Skip to main content
Tools Reference

Telivy Tools

Written By Christopher Scaminaci

Last updated 7 days ago

Telivy Tools

telivy_ · 28 tools · Free 28 Security risk assessment and reporting for MSPs. The credential is an API key against a fixed host. Page size stops at 100. The report tools return a short-lived link to the stored file rather than the bytes themselves.

All connector tools · Telivy setup guide

Telivy tool groups

General

ToolPlanAccessSummary
telivy_get_agent_versionsFreeRead-onlyReturns the latest published Telivy deep-scan agent versions for Windows and macOS.
telivy_get_finding_detailsFreeRead-onlyLooks up a finding by its short slug (e.g. "open-port", "weak-mfa") and returns the canonical name, description, risk explanation, remediation recommendation, severity, and reference links.
telivy_get_risk_progress_reportFreeRead-onlyReturns a time-windowed findings progress report for an assessment, optionally comparing two timestamp groups.

[Telivy] Returns the latest published Telivy deep-scan agent versions for Windows and macOS. Useful when an MSP needs to verify whether endpoints are running outdated agents before triaging scan-status issues.

[Telivy] Looks up a finding by its short slug (e.g. "open-port", "weak-mfa") and returns the canonical name, description, risk explanation, remediation recommendation, severity, and reference links. Use this to enrich findings surfaced by telivy_get_external_scan_findings or telivy_get_external_scan_finding_detail.

ParamTypeRequiredDefaultDescription
slugstringyesFinding slug as returned by other Telivy tools (e.g. "open-port", "breach-data-exposure").

[Telivy] Returns a time-windowed findings progress report for an assessment, optionally comparing two timestamp groups. Surfaces resolved vs. new vs. ongoing findings between scans. Use telivy_list_external_scans or telivy_list_risk_assessments to discover assessment IDs.

ParamTypeRequiredDefaultDescription
compareWithTimestampGroupstringnonullOptional second timestamp group to compare against. When omitted, progress is reported relative to the assessment's first scan.
currentTimestampGroupstringyesRequired. The current timestamp group (Telivy-internal scan grouping identifier) for which to report progress.
idstringyesThe Telivy assessment ID (external-scan or risk-assessment).

External Scans

ToolPlanAccessSummary
telivy_create_external_scanFreeWriteCreate a new external (attack-surface) scan for a domain.
telivy_get_external_scanFreeRead-onlyReturns the full external-scan record including security grades, scan status, last-scan timestamp, and assessment details.
telivy_get_external_scan_breach_dataFreeRead-onlyReturns dark-web/breach data exposures associated with the assessment's domain — leaked passwords, exposed accounts, breach dates, and source of disclosure.
telivy_get_external_scan_finding_detailFreeRead-onlyReturns the per-target detail records for a specific finding slug on an external scan (e.g. all hosts/ports affected by an "open-port" finding).
telivy_get_external_scan_findingsFreeRead-onlyReturns all security findings discovered by the external scan (open ports, weak TLS, expired certs, exposed services, breach data, etc.).
telivy_get_external_scan_reportFreeRead-onlyGenerates and downloads the external scan report (PDF or DOCX).
telivy_list_external_scansFreeRead-onlyList external (attack-surface) scan assessments.
telivy_rescan_external_scan_devicesFreeWriteMarks all devices associated with the assessment for rescan.
telivy_uninstall_external_scan_devicesFreeDestructiveDESTRUCTIVE: marks all devices associated with the assessment for agent uninstall.
telivy_update_external_scanFreeWriteUpdate an external scan's organization metadata (name, domain, client category/status).

[Telivy] Create a new external (attack-surface) scan for a domain. Requires organizationName and domain. Triggers Telivy to begin scanning the domain's public-facing services.

ParamTypeRequiredDefaultDescription
clientCategorystringnonullOptional client category. One of: breakfix, it_only, security_only, it_and_security.
clientStatusstringnonullOptional client status. One of: suspect, lead, client.
domainstringyesPrimary domain to scan (e.g. "example.com").
extraFieldsJsonstringnonullOptional JSON object of additional fields to merge into the request body for forward compatibility.
organizationNamestringyesOrganization name to associate with the scan.

[Telivy] Returns the full external-scan record including security grades, scan status, last-scan timestamp, and assessment details. Use telivy_list_external_scans to discover IDs.

ParamTypeRequiredDefaultDescription
idstringyesExternal scan ID.

[Telivy] Returns dark-web/breach data exposures associated with the assessment's domain — leaked passwords, exposed accounts, breach dates, and source of disclosure. Use to support incident response and credential rotation conversations.

ParamTypeRequiredDefaultDescription
idstringyesExternal scan ID.

[Telivy] Returns the per-target detail records for a specific finding slug on an external scan (e.g. all hosts/ports affected by an "open-port" finding). Use telivy_get_external_scan_findings to enumerate slugs first.

ParamTypeRequiredDefaultDescription
idstringyesExternal scan ID.
slugstringyesFinding slug, e.g. "open-port".

[Telivy] Returns all security findings discovered by the external scan (open ports, weak TLS, expired certs, exposed services, breach data, etc.). Each finding includes its slug — pass to telivy_get_external_scan_finding_detail or telivy_get_finding_details for more.

ParamTypeRequiredDefaultDescription
idstringyesExternal scan ID.

[Telivy] Generates and downloads the external scan report (PDF or DOCX). The binary is uploaded to StackJack blob storage and returned as a short-lived (~3 minute) read-only SAS URL. The agent should fetch the file from the URL within the expiry window — do NOT attempt to decode the URL as content.

ParamTypeRequiredDefaultDescription
detailedbooleannonullOptional. Set true for a detailed report; false for the executive summary. Defaults to Telivy's default (typically false).
formatstringno"pdf"Output format. One of: pdf, docx. Defaults to pdf.
idstringyesExternal scan ID.

[Telivy] List external (attack-surface) scan assessments. Returns ID, scan status, security grades, and assessment metadata. Use this to discover assessment IDs for downstream tools and to audit which client domains have been scanned.

ParamTypeRequiredDefaultDescription
assessmentSortBystringnonullSort field. One of: organizationName, assessmentStatus, createdAt, updatedAt. Defaults to createdAt.
limitintegerno50Page size (default 50, max 100).
offsetintegerno0Pagination offset (0-indexed). Default 0.
searchstringnonullFree-text search across organization name, domain, and contact fields.
sortOrderstringnonullSort order: ASC or DESC. Defaults to DESC.

[Telivy] Marks all devices associated with the assessment for rescan. Triggers the Telivy deep-scan agent on each endpoint to re-evaluate posture. Operates on agent-deployed devices; pure external scans without agents will no-op.

ParamTypeRequiredDefaultDescription
idstringyesExternal scan ID.

[Telivy] DESTRUCTIVE: marks all devices associated with the assessment for agent uninstall. Use only when offboarding a customer or decommissioning the assessment — this revokes Telivy's deep-scan visibility, removes posture data collection from every endpoint in the assessment, and CANNOT be undone without redeploying the agent on each device.

ParamTypeRequiredDefaultDescription
idstringyesExternal scan ID.

[Telivy] Update an external scan's organization metadata (name, domain, client category/status). Pass-through PUT with the same fields used in create. Idempotent: replaying the same body produces the same end-state.

ParamTypeRequiredDefaultDescription
clientCategorystringnonullOptional client category. One of: breakfix, it_only, security_only, it_and_security.
clientStatusstringnonullOptional client status. One of: suspect, lead, client.
domainstringyesPrimary domain.
extraFieldsJsonstringnonullOptional JSON object of additional fields to merge into the request body.
idstringyesExternal scan ID.
organizationNamestringyesOrganization name.

Risk Assessments

ToolPlanAccessSummary
telivy_convert_to_risk_assessmentFreeDestructiveConvert a Telivy 'application' (incomplete/partial assessment) into a full risk assessment.
telivy_create_risk_assessmentFreeWriteCreate a new deep-scan risk assessment.
telivy_get_risk_assessmentFreeRead-onlyReturns a single risk assessment with full scan status, monitoring config, executive summary, and assessment details.
telivy_get_risk_assessment_deviceFreeRead-onlyReturns full details for a single deep-scan device — OS, deep-scan findings, encryption status, open ports, security grades, browser-saved passwords, and PII inventory.
telivy_get_risk_assessment_domain_change_previewFreeRead-onlyReturns a preview of what would change if the assessment's primary domain were updated — affected scans, agents, and findings.
telivy_get_risk_assessment_gws_usersFreeRead-onlyReturns the Google Workspace user inventory for the assessment, including login status, last login timestamps, and 2-Step Verification enrollment per user.
telivy_get_risk_assessment_m365_usersFreeRead-onlyReturns the Microsoft 365 user inventory for the assessment, including login status, MFA enrollment per user, and recent login failure events.
telivy_get_risk_assessment_pii_summaryFreeRead-onlyReturns the PII exposure summary across all deep-scanned devices — counts of SSNs, credit cards, financial records, health records, etc., and per-device distribution.
telivy_get_risk_assessment_reportFreeRead-onlyGenerates and downloads a risk assessment report.
telivy_get_risk_assessment_scan_statusFreeRead-onlyReturns scan completion status across all devices in a risk assessment — counts by status (queued, scanning, completed, failed) and per-device summaries.
telivy_list_risk_assessment_devicesFreeRead-onlyList all deep-scan devices (endpoints with the Telivy agent installed) belonging to a risk assessment.
telivy_list_risk_assessmentsFreeRead-onlyList risk assessments (deep-scan agent-based assessments).
telivy_rescan_risk_assessment_deviceFreeWriteTriggers an out-of-band rescan on a single deep-scan device.
telivy_update_risk_assessmentFreeWriteUpdate a risk assessment's organization metadata.
telivy_update_risk_assessment_monitoring_settingsFreeWriteUpdate the monitoring frequency for a risk assessment.

[Telivy] Convert a Telivy 'application' (incomplete/partial assessment) into a full risk assessment. Use when an external scan has graduated to deep-scan readiness and you want to enable agent deployment + deep-scan reporting.

ParamTypeRequiredDefaultDescription
idstringyesApplication/assessment ID to convert.

[Telivy] Create a new deep-scan risk assessment. Requires organizationName and domain. Optional fields configure light vs full scan, antivirus integration, and PII jurisdiction.

ParamTypeRequiredDefaultDescription
antiVirusstringnonullOptional. Antivirus product the customer uses; surfaces in compatibility checks.
cleanupDomainChangebooleannonullOptional. When true, signals to clean up after a domain change. Default false.
clientCategorystringnonullOptional client category. One of: breakfix, it_only, security_only, it_and_security.
clientStatusstringnonullOptional client status. One of: suspect, lead, client.
countrystringnonullOptional. PII jurisdiction code. One of: US, CA, UK, ZA, AU, NZ, SG, PL. Defaults to US.
domainstringyesPrimary domain.
extraFieldsJsonstringnonullOptional JSON object of additional fields to merge into the request body.
isLightScanbooleannonullOptional. When true, creates a lightweight scan (faster, less detailed). Default false.
organizationNamestringyesOrganization name.

[Telivy] Returns a single risk assessment with full scan status, monitoring config, executive summary, and assessment details. Use telivy_list_risk_assessments to discover IDs.

ParamTypeRequiredDefaultDescription
idstringyesRisk assessment ID.

[Telivy] Returns full details for a single deep-scan device — OS, deep-scan findings, encryption status, open ports, security grades, browser-saved passwords, and PII inventory. Use telivy_list_risk_assessment_devices to discover deviceId values.

ParamTypeRequiredDefaultDescription
deviceIdstringyesDevice ID within the assessment.
idstringyesRisk assessment ID.

[Telivy] Returns a preview of what would change if the assessment's primary domain were updated — affected scans, agents, and findings. Use before performing a destructive domain change to surface impact.

ParamTypeRequiredDefaultDescription
idstringyesRisk assessment ID.

[Telivy] Returns the Google Workspace user inventory for the assessment, including login status, last login timestamps, and 2-Step Verification enrollment per user. Use to find accounts without 2SV before triaging MFA gaps.

ParamTypeRequiredDefaultDescription
idstringyesRisk assessment ID.

[Telivy] Returns the Microsoft 365 user inventory for the assessment, including login status, MFA enrollment per user, and recent login failure events. Use to surface MFA-disabled accounts and suspicious login activity.

ParamTypeRequiredDefaultDescription
idstringyesRisk assessment ID.

[Telivy] Returns the PII exposure summary across all deep-scanned devices — counts of SSNs, credit cards, financial records, health records, etc., and per-device distribution. Useful for compliance reporting and risk prioritization.

ParamTypeRequiredDefaultDescription
idstringyesRisk assessment ID.

[Telivy] Generates and downloads a risk assessment report. The binary is uploaded to StackJack blob storage and returned as a short-lived (~3 minute) read-only SAS URL. Supported reportType values: executive_security_summary_pdf, telivy_complete_report_pdf, telivy_complete_report_docx, telivy_external_scan_report_pdf, telivy_network_inventory_report_csv, internal_vulnerabilities_top_pdf, internal_vulnerabilities_executive_pdf, internal_vulnerabilities_network_pdf, internal_vulnerabilities_detailed_csv, applications_security_overview_csv, applications_security_detailed_csv, data_security_sensitive_documents_csv, data_security_detailed_risk_xlsx, telivy_passwords_report_csv, telivy_passwords_reuse_report_csv, telivy_dark_web_report_csv, m365_security_report_pdf, m365_security_data_report_xlsx, gws_security_report_pdf, gws_security_data_report_xlsx, legacy_complete_report_pdf.

ParamTypeRequiredDefaultDescription
idstringyesRisk assessment ID.
reportTypestringnonullReport type identifier. See tool description for the full list of supported values.

[Telivy] Returns scan completion status across all devices in a risk assessment — counts by status (queued, scanning, completed, failed) and per-device summaries. Use to monitor scan progress before pulling a fresh report.

ParamTypeRequiredDefaultDescription
idstringyesRisk assessment ID.

[Telivy] List all deep-scan devices (endpoints with the Telivy agent installed) belonging to a risk assessment. Each entry includes device ID, hostname, OS, scan timestamps, and high-level scan status. Use telivy_get_risk_assessment_device for full per-device findings.

ParamTypeRequiredDefaultDescription
idstringyesRisk assessment ID.

[Telivy] List risk assessments (deep-scan agent-based assessments). Returns scan status, monitoring frequency, executive summary scores, and assessment metadata. Use to discover assessment IDs for downstream device, user, PII, and report tools.

ParamTypeRequiredDefaultDescription
assessmentSortBystringnonullSort field. One of: organizationName, assessmentStatus, createdAt, updatedAt. Defaults to createdAt.
limitintegerno50Page size (default 50, max 100).
offsetintegerno0Pagination offset (0-indexed). Default 0.
scanStatusCsvstringnonullOptional comma-separated scan statuses to filter by. Each value is one of: not_started, in_progress, report_completed, archived.
searchstringnonullFree-text search across organization name, domain, and contact fields.
sortOrderstringnonullSort order: ASC or DESC. Defaults to DESC.

[Telivy] Triggers an out-of-band rescan on a single deep-scan device. Useful after remediation actions (e.g. enabling BitLocker, closing a port) when you want to verify the fix without waiting for the next scheduled scan.

ParamTypeRequiredDefaultDescription
deviceIdstringyesDevice ID within the assessment.
idstringyesRisk assessment ID.

[Telivy] Update a risk assessment's organization metadata. Pass-through PUT with the same fields used in create. Idempotent: replaying the same body produces the same end-state.

ParamTypeRequiredDefaultDescription
antiVirusstringnonullOptional. Antivirus product the customer uses.
cleanupDomainChangebooleannonullOptional. cleanup-domain-change flag.
clientCategorystringnonullOptional client category. One of: breakfix, it_only, security_only, it_and_security.
clientStatusstringnonullOptional client status. One of: suspect, lead, client.
countrystringnonullOptional. PII jurisdiction code. One of: US, CA, UK, ZA, AU, NZ, SG, PL.
domainstringyesPrimary domain.
extraFieldsJsonstringnonullOptional JSON object of additional fields to merge into the request body.
idstringyesRisk assessment ID.
isLightScanbooleannonullOptional. is-light-scan flag.
organizationNamestringyesOrganization name.

[Telivy] Update the monitoring frequency for a risk assessment. Pass DISABLE to turn off monitoring, or QUARTERLY/MONTHLY/WEEKLY to set a recurring scan cadence. Idempotent: replaying the same body produces the same end-state.

ParamTypeRequiredDefaultDescription
idstringyesRisk assessment ID.
monitoringFrequencystringyesMonitoring frequency. One of: DISABLE, QUARTERLY, MONTHLY, WEEKLY.