SentinelOne Tools
Written By Christopher Scaminaci
Last updated 7 days ago
SentinelOne Tools
s1_ · 696 tools · Free 367 · Pro 329Endpoint protection and EDR, plus the console's cloud and identity asset inventory, over the Management API v2.1. The credential is a console API token; the console host is per tenant and regional, so the instance address is required. Paging is a cursor capped at 1000 items - a larger tenant is truncated while the call still reports success, so narrow the filter rather than paging past it. Ten common query parameters are named arguments and everything else travels in one flat filters object that accepts scalars; where the vendor marks another one required, the tool description names it. Permissions are enforced per endpoint against the service user's role, so a refusal means one missing permission and every other tool keeps working. Endpoint actions select machines by filter rather than by id and answer 200 either way, so run the matching count first and re-read afterwards - a success body can carry an affected count of zero.
All connector tools · SentinelOne setup guide
SentinelOne tool groups
- Activity Log — 3 tools
- Agent Deployment and Updates — 26 tools
- Alerts — 7 tools
- Detection Rules — 18 tools
- Endpoint Actions — 39 tools
- Endpoints — 14 tools
- Network Discovery — 13 tools
- Network Quarantine — 15 tools
- Tasks — 7 tools
- Threat Intelligence — 6 tools
- Threats — 23 tools
- Accounts and Licensing — 13 tools
- Console Settings — 29 tools
- Graph Explorer — 16 tools
- Groups and Tags — 23 tools
- Log Collection — 8 tools
- Policies — 8 tools
- Reports — 9 tools
- Saved Views — 10 tools
- Sites — 15 tools
- Users and Roles — 31 tools
- Application Management — 11 tools
- Device Control — 12 tools
- Exclusions and Blocklist — 27 tools
- Firewall Control — 17 tools
- Integrations — 57 tools
- Marketplace — 9 tools
- PowerQuery — 6 tools
- Remote Forensics — 23 tools
- Remote Scripts — 16 tools
- Account — 8 tools
- AI ML — 8 tools
- Application Integration — 8 tools
- Asset Inventory — 9 tools
- Cloud Application — 8 tools
- Cloud Surface — 7 tools
- Container — 8 tools
- Data Analysis — 8 tools
- Data Store — 8 tools
- Developer Tool — 8 tools
- Device — 8 tools
- Endpoint Surface — 8 tools
- Filters — 4 tools
- Function — 8 tools
- Governance — 8 tools
- Identity — 8 tools
- Identity Surface — 7 tools
- Network — 8 tools
- Network Discovery Surface — 7 tools
- Notes — 2 tools
- Security Posture — 6 tools
- Server — 8 tools
- Storage — 8 tools
- Tags — 4 tools
- Unified Actions — 3 tools
- Workstation — 8 tools
Activity Log
s1_get_activities details
s1_get_activities details
[SentinelOne] Get Activities. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_activity_types details
s1_get_activity_types details
[SentinelOne] Get Activity Types. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_last_activity_syslog_message details
s1_get_last_activity_syslog_message details
[SentinelOne] Last activity as Syslog message. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
Agent Deployment and Updates
s1_add_cred_details details
s1_add_cred_details details
[SentinelOne] DESTRUCTIVE — Add cred details. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_create_cred_group details
s1_create_cred_group details
[SentinelOne] DESTRUCTIVE — Create Cred Group. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_create_policy details
s1_create_policy details
[SentinelOne] DESTRUCTIVE — Create Policy. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_create_policy_action details
s1_create_policy_action details
[SentinelOne] DESTRUCTIVE — Policy Action. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_deactivate_policies details
s1_deactivate_policies details
[SentinelOne] DESTRUCTIVE — Deactivate Policies. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. SentinelOne requires scopeLevel and osType on this endpoint — pass them in filtersJson or the call fails with a 400. scopeLevel: scope level, one of 'account', 'group', 'site' or 'tenant'. osType: OS type, one of 'linux', 'macos' or 'windows'. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_delete_cred_group details
s1_delete_cred_group details
[SentinelOne] DESTRUCTIVE — Delete Cred Group. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_delete_cred_group_detail details
s1_delete_cred_group_detail details
[SentinelOne] DESTRUCTIVE — Delete Cred Group Detail. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_delete_packages details
s1_delete_packages details
[SentinelOne] DESTRUCTIVE — Delete Packages. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_deploy_system_package details
s1_deploy_system_package details
[SentinelOne] DESTRUCTIVE — Deploy System Package. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_available_packages details
s1_get_available_packages details
[SentinelOne] Get Available Packages. SentinelOne requires scopeLevel and osType on this endpoint — pass them in filtersJson or the call fails with a 400. scopeLevel: scope level, one of 'account', 'group', 'site' or 'tenant'. osType: OS type, one of 'linux', 'macos' or 'windows'. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_cred_group_details details
s1_get_cred_group_details details
[SentinelOne] Get Cred group details. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_cred_groups details
s1_get_cred_groups details
[SentinelOne] Get Cred groups. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_latest_packages details
s1_get_latest_packages details
[SentinelOne] Get Latest Packages. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_parent_policies details
s1_get_parent_policies details
[SentinelOne] Get Parent Policies. SentinelOne requires scopeLevel, osType and skip on this endpoint — pass them in filtersJson or the call fails with a 400. scopeLevel: scope level, one of 'account', 'group', 'site' or 'tenant'. osType: OS type, one of 'linux', 'macos' or 'windows'. skip: the number of items to skip; SentinelOne stops at 1000, so page with cursor where the tool offers one. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_policies details
s1_get_policies details
[SentinelOne] Get Policies. SentinelOne requires scopeLevel, osType and skip on this endpoint — pass them in filtersJson or the call fails with a 400. scopeLevel: scope level, one of 'account', 'group', 'site' or 'tenant'. osType: OS type, one of 'linux', 'macos' or 'windows'. skip: the number of items to skip; SentinelOne stops at 1000, so page with cursor where the tool offers one. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_policies_os_count details
s1_get_policies_os_count details
[SentinelOne] All Policies OS Count. SentinelOne requires scopeLevel on this endpoint — pass it in filtersJson or the call fails with a 400. scopeLevel: scope level, one of 'account', 'group', 'site' or 'tenant'. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_policies_os_count_upgrade_policy details
s1_get_policies_os_count_upgrade_policy details
[SentinelOne] Policies OS Count. SentinelOne requires scopeLevel on this endpoint — pass it in filtersJson or the call fails with a 400. scopeLevel: scope level, one of 'account', 'group', 'site' or 'tenant'. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_has_policy details
s1_has_policy details
[SentinelOne] Has Policy. This is a POST that READS: the criteria travel in the request body, and nothing is created or changed. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_reorder_policies details
s1_reorder_policies details
[SentinelOne] DESTRUCTIVE — Reorder Policies. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_reset_policy_retry_counter details
s1_reset_policy_retry_counter details
[SentinelOne] DESTRUCTIVE — Reset Policy Retry Counter. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_set_scope_inheriting details
s1_set_scope_inheriting details
[SentinelOne] DESTRUCTIVE — Set Scope Inheriting. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_update_cred_group_details details
s1_update_cred_group_details details
[SentinelOne] DESTRUCTIVE — Update Cred Group Details. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_update_package details
s1_update_package details
[SentinelOne] DESTRUCTIVE — Update package. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_update_policy details
s1_update_policy details
[SentinelOne] DESTRUCTIVE — Update Policy. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_upload_agent_package details
s1_upload_agent_package details
[SentinelOne] DESTRUCTIVE — Upload Agent Package. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Scope to one customer with siteIds / accountIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_upload_system_package details
s1_upload_system_package details
[SentinelOne] DESTRUCTIVE — Upload System Package. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
Alerts
s1_create_internal_api_only_notify_action_was_triggered_without details
s1_create_internal_api_only_notify_action_was_triggered_without details
[SentinelOne] DESTRUCTIVE — Internal api only to notify action was triggered without actually performing it. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_create_perform_action_selected_assets_entities details
s1_create_perform_action_selected_assets_entities details
[SentinelOne] DESTRUCTIVE — Perform an Action on selected assets/entities. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_fetch_surface_ids_case_select_filters details
s1_fetch_surface_ids_case_select_filters details
[SentinelOne] Fetch surface ids in case of select all with filters. This is a POST that READS: the criteria travel in the request body, and nothing is created or changed. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_alerts details
s1_get_alerts details
[SentinelOne] Get alerts. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_available_actions_asset_entity_type details
s1_get_available_actions_asset_entity_type details
[SentinelOne] Get Available Actions by Asset/Entity Type. This is a POST that READS: the criteria travel in the request body, and nothing is created or changed. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_update_alert_analyst_verdict details
s1_update_alert_analyst_verdict details
[SentinelOne] DESTRUCTIVE — Update Alert Analyst Verdict. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_update_threat_incident details
s1_update_threat_incident details
[SentinelOne] DESTRUCTIVE — Update Threat Incident. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
Detection Rules
s1_activate_rules details
s1_activate_rules details
[SentinelOne] DESTRUCTIVE — Activate Rules. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_create_rule details
s1_create_rule details
[SentinelOne] DESTRUCTIVE — Create Rule. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_delete_rules details
s1_delete_rules details
[SentinelOne] DESTRUCTIVE — Delete Rules. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_disable_managed_detection_rule details
s1_disable_managed_detection_rule details
[SentinelOne] DESTRUCTIVE — Disable a Managed Detection Rule. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_disable_rules details
s1_disable_rules details
[SentinelOne] DESTRUCTIVE — Disable Rules. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_enable_managed_detection_rule details
s1_enable_managed_detection_rule details
[SentinelOne] DESTRUCTIVE — Enable a Managed Detection Rule. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_data_sources details
s1_get_data_sources details
[SentinelOne] Get Data Sources. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_free_text_filters details
s1_get_free_text_filters details
[SentinelOne] Free-Text Filters. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_managed_detection_rules details
s1_get_managed_detection_rules details
[SentinelOne] Get Managed Detection Rules. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_managed_detection_rules_detection_library details
s1_get_managed_detection_rules_detection_library details
[SentinelOne] Get Managed Detection Rules. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_rules details
s1_get_rules details
[SentinelOne] Get Rules. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_settings_managed_detection_rules details
s1_get_settings_managed_detection_rules details
[SentinelOne] Get settings for Managed Detection Rules. SentinelOne requires scopeLevel on this endpoint — pass it in filtersJson or the call fails with a 400. scopeLevel: scope level, one of 'global', 'group', 'account' or 'site'. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_severities details
s1_get_severities details
[SentinelOne] Get Severities. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_statuses details
s1_get_statuses details
[SentinelOne] Get Statuses. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_surfaces details
s1_get_surfaces details
[SentinelOne] Get Surfaces. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_template_detection_rules details
s1_get_template_detection_rules details
[SentinelOne] Get Template Detection Rules. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_update_rule details
s1_update_rule details
[SentinelOne] DESTRUCTIVE — Update Rule. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_update_settings_managed_detection_rules details
s1_update_settings_managed_detection_rules details
[SentinelOne] DESTRUCTIVE — Update settings for Managed Detection Rules. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
Endpoint Actions
s1_abort_scan details
s1_abort_scan details
[SentinelOne] DESTRUCTIVE — Abort Scan. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_approve_stateless_upgrades details
s1_approve_stateless_upgrades details
[SentinelOne] DESTRUCTIVE — Approve Stateless Upgrades. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_approve_uninstall details
s1_approve_uninstall details
[SentinelOne] DESTRUCTIVE — Approve Uninstall. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_broadcast_message details
s1_broadcast_message details
[SentinelOne] DESTRUCTIVE — Broadcast Message. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_can_run_remote_shell details
s1_can_run_remote_shell details
[SentinelOne] DESTRUCTIVE — Can run Remote Shell. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_clear_remote_shell details
s1_clear_remote_shell details
[SentinelOne] DESTRUCTIVE — Clear Remote Shell. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_connect_network details
s1_connect_network details
[SentinelOne] DESTRUCTIVE — Connect to Network. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_create_manage_endpoint_tags_add_remove_override details
s1_create_manage_endpoint_tags_add_remove_override details
[SentinelOne] DESTRUCTIVE — Manage endpoint tags: add, remove, override. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_create_randomize_uuid details
s1_create_randomize_uuid details
[SentinelOne] DESTRUCTIVE — Randomize UUID. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_create_terminate_remote_shell details
s1_create_terminate_remote_shell details
[SentinelOne] DESTRUCTIVE — Terminate Remote Shell. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_decommission details
s1_decommission details
[SentinelOne] DESTRUCTIVE — Decommission. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_disable_agent details
s1_disable_agent details
[SentinelOne] DESTRUCTIVE — Disable Agent. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_disable_network_discovery details
s1_disable_network_discovery details
[SentinelOne] DESTRUCTIVE — Disable Network Discovery. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_disconnect_network details
s1_disconnect_network details
[SentinelOne] DESTRUCTIVE — Disconnect from Network. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_edit_local_upgrade_downgrade_site_authorization details
s1_edit_local_upgrade_downgrade_site_authorization details
[SentinelOne] DESTRUCTIVE — Edit local upgrade/downgrade Site authorization. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_enable_agent details
s1_enable_agent details
[SentinelOne] DESTRUCTIVE — Enable Agent. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_enable_network_discovery details
s1_enable_network_discovery details
[SentinelOne] DESTRUCTIVE — Enable Network Discovery. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_fetch_files details
s1_fetch_files details
[SentinelOne] DESTRUCTIVE — Fetch Files. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_fetch_firewall_logs details
s1_fetch_firewall_logs details
[SentinelOne] DESTRUCTIVE — Fetch Firewall Logs. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_fetch_firewall_rules details
s1_fetch_firewall_rules details
[SentinelOne] DESTRUCTIVE — Fetch Firewall Rules. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_fetch_logs details
s1_fetch_logs details
[SentinelOne] DESTRUCTIVE — Fetch Logs. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_applications details
s1_get_applications details
[SentinelOne] DESTRUCTIVE — Get Applications. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_initiate_scan details
s1_initiate_scan details
[SentinelOne] DESTRUCTIVE — Initiate Scan. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_mark_up_date details
s1_mark_up_date details
[SentinelOne] DESTRUCTIVE — Mark as up-to-date. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_move_between_sites details
s1_move_between_sites details
[SentinelOne] DESTRUCTIVE — Move between Sites. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_move_console details
s1_move_console details
[SentinelOne] DESTRUCTIVE — Move to Console. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_reject_uninstall details
s1_reject_uninstall details
[SentinelOne] DESTRUCTIVE — Reject uninstall. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_reset_local_config details
s1_reset_local_config details
[SentinelOne] DESTRUCTIVE — Reset Local Config. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_reset_passphrase_capability details
s1_reset_passphrase_capability details
[SentinelOne] DESTRUCTIVE — Reset Passphrase Capability. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_reset_passphrases details
s1_reset_passphrases details
[SentinelOne] DESTRUCTIVE — Reset Passphrases. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_restart details
s1_restart details
[SentinelOne] DESTRUCTIVE — Restart. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_set_external_id details
s1_set_external_id details
[SentinelOne] DESTRUCTIVE — Set External ID. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_set_persistent_configuration_overrides details
s1_set_persistent_configuration_overrides details
[SentinelOne] DESTRUCTIVE — Set Persistent Configuration Overrides. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_shutdown details
s1_shutdown details
[SentinelOne] DESTRUCTIVE — Shutdown. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_start_remote_profiling details
s1_start_remote_profiling details
[SentinelOne] DESTRUCTIVE — Start Remote Profiling. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_start_remote_shell details
s1_start_remote_shell details
[SentinelOne] DESTRUCTIVE — Start Remote Shell. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_stop_remote_profiling details
s1_stop_remote_profiling details
[SentinelOne] DESTRUCTIVE — Stop Remote Profiling. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_uninstall details
s1_uninstall details
[SentinelOne] DESTRUCTIVE — Uninstall. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_update_software details
s1_update_software details
[SentinelOne] DESTRUCTIVE — Update Software. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
Endpoints
s1_count_agents details
s1_count_agents details
[SentinelOne] Count Agents. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_create_access_token details
s1_create_access_token details
[SentinelOne] DESTRUCTIVE — Create Access Token. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_delete_access_token details
s1_delete_access_token details
[SentinelOne] DESTRUCTIVE — Delete Access Token. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_disable_pna_hyperautomation details
s1_disable_pna_hyperautomation details
[SentinelOne] DESTRUCTIVE — Disable PNA for Hyperautomation. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_enable_agent_pna_hyperautomation details
s1_enable_agent_pna_hyperautomation details
[SentinelOne] DESTRUCTIVE — Enable Agent PNA for Hyperautomation. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_export_agent_logs details
s1_export_agent_logs details
[SentinelOne] Export Agent Logs. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_agents details
s1_get_agents details
[SentinelOne] Get Agents. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_applications_agents details
s1_get_applications_agents details
[SentinelOne] Applications. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_endpoint_tags_count_filters details
s1_get_endpoint_tags_count_filters details
[SentinelOne] Endpoint tags count by Filters. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_endpoint_tags_match_filters details
s1_get_endpoint_tags_match_filters details
[SentinelOne] Get the endpoint tags that match the filters. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_local_upgrade_downgrade_agent_authorization details
s1_get_local_upgrade_downgrade_agent_authorization details
[SentinelOne] Get local upgrade/downgrade Agent authorization. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_passphrase details
s1_get_passphrase details
[SentinelOne] Get Passphrase. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_processes details
s1_get_processes details
[SentinelOne] Processes. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_list_access_tokens details
s1_list_access_tokens details
[SentinelOne] List Access Tokens. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
Network Discovery
s1_change_device_review details
s1_change_device_review details
[SentinelOne] DESTRUCTIVE — Change Device Review. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_change_device_review_bulk details
s1_change_device_review_bulk details
[SentinelOne] DESTRUCTIVE — Change Device Review in Bulk. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_change_device_tags details
s1_change_device_tags details
[SentinelOne] DESTRUCTIVE — Change Device Tags. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_export_json_raw_data details
s1_export_json_raw_data details
[SentinelOne] Export JSON Raw Data. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_export_network_discovery_data details
s1_export_network_discovery_data details
[SentinelOne] Export Network Discovery Data. Scope to one customer with siteIds / accountIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_export_unprotected_endpoints_discovery_data details
s1_export_unprotected_endpoints_discovery_data details
[SentinelOne] Export Unprotected Endpoints Discovery Data. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_json_raw_data details
s1_get_json_raw_data details
[SentinelOne] JSON Raw Data. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_network_discovery_settings details
s1_get_network_discovery_settings details
[SentinelOne] Get Network Discovery Settings. Scope to one customer with siteIds / accountIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_network_discovery_table details
s1_get_network_discovery_table details
[SentinelOne] Get Network Discovery Table. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_unprotected_endpoints_discovery_settings details
s1_get_unprotected_endpoints_discovery_settings details
[SentinelOne] Get Unprotected Endpoints Discovery Settings. Scope to one customer with siteIds / accountIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_unprotected_endpoints_discovery_table details
s1_get_unprotected_endpoints_discovery_table details
[SentinelOne] Get Unprotected Endpoints Discovery Table. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_update_network_discovery_settings details
s1_update_network_discovery_settings details
[SentinelOne] DESTRUCTIVE — Update Network Discovery Settings. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_update_unprotected_endpoints_discovery_settings details
s1_update_unprotected_endpoints_discovery_settings details
[SentinelOne] DESTRUCTIVE — Update Unprotected Endpoints Discovery Settings. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
Network Quarantine
s1_add_rule_tags details
s1_add_rule_tags details
[SentinelOne] Add Rule Tags. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_copy_rules_network_quarantine_control details
s1_copy_rules_network_quarantine_control details
[SentinelOne] DESTRUCTIVE — Copy Rules. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_create_firewall_rule_firewall_control details
s1_create_firewall_rule_firewall_control details
[SentinelOne] DESTRUCTIVE — Create Firewall Rule. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_delete_rules_network_quarantine_control details
s1_delete_rules_network_quarantine_control details
[SentinelOne] DESTRUCTIVE — Delete Rules. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_enable_disable_rules_network_quarantine_control details
s1_enable_disable_rules_network_quarantine_control details
[SentinelOne] DESTRUCTIVE — Enable/Disable Rules. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_export_rules_network_quarantine_control details
s1_export_rules_network_quarantine_control details
[SentinelOne] Export Rules. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_configuration_network_quarantine_control details
s1_get_configuration_network_quarantine_control details
[SentinelOne] Get Configuration. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_firewall_rules_firewall_control details
s1_get_firewall_rules_firewall_control details
[SentinelOne] Get Firewall Rules. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_protocols details
s1_get_protocols details
[SentinelOne] Get Protocols. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_import_rules details
s1_import_rules details
[SentinelOne] DESTRUCTIVE — Import Rules. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_move_rules_network_quarantine_control details
s1_move_rules_network_quarantine_control details
[SentinelOne] DESTRUCTIVE — Move Rules. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_remove_rule_tags details
s1_remove_rule_tags details
[SentinelOne] DESTRUCTIVE — Remove Rule Tags. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_reorder_rules_network_quarantine_control details
s1_reorder_rules_network_quarantine_control details
[SentinelOne] DESTRUCTIVE — Reorder Rules. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_set_location details
s1_set_location details
[SentinelOne] DESTRUCTIVE — Set Location. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_update_configuration_network_quarantine_control details
s1_update_configuration_network_quarantine_control details
[SentinelOne] DESTRUCTIVE — Update Configuration. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
Tasks
s1_create_task details
s1_create_task details
[SentinelOne] DESTRUCTIVE — Create Task. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_export_maintenance_windows_csv details
s1_export_maintenance_windows_csv details
[SentinelOne] Export Maintenance Windows as CSV. Scope to one customer with siteIds / accountIds / groupIds. SentinelOne requires taskType on this endpoint — pass it in filtersJson or the call fails with a 400. taskType: task type, one of 'agents_upgrade', 'agent_version_change', 'auto_deploy', 'script_execution', 'cis_scan', 'gad' or 'forensics_collection'. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_child_scope_task_configuration details
s1_get_child_scope_task_configuration details
[SentinelOne] Get Child Scope Task Configuration. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. SentinelOne requires taskType on this endpoint — pass it in filtersJson or the call fails with a 400. taskType: task type, one of 'agents_upgrade', 'agent_version_change', 'auto_deploy', 'script_execution', 'cis_scan', 'gad' or 'forensics_collection'. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_task_configuration details
s1_get_task_configuration details
[SentinelOne] Get Task Configuration. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. SentinelOne requires taskType on this endpoint — pass it in filtersJson or the call fails with a 400. taskType: task type, one of 'agents_upgrade', 'agent_version_change', 'auto_deploy', 'script_execution', 'cis_scan', 'gad' or 'forensics_collection'. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_task_configuration_flexible_mw details
s1_get_task_configuration_flexible_mw details
[SentinelOne] Get Task Configuration (Flexible MW). Scope to one customer with siteIds / accountIds / groupIds. SentinelOne requires taskType on this endpoint — pass it in filtersJson or the call fails with a 400. taskType: task type, one of 'agents_upgrade', 'agent_version_change', 'auto_deploy', 'script_execution', 'cis_scan', 'gad' or 'forensics_collection'. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_has_child_scopes details
s1_has_child_scopes details
[SentinelOne] Has Child Scopes. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. SentinelOne requires taskType on this endpoint — pass it in filtersJson or the call fails with a 400. taskType: task type, one of 'agents_upgrade', 'agent_version_change', 'auto_deploy', 'script_execution', 'cis_scan', 'gad' or 'forensics_collection'. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_update_task_configuration_flexible_mw details
s1_update_task_configuration_flexible_mw details
[SentinelOne] DESTRUCTIVE — Update Task Configuration (Flexible MW). A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
Threat Intelligence
s1_create_iocs details
s1_create_iocs details
[SentinelOne] DESTRUCTIVE — Create IOCs. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_create_iocs_stix_bundle details
s1_create_iocs_stix_bundle details
[SentinelOne] DESTRUCTIVE — Create IOCs from STIX bundle. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_create_threat_intelligence_user_config details
s1_create_threat_intelligence_user_config details
[SentinelOne] Create Threat Intelligence user config. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_delete_iocs details
s1_delete_iocs details
[SentinelOne] DESTRUCTIVE — Delete IOCs. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_delete_threat_intelligence_user_config details
s1_delete_threat_intelligence_user_config details
[SentinelOne] DESTRUCTIVE — Delete Threat Intelligence user config. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_threat_intelligence_user_config details
s1_get_threat_intelligence_user_config details
[SentinelOne] Get Threat Intelligence user config. Scope to one customer with siteIds / accountIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
Threats
s1_add_blocklist details
s1_add_blocklist details
[SentinelOne] DESTRUCTIVE — Add to Blocklist. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_add_blocklist_deep_visibility details
s1_add_blocklist_deep_visibility details
[SentinelOne] DESTRUCTIVE — Add to Blocklist (Deep Visibility). A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_add_exclusions details
s1_add_exclusions details
[SentinelOne] DESTRUCTIVE — Add to Exclusions. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_add_note_multiple details
s1_add_note_multiple details
[SentinelOne] Add Note to Multiple. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_create_updated_threat_incident details
s1_create_updated_threat_incident details
[SentinelOne] DESTRUCTIVE — Updated Threat Incident. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_delete_threat_note details
s1_delete_threat_note details
[SentinelOne] DESTRUCTIVE — Delete Threat Note. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_disable_engines details
s1_disable_engines details
[SentinelOne] DESTRUCTIVE — Disable Engines. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_disconnect_container details
s1_disconnect_container details
[SentinelOne] DESTRUCTIVE — Disconnect Container. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_export_mitigation_report details
s1_export_mitigation_report details
[SentinelOne] Export Mitigation Report. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_export_threats details
s1_export_threats details
[SentinelOne] Export Threats. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_fetch_threat_file details
s1_fetch_threat_file details
[SentinelOne] DESTRUCTIVE — Fetch Threat File. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_events details
s1_get_events details
[SentinelOne] Get Events. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_exclusion_options details
s1_get_exclusion_options details
[SentinelOne] Exclusion Options. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_threat_notes details
s1_get_threat_notes details
[SentinelOne] Get Threat Notes. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_threat_timeline details
s1_get_threat_timeline details
[SentinelOne] Get Threat Timeline. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_threats details
s1_get_threats details
[SentinelOne] Get Threats. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_mark_threat_deep_visibility details
s1_mark_threat_deep_visibility details
[SentinelOne] DESTRUCTIVE — Mark as Threat (Deep Visibility). A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_mitigate_alerts details
s1_mitigate_alerts details
[SentinelOne] DESTRUCTIVE — Mitigate Alerts. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_mitigate_threats details
s1_mitigate_threats details
[SentinelOne] DESTRUCTIVE — Mitigate Threats. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_reconnect_container details
s1_reconnect_container details
[SentinelOne] DESTRUCTIVE — Reconnect Container. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_update_threat_analyst_verdict details
s1_update_threat_analyst_verdict details
[SentinelOne] DESTRUCTIVE — Update Threat Analyst Verdict. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_update_threat_external_ticket_id details
s1_update_threat_external_ticket_id details
[SentinelOne] DESTRUCTIVE — Update Threat External Ticket ID. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_update_threat_note details
s1_update_threat_note details
[SentinelOne] Update Threat Note. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
Accounts and Licensing
s1_create_account details
s1_create_account details
[SentinelOne] DESTRUCTIVE — Create an account, the MSP-level container above sites. A new account consumes license entitlement and establishes a new policy root, so this is a commercial action as much as a configuration one. A 200 response does not prove the change landed — re-read with s1_get_accounts to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_expire_account details
s1_expire_account details
[SentinelOne] DESTRUCTIVE — Expire an account immediately. An account is the container above sites, so this reaches EVERY site and every agent beneath it at once — the widest blast radius in this family. List what is underneath with s1_get_sites scoped to the account before you run it. s1_reactivate_account is the way back. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_generate_regenerate_uninstall_password details
s1_generate_regenerate_uninstall_password details
[SentinelOne] DESTRUCTIVE — Generate a new agent uninstall password for an account, replacing the current one. The old password stops working immediately, so any runbook, script or technician still holding it can no longer remove an agent. Read the current one with s1_get_uninstall_password first if you need it. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_account details
s1_get_account details
[SentinelOne] Get one account by its id, including its state, expiration date, license usage and the modules it has enabled. Get the id from s1_get_accounts. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_accounts details
s1_get_accounts details
[SentinelOne] List the accounts in the console that match the filter, with their state, expiration and license counts. In a SentinelOne console an ACCOUNT is the MSP-level container and a SITE is the customer beneath it, so start here to learn the account ids the rest of the connector takes. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Set countOnly=true to size a filter before acting on it. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_cloud_inventory_overview details
s1_get_cloud_inventory_overview details
[SentinelOne] Cloud Inventory resource overview. This is a POST that READS: the criteria travel in the request body, and nothing is created or changed. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_uninstall_password details
s1_get_uninstall_password details
[SentinelOne] Reveal the current agent uninstall password for an account, in plain text. This is the secret that lets a technician remove the SentinelOne agent from a machine, so treat the response as a credential: do not echo it into a ticket, a chat transcript or a log. It reads the password, it does not change it. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_uninstall_password_metadata details
s1_get_uninstall_password_metadata details
[SentinelOne] Get Uninstall Password Metadata. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_reactivate_account details
s1_reactivate_account details
[SentinelOne] DESTRUCTIVE — Reactivate an expired account. Every site beneath it can start consuming license again, so this is a billing-relevant action across the whole account. A 200 response does not prove the change landed — re-read with s1_get_account to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_revert_account_policy details
s1_revert_account_policy details
[SentinelOne] DESTRUCTIVE — Discard the account's own policy and revert it to inherit from the level above. Every explicit setting on the account is lost in one call, and every site, group and agent inheriting from it starts enforcing the parent's settings instead. Read s1_get_account_policy first and keep a copy — there is no undo. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_revoke_uninstall_password details
s1_revoke_uninstall_password details
[SentinelOne] DESTRUCTIVE — Revoke the account's agent uninstall password. Nobody can uninstall an agent with the old password afterwards, which will block a legitimate decommission until a new password is generated. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_update_account details
s1_update_account details
[SentinelOne] DESTRUCTIVE — Change an account's fields, which include its license allocation and expiration. Read the current values with s1_get_account and send them back with your change — the vendor treats this as a replace, so an omitted field is a changed field, and a dropped license number reaches every site beneath the account. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_update_sites_add_ons details
s1_update_sites_add_ons details
[SentinelOne] DESTRUCTIVE — Change which licensed modules are enabled on sites. This SPENDS LICENSE: enabling a module consumes entitlement and can change what the customer is billed for, and disabling one turns off the protection that module provides on every agent in those sites. Read the current module state with s1_get_sites first. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
Console Settings
s1_clear_pending_emails details
s1_clear_pending_emails details
[SentinelOne] DESTRUCTIVE — Cancel every console email that is queued but not yet sent. Anything waiting in the queue is discarded, including user invitations and verification mail people are currently waiting on, and there is no way to replay it — the messages have to be triggered again. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_create_location details
s1_create_location details
[SentinelOne] DESTRUCTIVE — Create a console LOCATION. A location is not a label: agents apply the Firewall Control rules whose Location Aware parameters match their location, so adding one changes which rule set live endpoints enforce. A 200 response does not prove the change landed — re-read with s1_get_locations to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_delete_locations details
s1_delete_locations details
[SentinelOne] DESTRUCTIVE — Delete network location definitions. Agents that matched a deleted location fall back to the fallback location's Firewall Control rules, so this changes what live endpoints enforce without touching any agent or any firewall rule. Read s1_get_locations first, and check `hasFirewallRules` to see which rules are tied to the location. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_delete_notification_recipient details
s1_delete_notification_recipient details
[SentinelOne] DESTRUCTIVE — Remove one notification recipient. That address stops receiving console alert mail immediately, which is invisible until an alert is missed. Confirm the recipient with s1_get_notification_recipients first. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_ad_fqdns details
s1_get_ad_fqdns details
[SentinelOne] Get AD FQDNs. Scope to one customer with siteIds / accountIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_ad_settings details
s1_get_ad_settings details
[SentinelOne] Get AD Settings. Scope to one customer with siteIds / accountIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_locations details
s1_get_locations details
[SentinelOne] List the network locations defined for a scope, with the parameters that match an agent to each one. Locations select which Firewall Control rules an agent enforces, so read this before changing firewall behavior. Filter on `hasFirewallRules` through filtersJson to find a location that no rule matches, which is the usual cause of an endpoint falling back to the fallback rule set. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Set countOnly=true to size a filter before acting on it. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_notification_recipients details
s1_get_notification_recipients details
[SentinelOne] Get Notification Recipients. Scope to one customer with siteIds / accountIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_smtp_settings details
s1_get_smtp_settings details
[SentinelOne] Get SMTP Settings. Scope to one customer with siteIds / accountIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_sso_service_provider_certificate details
s1_get_sso_service_provider_certificate details
[SentinelOne] Get SSO Service Provider Certificate. Scope to one customer with siteIds / accountIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_sso_settings details
s1_get_sso_settings details
[SentinelOne] Get SSO Settings. Scope to one customer with siteIds / accountIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_syslog_settings details
s1_get_syslog_settings details
[SentinelOne] Get Syslog Settings. Scope to one customer with siteIds / accountIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_system_config details
s1_get_system_config details
[SentinelOne] Get System Config. Scope to one customer with siteIds / accountIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_system_environment details
s1_get_system_environment details
[SentinelOne] System Environment. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_system_info details
s1_get_system_info details
[SentinelOne] System Info. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_system_status details
s1_get_system_status details
[SentinelOne] System Status. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_set_ad_fqdns details
s1_set_ad_fqdns details
[SentinelOne] DESTRUCTIVE — Replace the Active Directory scope mapping, which decides how directory groups map onto console scopes. Changing it moves administrators between scopes, widening or removing their reach without touching any user record. Read the current mapping with s1_get_ad_fqdns and send the complete set — this is a replace, so an omitted entry is a removed entry. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_set_ad_settings details
s1_set_ad_settings details
[SentinelOne] DESTRUCTIVE — Replace the console's Active Directory configuration. This governs how directory identities map into the console, so a wrong value can cut off directory-backed sign-in for every administrator. Read the current configuration with s1_get_ad_settings, keep a copy, and validate with s1_test_ad_settings before you write. This is a replace, so an omitted field is a changed field. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_set_notification_recipients details
s1_set_notification_recipients details
[SentinelOne] DESTRUCTIVE — Replace the list of people who receive console notifications. This REACHES PEOPLE both ways: addresses you add start receiving alert mail, and addresses you omit stop receiving it, so an incomplete body silently unsubscribes the on-call rota. Read the current list with s1_get_notification_recipients and send it back with your change. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_set_notification_settings details
s1_set_notification_settings details
[SentinelOne] DESTRUCTIVE — Replace the console's notification settings, which decide which events generate mail and to whom. Turning a category off stops alerts nobody will notice are missing until an incident is missed. Read the current settings first and send them back with your change — this is a replace, so an omitted field is a changed field. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_set_smtp_settings details
s1_set_smtp_settings details
[SentinelOne] DESTRUCTIVE — Replace the console's SMTP configuration. Every console notification and every user invitation is delivered through this, so a bad value silently stops all of them — including the verification emails users need to regain access. Read the current configuration with s1_get_smtp_settings, keep a copy, and validate with s1_test_smtp_settings before you write. This is a replace, so an omitted field is a changed field. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_set_sso_settings details
s1_set_sso_settings details
[SentinelOne] DESTRUCTIVE — Replace the console's SSO configuration. Getting this wrong locks every federated administrator out of the SentinelOne console, and fixing it then needs a local account that may not exist. Read the current configuration with s1_get_sso_settings, keep a copy, and validate with s1_test_sso_settings before you write. This is a replace, so an omitted field is a changed field. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_set_syslog_settings details
s1_set_syslog_settings details
[SentinelOne] DESTRUCTIVE — Replace the console's syslog forwarding configuration. If the customer's SIEM ingests SentinelOne through this, a wrong value stops the feed silently and the gap is only visible downstream. Read the current configuration with s1_get_syslog_settings, keep a copy, and validate with s1_test_syslog_settings before you write. This is a replace, so an omitted field is a changed field. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_set_system_config details
s1_set_system_config details
[SentinelOne] DESTRUCTIVE — Replace the console's system configuration. These are tenant-wide settings, so the blast radius is the whole console and a wrong value is visible to every administrator. Read the current configuration with s1_get_system_config and keep a copy — this is a replace, so an omitted field is a changed field. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_test_ad_settings details
s1_test_ad_settings details
[SentinelOne] DESTRUCTIVE — Test AD Settings. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_test_smtp_settings details
s1_test_smtp_settings details
[SentinelOne] DESTRUCTIVE — Test SMTP Settings. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_test_sso_settings details
s1_test_sso_settings details
[SentinelOne] DESTRUCTIVE — Test SSO Settings. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_test_syslog_settings details
s1_test_syslog_settings details
[SentinelOne] DESTRUCTIVE — Test Syslog Settings. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_update_location details
s1_update_location details
[SentinelOne] DESTRUCTIVE — Edit a console LOCATION. Locations select which Firewall Control rules an agent enforces, so an edit silently re-points live endpoints at a different rule set. This is a replace, so an omitted field is a cleared field: read the current location with s1_get_locations and send the complete object. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
Graph Explorer
s1_delete_graph_query details
s1_delete_graph_query details
[SentinelOne] DESTRUCTIVE — Delete graph query. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_asset_query_builder_metadata details
s1_get_asset_query_builder_metadata details
[SentinelOne] Get Graph Query Builder Initial Metadata. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_available_relations details
s1_get_available_relations details
[SentinelOne] Get the available relations. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_graph_explorer_autocomplete details
s1_get_graph_explorer_autocomplete details
[SentinelOne] Auto Complete. Scope to one customer with siteIds / accountIds / groupIds. SentinelOne requires key on this endpoint — pass it in filtersJson or the call fails with a 400. key: the search field key, one of the documented `<field>__contains` names. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_graph_query_builder_metadata details
s1_get_graph_query_builder_metadata details
[SentinelOne] Get Graph Query Builder Initial Metadata. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_graph_query_builder_options details
s1_get_graph_query_builder_options details
[SentinelOne] Get Query Builder metadata For Requested Resource Types. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_graph_query_list details
s1_get_graph_query_list details
[SentinelOne] List the saved Graph Explorer queries, with the owner and the query definition of each. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Set countOnly=true to size a filter before acting on it. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_graph_query_type_counts details
s1_get_graph_query_type_counts details
[SentinelOne] Get graph query counts by type. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_graph_recent_query_list details
s1_get_graph_recent_query_list details
[SentinelOne] Get graph recent query list. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_graph_services_feature_toggles details
s1_get_graph_services_feature_toggles details
[SentinelOne] Get all of the feature toggles for graph services. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_tag_autocomplete details
s1_get_tag_autocomplete details
[SentinelOne] Tag Auto Complete. This is a POST that READS: the criteria travel in the request body, and nothing is created or changed. Scope to one customer with siteIds / accountIds / groupIds. SentinelOne requires field on this endpoint — pass it in filtersJson or the call fails with a 400. field: search in keys or values, one of 'key' or 'value'. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_query_graph_explorer details
s1_query_graph_explorer details
[SentinelOne] Query the graph based on query builder filters. This is a POST that READS: the criteria travel in the request body, and nothing is created or changed. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_query_graph_explorer_v2 details
s1_query_graph_explorer_v2 details
[SentinelOne] Query the graph based on query builder filters. This is a POST that READS: the criteria travel in the request body, and nothing is created or changed. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_query_subgraph details
s1_query_subgraph details
[SentinelOne] Query the sub graph of an asset type and id. This is a POST that READS: the criteria travel in the request body, and nothing is created or changed. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_save_graph_query details
s1_save_graph_query details
[SentinelOne] Save graph query. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_update_graph_query details
s1_update_graph_query details
[SentinelOne] Update graph query. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
Groups and Tags
s1_create_endpoint_tag details
s1_create_endpoint_tag details
[SentinelOne] Create a new endpoint tag. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_create_group details
s1_create_group details
[SentinelOne] Create Group. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_create_tag_rule details
s1_create_tag_rule details
[SentinelOne] Create new tag rule. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_create_tags details
s1_create_tags details
[SentinelOne] Create Tags. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_delete_endpoint_tags details
s1_delete_endpoint_tags details
[SentinelOne] DESTRUCTIVE — Delete endpoint tags from Tag Manager. Any console view, dynamic group or automation that selects on a deleted tag stops matching, so agents can silently move between dynamic groups and therefore between policies. This is the Tag Manager set, not the asset tags that s1_delete_tags removes. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_delete_group details
s1_delete_group details
[SentinelOne] DESTRUCTIVE — Delete an agent group. The agents in it are not deleted, but they move out of the group and therefore stop receiving the group's policy and inherit the site policy instead, which is a live change to what those endpoints enforce. Check the agent count with s1_get_group first. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_delete_tag details
s1_delete_tag details
[SentinelOne] DESTRUCTIVE — Delete one asset tag by its id. Anything selecting on it stops matching. Confirm the tag with s1_get_tags first — asset tag ids and Tag Manager endpoint tag ids are different sets and are not interchangeable. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_delete_tag_rules details
s1_delete_tag_rules details
[SentinelOne] DESTRUCTIVE — Delete asset tag rules. The tags those rules applied automatically stop being maintained, so assets drift out of the tag over time and anything selecting on it quietly narrows. Read s1_get_tag_rules first, and s1_test_tag_rule_match_count to see how many assets a rule currently covers. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_delete_tags details
s1_delete_tags details
[SentinelOne] DESTRUCTIVE — Delete asset tags in bulk, by the criteria in the body rather than by a single id. Anything selecting on a deleted tag stops matching. This is the asset tag set; the Tag Manager endpoint tags are removed by s1_delete_endpoint_tags. A 200 response does not prove the change landed — the `affected` count can be 0. Re-read with s1_get_tags to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_group details
s1_get_group details
[SentinelOne] Get one agent group by its id, including its rank, type, filter definition and the site it belongs to. Get the id from s1_get_groups. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_group_registration_token details
s1_get_group_registration_token details
[SentinelOne] Get Site registration token by ID. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_groups details
s1_get_groups details
[SentinelOne] List the agent groups that match the filter, with the site each belongs to, its rank, its type (static or dynamic) and its agent count. Groups are how policy is applied below the site, so read this before moving agents or editing group policy. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Set countOnly=true to size a filter before acting on it. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_tag_rules details
s1_get_tag_rules details
[SentinelOne] Get all tags rules. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_tags details
s1_get_tags details
[SentinelOne] List the asset tags that match the filter, with the scope of each. These are the tags applied to inventory assets; the endpoint tag set that Tag Manager owns is a separate list. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Set countOnly=true to size a filter before acting on it. SentinelOne requires type on this endpoint — pass it in filtersJson or the call fails with a 400. type: the tag type, for example firewall. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_move_agents details
s1_move_agents details
[SentinelOne] DESTRUCTIVE — Move agents into a group by FILTER, not by a list of ids. The agents that move immediately start enforcing the destination group's policy instead of their old one, so a wrong or empty filter re-points protection for a whole fleet and SentinelOne answers 200 either way. Run the matching agent read with countOnly=true and the SAME filter first, and read the destination policy with s1_get_group_policy. A 200 response does not prove the change landed — the `affected` count can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_regenerate_group_token details
s1_regenerate_group_token details
[SentinelOne] DESTRUCTIVE — Regenerate a group's registration token. Every installer and deployment script carrying the old token stops being able to enroll agents into that group — already-installed agents keep working, but your deployment tooling breaks until it is updated with the new value from s1_get_group_registration_token. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_revert_group_policy details
s1_revert_group_policy details
[SentinelOne] DESTRUCTIVE — Discard the group's own policy and revert it to inherit from the site. Every explicit setting on the group is lost in one call, and its agents start enforcing the site's settings instead. Read s1_get_group_policy first and keep a copy — there is no undo. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_test_tag_rule_match_count details
s1_test_tag_rule_match_count details
[SentinelOne] Check how many assets this tag rule matches. This is a POST that READS: the criteria travel in the request body, and nothing is created or changed. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_update_endpoint_tag details
s1_update_endpoint_tag details
[SentinelOne] Edit an existing tag. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_update_group details
s1_update_group details
[SentinelOne] DESTRUCTIVE — Update Group. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_update_group_ranks details
s1_update_group_ranks details
[SentinelOne] DESTRUCTIVE — Reorder group ranks. Rank decides which dynamic group claims an agent when several match, so reordering silently moves endpoints between groups and therefore between policies, without touching any agent directly. Read the current order with s1_get_groups first and send the complete ordering. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_update_tag details
s1_update_tag details
[SentinelOne] Edit Tag. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_update_tag_rule details
s1_update_tag_rule details
[SentinelOne] Update tag rule. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
Log Collection
s1_change_activation_status_log_collection_rules details
s1_change_activation_status_log_collection_rules details
[SentinelOne] DESTRUCTIVE — Activate or deactivate log collection rules. This is the switch that makes a rule live: activating one starts agents collecting and shipping logs, and deactivating one stops the feed a SIEM may depend on. Read the current state with s1_get_log_collection_rules first. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_create_log_collection_rule details
s1_create_log_collection_rule details
[SentinelOne] Create a log collection rule. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_delete_log_collection_rules details
s1_delete_log_collection_rules details
[SentinelOne] DESTRUCTIVE — Delete log collection rules. The agents in scope stop shipping the logs those rules collected, so a downstream SIEM or investigation loses its source silently — the gap only shows up later, when the data is needed. Read s1_get_log_collection_rules first. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_export_log_collection_rules details
s1_export_log_collection_rules details
[SentinelOne] Export the log collection rules matching the filter. NOTE: SentinelOne serves this endpoint as a CSV file. StackJack tools return JSON, so this call reports a content-type error rather than a file — use s1_get_log_collection_rules, which returns the same rules as JSON and pages properly. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_log_collection_agent_type_counts details
s1_get_log_collection_agent_type_counts details
[SentinelOne] Get Agent type count. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_log_collection_rules details
s1_get_log_collection_rules details
[SentinelOne] List the log collection rules that match the filter, with the scope, agent type and activation state of each. A rule only ships logs once it is activated, so check the state here rather than assuming a created rule is live. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Set countOnly=true to size a filter before acting on it. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_log_collection_rules_by_agent_type details
s1_get_log_collection_rules_by_agent_type details
[SentinelOne] Get Log Collection rules by agent type. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_update_log_collection_rule details
s1_update_log_collection_rule details
[SentinelOne] DESTRUCTIVE — Change a log collection rule. If the rule is active the change reaches live agents, altering which paths and logs they collect, so an over-broad path can flood ingest and a narrowed one silently drops the source a SIEM depends on. Read the current rule with s1_get_log_collection_rules and send it back with your change. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
Policies
s1_get_account_policy details
s1_get_account_policy details
[SentinelOne] Account Policy. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_global_policy details
s1_get_global_policy details
[SentinelOne] Global Policy. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_group_policy details
s1_get_group_policy details
[SentinelOne] Group Policy. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_site_policy details
s1_get_site_policy details
[SentinelOne] Site Policy. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_update_account_policy details
s1_update_account_policy details
[SentinelOne] DESTRUCTIVE — Replace an account's agent policy. It reaches every site, group and agent beneath the account that inherits, and it changes what those endpoints actually enforce — detection mode, protection actions, engines. Read the current policy with s1_get_account_policy and send it back with your change; this is a replace, so an omitted field is a changed field. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_update_global_policy details
s1_update_global_policy details
[SentinelOne] DESTRUCTIVE — Replace the tenant-wide agent policy. This is the widest protection change in the connector: it reaches every account, every site and every agent that inherits from global, and it takes effect as agents check in. Read the current policy with s1_get_global_policy and send it back with your change — this is a replace, so an omitted field is a changed field. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_update_group_policy details
s1_update_group_policy details
[SentinelOne] DESTRUCTIVE — Replace a group's agent policy. Every agent in the group starts enforcing the new settings as it checks in, so this changes live protection for those endpoints. Read the current policy with s1_get_group_policy and send it back with your change; this is a replace, so an omitted field is a changed field. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_update_site_policy details
s1_update_site_policy details
[SentinelOne] DESTRUCTIVE — Replace a site's agent policy. Every group and agent under the site that inherits starts enforcing the new settings as it checks in, so this changes live protection for one customer. Read the current policy with s1_get_site_policy and send it back with your change; this is a replace, so an omitted field is a changed field. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
Reports
s1_create_default_report_task details
s1_create_default_report_task details
[SentinelOne] DESTRUCTIVE — Create a scheduled report task. The vendor schema carries a recipients list and attachment types, so this can mail console data with attachments to arbitrary addresses, immediately or on a recurring schedule. Check the recipients in the body before you send it. A 200 response does not prove the change landed — re-read with s1_get_default_report_tasks to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_delete_default_report_tasks details
s1_delete_default_report_tasks details
[SentinelOne] DESTRUCTIVE — Delete Default Report Tasks. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_delete_default_reports details
s1_delete_default_reports details
[SentinelOne] DESTRUCTIVE — Delete Default Reports. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_download_default_report details
s1_download_default_report details
[SentinelOne] Fetch a generated default report by id. NOTE: SentinelOne serves this endpoint as a PDF or HTML document, and report_format accepts only pdf or html. StackJack tools return JSON, so this call reports a content-type error rather than a document — use s1_get_default_reports to read the report's metadata, and download the file itself from the SentinelOne console. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_default_report_tasks details
s1_get_default_report_tasks details
[SentinelOne] List the report tasks that generate default reports now or on a schedule, including the recipients each task mails its report to. Read this before creating or editing a task, both to copy the shape of an existing one and to see who is already being emailed. Each task carries many lines, so filter rather than paging blind. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Set countOnly=true to size a filter before acting on it. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_default_reports details
s1_get_default_reports details
[SentinelOne] List the generated default reports that match the filter, with the schedule, insight type, date range and the user who created each one. Use it to get a report id for s1_download_default_report. Default reports need the Reports permission and the matching license. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Set countOnly=true to size a filter before acting on it. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_report_insight_types details
s1_get_report_insight_types details
[SentinelOne] Get Default Insight Reports. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_rss_feed details
s1_get_rss_feed details
[SentinelOne] S1 RSS Feed. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_update_default_report_task details
s1_update_default_report_task details
[SentinelOne] DESTRUCTIVE — Edit a scheduled report task. The edit schema carries the same recipients list, so it can add mail recipients to a task that had none or re-point an existing schedule. This is a replace, so read the current task first and send the complete object. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
Saved Views
s1_delete_filter details
s1_delete_filter details
[SentinelOne] DESTRUCTIVE — Delete Filter. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_delete_filter_xdr details
s1_delete_filter_xdr details
[SentinelOne] DESTRUCTIVE — Delete Filter. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_enriched_filters details
s1_get_enriched_filters details
[SentinelOne] Filters with Metadata. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_filters details
s1_get_filters details
[SentinelOne] List the saved filters (saved console views) that match the request, with the scope and the criteria each one stores. Saved filters are presentation only — they name a view, they never widen what a credential can reach. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Set countOnly=true to size a filter before acting on it. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_filters_xdr details
s1_get_filters_xdr details
[SentinelOne] Get Filters. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_save_filter details
s1_save_filter details
[SentinelOne] Save Filter. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_save_filter_xdr details
s1_save_filter_xdr details
[SentinelOne] Save Filter. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_update_filter details
s1_update_filter details
[SentinelOne] Update Filter. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_update_filter_xdr details
s1_update_filter_xdr details
[SentinelOne] Update Filter. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_upload_csv_filter details
s1_upload_csv_filter details
[SentinelOne] Upload CSV file. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
Sites
s1_create_site details
s1_create_site details
[SentinelOne] Create a site under an account. A new site begins consuming license against the account's entitlement, and its policy inheritance decides what agents enrolled into it will enforce. Check remaining entitlement with s1_get_account first. A 200 response does not prove the change landed — re-read with s1_get_sites to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_create_site_with_admin details
s1_create_site_with_admin details
[SentinelOne] DESTRUCTIVE — Create a site AND its first administrator in one call. Two things happen: a new site starts consuming license, and a console user is created with administrative rights over it, which normally means an invitation email is sent. This is not the same as adding a user to an existing site — use s1_create_site for a site alone. A 200 response does not prove the change landed — re-read with s1_get_sites to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_delete_site details
s1_delete_site details
[SentinelOne] DESTRUCTIVE — Delete a site. This removes the customer container itself, along with its groups and its policy, and the agents registered to it lose their site. Prefer s1_expire_site for offboarding, which stops the site while leaving its data readable. Confirm the site with s1_get_site and check its agent count first. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_expire_site details
s1_expire_site details
[SentinelOne] DESTRUCTIVE — Expire a site immediately. The site stops consuming license and its agents stop being managed from the console, which is a customer-visible loss of protection management. This is the offboarding verb; s1_reactivate_site is the way back. Confirm the site with s1_get_site first. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_site details
s1_get_site details
[SentinelOne] Get one site by its id, including its state, expiration date, license counts, policy inheritance and the account it belongs to. Get the id from s1_get_sites. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_site_local_upgrade_approved_agents details
s1_get_site_local_upgrade_approved_agents details
[SentinelOne] Get a CSV file of local upgrade/downgrade Site authorization data. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_site_local_upgrade_authorization details
s1_get_site_local_upgrade_authorization details
[SentinelOne] Get local upgrade/downgrade Site authorization. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_site_registration_token details
s1_get_site_registration_token details
[SentinelOne] Get Site registration token by ID. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_sites details
s1_get_sites details
[SentinelOne] List the sites that match the filter, with their state, expiration, license counts and the account each belongs to. A SITE is normally one customer, so this is the usual first call when scoping any other tool to a single customer — take siteIds from here. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Set countOnly=true to size a filter before acting on it. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_reactivate_site details
s1_reactivate_site details
[SentinelOne] DESTRUCTIVE — Reactivate an expired site. The site starts consuming license again and its agents return to managed state, so this is a billing-relevant action as well as an operational one. A 200 response does not prove the change landed — re-read with s1_get_site to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_regenerate_site_key details
s1_regenerate_site_key details
[SentinelOne] DESTRUCTIVE — Regenerate a site's registration token. Every installer and deployment script carrying the old token stops being able to enroll new agents — already-installed agents keep working, but your deployment tooling breaks until it is updated with the new value from s1_get_site_registration_token. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_revert_site_policy details
s1_revert_site_policy details
[SentinelOne] DESTRUCTIVE — Discard the site's own policy and revert it to inherit from the account. Every explicit setting on the site is lost in one call, and its groups and agents start enforcing the account's settings instead. Read s1_get_site_policy first and keep a copy — there is no undo. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_set_site_local_upgrade_authorization details
s1_set_site_local_upgrade_authorization details
[SentinelOne] DESTRUCTIVE — Change which agents in a site are authorized to be upgraded or DOWNGRADED locally, at the endpoint. Authorizing a downgrade lets someone with local access move an agent to an older build, which is a protection-posture decision, not a maintenance one. Read the current authorization with s1_get_site_local_upgrade_authorization first. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_update_site details
s1_update_site details
[SentinelOne] DESTRUCTIVE — Change a site's fields, which include its license allocation, expiration and policy inheritance. Read the current values with s1_get_site and send them back with your change — the vendor treats this as a replace, so an omitted field is a changed field. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_update_sites_bulk details
s1_update_sites_bulk details
[SentinelOne] DESTRUCTIVE — Change many sites in one call. The blast radius is every site in the body, and the same replace semantics apply to each, so an omitted field is a changed field across all of them at once. Read the current values with s1_get_sites first. A 200 response does not prove the change landed — the `affected` count can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
Users and Roles
s1_bulk_delete_service_users details
s1_bulk_delete_service_users details
[SentinelOne] DESTRUCTIVE — Delete every service user matching a FILTER, not a list of ids. This can revoke every API integration in scope at once, this connector included, and SentinelOne answers 200 either way. Run s1_get_service_users with the SAME filter and countOnly=true first, and check s1_get_current_user to see whether your own identity is in the set. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_bulk_delete_users details
s1_bulk_delete_users details
[SentinelOne] DESTRUCTIVE — Delete every console user matching a FILTER, not a list of ids. A wrong or empty filter is how you remove every administrator in scope, and SentinelOne answers 200 either way. Run s1_list_users with the SAME filter and countOnly=true first and read the count. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_check_remote_shell_permissions details
s1_check_remote_shell_permissions details
[SentinelOne] Check Remote Shell Permissions. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_check_tenant_admin_auth details
s1_check_tenant_admin_auth details
[SentinelOne] Check Global User. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_check_viewer_auth details
s1_check_viewer_auth details
[SentinelOne] Check Viewer. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_create_role details
s1_create_role details
[SentinelOne] DESTRUCTIVE — Create an RBAC role with a permission set. This is privilege-widening: whatever permissions you name become grantable to console users and to API service users, so an over-broad role is a standing escalation path. Start from s1_get_new_role_template for the permission vocabulary, and grant the narrowest set that does the job. A 200 response does not prove the change landed — re-read with s1_get_roles to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_create_service_user details
s1_create_service_user details
[SentinelOne] DESTRUCTIVE — Create a service user, which is an API-only identity, and mint its API token. The token is returned ONCE in this response and cannot be read back afterwards — capture it or it is lost. Treat the response as a credential: it grants API access at the role and scope you name, so pick the narrowest of both. A 200 response does not prove the change landed — re-read with s1_get_service_users to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_create_user details
s1_create_user details
[SentinelOne] DESTRUCTIVE — Create a console user with a role and a scope. This mints console access for a person and, if the console has onboarding enabled, EMAILS them an invitation. Give the narrowest role and the narrowest scope that does the job — read s1_get_roles first. A 200 response does not prove the change landed — re-read with s1_list_users to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_delete_role details
s1_delete_role details
[SentinelOne] DESTRUCTIVE — Delete an RBAC role. Every user and service user assigned to it loses the permissions it granted, so console access and running integrations can break at once. Read s1_get_role to see the permission set and s1_get_roles to see how many identities are assigned before you delete. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_delete_service_user details
s1_delete_service_user details
[SentinelOne] DESTRUCTIVE — Delete a service user. Every API token issued to that identity stops working at once, so any integration built on it breaks — including this StackJack connector, if you delete the identity it authenticates as. Check with s1_get_current_user before deleting a service user. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_delete_user details
s1_delete_user details
[SentinelOne] DESTRUCTIVE — Delete a console user. The person loses access to the SentinelOne console immediately, and anything they owned, such as saved views and report tasks, is orphaned. Confirm the identity with s1_get_user first — user ids and service user ids look alike and are not interchangeable. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_enable_2fa_app details
s1_enable_2fa_app details
[SentinelOne] DESTRUCTIVE — Complete two-factor enrollment for a console user by confirming the app code. From here on that person needs their authenticator to sign in, so losing the device means an administrator has to reset it. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_generate_api_token details
s1_generate_api_token details
[SentinelOne] DESTRUCTIVE — Mint a new API token for a console user. The token is returned ONCE in this response and cannot be read back — capture it or it is lost. It carries that user's full role and scope, so it is a credential with real reach, and minting one INVALIDATES that user's previous token, which breaks any integration still using it. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_generate_api_token_service_user details
s1_generate_api_token_service_user details
[SentinelOne] DESTRUCTIVE — Mint a new API token for a service user. The token is returned ONCE in this response and cannot be read back — capture it or it is lost, and treat it as a credential carrying that service user's role and scope. Any integration still holding the previous token for this identity stops working. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_generate_iframe_token details
s1_generate_iframe_token details
[SentinelOne] DESTRUCTIVE — Mint a short-lived token that embeds the SentinelOne console in an iframe. It is a bearer credential for the console session, so treat the response as a secret and do not paste it into a ticket or a chat transcript. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_current_user details
s1_get_current_user details
[SentinelOne] Get the console user that owns the API token this connector is using, with their role and scope. Use it to answer what this credential can actually do before a write fails with a 403, since SentinelOne enforces permissions per endpoint against this identity. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_new_role_template details
s1_get_new_role_template details
[SentinelOne] Get template for new role. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_role details
s1_get_role details
[SentinelOne] Get one RBAC role by its id, with the full permission list it grants. Get the id from s1_get_roles. This is the read that answers which permission a 403 is complaining about. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_roles details
s1_get_roles details
[SentinelOne] List the RBAC roles defined in the console, with the scope each is defined at and the number of users assigned. Read this before creating or editing a role, and to work out which role a 403 is pointing at. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Set countOnly=true to size a filter before acting on it. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_service_user details
s1_get_service_user details
[SentinelOne] Get Service User. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_service_users details
s1_get_service_users details
[SentinelOne] List the service users that match the filter, with their scope, role and token expiry. Service users are the API-only identities SentinelOne recommends for integrations, so this is where to check when a token is about to lapse. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Set countOnly=true to size a filter before acting on it. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_user details
s1_get_user details
[SentinelOne] Get one console user by their id, including role, scope, two-factor state and last login. Get the id from s1_list_users. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_user_api_token_details details
s1_get_user_api_token_details details
[SentinelOne] API Token by User ID. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_list_users details
s1_list_users details
[SentinelOne] List the console users that match the filter, with their role, scope, last login and whether they have verified their email. These are people who sign in to the SentinelOne console, not endpoint agents and not service users — see s1_get_service_users for API identities. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Set countOnly=true to size a filter before acting on it. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_request_2fa_app details
s1_request_2fa_app details
[SentinelOne] DESTRUCTIVE — Start two-factor enrollment for a console user, which returns the secret the authenticator app needs. This is auth-factor association: it changes how a person proves who they are, and a half-finished enrollment can leave them unable to sign in. Treat the response as a secret. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_revoke_api_token details
s1_revoke_api_token details
[SentinelOne] DESTRUCTIVE — Revoke a user's API token. Every integration authenticating with that token starts failing on its next call, and there is no undo — the replacement is a new token from s1_generate_api_token. If the identity is the one this connector uses, this revokes StackJack's own access; check with s1_get_current_user first. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_send_verification_email details
s1_send_verification_email details
[SentinelOne] DESTRUCTIVE — Send the onboarding verification email to every user matching a FILTER. This REACHES PEOPLE and it can lock them out: the vendor warns that active users are locked out of the console until they verify, unless the console has user-set password methods enabled. A wrong filter therefore mails, and locks out, every administrator in scope. Run s1_list_users with the SAME filter and countOnly=true first. SMTP must be configured for the Global scope or nothing is delivered. A 200 response does not prove delivery — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_update_role details
s1_update_role details
[SentinelOne] DESTRUCTIVE — Change an RBAC role's permission set. This is privilege-widening and it applies to every identity already assigned to the role, immediately — adding one permission grants it to all of them, and removing one can break a running integration. Read the current set with s1_get_role and send it back with your change; the vendor treats this as a replace, not a merge. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_update_service_user details
s1_update_service_user details
[SentinelOne] DESTRUCTIVE — Change a service user's fields, including its role and scope. This is privilege-widening for an API identity: every integration already using that identity's token gains or loses access immediately. Read the current values with s1_get_service_user and send them back with your change. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_update_user details
s1_update_user details
[SentinelOne] DESTRUCTIVE — Change a console user's fields, which include their role and their scope. Changing either is privilege-widening: it takes effect on that person's next request, with no further approval. Read the current values with s1_get_user and send them back with your change rather than a partial body. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_verify_onboarding_email details
s1_verify_onboarding_email details
[SentinelOne] DESTRUCTIVE — Redeem an onboarding verification token and SET THAT USER'S PASSWORD. This is a credential-setting call, not a status check: it completes a console sign-in identity for a person. Only use it when you are completing an invitation you already hold the token for. A 200 response does not prove the change landed — re-read with s1_get_user to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
Application Management
s1_get_aggregated_applications_risk details
s1_get_aggregated_applications_risk details
[SentinelOne] Get Aggregated Applications With Risk. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns applications carrying risk ROLLED UP across their versions, so one row per product rather than per installed version. Use s1_get_applications_risk when you need the per-version detail. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_app_inventory_endpoints details
s1_get_app_inventory_endpoints details
[SentinelOne] Get App Inventory Endpoints. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. SentinelOne requires applicationName and applicationVendor on this endpoint — pass them in filtersJson or the call fails with a 400. applicationName: the application name to match. applicationVendor: the application vendor to match. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the ENDPOINT side of the inventory: one row per endpoint with its application counts. Use s1_get_endpoint_apps for the same data keyed by application instead. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_application_cves details
s1_get_application_cves details
[SentinelOne] Get Application CVEs. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns known CVEs affecting software in the scope, one row per CVE. Use s1_get_endpoints_vulnerable_app to turn a CVE into the list of machines that need patching. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_application_inventory details
s1_get_application_inventory details
[SentinelOne] Get Application Inventory. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the installed-software inventory: one row per application found across the endpoints in scope. Start here when the question is "what is installed". A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_application_management_settings details
s1_get_application_management_settings details
[SentinelOne] Get Application Management Settings. Scope to one customer with siteIds / accountIds / groupIds. Returns the Application Management settings for the scope, including the scan schedule. Read this before s1_update_application_management_settings, which replaces the whole object. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_applications_risk details
s1_get_applications_risk details
[SentinelOne] Get Applications With Risk. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns applications carrying risk, one row per application, with the vulnerability counts that make it risky. Use s1_get_aggregated_applications_risk for the same data rolled up across versions. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_cve_data details
s1_get_cve_data details
[SentinelOne] Get CVE data. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the application-risk root: the CVE-derived risk data for the scope. The three narrower reads under it are s1_get_application_cves (per CVE), s1_get_applications_risk (per application) and s1_get_endpoints_vulnerable_app (per endpoint). A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_endpoint_apps details
s1_get_endpoint_apps details
[SentinelOne] Get Endpoint Apps. Returns the applications installed on endpoints, keyed by application. Use s1_get_app_inventory_endpoints for the same data keyed by endpoint instead. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_endpoints_vulnerable_app details
s1_get_endpoints_vulnerable_app details
[SentinelOne] Get Endpoints For Vulnerable App. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the endpoints running a vulnerable application — the read that turns a CVE or a risky application into the list of machines to patch. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_initiate_scan_application_management details
s1_initiate_scan_application_management details
[SentinelOne] DESTRUCTIVE — Initiate scan. This starts an application-inventory scan on every endpoint in the scope you pass. Scope it with siteIds, accountIds or groupIds first — with no scope it runs fleet-wide and every endpoint spends CPU on it at once. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_update_application_management_settings details
s1_update_application_management_settings details
[SentinelOne] DESTRUCTIVE — Update Application Management Settings. This replaces the whole application-management settings object for the scope. Send every field you want to keep: a field you omit is cleared, not left alone. Read s1_get_application_management_settings first and edit that payload. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
Device Control
s1_copy_rules details
s1_copy_rules details
[SentinelOne] DESTRUCTIVE — Copy Rules. This copies Device Control rules into ANOTHER scope, so it changes hardware policy somewhere you did not name in the read you ran first. Confirm the destination scope, not just the source. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_create_device_control_rule details
s1_create_device_control_rule details
[SentinelOne] DESTRUCTIVE — Create Device Control Rule. Device Control rules decide which USB, Bluetooth and other peripheral hardware may attach to every endpoint in scope. A new rule takes effect as soon as it is created, so a wrong device class can block keyboards or storage across a whole site. Confirm the scope and read s1_get_device_rules first. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_delete_rules_device_control details
s1_delete_rules_device_control details
[SentinelOne] DESTRUCTIVE — Delete Rules. Deleting a Device Control rule removes its restriction from every endpoint in scope immediately, and there is no undo or version history. If the rule was a block, the hardware it blocked is permitted from that moment. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_enable_disable_rules details
s1_enable_disable_rules details
[SentinelOne] DESTRUCTIVE — Enable/Disable Rules. Disabling a Device Control rule lifts its restriction on every endpoint in scope immediately; enabling one applies it just as fast. Confirm which rule ids you are toggling with s1_get_device_rules. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_export_rules details
s1_export_rules details
[SentinelOne] Export Rules. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. KNOWN LIMITATION: SentinelOne answers this endpoint with a CSV body, not JSON, so StackJack refuses it and the tool reports a content-type error. There is no format parameter to change that. Use s1_get_device_rules for the same rules as JSON. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_configuration details
s1_get_configuration details
[SentinelOne] Get Configuration. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the Device Control configuration for the scope, including whether Device Control is enforcing at all. Read this before s1_update_configuration, which replaces the whole object. The firewall equivalent is s1_get_configuration_firewall_control. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_device_control_events details
s1_get_device_control_events details
[SentinelOne] Get Device Control Events. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns Device Control EVENTS — the peripherals that were actually allowed or blocked on endpoints, not the rules. Use s1_get_device_rules for the rules themselves. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_device_rules details
s1_get_device_rules details
[SentinelOne] Get Device Rules. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the Device Control rules for the scope — which USB, Bluetooth and other peripheral hardware is allowed or blocked. Read this before any Device Control write; rule ids and rule ORDER both come from here. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_move_rules details
s1_move_rules details
[SentinelOne] DESTRUCTIVE — Move rules. This moves Device Control rules OUT of their current scope and into another one, so the source scope loses the restriction at the same moment the destination gains it. Confirm both scopes. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_reorder_rules details
s1_reorder_rules details
[SentinelOne] DESTRUCTIVE — Reorder Rules. Rule order decides which rule wins for a device that matches more than one of them. Reordering can flip an allow into a block for hardware that was working a moment ago, without changing any rule body. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_update_configuration details
s1_update_configuration details
[SentinelOne] DESTRUCTIVE — Update Configuration. This replaces the whole Device Control configuration for the scope, including whether Device Control is enforcing at all. Read s1_get_configuration first and edit that payload — an omitted field is cleared. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_update_device_rule details
s1_update_device_rule details
[SentinelOne] DESTRUCTIVE — Update Device Rule. This replaces the whole rule, not the fields you send. Read the rule with s1_get_device_rules and edit that payload, or the omitted fields are cleared. Device Control governs which peripherals may attach to every endpoint in scope. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
Exclusions and Blocklist
s1_create_blocklist_item details
s1_create_blocklist_item details
[SentinelOne] DESTRUCTIVE — Create Blocklist Item. A blocklist entry makes SentinelOne kill and quarantine the hash on every endpoint in scope. Blocking the hash of a file the customer depends on takes that software out of service fleet-wide. Check the hash with s1_validate_blocklist_item first. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_create_bulk_unified_exclusion details
s1_create_bulk_unified_exclusion details
[SentinelOne] DESTRUCTIVE — Create Bulk Unified Exclusion. This writes MANY exclusions in one call, each one telling SentinelOne to stop inspecting what it names. A single bad entry in the payload is a permanent blind spot that the console will not flag. Review every entry and confirm the scope before you send it. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_create_config_override details
s1_create_config_override details
[SentinelOne] DESTRUCTIVE — Create Config Override. A config override changes agent behavior for the scope and outranks the policy set in the console, so the console policy page will no longer describe what the agents are actually doing. Record why it exists — an override nobody remembers is how protection silently drifts. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_create_exclusion details
s1_create_exclusion details
[SentinelOne] DESTRUCTIVE — Create Exclusion. An exclusion tells SentinelOne to STOP inspecting the path, hash or process you name. Over-broad exclusions are the classic self-inflicted breach: the agent keeps running and keeps reporting healthy while what you excluded is no longer protected. Check the value with s1_validate_exclusion_item and confirm the scope before you write it. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_create_unified_exclusion details
s1_create_unified_exclusion details
[SentinelOne] DESTRUCTIVE — Create Unified Exclusion. An exclusion tells SentinelOne to STOP inspecting what you name, and a unified exclusion applies across surfaces rather than to one engine. The agent keeps reporting healthy afterwards, so an over-broad value leaves a blind spot nothing alerts on. Confirm the exact value and the scope first. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_delete_blocklist_item details
s1_delete_blocklist_item details
[SentinelOne] DESTRUCTIVE — Delete Blocklist Item. Removing a blocklist entry RE-PERMITS the hash you previously banned on every endpoint in scope. If the entry was there because of a real incident, this undoes that containment. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_delete_config_override details
s1_delete_config_override details
[SentinelOne] DESTRUCTIVE — Delete Config Override. Removing an override snaps the scope back to the console policy immediately. If the override existed to keep a business application working, that application can start being blocked. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_delete_config_overrides details
s1_delete_config_overrides details
[SentinelOne] DESTRUCTIVE — Delete Config Overrides. This removes MULTIPLE overrides at once, snapping every affected scope back to console policy immediately. Read s1_get_config_overrides first — an override that exists to keep a business application working is not obviously distinguishable from a stale one. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_delete_exclusions details
s1_delete_exclusions details
[SentinelOne] DESTRUCTIVE — Delete Exclusions. Removing an exclusion RE-ARMS detection on what it covered. Files and processes the customer relies on can be quarantined within minutes of this call. Read s1_get_exclusions first and be sure the exclusion is genuinely obsolete. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_delete_exclusions_unified_exclusions details
s1_delete_exclusions_unified_exclusions details
[SentinelOne] DESTRUCTIVE — Delete Exclusions. Removing an exclusion RE-ARMS detection on what it covered. Files and processes the customer relies on can be quarantined within minutes of this call. Read s1_get_exclusions_unified_exclusions first and be sure the exclusion is genuinely obsolete. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_export_unified_exclusions details
s1_export_unified_exclusions details
[SentinelOne] Export Unified Exclusions. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the currently filtered unified exclusions as a JSON export payload, in the shape s1_import_unified_exclusions accepts. This is the read half of copying exclusions between scopes. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_blocklist details
s1_get_blocklist details
[SentinelOne] Get Blocklist. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the blocklist for the scope: hashes SentinelOne kills and quarantines everywhere in it. This is the deny side; s1_get_exclusions is the allow side. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_blocklist_import_validation_report details
s1_get_blocklist_import_validation_report details
[SentinelOne] Get Blocklist Import Validation Report. Returns the validation report for a blocklist import, by the report id that s1_import_blocklist_items returned. Read it before you trust the import: the import call answers 200 even when rows were rejected. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_config_overrides details
s1_get_config_overrides details
[SentinelOne] Get Config Overrides. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the config overrides for the scope. An override outranks the policy set in the console, so this read is how you find out why agents are not behaving the way the policy page says they should. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_exclusion_actions details
s1_get_exclusion_actions details
[SentinelOne] Get Exclusion Actions. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. SentinelOne requires create on this endpoint — pass it in filtersJson or the call fails with a 400. create: a boolean the vendor documents only as `Create`; send true or false. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns which exclusion actions this tenant may use. Read it before building a unified-exclusion payload — an unsupported action is a 400, not an ignored field. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_exclusion_import_validation_report details
s1_get_exclusion_import_validation_report details
[SentinelOne] Get Exclusion Import Validation Report. Returns the validation report for an exclusion import, by the report id that s1_import_exclusions returned. Read it before you trust the import: the import call answers 200 even when rows were rejected. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_exclusions details
s1_get_exclusions details
[SentinelOne] Get Exclusions. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the LEGACY per-engine exclusions for the scope — paths, hashes, certificates and browsers that SentinelOne is told not to inspect. The newer cross-surface list is s1_get_exclusions_unified_exclusions; a tenant can have both, so check each before concluding nothing is excluded. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_exclusions_unified_exclusions details
s1_get_exclusions_unified_exclusions details
[SentinelOne] Get Exclusions. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the UNIFIED exclusions for the scope — the newer model that applies across surfaces rather than to one engine. The legacy per-engine list is s1_get_exclusions; a tenant can have both, so check each before concluding nothing is excluded. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_import_blocklist_items details
s1_import_blocklist_items details
[SentinelOne] DESTRUCTIVE — Import Blocklist Items. An import writes MANY blocklist entries in one call, and each one kills and quarantines its hash on every endpoint in scope. A bad hash in the payload takes working software out of service fleet-wide. Check the returned report id with s1_get_blocklist_import_validation_report before you trust the result. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_import_exclusions details
s1_import_exclusions details
[SentinelOne] DESTRUCTIVE — Import Exclusions. An import writes MANY exclusions in one call, each one a place SentinelOne will stop inspecting. Nothing in the console flags an over-broad entry afterwards. Send the payload through s1_validate_exclusion_item first, then check the returned report id with s1_get_exclusion_import_validation_report before you trust the result. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_import_unified_exclusions details
s1_import_unified_exclusions details
[SentinelOne] DESTRUCTIVE — Import Unified Exclusions. An import writes MANY exclusions in one call, each one a place SentinelOne will stop inspecting. Nothing in the console flags an over-broad entry afterwards. Review every entry, and confirm the destination scope — imports are normally used to copy exclusions BETWEEN scopes, so the target is easy to get wrong. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_update_blocklist_item details
s1_update_blocklist_item details
[SentinelOne] DESTRUCTIVE — Update Blocklist Item. This replaces the blocklist entry rather than merging into it, so an omitted field is cleared. Changing the hash re-permits the old one and starts killing the new one on every endpoint in scope. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_update_config_override details
s1_update_config_override details
[SentinelOne] DESTRUCTIVE — Update Config Override. This replaces the override rather than merging into it, so an omitted field is cleared. The override outranks console policy, so a wrong value changes agent behavior for the whole scope with nothing on the policy page to explain it. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_update_exclusions details
s1_update_exclusions details
[SentinelOne] DESTRUCTIVE — Update Exclusions. This replaces the exclusion rather than merging into it, so an omitted field is cleared. Both directions are dangerous: widening it creates a blind spot, narrowing it re-arms detection on files the customer relies on. Read s1_get_exclusions and edit that payload. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_update_exclusions_unified_exclusions details
s1_update_exclusions_unified_exclusions details
[SentinelOne] DESTRUCTIVE — Update Exclusions. This replaces the exclusion rather than merging into it, so an omitted field is cleared. Both directions are dangerous: widening it creates a blind spot, narrowing it re-arms detection on files the customer relies on. Read s1_get_exclusions_unified_exclusions and edit that payload. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_validate_blocklist_item details
s1_validate_blocklist_item details
[SentinelOne] Validate Blocklist Item. This is a POST that READS: the criteria travel in the request body, and nothing is created or changed. Checks a blocklist value WITHOUT writing it. Run this before s1_create_blocklist_item — a bad hash takes working software out of service on every endpoint in scope. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_validate_exclusion_item details
s1_validate_exclusion_item details
[SentinelOne] Validate Exclusion Item. This is a POST that READS: the criteria travel in the request body, and nothing is created or changed. Checks an exclusion value WITHOUT writing it. Run this before s1_create_exclusion — an over-broad exclusion is not reversible in its effect, because nothing was inspected while it was live. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
Firewall Control
s1_add_rule_tags_firewall_control details
s1_add_rule_tags_firewall_control details
[SentinelOne] Add Rule Tags. Attaches tags to firewall rules. Additive: it adds the tags you name and clears nothing, which is why this one is not marked destructive while its remove twin is. Tags drive which rules apply where, so check s1_get_tag_firewall_rules to see what a tag already carries. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_copy_rules_firewall_control details
s1_copy_rules_firewall_control details
[SentinelOne] DESTRUCTIVE — Copy Rules. This copies firewall rules into ANOTHER scope, so it changes network policy somewhere you did not name in the read you ran first. Confirm the destination scope, not just the source. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_create_firewall_rule details
s1_create_firewall_rule details
[SentinelOne] DESTRUCTIVE — Create Firewall Rule. Firewall Control rules govern network traffic on every endpoint in scope, and a new rule takes effect as soon as it is created. A wrong rule can cut a whole site off the network, or open a port the customer policy closes. Read s1_get_firewall_rules and confirm the scope first. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_delete_rules_firewall_control details
s1_delete_rules_firewall_control details
[SentinelOne] DESTRUCTIVE — Delete Rules. Deleting a firewall rule removes it from every endpoint in scope immediately, with no undo. If it was a block, that traffic is permitted from this moment; if it was the allow that kept a business application reachable, that application stops working. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_enable_disable_rules_firewall_control details
s1_enable_disable_rules_firewall_control details
[SentinelOne] DESTRUCTIVE — Enable/Disable Rules. Disabling a firewall rule lifts it on every endpoint in scope immediately, and enabling one applies it just as fast. Confirm the rule ids with s1_get_firewall_rules. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_export_rules_firewall_control details
s1_export_rules_firewall_control details
[SentinelOne] Export Rules. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the matching firewall rules as a JSON export payload, in the shape s1_import_rules_firewall_control accepts. This is the read half of copying rules between scopes. Firewall Control requires the Control SKU. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_configuration_firewall_control details
s1_get_configuration_firewall_control details
[SentinelOne] Get Configuration. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the Firewall Control configuration for the scope, including whether Firewall Control is enforcing at all. Read this before s1_update_configuration_firewall_control, which replaces the whole object. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_firewall_rules details
s1_get_firewall_rules details
[SentinelOne] Get Firewall Rules. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the Firewall Control rules for the scope. Read this before any firewall write; rule ids and rule ORDER both come from here, and order decides which rule wins. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_protocols_firewall_control details
s1_get_protocols_firewall_control details
[SentinelOne] Get Protocols. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the protocol vocabulary SentinelOne accepts in a firewall rule. Read it before composing a rule body; an unsupported protocol name is a 400, not an ignored field. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_tag_firewall_rules details
s1_get_tag_firewall_rules details
[SentinelOne] Get Tag Firewall Rules. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the firewall rules attached to one tag. Read it before removing that tag from anything — the rules listed here stop applying wherever the tag is detached. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_import_rules_firewall_control details
s1_import_rules_firewall_control details
[SentinelOne] DESTRUCTIVE — Import Rules. An import writes MANY firewall rules in one call, and they take effect on every endpoint in the destination scope. Imports are normally used to copy rules BETWEEN scopes, so the destination is the field to check twice. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_move_rules_firewall_control details
s1_move_rules_firewall_control details
[SentinelOne] DESTRUCTIVE — Move Rules. This moves firewall rules OUT of their current scope into another one, so the source scope loses that network policy at the same moment the destination gains it. Confirm both scopes. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_remove_rule_tags_firewall_control details
s1_remove_rule_tags_firewall_control details
[SentinelOne] DESTRUCTIVE — Remove Rule Tags. Removing a tag detaches the rule from every tag-driven assignment that used it, so rules can stop applying to endpoints that were relying on the tag. Read s1_get_tag_firewall_rules first to see what the tag currently carries. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_reorder_rules_firewall_control details
s1_reorder_rules_firewall_control details
[SentinelOne] DESTRUCTIVE — Reorder Rules. Firewall rule order decides which rule wins for traffic matching more than one of them. Reordering can turn an allow into a block for traffic that was flowing a moment ago, without changing any rule body. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_set_location_firewall_control details
s1_set_location_firewall_control details
[SentinelOne] DESTRUCTIVE — Set Location. This changes which network location a rule applies to, so a rule written for a guest network can start applying on the corporate one, or stop applying where it was needed. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_update_configuration_firewall_control details
s1_update_configuration_firewall_control details
[SentinelOne] DESTRUCTIVE — Update Configuration. This replaces the whole Firewall Control configuration for the scope, including whether Firewall Control is enforcing at all. Read s1_get_configuration_firewall_control first and edit that payload — an omitted field is cleared. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_update_firewall_rule details
s1_update_firewall_rule details
[SentinelOne] DESTRUCTIVE — Update Firewall Rule. This replaces the whole rule, not the fields you send, so an omitted field is cleared. Firewall rules decide what traffic every endpoint in scope may carry — read s1_get_firewall_rules and edit that payload. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
Integrations
s1_activate_workflow_version details
s1_activate_workflow_version details
[SentinelOne] DESTRUCTIVE — Activate a workflow version. An active Hyperautomation workflow takes actions on its own whenever its trigger fires — including endpoint actions — with no further prompt. Activating a version makes THAT version live in place of whatever was running. Read the version with s1_list_workflow_versions and know what its actions do before you activate it. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_batch_export_workflows details
s1_batch_export_workflows details
[SentinelOne] Batch export workflows. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the matching workflows as an export payload, in the shape s1_batch_import_workflows accepts. This is the read half of copying automation between scopes. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_batch_import_workflows details
s1_batch_import_workflows details
[SentinelOne] DESTRUCTIVE — Batch import workflows. This imports MANY workflows in one call, each arriving with its actions intact. Review the payload before you send it — imported workflows are arbitrary automation against your console and your endpoints. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_create_estimator_id details
s1_create_estimator_id details
[SentinelOne] Create Estimator ID. Creates an estimator handle for sizing a Cloud Funnel export. It creates a measurement object only — no telemetry starts flowing until s1_post_onboarding_cloud_funnel is called. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_create_evaluate_expression details
s1_create_evaluate_expression details
[SentinelOne] DESTRUCTIVE — Evaluate Expression. This evaluates a workflow expression against a real base action rather than in a sandbox, which is why it is classified as a write. Treat it as touching the action it names. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_create_expression_breakdown details
s1_create_expression_breakdown details
[SentinelOne] DESTRUCTIVE — Expression Breakdown. This breaks a workflow expression down against a real base action rather than in a sandbox, which is why it is classified as a write. Treat it as touching the action it names. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_create_onboard_new_vcs_integration details
s1_create_onboard_new_vcs_integration details
[SentinelOne] DESTRUCTIVE — Onboard a new VCS integration. This connects a source-control organization to SentinelOne and begins scanning its repositories. Confirm the organization is the customer's before you onboard it. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. SentinelOne requires scopeType and scopeIds on this endpoint — pass them in filtersJson or the call fails with a 400. scopeType: the scope type this call resolves against. scopeIds: the ids of the scopes it applies to. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_create_provision_persist_mssp_partner_key details
s1_create_provision_persist_mssp_partner_key details
[SentinelOne] DESTRUCTIVE — Provision - Persist MSSP partner key. This MINTS an MSSP partner credential. Treat the response as a secret — anything holding that key can act as the partner against the mobile-integration API. Confirm the partner before you run it, and store the key somewhere the customer controls. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_create_provision_provision_mssp_partner_admin_user details
s1_create_provision_provision_mssp_partner_admin_user details
[SentinelOne] DESTRUCTIVE — Provision - Provision MSSP partner with admin user. This creates an MSSP PARTNER together with an admin user, which is a real console principal with administrative reach over what the partner manages. It is a billable object and it is not a dry run. Confirm the partner details before you send it. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_create_provision_provision_tenant_admin_user details
s1_create_provision_provision_tenant_admin_user details
[SentinelOne] DESTRUCTIVE — Provision - Provision tenant with admin user. This creates a mobile-integration TENANT together with an admin user — a real, billable console object with an administrative principal attached. Check with s1_check_mobile_tenant_can_be_provisioned first; there is no undo through this API. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_create_register_tunnel_user details
s1_create_register_tunnel_user details
[SentinelOne] DESTRUCTIVE — Register Tunnel User. This registers a tunnel principal for reaching a self-managed VCS host, which is a credential-shaped object. Treat the response as a secret and confirm the host is the customer's. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. SentinelOne requires scopeType and scopeIds on this endpoint — pass them in filtersJson or the call fails with a 400. scopeType: the scope type this call resolves against. scopeIds: the ids of the scopes it applies to. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_create_vcs_cicd_scanner_policy details
s1_create_vcs_cicd_scanner_policy details
[SentinelOne] DESTRUCTIVE — Create a VCS and CICD scanner policy. A scanner policy decides which findings BREAK a build. A policy that is too strict blocks the customer's pipeline; one that is too loose lets vulnerable code merge. Check s1_get_max_allowed_priority for the ceiling before you set one. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. SentinelOne requires scopeType and scopeIds on this endpoint — pass them in filtersJson or the call fails with a 400. scopeType: the scope type this call resolves against. scopeIds: the ids of the scopes it applies to. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_deactivate_active_workflow details
s1_deactivate_active_workflow details
[SentinelOne] DESTRUCTIVE — Deactivate The active workflow. Deactivating stops the workflow from firing at all. If the workflow was the automation containing threats or notifying the on-call, that response stops happening and nothing else will flag its absence. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_delete_cloud_funnel_rule details
s1_delete_cloud_funnel_rule details
[SentinelOne] DESTRUCTIVE — Delete cloud funnel rule. Deleting the Cloud Funnel rule STOPS the telemetry export. Anything downstream that consumes that stream — a SIEM, a data lake — goes quiet, and the events produced while it is off are not backfilled. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_delete_mssp_partner_key details
s1_delete_mssp_partner_key details
[SentinelOne] DESTRUCTIVE — Deletes MSSP partner key by client ID. Deleting the partner key immediately breaks every mobile-integration client authenticating with it, and the key cannot be recovered — a replacement has to be minted and redistributed. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_delete_vcs_cicd_scanner_policy details
s1_delete_vcs_cicd_scanner_policy details
[SentinelOne] DESTRUCTIVE — Delete a VCS and CICD scanner policy. Deleting the scanner policy removes the gate: pipelines it was blocking start passing, and findings it was enforcing stop being enforced. Nothing in the pipeline reports that the policy is gone. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. SentinelOne requires scopeType and scopeIds on this endpoint — pass them in filtersJson or the call fails with a 400. scopeType: the scope type this call resolves against. scopeIds: the ids of the scopes it applies to. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_delete_vcs_integration_cnapp details
s1_delete_vcs_integration_cnapp details
[SentinelOne] DESTRUCTIVE — Delete a VCS integration. Off-boarding removes the source-control integration and stops its repositories being scanned. Re-connecting needs the VCS credentials again. Confirm the integration id with s1_list_vcs_integrations. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. SentinelOne requires scopeType and scopeIds on this endpoint — pass them in filtersJson or the call fails with a 400. scopeType: the scope type this call resolves against. scopeIds: the ids of the scopes it applies to. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_disable_scanning_repositories_vcs_integration details
s1_disable_scanning_repositories_vcs_integration details
[SentinelOne] DESTRUCTIVE — Disable scanning for repositories in a VCS integration. Disabling scanning STOPS analysis of the named repositories, so new commits go uninspected and existing findings stop being refreshed. Nothing alerts on the gap. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. SentinelOne requires scopeType and scopeIds on this endpoint — pass them in filtersJson or the call fails with a 400. scopeType: the scope type this call resolves against. scopeIds: the ids of the scopes it applies to. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_edit_tags_repositories_vcs_integration details
s1_edit_tags_repositories_vcs_integration details
[SentinelOne] DESTRUCTIVE — Edit tags for repositories in a VCS integration. Repository tags drive which scanner policy applies, so a tag change can move a repository onto a different policy — or off the one that was gating its findings. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. SentinelOne requires scopeType and scopeIds on this endpoint — pass them in filtersJson or the call fails with a 400. scopeType: the scope type this call resolves against. scopeIds: the ids of the scopes it applies to. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_edit_tags_vcs_integration details
s1_edit_tags_vcs_integration details
[SentinelOne] DESTRUCTIVE — Edit tags for a VCS integration. Integration tags drive which scanner policy applies, so a tag change can move the whole integration onto a different policy — or off the one that was gating its findings. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. SentinelOne requires scopeType and scopeIds on this endpoint — pass them in filtersJson or the call fails with a 400. scopeType: the scope type this call resolves against. scopeIds: the ids of the scopes it applies to. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_enable_scanning_repositories_vcs_integration details
s1_enable_scanning_repositories_vcs_integration details
[SentinelOne] DESTRUCTIVE — Enable scanning for repositories in a VCS integration. Enabling scanning starts pulling and analyzing the named repositories, which counts against the scanning entitlement and surfaces findings against code the customer may not expect to be scanned yet. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. SentinelOne requires scopeType and scopeIds on this endpoint — pass them in filtersJson or the call fails with a 400. scopeType: the scope type this call resolves against. scopeIds: the ids of the scopes it applies to. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_export_cloud_rogue_resources details
s1_export_cloud_rogue_resources details
[SentinelOne] Export cloud rogue resources to csv (default) or json. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds. Pass any other documented query parameter as a flat JSON object in filtersJson. DEFAULTS TO CSV, which StackJack refuses because it is not JSON. Pass {"exportFormat":"json"} in filtersJson to get a JSON body this tool can return. Rogue resources are cloud assets with no SentinelOne agent on them. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_fetch_filter_count details
s1_fetch_filter_count details
[SentinelOne] Fetch filter count. SentinelOne requires scopeType and scopeIds on this endpoint — pass them in filtersJson or the call fails with a 400. scopeType: the scope type this call resolves against. scopeIds: the ids of the scopes it applies to. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_fetch_repository_tags details
s1_fetch_repository_tags details
[SentinelOne] Fetch repository tags. This is a POST that READS: the criteria travel in the request body, and nothing is created or changed. SentinelOne requires scopeType and scopeIds on this endpoint — pass them in filtersJson or the call fails with a 400. scopeType: the scope type this call resolves against. scopeIds: the ids of the scopes it applies to. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_agent_merged_updates details
s1_get_agent_merged_updates details
[SentinelOne] Get Agent Merged Updates. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. SentinelOne requires agentId on this endpoint — pass it in filtersJson or the call fails with a 400. agentId: the agent id. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the content-update inventory: which detection-content versions the agents in scope have merged. This is content, not agent software version. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_aws_assume_role_external_id details
s1_get_aws_assume_role_external_id details
[SentinelOne] Get AWS assume role external ID. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_cloud_funnel_rule details
s1_get_cloud_funnel_rule details
[SentinelOne] Get cloud funnel rule. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the Cloud Funnel rule for the scope: whether SentinelOne telemetry is being exported to an external bucket, and to which one. Read it before assuming no data is leaving the tenant. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_cloud_rogue_resources details
s1_get_cloud_rogue_resources details
[SentinelOne] Get cloud rogue resources. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_devices_get_list_devices_specific_scope details
s1_get_devices_get_list_devices_specific_scope details
[SentinelOne] Devices - Get list of devices for specific scope. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the MOBILE devices in scope, from the mobile-integration surface. These are not the endpoint agents — those live in the Endpoints family. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_estimate_size_events details
s1_get_estimate_size_events details
[SentinelOne] Get estimate size of events. SentinelOne requires estimatorId on this endpoint — pass it in filtersJson or the call fails with a 400. estimatorId: the estimator query id. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_gateways details
s1_get_gateways details
[SentinelOne] Get Gateways. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the Ranger gateways for the scope — the relays that perform network discovery. Gateway ids for the update tools come from here. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_incidents_get_list_incidents details
s1_get_incidents_get_list_incidents details
[SentinelOne] Incidents - Get list of incidents. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the incidents raised by the mobile-integration surface. These are not endpoint threats — those live in the Endpoints family. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_max_allowed_priority details
s1_get_max_allowed_priority details
[SentinelOne] Get max allowed priority. SentinelOne requires scopeType, scopeIds, targetScopeType and targetScopeId on this endpoint — pass them in filtersJson or the call fails with a 400. scopeType: the scope type this call resolves against. scopeIds: the ids of the scopes it applies to. targetScopeType: the scope type being compared against. targetScopeId: the id of that target scope. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_provision_check_if_tenant_can_be_provisioned details
s1_get_provision_check_if_tenant_can_be_provisioned details
[SentinelOne] Provision - Check if tenant can be provisioned. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_provision_get_mssp_partner_admin_user details
s1_get_provision_get_mssp_partner_admin_user details
[SentinelOne] Provision - Get MSSP partner with admin user. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_provision_get_mssp_partner_key details
s1_get_provision_get_mssp_partner_key details
[SentinelOne] Provision - Get MSSP partner key. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_provision_get_tenant_users details
s1_get_provision_get_tenant_users details
[SentinelOne] Provision - Get tenant with users. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_vcs_cicd_scanner_policy details
s1_get_vcs_cicd_scanner_policy details
[SentinelOne] Get a VCS and CICD scanner policy. SentinelOne requires scopeType and scopeIds on this endpoint — pass them in filtersJson or the call fails with a 400. scopeType: the scope type this call resolves against. scopeIds: the ids of the scopes it applies to. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_workflow_execution_id details
s1_get_workflow_execution_id details
[SentinelOne] Get a workflow execution by its ID. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_import_workflow details
s1_import_workflow details
[SentinelOne] DESTRUCTIVE — Import workflow. An imported workflow arrives with its actions intact. Review what it does before you activate it — an imported workflow from an untrusted source is arbitrary automation against your console and your endpoints. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_list_vcs_cicd_scanner_policies details
s1_list_vcs_cicd_scanner_policies details
[SentinelOne] List VCS and CICD scanner policies. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_list_vcs_integration_repositories details
s1_list_vcs_integration_repositories details
[SentinelOne] List VCS integration repositories. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the repositories under one VCS integration, with whether each is being scanned. This is the read to run before enabling or disabling scanning. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_list_vcs_integrations details
s1_list_vcs_integrations details
[SentinelOne] List VCS integrations. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the source-control integrations connected to this console. Integration ids for every other VCS tool come from here. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_list_workflow_executions details
s1_list_workflow_executions details
[SentinelOne] List all workflow executions. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns Hyperautomation workflow executions — what the automation actually did, and when. Use s1_get_workflow_execution_id for the detail of one run. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_list_workflow_versions details
s1_list_workflow_versions details
[SentinelOne] List workflow versions. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the versions of one workflow. Read the version you intend to activate before calling s1_activate_workflow_version — activating swaps which version is live. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_list_workflows details
s1_list_workflows details
[SentinelOne] List all workflows. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the Hyperautomation workflows in scope. An ACTIVE workflow takes actions on its own when its trigger fires, so this read is how you find out what automation is already running before you add more. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_offboard_vcs_integration details
s1_offboard_vcs_integration details
[SentinelOne] DESTRUCTIVE — off-board (delete) a VCS integration. SentinelOne serves this as a GET, but the effect is a teardown, not a read: the source-control integration stops being scanned and its connection to the console is removed. Confirm the integration id against s1_list_vcs_integrations first — there is no undo, and re-onboarding needs the VCS credentials again. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. SentinelOne requires scopeType and scopeIds on this endpoint — pass them in filtersJson or the call fails with a 400. scopeType: the scope type this call resolves against. scopeIds: the ids of the scopes it applies to. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_post_onboarding_cloud_funnel details
s1_post_onboarding_cloud_funnel details
[SentinelOne] DESTRUCTIVE — Post onboarding cloud funnel. Cloud Funnel streams your SentinelOne telemetry out to an external bucket. Onboarding starts that export, so confirm the destination is a bucket the customer owns — this is a standing data egress, not a one-off copy. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_trigger_workflow_uses_manual_trigger details
s1_trigger_workflow_uses_manual_trigger details
[SentinelOne] DESTRUCTIVE — Trigger a workflow that uses a manual trigger. This RUNS the workflow now. Whatever actions the workflow contains execute immediately — including endpoint actions such as isolating or scanning machines. Read the workflow first; the trigger call itself carries no preview. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_update_gateway details
s1_update_gateway details
[SentinelOne] DESTRUCTIVE — Update Gateway. Ranger gateways are the relays that perform network discovery for a site. This replaces the gateway record rather than merging into it, so an omitted field is cleared, and a wrong value can stop discovery for that site with no alert. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_update_gateways details
s1_update_gateways details
[SentinelOne] DESTRUCTIVE — Update Gateways. This updates MULTIPLE Ranger gateways in one call. Gateways are the relays that perform network discovery, so a bad payload can stop discovery across several sites at once, with no alert. Read s1_get_gateways first. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_update_provision_update_mssp_partner_key details
s1_update_provision_update_mssp_partner_key details
[SentinelOne] DESTRUCTIVE — Provision - Update MSSP partner key. This rotates the MSSP partner credential. Every client still authenticating with the old key stops working the moment this lands, so have the replacement distribution ready before you call it. Treat the response as a secret. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_update_resync_vcs_integration_repositories details
s1_update_resync_vcs_integration_repositories details
[SentinelOne] DESTRUCTIVE — Resync VCS Integration Repositories. A resync re-reads the repository list from the provider and reconciles it, so repositories removed upstream stop being scanned and newly visible ones start. Expect scanning load right after this lands. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. SentinelOne requires scopeType and scopeIds on this endpoint — pass them in filtersJson or the call fails with a 400. scopeType: the scope type this call resolves against. scopeIds: the ids of the scopes it applies to. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_update_vcs_cicd_scanner_policy details
s1_update_vcs_cicd_scanner_policy details
[SentinelOne] DESTRUCTIVE — Update a VCS and CICD scanner policy. This replaces the scanner policy rather than merging into it, so an omitted field is cleared. The policy decides which findings break a build, so both directions have consequences. Read s1_get_vcs_cicd_scanner_policy and edit that payload. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. SentinelOne requires scopeType and scopeIds on this endpoint — pass them in filtersJson or the call fails with a 400. scopeType: the scope type this call resolves against. scopeIds: the ids of the scopes it applies to. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_update_vcs_integration details
s1_update_vcs_integration details
[SentinelOne] DESTRUCTIVE — Update a VCS integration. This replaces the integration record rather than merging into it, so an omitted field is cleared. Read s1_list_vcs_integrations and edit that payload. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. SentinelOne requires scopeType and scopeIds on this endpoint — pass them in filtersJson or the call fails with a 400. scopeType: the scope type this call resolves against. scopeIds: the ids of the scopes it applies to. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_validate_bucket details
s1_validate_bucket details
[SentinelOne] Validate Bucket. This is a POST that READS: the criteria travel in the request body, and nothing is created or changed. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_validate_query details
s1_validate_query details
[SentinelOne] Validate Query. This is a POST that READS: the criteria travel in the request body, and nothing is created or changed. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
Marketplace
s1_delete_application details
s1_delete_application details
[SentinelOne] DESTRUCTIVE — Delete Application. This uninstalls the application AND discards its configuration. Re-installing means configuring it from scratch, and anything downstream that consumed its output stops receiving data immediately. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_enable_disable_application details
s1_enable_disable_application details
[SentinelOne] DESTRUCTIVE — Enable Or Disable Application. Disabling stops the integration immediately, so anything downstream that depends on it — a SIEM feed, a ticket sync — stops receiving data with nothing else raising an alarm. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_application_log details
s1_get_application_log details
[SentinelOne] Get application log. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the activity log of one installed marketplace application — the first place to look when an integration has stopped delivering data. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_applications_catalog details
s1_get_applications_catalog details
[SentinelOne] Get Applications Catalog. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the marketplace catalog — what is available to install. Use s1_get_installed_applications for what is already in this console. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_configuration_fields details
s1_get_configuration_fields details
[SentinelOne] Get Configuration Fields. Returns the configuration fields a CATALOG application will ask for, before you install it. This is the read that shows what permissions and settings an install will require. For an already-installed app use s1_get_configuration_fields_installed_application. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_configuration_fields_installed_application details
s1_get_configuration_fields_installed_application details
[SentinelOne] Get Configuration Fields For Installed Application. Returns the configuration fields of an ALREADY-INSTALLED application, with its current values. Read this before s1_update_application_configuration, which replaces the whole object. For a catalog entry use s1_get_configuration_fields. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_installed_applications details
s1_get_installed_applications details
[SentinelOne] Get Installed Applications. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the marketplace applications INSTALLED in this console, with their state. Use s1_get_applications_catalog for what is available to install. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_install_applications details
s1_install_applications details
[SentinelOne] DESTRUCTIVE — Install Applications. An installed marketplace application runs with the console permissions its manifest requests and can read and act on console data. Read those permissions with s1_get_configuration_fields for the catalog entry before you install it. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_update_application_configuration details
s1_update_application_configuration details
[SentinelOne] DESTRUCTIVE — Update Application Configuration. This replaces the application configuration rather than merging into it, so an omitted field is cleared. Read s1_get_configuration_fields_installed_application and edit that payload; a cleared credential field silently breaks the integration. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
PowerQuery
s1_create_update_saved_searches details
s1_create_update_saved_searches details
[SentinelOne] Create or update saved searches. Part of SentinelOne's PowerQuery lane, which is asynchronous: launch, then poll until the query completes. Creates or updates a saved PowerQuery search. Not marked destructive because a saved search is a stored query with no operational consequence — but saved searches are SHARED within the scope, so an update overwrites what colleagues were using. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_delete_query details
s1_delete_query details
[SentinelOne] DESTRUCTIVE — Delete query. This CANCELS the running query and discards its results. A long-running query loses whatever it had already produced, and the data-lake time it spent is not refunded. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Pass any other documented query parameter as a flat JSON object in filtersJson. Part of SentinelOne's PowerQuery lane, which is asynchronous: launch, then poll until the query completes. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_delete_saved_searches details
s1_delete_saved_searches details
[SentinelOne] DESTRUCTIVE — Delete saved searches. Saved searches are shared within the scope, so this deletes them for everyone who was using them, not just for you. There is no undo. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Part of SentinelOne's PowerQuery lane, which is asynchronous: launch, then poll until the query completes. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_poll_query details
s1_get_poll_query details
[SentinelOne] Poll query. SentinelOne requires lastStepSeen on this endpoint — pass it in filtersJson or the call fails with a 400. lastStepSeen: the step number to resume the result from. Pass any other documented query parameter as a flat JSON object in filtersJson. Part of SentinelOne's PowerQuery lane, which is asynchronous: launch, then poll until the query completes. Poll a query launched by s1_launch_query until it reports complete. The forwardTag argument is the `_forwardTag` value from that launch response — the call is rejected without it, and there is no way to recover the value once the launch response is discarded. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_launch_query details
s1_launch_query details
[SentinelOne] Launch a query. This is a POST that READS: the criteria travel in the request body, and nothing is created or changed. Part of SentinelOne's PowerQuery lane, which is asynchronous: launch, then poll until the query completes. START HERE for PowerQuery. The response carries `_forwardTag`, a value StackJack lifts out of a response HEADER and folds into the body because SentinelOne returns it no other way. Keep it: s1_get_poll_query and s1_delete_query both REQUIRE it and are rejected without it. Note also that PowerQuery is rate-limited to about 3 requests per second against the identity in the token. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_list_saved_searches details
s1_list_saved_searches details
[SentinelOne] List saved searches. Pass any other documented query parameter as a flat JSON object in filtersJson. Part of SentinelOne's PowerQuery lane, which is asynchronous: launch, then poll until the query completes. Returns the saved PowerQuery searches for the scope. Saved searches are shared, so what you see here other people in the scope can see and delete too. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
Remote Forensics
s1_check_if_collection_file_exists_given_storyline details
s1_check_if_collection_file_exists_given_storyline details
[SentinelOne] Check if collection file exists for given storyline. SentinelOne requires storyline and agentId on this endpoint — pass them in filtersJson or the call fails with a 400. storyline: the storyline id. agentId: the agent id. Pass any other documented query parameter as a flat JSON object in filtersJson. Checks whether a collection file already exists for a storyline, without collecting anything. Run it before s1_start_forensics_collection to avoid re-running a collection that already happened. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_create_new_collection_profile details
s1_create_new_collection_profile details
[SentinelOne] Create new Collection profile. Creates a forensics collection profile, which decides which artifact types a collection gathers. Additive: it collects nothing by itself until a collection or scheduled task names it. Check s1_get_list_supported_artifact_types for the vocabulary. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_create_new_destination_profile details
s1_create_new_destination_profile details
[SentinelOne] Create new Destination profile. Creates a destination profile — where collected forensic data will be EXPORTED to. Additive: nothing is exported until a task names this profile or it is made the scope default. Confirm the destination belongs to the customer, because data sent through it leaves the SentinelOne tenant. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_delete_collection_profiles details
s1_delete_collection_profiles details
[SentinelOne] DESTRUCTIVE — Delete Collection profiles. Deleting a collection profile breaks every scheduled task that names it, and those tasks fail rather than falling back to a default. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_delete_destination_profile_id details
s1_delete_destination_profile_id details
[SentinelOne] DESTRUCTIVE — Delete Destination profile by ID. Deleting a destination profile breaks every scheduled task that exports through it, and the exports simply stop — read s1_get_available_scheduled_tasks first to see what depends on it. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_delete_multiple_destination_profiles_id details
s1_delete_multiple_destination_profiles_id details
[SentinelOne] DESTRUCTIVE — Delete multiple Destination profiles by ID. This deletes SEVERAL destination profiles at once, breaking every scheduled task that exports through any of them. Read s1_get_available_scheduled_tasks first to see what depends on them. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_delete_multiple_scheduled_tasks_id details
s1_delete_multiple_scheduled_tasks_id details
[SentinelOne] DESTRUCTIVE — Delete multiple scheduled tasks by ID. This cancels the future runs of several scheduled tasks at once. Nothing raises an alarm afterwards for a collection that was supposed to happen and did not. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_available_destination_profiles details
s1_get_available_destination_profiles details
[SentinelOne] Get available Destination profiles. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the destination profiles for the scope — where collected forensic data is EXPORTED to. Read this before assuming forensic output stays inside the SentinelOne tenant. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_available_scheduled_tasks details
s1_get_available_scheduled_tasks details
[SentinelOne] Get available Scheduled Tasks. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the scheduled forensics and remote-script tasks for the scope: automation that will run with nobody watching. Read it before deleting any profile or script, because these tasks fail rather than fall back when their dependency disappears. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_collection_profile_id details
s1_get_collection_profile_id details
[SentinelOne] Get Collection profile by ID. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_destination_profile_id details
s1_get_destination_profile_id details
[SentinelOne] Get Destination profile by ID. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_forensics_collection_file_url details
s1_get_forensics_collection_file_url details
[SentinelOne] Returns collection file download pre-signed url. SentinelOne requires siteId, agentId, signature, signatureType and uploadedTimestamp on this endpoint — pass them in filtersJson or the call fails with a 400. siteId: the site id. agentId: the agent id. signature: the collected file's signature. signatureType: the type of that signature. uploadedTimestamp: the timestamp SentinelOne recorded for the upload. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns a short-lived pre-signed download URL for a collected forensics file. The URL is the artifact, not the file: fetch it promptly, and treat it as sensitive because it grants access without further authentication. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_list_available_collection_profiles details
s1_get_list_available_collection_profiles details
[SentinelOne] Get list of available Collection profiles. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the collection profiles for the scope — each one decides which artifact types a forensics collection gathers. Profile ids for s1_start_forensics_collection come from here. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_list_supported_artifact_types details
s1_get_list_supported_artifact_types details
[SentinelOne] Get list of supported artifact types. Returns the artifact types a collection profile may gather. Read it before composing a profile — an unsupported type is a 400, not an ignored field. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_results_sent_data_exporter details
s1_get_results_sent_data_exporter details
[SentinelOne] Get results sent to data exporter. SentinelOne requires agentId on this endpoint — pass it in filtersJson or the call fails with a 400. agentId: the agent id. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns what the data exporter has actually sent through the destination profiles — the audit trail of forensic data leaving the tenant. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_return_result_collection_task details
s1_get_return_result_collection_task details
[SentinelOne] Return result of collection task. SentinelOne requires taskId on this endpoint — pass it in filtersJson or the call fails with a 400. taskId: the task id. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the result metadata of a forensics collection task. Use s1_get_forensics_collection_file_url to get a download link for the collected file itself. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_schedule_forensics_future_run details
s1_schedule_forensics_future_run details
[SentinelOne] DESTRUCTIVE — Schedule forensics for future run. This SCHEDULES a forensics collection, so it fires later with nobody watching. Everything true of running one now — endpoint CPU and disk cost, large uploads — is true then, against whatever machines match the scope at that time rather than the ones matching it today. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_schedule_remote_script_future_run details
s1_schedule_remote_script_future_run details
[SentinelOne] DESTRUCTIVE — Schedule remote script for future run. This SCHEDULES a remote script execution, so you are approving now a code execution that will run on live endpoints at a time you will not be watching, against whatever machines match the scope then. Read the script with s1_get_script_content before you schedule it. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_set_profile_default_profile_scope details
s1_set_profile_default_profile_scope details
[SentinelOne] DESTRUCTIVE — Set profile as default profile of the scope. This makes the profile the DEFAULT export destination for the whole scope, so tasks that named no profile start exporting here — including tasks somebody else created. Confirm the destination belongs to the customer. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_start_forensics_collection details
s1_start_forensics_collection details
[SentinelOne] DESTRUCTIVE — Start collection of Forensics artifacts according to specified profile. This runs a live forensics collection on the endpoints you target. It consumes endpoint CPU and disk while it runs, and it uploads artifacts that can be very large. Scope it tightly — a broad collection across a site is a noticeable performance event for the people using those machines. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_update_collection_profile_id details
s1_update_collection_profile_id details
[SentinelOne] DESTRUCTIVE — Update Collection profile by ID. This replaces the collection profile rather than merging into it, so an omitted field is cleared. Every scheduled task using this profile changes what it gathers from the next run onward. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_update_existing_destination_profile details
s1_update_existing_destination_profile details
[SentinelOne] DESTRUCTIVE — Update existing Destination profile. This replaces the destination profile rather than merging into it, so an omitted field is cleared. Changing the destination redirects where forensic data is exported — confirm the new destination belongs to the customer. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_update_existing_scheduled_task details
s1_update_existing_scheduled_task details
[SentinelOne] DESTRUCTIVE — Update existing Scheduled task. This replaces the scheduled task rather than merging into it, so an omitted field is cleared. Both the schedule and the scope can move, so read s1_get_available_scheduled_tasks and edit that payload. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
Remote Scripts
s1_approve_decline_pending_execution details
s1_approve_decline_pending_execution details
[SentinelOne] DESTRUCTIVE — Approve/decline pending execution. Approving RELEASES a held script execution to the endpoints immediately — you are the guardrail this queue exists to provide. Read the pending execution with s1_get_paginated_pending_executions and the script body with s1_get_script_content before you approve it. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_check_whether_guardrail_applies_execution details
s1_check_whether_guardrail_applies_execution details
[SentinelOne] Check whether guardrail applies to an execution. This is a POST that READS: the criteria travel in the request body, and nothing is created or changed. Checks whether a guardrail would block a proposed execution, WITHOUT running it. This is the safe pre-flight for s1_run_remote_script. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_delete_remote_script_guardrails_config details
s1_delete_remote_script_guardrails_config details
[SentinelOne] DESTRUCTIVE — Deletes a specific guardrails configuration. Guardrails are what stop a remote script from doing something the console forbids. DELETING the configuration removes that limit for the scope, so every later script execution there is permitted to do more than it could a moment ago. This is a privilege-widening change and nothing in the console flags it afterwards. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_delete_scripts details
s1_delete_scripts details
[SentinelOne] DESTRUCTIVE — Delete Scripts. Deleting a script breaks every scheduled task and workflow that calls it, and those fail rather than skipping. Read s1_get_available_scheduled_tasks before you delete one. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_paginated_pending_executions details
s1_get_paginated_pending_executions details
[SentinelOne] Get paginated pending executions. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns script executions waiting on approval. Each one is code held back from live endpoints until somebody releases it with s1_approve_decline_pending_execution — read the script content before you approve. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_remote_script_guardrails_config details
s1_get_remote_script_guardrails_config details
[SentinelOne] Gets a guardrails configuration for a given scope. SentinelOne requires scopeId and scopeLevel on this endpoint — pass them in filtersJson or the call fails with a 400. scopeId: the scope id. scopeLevel: scope level, one of 'account', 'site' or 'group'. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the guardrails configuration for the scope — the limits on what a remote script is permitted to do. Read it before changing it: loosening or deleting a guardrail widens what every later execution in that scope may do. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_remote_scripts_tasks_status details
s1_get_remote_scripts_tasks_status details
[SentinelOne] Get Remote Scripts Tasks Status. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the status of dispatched remote-script tasks — what ran, on which endpoints, and how it ended. A script dispatch answers 200 immediately, so this is where you find out whether it actually worked. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_script_content details
s1_get_script_content details
[SentinelOne] Get script content. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the CODE of a remote script. Read it before s1_run_remote_script or before approving a pending execution: this is the only place the thing you are about to run on customer endpoints is visible. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_script_results details
s1_get_script_results details
[SentinelOne] Get Script Results. This is a POST that READS: the criteria travel in the request body, and nothing is created or changed. Returns download URLs for the OUTPUT of scripts that already ran. It fetches stored results and dispatches nothing to endpoints, which is why it is a read despite its POST verb and its fetch-files path. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_scripts details
s1_get_scripts details
[SentinelOne] Get Scripts. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the remote-script library for the scope. Script ids for s1_run_remote_script come from here. This lists metadata only — read the actual code with s1_get_script_content before running anything. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_upload_limit_package details
s1_get_upload_limit_package details
[SentinelOne] Get upload limit for Package. Returns the size limit for a script package upload. Read it before s1_upload_new_script if the package is large. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_run_remote_script details
s1_run_remote_script details
[SentinelOne] DESTRUCTIVE — Run Remote Script. This RUNS CODE on live customer endpoints. It executes with the agent's privileges, it cannot be recalled once dispatched, and it acts on every endpoint matching the filter in the body — an over-broad or empty filter reaches the whole fleet and SentinelOne answers 200 either way. Run the matching agent read with countOnly=true first to see the blast radius, and read the script with s1_get_script_content so you know what you are about to run. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_update_script details
s1_update_script details
[SentinelOne] DESTRUCTIVE — Update a Script. This replaces the stored script, so every later execution — including already-scheduled ones — runs the NEW content. Review it: the approval somebody gave the old version does not carry over. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_update_script_remote_scripts details
s1_update_script_remote_scripts details
[SentinelOne] DESTRUCTIVE — Update a Script. This replaces the stored script, so every later execution — including already-scheduled ones — runs the NEW content. Review it: the approval somebody gave the old version does not carry over. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_upload_new_script details
s1_upload_new_script details
[SentinelOne] DESTRUCTIVE — Upload New Script. Whatever you upload here becomes runnable on customer endpoints by anyone holding script permissions. Review the content — this is the supply side of remote code execution, and the review has to happen now rather than at run time. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_upsert_remote_script_guardrails_config details
s1_upsert_remote_script_guardrails_config details
[SentinelOne] DESTRUCTIVE — Updates or inserts (if record does not exist) a guardrails configuration. Guardrails are what stop a remote script from doing something the console forbids. Rewriting the configuration WIDENS or narrows what every later script execution in that scope may do — this is a privilege change, not a settings tweak. It also replaces the whole configuration rather than merging, so an omitted field is cleared. Read s1_get_remote_script_guardrails_config and edit that payload. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
Account
s1_count_account_asset_filters details
s1_count_account_asset_filters details
[SentinelOne] Returns the number of Account assets behind each filter value — the counts the console shows beside each facet. Use it to size a filter before you act on what it matches. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_export_account_assets details
s1_export_account_assets details
[SentinelOne] Exports the Account asset class as JSON. StackJack always sends exportFormat=json. SentinelOne REQUIRES that parameter and also offers CSV, but a CSV body is not JSON and this tool could not parse it — so the format is pinned here and filtersJson cannot override it. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_account_asset_filter_values details
s1_get_account_asset_filter_values details
[SentinelOne] Returns matching values for one Account asset filter field — the type-ahead behind the console's filter box. Use it to discover the exact values a filter accepts before passing them to s1_list_account_assets; SentinelOne rejects an unknown filter value with a 400 rather than ignoring it. Scope to one customer with siteIds / accountIds / groupIds. SentinelOne requires text and key on this endpoint — pass them in filtersJson or the call fails with a 400. text: the search text to match. key: the search field key, one of the documented `<field>__contains` names. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_account_asset_text_filters details
s1_get_account_asset_text_filters details
[SentinelOne] Lists the Account asset fields that a free-text search covers. Read it to learn which fields a free-text query will and will not match before you rely on one. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_list_account_asset_actions details
s1_list_account_asset_actions details
[SentinelOne] Lists the inventory actions available for Account assets, with each action's current status. This is a POST that READS: the selection travels in the request body and nothing is changed. Call it before s1_run_account_asset_action to learn which action names that tool accepts. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_list_account_assets details
s1_list_account_assets details
[SentinelOne] Lists the Account asset class of the asset inventory. SentinelOne splits its inventory into 20 asset classes and this tool returns ONLY Account assets — use s1_list_assets when you want every class at once. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_run_account_asset_action details
s1_run_account_asset_action details
[SentinelOne] DESTRUCTIVE — runs an inventory action against the Account assets your request body selects. The body carries a FILTER, so the action reaches everything that matches it, and an empty filter matches the whole class. Run s1_list_account_assets with countOnly=true and the SAME filter first, and read the count before you send this. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_search_account_assets details
s1_search_account_assets details
[SentinelOne] Searches the Account asset class of the asset inventory using the filter criteria in the request body. This is a POST that READS — the vendor documents it as "POST API to get Assets", and it exists only because the inventory filter set is far too large for a query string. Nothing is created or changed. It is the body-filter twin of s1_list_account_assets. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
AI ML
s1_count_ai_ml_asset_filters details
s1_count_ai_ml_asset_filters details
[SentinelOne] Returns the number of AI/ML assets behind each filter value — the counts the console shows beside each facet. Use it to size a filter before you act on what it matches. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_export_ai_ml_assets details
s1_export_ai_ml_assets details
[SentinelOne] Exports the AI/ML asset class as JSON. StackJack always sends exportFormat=json. SentinelOne REQUIRES that parameter and also offers CSV, but a CSV body is not JSON and this tool could not parse it — so the format is pinned here and filtersJson cannot override it. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_ai_ml_asset_filter_values details
s1_get_ai_ml_asset_filter_values details
[SentinelOne] Returns matching values for one AI/ML asset filter field — the type-ahead behind the console's filter box. Use it to discover the exact values a filter accepts before passing them to s1_list_ai_ml_assets; SentinelOne rejects an unknown filter value with a 400 rather than ignoring it. Scope to one customer with siteIds / accountIds / groupIds. SentinelOne requires text and key on this endpoint — pass them in filtersJson or the call fails with a 400. text: the search text to match. key: the search field key, one of the documented `<field>__contains` names. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_ai_ml_asset_text_filters details
s1_get_ai_ml_asset_text_filters details
[SentinelOne] Lists the AI/ML asset fields that a free-text search covers. Read it to learn which fields a free-text query will and will not match before you rely on one. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_list_ai_ml_asset_actions details
s1_list_ai_ml_asset_actions details
[SentinelOne] Lists the inventory actions available for AI/ML assets, with each action's current status. This is a POST that READS: the selection travels in the request body and nothing is changed. Call it before s1_run_ai_ml_asset_action to learn which action names that tool accepts. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_list_ai_ml_assets details
s1_list_ai_ml_assets details
[SentinelOne] Lists the AI/ML asset class of the asset inventory. SentinelOne splits its inventory into 20 asset classes and this tool returns ONLY AI/ML assets — use s1_list_assets when you want every class at once. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_run_ai_ml_asset_action details
s1_run_ai_ml_asset_action details
[SentinelOne] DESTRUCTIVE — runs an inventory action against the AI/ML assets your request body selects. The body carries a FILTER, so the action reaches everything that matches it, and an empty filter matches the whole class. Run s1_list_ai_ml_assets with countOnly=true and the SAME filter first, and read the count before you send this. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_search_ai_ml_assets details
s1_search_ai_ml_assets details
[SentinelOne] Searches the AI/ML asset class of the asset inventory using the filter criteria in the request body. This is a POST that READS — the vendor documents it as "POST API to get Assets", and it exists only because the inventory filter set is far too large for a query string. Nothing is created or changed. It is the body-filter twin of s1_list_ai_ml_assets. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
Application Integration
s1_count_application_integration_asset_filters details
s1_count_application_integration_asset_filters details
[SentinelOne] Returns the number of Application Integration assets behind each filter value — the counts the console shows beside each facet. Use it to size a filter before you act on what it matches. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_export_application_integration_assets details
s1_export_application_integration_assets details
[SentinelOne] Exports the Application Integration asset class as JSON. StackJack always sends exportFormat=json. SentinelOne REQUIRES that parameter and also offers CSV, but a CSV body is not JSON and this tool could not parse it — so the format is pinned here and filtersJson cannot override it. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_application_integration_asset_filter_values details
s1_get_application_integration_asset_filter_values details
[SentinelOne] Returns matching values for one Application Integration asset filter field — the type-ahead behind the console's filter box. Use it to discover the exact values a filter accepts before passing them to s1_list_application_integration_assets; SentinelOne rejects an unknown filter value with a 400 rather than ignoring it. Scope to one customer with siteIds / accountIds / groupIds. SentinelOne requires text and key on this endpoint — pass them in filtersJson or the call fails with a 400. text: the search text to match. key: the search field key, one of the documented `<field>__contains` names. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_application_integration_asset_text_filters details
s1_get_application_integration_asset_text_filters details
[SentinelOne] Lists the Application Integration asset fields that a free-text search covers. Read it to learn which fields a free-text query will and will not match before you rely on one. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_list_application_integration_asset_actions details
s1_list_application_integration_asset_actions details
[SentinelOne] Lists the inventory actions available for Application Integration assets, with each action's current status. This is a POST that READS: the selection travels in the request body and nothing is changed. Call it before s1_run_application_integration_asset_action to learn which action names that tool accepts. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_list_application_integration_assets details
s1_list_application_integration_assets details
[SentinelOne] Lists the Application Integration asset class of the asset inventory. SentinelOne splits its inventory into 20 asset classes and this tool returns ONLY Application Integration assets — use s1_list_assets when you want every class at once. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_run_application_integration_asset_action details
s1_run_application_integration_asset_action details
[SentinelOne] DESTRUCTIVE — runs an inventory action against the Application Integration assets your request body selects. The body carries a FILTER, so the action reaches everything that matches it, and an empty filter matches the whole class. Run s1_list_application_integration_assets with countOnly=true and the SAME filter first, and read the count before you send this. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_search_application_integration_assets details
s1_search_application_integration_assets details
[SentinelOne] Searches the Application Integration asset class of the asset inventory using the filter criteria in the request body. This is a POST that READS — the vendor documents it as "POST API to get Assets", and it exists only because the inventory filter set is far too large for a query string. Nothing is created or changed. It is the body-filter twin of s1_list_application_integration_assets. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
Asset Inventory
s1_export_asset_cloud_tags details
s1_export_asset_cloud_tags details
[SentinelOne] Exports the cloud provider tags attached to inventory assets as JSON. These are the tags that came from AWS, Azure or GCP, not the SentinelOne tags that s1_list_asset_tags returns. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_export_assets details
s1_export_assets details
[SentinelOne] Exports assets across every inventory class as JSON. StackJack always sends exportFormat=json. SentinelOne REQUIRES that parameter and also offers CSV, but a CSV body is not JSON and this tool could not parse it — so the format is pinned here and filtersJson cannot override it. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_asset_category_counts details
s1_get_asset_category_counts details
[SentinelOne] Returns the asset inventory categories and the number of assets in each. A category is the top level of the inventory tree; s1_get_asset_subcategory_counts breaks each one down further. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_asset_inventory_counts details
s1_get_asset_inventory_counts details
[SentinelOne] Returns the asset counts behind each inventory menu item — the numbers the console shows next to each asset class. Use it to see where a customer's assets actually are before you start querying individual classes. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_asset_subcategory_counts details
s1_get_asset_subcategory_counts details
[SentinelOne] Returns the per-subcategory asset counts within the inventory categories. Use it after s1_get_asset_category_counts to narrow down where a customer's assets sit. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_list_any_asset_actions details
s1_list_any_asset_actions details
[SentinelOne] Lists the inventory actions available for the assets your request body selects, across every asset class, with each action's current status. This is a POST that READS: the selection travels in the body and nothing is changed. Call it before s1_run_any_asset_action to learn which action names that tool accepts. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_list_assets details
s1_list_assets details
[SentinelOne] Lists assets across EVERY class of the asset inventory. SentinelOne splits its inventory into 20 asset classes — servers, workstations, devices, identities, containers, cloud accounts and more — and this is the all-classes view. Filter with the category and resourceType parameters, or call the per-class tool (for example s1_list_device_assets) when you already know the class. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_run_any_asset_action details
s1_run_any_asset_action details
[SentinelOne] DESTRUCTIVE — runs an inventory action against assets in ANY class, selected by the filter in the request body. This is the BROADEST action tool in the inventory: it is not scoped to one asset class, so a loose or empty filter can reach servers, workstations, identities and cloud resources in a single call. Run s1_list_assets with countOnly=true and the SAME filter first, and read the count before you send this. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_search_assets details
s1_search_assets details
[SentinelOne] Searches assets across EVERY class of the asset inventory using the filter criteria in the request body. This is a POST that READS — the vendor documents it as "POST API to get assets", and it exists only because the inventory filter set is far too large for a query string. Nothing is created or changed. It is the body-filter twin of s1_list_assets. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
Cloud Application
s1_count_cloud_application_asset_filters details
s1_count_cloud_application_asset_filters details
[SentinelOne] Returns the number of Cloud Application assets behind each filter value — the counts the console shows beside each facet. Use it to size a filter before you act on what it matches. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_export_cloud_application_assets details
s1_export_cloud_application_assets details
[SentinelOne] Exports the Cloud Application asset class as JSON. StackJack always sends exportFormat=json. SentinelOne REQUIRES that parameter and also offers CSV, but a CSV body is not JSON and this tool could not parse it — so the format is pinned here and filtersJson cannot override it. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_cloud_application_asset_filter_values details
s1_get_cloud_application_asset_filter_values details
[SentinelOne] Returns matching values for one Cloud Application asset filter field — the type-ahead behind the console's filter box. Use it to discover the exact values a filter accepts before passing them to s1_list_cloud_application_assets; SentinelOne rejects an unknown filter value with a 400 rather than ignoring it. Scope to one customer with siteIds / accountIds / groupIds. SentinelOne requires text and key on this endpoint — pass them in filtersJson or the call fails with a 400. text: the search text to match. key: the search field key, one of the documented `<field>__contains` names. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_cloud_application_asset_text_filters details
s1_get_cloud_application_asset_text_filters details
[SentinelOne] Lists the Cloud Application asset fields that a free-text search covers. Read it to learn which fields a free-text query will and will not match before you rely on one. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_list_cloud_application_asset_actions details
s1_list_cloud_application_asset_actions details
[SentinelOne] Lists the inventory actions available for Cloud Application assets, with each action's current status. This is a POST that READS: the selection travels in the request body and nothing is changed. Call it before s1_run_cloud_application_asset_action to learn which action names that tool accepts. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_list_cloud_application_assets details
s1_list_cloud_application_assets details
[SentinelOne] Lists the Cloud Application asset class of the asset inventory. SentinelOne splits its inventory into 20 asset classes and this tool returns ONLY Cloud Application assets — use s1_list_assets when you want every class at once. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_run_cloud_application_asset_action details
s1_run_cloud_application_asset_action details
[SentinelOne] DESTRUCTIVE — runs an inventory action against the Cloud Application assets your request body selects. The body carries a FILTER, so the action reaches everything that matches it, and an empty filter matches the whole class. Run s1_list_cloud_application_assets with countOnly=true and the SAME filter first, and read the count before you send this. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_search_cloud_application_assets details
s1_search_cloud_application_assets details
[SentinelOne] Searches the Cloud Application asset class of the asset inventory using the filter criteria in the request body. This is a POST that READS — the vendor documents it as "POST API to get Assets", and it exists only because the inventory filter set is far too large for a query string. Nothing is created or changed. It is the body-filter twin of s1_list_cloud_application_assets. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
Cloud Surface
s1_count_cloud_surface_asset_filters details
s1_count_cloud_surface_asset_filters details
[SentinelOne] Returns the number of Cloud Surface assets behind each filter value — the counts the console shows beside each facet. Use it to size a filter before you act on what it matches. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_export_cloud_surface_assets details
s1_export_cloud_surface_assets details
[SentinelOne] Exports the Cloud Surface asset class as JSON. StackJack always sends exportFormat=json. SentinelOne REQUIRES that parameter and also offers CSV, but a CSV body is not JSON and this tool could not parse it — so the format is pinned here and filtersJson cannot override it. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_cloud_surface_asset_filter_values details
s1_get_cloud_surface_asset_filter_values details
[SentinelOne] Returns matching values for one Cloud Surface asset filter field — the type-ahead behind the console's filter box. Use it to discover the exact values a filter accepts before passing them to s1_list_cloud_surface_assets; SentinelOne rejects an unknown filter value with a 400 rather than ignoring it. Scope to one customer with siteIds / accountIds / groupIds. SentinelOne requires key and text on this endpoint — pass them in filtersJson or the call fails with a 400. key: the search field key, one of the documented `<field>__contains` names. text: the search text to match. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_cloud_surface_asset_text_filters details
s1_get_cloud_surface_asset_text_filters details
[SentinelOne] Lists the Cloud Surface asset fields that a free-text search covers. Read it to learn which fields a free-text query will and will not match before you rely on one. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_list_cloud_surface_asset_actions details
s1_list_cloud_surface_asset_actions details
[SentinelOne] Lists the inventory actions available for Cloud Surface assets, with each action's current status. This is a POST that READS: the selection travels in the request body and nothing is changed. Call it before s1_run_cloud_surface_asset_action to learn which action names that tool accepts. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_list_cloud_surface_assets details
s1_list_cloud_surface_assets details
[SentinelOne] Lists the Cloud Surface asset class of the asset inventory. SentinelOne splits its inventory into 20 asset classes and this tool returns ONLY Cloud Surface assets — use s1_list_assets when you want every class at once. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_run_cloud_surface_asset_action details
s1_run_cloud_surface_asset_action details
[SentinelOne] DESTRUCTIVE — runs an inventory action against the Cloud Surface assets your request body selects. The body carries a FILTER, so the action reaches everything that matches it, and an empty filter matches the whole class. Run s1_list_cloud_surface_assets with countOnly=true and the SAME filter first, and read the count before you send this. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
Container
s1_count_container_asset_filters details
s1_count_container_asset_filters details
[SentinelOne] Returns the number of Container assets behind each filter value — the counts the console shows beside each facet. Use it to size a filter before you act on what it matches. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_export_container_assets details
s1_export_container_assets details
[SentinelOne] Exports the Container asset class as JSON. StackJack always sends exportFormat=json. SentinelOne REQUIRES that parameter and also offers CSV, but a CSV body is not JSON and this tool could not parse it — so the format is pinned here and filtersJson cannot override it. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_container_asset_filter_values details
s1_get_container_asset_filter_values details
[SentinelOne] Returns matching values for one Container asset filter field — the type-ahead behind the console's filter box. Use it to discover the exact values a filter accepts before passing them to s1_list_container_assets; SentinelOne rejects an unknown filter value with a 400 rather than ignoring it. Scope to one customer with siteIds / accountIds / groupIds. SentinelOne requires key and text on this endpoint — pass them in filtersJson or the call fails with a 400. key: the search field key, one of the documented `<field>__contains` names. text: the search text to match. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_container_asset_text_filters details
s1_get_container_asset_text_filters details
[SentinelOne] Lists the Container asset fields that a free-text search covers. Read it to learn which fields a free-text query will and will not match before you rely on one. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_list_container_asset_actions details
s1_list_container_asset_actions details
[SentinelOne] Lists the inventory actions available for Container assets, with each action's current status. This is a POST that READS: the selection travels in the request body and nothing is changed. Call it before s1_run_container_asset_action to learn which action names that tool accepts. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_list_container_assets details
s1_list_container_assets details
[SentinelOne] Lists the Container asset class of the asset inventory. SentinelOne splits its inventory into 20 asset classes and this tool returns ONLY Container assets — use s1_list_assets when you want every class at once. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_run_container_asset_action details
s1_run_container_asset_action details
[SentinelOne] DESTRUCTIVE — runs an inventory action against the Container assets your request body selects. The body carries a FILTER, so the action reaches everything that matches it, and an empty filter matches the whole class. Run s1_list_container_assets with countOnly=true and the SAME filter first, and read the count before you send this. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_search_container_assets details
s1_search_container_assets details
[SentinelOne] Searches the Container asset class of the asset inventory using the filter criteria in the request body. This is a POST that READS — the vendor documents it as "POST API to get Assets", and it exists only because the inventory filter set is far too large for a query string. Nothing is created or changed. It is the body-filter twin of s1_list_container_assets. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
Data Analysis
s1_count_data_analysis_asset_filters details
s1_count_data_analysis_asset_filters details
[SentinelOne] Returns the number of Data Analysis assets behind each filter value — the counts the console shows beside each facet. Use it to size a filter before you act on what it matches. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_export_data_analysis_assets details
s1_export_data_analysis_assets details
[SentinelOne] Exports the Data Analysis asset class as JSON. StackJack always sends exportFormat=json. SentinelOne REQUIRES that parameter and also offers CSV, but a CSV body is not JSON and this tool could not parse it — so the format is pinned here and filtersJson cannot override it. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_data_analysis_asset_filter_values details
s1_get_data_analysis_asset_filter_values details
[SentinelOne] Returns matching values for one Data Analysis asset filter field — the type-ahead behind the console's filter box. Use it to discover the exact values a filter accepts before passing them to s1_list_data_analysis_assets; SentinelOne rejects an unknown filter value with a 400 rather than ignoring it. Scope to one customer with siteIds / accountIds / groupIds. SentinelOne requires text and key on this endpoint — pass them in filtersJson or the call fails with a 400. text: the search text to match. key: the search field key, one of the documented `<field>__contains` names. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_data_analysis_asset_text_filters details
s1_get_data_analysis_asset_text_filters details
[SentinelOne] Lists the Data Analysis asset fields that a free-text search covers. Read it to learn which fields a free-text query will and will not match before you rely on one. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_list_data_analysis_asset_actions details
s1_list_data_analysis_asset_actions details
[SentinelOne] Lists the inventory actions available for Data Analysis assets, with each action's current status. This is a POST that READS: the selection travels in the request body and nothing is changed. Call it before s1_run_data_analysis_asset_action to learn which action names that tool accepts. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_list_data_analysis_assets details
s1_list_data_analysis_assets details
[SentinelOne] Lists the Data Analysis asset class of the asset inventory. SentinelOne splits its inventory into 20 asset classes and this tool returns ONLY Data Analysis assets — use s1_list_assets when you want every class at once. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_run_data_analysis_asset_action details
s1_run_data_analysis_asset_action details
[SentinelOne] DESTRUCTIVE — runs an inventory action against the Data Analysis assets your request body selects. The body carries a FILTER, so the action reaches everything that matches it, and an empty filter matches the whole class. Run s1_list_data_analysis_assets with countOnly=true and the SAME filter first, and read the count before you send this. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_search_data_analysis_assets details
s1_search_data_analysis_assets details
[SentinelOne] Searches the Data Analysis asset class of the asset inventory using the filter criteria in the request body. This is a POST that READS — the vendor documents it as "POST API to get Assets", and it exists only because the inventory filter set is far too large for a query string. Nothing is created or changed. It is the body-filter twin of s1_list_data_analysis_assets. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
Data Store
s1_count_data_store_asset_filters details
s1_count_data_store_asset_filters details
[SentinelOne] Returns the number of Data Store assets behind each filter value — the counts the console shows beside each facet. Use it to size a filter before you act on what it matches. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_export_data_store_assets details
s1_export_data_store_assets details
[SentinelOne] Exports the Data Store asset class as JSON. StackJack always sends exportFormat=json. SentinelOne REQUIRES that parameter and also offers CSV, but a CSV body is not JSON and this tool could not parse it — so the format is pinned here and filtersJson cannot override it. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_data_store_asset_filter_values details
s1_get_data_store_asset_filter_values details
[SentinelOne] Returns matching values for one Data Store asset filter field — the type-ahead behind the console's filter box. Use it to discover the exact values a filter accepts before passing them to s1_list_data_store_assets; SentinelOne rejects an unknown filter value with a 400 rather than ignoring it. Scope to one customer with siteIds / accountIds / groupIds. SentinelOne requires key and text on this endpoint — pass them in filtersJson or the call fails with a 400. key: the search field key, one of the documented `<field>__contains` names. text: the search text to match. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_data_store_asset_text_filters details
s1_get_data_store_asset_text_filters details
[SentinelOne] Lists the Data Store asset fields that a free-text search covers. Read it to learn which fields a free-text query will and will not match before you rely on one. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_list_data_store_asset_actions details
s1_list_data_store_asset_actions details
[SentinelOne] Lists the inventory actions available for Data Store assets, with each action's current status. This is a POST that READS: the selection travels in the request body and nothing is changed. Call it before s1_run_data_store_asset_action to learn which action names that tool accepts. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_list_data_store_assets details
s1_list_data_store_assets details
[SentinelOne] Lists the Data Store asset class of the asset inventory. SentinelOne splits its inventory into 20 asset classes and this tool returns ONLY Data Store assets — use s1_list_assets when you want every class at once. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_run_data_store_asset_action details
s1_run_data_store_asset_action details
[SentinelOne] DESTRUCTIVE — runs an inventory action against the Data Store assets your request body selects. The body carries a FILTER, so the action reaches everything that matches it, and an empty filter matches the whole class. Run s1_list_data_store_assets with countOnly=true and the SAME filter first, and read the count before you send this. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_search_data_store_assets details
s1_search_data_store_assets details
[SentinelOne] Searches the Data Store asset class of the asset inventory using the filter criteria in the request body. This is a POST that READS — the vendor documents it as "POST API to get Assets", and it exists only because the inventory filter set is far too large for a query string. Nothing is created or changed. It is the body-filter twin of s1_list_data_store_assets. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
Developer Tool
s1_count_developer_tool_asset_filters details
s1_count_developer_tool_asset_filters details
[SentinelOne] Returns the number of Developer Tool assets behind each filter value — the counts the console shows beside each facet. Use it to size a filter before you act on what it matches. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_export_developer_tool_assets details
s1_export_developer_tool_assets details
[SentinelOne] Exports the Developer Tool asset class as JSON. StackJack always sends exportFormat=json. SentinelOne REQUIRES that parameter and also offers CSV, but a CSV body is not JSON and this tool could not parse it — so the format is pinned here and filtersJson cannot override it. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_developer_tool_asset_filter_values details
s1_get_developer_tool_asset_filter_values details
[SentinelOne] Returns matching values for one Developer Tool asset filter field — the type-ahead behind the console's filter box. Use it to discover the exact values a filter accepts before passing them to s1_list_developer_tool_assets; SentinelOne rejects an unknown filter value with a 400 rather than ignoring it. Scope to one customer with siteIds / accountIds / groupIds. SentinelOne requires text and key on this endpoint — pass them in filtersJson or the call fails with a 400. text: the search text to match. key: the search field key, one of the documented `<field>__contains` names. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_developer_tool_asset_text_filters details
s1_get_developer_tool_asset_text_filters details
[SentinelOne] Lists the Developer Tool asset fields that a free-text search covers. Read it to learn which fields a free-text query will and will not match before you rely on one. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_list_developer_tool_asset_actions details
s1_list_developer_tool_asset_actions details
[SentinelOne] Lists the inventory actions available for Developer Tool assets, with each action's current status. This is a POST that READS: the selection travels in the request body and nothing is changed. Call it before s1_run_developer_tool_asset_action to learn which action names that tool accepts. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_list_developer_tool_assets details
s1_list_developer_tool_assets details
[SentinelOne] Lists the Developer Tool asset class of the asset inventory. SentinelOne splits its inventory into 20 asset classes and this tool returns ONLY Developer Tool assets — use s1_list_assets when you want every class at once. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_run_developer_tool_asset_action details
s1_run_developer_tool_asset_action details
[SentinelOne] DESTRUCTIVE — runs an inventory action against the Developer Tool assets your request body selects. The body carries a FILTER, so the action reaches everything that matches it, and an empty filter matches the whole class. Run s1_list_developer_tool_assets with countOnly=true and the SAME filter first, and read the count before you send this. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_search_developer_tool_assets details
s1_search_developer_tool_assets details
[SentinelOne] Searches the Developer Tool asset class of the asset inventory using the filter criteria in the request body. This is a POST that READS — the vendor documents it as "POST API to get Assets", and it exists only because the inventory filter set is far too large for a query string. Nothing is created or changed. It is the body-filter twin of s1_list_developer_tool_assets. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
Device
s1_count_device_asset_filters details
s1_count_device_asset_filters details
[SentinelOne] Returns the number of Device assets behind each filter value — the counts the console shows beside each facet. Use it to size a filter before you act on what it matches. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_export_device_assets details
s1_export_device_assets details
[SentinelOne] Exports the Device asset class as JSON. StackJack always sends exportFormat=json. SentinelOne REQUIRES that parameter and also offers CSV, but a CSV body is not JSON and this tool could not parse it — so the format is pinned here and filtersJson cannot override it. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_device_asset_filter_values details
s1_get_device_asset_filter_values details
[SentinelOne] Returns matching values for one Device asset filter field — the type-ahead behind the console's filter box. Use it to discover the exact values a filter accepts before passing them to s1_list_device_assets; SentinelOne rejects an unknown filter value with a 400 rather than ignoring it. Scope to one customer with siteIds / accountIds / groupIds. SentinelOne requires key and text on this endpoint — pass them in filtersJson or the call fails with a 400. key: the search field key, one of the documented `<field>__contains` names. text: the search text to match. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_device_asset_text_filters details
s1_get_device_asset_text_filters details
[SentinelOne] Lists the Device asset fields that a free-text search covers. Read it to learn which fields a free-text query will and will not match before you rely on one. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_list_device_asset_actions details
s1_list_device_asset_actions details
[SentinelOne] Lists the inventory actions available for Device assets, with each action's current status. This is a POST that READS: the selection travels in the request body and nothing is changed. Call it before s1_run_device_asset_action to learn which action names that tool accepts. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_list_device_assets details
s1_list_device_assets details
[SentinelOne] Lists the Device asset class of the asset inventory. SentinelOne splits its inventory into 20 asset classes and this tool returns ONLY Device assets — use s1_list_assets when you want every class at once. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_run_device_asset_action details
s1_run_device_asset_action details
[SentinelOne] DESTRUCTIVE — runs an inventory action against the Device assets your request body selects. The body carries a FILTER, so the action reaches everything that matches it, and an empty filter matches the whole class. Run s1_list_device_assets with countOnly=true and the SAME filter first, and read the count before you send this. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_search_device_assets details
s1_search_device_assets details
[SentinelOne] Searches the Device asset class of the asset inventory using the filter criteria in the request body. This is a POST that READS — the vendor documents it as "POST API to get Assets", and it exists only because the inventory filter set is far too large for a query string. Nothing is created or changed. It is the body-filter twin of s1_list_device_assets. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
Endpoint Surface
s1_count_endpoint_surface_asset_filters details
s1_count_endpoint_surface_asset_filters details
[SentinelOne] Returns the number of Endpoint Surface assets behind each filter value — the counts the console shows beside each facet. Use it to size a filter before you act on what it matches. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_export_endpoint_surface_assets details
s1_export_endpoint_surface_assets details
[SentinelOne] Exports the Endpoint Surface asset class as JSON. StackJack always sends exportFormat=json. SentinelOne REQUIRES that parameter and also offers CSV, but a CSV body is not JSON and this tool could not parse it — so the format is pinned here and filtersJson cannot override it. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_endpoint_surface_asset_filter_values details
s1_get_endpoint_surface_asset_filter_values details
[SentinelOne] Returns matching values for one Endpoint Surface asset filter field — the type-ahead behind the console's filter box. Use it to discover the exact values a filter accepts before passing them to s1_list_endpoint_surface_assets; SentinelOne rejects an unknown filter value with a 400 rather than ignoring it. Scope to one customer with siteIds / accountIds / groupIds. SentinelOne requires key and text on this endpoint — pass them in filtersJson or the call fails with a 400. key: the search field key, one of the documented `<field>__contains` names. text: the search text to match. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_endpoint_surface_asset_text_filters details
s1_get_endpoint_surface_asset_text_filters details
[SentinelOne] Lists the Endpoint Surface asset fields that a free-text search covers. Read it to learn which fields a free-text query will and will not match before you rely on one. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_list_endpoint_surface_asset_actions details
s1_list_endpoint_surface_asset_actions details
[SentinelOne] Lists the inventory actions available for Endpoint Surface assets, with each action's current status. This is a POST that READS: the selection travels in the request body and nothing is changed. Call it before s1_run_endpoint_surface_asset_action to learn which action names that tool accepts. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_list_endpoint_surface_assets details
s1_list_endpoint_surface_assets details
[SentinelOne] Lists the Endpoint Surface asset class of the asset inventory. SentinelOne splits its inventory into 20 asset classes and this tool returns ONLY Endpoint Surface assets — use s1_list_assets when you want every class at once. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_run_endpoint_surface_asset_action details
s1_run_endpoint_surface_asset_action details
[SentinelOne] DESTRUCTIVE — runs an inventory action against the Endpoint Surface assets your request body selects. The body carries a FILTER, so the action reaches everything that matches it, and an empty filter matches the whole class. Run s1_list_endpoint_surface_assets with countOnly=true and the SAME filter first, and read the count before you send this. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_search_endpoint_surface_assets details
s1_search_endpoint_surface_assets details
[SentinelOne] Searches the Endpoint Surface asset class of the asset inventory using the filter criteria in the request body. This is a POST that READS — the vendor documents it as "POST API to get Assets", and it exists only because the inventory filter set is far too large for a query string. Nothing is created or changed. It is the body-filter twin of s1_list_endpoint_surface_assets. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
Filters
s1_count_asset_filters details
s1_count_asset_filters details
[SentinelOne] Returns the number of assets behind each inventory filter value, across every asset class — the counts the console shows beside each facet. Use it to size a filter before you act on what it matches. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_asset_filter_values details
s1_get_asset_filter_values details
[SentinelOne] Returns matching values for one inventory filter field across every asset class — the type-ahead behind the console's filter box. Use it to discover the exact values a filter accepts before passing them to s1_list_assets; SentinelOne rejects an unknown filter value with a 400 rather than ignoring it. Scope to one customer with siteIds / accountIds / groupIds. SentinelOne requires key and text on this endpoint — pass them in filtersJson or the call fails with a 400. key: the search field key, one of the documented `<field>__contains` names. text: the search text to match. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_asset_text_filters details
s1_get_asset_text_filters details
[SentinelOne] Lists the inventory fields that a free-text search covers, across every asset class. Read it to learn which fields a free-text query will and will not match before you rely on one. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_upload_asset_filter_csv details
s1_upload_asset_filter_csv details
[SentinelOne] Uploads a CSV of asset identifiers and stores it as a reusable inventory filter, returning the csvFilterId that the inventory list tools accept. This creates a saved filter and changes no asset, so it is not destructive — but the filter it creates can later be handed to a destructive action tool, so check what you uploaded. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
Function
s1_count_function_asset_filters details
s1_count_function_asset_filters details
[SentinelOne] Returns the number of Function assets behind each filter value — the counts the console shows beside each facet. Use it to size a filter before you act on what it matches. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_export_function_assets details
s1_export_function_assets details
[SentinelOne] Exports the Function asset class as JSON. StackJack always sends exportFormat=json. SentinelOne REQUIRES that parameter and also offers CSV, but a CSV body is not JSON and this tool could not parse it — so the format is pinned here and filtersJson cannot override it. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_function_asset_filter_values details
s1_get_function_asset_filter_values details
[SentinelOne] Returns matching values for one Function asset filter field — the type-ahead behind the console's filter box. Use it to discover the exact values a filter accepts before passing them to s1_list_function_assets; SentinelOne rejects an unknown filter value with a 400 rather than ignoring it. Scope to one customer with siteIds / accountIds / groupIds. SentinelOne requires text and key on this endpoint — pass them in filtersJson or the call fails with a 400. text: the search text to match. key: the search field key, one of the documented `<field>__contains` names. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_function_asset_text_filters details
s1_get_function_asset_text_filters details
[SentinelOne] Lists the Function asset fields that a free-text search covers. Read it to learn which fields a free-text query will and will not match before you rely on one. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_list_function_asset_actions details
s1_list_function_asset_actions details
[SentinelOne] Lists the inventory actions available for Function assets, with each action's current status. This is a POST that READS: the selection travels in the request body and nothing is changed. Call it before s1_run_function_asset_action to learn which action names that tool accepts. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_list_function_assets details
s1_list_function_assets details
[SentinelOne] Lists the Function asset class of the asset inventory. SentinelOne splits its inventory into 20 asset classes and this tool returns ONLY Function assets — use s1_list_assets when you want every class at once. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_run_function_asset_action details
s1_run_function_asset_action details
[SentinelOne] DESTRUCTIVE — runs an inventory action against the Function assets your request body selects. The body carries a FILTER, so the action reaches everything that matches it, and an empty filter matches the whole class. Run s1_list_function_assets with countOnly=true and the SAME filter first, and read the count before you send this. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_search_function_assets details
s1_search_function_assets details
[SentinelOne] Searches the Function asset class of the asset inventory using the filter criteria in the request body. This is a POST that READS — the vendor documents it as "POST API to get Assets", and it exists only because the inventory filter set is far too large for a query string. Nothing is created or changed. It is the body-filter twin of s1_list_function_assets. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
Governance
s1_count_governance_asset_filters details
s1_count_governance_asset_filters details
[SentinelOne] Returns the number of Governance assets behind each filter value — the counts the console shows beside each facet. Use it to size a filter before you act on what it matches. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_export_governance_assets details
s1_export_governance_assets details
[SentinelOne] Exports the Governance asset class as JSON. StackJack always sends exportFormat=json. SentinelOne REQUIRES that parameter and also offers CSV, but a CSV body is not JSON and this tool could not parse it — so the format is pinned here and filtersJson cannot override it. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_governance_asset_filter_values details
s1_get_governance_asset_filter_values details
[SentinelOne] Returns matching values for one Governance asset filter field — the type-ahead behind the console's filter box. Use it to discover the exact values a filter accepts before passing them to s1_list_governance_assets; SentinelOne rejects an unknown filter value with a 400 rather than ignoring it. Scope to one customer with siteIds / accountIds / groupIds. SentinelOne requires text and key on this endpoint — pass them in filtersJson or the call fails with a 400. text: the search text to match. key: the search field key, one of the documented `<field>__contains` names. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_governance_asset_text_filters details
s1_get_governance_asset_text_filters details
[SentinelOne] Lists the Governance asset fields that a free-text search covers. Read it to learn which fields a free-text query will and will not match before you rely on one. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_list_governance_asset_actions details
s1_list_governance_asset_actions details
[SentinelOne] Lists the inventory actions available for Governance assets, with each action's current status. This is a POST that READS: the selection travels in the request body and nothing is changed. Call it before s1_run_governance_asset_action to learn which action names that tool accepts. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_list_governance_assets details
s1_list_governance_assets details
[SentinelOne] Lists the Governance asset class of the asset inventory. SentinelOne splits its inventory into 20 asset classes and this tool returns ONLY Governance assets — use s1_list_assets when you want every class at once. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_run_governance_asset_action details
s1_run_governance_asset_action details
[SentinelOne] DESTRUCTIVE — runs an inventory action against the Governance assets your request body selects. The body carries a FILTER, so the action reaches everything that matches it, and an empty filter matches the whole class. Run s1_list_governance_assets with countOnly=true and the SAME filter first, and read the count before you send this. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_search_governance_assets details
s1_search_governance_assets details
[SentinelOne] Searches the Governance asset class of the asset inventory using the filter criteria in the request body. This is a POST that READS — the vendor documents it as "POST API to get Assets", and it exists only because the inventory filter set is far too large for a query string. Nothing is created or changed. It is the body-filter twin of s1_list_governance_assets. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
Identity
s1_count_identity_asset_filters details
s1_count_identity_asset_filters details
[SentinelOne] Returns the number of Identity assets behind each filter value — the counts the console shows beside each facet. Use it to size a filter before you act on what it matches. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_export_identity_assets details
s1_export_identity_assets details
[SentinelOne] Exports the Identity asset class as JSON. StackJack always sends exportFormat=json. SentinelOne REQUIRES that parameter and also offers CSV, but a CSV body is not JSON and this tool could not parse it — so the format is pinned here and filtersJson cannot override it. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_identity_asset_filter_values details
s1_get_identity_asset_filter_values details
[SentinelOne] Returns matching values for one Identity asset filter field — the type-ahead behind the console's filter box. Use it to discover the exact values a filter accepts before passing them to s1_list_identity_assets; SentinelOne rejects an unknown filter value with a 400 rather than ignoring it. Scope to one customer with siteIds / accountIds / groupIds. SentinelOne requires key and text on this endpoint — pass them in filtersJson or the call fails with a 400. key: the search field key, one of the documented `<field>__contains` names. text: the search text to match. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_identity_asset_text_filters details
s1_get_identity_asset_text_filters details
[SentinelOne] Lists the Identity asset fields that a free-text search covers. Read it to learn which fields a free-text query will and will not match before you rely on one. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_list_identity_asset_actions details
s1_list_identity_asset_actions details
[SentinelOne] Lists the inventory actions available for Identity assets, with each action's current status. This is a POST that READS: the selection travels in the request body and nothing is changed. Call it before s1_run_identity_asset_action to learn which action names that tool accepts. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_list_identity_assets details
s1_list_identity_assets details
[SentinelOne] Lists the Identity asset class of the asset inventory. SentinelOne splits its inventory into 20 asset classes and this tool returns ONLY Identity assets — use s1_list_assets when you want every class at once. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_run_identity_asset_action details
s1_run_identity_asset_action details
[SentinelOne] DESTRUCTIVE — runs an inventory action against the Identity assets your request body selects. The body carries a FILTER, so the action reaches everything that matches it, and an empty filter matches the whole class. Run s1_list_identity_assets with countOnly=true and the SAME filter first, and read the count before you send this. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_search_identity_assets details
s1_search_identity_assets details
[SentinelOne] Searches the Identity asset class of the asset inventory using the filter criteria in the request body. This is a POST that READS — the vendor documents it as "POST API to get Assets", and it exists only because the inventory filter set is far too large for a query string. Nothing is created or changed. It is the body-filter twin of s1_list_identity_assets. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
Identity Surface
s1_count_identity_surface_asset_filters details
s1_count_identity_surface_asset_filters details
[SentinelOne] Returns the number of Identity Surface assets behind each filter value — the counts the console shows beside each facet. Use it to size a filter before you act on what it matches. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_export_identity_surface_assets details
s1_export_identity_surface_assets details
[SentinelOne] Exports the Identity Surface asset class as JSON. StackJack always sends exportFormat=json. SentinelOne REQUIRES that parameter and also offers CSV, but a CSV body is not JSON and this tool could not parse it — so the format is pinned here and filtersJson cannot override it. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_identity_surface_asset_filter_values details
s1_get_identity_surface_asset_filter_values details
[SentinelOne] Returns matching values for one Identity Surface asset filter field — the type-ahead behind the console's filter box. Use it to discover the exact values a filter accepts before passing them to s1_list_identity_surface_assets; SentinelOne rejects an unknown filter value with a 400 rather than ignoring it. Scope to one customer with siteIds / accountIds / groupIds. SentinelOne requires key and text on this endpoint — pass them in filtersJson or the call fails with a 400. key: the search field key, one of the documented `<field>__contains` names. text: the search text to match. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_identity_surface_asset_text_filters details
s1_get_identity_surface_asset_text_filters details
[SentinelOne] Lists the Identity Surface asset fields that a free-text search covers. Read it to learn which fields a free-text query will and will not match before you rely on one. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_list_identity_surface_asset_actions details
s1_list_identity_surface_asset_actions details
[SentinelOne] Lists the inventory actions available for Identity Surface assets, with each action's current status. This is a POST that READS: the selection travels in the request body and nothing is changed. Call it before s1_run_identity_surface_asset_action to learn which action names that tool accepts. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_list_identity_surface_assets details
s1_list_identity_surface_assets details
[SentinelOne] Lists the Identity Surface asset class of the asset inventory. SentinelOne splits its inventory into 20 asset classes and this tool returns ONLY Identity Surface assets — use s1_list_assets when you want every class at once. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_run_identity_surface_asset_action details
s1_run_identity_surface_asset_action details
[SentinelOne] DESTRUCTIVE — runs an inventory action against the Identity Surface assets your request body selects. The body carries a FILTER, so the action reaches everything that matches it, and an empty filter matches the whole class. Run s1_list_identity_surface_assets with countOnly=true and the SAME filter first, and read the count before you send this. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
Network
s1_count_network_asset_filters details
s1_count_network_asset_filters details
[SentinelOne] Returns the number of Network assets behind each filter value — the counts the console shows beside each facet. Use it to size a filter before you act on what it matches. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_export_network_assets details
s1_export_network_assets details
[SentinelOne] Exports the Network asset class as JSON. StackJack always sends exportFormat=json. SentinelOne REQUIRES that parameter and also offers CSV, but a CSV body is not JSON and this tool could not parse it — so the format is pinned here and filtersJson cannot override it. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_network_asset_filter_values details
s1_get_network_asset_filter_values details
[SentinelOne] Returns matching values for one Network asset filter field — the type-ahead behind the console's filter box. Use it to discover the exact values a filter accepts before passing them to s1_list_network_assets; SentinelOne rejects an unknown filter value with a 400 rather than ignoring it. Scope to one customer with siteIds / accountIds / groupIds. SentinelOne requires text and key on this endpoint — pass them in filtersJson or the call fails with a 400. text: the search text to match. key: the search field key, one of the documented `<field>__contains` names. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_get_network_asset_text_filters details
s1_get_network_asset_text_filters details
[SentinelOne] Lists the Network asset fields that a free-text search covers. Read it to learn which fields a free-text query will and will not match before you rely on one. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_list_network_asset_actions details
s1_list_network_asset_actions details
[SentinelOne] Lists the inventory actions available for Network assets, with each action's current status. This is a POST that READS: the selection travels in the request body and nothing is changed. Call it before s1_run_network_asset_action to learn which action names that tool accepts. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_list_network_assets details
s1_list_network_assets details
[SentinelOne] Lists the Network asset class of the asset inventory. SentinelOne splits its inventory into 20 asset classes and this tool returns ONLY Network assets — use s1_list_assets when you want every class at once. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_run_network_asset_action details
s1_run_network_asset_action details
[SentinelOne] DESTRUCTIVE — runs an inventory action against the Network assets your request body selects. The body carries a FILTER, so the action reaches everything that matches it, and an empty filter matches the whole class. Run s1_list_network_assets with countOnly=true and the SAME filter first, and read the count before you send this. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_search_network_assets details
s1_search_network_assets details
[SentinelOne] Searches the Network asset class of the asset inventory using the filter criteria in the request body. This is a POST that READS — the vendor documents it as "POST API to get Assets", and it exists only because the inventory filter set is far too large for a query string. Nothing is created or changed. It is the body-filter twin of s1_list_network_assets. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
Network Discovery Surface
s1_count_network_discovery_surface_asset_filters details
s1_count_network_discovery_surface_asset_filters details
[SentinelOne] Returns the number of Network Discovery Surface assets behind each filter value — the counts the console shows beside each facet. Use it to size a filter before you act on what it matches. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.
s1_export_network_discovery_surface_assets details
s1_export_network_discovery_surface_assets details
[SentinelOne] Exports the Network Discovery Surface asset class as JSON. StackJack always sends exportFormat=json. SentinelOne REQUIRES that parameter and also offers CSV, but a CSV body is not JSON and this tool could not parse it — so the format is pinned here and filtersJson cannot override it. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a fl
More in Tools Reference
Atera ToolsAuvik ToolsAvanan (Check Point Harmony Email) ToolsConnectWise Sell ToolsStill need help? Ask the team