Skip to main content
Tools Reference

SentinelOne Tools

Written By Christopher Scaminaci

Last updated 7 days ago

SentinelOne Tools

s1_ · 696 tools · Free 367 · Pro 329Endpoint protection and EDR, plus the console's cloud and identity asset inventory, over the Management API v2.1. The credential is a console API token; the console host is per tenant and regional, so the instance address is required. Paging is a cursor capped at 1000 items - a larger tenant is truncated while the call still reports success, so narrow the filter rather than paging past it. Ten common query parameters are named arguments and everything else travels in one flat filters object that accepts scalars; where the vendor marks another one required, the tool description names it. Permissions are enforced per endpoint against the service user's role, so a refusal means one missing permission and every other tool keeps working. Endpoint actions select machines by filter rather than by id and answer 200 either way, so run the matching count first and re-read afterwards - a success body can carry an affected count of zero.

All connector tools · SentinelOne setup guide

SentinelOne tool groups

Activity Log

ToolPlanAccessSummary
s1_get_activitiesFreeRead-onlyGet Activities.
s1_get_activity_typesFreeRead-onlyGet Activity Types.
s1_get_last_activity_syslog_messageFreeRead-onlyLast activity as Syslog message.

[SentinelOne] Get Activities. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
idsstringnonullComma-separated list of ids to restrict the result to.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Get Activity Types. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

[SentinelOne] Last activity as Syslog message. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
idsstringnonullComma-separated list of ids to restrict the result to.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

Agent Deployment and Updates

ToolPlanAccessSummary
s1_add_cred_detailsProDestructiveDESTRUCTIVE — Add cred details.
s1_create_cred_groupProDestructiveDESTRUCTIVE — Create Cred Group.
s1_create_policyProDestructiveDESTRUCTIVE — Create Policy.
s1_create_policy_actionProDestructiveDESTRUCTIVE — Policy Action.
s1_deactivate_policiesProDestructiveDESTRUCTIVE — Deactivate Policies.
s1_delete_cred_groupProDestructiveDESTRUCTIVE — Delete Cred Group.
s1_delete_cred_group_detailProDestructiveDESTRUCTIVE — Delete Cred Group Detail.
s1_delete_packagesProDestructiveDESTRUCTIVE — Delete Packages.
s1_deploy_system_packageProDestructiveDESTRUCTIVE — Deploy System Package.
s1_get_available_packagesFreeRead-onlyGet Available Packages.
s1_get_cred_group_detailsFreeRead-onlyGet Cred group details.
s1_get_cred_groupsFreeRead-onlyGet Cred groups.
s1_get_latest_packagesFreeRead-onlyGet Latest Packages.
s1_get_parent_policiesFreeRead-onlyGet Parent Policies.
s1_get_policiesFreeRead-onlyGet Policies.
s1_get_policies_os_countFreeRead-onlyAll Policies OS Count.
s1_get_policies_os_count_upgrade_policyFreeRead-onlyPolicies OS Count.
s1_has_policyFreeRead-onlyHas Policy.
s1_reorder_policiesProDestructiveDESTRUCTIVE — Reorder Policies.
s1_reset_policy_retry_counterProDestructiveDESTRUCTIVE — Reset Policy Retry Counter.
s1_set_scope_inheritingProDestructiveDESTRUCTIVE — Set Scope Inheriting.
s1_update_cred_group_detailsProDestructiveDESTRUCTIVE — Update Cred Group Details.
s1_update_packageProDestructiveDESTRUCTIVE — Update package.
s1_update_policyProDestructiveDESTRUCTIVE — Update Policy.
s1_upload_agent_packageProDestructiveDESTRUCTIVE — Upload Agent Package.
s1_upload_system_packageProDestructiveDESTRUCTIVE — Upload System Package.

[SentinelOne] DESTRUCTIVE — Add cred details. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/ranger/cred-groups/details schema expects.

[SentinelOne] DESTRUCTIVE — Create Cred Group. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/ranger/cred-groups schema expects.

[SentinelOne] DESTRUCTIVE — Create Policy. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/upgrade-policy/policy schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).

[SentinelOne] DESTRUCTIVE — Policy Action. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/upgrade-policy/policy/ schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
policyidstringyesSentinelOne's own id for the agent deployment and updates resource this call targets.

[SentinelOne] DESTRUCTIVE — Deactivate Policies. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. SentinelOne requires scopeLevel and osType on this endpoint — pass them in filtersJson or the call fails with a 400. scopeLevel: scope level, one of 'account', 'group', 'site' or 'tenant'. osType: OS type, one of 'linux', 'macos' or 'windows'. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).

[SentinelOne] DESTRUCTIVE — Delete Cred Group. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
credGroupIdstringyesSentinelOne's own id for the agent deployment and updates resource this call targets.

[SentinelOne] DESTRUCTIVE — Delete Cred Group Detail. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
detailIdstringyesSentinelOne's own id for the agent deployment and updates resource this call targets.

[SentinelOne] DESTRUCTIVE — Delete Packages. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/update/agent/packages schema expects.

[SentinelOne] DESTRUCTIVE — Deploy System Package. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

[SentinelOne] Get Available Packages. SentinelOne requires scopeLevel and osType on this endpoint — pass them in filtersJson or the call fails with a 400. scopeLevel: scope level, one of 'account', 'group', 'site' or 'tenant'. osType: OS type, one of 'linux', 'macos' or 'windows'. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).

[SentinelOne] Get Cred group details. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
idsstringnonullComma-separated list of ids to restrict the result to.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Get Cred groups. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
idsstringnonullComma-separated list of ids to restrict the result to.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Get Latest Packages. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
idsstringnonullComma-separated list of ids to restrict the result to.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
searchQuerystringnonullFree-text search over the resource, as SentinelOne's own console search box would apply it.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Get Parent Policies. SentinelOne requires scopeLevel, osType and skip on this endpoint — pass them in filtersJson or the call fails with a 400. scopeLevel: scope level, one of 'account', 'group', 'site' or 'tenant'. osType: OS type, one of 'linux', 'macos' or 'windows'. skip: the number of items to skip; SentinelOne stops at 1000, so page with cursor where the tool offers one. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Get Policies. SentinelOne requires scopeLevel, osType and skip on this endpoint — pass them in filtersJson or the call fails with a 400. scopeLevel: scope level, one of 'account', 'group', 'site' or 'tenant'. osType: OS type, one of 'linux', 'macos' or 'windows'. skip: the number of items to skip; SentinelOne stops at 1000, so page with cursor where the tool offers one. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] All Policies OS Count. SentinelOne requires scopeLevel on this endpoint — pass it in filtersJson or the call fails with a 400. scopeLevel: scope level, one of 'account', 'group', 'site' or 'tenant'. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).

[SentinelOne] Policies OS Count. SentinelOne requires scopeLevel on this endpoint — pass it in filtersJson or the call fails with a 400. scopeLevel: scope level, one of 'account', 'group', 'site' or 'tenant'. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).

[SentinelOne] Has Policy. This is a POST that READS: the criteria travel in the request body, and nothing is created or changed. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/upgrade-policy/has-policy schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).

[SentinelOne] DESTRUCTIVE — Reorder Policies. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/upgrade-policy/reorder schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).

[SentinelOne] DESTRUCTIVE — Reset Policy Retry Counter. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
policyidstringyesSentinelOne's own id for the agent deployment and updates resource this call targets.

[SentinelOne] DESTRUCTIVE — Set Scope Inheriting. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/upgrade-policy/set-inheriting schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).

[SentinelOne] DESTRUCTIVE — Update Cred Group Details. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
detailIdstringyesSentinelOne's own id for the agent deployment and updates resource this call targets.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/ranger/cred-groups/details/ schema expects.

[SentinelOne] DESTRUCTIVE — Update package. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/update/agent/packages/ schema expects.
packageIdstringyesSentinelOne's own id for the agent deployment and updates resource this call targets.

[SentinelOne] DESTRUCTIVE — Update Policy. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/upgrade-policy/policy/ schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
policyidstringyesSentinelOne's own id for the agent deployment and updates resource this call targets.

[SentinelOne] DESTRUCTIVE — Upload Agent Package. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Scope to one customer with siteIds / accountIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] DESTRUCTIVE — Upload System Package. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).

Alerts

ToolPlanAccessSummary
s1_create_internal_api_only_notify_action_was_triggered_withoutProDestructiveDESTRUCTIVE — Internal api only to notify action was triggered without actually performing it.
s1_create_perform_action_selected_assets_entitiesProDestructiveDESTRUCTIVE — Perform an Action on selected assets/entities.
s1_fetch_surface_ids_case_select_filtersFreeRead-onlyFetch surface ids in case of select all with filters.
s1_get_alertsFreeRead-onlyGet alerts.
s1_get_available_actions_asset_entity_typeFreeRead-onlyGet Available Actions by Asset/Entity Type.
s1_update_alert_analyst_verdictProDestructiveDESTRUCTIVE — Update Alert Analyst Verdict.
s1_update_threat_incidentProDestructiveDESTRUCTIVE — Update Threat Incident.

[SentinelOne] DESTRUCTIVE — Internal api only to notify action was triggered without actually performing it. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/action-controller/perform-unified-action/notify schema expects.
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] DESTRUCTIVE — Perform an Action on selected assets/entities. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/action-controller/perform-unified-action schema expects.
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Fetch surface ids in case of select all with filters. This is a POST that READS: the criteria travel in the request body, and nothing is created or changed. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/action-controller/fetch-surface-ids schema expects.
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Get alerts. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
idsstringnonullComma-separated list of ids to restrict the result to.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
searchQuerystringnonullFree-text search over the resource, as SentinelOne's own console search box would apply it.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Get Available Actions by Asset/Entity Type. This is a POST that READS: the criteria travel in the request body, and nothing is created or changed. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/action-controller/fetch-unified-actions schema expects.
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] DESTRUCTIVE — Update Alert Analyst Verdict. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/cloud-detection/alerts/analyst-verdict schema expects.

[SentinelOne] DESTRUCTIVE — Update Threat Incident. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/cloud-detection/alerts/incident schema expects.

Detection Rules

ToolPlanAccessSummary
s1_activate_rulesProDestructiveDESTRUCTIVE — Activate Rules.
s1_create_ruleProDestructiveDESTRUCTIVE — Create Rule.
s1_delete_rulesProDestructiveDESTRUCTIVE — Delete Rules.
s1_disable_managed_detection_ruleProDestructiveDESTRUCTIVE — Disable a Managed Detection Rule.
s1_disable_rulesProDestructiveDESTRUCTIVE — Disable Rules.
s1_enable_managed_detection_ruleProDestructiveDESTRUCTIVE — Enable a Managed Detection Rule.
s1_get_data_sourcesFreeRead-onlyGet Data Sources.
s1_get_free_text_filtersFreeRead-onlyFree-Text Filters.
s1_get_managed_detection_rulesFreeRead-onlyGet Managed Detection Rules.
s1_get_managed_detection_rules_detection_libraryFreeRead-onlyGet Managed Detection Rules.
s1_get_rulesFreeRead-onlyGet Rules.
s1_get_settings_managed_detection_rulesFreeRead-onlyGet settings for Managed Detection Rules.
s1_get_severitiesFreeRead-onlyGet Severities.
s1_get_statusesFreeRead-onlyGet Statuses.
s1_get_surfacesFreeRead-onlyGet Surfaces.
s1_get_template_detection_rulesFreeRead-onlyGet Template Detection Rules.
s1_update_ruleProDestructiveDESTRUCTIVE — Update Rule.
s1_update_settings_managed_detection_rulesProDestructiveDESTRUCTIVE — Update settings for Managed Detection Rules.

[SentinelOne] DESTRUCTIVE — Activate Rules. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/cloud-detection/rules/enable schema expects.

[SentinelOne] DESTRUCTIVE — Create Rule. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/cloud-detection/rules schema expects.

[SentinelOne] DESTRUCTIVE — Delete Rules. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/cloud-detection/rules schema expects.

[SentinelOne] DESTRUCTIVE — Disable a Managed Detection Rule. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/detection-library/platform-rules/disable schema expects.

[SentinelOne] DESTRUCTIVE — Disable Rules. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/cloud-detection/rules/disable schema expects.

[SentinelOne] DESTRUCTIVE — Enable a Managed Detection Rule. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/detection-library/platform-rules/enable schema expects.

[SentinelOne] Get Data Sources. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

[SentinelOne] Free-Text Filters. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

[SentinelOne] Get Managed Detection Rules. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.

[SentinelOne] Get Managed Detection Rules. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
searchQuerystringnonullFree-text search over the resource, as SentinelOne's own console search box would apply it.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Get Rules. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
idsstringnonullComma-separated list of ids to restrict the result to.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
searchQuerystringnonullFree-text search over the resource, as SentinelOne's own console search box would apply it.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Get settings for Managed Detection Rules. SentinelOne requires scopeLevel on this endpoint — pass it in filtersJson or the call fails with a 400. scopeLevel: scope level, one of 'global', 'group', 'account' or 'site'. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).

[SentinelOne] Get Severities. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

[SentinelOne] Get Statuses. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

[SentinelOne] Get Surfaces. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

[SentinelOne] Get Template Detection Rules. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.

[SentinelOne] DESTRUCTIVE — Update Rule. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/cloud-detection/rules/ schema expects.
ruleIdstringyesSentinelOne's own id for the detection rules resource this call targets.

[SentinelOne] DESTRUCTIVE — Update settings for Managed Detection Rules. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/detection-library/platform-rules/settings schema expects.

Endpoint Actions

ToolPlanAccessSummary
s1_abort_scanProDestructiveDESTRUCTIVE — Abort Scan.
s1_approve_stateless_upgradesProDestructiveDESTRUCTIVE — Approve Stateless Upgrades.
s1_approve_uninstallProDestructiveDESTRUCTIVE — Approve Uninstall.
s1_broadcast_messageProDestructiveDESTRUCTIVE — Broadcast Message.
s1_can_run_remote_shellProDestructiveDESTRUCTIVE — Can run Remote Shell.
s1_clear_remote_shellProDestructiveDESTRUCTIVE — Clear Remote Shell.
s1_connect_networkProDestructiveDESTRUCTIVE — Connect to Network.
s1_create_manage_endpoint_tags_add_remove_overrideProDestructiveDESTRUCTIVE — Manage endpoint tags: add, remove, override.
s1_create_randomize_uuidProDestructiveDESTRUCTIVE — Randomize UUID.
s1_create_terminate_remote_shellProDestructiveDESTRUCTIVE — Terminate Remote Shell.
s1_decommissionProDestructiveDESTRUCTIVE — Decommission.
s1_disable_agentProDestructiveDESTRUCTIVE — Disable Agent.
s1_disable_network_discoveryProDestructiveDESTRUCTIVE — Disable Network Discovery.
s1_disconnect_networkProDestructiveDESTRUCTIVE — Disconnect from Network.
s1_edit_local_upgrade_downgrade_site_authorizationProDestructiveDESTRUCTIVE — Edit local upgrade/downgrade Site authorization.
s1_enable_agentProDestructiveDESTRUCTIVE — Enable Agent.
s1_enable_network_discoveryProDestructiveDESTRUCTIVE — Enable Network Discovery.
s1_fetch_filesProDestructiveDESTRUCTIVE — Fetch Files.
s1_fetch_firewall_logsProDestructiveDESTRUCTIVE — Fetch Firewall Logs.
s1_fetch_firewall_rulesProDestructiveDESTRUCTIVE — Fetch Firewall Rules.
s1_fetch_logsProDestructiveDESTRUCTIVE — Fetch Logs.
s1_get_applicationsProDestructiveDESTRUCTIVE — Get Applications.
s1_initiate_scanProDestructiveDESTRUCTIVE — Initiate Scan.
s1_mark_up_dateProDestructiveDESTRUCTIVE — Mark as up-to-date.
s1_move_between_sitesProDestructiveDESTRUCTIVE — Move between Sites.
s1_move_consoleProDestructiveDESTRUCTIVE — Move to Console.
s1_reject_uninstallProDestructiveDESTRUCTIVE — Reject uninstall.
s1_reset_local_configProDestructiveDESTRUCTIVE — Reset Local Config.
s1_reset_passphrase_capabilityProDestructiveDESTRUCTIVE — Reset Passphrase Capability.
s1_reset_passphrasesProDestructiveDESTRUCTIVE — Reset Passphrases.
s1_restartProDestructiveDESTRUCTIVE — Restart.
s1_set_external_idProDestructiveDESTRUCTIVE — Set External ID.
s1_set_persistent_configuration_overridesProDestructiveDESTRUCTIVE — Set Persistent Configuration Overrides.
s1_shutdownProDestructiveDESTRUCTIVE — Shutdown.
s1_start_remote_profilingProDestructiveDESTRUCTIVE — Start Remote Profiling.
s1_start_remote_shellProDestructiveDESTRUCTIVE — Start Remote Shell.
s1_stop_remote_profilingProDestructiveDESTRUCTIVE — Stop Remote Profiling.
s1_uninstallProDestructiveDESTRUCTIVE — Uninstall.
s1_update_softwareProDestructiveDESTRUCTIVE — Update Software.

[SentinelOne] DESTRUCTIVE — Abort Scan. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/agents/actions/abort-scan schema expects.

[SentinelOne] DESTRUCTIVE — Approve Stateless Upgrades. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/agents/actions/approve-stateless-upgrade schema expects.

[SentinelOne] DESTRUCTIVE — Approve Uninstall. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/agents/actions/approve-uninstall schema expects.

[SentinelOne] DESTRUCTIVE — Broadcast Message. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/agents/actions/broadcast schema expects.

[SentinelOne] DESTRUCTIVE — Can run Remote Shell. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/agents/actions/can-start-remote-shell schema expects.

[SentinelOne] DESTRUCTIVE — Clear Remote Shell. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/agents/actions/clear-remote-shell-session schema expects.

[SentinelOne] DESTRUCTIVE — Connect to Network. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/agents/actions/connect schema expects.

[SentinelOne] DESTRUCTIVE — Manage endpoint tags: add, remove, override. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/agents/actions/manage-tags schema expects.

[SentinelOne] DESTRUCTIVE — Randomize UUID. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/agents/actions/randomize-uuid schema expects.

[SentinelOne] DESTRUCTIVE — Terminate Remote Shell. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/agents/actions/terminate-remote-shell schema expects.

[SentinelOne] DESTRUCTIVE — Decommission. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/agents/actions/decommission schema expects.

[SentinelOne] DESTRUCTIVE — Disable Agent. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/agents/actions/disable-agent schema expects.

[SentinelOne] DESTRUCTIVE — Disable Network Discovery. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/agents/actions/ranger-disable schema expects.

[SentinelOne] DESTRUCTIVE — Disconnect from Network. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/agents/actions/disconnect schema expects.

[SentinelOne] DESTRUCTIVE — Edit local upgrade/downgrade Site authorization. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/agents/actions/local-upgrade-authorization schema expects.

[SentinelOne] DESTRUCTIVE — Enable Agent. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/agents/actions/enable-agent schema expects.

[SentinelOne] DESTRUCTIVE — Enable Network Discovery. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/agents/actions/ranger-enable schema expects.

[SentinelOne] DESTRUCTIVE — Fetch Files. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
agentIdstringyesSentinelOne's own id for the endpoint actions resource this call targets.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/agents//actions/fetch-files schema expects.

[SentinelOne] DESTRUCTIVE — Fetch Firewall Logs. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/agents/actions/firewall-logging schema expects.

[SentinelOne] DESTRUCTIVE — Fetch Firewall Rules. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/agents/actions/fetch-firewall-rules schema expects.

[SentinelOne] DESTRUCTIVE — Fetch Logs. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/agents/actions/fetch-logs schema expects.

[SentinelOne] DESTRUCTIVE — Get Applications. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/agents/actions/fetch-installed-apps schema expects.

[SentinelOne] DESTRUCTIVE — Initiate Scan. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/agents/actions/initiate-scan schema expects.

[SentinelOne] DESTRUCTIVE — Mark as up-to-date. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/agents/actions/mark-up-to-date schema expects.

[SentinelOne] DESTRUCTIVE — Move between Sites. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/agents/actions/move-to-site schema expects.

[SentinelOne] DESTRUCTIVE — Move to Console. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/agents/actions/move-to-console schema expects.

[SentinelOne] DESTRUCTIVE — Reject uninstall. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/agents/actions/reject-uninstall schema expects.

[SentinelOne] DESTRUCTIVE — Reset Local Config. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/agents/actions/reset-local-config schema expects.

[SentinelOne] DESTRUCTIVE — Reset Passphrase Capability. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/agents/actions/reset-passphrase/capability schema expects.

[SentinelOne] DESTRUCTIVE — Reset Passphrases. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/agents/actions/reset-passphrase schema expects.

[SentinelOne] DESTRUCTIVE — Restart. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/agents/actions/restart-machine schema expects.

[SentinelOne] DESTRUCTIVE — Set External ID. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/agents/actions/set-external-id schema expects.

[SentinelOne] DESTRUCTIVE — Set Persistent Configuration Overrides. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/agents/actions/set-config schema expects.

[SentinelOne] DESTRUCTIVE — Shutdown. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/agents/actions/shutdown schema expects.

[SentinelOne] DESTRUCTIVE — Start Remote Profiling. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/agents/actions/start-profiling schema expects.

[SentinelOne] DESTRUCTIVE — Start Remote Shell. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/agents/actions/start-remote-shell schema expects.

[SentinelOne] DESTRUCTIVE — Stop Remote Profiling. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/agents/actions/stop-profiling schema expects.

[SentinelOne] DESTRUCTIVE — Uninstall. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/agents/actions/uninstall schema expects.

[SentinelOne] DESTRUCTIVE — Update Software. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/agents/actions/update-software schema expects.

Endpoints

ToolPlanAccessSummary
s1_count_agentsFreeRead-onlyCount Agents.
s1_create_access_tokenProDestructiveDESTRUCTIVE — Create Access Token.
s1_delete_access_tokenProDestructiveDESTRUCTIVE — Delete Access Token.
s1_disable_pna_hyperautomationProDestructiveDESTRUCTIVE — Disable PNA for Hyperautomation.
s1_enable_agent_pna_hyperautomationProDestructiveDESTRUCTIVE — Enable Agent PNA for Hyperautomation.
s1_export_agent_logsFreeRead-onlyExport Agent Logs.
s1_get_agentsFreeRead-onlyGet Agents.
s1_get_applications_agentsFreeRead-onlyApplications.
s1_get_endpoint_tags_count_filtersFreeRead-onlyEndpoint tags count by Filters.
s1_get_endpoint_tags_match_filtersFreeRead-onlyGet the endpoint tags that match the filters.
s1_get_local_upgrade_downgrade_agent_authorizationFreeRead-onlyGet local upgrade/downgrade Agent authorization.
s1_get_passphraseFreeRead-onlyGet Passphrase.
s1_get_processesFreeRead-onlyProcesses.
s1_list_access_tokensFreeRead-onlyList Access Tokens.

[SentinelOne] Count Agents. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
idsstringnonullComma-separated list of ids to restrict the result to.
searchQuerystringnonullFree-text search over the resource, as SentinelOne's own console search box would apply it.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] DESTRUCTIVE — Create Access Token. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/agent-artifacts/token schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).

[SentinelOne] DESTRUCTIVE — Delete Access Token. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).

[SentinelOne] DESTRUCTIVE — Disable PNA for Hyperautomation. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/agents/disable-hyper-automation-pna schema expects.

[SentinelOne] DESTRUCTIVE — Enable Agent PNA for Hyperautomation. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/agents/enable-hyper-automation-pna schema expects.

[SentinelOne] Export Agent Logs. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
activityIdstringyesSentinelOne's own id for the endpoints resource this call targets.
agentIdstringyesSentinelOne's own id for the endpoints resource this call targets.

[SentinelOne] Get Agents. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
idsstringnonullComma-separated list of ids to restrict the result to.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
searchQuerystringnonullFree-text search over the resource, as SentinelOne's own console search box would apply it.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Applications. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
idsstringnonullComma-separated list of ids to restrict the result to.

[SentinelOne] Endpoint tags count by Filters. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
idsstringnonullComma-separated list of ids to restrict the result to.
searchQuerystringnonullFree-text search over the resource, as SentinelOne's own console search box would apply it.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Get the endpoint tags that match the filters. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
idsstringnonullComma-separated list of ids to restrict the result to.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
searchQuerystringnonullFree-text search over the resource, as SentinelOne's own console search box would apply it.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Get local upgrade/downgrade Agent authorization. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
agentIdstringyesSentinelOne's own id for the endpoints resource this call targets.

[SentinelOne] Get Passphrase. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
idsstringnonullComma-separated list of ids to restrict the result to.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
searchQuerystringnonullFree-text search over the resource, as SentinelOne's own console search box would apply it.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Processes. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
idsstringnonullComma-separated list of ids to restrict the result to.

[SentinelOne] List Access Tokens. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.

Network Discovery

ToolPlanAccessSummary
s1_change_device_reviewProDestructiveDESTRUCTIVE — Change Device Review.
s1_change_device_review_bulkProDestructiveDESTRUCTIVE — Change Device Review in Bulk.
s1_change_device_tagsProDestructiveDESTRUCTIVE — Change Device Tags.
s1_export_json_raw_dataFreeRead-onlyExport JSON Raw Data.
s1_export_network_discovery_dataFreeRead-onlyExport Network Discovery Data.
s1_export_unprotected_endpoints_discovery_dataFreeRead-onlyExport Unprotected Endpoints Discovery Data.
s1_get_json_raw_dataFreeRead-onlyJSON Raw Data.
s1_get_network_discovery_settingsFreeRead-onlyGet Network Discovery Settings.
s1_get_network_discovery_tableFreeRead-onlyGet Network Discovery Table.
s1_get_unprotected_endpoints_discovery_settingsFreeRead-onlyGet Unprotected Endpoints Discovery Settings.
s1_get_unprotected_endpoints_discovery_tableFreeRead-onlyGet Unprotected Endpoints Discovery Table.
s1_update_network_discovery_settingsProDestructiveDESTRUCTIVE — Update Network Discovery Settings.
s1_update_unprotected_endpoints_discovery_settingsProDestructiveDESTRUCTIVE — Update Unprotected Endpoints Discovery Settings.

[SentinelOne] DESTRUCTIVE — Change Device Review. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/ranger/device-review/ schema expects.
inventoryIdstringyesSentinelOne's own id for the network discovery resource this call targets.

[SentinelOne] DESTRUCTIVE — Change Device Review in Bulk. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/ranger/device-review schema expects.

[SentinelOne] DESTRUCTIVE — Change Device Tags. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/ranger/tags schema expects.

[SentinelOne] Export JSON Raw Data. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
inventoryIdstringyesSentinelOne's own id for the network discovery resource this call targets.

[SentinelOne] Export Network Discovery Data. Scope to one customer with siteIds / accountIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
idsstringnonullComma-separated list of ids to restrict the result to.
searchQuerystringnonullFree-text search over the resource, as SentinelOne's own console search box would apply it.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Export Unprotected Endpoints Discovery Data. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
idsstringnonullComma-separated list of ids to restrict the result to.
searchQuerystringnonullFree-text search over the resource, as SentinelOne's own console search box would apply it.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] JSON Raw Data. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
inventoryIdstringyesSentinelOne's own id for the network discovery resource this call targets.

[SentinelOne] Get Network Discovery Settings. Scope to one customer with siteIds / accountIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Get Network Discovery Table. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
idsstringnonullComma-separated list of ids to restrict the result to.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
searchQuerystringnonullFree-text search over the resource, as SentinelOne's own console search box would apply it.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Get Unprotected Endpoints Discovery Settings. Scope to one customer with siteIds / accountIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Get Unprotected Endpoints Discovery Table. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
idsstringnonullComma-separated list of ids to restrict the result to.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
searchQuerystringnonullFree-text search over the resource, as SentinelOne's own console search box would apply it.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] DESTRUCTIVE — Update Network Discovery Settings. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/ranger/settings schema expects.

[SentinelOne] DESTRUCTIVE — Update Unprotected Endpoints Discovery Settings. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/rogues/settings schema expects.

Network Quarantine

ToolPlanAccessSummary
s1_add_rule_tagsProWriteAdd Rule Tags.
s1_copy_rules_network_quarantine_controlProDestructiveDESTRUCTIVE — Copy Rules.
s1_create_firewall_rule_firewall_controlProDestructiveDESTRUCTIVE — Create Firewall Rule.
s1_delete_rules_network_quarantine_controlProDestructiveDESTRUCTIVE — Delete Rules.
s1_enable_disable_rules_network_quarantine_controlProDestructiveDESTRUCTIVE — Enable/Disable Rules.
s1_export_rules_network_quarantine_controlFreeRead-onlyExport Rules.
s1_get_configuration_network_quarantine_controlFreeRead-onlyGet Configuration.
s1_get_firewall_rules_firewall_controlFreeRead-onlyGet Firewall Rules.
s1_get_protocolsFreeRead-onlyGet Protocols.
s1_import_rulesProDestructiveDESTRUCTIVE — Import Rules.
s1_move_rules_network_quarantine_controlProDestructiveDESTRUCTIVE — Move Rules.
s1_remove_rule_tagsProDestructiveDESTRUCTIVE — Remove Rule Tags.
s1_reorder_rules_network_quarantine_controlProDestructiveDESTRUCTIVE — Reorder Rules.
s1_set_locationProDestructiveDESTRUCTIVE — Set Location.
s1_update_configuration_network_quarantine_controlProDestructiveDESTRUCTIVE — Update Configuration.

[SentinelOne] Add Rule Tags. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/firewall-control//add-tags schema expects.
firewallRuleCategorystringyesSentinelOne's own id for the network quarantine resource this call targets.

[SentinelOne] DESTRUCTIVE — Copy Rules. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/firewall-control//copy-rules schema expects.
firewallRuleCategorystringyesSentinelOne's own id for the network quarantine resource this call targets.

[SentinelOne] DESTRUCTIVE — Create Firewall Rule. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/firewall-control/ schema expects.
firewallRuleCategorystringyesSentinelOne's own id for the network quarantine resource this call targets.

[SentinelOne] DESTRUCTIVE — Delete Rules. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/firewall-control/ schema expects.
firewallRuleCategorystringyesSentinelOne's own id for the network quarantine resource this call targets.

[SentinelOne] DESTRUCTIVE — Enable/Disable Rules. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/firewall-control//enable schema expects.
firewallRuleCategorystringyesSentinelOne's own id for the network quarantine resource this call targets.

[SentinelOne] Export Rules. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
firewallRuleCategorystringyesSentinelOne's own id for the network quarantine resource this call targets.
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
idsstringnonullComma-separated list of ids to restrict the result to.
searchQuerystringnonullFree-text search over the resource, as SentinelOne's own console search box would apply it.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Get Configuration. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
firewallRuleCategorystringyesSentinelOne's own id for the network quarantine resource this call targets.
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Get Firewall Rules. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
firewallRuleCategorystringyesSentinelOne's own id for the network quarantine resource this call targets.
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
idsstringnonullComma-separated list of ids to restrict the result to.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
searchQuerystringnonullFree-text search over the resource, as SentinelOne's own console search box would apply it.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Get Protocols. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
firewallRuleCategorystringyesSentinelOne's own id for the network quarantine resource this call targets.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
searchQuerystringnonullFree-text search over the resource, as SentinelOne's own console search box would apply it.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] DESTRUCTIVE — Import Rules. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
firewallRuleCategorystringyesSentinelOne's own id for the network quarantine resource this call targets.
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] DESTRUCTIVE — Move Rules. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/firewall-control//move-rules schema expects.
firewallRuleCategorystringyesSentinelOne's own id for the network quarantine resource this call targets.

[SentinelOne] DESTRUCTIVE — Remove Rule Tags. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/firewall-control//remove-tags schema expects.
firewallRuleCategorystringyesSentinelOne's own id for the network quarantine resource this call targets.

[SentinelOne] DESTRUCTIVE — Reorder Rules. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/firewall-control//reorder schema expects.
firewallRuleCategorystringyesSentinelOne's own id for the network quarantine resource this call targets.

[SentinelOne] DESTRUCTIVE — Set Location. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/firewall-control//set-location schema expects.
firewallRuleCategorystringyesSentinelOne's own id for the network quarantine resource this call targets.

[SentinelOne] DESTRUCTIVE — Update Configuration. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/firewall-control//configuration schema expects.
firewallRuleCategorystringyesSentinelOne's own id for the network quarantine resource this call targets.

Tasks

ToolPlanAccessSummary
s1_create_taskProDestructiveDESTRUCTIVE — Create Task.
s1_export_maintenance_windows_csvFreeRead-onlyExport Maintenance Windows as CSV.
s1_get_child_scope_task_configurationFreeRead-onlyGet Child Scope Task Configuration.
s1_get_task_configurationFreeRead-onlyGet Task Configuration.
s1_get_task_configuration_flexible_mwFreeRead-onlyGet Task Configuration (Flexible MW).
s1_has_child_scopesFreeRead-onlyHas Child Scopes.
s1_update_task_configuration_flexible_mwProDestructiveDESTRUCTIVE — Update Task Configuration (Flexible MW).

[SentinelOne] DESTRUCTIVE — Create Task. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/tasks-configuration schema expects.

[SentinelOne] Export Maintenance Windows as CSV. Scope to one customer with siteIds / accountIds / groupIds. SentinelOne requires taskType on this endpoint — pass it in filtersJson or the call fails with a 400. taskType: task type, one of 'agents_upgrade', 'agent_version_change', 'auto_deploy', 'script_execution', 'cis_scan', 'gad' or 'forensics_collection'. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Get Child Scope Task Configuration. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. SentinelOne requires taskType on this endpoint — pass it in filtersJson or the call fails with a 400. taskType: task type, one of 'agents_upgrade', 'agent_version_change', 'auto_deploy', 'script_execution', 'cis_scan', 'gad' or 'forensics_collection'. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
searchQuerystringnonullFree-text search over the resource, as SentinelOne's own console search box would apply it.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Get Task Configuration. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. SentinelOne requires taskType on this endpoint — pass it in filtersJson or the call fails with a 400. taskType: task type, one of 'agents_upgrade', 'agent_version_change', 'auto_deploy', 'script_execution', 'cis_scan', 'gad' or 'forensics_collection'. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Get Task Configuration (Flexible MW). Scope to one customer with siteIds / accountIds / groupIds. SentinelOne requires taskType on this endpoint — pass it in filtersJson or the call fails with a 400. taskType: task type, one of 'agents_upgrade', 'agent_version_change', 'auto_deploy', 'script_execution', 'cis_scan', 'gad' or 'forensics_collection'. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Has Child Scopes. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. SentinelOne requires taskType on this endpoint — pass it in filtersJson or the call fails with a 400. taskType: task type, one of 'agents_upgrade', 'agent_version_change', 'auto_deploy', 'script_execution', 'cis_scan', 'gad' or 'forensics_collection'. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] DESTRUCTIVE — Update Task Configuration (Flexible MW). A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/tasks-configuration/flexible schema expects.

Threat Intelligence

ToolPlanAccessSummary
s1_create_iocsProDestructiveDESTRUCTIVE — Create IOCs.
s1_create_iocs_stix_bundleProDestructiveDESTRUCTIVE — Create IOCs from STIX bundle.
s1_create_threat_intelligence_user_configProWriteCreate Threat Intelligence user config.
s1_delete_iocsProDestructiveDESTRUCTIVE — Delete IOCs.
s1_delete_threat_intelligence_user_configProDestructiveDESTRUCTIVE — Delete Threat Intelligence user config.
s1_get_threat_intelligence_user_configFreeRead-onlyGet Threat Intelligence user config.

[SentinelOne] DESTRUCTIVE — Create IOCs. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/threat-intelligence/iocs schema expects.

[SentinelOne] DESTRUCTIVE — Create IOCs from STIX bundle. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/threat-intelligence/iocs/stix schema expects.

[SentinelOne] Create Threat Intelligence user config. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/threat-intelligence/user-config schema expects.

[SentinelOne] DESTRUCTIVE — Delete IOCs. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/threat-intelligence/iocs schema expects.

[SentinelOne] DESTRUCTIVE — Delete Threat Intelligence user config. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/threat-intelligence/user-config schema expects.

[SentinelOne] Get Threat Intelligence user config. Scope to one customer with siteIds / accountIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

Threats

ToolPlanAccessSummary
s1_add_blocklistProDestructiveDESTRUCTIVE — Add to Blocklist.
s1_add_blocklist_deep_visibilityProDestructiveDESTRUCTIVE — Add to Blocklist (Deep Visibility).
s1_add_exclusionsProDestructiveDESTRUCTIVE — Add to Exclusions.
s1_add_note_multipleProWriteAdd Note to Multiple.
s1_create_updated_threat_incidentProDestructiveDESTRUCTIVE — Updated Threat Incident.
s1_delete_threat_noteProDestructiveDESTRUCTIVE — Delete Threat Note.
s1_disable_enginesProDestructiveDESTRUCTIVE — Disable Engines.
s1_disconnect_containerProDestructiveDESTRUCTIVE — Disconnect Container.
s1_export_mitigation_reportFreeRead-onlyExport Mitigation Report.
s1_export_threatsFreeRead-onlyExport Threats.
s1_fetch_threat_fileProDestructiveDESTRUCTIVE — Fetch Threat File.
s1_get_eventsFreeRead-onlyGet Events.
s1_get_exclusion_optionsFreeRead-onlyExclusion Options.
s1_get_threat_notesFreeRead-onlyGet Threat Notes.
s1_get_threat_timelineFreeRead-onlyGet Threat Timeline.
s1_get_threatsFreeRead-onlyGet Threats.
s1_mark_threat_deep_visibilityProDestructiveDESTRUCTIVE — Mark as Threat (Deep Visibility).
s1_mitigate_alertsProDestructiveDESTRUCTIVE — Mitigate Alerts.
s1_mitigate_threatsProDestructiveDESTRUCTIVE — Mitigate Threats.
s1_reconnect_containerProDestructiveDESTRUCTIVE — Reconnect Container.
s1_update_threat_analyst_verdictProDestructiveDESTRUCTIVE — Update Threat Analyst Verdict.
s1_update_threat_external_ticket_idProDestructiveDESTRUCTIVE — Update Threat External Ticket ID.
s1_update_threat_noteProWriteUpdate Threat Note.

[SentinelOne] DESTRUCTIVE — Add to Blocklist. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/threats/add-to-blacklist schema expects.

[SentinelOne] DESTRUCTIVE — Add to Blocklist (Deep Visibility). A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/threats/dv-add-to-blacklist schema expects.

[SentinelOne] DESTRUCTIVE — Add to Exclusions. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/threats/add-to-exclusions schema expects.

[SentinelOne] Add Note to Multiple. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/threats/notes schema expects.

[SentinelOne] DESTRUCTIVE — Updated Threat Incident. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/threats/incident schema expects.

[SentinelOne] DESTRUCTIVE — Delete Threat Note. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
noteIdstringyesSentinelOne's own id for the threats resource this call targets.
threatIdstringyesSentinelOne's own id for the threats resource this call targets.

[SentinelOne] DESTRUCTIVE — Disable Engines. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/threats/engines/disable schema expects.

[SentinelOne] DESTRUCTIVE — Disconnect Container. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/threats/actions/container-network-disconnect schema expects.

[SentinelOne] Export Mitigation Report. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
reportIdstringyesSentinelOne's own id for the threats resource this call targets.

[SentinelOne] Export Threats. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
idsstringnonullComma-separated list of ids to restrict the result to.
searchQuerystringnonullFree-text search over the resource, as SentinelOne's own console search box would apply it.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] DESTRUCTIVE — Fetch Threat File. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/threats/fetch-file schema expects.

[SentinelOne] Get Events. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.
threatIdstringyesSentinelOne's own id for the threats resource this call targets.

[SentinelOne] Exclusion Options. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
threatIdstringyesSentinelOne's own id for the threats resource this call targets.

[SentinelOne] Get Threat Notes. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.
threatIdstringyesSentinelOne's own id for the threats resource this call targets.

[SentinelOne] Get Threat Timeline. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
searchQuerystringnonullFree-text search over the resource, as SentinelOne's own console search box would apply it.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.
threatIdstringyesSentinelOne's own id for the threats resource this call targets.

[SentinelOne] Get Threats. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
idsstringnonullComma-separated list of ids to restrict the result to.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
searchQuerystringnonullFree-text search over the resource, as SentinelOne's own console search box would apply it.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] DESTRUCTIVE — Mark as Threat (Deep Visibility). A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/threats/dv-mark-as-threat schema expects.

[SentinelOne] DESTRUCTIVE — Mitigate Alerts. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/threats/mitigate-alerts schema expects.

[SentinelOne] DESTRUCTIVE — Mitigate Threats. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
actionstringyesSentinelOne's own id for the threats resource this call targets.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/threats/mitigate/ schema expects.

[SentinelOne] DESTRUCTIVE — Reconnect Container. This acts on EVERY endpoint matching the filter in the request body, not on one machine. Run the matching read with countOnly=true FIRST to see how many endpoints the filter selects. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/threats/actions/container-network-connect schema expects.

[SentinelOne] DESTRUCTIVE — Update Threat Analyst Verdict. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/threats/analyst-verdict schema expects.

[SentinelOne] DESTRUCTIVE — Update Threat External Ticket ID. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/threats/external-ticket-id schema expects.

[SentinelOne] Update Threat Note. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/threats//notes/ schema expects.
noteIdstringyesSentinelOne's own id for the threats resource this call targets.
threatIdstringyesSentinelOne's own id for the threats resource this call targets.

Accounts and Licensing

ToolPlanAccessSummary
s1_create_accountProDestructiveDESTRUCTIVE — Create an account, the MSP-level container above sites.
s1_expire_accountProDestructiveDESTRUCTIVE — Expire an account immediately.
s1_generate_regenerate_uninstall_passwordProDestructiveDESTRUCTIVE — Generate a new agent uninstall password for an account, replacing the current one.
s1_get_accountFreeRead-onlyGet one account by its id, including its state, expiration date, license usage and the modules it has enabled.
s1_get_accountsFreeRead-onlyList the accounts in the console that match the filter, with their state, expiration and license counts.
s1_get_cloud_inventory_overviewFreeRead-onlyCloud Inventory resource overview.
s1_get_uninstall_passwordFreeRead-onlyReveal the current agent uninstall password for an account, in plain text.
s1_get_uninstall_password_metadataFreeRead-onlyGet Uninstall Password Metadata.
s1_reactivate_accountProDestructiveDESTRUCTIVE — Reactivate an expired account.
s1_revert_account_policyProDestructiveDESTRUCTIVE — Discard the account's own policy and revert it to inherit from the level above.
s1_revoke_uninstall_passwordProDestructiveDESTRUCTIVE — Revoke the account's agent uninstall password.
s1_update_accountProDestructiveDESTRUCTIVE — Change an account's fields, which include its license allocation and expiration.
s1_update_sites_add_onsProDestructiveDESTRUCTIVE — Change which licensed modules are enabled on sites.

[SentinelOne] DESTRUCTIVE — Create an account, the MSP-level container above sites. A new account consumes license entitlement and establishes a new policy root, so this is a commercial action as much as a configuration one. A 200 response does not prove the change landed — re-read with s1_get_accounts to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/accounts schema expects.

[SentinelOne] DESTRUCTIVE — Expire an account immediately. An account is the container above sites, so this reaches EVERY site and every agent beneath it at once — the widest blast radius in this family. List what is underneath with s1_get_sites scoped to the account before you run it. s1_reactivate_account is the way back. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdstringyesSentinelOne's own id for the accounts and licensing resource this call targets.

[SentinelOne] DESTRUCTIVE — Generate a new agent uninstall password for an account, replacing the current one. The old password stops working immediately, so any runbook, script or technician still holding it can no longer remove an agent. Read the current one with s1_get_uninstall_password first if you need it. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdstringyesSentinelOne's own id for the accounts and licensing resource this call targets.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/accounts//uninstall-password/generate schema expects.

[SentinelOne] Get one account by its id, including its state, expiration date, license usage and the modules it has enabled. Get the id from s1_get_accounts. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdstringyesSentinelOne's own id for the accounts and licensing resource this call targets.

[SentinelOne] List the accounts in the console that match the filter, with their state, expiration and license counts. In a SentinelOne console an ACCOUNT is the MSP-level container and a SITE is the customer beneath it, so start here to learn the account ids the rest of the connector takes. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Set countOnly=true to size a filter before acting on it. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
idsstringnonullComma-separated list of ids to restrict the result to.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
searchQuerystringnonullFree-text search over the resource, as SentinelOne's own console search box would apply it.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Cloud Inventory resource overview. This is a POST that READS: the criteria travel in the request body, and nothing is created or changed. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/assets/overview schema expects.
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Reveal the current agent uninstall password for an account, in plain text. This is the secret that lets a technician remove the SentinelOne agent from a machine, so treat the response as a credential: do not echo it into a ticket, a chat transcript or a log. It reads the password, it does not change it. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdstringyesSentinelOne's own id for the accounts and licensing resource this call targets.

[SentinelOne] Get Uninstall Password Metadata. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdstringyesSentinelOne's own id for the accounts and licensing resource this call targets.

[SentinelOne] DESTRUCTIVE — Reactivate an expired account. Every site beneath it can start consuming license again, so this is a billing-relevant action across the whole account. A 200 response does not prove the change landed — re-read with s1_get_account to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdstringyesSentinelOne's own id for the accounts and licensing resource this call targets.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/accounts//reactivate schema expects.

[SentinelOne] DESTRUCTIVE — Discard the account's own policy and revert it to inherit from the level above. Every explicit setting on the account is lost in one call, and every site, group and agent inheriting from it starts enforcing the parent's settings instead. Read s1_get_account_policy first and keep a copy — there is no undo. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdstringyesSentinelOne's own id for the accounts and licensing resource this call targets.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/accounts//revert-policy schema expects.

[SentinelOne] DESTRUCTIVE — Revoke the account's agent uninstall password. Nobody can uninstall an agent with the old password afterwards, which will block a legitimate decommission until a new password is generated. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdstringyesSentinelOne's own id for the accounts and licensing resource this call targets.

[SentinelOne] DESTRUCTIVE — Change an account's fields, which include its license allocation and expiration. Read the current values with s1_get_account and send them back with your change — the vendor treats this as a replace, so an omitted field is a changed field, and a dropped license number reaches every site beneath the account. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdstringyesSentinelOne's own id for the accounts and licensing resource this call targets.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/accounts/ schema expects.

[SentinelOne] DESTRUCTIVE — Change which licensed modules are enabled on sites. This SPENDS LICENSE: enabling a module consumes entitlement and can change what the customer is billed for, and disabling one turns off the protection that module provides on every agent in those sites. Read the current module state with s1_get_sites first. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/licenses/update-sites-modules schema expects.

Console Settings

ToolPlanAccessSummary
s1_clear_pending_emailsProDestructiveDESTRUCTIVE — Cancel every console email that is queued but not yet sent.
s1_create_locationProDestructiveDESTRUCTIVE — Create a console LOCATION.
s1_delete_locationsProDestructiveDESTRUCTIVE — Delete network location definitions.
s1_delete_notification_recipientProDestructiveDESTRUCTIVE — Remove one notification recipient.
s1_get_ad_fqdnsFreeRead-onlyGet AD FQDNs.
s1_get_ad_settingsFreeRead-onlyGet AD Settings.
s1_get_locationsFreeRead-onlyList the network locations defined for a scope, with the parameters that match an agent to each one.
s1_get_notification_recipientsFreeRead-onlyGet Notification Recipients.
s1_get_smtp_settingsFreeRead-onlyGet SMTP Settings.
s1_get_sso_service_provider_certificateFreeRead-onlyGet SSO Service Provider Certificate.
s1_get_sso_settingsFreeRead-onlyGet SSO Settings.
s1_get_syslog_settingsFreeRead-onlyGet Syslog Settings.
s1_get_system_configFreeRead-onlyGet System Config.
s1_get_system_environmentFreeRead-onlySystem Environment.
s1_get_system_infoFreeRead-onlySystem Info.
s1_get_system_statusFreeRead-onlySystem Status.
s1_set_ad_fqdnsProDestructiveDESTRUCTIVE — Replace the Active Directory scope mapping, which decides how directory groups map onto console scopes.
s1_set_ad_settingsProDestructiveDESTRUCTIVE — Replace the console's Active Directory configuration.
s1_set_notification_recipientsProDestructiveDESTRUCTIVE — Replace the list of people who receive console notifications.
s1_set_notification_settingsProDestructiveDESTRUCTIVE — Replace the console's notification settings, which decide which events generate mail and to whom.
s1_set_smtp_settingsProDestructiveDESTRUCTIVE — Replace the console's SMTP configuration.
s1_set_sso_settingsProDestructiveDESTRUCTIVE — Replace the console's SSO configuration.
s1_set_syslog_settingsProDestructiveDESTRUCTIVE — Replace the console's syslog forwarding configuration.
s1_set_system_configProDestructiveDESTRUCTIVE — Replace the console's system configuration.
s1_test_ad_settingsProDestructiveDESTRUCTIVE — Test AD Settings.
s1_test_smtp_settingsProDestructiveDESTRUCTIVE — Test SMTP Settings.
s1_test_sso_settingsProDestructiveDESTRUCTIVE — Test SSO Settings.
s1_test_syslog_settingsProDestructiveDESTRUCTIVE — Test Syslog Settings.
s1_update_locationProDestructiveDESTRUCTIVE — Edit a console LOCATION.

[SentinelOne] DESTRUCTIVE — Cancel every console email that is queued but not yet sent. Anything waiting in the queue is discarded, including user invitations and verification mail people are currently waiting on, and there is no way to replay it — the messages have to be triggered again. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/settings/notifications/cancel-pending-emails schema expects.

[SentinelOne] DESTRUCTIVE — Create a console LOCATION. A location is not a label: agents apply the Firewall Control rules whose Location Aware parameters match their location, so adding one changes which rule set live endpoints enforce. A 200 response does not prove the change landed — re-read with s1_get_locations to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/locations schema expects.

[SentinelOne] DESTRUCTIVE — Delete network location definitions. Agents that matched a deleted location fall back to the fallback location's Firewall Control rules, so this changes what live endpoints enforce without touching any agent or any firewall rule. Read s1_get_locations first, and check `hasFirewallRules` to see which rules are tied to the location. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/locations schema expects.

[SentinelOne] DESTRUCTIVE — Remove one notification recipient. That address stops receiving console alert mail immediately, which is invisible until an alert is missed. Confirm the recipient with s1_get_notification_recipients first. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
recipientIdstringyesSentinelOne's own id for the console settings resource this call targets.

[SentinelOne] Get AD FQDNs. Scope to one customer with siteIds / accountIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Get AD Settings. Scope to one customer with siteIds / accountIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] List the network locations defined for a scope, with the parameters that match an agent to each one. Locations select which Firewall Control rules an agent enforces, so read this before changing firewall behavior. Filter on `hasFirewallRules` through filtersJson to find a location that no rule matches, which is the usual cause of an endpoint falling back to the fallback rule set. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Set countOnly=true to size a filter before acting on it. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
idsstringnonullComma-separated list of ids to restrict the result to.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Get Notification Recipients. Scope to one customer with siteIds / accountIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
searchQuerystringnonullFree-text search over the resource, as SentinelOne's own console search box would apply it.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Get SMTP Settings. Scope to one customer with siteIds / accountIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Get SSO Service Provider Certificate. Scope to one customer with siteIds / accountIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Get SSO Settings. Scope to one customer with siteIds / accountIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Get Syslog Settings. Scope to one customer with siteIds / accountIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Get System Config. Scope to one customer with siteIds / accountIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] System Environment. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

[SentinelOne] System Info. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

[SentinelOne] System Status. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

[SentinelOne] DESTRUCTIVE — Replace the Active Directory scope mapping, which decides how directory groups map onto console scopes. Changing it moves administrators between scopes, widening or removing their reach without touching any user record. Read the current mapping with s1_get_ad_fqdns and send the complete set — this is a replace, so an omitted entry is a removed entry. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/settings/active-directory/scope-mapping schema expects.

[SentinelOne] DESTRUCTIVE — Replace the console's Active Directory configuration. This governs how directory identities map into the console, so a wrong value can cut off directory-backed sign-in for every administrator. Read the current configuration with s1_get_ad_settings, keep a copy, and validate with s1_test_ad_settings before you write. This is a replace, so an omitted field is a changed field. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/settings/active-directory schema expects.

[SentinelOne] DESTRUCTIVE — Replace the list of people who receive console notifications. This REACHES PEOPLE both ways: addresses you add start receiving alert mail, and addresses you omit stop receiving it, so an incomplete body silently unsubscribes the on-call rota. Read the current list with s1_get_notification_recipients and send it back with your change. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/settings/recipients schema expects.

[SentinelOne] DESTRUCTIVE — Replace the console's notification settings, which decide which events generate mail and to whom. Turning a category off stops alerts nobody will notice are missing until an incident is missed. Read the current settings first and send them back with your change — this is a replace, so an omitted field is a changed field. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/settings/notifications schema expects.

[SentinelOne] DESTRUCTIVE — Replace the console's SMTP configuration. Every console notification and every user invitation is delivered through this, so a bad value silently stops all of them — including the verification emails users need to regain access. Read the current configuration with s1_get_smtp_settings, keep a copy, and validate with s1_test_smtp_settings before you write. This is a replace, so an omitted field is a changed field. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/settings/smtp schema expects.

[SentinelOne] DESTRUCTIVE — Replace the console's SSO configuration. Getting this wrong locks every federated administrator out of the SentinelOne console, and fixing it then needs a local account that may not exist. Read the current configuration with s1_get_sso_settings, keep a copy, and validate with s1_test_sso_settings before you write. This is a replace, so an omitted field is a changed field. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/settings/sso schema expects.

[SentinelOne] DESTRUCTIVE — Replace the console's syslog forwarding configuration. If the customer's SIEM ingests SentinelOne through this, a wrong value stops the feed silently and the gap is only visible downstream. Read the current configuration with s1_get_syslog_settings, keep a copy, and validate with s1_test_syslog_settings before you write. This is a replace, so an omitted field is a changed field. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/settings/syslog schema expects.

[SentinelOne] DESTRUCTIVE — Replace the console's system configuration. These are tenant-wide settings, so the blast radius is the whole console and a wrong value is visible to every administrator. Read the current configuration with s1_get_system_config and keep a copy — this is a replace, so an omitted field is a changed field. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/system/configuration schema expects.

[SentinelOne] DESTRUCTIVE — Test AD Settings. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/settings/active-directory/test schema expects.

[SentinelOne] DESTRUCTIVE — Test SMTP Settings. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/settings/smtp/test schema expects.

[SentinelOne] DESTRUCTIVE — Test SSO Settings. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/settings/sso/test schema expects.

[SentinelOne] DESTRUCTIVE — Test Syslog Settings. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/settings/syslog/test schema expects.

[SentinelOne] DESTRUCTIVE — Edit a console LOCATION. Locations select which Firewall Control rules an agent enforces, so an edit silently re-points live endpoints at a different rule set. This is a replace, so an omitted field is a cleared field: read the current location with s1_get_locations and send the complete object. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/locations/ schema expects.
locationIdstringyesSentinelOne's own id for the console settings resource this call targets.

Graph Explorer

ToolPlanAccessSummary
s1_delete_graph_queryProDestructiveDESTRUCTIVE — Delete graph query.
s1_get_asset_query_builder_metadataFreeRead-onlyGet Graph Query Builder Initial Metadata.
s1_get_available_relationsFreeRead-onlyGet the available relations.
s1_get_graph_explorer_autocompleteFreeRead-onlyAuto Complete.
s1_get_graph_query_builder_metadataFreeRead-onlyGet Graph Query Builder Initial Metadata.
s1_get_graph_query_builder_optionsFreeRead-onlyGet Query Builder metadata For Requested Resource Types.
s1_get_graph_query_listFreeRead-onlyList the saved Graph Explorer queries, with the owner and the query definition of each.
s1_get_graph_query_type_countsFreeRead-onlyGet graph query counts by type.
s1_get_graph_recent_query_listFreeRead-onlyGet graph recent query list.
s1_get_graph_services_feature_togglesFreeRead-onlyGet all of the feature toggles for graph services.
s1_get_tag_autocompleteFreeRead-onlyTag Auto Complete.
s1_query_graph_explorerFreeRead-onlyQuery the graph based on query builder filters.
s1_query_graph_explorer_v2FreeRead-onlyQuery the graph based on query builder filters.
s1_query_subgraphFreeRead-onlyQuery the sub graph of an asset type and id.
s1_save_graph_queryProWriteSave graph query.
s1_update_graph_queryProWriteUpdate graph query.

[SentinelOne] DESTRUCTIVE — Delete graph query. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
queryIdstringyesSentinelOne's own id for the graph explorer resource this call targets.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Get Graph Query Builder Initial Metadata. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Get the available relations. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Auto Complete. Scope to one customer with siteIds / accountIds / groupIds. SentinelOne requires key on this endpoint — pass it in filtersJson or the call fails with a 400. key: the search field key, one of the documented `<field>__contains` names. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
idsstringnonullComma-separated list of ids to restrict the result to.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Get Graph Query Builder Initial Metadata. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Get Query Builder metadata For Requested Resource Types. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
idsstringnonullComma-separated list of ids to restrict the result to.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] List the saved Graph Explorer queries, with the owner and the query definition of each. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Set countOnly=true to size a filter before acting on it. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Get graph query counts by type. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Get graph recent query list. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Get all of the feature toggles for graph services. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Tag Auto Complete. This is a POST that READS: the criteria travel in the request body, and nothing is created or changed. Scope to one customer with siteIds / accountIds / groupIds. SentinelOne requires field on this endpoint — pass it in filtersJson or the call fails with a 400. field: search in keys or values, one of 'key' or 'value'. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
idsstringnonullComma-separated list of ids to restrict the result to.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Query the graph based on query builder filters. This is a POST that READS: the criteria travel in the request body, and nothing is created or changed. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/graph-explorer/query/explorer schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Query the graph based on query builder filters. This is a POST that READS: the criteria travel in the request body, and nothing is created or changed. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/graph-explorer/query/explorer/v2 schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Query the sub graph of an asset type and id. This is a POST that READS: the criteria travel in the request body, and nothing is created or changed. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/graph-explorer/query/subgraph schema expects.
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Save graph query. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/graph-explorer/query/management/query schema expects.
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Update graph query. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/graph-explorer/query/management/query/ schema expects.
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
queryIdstringyesSentinelOne's own id for the graph explorer resource this call targets.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

Groups and Tags

ToolPlanAccessSummary
s1_create_endpoint_tagProWriteCreate a new endpoint tag.
s1_create_groupProWriteCreate Group.
s1_create_tag_ruleProWriteCreate new tag rule.
s1_create_tagsProWriteCreate Tags.
s1_delete_endpoint_tagsProDestructiveDESTRUCTIVE — Delete endpoint tags from Tag Manager.
s1_delete_groupProDestructiveDESTRUCTIVE — Delete an agent group.
s1_delete_tagProDestructiveDESTRUCTIVE — Delete one asset tag by its id.
s1_delete_tag_rulesProDestructiveDESTRUCTIVE — Delete asset tag rules.
s1_delete_tagsProDestructiveDESTRUCTIVE — Delete asset tags in bulk, by the criteria in the body rather than by a single id.
s1_get_groupFreeRead-onlyGet one agent group by its id, including its rank, type, filter definition and the site it belongs to.
s1_get_group_registration_tokenFreeRead-onlyGet Site registration token by ID.
s1_get_groupsFreeRead-onlyList the agent groups that match the filter, with the site each belongs to, its rank, its type (static or dynamic) and its agent count.
s1_get_tag_rulesFreeRead-onlyGet all tags rules.
s1_get_tagsFreeRead-onlyList the asset tags that match the filter, with the scope of each.
s1_move_agentsProDestructiveDESTRUCTIVE — Move agents into a group by FILTER, not by a list of ids.
s1_regenerate_group_tokenProDestructiveDESTRUCTIVE — Regenerate a group's registration token.
s1_revert_group_policyProDestructiveDESTRUCTIVE — Discard the group's own policy and revert it to inherit from the site.
s1_test_tag_rule_match_countFreeRead-onlyCheck how many assets this tag rule matches.
s1_update_endpoint_tagProWriteEdit an existing tag.
s1_update_groupProDestructiveDESTRUCTIVE — Update Group.
s1_update_group_ranksProDestructiveDESTRUCTIVE — Reorder group ranks.
s1_update_tagProWriteEdit Tag.
s1_update_tag_ruleProWriteUpdate tag rule.

[SentinelOne] Create a new endpoint tag. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/tag-manager schema expects.

[SentinelOne] Create Group. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/groups schema expects.

[SentinelOne] Create new tag rule. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/assets/tags/rules schema expects.
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Create Tags. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/tags schema expects.

[SentinelOne] DESTRUCTIVE — Delete endpoint tags from Tag Manager. Any console view, dynamic group or automation that selects on a deleted tag stops matching, so agents can silently move between dynamic groups and therefore between policies. This is the Tag Manager set, not the asset tags that s1_delete_tags removes. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/tag-manager schema expects.

[SentinelOne] DESTRUCTIVE — Delete an agent group. The agents in it are not deleted, but they move out of the group and therefore stop receiving the group's policy and inherit the site policy instead, which is a live change to what those endpoints enforce. Check the agent count with s1_get_group first. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
groupIdstringyesSentinelOne's own id for the groups and tags resource this call targets.

[SentinelOne] DESTRUCTIVE — Delete one asset tag by its id. Anything selecting on it stops matching. Confirm the tag with s1_get_tags first — asset tag ids and Tag Manager endpoint tag ids are different sets and are not interchangeable. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
tagIdstringyesSentinelOne's own id for the groups and tags resource this call targets.

[SentinelOne] DESTRUCTIVE — Delete asset tag rules. The tags those rules applied automatically stop being maintained, so assets drift out of the tag over time and anything selecting on it quietly narrows. Read s1_get_tag_rules first, and s1_test_tag_rule_match_count to see how many assets a rule currently covers. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
idsstringnonullComma-separated list of ids to restrict the result to.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] DESTRUCTIVE — Delete asset tags in bulk, by the criteria in the body rather than by a single id. Anything selecting on a deleted tag stops matching. This is the asset tag set; the Tag Manager endpoint tags are removed by s1_delete_endpoint_tags. A 200 response does not prove the change landed — the `affected` count can be 0. Re-read with s1_get_tags to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/tags schema expects.

[SentinelOne] Get one agent group by its id, including its rank, type, filter definition and the site it belongs to. Get the id from s1_get_groups. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
groupIdstringyesSentinelOne's own id for the groups and tags resource this call targets.

[SentinelOne] Get Site registration token by ID. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
groupIdstringyesSentinelOne's own id for the groups and tags resource this call targets.

[SentinelOne] List the agent groups that match the filter, with the site each belongs to, its rank, its type (static or dynamic) and its agent count. Groups are how policy is applied below the site, so read this before moving agents or editing group policy. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Set countOnly=true to size a filter before acting on it. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
searchQuerystringnonullFree-text search over the resource, as SentinelOne's own console search box would apply it.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Get all tags rules. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
idsstringnonullComma-separated list of ids to restrict the result to.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] List the asset tags that match the filter, with the scope of each. These are the tags applied to inventory assets; the endpoint tag set that Tag Manager owns is a separate list. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Set countOnly=true to size a filter before acting on it. SentinelOne requires type on this endpoint — pass it in filtersJson or the call fails with a 400. type: the tag type, for example firewall. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
idsstringnonullComma-separated list of ids to restrict the result to.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
searchQuerystringnonullFree-text search over the resource, as SentinelOne's own console search box would apply it.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] DESTRUCTIVE — Move agents into a group by FILTER, not by a list of ids. The agents that move immediately start enforcing the destination group's policy instead of their old one, so a wrong or empty filter re-points protection for a whole fleet and SentinelOne answers 200 either way. Run the matching agent read with countOnly=true and the SAME filter first, and read the destination policy with s1_get_group_policy. A 200 response does not prove the change landed — the `affected` count can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/groups//move-agents schema expects.
groupIdstringyesSentinelOne's own id for the groups and tags resource this call targets.

[SentinelOne] DESTRUCTIVE — Regenerate a group's registration token. Every installer and deployment script carrying the old token stops being able to enroll agents into that group — already-installed agents keep working, but your deployment tooling breaks until it is updated with the new value from s1_get_group_registration_token. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
groupIdstringyesSentinelOne's own id for the groups and tags resource this call targets.

[SentinelOne] DESTRUCTIVE — Discard the group's own policy and revert it to inherit from the site. Every explicit setting on the group is lost in one call, and its agents start enforcing the site's settings instead. Read s1_get_group_policy first and keep a copy — there is no undo. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/groups//revert-policy schema expects.
groupIdstringyesSentinelOne's own id for the groups and tags resource this call targets.

[SentinelOne] Check how many assets this tag rule matches. This is a POST that READS: the criteria travel in the request body, and nothing is created or changed. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/assets/tags/rules/test schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Edit an existing tag. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/tag-manager/ schema expects.
tagIdstringyesSentinelOne's own id for the groups and tags resource this call targets.

[SentinelOne] DESTRUCTIVE — Update Group. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/groups/ schema expects.
groupIdstringyesSentinelOne's own id for the groups and tags resource this call targets.

[SentinelOne] DESTRUCTIVE — Reorder group ranks. Rank decides which dynamic group claims an agent when several match, so reordering silently moves endpoints between groups and therefore between policies, without touching any agent directly. Read the current order with s1_get_groups first and send the complete ordering. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/groups/ranks schema expects.

[SentinelOne] Edit Tag. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/tags/ schema expects.
tagIdstringyesSentinelOne's own id for the groups and tags resource this call targets.

[SentinelOne] Update tag rule. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/assets/tags/rules schema expects.
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

Log Collection

ToolPlanAccessSummary
s1_change_activation_status_log_collection_rulesProDestructiveDESTRUCTIVE — Activate or deactivate log collection rules.
s1_create_log_collection_ruleProWriteCreate a log collection rule.
s1_delete_log_collection_rulesProDestructiveDESTRUCTIVE — Delete log collection rules.
s1_export_log_collection_rulesFreeRead-onlyExport the log collection rules matching the filter.
s1_get_log_collection_agent_type_countsFreeRead-onlyGet Agent type count.
s1_get_log_collection_rulesFreeRead-onlyList the log collection rules that match the filter, with the scope, agent type and activation state of each.
s1_get_log_collection_rules_by_agent_typeFreeRead-onlyGet Log Collection rules by agent type.
s1_update_log_collection_ruleProDestructiveDESTRUCTIVE — Change a log collection rule.

[SentinelOne] DESTRUCTIVE — Activate or deactivate log collection rules. This is the switch that makes a rule live: activating one starts agents collecting and shipping logs, and deactivating one stops the feed a SIEM may depend on. Read the current state with s1_get_log_collection_rules first. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/log-collection/rules/activation schema expects.

[SentinelOne] Create a log collection rule. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/log-collection/rules schema expects.

[SentinelOne] DESTRUCTIVE — Delete log collection rules. The agents in scope stop shipping the logs those rules collected, so a downstream SIEM or investigation loses its source silently — the gap only shows up later, when the data is needed. Read s1_get_log_collection_rules first. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/log-collection/rules schema expects.

[SentinelOne] Export the log collection rules matching the filter. NOTE: SentinelOne serves this endpoint as a CSV file. StackJack tools return JSON, so this call reports a content-type error rather than a file — use s1_get_log_collection_rules, which returns the same rules as JSON and pages properly. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
idsstringnonullComma-separated list of ids to restrict the result to.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Get Agent type count. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] List the log collection rules that match the filter, with the scope, agent type and activation state of each. A rule only ships logs once it is activated, so check the state here rather than assuming a created rule is live. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Set countOnly=true to size a filter before acting on it. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
idsstringnonullComma-separated list of ids to restrict the result to.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Get Log Collection rules by agent type. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
agentTypestringyesSentinelOne's own id for the log collection resource this call targets.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
idsstringnonullComma-separated list of ids to restrict the result to.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] DESTRUCTIVE — Change a log collection rule. If the rule is active the change reaches live agents, altering which paths and logs they collect, so an over-broad path can flood ingest and a narrowed one silently drops the source a SIEM depends on. Read the current rule with s1_get_log_collection_rules and send it back with your change. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/log-collection/rules/ schema expects.
ruleIdstringyesSentinelOne's own id for the log collection resource this call targets.

Policies

ToolPlanAccessSummary
s1_get_account_policyFreeRead-onlyAccount Policy.
s1_get_global_policyFreeRead-onlyGlobal Policy.
s1_get_group_policyFreeRead-onlyGroup Policy.
s1_get_site_policyFreeRead-onlySite Policy.
s1_update_account_policyProDestructiveDESTRUCTIVE — Replace an account's agent policy.
s1_update_global_policyProDestructiveDESTRUCTIVE — Replace the tenant-wide agent policy.
s1_update_group_policyProDestructiveDESTRUCTIVE — Replace a group's agent policy.
s1_update_site_policyProDestructiveDESTRUCTIVE — Replace a site's agent policy.

[SentinelOne] Account Policy. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdstringyesSentinelOne's own id for the policies resource this call targets.

[SentinelOne] Global Policy. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

[SentinelOne] Group Policy. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
groupIdstringyesSentinelOne's own id for the policies resource this call targets.

[SentinelOne] Site Policy. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
siteIdstringyesSentinelOne's own id for the policies resource this call targets.

[SentinelOne] DESTRUCTIVE — Replace an account's agent policy. It reaches every site, group and agent beneath the account that inherits, and it changes what those endpoints actually enforce — detection mode, protection actions, engines. Read the current policy with s1_get_account_policy and send it back with your change; this is a replace, so an omitted field is a changed field. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdstringyesSentinelOne's own id for the policies resource this call targets.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/accounts//policy schema expects.

[SentinelOne] DESTRUCTIVE — Replace the tenant-wide agent policy. This is the widest protection change in the connector: it reaches every account, every site and every agent that inherits from global, and it takes effect as agents check in. Read the current policy with s1_get_global_policy and send it back with your change — this is a replace, so an omitted field is a changed field. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/tenant/policy schema expects.

[SentinelOne] DESTRUCTIVE — Replace a group's agent policy. Every agent in the group starts enforcing the new settings as it checks in, so this changes live protection for those endpoints. Read the current policy with s1_get_group_policy and send it back with your change; this is a replace, so an omitted field is a changed field. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/groups//policy schema expects.
groupIdstringyesSentinelOne's own id for the policies resource this call targets.

[SentinelOne] DESTRUCTIVE — Replace a site's agent policy. Every group and agent under the site that inherits starts enforcing the new settings as it checks in, so this changes live protection for one customer. Read the current policy with s1_get_site_policy and send it back with your change; this is a replace, so an omitted field is a changed field. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/sites//policy schema expects.
siteIdstringyesSentinelOne's own id for the policies resource this call targets.

Reports

ToolPlanAccessSummary
s1_create_default_report_taskProDestructiveDESTRUCTIVE — Create a scheduled report task.
s1_delete_default_report_tasksProDestructiveDESTRUCTIVE — Delete Default Report Tasks.
s1_delete_default_reportsProDestructiveDESTRUCTIVE — Delete Default Reports.
s1_download_default_reportFreeRead-onlyFetch a generated default report by id.
s1_get_default_report_tasksFreeRead-onlyList the report tasks that generate default reports now or on a schedule, including the recipients each task mails its report to.
s1_get_default_reportsFreeRead-onlyList the generated default reports that match the filter, with the schedule, insight type, date range and the user who created each one.
s1_get_report_insight_typesFreeRead-onlyGet Default Insight Reports.
s1_get_rss_feedFreeRead-onlyS1 RSS Feed.
s1_update_default_report_taskProDestructiveDESTRUCTIVE — Edit a scheduled report task.

[SentinelOne] DESTRUCTIVE — Create a scheduled report task. The vendor schema carries a recipients list and attachment types, so this can mail console data with attachments to arbitrary addresses, immediately or on a recurring schedule. Check the recipients in the body before you send it. A 200 response does not prove the change landed — re-read with s1_get_default_report_tasks to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/report-tasks schema expects.

[SentinelOne] DESTRUCTIVE — Delete Default Report Tasks. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/reports/delete-tasks schema expects.

[SentinelOne] DESTRUCTIVE — Delete Default Reports. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/reports/delete-reports schema expects.

[SentinelOne] Fetch a generated default report by id. NOTE: SentinelOne serves this endpoint as a PDF or HTML document, and report_format accepts only pdf or html. StackJack tools return JSON, so this call reports a content-type error rather than a document — use s1_get_default_reports to read the report's metadata, and download the file itself from the SentinelOne console. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
reportFormatstringyesSentinelOne's own id for the reports resource this call targets.
reportIdstringyesSentinelOne's own id for the reports resource this call targets.

[SentinelOne] List the report tasks that generate default reports now or on a schedule, including the recipients each task mails its report to. Read this before creating or editing a task, both to copy the shape of an existing one and to see who is already being emailed. Each task carries many lines, so filter rather than paging blind. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Set countOnly=true to size a filter before acting on it. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
idsstringnonullComma-separated list of ids to restrict the result to.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
searchQuerystringnonullFree-text search over the resource, as SentinelOne's own console search box would apply it.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] List the generated default reports that match the filter, with the schedule, insight type, date range and the user who created each one. Use it to get a report id for s1_download_default_report. Default reports need the Reports permission and the matching license. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Set countOnly=true to size a filter before acting on it. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
idsstringnonullComma-separated list of ids to restrict the result to.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
searchQuerystringnonullFree-text search over the resource, as SentinelOne's own console search box would apply it.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Get Default Insight Reports. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] S1 RSS Feed. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

[SentinelOne] DESTRUCTIVE — Edit a scheduled report task. The edit schema carries the same recipients list, so it can add mail recipients to a task that had none or re-point an existing schedule. This is a replace, so read the current task first and send the complete object. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/report-tasks/ schema expects.
taskIdstringyesSentinelOne's own id for the reports resource this call targets.

Saved Views

ToolPlanAccessSummary
s1_delete_filterProDestructiveDESTRUCTIVE — Delete Filter.
s1_delete_filter_xdrProDestructiveDESTRUCTIVE — Delete Filter.
s1_get_enriched_filtersFreeRead-onlyFilters with Metadata.
s1_get_filtersFreeRead-onlyList the saved filters (saved console views) that match the request, with the scope and the criteria each one stores.
s1_get_filters_xdrFreeRead-onlyGet Filters.
s1_save_filterProWriteSave Filter.
s1_save_filter_xdrProWriteSave Filter.
s1_update_filterProWriteUpdate Filter.
s1_update_filter_xdrProWriteUpdate Filter.
s1_upload_csv_filterProWriteUpload CSV file.

[SentinelOne] DESTRUCTIVE — Delete Filter. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
filterIdstringyesSentinelOne's own id for the saved views resource this call targets.

[SentinelOne] DESTRUCTIVE — Delete Filter. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
filterIdstringyesSentinelOne's own id for the saved views resource this call targets.

[SentinelOne] Filters with Metadata. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
idsstringnonullComma-separated list of ids to restrict the result to.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
searchQuerystringnonullFree-text search over the resource, as SentinelOne's own console search box would apply it.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] List the saved filters (saved console views) that match the request, with the scope and the criteria each one stores. Saved filters are presentation only — they name a view, they never widen what a credential can reach. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Set countOnly=true to size a filter before acting on it. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
idsstringnonullComma-separated list of ids to restrict the result to.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
searchQuerystringnonullFree-text search over the resource, as SentinelOne's own console search box would apply it.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Get Filters. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
idsstringnonullComma-separated list of ids to restrict the result to.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
searchQuerystringnonullFree-text search over the resource, as SentinelOne's own console search box would apply it.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Save Filter. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/filters schema expects.

[SentinelOne] Save Filter. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/filters schema expects.

[SentinelOne] Update Filter. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/filters/ schema expects.
filterIdstringyesSentinelOne's own id for the saved views resource this call targets.

[SentinelOne] Update Filter. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/filters/ schema expects.
filterIdstringyesSentinelOne's own id for the saved views resource this call targets.

[SentinelOne] Upload CSV file. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).

Sites

ToolPlanAccessSummary
s1_create_siteProWriteCreate a site under an account.
s1_create_site_with_adminProDestructiveDESTRUCTIVE — Create a site AND its first administrator in one call.
s1_delete_siteProDestructiveDESTRUCTIVE — Delete a site.
s1_expire_siteProDestructiveDESTRUCTIVE — Expire a site immediately.
s1_get_siteFreeRead-onlyGet one site by its id, including its state, expiration date, license counts, policy inheritance and the account it belongs to.
s1_get_site_local_upgrade_approved_agentsFreeRead-onlyGet a CSV file of local upgrade/downgrade Site authorization data.
s1_get_site_local_upgrade_authorizationFreeRead-onlyGet local upgrade/downgrade Site authorization.
s1_get_site_registration_tokenFreeRead-onlyGet Site registration token by ID.
s1_get_sitesFreeRead-onlyList the sites that match the filter, with their state, expiration, license counts and the account each belongs to.
s1_reactivate_siteProDestructiveDESTRUCTIVE — Reactivate an expired site.
s1_regenerate_site_keyProDestructiveDESTRUCTIVE — Regenerate a site's registration token.
s1_revert_site_policyProDestructiveDESTRUCTIVE — Discard the site's own policy and revert it to inherit from the account.
s1_set_site_local_upgrade_authorizationProDestructiveDESTRUCTIVE — Change which agents in a site are authorized to be upgraded or DOWNGRADED locally, at the endpoint.
s1_update_siteProDestructiveDESTRUCTIVE — Change a site's fields, which include its license allocation, expiration and policy inheritance.
s1_update_sites_bulkProDestructiveDESTRUCTIVE — Change many sites in one call.

[SentinelOne] Create a site under an account. A new site begins consuming license against the account's entitlement, and its policy inheritance decides what agents enrolled into it will enforce. Check remaining entitlement with s1_get_account first. A 200 response does not prove the change landed — re-read with s1_get_sites to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/sites schema expects.

[SentinelOne] DESTRUCTIVE — Create a site AND its first administrator in one call. Two things happen: a new site starts consuming license, and a console user is created with administrative rights over it, which normally means an invitation email is sent. This is not the same as adding a user to an existing site — use s1_create_site for a site alone. A 200 response does not prove the change landed — re-read with s1_get_sites to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/site-with-admin schema expects.

[SentinelOne] DESTRUCTIVE — Delete a site. This removes the customer container itself, along with its groups and its policy, and the agents registered to it lose their site. Prefer s1_expire_site for offboarding, which stops the site while leaving its data readable. Confirm the site with s1_get_site and check its agent count first. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
siteIdstringyesSentinelOne's own id for the sites resource this call targets.

[SentinelOne] DESTRUCTIVE — Expire a site immediately. The site stops consuming license and its agents stop being managed from the console, which is a customer-visible loss of protection management. This is the offboarding verb; s1_reactivate_site is the way back. Confirm the site with s1_get_site first. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
siteIdstringyesSentinelOne's own id for the sites resource this call targets.

[SentinelOne] Get one site by its id, including its state, expiration date, license counts, policy inheritance and the account it belongs to. Get the id from s1_get_sites. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
siteIdstringyesSentinelOne's own id for the sites resource this call targets.

[SentinelOne] Get a CSV file of local upgrade/downgrade Site authorization data. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
siteIdstringyesSentinelOne's own id for the sites resource this call targets.

[SentinelOne] Get local upgrade/downgrade Site authorization. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
siteIdstringyesSentinelOne's own id for the sites resource this call targets.

[SentinelOne] Get Site registration token by ID. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
siteIdstringyesSentinelOne's own id for the sites resource this call targets.

[SentinelOne] List the sites that match the filter, with their state, expiration, license counts and the account each belongs to. A SITE is normally one customer, so this is the usual first call when scoping any other tool to a single customer — take siteIds from here. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Set countOnly=true to size a filter before acting on it. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
searchQuerystringnonullFree-text search over the resource, as SentinelOne's own console search box would apply it.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] DESTRUCTIVE — Reactivate an expired site. The site starts consuming license again and its agents return to managed state, so this is a billing-relevant action as well as an operational one. A 200 response does not prove the change landed — re-read with s1_get_site to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/sites//reactivate schema expects.
siteIdstringyesSentinelOne's own id for the sites resource this call targets.

[SentinelOne] DESTRUCTIVE — Regenerate a site's registration token. Every installer and deployment script carrying the old token stops being able to enroll new agents — already-installed agents keep working, but your deployment tooling breaks until it is updated with the new value from s1_get_site_registration_token. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
siteIdstringyesSentinelOne's own id for the sites resource this call targets.

[SentinelOne] DESTRUCTIVE — Discard the site's own policy and revert it to inherit from the account. Every explicit setting on the site is lost in one call, and its groups and agents start enforcing the account's settings instead. Read s1_get_site_policy first and keep a copy — there is no undo. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/sites//revert-policy schema expects.
siteIdstringyesSentinelOne's own id for the sites resource this call targets.

[SentinelOne] DESTRUCTIVE — Change which agents in a site are authorized to be upgraded or DOWNGRADED locally, at the endpoint. Authorizing a downgrade lets someone with local access move an agent to an older build, which is a protection-posture decision, not a maintenance one. Read the current authorization with s1_get_site_local_upgrade_authorization first. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/sites//local-authorization schema expects.
siteIdstringyesSentinelOne's own id for the sites resource this call targets.

[SentinelOne] DESTRUCTIVE — Change a site's fields, which include its license allocation, expiration and policy inheritance. Read the current values with s1_get_site and send them back with your change — the vendor treats this as a replace, so an omitted field is a changed field. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/sites/ schema expects.
siteIdstringyesSentinelOne's own id for the sites resource this call targets.

[SentinelOne] DESTRUCTIVE — Change many sites in one call. The blast radius is every site in the body, and the same replace semantics apply to each, so an omitted field is a changed field across all of them at once. Read the current values with s1_get_sites first. A 200 response does not prove the change landed — the `affected` count can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/sites/update-bulk schema expects.

Users and Roles

ToolPlanAccessSummary
s1_bulk_delete_service_usersProDestructiveDESTRUCTIVE — Delete every service user matching a FILTER, not a list of ids.
s1_bulk_delete_usersProDestructiveDESTRUCTIVE — Delete every console user matching a FILTER, not a list of ids.
s1_check_remote_shell_permissionsFreeRead-onlyCheck Remote Shell Permissions.
s1_check_tenant_admin_authFreeRead-onlyCheck Global User.
s1_check_viewer_authFreeRead-onlyCheck Viewer.
s1_create_roleProDestructiveDESTRUCTIVE — Create an RBAC role with a permission set.
s1_create_service_userProDestructiveDESTRUCTIVE — Create a service user, which is an API-only identity, and mint its API token.
s1_create_userProDestructiveDESTRUCTIVE — Create a console user with a role and a scope.
s1_delete_roleProDestructiveDESTRUCTIVE — Delete an RBAC role.
s1_delete_service_userProDestructiveDESTRUCTIVE — Delete a service user.
s1_delete_userProDestructiveDESTRUCTIVE — Delete a console user.
s1_enable_2fa_appProDestructiveDESTRUCTIVE — Complete two-factor enrollment for a console user by confirming the app code.
s1_generate_api_tokenProDestructiveDESTRUCTIVE — Mint a new API token for a console user.
s1_generate_api_token_service_userProDestructiveDESTRUCTIVE — Mint a new API token for a service user.
s1_generate_iframe_tokenProDestructiveDESTRUCTIVE — Mint a short-lived token that embeds the SentinelOne console in an iframe.
s1_get_current_userFreeRead-onlyGet the console user that owns the API token this connector is using, with their role and scope.
s1_get_new_role_templateFreeRead-onlyGet template for new role.
s1_get_roleFreeRead-onlyGet one RBAC role by its id, with the full permission list it grants.
s1_get_rolesFreeRead-onlyList the RBAC roles defined in the console, with the scope each is defined at and the number of users assigned.
s1_get_service_userFreeRead-onlyGet Service User.
s1_get_service_usersFreeRead-onlyList the service users that match the filter, with their scope, role and token expiry.
s1_get_userFreeRead-onlyGet one console user by their id, including role, scope, two-factor state and last login.
s1_get_user_api_token_detailsFreeRead-onlyAPI Token by User ID.
s1_list_usersFreeRead-onlyList the console users that match the filter, with their role, scope, last login and whether they have verified their email.
s1_request_2fa_appProDestructiveDESTRUCTIVE — Start two-factor enrollment for a console user, which returns the secret the authenticator app needs.
s1_revoke_api_tokenProDestructiveDESTRUCTIVE — Revoke a user's API token.
s1_send_verification_emailProDestructiveDESTRUCTIVE — Send the onboarding verification email to every user matching a FILTER.
s1_update_roleProDestructiveDESTRUCTIVE — Change an RBAC role's permission set.
s1_update_service_userProDestructiveDESTRUCTIVE — Change a service user's fields, including its role and scope.
s1_update_userProDestructiveDESTRUCTIVE — Change a console user's fields, which include their role and their scope.
s1_verify_onboarding_emailProDestructiveDESTRUCTIVE — Redeem an onboarding verification token and SET THAT USER'S PASSWORD.

[SentinelOne] DESTRUCTIVE — Delete every service user matching a FILTER, not a list of ids. This can revoke every API integration in scope at once, this connector included, and SentinelOne answers 200 either way. Run s1_get_service_users with the SAME filter and countOnly=true first, and check s1_get_current_user to see whether your own identity is in the set. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/service-users/delete-service-users schema expects.

[SentinelOne] DESTRUCTIVE — Delete every console user matching a FILTER, not a list of ids. A wrong or empty filter is how you remove every administrator in scope, and SentinelOne answers 200 either way. Run s1_list_users with the SAME filter and countOnly=true first and read the count. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/users/delete-users schema expects.

[SentinelOne] Check Remote Shell Permissions. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

[SentinelOne] Check Global User. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

[SentinelOne] Check Viewer. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

[SentinelOne] DESTRUCTIVE — Create an RBAC role with a permission set. This is privilege-widening: whatever permissions you name become grantable to console users and to API service users, so an over-broad role is a standing escalation path. Start from s1_get_new_role_template for the permission vocabulary, and grant the narrowest set that does the job. A 200 response does not prove the change landed — re-read with s1_get_roles to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/rbac/role schema expects.

[SentinelOne] DESTRUCTIVE — Create a service user, which is an API-only identity, and mint its API token. The token is returned ONCE in this response and cannot be read back afterwards — capture it or it is lost. Treat the response as a credential: it grants API access at the role and scope you name, so pick the narrowest of both. A 200 response does not prove the change landed — re-read with s1_get_service_users to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/service-users schema expects.

[SentinelOne] DESTRUCTIVE — Create a console user with a role and a scope. This mints console access for a person and, if the console has onboarding enabled, EMAILS them an invitation. Give the narrowest role and the narrowest scope that does the job — read s1_get_roles first. A 200 response does not prove the change landed — re-read with s1_list_users to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/users schema expects.

[SentinelOne] DESTRUCTIVE — Delete an RBAC role. Every user and service user assigned to it loses the permissions it granted, so console access and running integrations can break at once. Read s1_get_role to see the permission set and s1_get_roles to see how many identities are assigned before you delete. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/rbac/role/ schema expects.
roleIdstringyesSentinelOne's own id for the users and roles resource this call targets.

[SentinelOne] DESTRUCTIVE — Delete a service user. Every API token issued to that identity stops working at once, so any integration built on it breaks — including this StackJack connector, if you delete the identity it authenticates as. Check with s1_get_current_user before deleting a service user. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
serviceUserIdstringyesSentinelOne's own id for the users and roles resource this call targets.

[SentinelOne] DESTRUCTIVE — Delete a console user. The person loses access to the SentinelOne console immediately, and anything they owned, such as saved views and report tasks, is orphaned. Confirm the identity with s1_get_user first — user ids and service user ids look alike and are not interchangeable. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
userIdstringyesSentinelOne's own id for the users and roles resource this call targets.

[SentinelOne] DESTRUCTIVE — Complete two-factor enrollment for a console user by confirming the app code. From here on that person needs their authenticator to sign in, so losing the device means an administrator has to reset it. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/users/enable-app schema expects.

[SentinelOne] DESTRUCTIVE — Mint a new API token for a console user. The token is returned ONCE in this response and cannot be read back — capture it or it is lost. It carries that user's full role and scope, so it is a credential with real reach, and minting one INVALIDATES that user's previous token, which breaks any integration still using it. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/users/generate-api-token schema expects.

[SentinelOne] DESTRUCTIVE — Mint a new API token for a service user. The token is returned ONCE in this response and cannot be read back — capture it or it is lost, and treat it as a credential carrying that service user's role and scope. Any integration still holding the previous token for this identity stops working. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/service-users//generate-api-token schema expects.
serviceUserIdstringyesSentinelOne's own id for the users and roles resource this call targets.

[SentinelOne] DESTRUCTIVE — Mint a short-lived token that embeds the SentinelOne console in an iframe. It is a bearer credential for the console session, so treat the response as a secret and do not paste it into a ticket or a chat transcript. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/users/generate-iframe-token schema expects.

[SentinelOne] Get the console user that owns the API token this connector is using, with their role and scope. Use it to answer what this credential can actually do before a write fails with a 403, since SentinelOne enforces permissions per endpoint against this identity. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Get template for new role. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Get one RBAC role by its id, with the full permission list it grants. Get the id from s1_get_roles. This is the read that answers which permission a 403 is complaining about. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
roleIdstringyesSentinelOne's own id for the users and roles resource this call targets.
searchQuerystringnonullFree-text search over the resource, as SentinelOne's own console search box would apply it.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] List the RBAC roles defined in the console, with the scope each is defined at and the number of users assigned. Read this before creating or editing a role, and to work out which role a 403 is pointing at. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Set countOnly=true to size a filter before acting on it. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
idsstringnonullComma-separated list of ids to restrict the result to.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
searchQuerystringnonullFree-text search over the resource, as SentinelOne's own console search box would apply it.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Get Service User. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
serviceUserIdstringyesSentinelOne's own id for the users and roles resource this call targets.

[SentinelOne] List the service users that match the filter, with their scope, role and token expiry. Service users are the API-only identities SentinelOne recommends for integrations, so this is where to check when a token is about to lapse. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Set countOnly=true to size a filter before acting on it. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
idsstringnonullComma-separated list of ids to restrict the result to.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
searchQuerystringnonullFree-text search over the resource, as SentinelOne's own console search box would apply it.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Get one console user by their id, including role, scope, two-factor state and last login. Get the id from s1_list_users. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
userIdstringyesSentinelOne's own id for the users and roles resource this call targets.

[SentinelOne] API Token by User ID. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
userIdstringyesSentinelOne's own id for the users and roles resource this call targets.

[SentinelOne] List the console users that match the filter, with their role, scope, last login and whether they have verified their email. These are people who sign in to the SentinelOne console, not endpoint agents and not service users — see s1_get_service_users for API identities. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Set countOnly=true to size a filter before acting on it. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
idsstringnonullComma-separated list of ids to restrict the result to.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
searchQuerystringnonullFree-text search over the resource, as SentinelOne's own console search box would apply it.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] DESTRUCTIVE — Start two-factor enrollment for a console user, which returns the secret the authenticator app needs. This is auth-factor association: it changes how a person proves who they are, and a half-finished enrollment can leave them unable to sign in. Treat the response as a secret. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/users/request-app schema expects.

[SentinelOne] DESTRUCTIVE — Revoke a user's API token. Every integration authenticating with that token starts failing on its next call, and there is no undo — the replacement is a new token from s1_generate_api_token. If the identity is the one this connector uses, this revokes StackJack's own access; check with s1_get_current_user first. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/users/revoke-api-token schema expects.

[SentinelOne] DESTRUCTIVE — Send the onboarding verification email to every user matching a FILTER. This REACHES PEOPLE and it can lock them out: the vendor warns that active users are locked out of the console until they verify, unless the console has user-set password methods enabled. A wrong filter therefore mails, and locks out, every administrator in scope. Run s1_list_users with the SAME filter and countOnly=true first. SMTP must be configured for the Global scope or nothing is delivered. A 200 response does not prove delivery — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/users/onboarding/send-verification-email schema expects.

[SentinelOne] DESTRUCTIVE — Change an RBAC role's permission set. This is privilege-widening and it applies to every identity already assigned to the role, immediately — adding one permission grants it to all of them, and removing one can break a running integration. Read the current set with s1_get_role and send it back with your change; the vendor treats this as a replace, not a merge. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/rbac/role/ schema expects.
roleIdstringyesSentinelOne's own id for the users and roles resource this call targets.

[SentinelOne] DESTRUCTIVE — Change a service user's fields, including its role and scope. This is privilege-widening for an API identity: every integration already using that identity's token gains or loses access immediately. Read the current values with s1_get_service_user and send them back with your change. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/service-users/ schema expects.
serviceUserIdstringyesSentinelOne's own id for the users and roles resource this call targets.

[SentinelOne] DESTRUCTIVE — Change a console user's fields, which include their role and their scope. Changing either is privilege-widening: it takes effect on that person's next request, with no further approval. Read the current values with s1_get_user and send them back with your change rather than a partial body. A 200 response does not prove the change landed — re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/users/ schema expects.
userIdstringyesSentinelOne's own id for the users and roles resource this call targets.

[SentinelOne] DESTRUCTIVE — Redeem an onboarding verification token and SET THAT USER'S PASSWORD. This is a credential-setting call, not a status check: it completes a console sign-in identity for a person. Only use it when you are completing an invitation you already hold the token for. A 200 response does not prove the change landed — re-read with s1_get_user to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/users/onboarding/verify schema expects.

Application Management

ToolPlanAccessSummary
s1_get_aggregated_applications_riskFreeRead-onlyGet Aggregated Applications With Risk.
s1_get_app_inventory_endpointsFreeRead-onlyGet App Inventory Endpoints.
s1_get_application_cvesFreeRead-onlyGet Application CVEs.
s1_get_application_inventoryFreeRead-onlyGet Application Inventory.
s1_get_application_management_settingsFreeRead-onlyGet Application Management Settings.
s1_get_applications_riskFreeRead-onlyGet Applications With Risk.
s1_get_cve_dataFreeRead-onlyGet CVE data.
s1_get_endpoint_appsFreeRead-onlyGet Endpoint Apps.
s1_get_endpoints_vulnerable_appFreeRead-onlyGet Endpoints For Vulnerable App.
s1_initiate_scan_application_managementProDestructiveDESTRUCTIVE — Initiate scan.
s1_update_application_management_settingsProDestructiveDESTRUCTIVE — Update Application Management Settings.

[SentinelOne] Get Aggregated Applications With Risk. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns applications carrying risk ROLLED UP across their versions, so one row per product rather than per installed version. Use s1_get_applications_risk when you need the per-version detail. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Get App Inventory Endpoints. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. SentinelOne requires applicationName and applicationVendor on this endpoint — pass them in filtersJson or the call fails with a 400. applicationName: the application name to match. applicationVendor: the application vendor to match. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the ENDPOINT side of the inventory: one row per endpoint with its application counts. Use s1_get_endpoint_apps for the same data keyed by application instead. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Get Application CVEs. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns known CVEs affecting software in the scope, one row per CVE. Use s1_get_endpoints_vulnerable_app to turn a CVE into the list of machines that need patching. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Get Application Inventory. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the installed-software inventory: one row per application found across the endpoints in scope. Start here when the question is "what is installed". A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Get Application Management Settings. Scope to one customer with siteIds / accountIds / groupIds. Returns the Application Management settings for the scope, including the scan schedule. Read this before s1_update_application_management_settings, which replaces the whole object. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Get Applications With Risk. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns applications carrying risk, one row per application, with the vulnerability counts that make it risky. Use s1_get_aggregated_applications_risk for the same data rolled up across versions. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Get CVE data. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the application-risk root: the CVE-derived risk data for the scope. The three narrower reads under it are s1_get_application_cves (per CVE), s1_get_applications_risk (per application) and s1_get_endpoints_vulnerable_app (per endpoint). A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Get Endpoint Apps. Returns the applications installed on endpoints, keyed by application. Use s1_get_app_inventory_endpoints for the same data keyed by endpoint instead. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
idsstringnonullComma-separated list of ids to restrict the result to.

[SentinelOne] Get Endpoints For Vulnerable App. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the endpoints running a vulnerable application — the read that turns a CVE or a risky application into the list of machines to patch. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] DESTRUCTIVE — Initiate scan. This starts an application-inventory scan on every endpoint in the scope you pass. Scope it with siteIds, accountIds or groupIds first — with no scope it runs fleet-wide and every endpoint spends CPU on it at once. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/application-management/scan schema expects.

[SentinelOne] DESTRUCTIVE — Update Application Management Settings. This replaces the whole application-management settings object for the scope. Send every field you want to keep: a field you omit is cleared, not left alone. Read s1_get_application_management_settings first and edit that payload. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/application-management/settings schema expects.

Device Control

ToolPlanAccessSummary
s1_copy_rulesProDestructiveDESTRUCTIVE — Copy Rules.
s1_create_device_control_ruleProDestructiveDESTRUCTIVE — Create Device Control Rule.
s1_delete_rules_device_controlProDestructiveDESTRUCTIVE — Delete Rules.
s1_enable_disable_rulesProDestructiveDESTRUCTIVE — Enable/Disable Rules.
s1_export_rulesFreeRead-onlyExport Rules.
s1_get_configurationFreeRead-onlyGet Configuration.
s1_get_device_control_eventsFreeRead-onlyGet Device Control Events.
s1_get_device_rulesFreeRead-onlyGet Device Rules.
s1_move_rulesProDestructiveDESTRUCTIVE — Move rules.
s1_reorder_rulesProDestructiveDESTRUCTIVE — Reorder Rules.
s1_update_configurationProDestructiveDESTRUCTIVE — Update Configuration.
s1_update_device_ruleProDestructiveDESTRUCTIVE — Update Device Rule.

[SentinelOne] DESTRUCTIVE — Copy Rules. This copies Device Control rules into ANOTHER scope, so it changes hardware policy somewhere you did not name in the read you ran first. Confirm the destination scope, not just the source. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/device-control/copy-rules schema expects.

[SentinelOne] DESTRUCTIVE — Create Device Control Rule. Device Control rules decide which USB, Bluetooth and other peripheral hardware may attach to every endpoint in scope. A new rule takes effect as soon as it is created, so a wrong device class can block keyboards or storage across a whole site. Confirm the scope and read s1_get_device_rules first. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/device-control schema expects.

[SentinelOne] DESTRUCTIVE — Delete Rules. Deleting a Device Control rule removes its restriction from every endpoint in scope immediately, and there is no undo or version history. If the rule was a block, the hardware it blocked is permitted from that moment. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/device-control schema expects.

[SentinelOne] DESTRUCTIVE — Enable/Disable Rules. Disabling a Device Control rule lifts its restriction on every endpoint in scope immediately; enabling one applies it just as fast. Confirm which rule ids you are toggling with s1_get_device_rules. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/device-control/enable schema expects.

[SentinelOne] Export Rules. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. KNOWN LIMITATION: SentinelOne answers this endpoint with a CSV body, not JSON, so StackJack refuses it and the tool reports a content-type error. There is no format parameter to change that. Use s1_get_device_rules for the same rules as JSON. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
idsstringnonullComma-separated list of ids to restrict the result to.
searchQuerystringnonullFree-text search over the resource, as SentinelOne's own console search box would apply it.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Get Configuration. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the Device Control configuration for the scope, including whether Device Control is enforcing at all. Read this before s1_update_configuration, which replaces the whole object. The firewall equivalent is s1_get_configuration_firewall_control. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Get Device Control Events. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns Device Control EVENTS — the peripherals that were actually allowed or blocked on endpoints, not the rules. Use s1_get_device_rules for the rules themselves. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
idsstringnonullComma-separated list of ids to restrict the result to.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
searchQuerystringnonullFree-text search over the resource, as SentinelOne's own console search box would apply it.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Get Device Rules. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the Device Control rules for the scope — which USB, Bluetooth and other peripheral hardware is allowed or blocked. Read this before any Device Control write; rule ids and rule ORDER both come from here. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
idsstringnonullComma-separated list of ids to restrict the result to.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
searchQuerystringnonullFree-text search over the resource, as SentinelOne's own console search box would apply it.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] DESTRUCTIVE — Move rules. This moves Device Control rules OUT of their current scope and into another one, so the source scope loses the restriction at the same moment the destination gains it. Confirm both scopes. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/device-control/move-rules schema expects.

[SentinelOne] DESTRUCTIVE — Reorder Rules. Rule order decides which rule wins for a device that matches more than one of them. Reordering can flip an allow into a block for hardware that was working a moment ago, without changing any rule body. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/device-control/reorder schema expects.

[SentinelOne] DESTRUCTIVE — Update Configuration. This replaces the whole Device Control configuration for the scope, including whether Device Control is enforcing at all. Read s1_get_configuration first and edit that payload — an omitted field is cleared. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/device-control/configuration schema expects.

[SentinelOne] DESTRUCTIVE — Update Device Rule. This replaces the whole rule, not the fields you send. Read the rule with s1_get_device_rules and edit that payload, or the omitted fields are cleared. Device Control governs which peripherals may attach to every endpoint in scope. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/device-control/ schema expects.
ruleIdstringyesSentinelOne's own id for the device control resource this call targets.

Exclusions and Blocklist

ToolPlanAccessSummary
s1_create_blocklist_itemProDestructiveDESTRUCTIVE — Create Blocklist Item.
s1_create_bulk_unified_exclusionProDestructiveDESTRUCTIVE — Create Bulk Unified Exclusion.
s1_create_config_overrideProDestructiveDESTRUCTIVE — Create Config Override.
s1_create_exclusionProDestructiveDESTRUCTIVE — Create Exclusion.
s1_create_unified_exclusionProDestructiveDESTRUCTIVE — Create Unified Exclusion.
s1_delete_blocklist_itemProDestructiveDESTRUCTIVE — Delete Blocklist Item.
s1_delete_config_overrideProDestructiveDESTRUCTIVE — Delete Config Override.
s1_delete_config_overridesProDestructiveDESTRUCTIVE — Delete Config Overrides.
s1_delete_exclusionsProDestructiveDESTRUCTIVE — Delete Exclusions.
s1_delete_exclusions_unified_exclusionsProDestructiveDESTRUCTIVE — Delete Exclusions.
s1_export_unified_exclusionsFreeRead-onlyExport Unified Exclusions.
s1_get_blocklistFreeRead-onlyGet Blocklist.
s1_get_blocklist_import_validation_reportFreeRead-onlyGet Blocklist Import Validation Report.
s1_get_config_overridesFreeRead-onlyGet Config Overrides.
s1_get_exclusion_actionsFreeRead-onlyGet Exclusion Actions.
s1_get_exclusion_import_validation_reportFreeRead-onlyGet Exclusion Import Validation Report.
s1_get_exclusionsFreeRead-onlyGet Exclusions.
s1_get_exclusions_unified_exclusionsFreeRead-onlyGet Exclusions.
s1_import_blocklist_itemsProDestructiveDESTRUCTIVE — Import Blocklist Items.
s1_import_exclusionsProDestructiveDESTRUCTIVE — Import Exclusions.
s1_import_unified_exclusionsProDestructiveDESTRUCTIVE — Import Unified Exclusions.
s1_update_blocklist_itemProDestructiveDESTRUCTIVE — Update Blocklist Item.
s1_update_config_overrideProDestructiveDESTRUCTIVE — Update Config Override.
s1_update_exclusionsProDestructiveDESTRUCTIVE — Update Exclusions.
s1_update_exclusions_unified_exclusionsProDestructiveDESTRUCTIVE — Update Exclusions.
s1_validate_blocklist_itemFreeRead-onlyValidate Blocklist Item.
s1_validate_exclusion_itemFreeRead-onlyValidate Exclusion Item.

[SentinelOne] DESTRUCTIVE — Create Blocklist Item. A blocklist entry makes SentinelOne kill and quarantine the hash on every endpoint in scope. Blocking the hash of a file the customer depends on takes that software out of service fleet-wide. Check the hash with s1_validate_blocklist_item first. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/restrictions schema expects.

[SentinelOne] DESTRUCTIVE — Create Bulk Unified Exclusion. This writes MANY exclusions in one call, each one telling SentinelOne to stop inspecting what it names. A single bad entry in the payload is a permanent blind spot that the console will not flag. Review every entry and confirm the scope before you send it. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/unified-exclusions/bulk schema expects.

[SentinelOne] DESTRUCTIVE — Create Config Override. A config override changes agent behavior for the scope and outranks the policy set in the console, so the console policy page will no longer describe what the agents are actually doing. Record why it exists — an override nobody remembers is how protection silently drifts. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/config-override schema expects.

[SentinelOne] DESTRUCTIVE — Create Exclusion. An exclusion tells SentinelOne to STOP inspecting the path, hash or process you name. Over-broad exclusions are the classic self-inflicted breach: the agent keeps running and keeps reporting healthy while what you excluded is no longer protected. Check the value with s1_validate_exclusion_item and confirm the scope before you write it. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/exclusions schema expects.

[SentinelOne] DESTRUCTIVE — Create Unified Exclusion. An exclusion tells SentinelOne to STOP inspecting what you name, and a unified exclusion applies across surfaces rather than to one engine. The agent keeps reporting healthy afterwards, so an over-broad value leaves a blind spot nothing alerts on. Confirm the exact value and the scope first. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/unified-exclusions schema expects.

[SentinelOne] DESTRUCTIVE — Delete Blocklist Item. Removing a blocklist entry RE-PERMITS the hash you previously banned on every endpoint in scope. If the entry was there because of a real incident, this undoes that containment. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/restrictions schema expects.

[SentinelOne] DESTRUCTIVE — Delete Config Override. Removing an override snaps the scope back to the console policy immediately. If the override existed to keep a business application working, that application can start being blocked. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
overrideIdstringyesSentinelOne's own id for the exclusions and blocklist resource this call targets.

[SentinelOne] DESTRUCTIVE — Delete Config Overrides. This removes MULTIPLE overrides at once, snapping every affected scope back to console policy immediately. Read s1_get_config_overrides first — an override that exists to keep a business application working is not obviously distinguishable from a stale one. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/config-override schema expects.

[SentinelOne] DESTRUCTIVE — Delete Exclusions. Removing an exclusion RE-ARMS detection on what it covered. Files and processes the customer relies on can be quarantined within minutes of this call. Read s1_get_exclusions first and be sure the exclusion is genuinely obsolete. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/exclusions schema expects.

[SentinelOne] DESTRUCTIVE — Delete Exclusions. Removing an exclusion RE-ARMS detection on what it covered. Files and processes the customer relies on can be quarantined within minutes of this call. Read s1_get_exclusions_unified_exclusions first and be sure the exclusion is genuinely obsolete. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/unified-exclusions schema expects.

[SentinelOne] Export Unified Exclusions. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the currently filtered unified exclusions as a JSON export payload, in the shape s1_import_unified_exclusions accepts. This is the read half of copying exclusions between scopes. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
idsstringnonullComma-separated list of ids to restrict the result to.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Get Blocklist. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the blocklist for the scope: hashes SentinelOne kills and quarantines everywhere in it. This is the deny side; s1_get_exclusions is the allow side. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
idsstringnonullComma-separated list of ids to restrict the result to.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
searchQuerystringnonullFree-text search over the resource, as SentinelOne's own console search box would apply it.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Get Blocklist Import Validation Report. Returns the validation report for a blocklist import, by the report id that s1_import_blocklist_items returned. Read it before you trust the import: the import call answers 200 even when rows were rejected. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
reportIdstringyesSentinelOne's own id for the exclusions and blocklist resource this call targets.

[SentinelOne] Get Config Overrides. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the config overrides for the scope. An override outranks the policy set in the console, so this read is how you find out why agents are not behaving the way the policy page says they should. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
idsstringnonullComma-separated list of ids to restrict the result to.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
searchQuerystringnonullFree-text search over the resource, as SentinelOne's own console search box would apply it.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Get Exclusion Actions. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. SentinelOne requires create on this endpoint — pass it in filtersJson or the call fails with a 400. create: a boolean the vendor documents only as `Create`; send true or false. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns which exclusion actions this tenant may use. Read it before building a unified-exclusion payload — an unsupported action is a 400, not an ignored field. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
idsstringnonullComma-separated list of ids to restrict the result to.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Get Exclusion Import Validation Report. Returns the validation report for an exclusion import, by the report id that s1_import_exclusions returned. Read it before you trust the import: the import call answers 200 even when rows were rejected. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
reportIdstringyesSentinelOne's own id for the exclusions and blocklist resource this call targets.

[SentinelOne] Get Exclusions. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the LEGACY per-engine exclusions for the scope — paths, hashes, certificates and browsers that SentinelOne is told not to inspect. The newer cross-surface list is s1_get_exclusions_unified_exclusions; a tenant can have both, so check each before concluding nothing is excluded. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
idsstringnonullComma-separated list of ids to restrict the result to.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
searchQuerystringnonullFree-text search over the resource, as SentinelOne's own console search box would apply it.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Get Exclusions. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the UNIFIED exclusions for the scope — the newer model that applies across surfaces rather than to one engine. The legacy per-engine list is s1_get_exclusions; a tenant can have both, so check each before concluding nothing is excluded. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
idsstringnonullComma-separated list of ids to restrict the result to.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] DESTRUCTIVE — Import Blocklist Items. An import writes MANY blocklist entries in one call, and each one kills and quarantines its hash on every endpoint in scope. A bad hash in the payload takes working software out of service fleet-wide. Check the returned report id with s1_get_blocklist_import_validation_report before you trust the result. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).

[SentinelOne] DESTRUCTIVE — Import Exclusions. An import writes MANY exclusions in one call, each one a place SentinelOne will stop inspecting. Nothing in the console flags an over-broad entry afterwards. Send the payload through s1_validate_exclusion_item first, then check the returned report id with s1_get_exclusion_import_validation_report before you trust the result. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).

[SentinelOne] DESTRUCTIVE — Import Unified Exclusions. An import writes MANY exclusions in one call, each one a place SentinelOne will stop inspecting. Nothing in the console flags an over-broad entry afterwards. Review every entry, and confirm the destination scope — imports are normally used to copy exclusions BETWEEN scopes, so the target is easy to get wrong. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).

[SentinelOne] DESTRUCTIVE — Update Blocklist Item. This replaces the blocklist entry rather than merging into it, so an omitted field is cleared. Changing the hash re-permits the old one and starts killing the new one on every endpoint in scope. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/restrictions schema expects.

[SentinelOne] DESTRUCTIVE — Update Config Override. This replaces the override rather than merging into it, so an omitted field is cleared. The override outranks console policy, so a wrong value changes agent behavior for the whole scope with nothing on the policy page to explain it. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/config-override/ schema expects.
overrideIdstringyesSentinelOne's own id for the exclusions and blocklist resource this call targets.

[SentinelOne] DESTRUCTIVE — Update Exclusions. This replaces the exclusion rather than merging into it, so an omitted field is cleared. Both directions are dangerous: widening it creates a blind spot, narrowing it re-arms detection on files the customer relies on. Read s1_get_exclusions and edit that payload. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/exclusions schema expects.

[SentinelOne] DESTRUCTIVE — Update Exclusions. This replaces the exclusion rather than merging into it, so an omitted field is cleared. Both directions are dangerous: widening it creates a blind spot, narrowing it re-arms detection on files the customer relies on. Read s1_get_exclusions_unified_exclusions and edit that payload. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/unified-exclusions schema expects.

[SentinelOne] Validate Blocklist Item. This is a POST that READS: the criteria travel in the request body, and nothing is created or changed. Checks a blocklist value WITHOUT writing it. Run this before s1_create_blocklist_item — a bad hash takes working software out of service on every endpoint in scope. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/restrictions/validate schema expects.

[SentinelOne] Validate Exclusion Item. This is a POST that READS: the criteria travel in the request body, and nothing is created or changed. Checks an exclusion value WITHOUT writing it. Run this before s1_create_exclusion — an over-broad exclusion is not reversible in its effect, because nothing was inspected while it was live. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/exclusions/validate schema expects.

Firewall Control

ToolPlanAccessSummary
s1_add_rule_tags_firewall_controlProWriteAdd Rule Tags.
s1_copy_rules_firewall_controlProDestructiveDESTRUCTIVE — Copy Rules.
s1_create_firewall_ruleProDestructiveDESTRUCTIVE — Create Firewall Rule.
s1_delete_rules_firewall_controlProDestructiveDESTRUCTIVE — Delete Rules.
s1_enable_disable_rules_firewall_controlProDestructiveDESTRUCTIVE — Enable/Disable Rules.
s1_export_rules_firewall_controlFreeRead-onlyExport Rules.
s1_get_configuration_firewall_controlFreeRead-onlyGet Configuration.
s1_get_firewall_rulesFreeRead-onlyGet Firewall Rules.
s1_get_protocols_firewall_controlFreeRead-onlyGet Protocols.
s1_get_tag_firewall_rulesFreeRead-onlyGet Tag Firewall Rules.
s1_import_rules_firewall_controlProDestructiveDESTRUCTIVE — Import Rules.
s1_move_rules_firewall_controlProDestructiveDESTRUCTIVE — Move Rules.
s1_remove_rule_tags_firewall_controlProDestructiveDESTRUCTIVE — Remove Rule Tags.
s1_reorder_rules_firewall_controlProDestructiveDESTRUCTIVE — Reorder Rules.
s1_set_location_firewall_controlProDestructiveDESTRUCTIVE — Set Location.
s1_update_configuration_firewall_controlProDestructiveDESTRUCTIVE — Update Configuration.
s1_update_firewall_ruleProDestructiveDESTRUCTIVE — Update Firewall Rule.

[SentinelOne] Add Rule Tags. Attaches tags to firewall rules. Additive: it adds the tags you name and clears nothing, which is why this one is not marked destructive while its remove twin is. Tags drive which rules apply where, so check s1_get_tag_firewall_rules to see what a tag already carries. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/firewall-control/add-tags schema expects.

[SentinelOne] DESTRUCTIVE — Copy Rules. This copies firewall rules into ANOTHER scope, so it changes network policy somewhere you did not name in the read you ran first. Confirm the destination scope, not just the source. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/firewall-control/copy-rules schema expects.

[SentinelOne] DESTRUCTIVE — Create Firewall Rule. Firewall Control rules govern network traffic on every endpoint in scope, and a new rule takes effect as soon as it is created. A wrong rule can cut a whole site off the network, or open a port the customer policy closes. Read s1_get_firewall_rules and confirm the scope first. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/firewall-control schema expects.

[SentinelOne] DESTRUCTIVE — Delete Rules. Deleting a firewall rule removes it from every endpoint in scope immediately, with no undo. If it was a block, that traffic is permitted from this moment; if it was the allow that kept a business application reachable, that application stops working. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/firewall-control schema expects.

[SentinelOne] DESTRUCTIVE — Enable/Disable Rules. Disabling a firewall rule lifts it on every endpoint in scope immediately, and enabling one applies it just as fast. Confirm the rule ids with s1_get_firewall_rules. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/firewall-control/enable schema expects.

[SentinelOne] Export Rules. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the matching firewall rules as a JSON export payload, in the shape s1_import_rules_firewall_control accepts. This is the read half of copying rules between scopes. Firewall Control requires the Control SKU. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
idsstringnonullComma-separated list of ids to restrict the result to.
searchQuerystringnonullFree-text search over the resource, as SentinelOne's own console search box would apply it.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Get Configuration. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the Firewall Control configuration for the scope, including whether Firewall Control is enforcing at all. Read this before s1_update_configuration_firewall_control, which replaces the whole object. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Get Firewall Rules. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the Firewall Control rules for the scope. Read this before any firewall write; rule ids and rule ORDER both come from here, and order decides which rule wins. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
idsstringnonullComma-separated list of ids to restrict the result to.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
searchQuerystringnonullFree-text search over the resource, as SentinelOne's own console search box would apply it.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Get Protocols. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the protocol vocabulary SentinelOne accepts in a firewall rule. Read it before composing a rule body; an unsupported protocol name is a 400, not an ignored field. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
searchQuerystringnonullFree-text search over the resource, as SentinelOne's own console search box would apply it.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Get Tag Firewall Rules. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the firewall rules attached to one tag. Read it before removing that tag from anything — the rules listed here stop applying wherever the tag is detached. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
idsstringnonullComma-separated list of ids to restrict the result to.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
searchQuerystringnonullFree-text search over the resource, as SentinelOne's own console search box would apply it.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.
tagIdstringyesSentinelOne's own id for the firewall control resource this call targets.

[SentinelOne] DESTRUCTIVE — Import Rules. An import writes MANY firewall rules in one call, and they take effect on every endpoint in the destination scope. Imports are normally used to copy rules BETWEEN scopes, so the destination is the field to check twice. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] DESTRUCTIVE — Move Rules. This moves firewall rules OUT of their current scope into another one, so the source scope loses that network policy at the same moment the destination gains it. Confirm both scopes. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/firewall-control/move-rules schema expects.

[SentinelOne] DESTRUCTIVE — Remove Rule Tags. Removing a tag detaches the rule from every tag-driven assignment that used it, so rules can stop applying to endpoints that were relying on the tag. Read s1_get_tag_firewall_rules first to see what the tag currently carries. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/firewall-control/remove-tags schema expects.

[SentinelOne] DESTRUCTIVE — Reorder Rules. Firewall rule order decides which rule wins for traffic matching more than one of them. Reordering can turn an allow into a block for traffic that was flowing a moment ago, without changing any rule body. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/firewall-control/reorder schema expects.

[SentinelOne] DESTRUCTIVE — Set Location. This changes which network location a rule applies to, so a rule written for a guest network can start applying on the corporate one, or stop applying where it was needed. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/firewall-control/set-location schema expects.

[SentinelOne] DESTRUCTIVE — Update Configuration. This replaces the whole Firewall Control configuration for the scope, including whether Firewall Control is enforcing at all. Read s1_get_configuration_firewall_control first and edit that payload — an omitted field is cleared. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/firewall-control/configuration schema expects.

[SentinelOne] DESTRUCTIVE — Update Firewall Rule. This replaces the whole rule, not the fields you send, so an omitted field is cleared. Firewall rules decide what traffic every endpoint in scope may carry — read s1_get_firewall_rules and edit that payload. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/firewall-control/ schema expects.
firewallRuleCategorystringyesSentinelOne's own id for the firewall control resource this call targets.

Integrations

ToolPlanAccessSummary
s1_activate_workflow_versionProDestructiveDESTRUCTIVE — Activate a workflow version.
s1_batch_export_workflowsFreeRead-onlyBatch export workflows.
s1_batch_import_workflowsProDestructiveDESTRUCTIVE — Batch import workflows.
s1_create_estimator_idProWriteCreate Estimator ID.
s1_create_evaluate_expressionProDestructiveDESTRUCTIVE — Evaluate Expression.
s1_create_expression_breakdownProDestructiveDESTRUCTIVE — Expression Breakdown.
s1_create_onboard_new_vcs_integrationProDestructiveDESTRUCTIVE — Onboard a new VCS integration.
s1_create_provision_persist_mssp_partner_keyProDestructiveDESTRUCTIVE — Provision - Persist MSSP partner key.
s1_create_provision_provision_mssp_partner_admin_userProDestructiveDESTRUCTIVE — Provision - Provision MSSP partner with admin user.
s1_create_provision_provision_tenant_admin_userProDestructiveDESTRUCTIVE — Provision - Provision tenant with admin user.
s1_create_register_tunnel_userProDestructiveDESTRUCTIVE — Register Tunnel User.
s1_create_vcs_cicd_scanner_policyProDestructiveDESTRUCTIVE — Create a VCS and CICD scanner policy.
s1_deactivate_active_workflowProDestructiveDESTRUCTIVE — Deactivate The active workflow.
s1_delete_cloud_funnel_ruleProDestructiveDESTRUCTIVE — Delete cloud funnel rule.
s1_delete_mssp_partner_keyProDestructiveDESTRUCTIVE — Deletes MSSP partner key by client ID.
s1_delete_vcs_cicd_scanner_policyProDestructiveDESTRUCTIVE — Delete a VCS and CICD scanner policy.
s1_delete_vcs_integration_cnappProDestructiveDESTRUCTIVE — Delete a VCS integration.
s1_disable_scanning_repositories_vcs_integrationProDestructiveDESTRUCTIVE — Disable scanning for repositories in a VCS integration.
s1_edit_tags_repositories_vcs_integrationProDestructiveDESTRUCTIVE — Edit tags for repositories in a VCS integration.
s1_edit_tags_vcs_integrationProDestructiveDESTRUCTIVE — Edit tags for a VCS integration.
s1_enable_scanning_repositories_vcs_integrationProDestructiveDESTRUCTIVE — Enable scanning for repositories in a VCS integration.
s1_export_cloud_rogue_resourcesFreeRead-onlyExport cloud rogue resources to csv (default) or json.
s1_fetch_filter_countFreeRead-onlyFetch filter count.
s1_fetch_repository_tagsFreeRead-onlyFetch repository tags.
s1_get_agent_merged_updatesFreeRead-onlyGet Agent Merged Updates.
s1_get_aws_assume_role_external_idFreeRead-onlyGet AWS assume role external ID.
s1_get_cloud_funnel_ruleFreeRead-onlyGet cloud funnel rule.
s1_get_cloud_rogue_resourcesFreeRead-onlyGet cloud rogue resources.
s1_get_devices_get_list_devices_specific_scopeFreeRead-onlyDevices - Get list of devices for specific scope.
s1_get_estimate_size_eventsFreeRead-onlyGet estimate size of events.
s1_get_gatewaysFreeRead-onlyGet Gateways.
s1_get_incidents_get_list_incidentsFreeRead-onlyIncidents - Get list of incidents.
s1_get_max_allowed_priorityFreeRead-onlyGet max allowed priority.
s1_get_provision_check_if_tenant_can_be_provisionedFreeRead-onlyProvision - Check if tenant can be provisioned.
s1_get_provision_get_mssp_partner_admin_userFreeRead-onlyProvision - Get MSSP partner with admin user.
s1_get_provision_get_mssp_partner_keyFreeRead-onlyProvision - Get MSSP partner key.
s1_get_provision_get_tenant_usersFreeRead-onlyProvision - Get tenant with users.
s1_get_vcs_cicd_scanner_policyFreeRead-onlyGet a VCS and CICD scanner policy.
s1_get_workflow_execution_idFreeRead-onlyGet a workflow execution by its ID.
s1_import_workflowProDestructiveDESTRUCTIVE — Import workflow.
s1_list_vcs_cicd_scanner_policiesFreeRead-onlyList VCS and CICD scanner policies.
s1_list_vcs_integration_repositoriesFreeRead-onlyList VCS integration repositories.
s1_list_vcs_integrationsFreeRead-onlyList VCS integrations.
s1_list_workflow_executionsFreeRead-onlyList all workflow executions.
s1_list_workflow_versionsFreeRead-onlyList workflow versions.
s1_list_workflowsFreeRead-onlyList all workflows.
s1_offboard_vcs_integrationProDestructiveDESTRUCTIVE — off-board (delete) a VCS integration.
s1_post_onboarding_cloud_funnelProDestructiveDESTRUCTIVE — Post onboarding cloud funnel.
s1_trigger_workflow_uses_manual_triggerProDestructiveDESTRUCTIVE — Trigger a workflow that uses a manual trigger.
s1_update_gatewayProDestructiveDESTRUCTIVE — Update Gateway.
s1_update_gatewaysProDestructiveDESTRUCTIVE — Update Gateways.
s1_update_provision_update_mssp_partner_keyProDestructiveDESTRUCTIVE — Provision - Update MSSP partner key.
s1_update_resync_vcs_integration_repositoriesProDestructiveDESTRUCTIVE — Resync VCS Integration Repositories.
s1_update_vcs_cicd_scanner_policyProDestructiveDESTRUCTIVE — Update a VCS and CICD scanner policy.
s1_update_vcs_integrationProDestructiveDESTRUCTIVE — Update a VCS integration.
s1_validate_bucketFreeRead-onlyValidate Bucket.
s1_validate_queryFreeRead-onlyValidate Query.

[SentinelOne] DESTRUCTIVE — Activate a workflow version. An active Hyperautomation workflow takes actions on its own whenever its trigger fires — including endpoint actions — with no further prompt. Activating a version makes THAT version live in place of whatever was running. Read the version with s1_list_workflow_versions and know what its actions do before you activate it. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/hyper-automate/api/public/workflows///activation schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
versionIdstringyesSentinelOne's own id for the integrations resource this call targets.
workflowIdstringyesSentinelOne's own id for the integrations resource this call targets.

[SentinelOne] Batch export workflows. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the matching workflows as an export payload, in the shape s1_batch_import_workflows accepts. This is the read half of copying automation between scopes. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] DESTRUCTIVE — Batch import workflows. This imports MANY workflows in one call, each arriving with its actions intact. Review the payload before you send it — imported workflows are arbitrary automation against your console and your endpoints. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/hyper-automate/api/public/workflow-import-export/import/batch schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Create Estimator ID. Creates an estimator handle for sizing a Cloud Funnel export. It creates a measurement object only — no telemetry starts flowing until s1_post_onboarding_cloud_funnel is called. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/cloud-funnel/estimator schema expects.

[SentinelOne] DESTRUCTIVE — Evaluate Expression. This evaluates a workflow expression against a real base action rather than in a sandbox, which is why it is classified as a write. Treat it as touching the action it names. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
baseActionIdstringyesSentinelOne's own id for the integrations resource this call targets.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/hyper-automate/api/public/workflow-action-expressions//evaluate-expression schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] DESTRUCTIVE — Expression Breakdown. This breaks a workflow expression down against a real base action rather than in a sandbox, which is why it is classified as a write. Treat it as touching the action it names. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
baseActionIdstringyesSentinelOne's own id for the integrations resource this call targets.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/hyper-automate/api/public/workflow-action-expressions//expression-breakdown schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] DESTRUCTIVE — Onboard a new VCS integration. This connects a source-control organization to SentinelOne and begins scanning its repositories. Confirm the organization is the customer's before you onboard it. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. SentinelOne requires scopeType and scopeIds on this endpoint — pass them in filtersJson or the call fails with a 400. scopeType: the scope type this call resolves against. scopeIds: the ids of the scopes it applies to. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/cnapp/vcs/onboarding schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).

[SentinelOne] DESTRUCTIVE — Provision - Persist MSSP partner key. This MINTS an MSSP partner credential. Treat the response as a secret — anything holding that key can act as the partner against the mobile-integration API. Confirm the partner before you run it, and store the key somewhere the customer controls. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/mobile-integration/provisioning/partner-key schema expects.

[SentinelOne] DESTRUCTIVE — Provision - Provision MSSP partner with admin user. This creates an MSSP PARTNER together with an admin user, which is a real console principal with administrative reach over what the partner manages. It is a billable object and it is not a dry run. Confirm the partner details before you send it. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/mobile-integration/mssp-provisioning/partner schema expects.

[SentinelOne] DESTRUCTIVE — Provision - Provision tenant with admin user. This creates a mobile-integration TENANT together with an admin user — a real, billable console object with an administrative principal attached. Check with s1_check_mobile_tenant_can_be_provisioned first; there is no undo through this API. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/mobile-integration/provisioning/tenant schema expects.

[SentinelOne] DESTRUCTIVE — Register Tunnel User. This registers a tunnel principal for reaching a self-managed VCS host, which is a credential-shaped object. Treat the response as a secret and confirm the host is the customer's. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. SentinelOne requires scopeType and scopeIds on this endpoint — pass them in filtersJson or the call fails with a 400. scopeType: the scope type this call resolves against. scopeIds: the ids of the scopes it applies to. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/cnapp/vcs/tunnel/user schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).

[SentinelOne] DESTRUCTIVE — Create a VCS and CICD scanner policy. A scanner policy decides which findings BREAK a build. A policy that is too strict blocks the customer's pipeline; one that is too loose lets vulnerable code merge. Check s1_get_max_allowed_priority for the ceiling before you set one. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. SentinelOne requires scopeType and scopeIds on this endpoint — pass them in filtersJson or the call fails with a 400. scopeType: the scope type this call resolves against. scopeIds: the ids of the scopes it applies to. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/cnapp/vcs/scanner-policy schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).

[SentinelOne] DESTRUCTIVE — Deactivate The active workflow. Deactivating stops the workflow from firing at all. If the workflow was the automation containing threats or notifying the on-call, that response stops happening and nothing else will flag its absence. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/hyper-automate/api/public/workflows//deactivate schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
workflowIdstringyesSentinelOne's own id for the integrations resource this call targets.

[SentinelOne] DESTRUCTIVE — Delete cloud funnel rule. Deleting the Cloud Funnel rule STOPS the telemetry export. Anything downstream that consumes that stream — a SIEM, a data lake — goes quiet, and the events produced while it is off are not backfilled. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/cloud-funnel/onboarding schema expects.

[SentinelOne] DESTRUCTIVE — Deletes MSSP partner key by client ID. Deleting the partner key immediately breaks every mobile-integration client authenticating with it, and the key cannot be recovered — a replacement has to be minted and redistributed. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
clientIdstringyesSentinelOne's own id for the integrations resource this call targets.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/mobile-integration/provisioning/partner-key/ schema expects.

[SentinelOne] DESTRUCTIVE — Delete a VCS and CICD scanner policy. Deleting the scanner policy removes the gate: pipelines it was blocking start passing, and findings it was enforcing stop being enforced. Nothing in the pipeline reports that the policy is gone. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. SentinelOne requires scopeType and scopeIds on this endpoint — pass them in filtersJson or the call fails with a 400. scopeType: the scope type this call resolves against. scopeIds: the ids of the scopes it applies to. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
policyIdstringyesSentinelOne's own id for the integrations resource this call targets.

[SentinelOne] DESTRUCTIVE — Delete a VCS integration. Off-boarding removes the source-control integration and stops its repositories being scanned. Re-connecting needs the VCS credentials again. Confirm the integration id with s1_list_vcs_integrations. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. SentinelOne requires scopeType and scopeIds on this endpoint — pass them in filtersJson or the call fails with a 400. scopeType: the scope type this call resolves against. scopeIds: the ids of the scopes it applies to. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
vcsIntegrationIdstringyesSentinelOne's own id for the integrations resource this call targets.

[SentinelOne] DESTRUCTIVE — Disable scanning for repositories in a VCS integration. Disabling scanning STOPS analysis of the named repositories, so new commits go uninspected and existing findings stop being refreshed. Nothing alerts on the gap. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. SentinelOne requires scopeType and scopeIds on this endpoint — pass them in filtersJson or the call fails with a 400. scopeType: the scope type this call resolves against. scopeIds: the ids of the scopes it applies to. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/cnapp/vcs/integration//repos/disable-scan schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
integrationIdstringyesSentinelOne's own id for the integrations resource this call targets.

[SentinelOne] DESTRUCTIVE — Edit tags for repositories in a VCS integration. Repository tags drive which scanner policy applies, so a tag change can move a repository onto a different policy — or off the one that was gating its findings. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. SentinelOne requires scopeType and scopeIds on this endpoint — pass them in filtersJson or the call fails with a 400. scopeType: the scope type this call resolves against. scopeIds: the ids of the scopes it applies to. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/cnapp/vcs/integration//repos/edit-tags schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
integrationIdstringyesSentinelOne's own id for the integrations resource this call targets.

[SentinelOne] DESTRUCTIVE — Edit tags for a VCS integration. Integration tags drive which scanner policy applies, so a tag change can move the whole integration onto a different policy — or off the one that was gating its findings. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. SentinelOne requires scopeType and scopeIds on this endpoint — pass them in filtersJson or the call fails with a 400. scopeType: the scope type this call resolves against. scopeIds: the ids of the scopes it applies to. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/cnapp/vcs/integrations/edit-tags schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).

[SentinelOne] DESTRUCTIVE — Enable scanning for repositories in a VCS integration. Enabling scanning starts pulling and analyzing the named repositories, which counts against the scanning entitlement and surfaces findings against code the customer may not expect to be scanned yet. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. SentinelOne requires scopeType and scopeIds on this endpoint — pass them in filtersJson or the call fails with a 400. scopeType: the scope type this call resolves against. scopeIds: the ids of the scopes it applies to. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/cnapp/vcs/integration//repos/enable-scan schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
integrationIdstringyesSentinelOne's own id for the integrations resource this call targets.

[SentinelOne] Export cloud rogue resources to csv (default) or json. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds. Pass any other documented query parameter as a flat JSON object in filtersJson. DEFAULTS TO CSV, which StackJack refuses because it is not JSON. Pass {"exportFormat":"json"} in filtersJson to get a JSON body this tool can return. Rogue resources are cloud assets with no SentinelOne agent on them. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Fetch filter count. SentinelOne requires scopeType and scopeIds on this endpoint — pass them in filtersJson or the call fails with a 400. scopeType: the scope type this call resolves against. scopeIds: the ids of the scopes it applies to. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).

[SentinelOne] Fetch repository tags. This is a POST that READS: the criteria travel in the request body, and nothing is created or changed. SentinelOne requires scopeType and scopeIds on this endpoint — pass them in filtersJson or the call fails with a 400. scopeType: the scope type this call resolves against. scopeIds: the ids of the scopes it applies to. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/cnapp/vcs/integration//repos/get-tags schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
integrationIdstringyesSentinelOne's own id for the integrations resource this call targets.

[SentinelOne] Get Agent Merged Updates. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. SentinelOne requires agentId on this endpoint — pass it in filtersJson or the call fails with a 400. agentId: the agent id. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the content-update inventory: which detection-content versions the agents in scope have merged. This is content, not agent software version. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Get AWS assume role external ID. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).

[SentinelOne] Get cloud funnel rule. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the Cloud Funnel rule for the scope: whether SentinelOne telemetry is being exported to an external bucket, and to which one. Read it before assuming no data is leaving the tenant. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).

[SentinelOne] Get cloud rogue resources. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Devices - Get list of devices for specific scope. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the MOBILE devices in scope, from the mobile-integration surface. These are not the endpoint agents — those live in the Endpoints family. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Get estimate size of events. SentinelOne requires estimatorId on this endpoint — pass it in filtersJson or the call fails with a 400. estimatorId: the estimator query id. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).

[SentinelOne] Get Gateways. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the Ranger gateways for the scope — the relays that perform network discovery. Gateway ids for the update tools come from here. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
idsstringnonullComma-separated list of ids to restrict the result to.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
searchQuerystringnonullFree-text search over the resource, as SentinelOne's own console search box would apply it.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Incidents - Get list of incidents. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the incidents raised by the mobile-integration surface. These are not endpoint threats — those live in the Endpoints family. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Get max allowed priority. SentinelOne requires scopeType, scopeIds, targetScopeType and targetScopeId on this endpoint — pass them in filtersJson or the call fails with a 400. scopeType: the scope type this call resolves against. scopeIds: the ids of the scopes it applies to. targetScopeType: the scope type being compared against. targetScopeId: the id of that target scope. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).

[SentinelOne] Provision - Check if tenant can be provisioned. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Provision - Get MSSP partner with admin user. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Provision - Get MSSP partner key. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Provision - Get tenant with users. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Get a VCS and CICD scanner policy. SentinelOne requires scopeType and scopeIds on this endpoint — pass them in filtersJson or the call fails with a 400. scopeType: the scope type this call resolves against. scopeIds: the ids of the scopes it applies to. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
policyIdstringyesSentinelOne's own id for the integrations resource this call targets.

[SentinelOne] Get a workflow execution by its ID. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
workflowExecutionIdstringyesSentinelOne's own id for the integrations resource this call targets.

[SentinelOne] DESTRUCTIVE — Import workflow. An imported workflow arrives with its actions intact. Review what it does before you activate it — an imported workflow from an untrusted source is arbitrary automation against your console and your endpoints. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/hyper-automate/api/public/workflow-import-export/import schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] List VCS and CICD scanner policies. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.

[SentinelOne] List VCS integration repositories. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the repositories under one VCS integration, with whether each is being scanned. This is the read to run before enabling or disabling scanning. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
vcsIntegrationIdstringyesSentinelOne's own id for the integrations resource this call targets.

[SentinelOne] List VCS integrations. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the source-control integrations connected to this console. Integration ids for every other VCS tool come from here. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.

[SentinelOne] List all workflow executions. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns Hyperautomation workflow executions — what the automation actually did, and when. Use s1_get_workflow_execution_id for the detail of one run. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] List workflow versions. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the versions of one workflow. Read the version you intend to activate before calling s1_activate_workflow_version — activating swaps which version is live. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
workflowIdstringyesSentinelOne's own id for the integrations resource this call targets.

[SentinelOne] List all workflows. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the Hyperautomation workflows in scope. An ACTIVE workflow takes actions on its own when its trigger fires, so this read is how you find out what automation is already running before you add more. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] DESTRUCTIVE — off-board (delete) a VCS integration. SentinelOne serves this as a GET, but the effect is a teardown, not a read: the source-control integration stops being scanned and its connection to the console is removed. Confirm the integration id against s1_list_vcs_integrations first — there is no undo, and re-onboarding needs the VCS credentials again. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. SentinelOne requires scopeType and scopeIds on this endpoint — pass them in filtersJson or the call fails with a 400. scopeType: the scope type this call resolves against. scopeIds: the ids of the scopes it applies to. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
integrationIdstringyesSentinelOne's own id for the VCS integration to off-board. From s1_list_vcs_integrations.

[SentinelOne] DESTRUCTIVE — Post onboarding cloud funnel. Cloud Funnel streams your SentinelOne telemetry out to an external bucket. Onboarding starts that export, so confirm the destination is a bucket the customer owns — this is a standing data egress, not a one-off copy. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/cloud-funnel/onboarding schema expects.

[SentinelOne] DESTRUCTIVE — Trigger a workflow that uses a manual trigger. This RUNS the workflow now. Whatever actions the workflow contains execute immediately — including endpoint actions such as isolating or scanning machines. Read the workflow first; the trigger call itself carries no preview. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/hyper-automate/api/public/workflow-execution/manual// schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
versionIdstringyesSentinelOne's own id for the integrations resource this call targets.
workflowIdstringyesSentinelOne's own id for the integrations resource this call targets.

[SentinelOne] DESTRUCTIVE — Update Gateway. Ranger gateways are the relays that perform network discovery for a site. This replaces the gateway record rather than merging into it, so an omitted field is cleared, and a wrong value can stop discovery for that site with no alert. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/ranger/gateways/ schema expects.
gatewayIdstringyesSentinelOne's own id for the integrations resource this call targets.

[SentinelOne] DESTRUCTIVE — Update Gateways. This updates MULTIPLE Ranger gateways in one call. Gateways are the relays that perform network discovery, so a bad payload can stop discovery across several sites at once, with no alert. Read s1_get_gateways first. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/ranger/gateways/update schema expects.

[SentinelOne] DESTRUCTIVE — Provision - Update MSSP partner key. This rotates the MSSP partner credential. Every client still authenticating with the old key stops working the moment this lands, so have the replacement distribution ready before you call it. Treat the response as a secret. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/mobile-integration/provisioning/partner-key schema expects.

[SentinelOne] DESTRUCTIVE — Resync VCS Integration Repositories. A resync re-reads the repository list from the provider and reconciles it, so repositories removed upstream stop being scanned and newly visible ones start. Expect scanning load right after this lands. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. SentinelOne requires scopeType and scopeIds on this endpoint — pass them in filtersJson or the call fails with a 400. scopeType: the scope type this call resolves against. scopeIds: the ids of the scopes it applies to. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
vcsIntegrationIdstringyesSentinelOne's own id for the integrations resource this call targets.

[SentinelOne] DESTRUCTIVE — Update a VCS and CICD scanner policy. This replaces the scanner policy rather than merging into it, so an omitted field is cleared. The policy decides which findings break a build, so both directions have consequences. Read s1_get_vcs_cicd_scanner_policy and edit that payload. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. SentinelOne requires scopeType and scopeIds on this endpoint — pass them in filtersJson or the call fails with a 400. scopeType: the scope type this call resolves against. scopeIds: the ids of the scopes it applies to. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/cnapp/vcs/scanner-policy/ schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
policyIdstringyesSentinelOne's own id for the integrations resource this call targets.

[SentinelOne] DESTRUCTIVE — Update a VCS integration. This replaces the integration record rather than merging into it, so an omitted field is cleared. Read s1_list_vcs_integrations and edit that payload. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. SentinelOne requires scopeType and scopeIds on this endpoint — pass them in filtersJson or the call fails with a 400. scopeType: the scope type this call resolves against. scopeIds: the ids of the scopes it applies to. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/cnapp/vcs/integration/ schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
vcsIntegrationIdstringyesSentinelOne's own id for the integrations resource this call targets.

[SentinelOne] Validate Bucket. This is a POST that READS: the criteria travel in the request body, and nothing is created or changed. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/cloud-funnel/validate-bucket-permissions schema expects.

[SentinelOne] Validate Query. This is a POST that READS: the criteria travel in the request body, and nothing is created or changed. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/cloud-funnel/validate-query schema expects.

Marketplace

ToolPlanAccessSummary
s1_delete_applicationProDestructiveDESTRUCTIVE — Delete Application.
s1_enable_disable_applicationProDestructiveDESTRUCTIVE — Enable Or Disable Application.
s1_get_application_logFreeRead-onlyGet application log.
s1_get_applications_catalogFreeRead-onlyGet Applications Catalog.
s1_get_configuration_fieldsFreeRead-onlyGet Configuration Fields.
s1_get_configuration_fields_installed_applicationFreeRead-onlyGet Configuration Fields For Installed Application.
s1_get_installed_applicationsFreeRead-onlyGet Installed Applications.
s1_install_applicationsProDestructiveDESTRUCTIVE — Install Applications.
s1_update_application_configurationProDestructiveDESTRUCTIVE — Update Application Configuration.

[SentinelOne] DESTRUCTIVE — Delete Application. This uninstalls the application AND discards its configuration. Re-installing means configuring it from scratch, and anything downstream that consumed its output stops receiving data immediately. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/singularity-marketplace/applications schema expects.

[SentinelOne] DESTRUCTIVE — Enable Or Disable Application. Disabling stops the integration immediately, so anything downstream that depends on it — a SIEM feed, a ticket sync — stops receiving data with nothing else raising an alarm. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
applicationModestringyesSentinelOne's own id for the marketplace resource this call targets.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/singularity-marketplace/applications/ schema expects.

[SentinelOne] Get application log. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the activity log of one installed marketplace application — the first place to look when an integration has stopped delivering data. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
idstringyesSentinelOne's own id for the marketplace resource this call targets.

[SentinelOne] Get Applications Catalog. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the marketplace catalog — what is available to install. Use s1_get_installed_applications for what is already in this console. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
searchQuerystringnonullFree-text search over the resource, as SentinelOne's own console search box would apply it.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Get Configuration Fields. Returns the configuration fields a CATALOG application will ask for, before you install it. This is the read that shows what permissions and settings an install will require. For an already-installed app use s1_get_configuration_fields_installed_application. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
applicationCatalogIdstringyesSentinelOne's own id for the marketplace resource this call targets.

[SentinelOne] Get Configuration Fields For Installed Application. Returns the configuration fields of an ALREADY-INSTALLED application, with its current values. Read this before s1_update_application_configuration, which replaces the whole object. For a catalog entry use s1_get_configuration_fields. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
applicationIdstringyesSentinelOne's own id for the marketplace resource this call targets.

[SentinelOne] Get Installed Applications. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the marketplace applications INSTALLED in this console, with their state. Use s1_get_applications_catalog for what is available to install. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
searchQuerystringnonullFree-text search over the resource, as SentinelOne's own console search box would apply it.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] DESTRUCTIVE — Install Applications. An installed marketplace application runs with the console permissions its manifest requests and can read and act on console data. Read those permissions with s1_get_configuration_fields for the catalog entry before you install it. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/singularity-marketplace/applications schema expects.

[SentinelOne] DESTRUCTIVE — Update Application Configuration. This replaces the application configuration rather than merging into it, so an omitted field is cleared. Read s1_get_configuration_fields_installed_application and edit that payload; a cleared credential field silently breaks the integration. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/singularity-marketplace/applications schema expects.

PowerQuery

ToolPlanAccessSummary
s1_create_update_saved_searchesProWriteCreate or update saved searches.
s1_delete_queryProDestructiveDESTRUCTIVE — Delete query.
s1_delete_saved_searchesProDestructiveDESTRUCTIVE — Delete saved searches.
s1_get_poll_queryFreeRead-onlyPoll query.
s1_launch_queryFreeRead-onlyLaunch a query.
s1_list_saved_searchesFreeRead-onlyList saved searches.

[SentinelOne] Create or update saved searches. Part of SentinelOne's PowerQuery lane, which is asynchronous: launch, then poll until the query completes. Creates or updates a saved PowerQuery search. Not marked destructive because a saved search is a stored query with no operational consequence — but saved searches are SHARED within the scope, so an update overwrites what colleagues were using. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /sdl/v2/api/saved-searches schema expects.

[SentinelOne] DESTRUCTIVE — Delete query. This CANCELS the running query and discards its results. A long-running query loses whatever it had already produced, and the data-lake time it spent is not refunded. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Pass any other documented query parameter as a flat JSON object in filtersJson. Part of SentinelOne's PowerQuery lane, which is asynchronous: launch, then poll until the query completes. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
forwardTagstringyesThe _forwardTag value returned by s1_launch_query. REQUIRED: SentinelOne uses it to route to the replica holding the query, and rejects a poll or cancel without it.
idstringyesSentinelOne's own id for the powerquery resource this call targets.

[SentinelOne] DESTRUCTIVE — Delete saved searches. Saved searches are shared within the scope, so this deletes them for everyone who was using them, not just for you. There is no undo. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Part of SentinelOne's PowerQuery lane, which is asynchronous: launch, then poll until the query completes. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /sdl/v2/api/saved-searches/batch-delete schema expects.

[SentinelOne] Poll query. SentinelOne requires lastStepSeen on this endpoint — pass it in filtersJson or the call fails with a 400. lastStepSeen: the step number to resume the result from. Pass any other documented query parameter as a flat JSON object in filtersJson. Part of SentinelOne's PowerQuery lane, which is asynchronous: launch, then poll until the query completes. Poll a query launched by s1_launch_query until it reports complete. The forwardTag argument is the `_forwardTag` value from that launch response — the call is rejected without it, and there is no way to recover the value once the launch response is discarded. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
forwardTagstringyesThe _forwardTag value returned by s1_launch_query. REQUIRED: SentinelOne uses it to route to the replica holding the query, and rejects a poll or cancel without it.
idstringyesSentinelOne's own id for the powerquery resource this call targets.

[SentinelOne] Launch a query. This is a POST that READS: the criteria travel in the request body, and nothing is created or changed. Part of SentinelOne's PowerQuery lane, which is asynchronous: launch, then poll until the query completes. START HERE for PowerQuery. The response carries `_forwardTag`, a value StackJack lifts out of a response HEADER and folds into the body because SentinelOne returns it no other way. Keep it: s1_get_poll_query and s1_delete_query both REQUIRE it and are rejected without it. Note also that PowerQuery is rate-limited to about 3 requests per second against the identity in the token. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /sdl/v2/api/queries schema expects.

[SentinelOne] List saved searches. Pass any other documented query parameter as a flat JSON object in filtersJson. Part of SentinelOne's PowerQuery lane, which is asynchronous: launch, then poll until the query completes. Returns the saved PowerQuery searches for the scope. Saved searches are shared, so what you see here other people in the scope can see and delete too. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).

Remote Forensics

ToolPlanAccessSummary
s1_check_if_collection_file_exists_given_storylineFreeRead-onlyCheck if collection file exists for given storyline.
s1_create_new_collection_profileProWriteCreate new Collection profile.
s1_create_new_destination_profileProWriteCreate new Destination profile.
s1_delete_collection_profilesProDestructiveDESTRUCTIVE — Delete Collection profiles.
s1_delete_destination_profile_idProDestructiveDESTRUCTIVE — Delete Destination profile by ID.
s1_delete_multiple_destination_profiles_idProDestructiveDESTRUCTIVE — Delete multiple Destination profiles by ID.
s1_delete_multiple_scheduled_tasks_idProDestructiveDESTRUCTIVE — Delete multiple scheduled tasks by ID.
s1_get_available_destination_profilesFreeRead-onlyGet available Destination profiles.
s1_get_available_scheduled_tasksFreeRead-onlyGet available Scheduled Tasks.
s1_get_collection_profile_idFreeRead-onlyGet Collection profile by ID.
s1_get_destination_profile_idFreeRead-onlyGet Destination profile by ID.
s1_get_forensics_collection_file_urlFreeRead-onlyReturns collection file download pre-signed url.
s1_get_list_available_collection_profilesFreeRead-onlyGet list of available Collection profiles.
s1_get_list_supported_artifact_typesFreeRead-onlyGet list of supported artifact types.
s1_get_results_sent_data_exporterFreeRead-onlyGet results sent to data exporter.
s1_get_return_result_collection_taskFreeRead-onlyReturn result of collection task.
s1_schedule_forensics_future_runProDestructiveDESTRUCTIVE — Schedule forensics for future run.
s1_schedule_remote_script_future_runProDestructiveDESTRUCTIVE — Schedule remote script for future run.
s1_set_profile_default_profile_scopeProDestructiveDESTRUCTIVE — Set profile as default profile of the scope.
s1_start_forensics_collectionProDestructiveDESTRUCTIVE — Start collection of Forensics artifacts according to specified profile.
s1_update_collection_profile_idProDestructiveDESTRUCTIVE — Update Collection profile by ID.
s1_update_existing_destination_profileProDestructiveDESTRUCTIVE — Update existing Destination profile.
s1_update_existing_scheduled_taskProDestructiveDESTRUCTIVE — Update existing Scheduled task.

[SentinelOne] Check if collection file exists for given storyline. SentinelOne requires storyline and agentId on this endpoint — pass them in filtersJson or the call fails with a 400. storyline: the storyline id. agentId: the agent id. Pass any other documented query parameter as a flat JSON object in filtersJson. Checks whether a collection file already exists for a storyline, without collecting anything. Run it before s1_start_forensics_collection to avoid re-running a collection that already happened. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).

[SentinelOne] Create new Collection profile. Creates a forensics collection profile, which decides which artifact types a collection gathers. Additive: it collects nothing by itself until a collection or scheduled task names it. Check s1_get_list_supported_artifact_types for the vocabulary. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/remote-ops/forensics/collection-profiles schema expects.

[SentinelOne] Create new Destination profile. Creates a destination profile — where collected forensic data will be EXPORTED to. Additive: nothing is exported until a task names this profile or it is made the scope default. Confirm the destination belongs to the customer, because data sent through it leaves the SentinelOne tenant. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/remote-ops/data-exporter/destination-profiles schema expects.

[SentinelOne] DESTRUCTIVE — Delete Collection profiles. Deleting a collection profile breaks every scheduled task that names it, and those tasks fail rather than falling back to a default. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/remote-ops/forensics/collection-profiles schema expects.

[SentinelOne] DESTRUCTIVE — Delete Destination profile by ID. Deleting a destination profile breaks every scheduled task that exports through it, and the exports simply stop — read s1_get_available_scheduled_tasks first to see what depends on it. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
profileIdstringyesSentinelOne's own id for the remote forensics resource this call targets.

[SentinelOne] DESTRUCTIVE — Delete multiple Destination profiles by ID. This deletes SEVERAL destination profiles at once, breaking every scheduled task that exports through any of them. Read s1_get_available_scheduled_tasks first to see what depends on them. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/remote-ops/data-exporter/destination-profiles schema expects.

[SentinelOne] DESTRUCTIVE — Delete multiple scheduled tasks by ID. This cancels the future runs of several scheduled tasks at once. Nothing raises an alarm afterwards for a collection that was supposed to happen and did not. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/remote-ops/scheduled-tasks schema expects.

[SentinelOne] Get available Destination profiles. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the destination profiles for the scope — where collected forensic data is EXPORTED to. Read this before assuming forensic output stays inside the SentinelOne tenant. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).

[SentinelOne] Get available Scheduled Tasks. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the scheduled forensics and remote-script tasks for the scope: automation that will run with nobody watching. Read it before deleting any profile or script, because these tasks fail rather than fall back when their dependency disappears. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
idsstringnonullComma-separated list of ids to restrict the result to.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
searchQuerystringnonullFree-text search over the resource, as SentinelOne's own console search box would apply it.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Get Collection profile by ID. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
profileIdstringyesSentinelOne's own id for the remote forensics resource this call targets.

[SentinelOne] Get Destination profile by ID. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
profileIdstringyesSentinelOne's own id for the remote forensics resource this call targets.

[SentinelOne] Returns collection file download pre-signed url. SentinelOne requires siteId, agentId, signature, signatureType and uploadedTimestamp on this endpoint — pass them in filtersJson or the call fails with a 400. siteId: the site id. agentId: the agent id. signature: the collected file's signature. signatureType: the type of that signature. uploadedTimestamp: the timestamp SentinelOne recorded for the upload. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns a short-lived pre-signed download URL for a collected forensics file. The URL is the artifact, not the file: fetch it promptly, and treat it as sensitive because it grants access without further authentication. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).

[SentinelOne] Get list of available Collection profiles. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the collection profiles for the scope — each one decides which artifact types a forensics collection gathers. Profile ids for s1_start_forensics_collection come from here. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
idsstringnonullComma-separated list of ids to restrict the result to.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
searchQuerystringnonullFree-text search over the resource, as SentinelOne's own console search box would apply it.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Get list of supported artifact types. Returns the artifact types a collection profile may gather. Read it before composing a profile — an unsupported type is a 400, not an ignored field. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

[SentinelOne] Get results sent to data exporter. SentinelOne requires agentId on this endpoint — pass it in filtersJson or the call fails with a 400. agentId: the agent id. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns what the data exporter has actually sent through the destination profiles — the audit trail of forensic data leaving the tenant. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).

[SentinelOne] Return result of collection task. SentinelOne requires taskId on this endpoint — pass it in filtersJson or the call fails with a 400. taskId: the task id. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the result metadata of a forensics collection task. Use s1_get_forensics_collection_file_url to get a download link for the collected file itself. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).

[SentinelOne] DESTRUCTIVE — Schedule forensics for future run. This SCHEDULES a forensics collection, so it fires later with nobody watching. Everything true of running one now — endpoint CPU and disk cost, large uploads — is true then, against whatever machines match the scope at that time rather than the ones matching it today. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/remote-ops/schedule/forensics schema expects.

[SentinelOne] DESTRUCTIVE — Schedule remote script for future run. This SCHEDULES a remote script execution, so you are approving now a code execution that will run on live endpoints at a time you will not be watching, against whatever machines match the scope then. Read the script with s1_get_script_content before you schedule it. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/remote-ops/schedule/remote-script schema expects.

[SentinelOne] DESTRUCTIVE — Set profile as default profile of the scope. This makes the profile the DEFAULT export destination for the whole scope, so tasks that named no profile start exporting here — including tasks somebody else created. Confirm the destination belongs to the customer. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/remote-ops/data-exporter/destination-profiles/set-default schema expects.

[SentinelOne] DESTRUCTIVE — Start collection of Forensics artifacts according to specified profile. This runs a live forensics collection on the endpoints you target. It consumes endpoint CPU and disk while it runs, and it uploads artifacts that can be very large. Scope it tightly — a broad collection across a site is a noticeable performance event for the people using those machines. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/remote-ops/forensics/start-collection schema expects.

[SentinelOne] DESTRUCTIVE — Update Collection profile by ID. This replaces the collection profile rather than merging into it, so an omitted field is cleared. Every scheduled task using this profile changes what it gathers from the next run onward. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/remote-ops/forensics/collection-profiles/ schema expects.
profileIdstringyesSentinelOne's own id for the remote forensics resource this call targets.

[SentinelOne] DESTRUCTIVE — Update existing Destination profile. This replaces the destination profile rather than merging into it, so an omitted field is cleared. Changing the destination redirects where forensic data is exported — confirm the new destination belongs to the customer. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/remote-ops/data-exporter/destination-profiles/ schema expects.
profileIdstringyesSentinelOne's own id for the remote forensics resource this call targets.

[SentinelOne] DESTRUCTIVE — Update existing Scheduled task. This replaces the scheduled task rather than merging into it, so an omitted field is cleared. Both the schedule and the scope can move, so read s1_get_available_scheduled_tasks and edit that payload. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/remote-ops/scheduled-tasks/ schema expects.
scheduledTaskIdstringyesSentinelOne's own id for the remote forensics resource this call targets.

Remote Scripts

ToolPlanAccessSummary
s1_approve_decline_pending_executionProDestructiveDESTRUCTIVE — Approve/decline pending execution.
s1_check_whether_guardrail_applies_executionFreeRead-onlyCheck whether guardrail applies to an execution.
s1_delete_remote_script_guardrails_configProDestructiveDESTRUCTIVE — Deletes a specific guardrails configuration.
s1_delete_scriptsProDestructiveDESTRUCTIVE — Delete Scripts.
s1_get_paginated_pending_executionsFreeRead-onlyGet paginated pending executions.
s1_get_remote_script_guardrails_configFreeRead-onlyGets a guardrails configuration for a given scope.
s1_get_remote_scripts_tasks_statusFreeRead-onlyGet Remote Scripts Tasks Status.
s1_get_script_contentFreeRead-onlyGet script content.
s1_get_script_resultsFreeRead-onlyGet Script Results.
s1_get_scriptsFreeRead-onlyGet Scripts.
s1_get_upload_limit_packageFreeRead-onlyGet upload limit for Package.
s1_run_remote_scriptProDestructiveDESTRUCTIVE — Run Remote Script.
s1_update_scriptProDestructiveDESTRUCTIVE — Update a Script.
s1_update_script_remote_scriptsProDestructiveDESTRUCTIVE — Update a Script.
s1_upload_new_scriptProDestructiveDESTRUCTIVE — Upload New Script.
s1_upsert_remote_script_guardrails_configProDestructiveDESTRUCTIVE — Updates or inserts (if record does not exist) a guardrails configuration.

[SentinelOne] DESTRUCTIVE — Approve/decline pending execution. Approving RELEASES a held script execution to the endpoints immediately — you are the guardrail this queue exists to provide. Read the pending execution with s1_get_paginated_pending_executions and the script body with s1_get_script_content before you approve it. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/remote-scripts/pending-executions/ schema expects.
pendingExecutionIdstringyesSentinelOne's own id for the remote scripts resource this call targets.

[SentinelOne] Check whether guardrail applies to an execution. This is a POST that READS: the criteria travel in the request body, and nothing is created or changed. Checks whether a guardrail would block a proposed execution, WITHOUT running it. This is the safe pre-flight for s1_run_remote_script. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/remote-scripts/guardrails/check schema expects.

[SentinelOne] DESTRUCTIVE — Deletes a specific guardrails configuration. Guardrails are what stop a remote script from doing something the console forbids. DELETING the configuration removes that limit for the scope, so every later script execution there is permitted to do more than it could a moment ago. This is a privilege-widening change and nothing in the console flags it afterwards. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/remote-scripts/guardrails/configuration schema expects.

[SentinelOne] DESTRUCTIVE — Delete Scripts. Deleting a script breaks every scheduled task and workflow that calls it, and those fail rather than skipping. Read s1_get_available_scheduled_tasks before you delete one. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/remote-scripts schema expects.

[SentinelOne] Get paginated pending executions. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns script executions waiting on approval. Each one is code held back from live endpoints until somebody releases it with s1_approve_decline_pending_execution — read the script content before you approve. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Gets a guardrails configuration for a given scope. SentinelOne requires scopeId and scopeLevel on this endpoint — pass them in filtersJson or the call fails with a 400. scopeId: the scope id. scopeLevel: scope level, one of 'account', 'site' or 'group'. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the guardrails configuration for the scope — the limits on what a remote script is permitted to do. Read it before changing it: loosening or deleting a guardrail widens what every later execution in that scope may do. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).

[SentinelOne] Get Remote Scripts Tasks Status. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the status of dispatched remote-script tasks — what ran, on which endpoints, and how it ended. A script dispatch answers 200 immediately, so this is where you find out whether it actually worked. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
idsstringnonullComma-separated list of ids to restrict the result to.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
searchQuerystringnonullFree-text search over the resource, as SentinelOne's own console search box would apply it.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Get script content. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the CODE of a remote script. Read it before s1_run_remote_script or before approving a pending execution: this is the only place the thing you are about to run on customer endpoints is visible. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).

[SentinelOne] Get Script Results. This is a POST that READS: the criteria travel in the request body, and nothing is created or changed. Returns download URLs for the OUTPUT of scripts that already ran. It fetches stored results and dispatches nothing to endpoints, which is why it is a read despite its POST verb and its fetch-files path. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/remote-scripts/fetch-files schema expects.

[SentinelOne] Get Scripts. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. Returns the remote-script library for the scope. Script ids for s1_run_remote_script come from here. This lists metadata only — read the actual code with s1_get_script_content before running anything. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
idsstringnonullComma-separated list of ids to restrict the result to.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
searchQuerystringnonullFree-text search over the resource, as SentinelOne's own console search box would apply it.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Get upload limit for Package. Returns the size limit for a script package upload. Read it before s1_upload_new_script if the package is large. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

[SentinelOne] DESTRUCTIVE — Run Remote Script. This RUNS CODE on live customer endpoints. It executes with the agent's privileges, it cannot be recalled once dispatched, and it acts on every endpoint matching the filter in the body — an over-broad or empty filter reaches the whole fleet and SentinelOne answers 200 either way. Run the matching agent read with countOnly=true first to see the blast radius, and read the script with s1_get_script_content so you know what you are about to run. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/remote-scripts/execute schema expects.

[SentinelOne] DESTRUCTIVE — Update a Script. This replaces the stored script, so every later execution — including already-scheduled ones — runs the NEW content. Review it: the approval somebody gave the old version does not carry over. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/remote-scripts/ schema expects.
scriptIdstringyesSentinelOne's own id for the remote scripts resource this call targets.

[SentinelOne] DESTRUCTIVE — Update a Script. This replaces the stored script, so every later execution — including already-scheduled ones — runs the NEW content. Review it: the approval somebody gave the old version does not carry over. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
scriptIdstringyesSentinelOne's own id for the remote scripts resource this call targets.

[SentinelOne] DESTRUCTIVE — Upload New Script. Whatever you upload here becomes runnable on customer endpoints by anyone holding script permissions. Review the content — this is the supply side of remote code execution, and the review has to happen now rather than at run time. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).

[SentinelOne] DESTRUCTIVE — Updates or inserts (if record does not exist) a guardrails configuration. Guardrails are what stop a remote script from doing something the console forbids. Rewriting the configuration WIDENS or narrows what every later script execution in that scope may do — this is a privilege change, not a settings tweak. It also replaces the whole configuration rather than merging, so an omitted field is cleared. Read s1_get_remote_script_guardrails_config and edit that payload. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/remote-scripts/guardrails/configuration schema expects.

Account

ToolPlanAccessSummary
s1_count_account_asset_filtersFreeRead-onlyReturns the number of Account assets behind each filter value — the counts the console shows beside each facet.
s1_export_account_assetsFreeRead-onlyExports the Account asset class as JSON.
s1_get_account_asset_filter_valuesFreeRead-onlyReturns matching values for one Account asset filter field — the type-ahead behind the console's filter box.
s1_get_account_asset_text_filtersFreeRead-onlyLists the Account asset fields that a free-text search covers.
s1_list_account_asset_actionsFreeRead-onlyLists the inventory actions available for Account assets, with each action's current status.
s1_list_account_assetsFreeRead-onlyLists the Account asset class of the asset inventory.
s1_run_account_asset_actionProDestructiveDESTRUCTIVE — runs an inventory action against the Account assets your request body selects.
s1_search_account_assetsFreeRead-onlySearches the Account asset class of the asset inventory using the filter criteria in the request body.

[SentinelOne] Returns the number of Account assets behind each filter value — the counts the console shows beside each facet. Use it to size a filter before you act on what it matches. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Exports the Account asset class as JSON. StackJack always sends exportFormat=json. SentinelOne REQUIRES that parameter and also offers CSV, but a CSV body is not JSON and this tool could not parse it — so the format is pinned here and filtersJson cannot override it. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Returns matching values for one Account asset filter field — the type-ahead behind the console's filter box. Use it to discover the exact values a filter accepts before passing them to s1_list_account_assets; SentinelOne rejects an unknown filter value with a 400 rather than ignoring it. Scope to one customer with siteIds / accountIds / groupIds. SentinelOne requires text and key on this endpoint — pass them in filtersJson or the call fails with a 400. text: the search text to match. key: the search field key, one of the documented `<field>__contains` names. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Lists the Account asset fields that a free-text search covers. Read it to learn which fields a free-text query will and will not match before you rely on one. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

[SentinelOne] Lists the inventory actions available for Account assets, with each action's current status. This is a POST that READS: the selection travels in the request body and nothing is changed. Call it before s1_run_account_asset_action to learn which action names that tool accepts. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/assets/account/available-actions/with-status schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Lists the Account asset class of the asset inventory. SentinelOne splits its inventory into 20 asset classes and this tool returns ONLY Account assets — use s1_list_assets when you want every class at once. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] DESTRUCTIVE — runs an inventory action against the Account assets your request body selects. The body carries a FILTER, so the action reaches everything that matches it, and an empty filter matches the whole class. Run s1_list_account_assets with countOnly=true and the SAME filter first, and read the count before you send this. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/assets/account/action schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Searches the Account asset class of the asset inventory using the filter criteria in the request body. This is a POST that READS — the vendor documents it as "POST API to get Assets", and it exists only because the inventory filter set is far too large for a query string. Nothing is created or changed. It is the body-filter twin of s1_list_account_assets. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/assets/account schema expects.
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

AI ML

ToolPlanAccessSummary
s1_count_ai_ml_asset_filtersFreeRead-onlyReturns the number of AI/ML assets behind each filter value — the counts the console shows beside each facet.
s1_export_ai_ml_assetsFreeRead-onlyExports the AI/ML asset class as JSON.
s1_get_ai_ml_asset_filter_valuesFreeRead-onlyReturns matching values for one AI/ML asset filter field — the type-ahead behind the console's filter box.
s1_get_ai_ml_asset_text_filtersFreeRead-onlyLists the AI/ML asset fields that a free-text search covers.
s1_list_ai_ml_asset_actionsFreeRead-onlyLists the inventory actions available for AI/ML assets, with each action's current status.
s1_list_ai_ml_assetsFreeRead-onlyLists the AI/ML asset class of the asset inventory.
s1_run_ai_ml_asset_actionProDestructiveDESTRUCTIVE — runs an inventory action against the AI/ML assets your request body selects.
s1_search_ai_ml_assetsFreeRead-onlySearches the AI/ML asset class of the asset inventory using the filter criteria in the request body.

[SentinelOne] Returns the number of AI/ML assets behind each filter value — the counts the console shows beside each facet. Use it to size a filter before you act on what it matches. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Exports the AI/ML asset class as JSON. StackJack always sends exportFormat=json. SentinelOne REQUIRES that parameter and also offers CSV, but a CSV body is not JSON and this tool could not parse it — so the format is pinned here and filtersJson cannot override it. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Returns matching values for one AI/ML asset filter field — the type-ahead behind the console's filter box. Use it to discover the exact values a filter accepts before passing them to s1_list_ai_ml_assets; SentinelOne rejects an unknown filter value with a 400 rather than ignoring it. Scope to one customer with siteIds / accountIds / groupIds. SentinelOne requires text and key on this endpoint — pass them in filtersJson or the call fails with a 400. text: the search text to match. key: the search field key, one of the documented `<field>__contains` names. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Lists the AI/ML asset fields that a free-text search covers. Read it to learn which fields a free-text query will and will not match before you rely on one. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

[SentinelOne] Lists the inventory actions available for AI/ML assets, with each action's current status. This is a POST that READS: the selection travels in the request body and nothing is changed. Call it before s1_run_ai_ml_asset_action to learn which action names that tool accepts. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/assets/ai-ml/available-actions/with-status schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Lists the AI/ML asset class of the asset inventory. SentinelOne splits its inventory into 20 asset classes and this tool returns ONLY AI/ML assets — use s1_list_assets when you want every class at once. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] DESTRUCTIVE — runs an inventory action against the AI/ML assets your request body selects. The body carries a FILTER, so the action reaches everything that matches it, and an empty filter matches the whole class. Run s1_list_ai_ml_assets with countOnly=true and the SAME filter first, and read the count before you send this. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/assets/ai-ml/action schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Searches the AI/ML asset class of the asset inventory using the filter criteria in the request body. This is a POST that READS — the vendor documents it as "POST API to get Assets", and it exists only because the inventory filter set is far too large for a query string. Nothing is created or changed. It is the body-filter twin of s1_list_ai_ml_assets. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/assets/ai-ml schema expects.
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

Application Integration

ToolPlanAccessSummary
s1_count_application_integration_asset_filtersFreeRead-onlyReturns the number of Application Integration assets behind each filter value — the counts the console shows beside each facet.
s1_export_application_integration_assetsFreeRead-onlyExports the Application Integration asset class as JSON.
s1_get_application_integration_asset_filter_valuesFreeRead-onlyReturns matching values for one Application Integration asset filter field — the type-ahead behind the console's filter box.
s1_get_application_integration_asset_text_filtersFreeRead-onlyLists the Application Integration asset fields that a free-text search covers.
s1_list_application_integration_asset_actionsFreeRead-onlyLists the inventory actions available for Application Integration assets, with each action's current status.
s1_list_application_integration_assetsFreeRead-onlyLists the Application Integration asset class of the asset inventory.
s1_run_application_integration_asset_actionProDestructiveDESTRUCTIVE — runs an inventory action against the Application Integration assets your request body selects.
s1_search_application_integration_assetsFreeRead-onlySearches the Application Integration asset class of the asset inventory using the filter criteria in the request body.

[SentinelOne] Returns the number of Application Integration assets behind each filter value — the counts the console shows beside each facet. Use it to size a filter before you act on what it matches. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Exports the Application Integration asset class as JSON. StackJack always sends exportFormat=json. SentinelOne REQUIRES that parameter and also offers CSV, but a CSV body is not JSON and this tool could not parse it — so the format is pinned here and filtersJson cannot override it. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Returns matching values for one Application Integration asset filter field — the type-ahead behind the console's filter box. Use it to discover the exact values a filter accepts before passing them to s1_list_application_integration_assets; SentinelOne rejects an unknown filter value with a 400 rather than ignoring it. Scope to one customer with siteIds / accountIds / groupIds. SentinelOne requires text and key on this endpoint — pass them in filtersJson or the call fails with a 400. text: the search text to match. key: the search field key, one of the documented `<field>__contains` names. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Lists the Application Integration asset fields that a free-text search covers. Read it to learn which fields a free-text query will and will not match before you rely on one. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

[SentinelOne] Lists the inventory actions available for Application Integration assets, with each action's current status. This is a POST that READS: the selection travels in the request body and nothing is changed. Call it before s1_run_application_integration_asset_action to learn which action names that tool accepts. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/assets/application-integration/available-actions/with-status schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Lists the Application Integration asset class of the asset inventory. SentinelOne splits its inventory into 20 asset classes and this tool returns ONLY Application Integration assets — use s1_list_assets when you want every class at once. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] DESTRUCTIVE — runs an inventory action against the Application Integration assets your request body selects. The body carries a FILTER, so the action reaches everything that matches it, and an empty filter matches the whole class. Run s1_list_application_integration_assets with countOnly=true and the SAME filter first, and read the count before you send this. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/assets/application-integration/action schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Searches the Application Integration asset class of the asset inventory using the filter criteria in the request body. This is a POST that READS — the vendor documents it as "POST API to get Assets", and it exists only because the inventory filter set is far too large for a query string. Nothing is created or changed. It is the body-filter twin of s1_list_application_integration_assets. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/assets/application-integration schema expects.
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

Asset Inventory

ToolPlanAccessSummary
s1_export_asset_cloud_tagsFreeRead-onlyExports the cloud provider tags attached to inventory assets as JSON.
s1_export_assetsFreeRead-onlyExports assets across every inventory class as JSON.
s1_get_asset_category_countsFreeRead-onlyReturns the asset inventory categories and the number of assets in each.
s1_get_asset_inventory_countsFreeRead-onlyReturns the asset counts behind each inventory menu item — the numbers the console shows next to each asset class.
s1_get_asset_subcategory_countsFreeRead-onlyReturns the per-subcategory asset counts within the inventory categories.
s1_list_any_asset_actionsFreeRead-onlyLists the inventory actions available for the assets your request body selects, across every asset class, with each action's current status.
s1_list_assetsFreeRead-onlyLists assets across EVERY class of the asset inventory.
s1_run_any_asset_actionProDestructiveDESTRUCTIVE — runs an inventory action against assets in ANY class, selected by the filter in the request body.
s1_search_assetsFreeRead-onlySearches assets across EVERY class of the asset inventory using the filter criteria in the request body.

[SentinelOne] Exports the cloud provider tags attached to inventory assets as JSON. These are the tags that came from AWS, Azure or GCP, not the SentinelOne tags that s1_list_asset_tags returns. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Exports assets across every inventory class as JSON. StackJack always sends exportFormat=json. SentinelOne REQUIRES that parameter and also offers CSV, but a CSV body is not JSON and this tool could not parse it — so the format is pinned here and filtersJson cannot override it. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Returns the asset inventory categories and the number of assets in each. A category is the top level of the inventory tree; s1_get_asset_subcategory_counts breaks each one down further. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Returns the asset counts behind each inventory menu item — the numbers the console shows next to each asset class. Use it to see where a customer's assets actually are before you start querying individual classes. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Returns the per-subcategory asset counts within the inventory categories. Use it after s1_get_asset_category_counts to narrow down where a customer's assets sit. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Lists the inventory actions available for the assets your request body selects, across every asset class, with each action's current status. This is a POST that READS: the selection travels in the body and nothing is changed. Call it before s1_run_any_asset_action to learn which action names that tool accepts. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/assets/available-actions/with-status schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Lists assets across EVERY class of the asset inventory. SentinelOne splits its inventory into 20 asset classes — servers, workstations, devices, identities, containers, cloud accounts and more — and this is the all-classes view. Filter with the category and resourceType parameters, or call the per-class tool (for example s1_list_device_assets) when you already know the class. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] DESTRUCTIVE — runs an inventory action against assets in ANY class, selected by the filter in the request body. This is the BROADEST action tool in the inventory: it is not scoped to one asset class, so a loose or empty filter can reach servers, workstations, identities and cloud resources in a single call. Run s1_list_assets with countOnly=true and the SAME filter first, and read the count before you send this. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/assets/action schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Searches assets across EVERY class of the asset inventory using the filter criteria in the request body. This is a POST that READS — the vendor documents it as "POST API to get assets", and it exists only because the inventory filter set is far too large for a query string. Nothing is created or changed. It is the body-filter twin of s1_list_assets. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/assets schema expects.
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

Cloud Application

ToolPlanAccessSummary
s1_count_cloud_application_asset_filtersFreeRead-onlyReturns the number of Cloud Application assets behind each filter value — the counts the console shows beside each facet.
s1_export_cloud_application_assetsFreeRead-onlyExports the Cloud Application asset class as JSON.
s1_get_cloud_application_asset_filter_valuesFreeRead-onlyReturns matching values for one Cloud Application asset filter field — the type-ahead behind the console's filter box.
s1_get_cloud_application_asset_text_filtersFreeRead-onlyLists the Cloud Application asset fields that a free-text search covers.
s1_list_cloud_application_asset_actionsFreeRead-onlyLists the inventory actions available for Cloud Application assets, with each action's current status.
s1_list_cloud_application_assetsFreeRead-onlyLists the Cloud Application asset class of the asset inventory.
s1_run_cloud_application_asset_actionProDestructiveDESTRUCTIVE — runs an inventory action against the Cloud Application assets your request body selects.
s1_search_cloud_application_assetsFreeRead-onlySearches the Cloud Application asset class of the asset inventory using the filter criteria in the request body.

[SentinelOne] Returns the number of Cloud Application assets behind each filter value — the counts the console shows beside each facet. Use it to size a filter before you act on what it matches. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Exports the Cloud Application asset class as JSON. StackJack always sends exportFormat=json. SentinelOne REQUIRES that parameter and also offers CSV, but a CSV body is not JSON and this tool could not parse it — so the format is pinned here and filtersJson cannot override it. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Returns matching values for one Cloud Application asset filter field — the type-ahead behind the console's filter box. Use it to discover the exact values a filter accepts before passing them to s1_list_cloud_application_assets; SentinelOne rejects an unknown filter value with a 400 rather than ignoring it. Scope to one customer with siteIds / accountIds / groupIds. SentinelOne requires text and key on this endpoint — pass them in filtersJson or the call fails with a 400. text: the search text to match. key: the search field key, one of the documented `<field>__contains` names. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Lists the Cloud Application asset fields that a free-text search covers. Read it to learn which fields a free-text query will and will not match before you rely on one. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

[SentinelOne] Lists the inventory actions available for Cloud Application assets, with each action's current status. This is a POST that READS: the selection travels in the request body and nothing is changed. Call it before s1_run_cloud_application_asset_action to learn which action names that tool accepts. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/assets/cloud-application/available-actions/with-status schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Lists the Cloud Application asset class of the asset inventory. SentinelOne splits its inventory into 20 asset classes and this tool returns ONLY Cloud Application assets — use s1_list_assets when you want every class at once. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] DESTRUCTIVE — runs an inventory action against the Cloud Application assets your request body selects. The body carries a FILTER, so the action reaches everything that matches it, and an empty filter matches the whole class. Run s1_list_cloud_application_assets with countOnly=true and the SAME filter first, and read the count before you send this. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/assets/cloud-application/action schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Searches the Cloud Application asset class of the asset inventory using the filter criteria in the request body. This is a POST that READS — the vendor documents it as "POST API to get Assets", and it exists only because the inventory filter set is far too large for a query string. Nothing is created or changed. It is the body-filter twin of s1_list_cloud_application_assets. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/assets/cloud-application schema expects.
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

Cloud Surface

ToolPlanAccessSummary
s1_count_cloud_surface_asset_filtersFreeRead-onlyReturns the number of Cloud Surface assets behind each filter value — the counts the console shows beside each facet.
s1_export_cloud_surface_assetsFreeRead-onlyExports the Cloud Surface asset class as JSON.
s1_get_cloud_surface_asset_filter_valuesFreeRead-onlyReturns matching values for one Cloud Surface asset filter field — the type-ahead behind the console's filter box.
s1_get_cloud_surface_asset_text_filtersFreeRead-onlyLists the Cloud Surface asset fields that a free-text search covers.
s1_list_cloud_surface_asset_actionsFreeRead-onlyLists the inventory actions available for Cloud Surface assets, with each action's current status.
s1_list_cloud_surface_assetsFreeRead-onlyLists the Cloud Surface asset class of the asset inventory.
s1_run_cloud_surface_asset_actionProDestructiveDESTRUCTIVE — runs an inventory action against the Cloud Surface assets your request body selects.

[SentinelOne] Returns the number of Cloud Surface assets behind each filter value — the counts the console shows beside each facet. Use it to size a filter before you act on what it matches. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Exports the Cloud Surface asset class as JSON. StackJack always sends exportFormat=json. SentinelOne REQUIRES that parameter and also offers CSV, but a CSV body is not JSON and this tool could not parse it — so the format is pinned here and filtersJson cannot override it. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Returns matching values for one Cloud Surface asset filter field — the type-ahead behind the console's filter box. Use it to discover the exact values a filter accepts before passing them to s1_list_cloud_surface_assets; SentinelOne rejects an unknown filter value with a 400 rather than ignoring it. Scope to one customer with siteIds / accountIds / groupIds. SentinelOne requires key and text on this endpoint — pass them in filtersJson or the call fails with a 400. key: the search field key, one of the documented `<field>__contains` names. text: the search text to match. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Lists the Cloud Surface asset fields that a free-text search covers. Read it to learn which fields a free-text query will and will not match before you rely on one. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

[SentinelOne] Lists the inventory actions available for Cloud Surface assets, with each action's current status. This is a POST that READS: the selection travels in the request body and nothing is changed. Call it before s1_run_cloud_surface_asset_action to learn which action names that tool accepts. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/assets/surface/cloud/available-actions/with-status schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Lists the Cloud Surface asset class of the asset inventory. SentinelOne splits its inventory into 20 asset classes and this tool returns ONLY Cloud Surface assets — use s1_list_assets when you want every class at once. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] DESTRUCTIVE — runs an inventory action against the Cloud Surface assets your request body selects. The body carries a FILTER, so the action reaches everything that matches it, and an empty filter matches the whole class. Run s1_list_cloud_surface_assets with countOnly=true and the SAME filter first, and read the count before you send this. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/assets/surface/cloud/action schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

Container

ToolPlanAccessSummary
s1_count_container_asset_filtersFreeRead-onlyReturns the number of Container assets behind each filter value — the counts the console shows beside each facet.
s1_export_container_assetsFreeRead-onlyExports the Container asset class as JSON.
s1_get_container_asset_filter_valuesFreeRead-onlyReturns matching values for one Container asset filter field — the type-ahead behind the console's filter box.
s1_get_container_asset_text_filtersFreeRead-onlyLists the Container asset fields that a free-text search covers.
s1_list_container_asset_actionsFreeRead-onlyLists the inventory actions available for Container assets, with each action's current status.
s1_list_container_assetsFreeRead-onlyLists the Container asset class of the asset inventory.
s1_run_container_asset_actionProDestructiveDESTRUCTIVE — runs an inventory action against the Container assets your request body selects.
s1_search_container_assetsFreeRead-onlySearches the Container asset class of the asset inventory using the filter criteria in the request body.

[SentinelOne] Returns the number of Container assets behind each filter value — the counts the console shows beside each facet. Use it to size a filter before you act on what it matches. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Exports the Container asset class as JSON. StackJack always sends exportFormat=json. SentinelOne REQUIRES that parameter and also offers CSV, but a CSV body is not JSON and this tool could not parse it — so the format is pinned here and filtersJson cannot override it. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Returns matching values for one Container asset filter field — the type-ahead behind the console's filter box. Use it to discover the exact values a filter accepts before passing them to s1_list_container_assets; SentinelOne rejects an unknown filter value with a 400 rather than ignoring it. Scope to one customer with siteIds / accountIds / groupIds. SentinelOne requires key and text on this endpoint — pass them in filtersJson or the call fails with a 400. key: the search field key, one of the documented `<field>__contains` names. text: the search text to match. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Lists the Container asset fields that a free-text search covers. Read it to learn which fields a free-text query will and will not match before you rely on one. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

[SentinelOne] Lists the inventory actions available for Container assets, with each action's current status. This is a POST that READS: the selection travels in the request body and nothing is changed. Call it before s1_run_container_asset_action to learn which action names that tool accepts. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/assets/container/available-actions/with-status schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Lists the Container asset class of the asset inventory. SentinelOne splits its inventory into 20 asset classes and this tool returns ONLY Container assets — use s1_list_assets when you want every class at once. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] DESTRUCTIVE — runs an inventory action against the Container assets your request body selects. The body carries a FILTER, so the action reaches everything that matches it, and an empty filter matches the whole class. Run s1_list_container_assets with countOnly=true and the SAME filter first, and read the count before you send this. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/assets/container/action schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Searches the Container asset class of the asset inventory using the filter criteria in the request body. This is a POST that READS — the vendor documents it as "POST API to get Assets", and it exists only because the inventory filter set is far too large for a query string. Nothing is created or changed. It is the body-filter twin of s1_list_container_assets. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/assets/container schema expects.
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

Data Analysis

ToolPlanAccessSummary
s1_count_data_analysis_asset_filtersFreeRead-onlyReturns the number of Data Analysis assets behind each filter value — the counts the console shows beside each facet.
s1_export_data_analysis_assetsFreeRead-onlyExports the Data Analysis asset class as JSON.
s1_get_data_analysis_asset_filter_valuesFreeRead-onlyReturns matching values for one Data Analysis asset filter field — the type-ahead behind the console's filter box.
s1_get_data_analysis_asset_text_filtersFreeRead-onlyLists the Data Analysis asset fields that a free-text search covers.
s1_list_data_analysis_asset_actionsFreeRead-onlyLists the inventory actions available for Data Analysis assets, with each action's current status.
s1_list_data_analysis_assetsFreeRead-onlyLists the Data Analysis asset class of the asset inventory.
s1_run_data_analysis_asset_actionProDestructiveDESTRUCTIVE — runs an inventory action against the Data Analysis assets your request body selects.
s1_search_data_analysis_assetsFreeRead-onlySearches the Data Analysis asset class of the asset inventory using the filter criteria in the request body.

[SentinelOne] Returns the number of Data Analysis assets behind each filter value — the counts the console shows beside each facet. Use it to size a filter before you act on what it matches. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Exports the Data Analysis asset class as JSON. StackJack always sends exportFormat=json. SentinelOne REQUIRES that parameter and also offers CSV, but a CSV body is not JSON and this tool could not parse it — so the format is pinned here and filtersJson cannot override it. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Returns matching values for one Data Analysis asset filter field — the type-ahead behind the console's filter box. Use it to discover the exact values a filter accepts before passing them to s1_list_data_analysis_assets; SentinelOne rejects an unknown filter value with a 400 rather than ignoring it. Scope to one customer with siteIds / accountIds / groupIds. SentinelOne requires text and key on this endpoint — pass them in filtersJson or the call fails with a 400. text: the search text to match. key: the search field key, one of the documented `<field>__contains` names. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Lists the Data Analysis asset fields that a free-text search covers. Read it to learn which fields a free-text query will and will not match before you rely on one. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

[SentinelOne] Lists the inventory actions available for Data Analysis assets, with each action's current status. This is a POST that READS: the selection travels in the request body and nothing is changed. Call it before s1_run_data_analysis_asset_action to learn which action names that tool accepts. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/assets/data-analysis/available-actions/with-status schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Lists the Data Analysis asset class of the asset inventory. SentinelOne splits its inventory into 20 asset classes and this tool returns ONLY Data Analysis assets — use s1_list_assets when you want every class at once. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] DESTRUCTIVE — runs an inventory action against the Data Analysis assets your request body selects. The body carries a FILTER, so the action reaches everything that matches it, and an empty filter matches the whole class. Run s1_list_data_analysis_assets with countOnly=true and the SAME filter first, and read the count before you send this. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/assets/data-analysis/action schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Searches the Data Analysis asset class of the asset inventory using the filter criteria in the request body. This is a POST that READS — the vendor documents it as "POST API to get Assets", and it exists only because the inventory filter set is far too large for a query string. Nothing is created or changed. It is the body-filter twin of s1_list_data_analysis_assets. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/assets/data-analysis schema expects.
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

Data Store

ToolPlanAccessSummary
s1_count_data_store_asset_filtersFreeRead-onlyReturns the number of Data Store assets behind each filter value — the counts the console shows beside each facet.
s1_export_data_store_assetsFreeRead-onlyExports the Data Store asset class as JSON.
s1_get_data_store_asset_filter_valuesFreeRead-onlyReturns matching values for one Data Store asset filter field — the type-ahead behind the console's filter box.
s1_get_data_store_asset_text_filtersFreeRead-onlyLists the Data Store asset fields that a free-text search covers.
s1_list_data_store_asset_actionsFreeRead-onlyLists the inventory actions available for Data Store assets, with each action's current status.
s1_list_data_store_assetsFreeRead-onlyLists the Data Store asset class of the asset inventory.
s1_run_data_store_asset_actionProDestructiveDESTRUCTIVE — runs an inventory action against the Data Store assets your request body selects.
s1_search_data_store_assetsFreeRead-onlySearches the Data Store asset class of the asset inventory using the filter criteria in the request body.

[SentinelOne] Returns the number of Data Store assets behind each filter value — the counts the console shows beside each facet. Use it to size a filter before you act on what it matches. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Exports the Data Store asset class as JSON. StackJack always sends exportFormat=json. SentinelOne REQUIRES that parameter and also offers CSV, but a CSV body is not JSON and this tool could not parse it — so the format is pinned here and filtersJson cannot override it. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Returns matching values for one Data Store asset filter field — the type-ahead behind the console's filter box. Use it to discover the exact values a filter accepts before passing them to s1_list_data_store_assets; SentinelOne rejects an unknown filter value with a 400 rather than ignoring it. Scope to one customer with siteIds / accountIds / groupIds. SentinelOne requires key and text on this endpoint — pass them in filtersJson or the call fails with a 400. key: the search field key, one of the documented `<field>__contains` names. text: the search text to match. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Lists the Data Store asset fields that a free-text search covers. Read it to learn which fields a free-text query will and will not match before you rely on one. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

[SentinelOne] Lists the inventory actions available for Data Store assets, with each action's current status. This is a POST that READS: the selection travels in the request body and nothing is changed. Call it before s1_run_data_store_asset_action to learn which action names that tool accepts. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/assets/data-store/available-actions/with-status schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Lists the Data Store asset class of the asset inventory. SentinelOne splits its inventory into 20 asset classes and this tool returns ONLY Data Store assets — use s1_list_assets when you want every class at once. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] DESTRUCTIVE — runs an inventory action against the Data Store assets your request body selects. The body carries a FILTER, so the action reaches everything that matches it, and an empty filter matches the whole class. Run s1_list_data_store_assets with countOnly=true and the SAME filter first, and read the count before you send this. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/assets/data-store/action schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Searches the Data Store asset class of the asset inventory using the filter criteria in the request body. This is a POST that READS — the vendor documents it as "POST API to get Assets", and it exists only because the inventory filter set is far too large for a query string. Nothing is created or changed. It is the body-filter twin of s1_list_data_store_assets. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/assets/data-store schema expects.
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

Developer Tool

ToolPlanAccessSummary
s1_count_developer_tool_asset_filtersFreeRead-onlyReturns the number of Developer Tool assets behind each filter value — the counts the console shows beside each facet.
s1_export_developer_tool_assetsFreeRead-onlyExports the Developer Tool asset class as JSON.
s1_get_developer_tool_asset_filter_valuesFreeRead-onlyReturns matching values for one Developer Tool asset filter field — the type-ahead behind the console's filter box.
s1_get_developer_tool_asset_text_filtersFreeRead-onlyLists the Developer Tool asset fields that a free-text search covers.
s1_list_developer_tool_asset_actionsFreeRead-onlyLists the inventory actions available for Developer Tool assets, with each action's current status.
s1_list_developer_tool_assetsFreeRead-onlyLists the Developer Tool asset class of the asset inventory.
s1_run_developer_tool_asset_actionProDestructiveDESTRUCTIVE — runs an inventory action against the Developer Tool assets your request body selects.
s1_search_developer_tool_assetsFreeRead-onlySearches the Developer Tool asset class of the asset inventory using the filter criteria in the request body.

[SentinelOne] Returns the number of Developer Tool assets behind each filter value — the counts the console shows beside each facet. Use it to size a filter before you act on what it matches. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Exports the Developer Tool asset class as JSON. StackJack always sends exportFormat=json. SentinelOne REQUIRES that parameter and also offers CSV, but a CSV body is not JSON and this tool could not parse it — so the format is pinned here and filtersJson cannot override it. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Returns matching values for one Developer Tool asset filter field — the type-ahead behind the console's filter box. Use it to discover the exact values a filter accepts before passing them to s1_list_developer_tool_assets; SentinelOne rejects an unknown filter value with a 400 rather than ignoring it. Scope to one customer with siteIds / accountIds / groupIds. SentinelOne requires text and key on this endpoint — pass them in filtersJson or the call fails with a 400. text: the search text to match. key: the search field key, one of the documented `<field>__contains` names. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Lists the Developer Tool asset fields that a free-text search covers. Read it to learn which fields a free-text query will and will not match before you rely on one. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

[SentinelOne] Lists the inventory actions available for Developer Tool assets, with each action's current status. This is a POST that READS: the selection travels in the request body and nothing is changed. Call it before s1_run_developer_tool_asset_action to learn which action names that tool accepts. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/assets/developer-tool/available-actions/with-status schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Lists the Developer Tool asset class of the asset inventory. SentinelOne splits its inventory into 20 asset classes and this tool returns ONLY Developer Tool assets — use s1_list_assets when you want every class at once. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] DESTRUCTIVE — runs an inventory action against the Developer Tool assets your request body selects. The body carries a FILTER, so the action reaches everything that matches it, and an empty filter matches the whole class. Run s1_list_developer_tool_assets with countOnly=true and the SAME filter first, and read the count before you send this. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/assets/developer-tool/action schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Searches the Developer Tool asset class of the asset inventory using the filter criteria in the request body. This is a POST that READS — the vendor documents it as "POST API to get Assets", and it exists only because the inventory filter set is far too large for a query string. Nothing is created or changed. It is the body-filter twin of s1_list_developer_tool_assets. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/assets/developer-tool schema expects.
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

Device

ToolPlanAccessSummary
s1_count_device_asset_filtersFreeRead-onlyReturns the number of Device assets behind each filter value — the counts the console shows beside each facet.
s1_export_device_assetsFreeRead-onlyExports the Device asset class as JSON.
s1_get_device_asset_filter_valuesFreeRead-onlyReturns matching values for one Device asset filter field — the type-ahead behind the console's filter box.
s1_get_device_asset_text_filtersFreeRead-onlyLists the Device asset fields that a free-text search covers.
s1_list_device_asset_actionsFreeRead-onlyLists the inventory actions available for Device assets, with each action's current status.
s1_list_device_assetsFreeRead-onlyLists the Device asset class of the asset inventory.
s1_run_device_asset_actionProDestructiveDESTRUCTIVE — runs an inventory action against the Device assets your request body selects.
s1_search_device_assetsFreeRead-onlySearches the Device asset class of the asset inventory using the filter criteria in the request body.

[SentinelOne] Returns the number of Device assets behind each filter value — the counts the console shows beside each facet. Use it to size a filter before you act on what it matches. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Exports the Device asset class as JSON. StackJack always sends exportFormat=json. SentinelOne REQUIRES that parameter and also offers CSV, but a CSV body is not JSON and this tool could not parse it — so the format is pinned here and filtersJson cannot override it. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Returns matching values for one Device asset filter field — the type-ahead behind the console's filter box. Use it to discover the exact values a filter accepts before passing them to s1_list_device_assets; SentinelOne rejects an unknown filter value with a 400 rather than ignoring it. Scope to one customer with siteIds / accountIds / groupIds. SentinelOne requires key and text on this endpoint — pass them in filtersJson or the call fails with a 400. key: the search field key, one of the documented `<field>__contains` names. text: the search text to match. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Lists the Device asset fields that a free-text search covers. Read it to learn which fields a free-text query will and will not match before you rely on one. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

[SentinelOne] Lists the inventory actions available for Device assets, with each action's current status. This is a POST that READS: the selection travels in the request body and nothing is changed. Call it before s1_run_device_asset_action to learn which action names that tool accepts. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/assets/device/available-actions/with-status schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Lists the Device asset class of the asset inventory. SentinelOne splits its inventory into 20 asset classes and this tool returns ONLY Device assets — use s1_list_assets when you want every class at once. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] DESTRUCTIVE — runs an inventory action against the Device assets your request body selects. The body carries a FILTER, so the action reaches everything that matches it, and an empty filter matches the whole class. Run s1_list_device_assets with countOnly=true and the SAME filter first, and read the count before you send this. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/assets/device/action schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Searches the Device asset class of the asset inventory using the filter criteria in the request body. This is a POST that READS — the vendor documents it as "POST API to get Assets", and it exists only because the inventory filter set is far too large for a query string. Nothing is created or changed. It is the body-filter twin of s1_list_device_assets. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/assets/device schema expects.
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

Endpoint Surface

ToolPlanAccessSummary
s1_count_endpoint_surface_asset_filtersFreeRead-onlyReturns the number of Endpoint Surface assets behind each filter value — the counts the console shows beside each facet.
s1_export_endpoint_surface_assetsFreeRead-onlyExports the Endpoint Surface asset class as JSON.
s1_get_endpoint_surface_asset_filter_valuesFreeRead-onlyReturns matching values for one Endpoint Surface asset filter field — the type-ahead behind the console's filter box.
s1_get_endpoint_surface_asset_text_filtersFreeRead-onlyLists the Endpoint Surface asset fields that a free-text search covers.
s1_list_endpoint_surface_asset_actionsFreeRead-onlyLists the inventory actions available for Endpoint Surface assets, with each action's current status.
s1_list_endpoint_surface_assetsFreeRead-onlyLists the Endpoint Surface asset class of the asset inventory.
s1_run_endpoint_surface_asset_actionProDestructiveDESTRUCTIVE — runs an inventory action against the Endpoint Surface assets your request body selects.
s1_search_endpoint_surface_assetsFreeRead-onlySearches the Endpoint Surface asset class of the asset inventory using the filter criteria in the request body.

[SentinelOne] Returns the number of Endpoint Surface assets behind each filter value — the counts the console shows beside each facet. Use it to size a filter before you act on what it matches. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Exports the Endpoint Surface asset class as JSON. StackJack always sends exportFormat=json. SentinelOne REQUIRES that parameter and also offers CSV, but a CSV body is not JSON and this tool could not parse it — so the format is pinned here and filtersJson cannot override it. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Returns matching values for one Endpoint Surface asset filter field — the type-ahead behind the console's filter box. Use it to discover the exact values a filter accepts before passing them to s1_list_endpoint_surface_assets; SentinelOne rejects an unknown filter value with a 400 rather than ignoring it. Scope to one customer with siteIds / accountIds / groupIds. SentinelOne requires key and text on this endpoint — pass them in filtersJson or the call fails with a 400. key: the search field key, one of the documented `<field>__contains` names. text: the search text to match. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Lists the Endpoint Surface asset fields that a free-text search covers. Read it to learn which fields a free-text query will and will not match before you rely on one. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

[SentinelOne] Lists the inventory actions available for Endpoint Surface assets, with each action's current status. This is a POST that READS: the selection travels in the request body and nothing is changed. Call it before s1_run_endpoint_surface_asset_action to learn which action names that tool accepts. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/assets/surface/endpoint/available-actions/with-status schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Lists the Endpoint Surface asset class of the asset inventory. SentinelOne splits its inventory into 20 asset classes and this tool returns ONLY Endpoint Surface assets — use s1_list_assets when you want every class at once. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] DESTRUCTIVE — runs an inventory action against the Endpoint Surface assets your request body selects. The body carries a FILTER, so the action reaches everything that matches it, and an empty filter matches the whole class. Run s1_list_endpoint_surface_assets with countOnly=true and the SAME filter first, and read the count before you send this. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/assets/surface/endpoint/action schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Searches the Endpoint Surface asset class of the asset inventory using the filter criteria in the request body. This is a POST that READS — the vendor documents it as "POST API to get Assets", and it exists only because the inventory filter set is far too large for a query string. Nothing is created or changed. It is the body-filter twin of s1_list_endpoint_surface_assets. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/assets/surface/endpoint schema expects.
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

Filters

ToolPlanAccessSummary
s1_count_asset_filtersFreeRead-onlyReturns the number of assets behind each inventory filter value, across every asset class — the counts the console shows beside each facet.
s1_get_asset_filter_valuesFreeRead-onlyReturns matching values for one inventory filter field across every asset class — the type-ahead behind the console's filter box.
s1_get_asset_text_filtersFreeRead-onlyLists the inventory fields that a free-text search covers, across every asset class.
s1_upload_asset_filter_csvProWriteUploads a CSV of asset identifiers and stores it as a reusable inventory filter, returning the csvFilterId that the inventory list tools accept.

[SentinelOne] Returns the number of assets behind each inventory filter value, across every asset class — the counts the console shows beside each facet. Use it to size a filter before you act on what it matches. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Returns matching values for one inventory filter field across every asset class — the type-ahead behind the console's filter box. Use it to discover the exact values a filter accepts before passing them to s1_list_assets; SentinelOne rejects an unknown filter value with a 400 rather than ignoring it. Scope to one customer with siteIds / accountIds / groupIds. SentinelOne requires key and text on this endpoint — pass them in filtersJson or the call fails with a 400. key: the search field key, one of the documented `<field>__contains` names. text: the search text to match. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Lists the inventory fields that a free-text search covers, across every asset class. Read it to learn which fields a free-text query will and will not match before you rely on one. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

[SentinelOne] Uploads a CSV of asset identifiers and stores it as a reusable inventory filter, returning the csvFilterId that the inventory list tools accept. This creates a saved filter and changes no asset, so it is not destructive — but the filter it creates can later be handed to a destructive action tool, so check what you uploaded. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).

Function

ToolPlanAccessSummary
s1_count_function_asset_filtersFreeRead-onlyReturns the number of Function assets behind each filter value — the counts the console shows beside each facet.
s1_export_function_assetsFreeRead-onlyExports the Function asset class as JSON.
s1_get_function_asset_filter_valuesFreeRead-onlyReturns matching values for one Function asset filter field — the type-ahead behind the console's filter box.
s1_get_function_asset_text_filtersFreeRead-onlyLists the Function asset fields that a free-text search covers.
s1_list_function_asset_actionsFreeRead-onlyLists the inventory actions available for Function assets, with each action's current status.
s1_list_function_assetsFreeRead-onlyLists the Function asset class of the asset inventory.
s1_run_function_asset_actionProDestructiveDESTRUCTIVE — runs an inventory action against the Function assets your request body selects.
s1_search_function_assetsFreeRead-onlySearches the Function asset class of the asset inventory using the filter criteria in the request body.

[SentinelOne] Returns the number of Function assets behind each filter value — the counts the console shows beside each facet. Use it to size a filter before you act on what it matches. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Exports the Function asset class as JSON. StackJack always sends exportFormat=json. SentinelOne REQUIRES that parameter and also offers CSV, but a CSV body is not JSON and this tool could not parse it — so the format is pinned here and filtersJson cannot override it. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Returns matching values for one Function asset filter field — the type-ahead behind the console's filter box. Use it to discover the exact values a filter accepts before passing them to s1_list_function_assets; SentinelOne rejects an unknown filter value with a 400 rather than ignoring it. Scope to one customer with siteIds / accountIds / groupIds. SentinelOne requires text and key on this endpoint — pass them in filtersJson or the call fails with a 400. text: the search text to match. key: the search field key, one of the documented `<field>__contains` names. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Lists the Function asset fields that a free-text search covers. Read it to learn which fields a free-text query will and will not match before you rely on one. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

[SentinelOne] Lists the inventory actions available for Function assets, with each action's current status. This is a POST that READS: the selection travels in the request body and nothing is changed. Call it before s1_run_function_asset_action to learn which action names that tool accepts. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/assets/function/available-actions/with-status schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Lists the Function asset class of the asset inventory. SentinelOne splits its inventory into 20 asset classes and this tool returns ONLY Function assets — use s1_list_assets when you want every class at once. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] DESTRUCTIVE — runs an inventory action against the Function assets your request body selects. The body carries a FILTER, so the action reaches everything that matches it, and an empty filter matches the whole class. Run s1_list_function_assets with countOnly=true and the SAME filter first, and read the count before you send this. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/assets/function/action schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Searches the Function asset class of the asset inventory using the filter criteria in the request body. This is a POST that READS — the vendor documents it as "POST API to get Assets", and it exists only because the inventory filter set is far too large for a query string. Nothing is created or changed. It is the body-filter twin of s1_list_function_assets. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/assets/function schema expects.
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

Governance

ToolPlanAccessSummary
s1_count_governance_asset_filtersFreeRead-onlyReturns the number of Governance assets behind each filter value — the counts the console shows beside each facet.
s1_export_governance_assetsFreeRead-onlyExports the Governance asset class as JSON.
s1_get_governance_asset_filter_valuesFreeRead-onlyReturns matching values for one Governance asset filter field — the type-ahead behind the console's filter box.
s1_get_governance_asset_text_filtersFreeRead-onlyLists the Governance asset fields that a free-text search covers.
s1_list_governance_asset_actionsFreeRead-onlyLists the inventory actions available for Governance assets, with each action's current status.
s1_list_governance_assetsFreeRead-onlyLists the Governance asset class of the asset inventory.
s1_run_governance_asset_actionProDestructiveDESTRUCTIVE — runs an inventory action against the Governance assets your request body selects.
s1_search_governance_assetsFreeRead-onlySearches the Governance asset class of the asset inventory using the filter criteria in the request body.

[SentinelOne] Returns the number of Governance assets behind each filter value — the counts the console shows beside each facet. Use it to size a filter before you act on what it matches. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Exports the Governance asset class as JSON. StackJack always sends exportFormat=json. SentinelOne REQUIRES that parameter and also offers CSV, but a CSV body is not JSON and this tool could not parse it — so the format is pinned here and filtersJson cannot override it. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Returns matching values for one Governance asset filter field — the type-ahead behind the console's filter box. Use it to discover the exact values a filter accepts before passing them to s1_list_governance_assets; SentinelOne rejects an unknown filter value with a 400 rather than ignoring it. Scope to one customer with siteIds / accountIds / groupIds. SentinelOne requires text and key on this endpoint — pass them in filtersJson or the call fails with a 400. text: the search text to match. key: the search field key, one of the documented `<field>__contains` names. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Lists the Governance asset fields that a free-text search covers. Read it to learn which fields a free-text query will and will not match before you rely on one. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

[SentinelOne] Lists the inventory actions available for Governance assets, with each action's current status. This is a POST that READS: the selection travels in the request body and nothing is changed. Call it before s1_run_governance_asset_action to learn which action names that tool accepts. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/assets/governance/available-actions/with-status schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Lists the Governance asset class of the asset inventory. SentinelOne splits its inventory into 20 asset classes and this tool returns ONLY Governance assets — use s1_list_assets when you want every class at once. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] DESTRUCTIVE — runs an inventory action against the Governance assets your request body selects. The body carries a FILTER, so the action reaches everything that matches it, and an empty filter matches the whole class. Run s1_list_governance_assets with countOnly=true and the SAME filter first, and read the count before you send this. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/assets/governance/action schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Searches the Governance asset class of the asset inventory using the filter criteria in the request body. This is a POST that READS — the vendor documents it as "POST API to get Assets", and it exists only because the inventory filter set is far too large for a query string. Nothing is created or changed. It is the body-filter twin of s1_list_governance_assets. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/assets/governance schema expects.
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

Identity

ToolPlanAccessSummary
s1_count_identity_asset_filtersFreeRead-onlyReturns the number of Identity assets behind each filter value — the counts the console shows beside each facet.
s1_export_identity_assetsFreeRead-onlyExports the Identity asset class as JSON.
s1_get_identity_asset_filter_valuesFreeRead-onlyReturns matching values for one Identity asset filter field — the type-ahead behind the console's filter box.
s1_get_identity_asset_text_filtersFreeRead-onlyLists the Identity asset fields that a free-text search covers.
s1_list_identity_asset_actionsFreeRead-onlyLists the inventory actions available for Identity assets, with each action's current status.
s1_list_identity_assetsFreeRead-onlyLists the Identity asset class of the asset inventory.
s1_run_identity_asset_actionProDestructiveDESTRUCTIVE — runs an inventory action against the Identity assets your request body selects.
s1_search_identity_assetsFreeRead-onlySearches the Identity asset class of the asset inventory using the filter criteria in the request body.

[SentinelOne] Returns the number of Identity assets behind each filter value — the counts the console shows beside each facet. Use it to size a filter before you act on what it matches. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Exports the Identity asset class as JSON. StackJack always sends exportFormat=json. SentinelOne REQUIRES that parameter and also offers CSV, but a CSV body is not JSON and this tool could not parse it — so the format is pinned here and filtersJson cannot override it. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Returns matching values for one Identity asset filter field — the type-ahead behind the console's filter box. Use it to discover the exact values a filter accepts before passing them to s1_list_identity_assets; SentinelOne rejects an unknown filter value with a 400 rather than ignoring it. Scope to one customer with siteIds / accountIds / groupIds. SentinelOne requires key and text on this endpoint — pass them in filtersJson or the call fails with a 400. key: the search field key, one of the documented `<field>__contains` names. text: the search text to match. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Lists the Identity asset fields that a free-text search covers. Read it to learn which fields a free-text query will and will not match before you rely on one. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

[SentinelOne] Lists the inventory actions available for Identity assets, with each action's current status. This is a POST that READS: the selection travels in the request body and nothing is changed. Call it before s1_run_identity_asset_action to learn which action names that tool accepts. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/assets/identity/available-actions/with-status schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Lists the Identity asset class of the asset inventory. SentinelOne splits its inventory into 20 asset classes and this tool returns ONLY Identity assets — use s1_list_assets when you want every class at once. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] DESTRUCTIVE — runs an inventory action against the Identity assets your request body selects. The body carries a FILTER, so the action reaches everything that matches it, and an empty filter matches the whole class. Run s1_list_identity_assets with countOnly=true and the SAME filter first, and read the count before you send this. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/assets/identity/action schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Searches the Identity asset class of the asset inventory using the filter criteria in the request body. This is a POST that READS — the vendor documents it as "POST API to get Assets", and it exists only because the inventory filter set is far too large for a query string. Nothing is created or changed. It is the body-filter twin of s1_list_identity_assets. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/assets/identity schema expects.
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

Identity Surface

ToolPlanAccessSummary
s1_count_identity_surface_asset_filtersFreeRead-onlyReturns the number of Identity Surface assets behind each filter value — the counts the console shows beside each facet.
s1_export_identity_surface_assetsFreeRead-onlyExports the Identity Surface asset class as JSON.
s1_get_identity_surface_asset_filter_valuesFreeRead-onlyReturns matching values for one Identity Surface asset filter field — the type-ahead behind the console's filter box.
s1_get_identity_surface_asset_text_filtersFreeRead-onlyLists the Identity Surface asset fields that a free-text search covers.
s1_list_identity_surface_asset_actionsFreeRead-onlyLists the inventory actions available for Identity Surface assets, with each action's current status.
s1_list_identity_surface_assetsFreeRead-onlyLists the Identity Surface asset class of the asset inventory.
s1_run_identity_surface_asset_actionProDestructiveDESTRUCTIVE — runs an inventory action against the Identity Surface assets your request body selects.

[SentinelOne] Returns the number of Identity Surface assets behind each filter value — the counts the console shows beside each facet. Use it to size a filter before you act on what it matches. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Exports the Identity Surface asset class as JSON. StackJack always sends exportFormat=json. SentinelOne REQUIRES that parameter and also offers CSV, but a CSV body is not JSON and this tool could not parse it — so the format is pinned here and filtersJson cannot override it. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Returns matching values for one Identity Surface asset filter field — the type-ahead behind the console's filter box. Use it to discover the exact values a filter accepts before passing them to s1_list_identity_surface_assets; SentinelOne rejects an unknown filter value with a 400 rather than ignoring it. Scope to one customer with siteIds / accountIds / groupIds. SentinelOne requires key and text on this endpoint — pass them in filtersJson or the call fails with a 400. key: the search field key, one of the documented `<field>__contains` names. text: the search text to match. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Lists the Identity Surface asset fields that a free-text search covers. Read it to learn which fields a free-text query will and will not match before you rely on one. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

[SentinelOne] Lists the inventory actions available for Identity Surface assets, with each action's current status. This is a POST that READS: the selection travels in the request body and nothing is changed. Call it before s1_run_identity_surface_asset_action to learn which action names that tool accepts. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/assets/surface/identity/available-actions/with-status schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Lists the Identity Surface asset class of the asset inventory. SentinelOne splits its inventory into 20 asset classes and this tool returns ONLY Identity Surface assets — use s1_list_assets when you want every class at once. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] DESTRUCTIVE — runs an inventory action against the Identity Surface assets your request body selects. The body carries a FILTER, so the action reaches everything that matches it, and an empty filter matches the whole class. Run s1_list_identity_surface_assets with countOnly=true and the SAME filter first, and read the count before you send this. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/assets/surface/identity/action schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

Network

ToolPlanAccessSummary
s1_count_network_asset_filtersFreeRead-onlyReturns the number of Network assets behind each filter value — the counts the console shows beside each facet.
s1_export_network_assetsFreeRead-onlyExports the Network asset class as JSON.
s1_get_network_asset_filter_valuesFreeRead-onlyReturns matching values for one Network asset filter field — the type-ahead behind the console's filter box.
s1_get_network_asset_text_filtersFreeRead-onlyLists the Network asset fields that a free-text search covers.
s1_list_network_asset_actionsFreeRead-onlyLists the inventory actions available for Network assets, with each action's current status.
s1_list_network_assetsFreeRead-onlyLists the Network asset class of the asset inventory.
s1_run_network_asset_actionProDestructiveDESTRUCTIVE — runs an inventory action against the Network assets your request body selects.
s1_search_network_assetsFreeRead-onlySearches the Network asset class of the asset inventory using the filter criteria in the request body.

[SentinelOne] Returns the number of Network assets behind each filter value — the counts the console shows beside each facet. Use it to size a filter before you act on what it matches. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Exports the Network asset class as JSON. StackJack always sends exportFormat=json. SentinelOne REQUIRES that parameter and also offers CSV, but a CSV body is not JSON and this tool could not parse it — so the format is pinned here and filtersJson cannot override it. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] Returns matching values for one Network asset filter field — the type-ahead behind the console's filter box. Use it to discover the exact values a filter accepts before passing them to s1_list_network_assets; SentinelOne rejects an unknown filter value with a 400 rather than ignoring it. Scope to one customer with siteIds / accountIds / groupIds. SentinelOne requires text and key on this endpoint — pass them in filtersJson or the call fails with a 400. text: the search text to match. key: the search field key, one of the documented `<field>__contains` names. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Lists the Network asset fields that a free-text search covers. Read it to learn which fields a free-text query will and will not match before you rely on one. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

[SentinelOne] Lists the inventory actions available for Network assets, with each action's current status. This is a POST that READS: the selection travels in the request body and nothing is changed. Call it before s1_run_network_asset_action to learn which action names that tool accepts. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/assets/network/available-actions/with-status schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Lists the Network asset class of the asset inventory. SentinelOne splits its inventory into 20 asset classes and this tool returns ONLY Network assets — use s1_list_assets when you want every class at once. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
countOnlybooleannonullReturn only the matching count, not the rows. Use this to check the blast radius of a filter before acting on it.
cursorstringnonullOpaque paging cursor. Pass the `pagination.nextCursor` value from the previous response; omit for the first page.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
limitintegernonullMaximum rows to return. SentinelOne caps this at 1000; larger values are clamped.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.
sortBystringnonullField to sort by. SentinelOne validates this against a PER-ENDPOINT enum — an unsupported value is a 400, not an ignored parameter.
sortOrderstringnonullSort direction: asc or desc.

[SentinelOne] DESTRUCTIVE — runs an inventory action against the Network assets your request body selects. The body carries a FILTER, so the action reaches everything that matches it, and an empty filter matches the whole class. Run s1_list_network_assets with countOnly=true and the SAME filter first, and read the count before you send this. A 200 response does not prove the change landed — SentinelOne returns a success-shaped body with an `affected` count that can be 0. Re-read to confirm. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/assets/network/action schema expects.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Searches the Network asset class of the asset inventory using the filter criteria in the request body. This is a POST that READS — the vendor documents it as "POST API to get Assets", and it exists only because the inventory filter set is far too large for a query string. Nothing is created or changed. It is the body-filter twin of s1_list_network_assets. Scope to one customer with siteIds / accountIds / groupIds. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
fieldsJsonstringyesJSON object request body, in the shape SentinelOne's /web/api/v2.1/xdr/assets/network schema expects.
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

Network Discovery Surface

ToolPlanAccessSummary
s1_count_network_discovery_surface_asset_filtersFreeRead-onlyReturns the number of Network Discovery Surface assets behind each filter value — the counts the console shows beside each facet.
s1_export_network_discovery_surface_assetsFreeRead-onlyExports the Network Discovery Surface asset class as JSON.
s1_get_network_discovery_surface_asset_filter_valuesFreeRead-onlyReturns matching values for one Network Discovery Surface asset filter field — the type-ahead behind the console's filter box.
s1_get_network_discovery_surface_asset_text_filtersFreeRead-onlyLists the Network Discovery Surface asset fields that a free-text search covers.
s1_list_network_discovery_surface_asset_actionsFreeRead-onlyLists the inventory actions available for Network Discovery Surface assets, with each action's current status.
s1_list_network_discovery_surface_assetsFreeRead-onlyLists the Network Discovery Surface asset class of the asset inventory.
s1_run_network_discovery_surface_asset_actionProDestructiveDESTRUCTIVE — runs an inventory action against the Network Discovery Surface assets your request body selects.

[SentinelOne] Returns the number of Network Discovery Surface assets behind each filter value — the counts the console shows beside each facet. Use it to size a filter before you act on what it matches. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a flat JSON object in filtersJson. A 403 here means the console API token's ROLE lacks a permission for this endpoint — widen the service user's role in SentinelOne, it is not a StackJack setting.

ParamTypeRequiredDefaultDescription
accountIdsstringnonullComma-separated SentinelOne account ids. From s1_get_accounts.
filtersJsonstringnonullAny other documented query parameter for this endpoint, as a flat JSON object of name/value pairs (for example {"osTypes":"windows","isActive":"true"}).
groupIdsstringnonullComma-separated SentinelOne group ids. From s1_get_groups.
siteIdsstringnonullComma-separated SentinelOne site ids — the usual way to scope a call to ONE customer. From s1_get_sites.

[SentinelOne] Exports the Network Discovery Surface asset class as JSON. StackJack always sends exportFormat=json. SentinelOne REQUIRES that parameter and also offers CSV, but a CSV body is not JSON and this tool could not parse it — so the format is pinned here and filtersJson cannot override it. Page with cursor: pass the response's `pagination.nextCursor` back as cursor until it is null. Do not page by offset — SentinelOne stops at 1000 items and truncates silently. Scope to one customer with siteIds / accountIds / groupIds. Pass any other documented query parameter as a fl