Skip to main content
Tools Reference

Liongard Tools

Written By Christopher Scaminaci

Last updated 7 days ago

Liongard Tools

liongard_ · 77 tools · Free 44 · Pro 33 IT environment discovery, documentation and change detection. The credential is a Liongard access key and secret key. Both the v1 and v2 endpoints are covered, and the v1 tools carry a _v1 suffix in their names. Page size stops at 2000. Searches are POSTs that only read. The v1 report downloads return a short-lived link to the stored file.

All connector tools · Liongard setup guide

Liongard tool groups

Environments

ToolPlanAccessSummary
liongard_count_environmentsFreeRead-onlyReturns the total number of environments visible to the API key.
liongard_create_environmentProWriteCreate a new environment.
liongard_create_environments_bulkProWriteCreate multiple environments in one call.
liongard_delete_environmentProDestructiveWARNING: Permanently delete an environment.
liongard_get_environmentFreeRead-onlyGet a single environment by ID.
liongard_get_environment_related_entitiesFreeRead-onlyFetch all dependent objects for an environment in one call: launchpoints, agents, integration mappings, and child environments.
liongard_list_environmentsFreeRead-onlyList environments (top-level customer/site containers).
liongard_query_environment_dashboardFreeRead-onlyRun dashboard-metric queries against a single environment.
liongard_update_environmentProWriteUpdate a single environment by ID.
liongard_update_environments_bulkProWriteUpdate multiple environments in one call.

[Liongard] Returns the total number of environments visible to the API key. Useful as a cheap health check or to size pagination loops before calling liongard_list_environments.

[Liongard] Create a new environment. Body requires Name, Description, Parent (nullable), ShortName, and Tier (must be 'Core' or 'Essentials'). Returns the created environment with its assigned ID.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON body: {"Name": "Acme Corp", "Description": "...", "Parent": null, "ShortName": "acme", "Tier": "Core"}.

[Liongard] Create multiple environments in one call. Body must be a JSON array of environment-create objects (same shape as liongard_create_environment).

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON array of environment objects, each with Name/Description/Parent/ShortName/Tier.

[Liongard] WARNING: Permanently delete an environment. Setting relatedEntities=true also deletes child agents, launchpoints, and integration mappings — non-reversible. Use liongard_get_environment_related_entities first to understand the blast radius.

ParamTypeRequiredDefaultDescription
environmentIdintegeryesEnvironment ID (integer).
relatedEntitiesbooleannonullIf true, cascade-delete child agents/launchpoints/mappings. Default false (delete fails if children exist).

[Liongard] Get a single environment by ID. Returns full environment metadata including parent, short name, tier, creation date, and IDs of associated launchpoints/agents. Use liongard_list_environments to discover IDs.

ParamTypeRequiredDefaultDescription
environmentIdintegeryesEnvironment ID (integer).

[Liongard] List environments (top-level customer/site containers). Each environment groups inspectors, agents, launchpoints, and asset inventory. Returns paginated array with environment IDs, names, descriptions, and tier (Core or Essentials). Takes the FLAT parameters page/pageSize/columns/orderBy only — this is a GET, not a POST-for-search; a nested / object is NOT accepted (the stackjack_run_* dispatchers reject unknown arguments; a direct call silently ignores them). Liongard offers no server-side name filter on this endpoint: to find an environment by name, page through with orderBy='Name' and match client-side. Use liongard_get_environment for full details and liongard_get_environment_related_entities to fetch dependent objects.

ParamTypeRequiredDefaultDescription
columnsstringnonullOptional CSV of column names to limit response shape (e.g. 'ID,Name,Tier').
orderBystringnonullOptional sort expression (e.g. 'Name', 'CreatedOn DESC').
pageintegerno1Page number (1-based). Default 1.
pageSizeintegerno25Page size (default 25, max 2000).

[Liongard] Run dashboard-metric queries against a single environment. Body must contain a queryIdentifiers array of dashboard metric names (e.g. 'm365TotalUsers', 'workstationOsVersionPct', 'winServerEDRSoftware', 'macOSPctEncryptedAtRest'). See Liongard's UI dashboard for the full enum (60+ values). Use this for posture-snapshot reports.

ParamTypeRequiredDefaultDescription
environmentIdintegeryesEnvironment ID (integer).
queryBodyJsonstringyesJSON body: {"queryIdentifiers": ["m365TotalUsers", "workstationOsVersionPct"]}. See Liongard dashboard for valid query names.

[Liongard] Update a single environment by ID. Body uses the same shape as create (Name/Description/Parent/ShortName/Tier). Use liongard_list_environments to find IDs.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON body with fields to update (same shape as create).
environmentIdintegeryesEnvironment ID (integer).

[Liongard] Update multiple environments in one call. Body must be a JSON array of {EnvironmentId, Name, Description, Parent, ShortName, Tier} objects.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON array, each object containing EnvironmentId + fields to update.

Environment Groups

ToolPlanAccessSummary
liongard_create_environment_groupProWriteCreate an environment group.
liongard_delete_environment_groupsProDestructiveWARNING: Permanently delete one or more environment groups.
liongard_list_environment_groupsFreeRead-onlyList environment groups.
liongard_update_environment_groupProWriteUpdate a single environment group.

[Liongard] Create an environment group. Body requires AutoAddNewEnvironments (bool), Description, Environments (int[]), Name, Users (array of {UserID, GroupID}).

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON body: {"AutoAddNewEnvironments": true, "Description": "...", "Environments": [1,2], "Name": "...", "Users": [{"UserID":N, "GroupID":M}]}.

[Liongard] WARNING: Permanently delete one or more environment groups. Liongard quirk: this is a DELETE with a JSON BODY (not a path-based delete). Body shape: {"EnvironmentGroupIDs": [1, 2, 3]}. Environments inside the groups are NOT deleted — only the group association.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON body: {"EnvironmentGroupIDs": [1, 2, 3]}.

[Liongard] List environment groups. Each group bundles environment IDs and user permission assignments. Use to discover group IDs before applying group-level permissions.

ParamTypeRequiredDefaultDescription
idsstringnonullOptional comma-separated environment-group IDs to filter to specific groups.
pageintegerno1Page number (1-based). Default 1.
pageSizeintegerno25Page size (default 25, max 2000).

[Liongard] Update a single environment group. Body shape matches liongard_create_environment_group. Use liongard_list_environment_groups to find IDs.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON body with fields to update.
environmentGroupIdstringyesEnvironment group ID (string-of-integer per Liongard spec).

Agents

ToolPlanAccessSummary
liongard_delete_agentsProDestructiveWARNING: Permanently delete one or more agents.
liongard_generate_agent_installerProWriteGenerate a one-time installer download URL for a new agent in a specific environment.
liongard_list_agentsFreeRead-onlyList agents (Liongard collectors deployed in customer networks).

[Liongard] WARNING: Permanently delete one or more agents. Liongard quirk: this is a DELETE with a JSON BODY (not path-based). Body shape: {"AgentIDs": [1,2,3]}. Optional disableLaunchpoints flag also disables every launchpoint that pointed at the deleted agents. Use liongard_list_agents first to confirm IDs.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON body: {"AgentIDs": [1, 2, 3]}.
disableLaunchpointsbooleannonullIf true, also disable launchpoints that referenced the deleted agents.

[Liongard] Generate a one-time installer download URL for a new agent in a specific environment. Body requires os ('windows', 'mac', or 'linux') and environmentID. Returns an installer URL or installer artifact metadata.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON body: {"os": "windows"|"mac"|"linux", "environmentID": N}.

[Liongard] List agents (Liongard collectors deployed in customer networks). Liongard quirk: this is a POST-for-search endpoint at /view/agents. Body envelope: {Filters, Sorting, Pagination}. Liongard requires empty arrays even when not filtering — this tool sends defaults automatically when bodyJson is null. Optional flags excludeSummary/excludeAgents/excludeManaged trim the response shape.

ParamTypeRequiredDefaultDescription
bodyJsonstringnonullJSON body: {"Filters": [], "Sorting": [], "Pagination": {"Page": 1, "PageSize": 25}}. Pass null for defaults.
excludeAgentsbooleannonullSet true to skip the agents array in the response.
excludeManagedbooleannonullSet true to skip Liongard-managed (cloud) agents and return only customer-deployed agents.
excludeSummarybooleannonullSet true to skip the summary block in the response.

Asset Inventory — Identities

ToolPlanAccessSummary
liongard_get_identityFreeRead-onlyGet a single identity by UUID.
liongard_list_identitiesFreeRead-onlyQuery identities (users, service accounts, admins, guests, etc.) within an environment's asset inventory.
liongard_update_identities_bulkProWriteBulk-update inventory state, status, and type across many identities.
liongard_update_identityProWriteUpdate a single identity's classification (type, status, location, inventoryState, isManual).

[Liongard] Get a single identity by UUID. Returns full identity details including type, status, location, manual-curation flag.

ParamTypeRequiredDefaultDescription
identityIdstringyesIdentity UUID (e.g. 'f67ed3a3-ab41-4a03-ba96-aee435534fce').

[Liongard] Query identities (users, service accounts, admins, guests, etc.) within an environment's asset inventory. POST-for-search: body requires Environment (int, REQUIRED) and Filters/Pagination/Sorting (Liongard requires empty arrays even when unused). Returns identity records with type, status, location, inventory state, and isManual flag.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON body: {"Environment": <envId>, "Filters": [], "Sorting": [], "Pagination": {"Page":1,"PageSize":25}}. Environment is required.

[Liongard] Bulk-update inventory state, status, and type across many identities. Liongard quirk: this is a POST-for-update (not a PUT), per the bulk-mutate convention. Body: {"Environment": N, "IDs": ["uuid1","uuid2"], "InventoryState": "Archive", "Status": "inactive", "Type": "user"}.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON body: {"Environment": N, "IDs": ["uuid1"], "InventoryState": "...", "Status": "...", "Type": "..."}.

[Liongard] Update a single identity's classification (type, status, location, inventoryState, isManual). Type values: service|user|admin|guest|shared|system|application. Status values: suspended|active|inactive|expired|deactivated|deleted|pending-activation. InventoryState: Inventory|Archive|Discovery.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON body: {"Environment": N, "Type": "user", "Status": "active", "Location": "...", "IsLocationManaged": true, "InventoryState": "Inventory", "IsManual": false}.
identityIdstringyesIdentity UUID.

Asset Inventory — Devices

ToolPlanAccessSummary
liongard_get_deviceFreeRead-onlyGet a single device profile by UUID.
liongard_list_devicesFreeRead-onlyQuery device profiles within an environment's asset inventory.
liongard_update_deviceProWriteUpdate a device's classification or asset metadata.
liongard_update_devices_bulkProWriteBulk-update inventory state, status, and type across many device profiles.

[Liongard] Get a single device profile by UUID. Returns full device metadata: alias, class, status, category, type, role, location, host info, asset tag, purchase date, warranty/EOL dates, environment.

ParamTypeRequiredDefaultDescription
deviceIdstringyesDevice profile UUID.

[Liongard] Query device profiles within an environment's asset inventory. POST-for-search: body requires Environment, Filters, Pagination, Sorting (empty arrays required). Returns devices with class, status, category, type, role, location, and asset metadata.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON body: {"Environment": N, "Filters": [], "Sorting": [], "Pagination": {"Page":1,"PageSize":25}}. Environment is required.

[Liongard] Update a device's classification or asset metadata. Many enum fields: Class (critical|standar — Liongard spec typo, pass through as 'standar'), Status (active|inactive|idle|standby), Category (compute|network|iot-printer|storage), Type (server|host|desktop|laptop|smartphone|tablet), Role (15 values incl. domain-directory|vm-host|vm-guest|pbx|voip|dns|sql|backup|user-device). See Liongard docs for the full enum tree.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON body with fields to update (Alias, Class, Status, Category, Type, Role, Location, Environment, asset metadata, etc.).
deviceIdstringyesDevice profile UUID.

[Liongard] Bulk-update inventory state, status, and type across many device profiles. Liongard quirk: POST-for-update. Body: {"Environment": N, "IDs": ["uuid1","uuid2"], "InventoryState": "Archive", "Status": "inactive", "Type": "server"}.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON body: {"Environment": N, "IDs": ["uuid1"], "InventoryState": "...", "Status": "...", "Type": "..."}.

Metrics

ToolPlanAccessSummary
liongard_evaluate_metricsFreeRead-onlyEvaluate one or more metrics across systems and return the values.
liongard_evaluate_metrics_by_systemFreeRead-onlyEvaluate ALL enabled metrics for a list of system IDs.
liongard_get_metric_related_environmentsFreeRead-onlyReturns the environment IDs where a given metric is currently evaluated.
liongard_list_metricsFreeRead-onlyList defined metrics.

[Liongard] Evaluate one or more metrics across systems and return the values. WARNING: this endpoint has a STRICTER rate limit (100 req/min vs the platform-wide 2000 req/5min). Batch metric IDs into a single call rather than firing per-metric. Body: {"Metrics": [<int or UUID>], "Filters": [{"Field":"EnvironmentID","Op":"equal_to","Values":[1]}], "Sorting": [], "Pagination": {"Page":1,"PageSize":25}}. Filters/Sorting empty arrays required even when unused.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON body: {"Metrics": [<id-or-uuid>], "Filters": [], "Sorting": [], "Pagination": {"Page":1,"PageSize":25}}. Metrics array can mix integer IDs and UUIDs.
includeNonVisiblebooleannonullIf true, include disabled (display=off) metrics. Default false.

[Liongard] Evaluate ALL enabled metrics for a list of system IDs. Returns metric values per system. Useful when you want a posture snapshot for specific systems rather than a metric-first view. Body: {"Systems": [N1, N2], "Filters": [], "Sorting": [], "Pagination": }.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON body: {"Systems": [int IDs], "Filters": [], "Sorting": [], "Pagination": {"Page":1,"PageSize":25}}.

[Liongard] List defined metrics. Liongard quirk: this endpoint uses UPPERCASE Page/PageSize query params (most other endpoints use lowercase). Filters/Sorting are passed as repeated form params with JSON-string values, e.g. Filters[]={"FilterBy":"Name","Op":"contains","Value":"Active Directory"}.

ParamTypeRequiredDefaultDescription
filtersarraynonullOptional repeated filter expressions as JSON strings. Each: {"FilterBy":"Name","Op":"contains","Value":"..."}.
pageintegernonullPage number (1-based). Default 1.
pageSizeintegernonullPage size (default 25, max 2000).
sortingarraynonullOptional repeated sort expressions as JSON strings. Each: {"SortBy":"ID","Direction":"DESC"}.

Timeline & Detections

ToolPlanAccessSummary
liongard_list_detectionsFreeRead-onlyList detection events (alert-style records derived from inspector runs).
liongard_query_timelineFreeRead-onlyQuery timeline entries (inspector runs).

[Liongard] List detection events (alert-style records derived from inspector runs). POST-for-search body: {Pagination, Filters, Sorting, StartDate, EndDate}. StartDate/EndDate use ISO 8601 with Z (e.g. '2026-04-01T00:00:00.000Z'); Filters/Sorting may be empty arrays. Filter entries use {"FilterBy","Op","Value"} — NOT the {Field,Op,Values} shape in Liongard's own OAS, which the live validator rejects. FilterBy is one of 'name' | 'change-detection' (Op: contains, does_not_contain, matches_exactly, starts_with, ends_with, is_empty, is_not_empty; Value MUST be a string, even for numbers) or 'date' (Op: between_two_date_times/not_between_two_date_times with From/To, or exactly_on_date_time/from_a_date_time_forward/up_to_certain_date_time with Value). Broad queries can take 30-50s on large instances.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON body: {"Pagination": {"Page":1,"PageSize":25}, "Filters": [{"FilterBy":"name","Op":"contains","Value":"expiration"}], "Sorting": [], "StartDate": "2026-04-01T00:00:00.000Z", "EndDate": "2026-05-01T00:00:00.000Z"}. Filter Values must be strings.

[Liongard] Query timeline entries (inspector runs). Each entry includes Status (queued/running/completed/failed), AdHoc, SystemID, SystemDetailID (presence indicates a dataprint exists), ChangeDetections, ScheduledAt/RunningAt/FinishedAt timestamps, ExitCode, ExitMessage. KNOWN VENDOR LIMITATIONS: Liongard's validator rejects every documented Filters shape on this endpoint (400 'Invalid request body' — do NOT send Filters entries), an empty Sorting array triggers a vendor 500 (StackJack strips empty Filters/Sorting automatically), and the query runs unfiltered — on instances with large timelines it may exceed the 2-minute budget and time out. For filtered change history use liongard_list_detections instead.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON body: {"Sorting": [{"Field":"ID","Direction":"DESC"}], "Pagination": {"Page":1,"PageSize":25}}. Omit Filters entirely (entries are rejected upstream); empty Filters/Sorting arrays are stripped before sending.

Dataprints

ToolPlanAccessSummary
liongard_evaluate_dataprintFreeRead-onlyRun a JMESPath query against a system's inspection dataprint and return the matched values.

[Liongard] Run a JMESPath query against a system's inspection dataprint and return the matched values. JMESPath is a JSON query language (https://jmespath.org). Use liongard_get_inspector_schema_v1 to discover property paths for a given inspector. Body: {"QueryPath": "<jmespath expression>", "Pagination": {"Page":1,"PageSize":25}}.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON body: {"QueryPath": "users[?accountEnabled].userPrincipalName", "Pagination": {"Page":1,"PageSize":25}}. JMESPath: https://jmespath.org/specification.html
systemDetailIdintegeryesSystem detail ID (integer). Find via liongard_query_timeline — entries with a SystemDetailID have an evaluable dataprint.

Webhooks

ToolPlanAccessSummary
liongard_create_webhookProWriteRegister a new webhook.
liongard_delete_webhookProDestructiveDelete a webhook by UUID.
liongard_generate_webhook_signing_keyProDestructiveWARNING: DESTRUCTIVE.
liongard_get_webhookFreeRead-onlyGet a single webhook by UUID.
liongard_list_webhooksFreeRead-onlyList configured webhooks.
liongard_update_webhookProWriteUpdate a single webhook.

[Liongard] Register a new webhook. WARNING: Liongard validates the URL is reachable at create time — returns 404 if the destination URL refuses the verification ping. Make sure the receiver is deployed and accepting requests before calling this. Body: {"Description": "...", "Url": "https://...", "Events": ["alert.created"]}. Currently only 'alert.created' is supported.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON body: {"Description": "...", "Url": "https://...", "Events": ["alert.created"]}.
ParamTypeRequiredDefaultDescription
webhookIdstringyesWebhook UUID.

[Liongard] WARNING: DESTRUCTIVE. Generates a new global signing key used for HMAC-SHA256 signing of ALL webhook payloads. Calling this immediately invalidates HMAC verification for ALL existing webhook receivers — every receiver must be updated with the new key before the next event arrives. Use ONLY when rotating a compromised key. Returns the new signing key in the response (one-time visibility).

ParamTypeRequiredDefaultDescription
webhookIdstringyesWebhook UUID.

[Liongard] List configured webhooks. Each webhook has ID (UUID), URL, Description, Events (array; currently only 'alert.created' is published), Active flag, Health, CreatedOn, CreatedBy.

[Liongard] Update a single webhook. Adds Active toggle vs. create. Body: {"Description": "...", "Url": "https://...", "Events": ["alert.created"], "Active": true}.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON body: {"Description": "...", "Url": "...", "Events": [...], "Active": true|false}.
webhookIdstringyesWebhook UUID.

Inspectors (v1)

ToolPlanAccessSummary
liongard_get_inspector_schema_v1FreeRead-onlyReturns the JSON schema for an inspector's dataprint output, including all property paths (JMESPath-compatible).
liongard_get_inspector_v1FreeRead-onlyGet a single inspector's metadata: name, version, description, inspection schedule, configuration schema.
liongard_list_inspectors_v1FreeRead-onlyList all inspectors available in this tenant.

[Liongard v1] Returns the JSON schema for an inspector's dataprint output, including all property paths (JMESPath-compatible). Pair with liongard_evaluate_dataprint (v2) to query specific values from a system's inspection.

ParamTypeRequiredDefaultDescription
inspectorIdintegeryesInspector ID (integer).

[Liongard v1] Get a single inspector's metadata: name, version, description, inspection schedule, configuration schema. Use liongard_list_inspectors_v1 to discover IDs.

ParamTypeRequiredDefaultDescription
inspectorIdintegeryesInspector ID (integer).

[Liongard v1] List all inspectors available in this tenant. Each inspector is a data source definition (e.g. 'Microsoft 365 Inspector'). Use to discover available data sources before chaining to liongard_get_inspector_schema_v1 for property paths usable in dataprint queries.

ParamTypeRequiredDefaultDescription
fieldsstringnonullOptional CSV of fields to limit response shape (e.g. 'ID,Name,Version'). StackJack sends these to Liongard as repeated fields[] params.

Systems (v1)

ToolPlanAccessSummary
liongard_get_system_details_v1FreeRead-onlyGet the most recent inspection details (dataprint snapshot) for a system.
liongard_get_system_v1FreeRead-onlyGet a single system (inspector instance) with its current configuration and binding to an environment.
liongard_list_systems_v1FreeRead-onlyList inspector instances (systems).

[Liongard v1] Get the most recent inspection details (dataprint snapshot) for a system. Returns the full inspector output. For targeted queries against this output, use liongard_evaluate_dataprint (v2) with the SystemDetailID.

ParamTypeRequiredDefaultDescription
systemIdintegeryesSystem ID (integer).
ParamTypeRequiredDefaultDescription
systemIdintegeryesSystem ID (integer).

[Liongard v1] List inspector instances (systems). v1 filter quirk: each filter is a JSON object inside a bracket-array query param, e.g. conditions[]={"path":"Name","op":"equals","value":"Contoso"}. Allowed path names are endpoint-specific and not published by Liongard — an unsupported path returns 400 'must be equal to constant'; known-good ops include equals, is, contains.

ParamTypeRequiredDefaultDescription
conditionsstringnonullOptional pre-formatted Liongard v1 conditions query suffix, appended to the URL verbatim (no leading '?'). Format: conditions[]={"path":"Name","op":"equals","value":"Contoso"} — one conditions[]= per filter, '&'-joined. Percent-encode individual VALUES if they contain '&', '#', or '+'. Unsupported path names return 400.
fieldsstringnonullOptional CSV of fields to limit response shape (e.g. 'ID,Name'). StackJack sends these to Liongard as repeated fields[] params.

Launchpoints (v1)

ToolPlanAccessSummary
liongard_create_launchpoint_v1ProWriteCreate a new launchpoint.
liongard_delete_launchpoint_v1ProDestructiveDelete a launchpoint.
liongard_get_launchpoint_v1FreeRead-onlyGet a single launchpoint by ID with full configuration.
liongard_list_launchpoints_v1FreeRead-onlyList launchpoints (scheduled inspection triggers).
liongard_run_launchpoint_v1ProWriteTrigger a manual ad-hoc run of a launchpoint's inspection.
liongard_update_launchpoint_v1ProWriteUpdate launchpoint schedule or configuration.

[Liongard v1] Create a new launchpoint. Body shape: schedule, system, agent, configuration. Consult Liongard's v1 API explorer for the exact schema (varies by inspector type).

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON body — see Liongard v1 docs for the exact schema.

[Liongard v1] Delete a launchpoint. Stops scheduled inspections; the underlying system is not deleted.

ParamTypeRequiredDefaultDescription
launchpointIdintegeryesLaunchpoint ID (integer).
ParamTypeRequiredDefaultDescription
launchpointIdintegeryesLaunchpoint ID (integer).

[Liongard v1] List launchpoints (scheduled inspection triggers). Returns Schedule, NextScheduledFor, AssociatedSystem, AssociatedAgent, and configuration.

ParamTypeRequiredDefaultDescription
conditionsstringnonullOptional pre-formatted Liongard v1 conditions query suffix, appended to the URL verbatim (no leading '?'). Format: conditions[]={"path":"Name","op":"equals","value":"AD-Acme"} — one conditions[]= per filter, '&'-joined. Allowed path names are endpoint-specific and unpublished; an unsupported path returns 400. Percent-encode individual VALUES containing '&', '#', or '+'.
fieldsstringnonullOptional CSV of fields to limit response shape (e.g. 'ID,Name'). StackJack sends these to Liongard as repeated fields[] params.

[Liongard v1] Trigger a manual ad-hoc run of a launchpoint's inspection. ASYNC — returns immediately; the actual inspection runs in the background. Poll liongard_query_timeline (v2) to see the resulting timeline entry transition through running → completed/failed.

ParamTypeRequiredDefaultDescription
launchpointIdintegeryesLaunchpoint ID (integer).
ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON body with fields to update.
launchpointIdintegeryesLaunchpoint ID (integer).

Users (v1)

ToolPlanAccessSummary
liongard_create_user_v1ProWriteCreate a Liongard user.
liongard_delete_user_v1ProDestructiveWARNING: Permanently delete a user.
liongard_get_user_v1FreeRead-onlyGet a single user by ID with full role and group memberships.
liongard_list_users_v1FreeRead-onlyList Liongard tenant users with their role assignments and account status.
liongard_update_user_v1ProWriteUpdate user details or role assignments.

[Liongard v1] Create a Liongard user. Body shape includes Email, Name, Role assignments. Consult Liongard's v1 API explorer for exact schema (varies by tenant tier).

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON body — see Liongard v1 docs.

[Liongard v1] WARNING: Permanently delete a user. Removes all role assignments and revokes any API keys owned by that user.

ParamTypeRequiredDefaultDescription
userIdintegeryesUser ID (integer).
ParamTypeRequiredDefaultDescription
userIdintegeryesUser ID (integer).

[Liongard v1] List Liongard tenant users with their role assignments and account status. Useful for permission audits.

ParamTypeRequiredDefaultDescription
fieldsstringnonullOptional CSV of fields to limit response shape (e.g. 'ID,Name'). StackJack sends these to Liongard as repeated fields[] params.
ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON body with fields to update.
userIdintegeryesUser ID (integer).

Service Providers (v1)

ToolPlanAccessSummary
liongard_get_service_provider_v1FreeRead-onlyGet a single service provider's metadata.
liongard_list_service_providers_v1FreeRead-onlyList service providers (top-level MSP entities).
ParamTypeRequiredDefaultDescription
serviceProviderIdintegeryesService Provider ID (integer).

[Liongard v1] List service providers (top-level MSP entities). Most tenants have a single SP; multi-SP setups use this for tenant discovery.

Reports (v1)

ToolPlanAccessSummary
liongard_download_report_v1FreeRead-onlyDownload a generated report binary and return a short-lived SAS URL pointing to the blob-stored copy.
liongard_generate_report_v1ProWriteTrigger report generation.
liongard_get_report_v1FreeRead-onlyGet a single report's metadata: status (pending/running/complete/failed), generated_at, expires_at, source data.
liongard_list_reports_v1FreeRead-onlyList Liongard reports (audit outputs, configuration snapshots, etc.) with their generation status.

[Liongard v1] Download a generated report binary and return a short-lived SAS URL pointing to the blob-stored copy. The connector enforces a 100 MB size cap. Confirm the report status is 'complete' (via liongard_get_report_v1) before calling — otherwise this returns 404 or partial content.

ParamTypeRequiredDefaultDescription
reportIdintegeryesReport ID (integer).
sasTtlMinutesintegerno60How long the SAS URL should remain valid, in minutes. Default 60.

[Liongard v1] Trigger report generation. ASYNC — returns a job/report ID immediately. Poll liongard_get_report_v1 until status transitions from 'pending'/'running' to 'complete', then call liongard_download_report_v1 to fetch the binary. Body shape varies by report type — consult Liongard's v1 API explorer.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON body — see Liongard v1 docs for the exact report-type schema.
ParamTypeRequiredDefaultDescription
reportIdintegeryesReport ID (integer).
ParamTypeRequiredDefaultDescription
fieldsstringnonullOptional CSV of fields to limit response shape (e.g. 'ID,Name'). StackJack sends these to Liongard as repeated fields[] params.

Alerts (v1)

ToolPlanAccessSummary
liongard_acknowledge_alert_v1ProDestructiveMark an alert as acknowledged.
liongard_get_alert_v1FreeRead-onlyGet a single alert by ID with full context.
liongard_list_alerts_v1FreeRead-onlyList alerts (notifications from inspector runs).

[Liongard v1] Mark an alert as acknowledged. Idempotent — safe to call repeatedly. Useful for clearing resolved findings from the active alert queue.

ParamTypeRequiredDefaultDescription
alertIdintegeryesAlert ID (integer).
ParamTypeRequiredDefaultDescription
alertIdintegeryesAlert ID (integer).

[Liongard v1] List alerts (notifications from inspector runs). Returns severity, status (acknowledged/unacknowledged), source system, and alert text.

ParamTypeRequiredDefaultDescription
conditionsstringnonullOptional pre-formatted Liongard v1 conditions query suffix, appended to the URL verbatim (no leading '?'). Format: conditions[]={"path":"Acknowledged","op":"is","value":false} — one conditions[]= per filter, '&'-joined. Allowed path names are endpoint-specific and unpublished; an unsupported path returns 400. Percent-encode individual VALUES containing '&', '#', or '+'.
fieldsstringnonullOptional CSV of fields to limit response shape (e.g. 'ID,Name'). StackJack sends these to Liongard as repeated fields[] params.

Tags (v1)

ToolPlanAccessSummary
liongard_create_tag_v1ProWriteCreate a new tag.
liongard_delete_tag_v1ProDestructiveDelete a tag.
liongard_get_tag_v1FreeRead-onlyGet a single tag by ID.
liongard_list_tags_v1FreeRead-onlyList all tags defined in this tenant.
liongard_update_tag_v1ProWriteUpdate tag metadata.

[Liongard v1] Create a new tag. Body: {"Name": "...", "Description": "...", "Color": "#hex"} or similar. Consult Liongard's v1 API explorer for exact schema.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON body — see Liongard v1 docs.

[Liongard v1] Delete a tag. Removes the tag from all entities it was applied to.

ParamTypeRequiredDefaultDescription
tagIdintegeryesTag ID (integer).
ParamTypeRequiredDefaultDescription
tagIdintegeryesTag ID (integer).
ParamTypeRequiredDefaultDescription
fieldsstringnonullOptional CSV of fields to limit response shape (e.g. 'ID,Name'). StackJack sends these to Liongard as repeated fields[] params.
ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON body with fields to update.
tagIdintegeryesTag ID (integer).

Notes (v1)

ToolPlanAccessSummary
liongard_create_note_v1ProWriteCreate a note attached to an entity.
liongard_delete_note_v1ProDestructiveDelete a note.
liongard_get_note_v1FreeRead-onlyGet a single note by ID.
liongard_list_notes_v1FreeRead-onlyList notes.
liongard_update_note_v1ProWriteUpdate note text or metadata.

[Liongard v1] Create a note attached to an entity. Body requires entity_type ('Environment'|'System'|'Launchpoint') and entity_id, plus the note text. Consult Liongard's v1 API explorer for exact schema.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON body — see Liongard v1 docs.
ParamTypeRequiredDefaultDescription
noteIdintegeryesNote ID (integer).
ParamTypeRequiredDefaultDescription
noteIdintegeryesNote ID (integer).

[Liongard v1] List notes. Filter by entity_type / entity_id via the conditions param to scope to a specific environment or system.

ParamTypeRequiredDefaultDescription
conditionsstringnonullOptional pre-formatted Liongard v1 conditions query suffix, appended to the URL verbatim (no leading '?'). Format: conditions[]={"path":"EntityType","op":"equals","value":"Environment"} — one conditions[]= per filter, '&'-joined. Allowed path names are endpoint-specific and unpublished; an unsupported path returns 400. Percent-encode individual VALUES containing '&', '#', or '+'.
fieldsstringnonullOptional CSV of fields to limit response shape (e.g. 'ID,Name'). StackJack sends these to Liongard as repeated fields[] params.
ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON body with fields to update.
noteIdintegeryesNote ID (integer).

Roles (v1)

ToolPlanAccessSummary
liongard_get_role_v1FreeRead-onlyGet a single role by ID with its full permission set.
liongard_list_roles_v1FreeRead-onlyList all roles defined in this tenant.
ParamTypeRequiredDefaultDescription
roleIdintegeryesRole ID (integer).

[Liongard v1] List all roles defined in this tenant. Use to enumerate role names + permission sets when auditing user assignments.

Audit Log (v1)

ToolPlanAccessSummary
liongard_list_audit_log_v1FreeRead-onlyList audit log entries with optional date-range filter.

[Liongard v1] List audit log entries with optional date-range filter. Returns who-did-what records (user, action, target, timestamp) for compliance and security review.

ParamTypeRequiredDefaultDescription
endDatestringnonullOptional ISO 8601 end date (e.g. '2026-05-01T00:00:00Z').
pageintegernonullPage number (1-based). Default 1.
pageSizeintegernonullPage size (default 25, max 2000).
startDatestringnonullOptional ISO 8601 start date (e.g. '2026-04-01T00:00:00Z').