Skip to main content
Tools Reference

CyberQP Tools

Written By Christopher Scaminaci

Last updated 7 days ago

CyberQP Tools

qp_ · 19 tools · Free 11 · Pro 8 Privileged-access management: just-in-time admin accounts and policies, password and one-time-code retrieval, customers, tenant metadata, identity verification and events. There is no machine-to-machine grant - the durable credential is a refresh token captured once through an interactive admin consent in a browser, and it is refreshed automatically from then on. The regional host is part of the instance address, US, EU or Canada. Paging is page and limit on the customer, tenant and JIT-account lists, with limit capped at 100. The customer list requires a directory type of AD, Office or Local.

All connector tools · CyberQP setup guide

JIT Accounts & Policies

ToolPlanAccessSummary
qp_check_jit_account_existsFreeRead-onlyCheck whether a JIT account already exists for a customer and directory type before creating one.
qp_create_jit_accountProWriteCreate a just-in-time privileged admin account for a customer.
qp_delete_jit_accountProDestructivePermanently delete a JIT privileged admin account.
qp_delete_jit_account_otp_secretProDestructiveDelete the stored OTP (TOTP) secret from a JIT account.
qp_disable_jit_accountProWriteDisable (de-elevate) a JIT privileged admin account.
qp_enable_jit_accountProWriteEnable (elevate) a JIT privileged admin account for a bounded window.
qp_get_jit_account_otpFreeRead-onlyRetrieve the current TOTP code(s) for a JIT privileged admin account's stored OTP secret.
qp_get_jit_account_passwordFreeRead-onlyRetrieve the CURRENT CLEARTEXT password for a JIT privileged admin account.
qp_list_customer_jit_accountsFreeRead-onlyList the just-in-time (JIT) privileged admin accounts for a single customer.
qp_list_jit_policiesFreeRead-onlyList the JIT account policies available for a customer and account type.
qp_list_tenant_jit_accountsFreeRead-onlyList every JIT privileged admin account across the whole tenant (all customers).
qp_save_jit_account_otp_secretProWriteStore/replace the OTP (TOTP) secret for a JIT account so its live codes can later be read with qp_get_jit_account_otp.

[CyberQP] Check whether a JIT account already exists for a customer and directory type before creating one. userType is REQUIRED and must be one of AD, OFFICE, or LOCAL. agentId is optional and applies only to LOCAL accounts. customerId comes from qp_list_customers.

ParamTypeRequiredDefaultDescription
agentIdstringnonullOptional agent id — LOCAL accounts only.
customerIdstringyesCustomer id to check. From qp_list_customers.
userTypestringyesDirectory type (REQUIRED): AD, OFFICE, or LOCAL.

[CyberQP] Create a just-in-time privileged admin account for a customer. bodyJson is the request body: { username, userType (AD|OFFICE|LOCAL), policyId (from qp_list_jit_policies), duration (1h|4h|8h|1d|3d|7d|30d), reason, agentId? }. agentId applies to LOCAL accounts only. customerId from qp_list_customers. Returns the created account JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesBody JSON: { username, userType (AD|OFFICE|LOCAL), policyId, duration (1h|4h|8h|1d|3d|7d|30d), reason, agentId? (LOCAL only) }.
customerIdstringyesCustomer id to create the account under. From qp_list_customers.

[CyberQP] Permanently delete a JIT privileged admin account. Irreversible — the account and its stored secrets are removed. customerId from qp_list_customers; accountId from qp_list_customer_jit_accounts / qp_list_tenant_jit_accounts.

ParamTypeRequiredDefaultDescription
accountIdstringyesJIT account id to delete. From qp_list_customer_jit_accounts / qp_list_tenant_jit_accounts.
customerIdstringyesCustomer id owning the account. From qp_list_customers.

[CyberQP] Delete the stored OTP (TOTP) secret from a JIT account. After this, qp_get_jit_account_otp will no longer return codes until a new secret is saved. Irreversible. customerId from qp_list_customers; accountId from qp_list_customer_jit_accounts.

ParamTypeRequiredDefaultDescription
accountIdstringyesJIT account id. From qp_list_customer_jit_accounts / qp_list_tenant_jit_accounts.
customerIdstringyesCustomer id owning the account. From qp_list_customers.

[CyberQP] Disable (de-elevate) a JIT privileged admin account. bodyJson is an OPTIONAL request body carrying audit metadata: { metadata?: { application, device?, ipAddress? } }; omit it to send an empty body. Reversible via qp_enable_jit_account. customerId from qp_list_customers; accountId from qp_list_customer_jit_accounts.

ParamTypeRequiredDefaultDescription
accountIdstringyesJIT account id. From qp_list_customer_jit_accounts / qp_list_tenant_jit_accounts.
bodyJsonstringnonullOptional body JSON: { metadata?: { application, device?, ipAddress? } }. Omit for an empty body.
customerIdstringyesCustomer id owning the account. From qp_list_customers.

[CyberQP] Enable (elevate) a JIT privileged admin account for a bounded window. bodyJson is the request body: { policyId (from qp_list_jit_policies), duration (1h|4h|8h|1d|3d|7d|30d), reason }. Reversible via qp_disable_jit_account. customerId from qp_list_customers; accountId from qp_list_customer_jit_accounts.

ParamTypeRequiredDefaultDescription
accountIdstringyesJIT account id. From qp_list_customer_jit_accounts / qp_list_tenant_jit_accounts.
bodyJsonstringyesBody JSON: { policyId, duration (1h|4h|8h|1d|3d|7d|30d), reason }.
customerIdstringyesCustomer id owning the account. From qp_list_customers.

[CyberQP] Retrieve the current TOTP code(s) for a JIT privileged admin account's stored OTP secret. This returns a live one-time-passcode — handle as sensitive material. Requires an OTP secret to have been saved (qp_save_jit_account_otp_secret). customerId from qp_list_customers; accountId from qp_list_customer_jit_accounts.

ParamTypeRequiredDefaultDescription
accountIdstringyesJIT account id. From qp_list_customer_jit_accounts / qp_list_tenant_jit_accounts.
customerIdstringyesCustomer id owning the account. From qp_list_customers.

[CyberQP] Retrieve the CURRENT CLEARTEXT password for a JIT privileged admin account. This returns a live privileged secret — handle the response as sensitive material. customerId from qp_list_customers; accountId from qp_list_customer_jit_accounts / qp_list_tenant_jit_accounts.

ParamTypeRequiredDefaultDescription
accountIdstringyesJIT account id. From qp_list_customer_jit_accounts / qp_list_tenant_jit_accounts.
customerIdstringyesCustomer id owning the account. From qp_list_customers.

[CyberQP] List the just-in-time (JIT) privileged admin accounts for a single customer. Paginated via limit + page; response envelope {totalItems, data:[...]}. customerId comes from qp_list_customers. Account ids in the response feed qp_get_jit_account_password, qp_enable_jit_account, and the other per-account tools.

ParamTypeRequiredDefaultDescription
customerIdstringyesCustomer id whose JIT accounts to list. From qp_list_customers.
limitintegerno25Max results per page (1-100, default 25).
pageintegerno11-based page number (default 1).
searchTextstringnonullOptional free-text filter on account username/display.

[CyberQP] List the JIT account policies available for a customer and account type. Both accountType (AD, OFFICE, LOCAL, or HYBRID) and customerId are REQUIRED. NOT paginated. The returned policy ids feed the policyId parameter of qp_create_jit_account and qp_enable_jit_account.

ParamTypeRequiredDefaultDescription
accountTypestringyesAccount type (REQUIRED): AD, OFFICE, LOCAL, or HYBRID.
customerIdstringyesCustomer id (REQUIRED). From qp_list_customers.

[CyberQP] List every JIT privileged admin account across the whole tenant (all customers). Paginated via limit + page; response envelope {totalItems, data:[...]}. For a single customer's accounts use qp_list_customer_jit_accounts instead.

ParamTypeRequiredDefaultDescription
limitintegerno25Max results per page (1-100, default 25).
pageintegerno11-based page number (default 1).
searchTextstringnonullOptional free-text filter on account username/display.

[CyberQP] Store/replace the OTP (TOTP) secret for a JIT account so its live codes can later be read with qp_get_jit_account_otp. bodyJson is the request body: where otp is a base32 secret of at least 16 characters. customerId from qp_list_customers; accountId from qp_list_customer_jit_accounts.

ParamTypeRequiredDefaultDescription
accountIdstringyesJIT account id. From qp_list_customer_jit_accounts / qp_list_tenant_jit_accounts.
bodyJsonstringyesBody JSON: — a base32 secret, minimum 16 characters.
customerIdstringyesCustomer id owning the account. From qp_list_customers.

Platform

ToolPlanAccessSummary
qp_get_auth_statusFreeRead-onlyGet the authenticated technician's auth/session status for the connected CyberQP tenant.
qp_get_customer_account_countsFreeRead-onlyGet the account counts for a single customer (managed organization), identified by its customer id from qp_list_customers.
qp_get_install_tokenFreeRead-onlyGet the CyberQP agent install token for the connected tenant.
qp_get_tenant_company_dataFreeRead-onlyGet the connected CyberQP tenant's company/branding metadata (company name, and related tenant profile data).
qp_list_customersFreeRead-onlyList the customers (managed organizations) in your CyberQP tenant.
qp_process_eventProWriteSubmit an event to CyberQP for processing.
qp_trigger_identity_verificationProWriteTrigger a self-serve identity-verification notification for an end user.

[CyberQP] Get the authenticated technician's auth/session status for the connected CyberQP tenant. Use this to confirm the connector's credentials are live and to see the authenticated identity and scopes. This is also the endpoint StackJack's Test Connection uses to validate CyberQP credentials.

[CyberQP] Get the account counts for a single customer (managed organization), identified by its customer id from qp_list_customers. Returns per-directory account tallies for the customer.

ParamTypeRequiredDefaultDescription
customerIdstringyesThe customer id (from qp_list_customers).

[CyberQP] Get the CyberQP agent install token for the connected tenant. This token is used to enroll/install the CyberQP agent on endpoints. Treat the returned value as a secret.

[CyberQP] List the customers (managed organizations) in your CyberQP tenant. directoryType is REQUIRED by CyberQP and selects which directory the customers are drawn from — one of AD (on-prem Active Directory), OFFICE (Microsoft 365 / Entra ID), or LOCAL (local machine accounts). Optional name filters by (partial) customer name. Page-based pagination via page (1-based) + limit (max 100). Use the returned customer id with qp_get_customer_account_counts, qp_list_customer_jit_accounts, and the JIT account tools.

ParamTypeRequiredDefaultDescription
directoryTypestringyesREQUIRED directory type: one of AD, OFFICE, or LOCAL.
limitintegerno25Records per page (default 25, max 100).
namestringnonullOptional customer-name filter.
pageintegerno11-based page number (default 1).

[CyberQP] Submit an event to CyberQP for processing. Provide a JSON object body with required fields: customerId (the customer id from qp_list_customers), accountId (the target account id), and action (the event action to process). Events can drive downstream CyberQP automation for the referenced account.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body. Required: customerId (string), accountId (string), action (string).

[CyberQP] Trigger a self-serve identity-verification notification for an end user. Provide a JSON object body with required fields: email (the end user's email address) and ticketId (the associated support ticket id). This sends the user a verification prompt; it does not itself return a verification result.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesJSON object body. Required: email (string), ticketId (string).