchpoint_v1 details
liongard_create_launchpoint_v1 details
[Liongard v1] Create a new launchpoint. Body shape: schedule, system, agent, configuration. Consult Liongard's v1 API explorer for the exact schema (varies by inspector type).
liongard_delete_launchpoint_v1 details
liongard_delete_launchpoint_v1 details
[Liongard v1] Delete a launchpoint. Stops scheduled inspections; the underlying system is not deleted.
liongard_get_launchpoint_v1 details
liongard_get_launchpoint_v1 details
liongard_list_launchpoints_v1 details
liongard_list_launchpoints_v1 details
[Liongard v1] List launchpoints (scheduled inspection triggers). Returns Schedule, NextScheduledFor, AssociatedSystem, AssociatedAgent, and configuration.
liongard_run_launchpoint_v1 details
liongard_run_launchpoint_v1 details
[Liongard v1] Trigger a manual ad-hoc run of a launchpoint's inspection. ASYNC — returns immediately; the actual inspection runs in the background. Poll liongard_query_timeline (v2) to see the resulting timeline entry transition through running → completed/failed.
liongard_update_launchpoint_v1 details
liongard_update_launchpoint_v1 details
Users (v1)
liongard_create_user_v1 details
liongard_create_user_v1 details
[Liongard v1] Create a Liongard user. Body shape includes Email, Name, Role assignments. Consult Liongard's v1 API explorer for exact schema (varies by tenant tier).
liongard_delete_user_v1 details
liongard_delete_user_v1 details
[Liongard v1] WARNING: Permanently delete a user. Removes all role assignments and revokes any API keys owned by that user.
liongard_get_user_v1 details
liongard_get_user_v1 details
liongard_list_users_v1 details
liongard_list_users_v1 details
[Liongard v1] List Liongard tenant users with their role assignments and account status. Useful for permission audits.
liongard_update_user_v1 details
liongard_update_user_v1 details
Service Providers (v1)
liongard_get_service_provider_v1 details
liongard_get_service_provider_v1 details
liongard_list_service_providers_v1 details
liongard_list_service_providers_v1 details
[Liongard v1] List service providers (top-level MSP entities). Most tenants have a single SP; multi-SP setups use this for tenant discovery.
Reports (v1)
liongard_download_report_v1 details
liongard_download_report_v1 details
[Liongard v1] Download a generated report binary and return a short-lived SAS URL pointing to the blob-stored copy. The connector enforces a 100 MB size cap. Confirm the report status is 'complete' (via liongard_get_report_v1) before calling — otherwise this returns 404 or partial content.
liongard_generate_report_v1 details
liongard_generate_report_v1 details
[Liongard v1] Trigger report generation. ASYNC — returns a job/report ID immediately. Poll liongard_get_report_v1 until status transitions from 'pending'/'running' to 'complete', then call liongard_download_report_v1 to fetch the binary. Body shape varies by report type — consult Liongard's v1 API explorer.
liongard_get_report_v1 details
liongard_get_report_v1 details
liongard_list_reports_v1 details
liongard_list_reports_v1 details
Alerts (v1)
liongard_acknowledge_alert_v1 details
liongard_acknowledge_alert_v1 details
[Liongard v1] Mark an alert as acknowledged. Idempotent — safe to call repeatedly. Useful for clearing resolved findings from the active alert queue.
liongard_get_alert_v1 details
liongard_get_alert_v1 details
liongard_list_alerts_v1 details
liongard_list_alerts_v1 details
[Liongard v1] List alerts (notifications from inspector runs). Returns severity, status (acknowledged/unacknowledged), source system, and alert text.
Tags (v1)
liongard_create_tag_v1 details
liongard_create_tag_v1 details
[Liongard v1] Create a new tag. Body: {"Name": "...", "Description": "...", "Color": "#hex"} or similar. Consult Liongard's v1 API explorer for exact schema.
liongard_delete_tag_v1 details
liongard_delete_tag_v1 details
[Liongard v1] Delete a tag. Removes the tag from all entities it was applied to.
liongard_get_tag_v1 details
liongard_get_tag_v1 details
liongard_list_tags_v1 details
liongard_list_tags_v1 details
liongard_update_tag_v1 details
liongard_update_tag_v1 details
Notes (v1)
liongard_create_note_v1 details
liongard_create_note_v1 details
[Liongard v1] Create a note attached to an entity. Body requires entity_type ('Environment'|'System'|'Launchpoint') and entity_id, plus the note text. Consult Liongard's v1 API explorer for exact schema.
liongard_delete_note_v1 details
liongard_delete_note_v1 details
liongard_get_note_v1 details
liongard_get_note_v1 details
liongard_list_notes_v1 details
liongard_list_notes_v1 details
[Liongard v1] List notes. Filter by entity_type / entity_id via the conditions param to scope to a specific environment or system.
liongard_update_note_v1 details
liongard_update_note_v1 details
Roles (v1)
liongard_get_role_v1 details
liongard_get_role_v1 details
liongard_list_roles_v1 details
liongard_list_roles_v1 details
[Liongard v1] List all roles defined in this tenant. Use to enumerate role names + permission sets when auditing user assignments.
Audit Log (v1)
liongard_list_audit_log_v1 details
liongard_list_audit_log_v1 details
[Liongard v1] List audit log entries with optional date-range filter. Returns who-did-what records (user, action, target, timestamp) for compliance and security review.
More in Tools Reference
Atera ToolsAuvik ToolsAvanan (Check Point Harmony Email) ToolsConnectWise Sell ToolsStill need help? Ask the team