Connect MySonicWall
MySonicWall is SonicWall's customer and partner portal: where products are registered, licenses and subscriptions are managed, firmware is downloaded, users and user groups are administered and, for…
Written By Christopher Scaminaci
Last updated About 3 hours ago
MySonicWall is SonicWall's customer and partner portal: where products are registered, licenses and subscriptions are managed, firmware is downloaded, users and user groups are administered and, for partners on SonicWall's Service Provider Plan, where monthly-billed services are provisioned into customer tenants. It is not the place a firewall is configured; that happens on the appliance or in SonicWall's separate management products.
Connecting MySonicWall to StackJack gives your AI assistant a family of msw_ MCP tools. MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:
- Find your tenants - the customer tenants on your account and the cloud tenants with active subscriptions, with the ids every other tool needs, and the address stored for each one
- Watch license and firmware state - the registered products across your tenants with serial numbers, status, firmware version and support expiry, one product's license detail (services, node counts, expiry), and the firmware and downloads available for a serial number. "Which client firewalls have services about to lapse" is the question most SonicWall MSPs still answer by hand
- Reconcile billing - the monthly license usage report by MSSP, tenant, month, year and SKU, and the list of products and services a tenant can be provisioned with
- Review access - the MySonicWall users on your account with their user groups and two-factor status, the user groups themselves, and the activity log of who did what and when
- Onboard a client (on Pro plans) - create a tenant and set its address, create a user group, invite a user and add people to a group
- Provision monthly services (on Pro plans) - provision a new monthly-billed product into a tenant, or edit an existing one
- Connect SonicWall's management products (on Pro plans) - mint the short-lived access code that SonicWall's Network Security Manager and Capture Client exchange for their own API token
What you need
A MySonicWall account and a user on it who can generate an API key. Most of this API serves SonicWall's Service Provider Plan (the monthly billing program for MSSPs and managed service providers): the tenant, provisioning, license report and user group tools need the MSSP role on such an account. SonicWall does not say exactly which routes refuse an account outside that plan, so on an ordinary reseller account a tool may answer with an empty list or an error. Products, firmware, users and activity follow the access of the user who generated the key.
How StackJack authenticates to MySonicWall
MySonicWall uses a personal API key. You generate it in MySonicWall while signed in as one user, and paste it into StackJack. There is no client ID, no second secret and no web address to enter: the service lives at one fixed address for everyone.
The key is one user's key
SonicWall says "your API access is determined based on the access levels in MySonicWall." The key carries the role of the user who generated it, so what StackJack can do is exactly what that user can do. Two things follow:
- Generate the key from a dedicated user that holds the MSSP role, with Read-Only access if you only want reporting or Admin access if you want your AI to provision and invite. Then the connector does not stop the day a technician leaves.
- An administrator of the account can see and revoke any user's key, and anyone holding the key acts as that user. Treat it as a password.
Keys expire
A MySonicWall key lasts one year at most, and the default is one year. Nothing warns you before it lapses. Put the renewal date in your calendar. When a key expires StackJack's health check starts failing, and after three failures in a row the connector switches itself off; generate a new key and save it to bring the connector back.
Steps
- Choose the MySonicWall user the key belongs to, ideally a dedicated service user with the MSSP role.
- Sign in to MySonicWall as that user and go to Monthly Billing, Access Management, Users. If you do not have monthly billing, go to My Workspace, User Groups, User list.
- Choose Generate My API Key above the table. Enter a description such as "StackJack" and set the validity. One year is the default and the maximum, so a shorter period only means renewing sooner.
- Leave the Source IP Address field blank. It is optional, and a key restricted to one address refuses every StackJack call. If your policy requires an address restriction, open a StackJack support ticket for the addresses to allow, and note that StackJack runs two regions.
- Copy the key now. MySonicWall shows it once and cannot show it again after you close the window.
- Paste it into StackJack. Open Connectors, choose MySonicWall and paste the key. Optionally enter the MySonicWall user name the key was generated for (see below).
- Run a Test Connection. StackJack checks the key by asking MySonicWall for your cloud tenants, the first call SonicWall's own guide makes. It only reads the list of tenants and changes nothing.
If you cannot see Generate My API Key on your account, SonicWall's own article says to open a customer service request with SonicWall.
The optional MySonicWall username
The firmware lookup for a serial number needs the MySonicWall user name the key was generated for, and the key alone does not reveal it. Enter it once on the connector and the firmware tool uses it by default; your AI can also pass it on any call. Leave it blank if you do not use that tool. Clearing the box and saving removes the stored name.
What to know before your AI uses this connector
Every tenant-scoped tool takes a tenant id from a list
MySonicWall calls a customer tenant a product group. Nothing is addressed by name: your AI first lists tenants (or cloud tenants) and then passes the id it gets. SonicWall does not say outright that one key reaches every tenant, but the shape of the API strongly suggests it does for a key generated by an MSSP-level user. If you keep separate MySonicWall accounts, add one connection per account (see below).
Some tools change something real
Read tools change nothing. The writes are Pro tools, and these are marked destructive:
- Provisioning or editing a monthly product adds a recurring charge to your SonicWall bill. An edit can lower a node count, and the call can end a service. Your AI is told to take the product, service and data center ids from the provisionable-services list first, and StackJack refuses the call locally if the mode is not PROVISION or EDIT, if a required id or the node count is blank, or if an edit names no serial number.
- Inviting a user emails a real person and grants them access to your MySonicWall account.
- The two group-membership tools can remove users as well as add them. SonicWall publishes two near-identical routes for this and does not say which one is canonical, so both are offered. Each carries a flag that can remove a member and a flag that can email them.
- Updating a tenant address may replace the whole address. SonicWall does not say whether the new address replaces or merges, so your AI is told to read the address first and send the complete address back.
- Creating a tenant may bill you or notify someone. SonicWall's guide calls it provisioning a tenant and documents no charge and no notification, so StackJack treats it as a call that could do either.
- Generating an access code mints a credential. The code is valid for 5 minutes, and SonicWall's Network Security Manager or Capture Client exchanges it for an API token that acts as the user who owns the key. Treat the answer like a password.
Creating a user group is not marked destructive. SonicWall documents no charge and no invitation for it, but does not rule one out either.
Whether your AI application asks you to confirm before running a destructive tool depends on that application's own settings; see Destructive tools and confirmation. Review that setting before you let an assistant near the destructive tools above.
A few answers carry registration values
The product list, a product's service info, the provisioning call and the activity log can return device authentication codes, a license activation key or a field named as a password, and the access-code call answers with a credential. StackJack never saves these answers for tests and never turns an oversized one into a downloadable file; a very large answer from one of them comes back as a plain refusal instead. Do not paste these answers into tickets or chat.
Paging is in the request, and the limits are StackJack's
The product list, the user group list, the license usage report and the activity log are read through requests that carry their filters in the body, and the ones that page do it there. SonicWall documents no maximum page size, no default and no starting page number, so StackJack caps a page at 100 and passes a page number through exactly as given. If a list looks short, ask for the next page rather than a bigger one. The product list also has a paging switch, isPaged, whose accepted value SonicWall does not document, and SonicWall does not say whether paging applies without it, so a product list asked for without it may come back whole.
The answers are SonicWall's own
Every MySonicWall answer wraps its data in a short status envelope. StackJack passes it through untouched, and SonicWall does not publish what its status values mean. A key that has expired or been revoked is refused with no message at all.
Plans and limits
Read tools are available on the Free tier. Creating, provisioning, inviting, changing membership and generating an access code are Pro. Business reaches the same tools as Pro and differs by monthly call quota.
See the generated MySonicWall tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.
SonicWall publishes no rate limit, so StackJack paces requests at a conservative rate and backs off if it is throttled. Pacing smooths a burst; it does not guarantee that every call arrives. Retries are bounded, a write is never sent twice automatically, and a wide enough read can still come back throttled or time out. Narrow the read, and check whether a write landed before repeating it; see Retrying a failed or timed-out write.
StackJack covers the API SonicWall publishes for MySonicWall. SonicWall's separate management products, Network Security Manager and Capture Client, are different services with their own tokens. This connector can mint the short-lived access code they exchange for a token, but it never calls them.
Several customers
If you hold more than one MySonicWall account, add one connection per account from the connector's card, name each one after the account, and your AI names it on each call. Omit the name and the call runs against your default connection. Pin an endpoint to one connection when an AI should never reach past a single account. See Several connections of one connector.
Troubleshooting
"MySonicWall rejected the API key" - the key has most likely expired (one year at most) or an administrator revoked it. MySonicWall refuses a bad key with no message, so StackJack cannot tell which. Generate a new key as described above, paste it into the connector and run a Test Connection.
"MySonicWall accepted the API key but refused this call" - the key is fine but the user who generated it does not have the access this tool needs. Tenant, provisioning, license report and user group tools need the MSSP role on a Service Provider Plan account. Generate the key from a user that holds it, or ask a MySonicWall administrator to raise that user's access.
Every call is refused although the key is new - check the key's Source IP Address field. If it is set, StackJack's calls are refused. Leave it blank, or open a StackJack support ticket for the addresses to allow.
A tool answers an empty list or an error for a tenant you can see in the portal - you may be outside the Service Provider Plan for that route, or the generating user cannot see that tenant. SonicWall does not document which.
The firmware tool says it needs a user name - enter the MySonicWall username on the connector, or have your AI pass one on the call.
"Something answered at the MySonicWall address, but it was not a MySonicWall JSON answer" - a proxy, a firewall or a portal page replied instead. A read changed nothing and can be retried. After a write, check MySonicWall before repeating it.
The connector switched itself off - the key lapsed. Generate a new one and save it on the connector.
MySonicWall tools
msw_ · 20 tools · Free 12 · Pro 8
Tenants
Cloud Tenants
Products
Users and Groups
License Report
User Activity
Was this helpful?
More in Connector guides
Connect Acronis Cyber Protect CloudConnect Action1Connect AddigyConnect AlertOpsStill need help? Ask the team