Connect N-able N-sight RMM
N-able N-sight RMM is N-able's remote monitoring and management platform for smaller MSPs, marketed today as N-able N-sight. It is where your clients, sites and devices report in, where checks fail…
Written By Christopher Scaminaci
Last updated About 3 hours ago
N-able N-sight RMM is N-able's remote monitoring and management platform for smaller MSPs, marketed today as N-able N-sight. It is where your clients, sites and devices report in, where checks fail and raise alerts, and where patching, Managed Antivirus and Backup and Recovery are run. StackJack talks to it through N-sight's Data Extraction API.
This is a different connector from N-able N-central, which StackJack also supports. They are separate products with separate credentials, and you can connect either or both.
Connecting N-sight to StackJack gives your AI assistant a family of nsight_ MCP tools. MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:
- See what is broken right now - the failing checks across your account or one client, the open outages and the last 61 days of closed ones, the formatted output of any check, and a device's performance and disk history
- Walk the estate - your clients, their sites, and the servers, workstations and mobile devices at each, with a device's full monitoring detail and its check configuration
- Check patching - every patch on a device with its severity and current policy, and (on Pro plans) approve, ignore, retry, reprocess or reset patches
- Check antivirus - the antivirus products N-sight supports and their definition history, a device's antivirus check history, and Managed Antivirus scans, threats and quarantine, and (on Pro plans) start, pause, resume or cancel a scan, update definitions, and release or delete quarantined files
- Check backups - Backup and Recovery sessions and their sizes, the monthly selection sizes for billing, and the last 90 days of backup check results
- Answer asset questions - a device's hardware and software, licensed software, license groups and per-client license counts
- Look after the account - add clients and sites, add notes to a check, clear a failing check, run an Automated Task that is already configured on a device, and read the account's general settings (writes need a Pro plan)
- Hand over an agent installer - build a site installation package and get a short-lived download link for it
How StackJack authenticates to N-sight
N-sight gives you one thing: an API key. You paste it into StackJack and pick your territory. There is no client ID, no second secret, no sign-in and nothing to renew on a schedule.
Use the key your account already has
Do not press Regenerate to get a key for StackJack. An N-sight account has exactly one API key, and regenerating it overwrites the old one. Every other integration that uses it, such as a PSA sync, a documentation tool or a script of your own, stops working until it is given the new key, and neither N-sight nor StackJack can warn you first. Copy the key that is already there. Create a new one only if the account has none.
Pick your territory
N-sight runs in eleven separate territories, and your account lives in exactly one of them: Americas, Asia, Australia, Europe, France (FR), France1, Germany, Ireland, Poland, United Kingdom and United States. A key only works against its own territory's server.
StackJack asks which one you are on and stores that choice, so the connection cannot drift onto the wrong server later. There is no default. If you pick the wrong territory, N-sight refuses the key with a "Login failed" answer that looks exactly like a bad key. If a key you are sure of is refused, check the territory before you change anything in N-sight.
The address you sign in to N-sight at usually names the region. If you use a custom dashboard domain that hides it, N-able's own guide explains how to work it out, and the setup steps in StackJack link to it.
Steps
- Find your territory (see above).
- Sign in to N-sight with an account that may generate the key: a Superuser, a (non-Classic) Administrator, a login with the required General permissions enabled, or the Agent Key if it is enabled.
- In the All Devices view, go to Settings > General Settings > API.
- If a key is already shown, copy it. Do not press Regenerate. If there is none, select Generate and copy the new one.
- In StackJack, open the N-able N-sight RMM connector, select your territory, paste the key, and save.
The key sees only the clients in your Agent Key's client group
If your Agent Key is assigned to a client group that holds only some of your clients, the API key returns only those clients. A key that works can therefore still show part of your estate. If a client you expect is missing, or a list comes back empty, check the client group in N-sight first: that is a setting there, not an outage, and not a StackJack problem.
What to know before you turn it on
N-sight has no read-only key
An N-sight API key has no scopes. It can use every service, so the key itself cannot limit what an AI assistant does. StackJack's own controls are the way to limit it: reads are on the Free plan and every change is on the Pro plan, and you can leave tools out of an endpoint's tool selection.
Some tools act on live endpoints
Some of the write tools deserve a closer look before you let an assistant near them. Each of these is marked destructive:
- Approving, ignoring, setting to do nothing, setting to inherit, reprocessing or retrying a patch decides what installs on a live customer endpoint. Ignoring a security update leaves the machine exposed until someone reverses it, and setting a patch back to inherit can switch on an approval that was not meant to be live.
- Running an Automated Task runs a script that is already configured on the device, on that live endpoint, now. StackJack cannot push a new script; it can only run one that is already there.
- Pausing or cancelling an antivirus scan leaves the endpoint unscanned until someone starts another.
- Releasing a file from antivirus quarantine puts it back on the live endpoint where it can run again, and deleting it from quarantine is permanent.
- Clearing a failing check marks it acknowledged and silences its alert until it passes, until its next run or until a date. N-sight writes an entry in its User Audit Report every time.
Whether your AI application asks you to confirm before running one depends on that application's own settings; see Destructive tools and confirmation. Review that setting before you enable the write tools.
Notes marked client-facing are read by your customer
When a check is cleared or a note is added, N-sight lets you write a private (technical) note and a public note. The public note is client-facing: your customer can read it. The tools say so, and an assistant should write it for the customer, not for you.
A write is sent once, and never retried for you
N-sight performs every change as an ordinary web request, which is the kind of request a network would normally retry on a timeout. StackJack deliberately does not: a change is sent exactly once, so a slow answer can never approve a patch or start a task twice. The cost is that after a timeout you have to check the state yourself before you repeat a change. See Retrying a failed or timed-out write.
Some reads return product keys, saved remote-desktop details and SNMP community strings
The device lists and the asset details carry Windows product keys, and the server list also carries each server's saved remote-desktop address, user name and domain. The configuration of an SNMP check or a bandwidth monitoring check carries the SNMP community string for the device it watches, which works as that device's password. StackJack treats those answers as sensitive: a very large answer of that kind is refused rather than saved to a download link. They do reach your AI assistant when it asks, so grant them deliberately and do not paste them into tickets or chat.
There is no paging, so ask for the narrowest thing
N-sight has no pages. An account-wide call returns everything, and on a large account that can be big and slow. N-able itself advises narrowing by client, and StackJack's tools steer an assistant the same way: the failing-check read takes a client, the device reads take a site or a client, and everything per device takes a device. There is also no "all devices" call in N-sight at all: devices are read per site or per client. N-able asks API users to stay under 60 calls a minute, and StackJack stays below that for you.
Answers are converted from XML
N-sight answers in XML and nothing else. StackJack converts every answer to JSON so your assistant can read it, keeping every value exactly as N-sight sent it, as text. Where N-sight's own examples show a repeating list, it arrives as a list even when there is only one entry, while a single value such as a user name or a patch flag stays plain text. The one exception is the agent installer, which is a file: StackJack stores it and hands your assistant a temporary download link instead. The link is short-lived, about thirty minutes, so fetch it when you get it. If N-sight answers an installer request with a short status document instead of a file, you get that document converted like any other answer and no link is made.
Managed Antivirus has two engines
Managed Antivirus devices run either the older VIPRE engine or Bitdefender. The antivirus read tools default to Bitdefender, as N-sight's own guide documents, and take an optional engine version if you need to ask about a VIPRE device.
One tool is deprecated
N-able has marked its agentless assets feature as deprecated. The tool for it is still available and says so, but the workstation list already includes agentless scans and mini-agent devices, so prefer that.
Plans and limits
Read tools are available on the Free plan. Every change needs Pro, whether it is adding a client, adding a note to a check, or acting on an endpoint. Business offers the same tool set as Pro with a higher monthly call quota. N-sight has no per-user sign-in, so every call authenticates as the account's one key, and N-sight's own audit trail records it that way.
If you run two N-sight accounts, for example in two territories, add a separate named connection for each, with that account's territory and key. See Several connections of one connector.
See the generated N-able N-sight RMM tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.
Troubleshooting
"N-able N-sight RMM refused the API key" - three causes, in the order worth checking. The territory is wrong; the key was regenerated in N-sight (every integration using it stopped at the same moment, so check whether something else broke too); or the key was pasted incompletely. A key from one territory used with another selected fails exactly this way, and it is the easiest of the three to miss because the message is the same.
A connection test passes but a client is missing - the key is valid and the client is outside your Agent Key's client group. Add it to the group in N-sight.
"refused one of the arguments" - an id was not valid for the call. Client, site, device and check ids come from the list tools: a site id from the site list, a device id from a device list, a check id from the check list. This is not a problem with the connection.
"answered with something that is not its XML reply" - a proxy, firewall or sign-in page in front of the N-sight server answered instead, so the request may never have reached N-sight. Your key is not at fault. Try again in a few minutes, and check the state before you repeat a change.
"Something in front of the N-able N-sight RMM server refused the request" - N-sight itself reports a wrong key as "Login failed", never as a refusal, so this is a firewall or an edge rule rather than the key. It is usually temporary.
A read is slow or times out - you asked for the whole account. Ask for one client, one site or one device instead.
N-able N-sight RMM tools
nsight_ · 58 tools · Free 40 · Pro 18
Clients, sites and devices
Checks and results
Antivirus update checks
Asset tracking
Settings
Patch management
Managed Antivirus
Backup and Recovery
Automated tasks
Was this helpful?
More in Connector guides
Connect Acronis Cyber Protect CloudConnect Action1Connect AddigyConnect AlertOpsStill need help? Ask the team