Skip to main content
Tools Reference

ThreatLocker Tools

Written By Christopher Scaminaci

Last updated 7 days ago

ThreatLocker Tools

tl_ · 93 tools · Free 53 · Pro 40 Application allowlisting, ringfencing and endpoint control. The credential is an API user token sent as the raw Authorization value with no Bearer prefix - adding a scheme fails every call. The instance host is per tenant. Organization scope rides a managed organization id, defaulted from the credential and overridable on every tool. POST carries search filters here, so many POSTs are reads and the HTTP verb is not the safety boundary; there are no DELETE verbs at all, and deletion is a named POST or PUT. Paging is a page number with a page size capped at 500 here, since the vendor documents no maximum, and there are no cursors. The vendor publishes no response schemas, no rate limit and no idempotency contract, and its status meanings are inverted: a 401 means a missing permission and a 403 means a bad credential.

All connector tools · ThreatLocker setup guide

ThreatLocker tool groups

Unified Audit

ToolPlanAccessSummary
tl_search_unified_auditFreeRead-onlySearch the Unified Audit — the activity log behind the Portal's Audit page.

[ThreatLocker] Search the Unified Audit — the activity log behind the Portal's Audit page. Requires a UTC start and end date (e.g. 2026-07-30T00:00:00Z) plus paging. Filters: actionId (Permit=1, Deny=2, Deny with request option=3, Ringfenced=6, Any Deny=99); actionType (execute, install, network, registry, read, write, move, delete, baseline, powershell, elevate, configuration, dns); hostname; fullPath; onlyTrueDenies; simulateDeny; showChildOrganizations. For a large range: run the search, read totalItems from the response headers, then pass that value back as totalRows on later pages — totalRows is a total-count hint, never a page size. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
actionIdintegernonullOptional action id: Permit=1, Deny=2, Deny (Option to Request)=3, Ringfenced=6, Any Deny=99.
actionTypestringnonullOptional action type: execute, install, network, registry, read, write, move, delete, baseline, powershell, elevate, configuration, or dns.
endDatestringyesRequired. End of the search window, UTC ISO-8601 (e.g. 2026-07-31T00:00:00Z).
exportModebooleannonullOptional. Return the export-mode projection instead of the grid projection.
fullPathstringnonullOptional. Filter to a specific full file path.
groupBysJsonstringnonullOptional. JSON array of integer group-by field ids from the Unified Audit article (e.g. Username=1, Process Path=2, Application Name=8, Full Path=10, Hash=11, SHA256=12, Asset Name=17).
hostnamestringnonullOptional. Filter to one computer's hostname.
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector. Discover child organization ids with tl_search_child_organizations.
onlyTrueDeniesbooleannonullOptional. Exclude denies that were only simulated.
pageNumberintegeryesRequired. 1-based page number.
pageSizeintegeryesRequired. Rows per page. Capped at 500 by StackJack (ThreatLocker documents no maximum).
paramsFieldsDtoJsonstringnonullOptional. The Remove White Noise filter array, verbatim JSON — each item is {name, filterType, fieldType, value, label, dropdownLabel, isDropDown}. Omit for an unfiltered search (an empty array is sent).
showChildOrganizationsbooleannonullOptional. Include events from child organizations.
showTotalCountbooleannonullOptional. Include the total row count in the response.
simulateDenybooleannonullOptional. Include what WOULD have been denied (simulation) alongside real denies.
startDatestringyesRequired. Start of the search window, UTC ISO-8601 (e.g. 2026-07-30T00:00:00Z).
totalRowsintegernonullOptional. For pages after the first: the totalItems value from an earlier response's headers. This is the vendor's large-result hint, not a page size.

System Audit

ToolPlanAccessSummary
tl_get_system_audit_health_centerFreeRead-onlyGet the Health Center view of the System Audit — the recent-activity rollup the Portal shows over a trailing number of days.
tl_search_system_auditFreeRead-onlySearch the System Audit — the record of administrative and configuration changes in the ThreatLocker Portal.

[ThreatLocker] Get the Health Center view of the System Audit — the recent-activity rollup the Portal shows over a trailing number of days. Requires the day count, whether to scope to the signed-in administrator, and paging. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
daysintegeryesRequired. How many trailing days to summarize.
isLoggedInbooleanyesRequired. True to scope the rollup to the signed-in administrator's own activity.
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector.
pageNumberintegeryesRequired. 1-based page number.
pageSizeintegeryesRequired. Rows per page. Capped at 500 by StackJack (ThreatLocker documents no maximum).
searchTextstringnonullOptional. Free-text filter.

[ThreatLocker] Search the System Audit — the record of administrative and configuration changes in the ThreatLocker Portal. Requires a UTC start and end date plus paging; optional filters include the acting user's email address, the source IP address, a specific object id, an action list, free-text details, and child-organization inclusion. Use this to answer 'who changed this policy and when'. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
actionsJsonstringnonullOptional. JSON array of audit action names to include.
afterKeysJsonstringnonullOptional. The afterKeys object from a previous response, for deep paging through a large result set.
detailsstringnonullOptional. Free-text match against the change details.
effectiveActionstringnonullOptional. Filter to a single effective action.
emailAddressstringnonullOptional. Filter to the email address of the administrator who made the change.
endDatestringyesRequired. End of the search window, UTC ISO-8601.
iPAddressstringnonullOptional. Filter to the source IP address the change came from.
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector.
objectIdstringnonullOptional. Filter to changes affecting one object's GUID (a policy, computer, group, and so on).
pageNumberintegeryesRequired. 1-based page number.
pageSizeintegeryesRequired. Rows per page. Capped at 500 by StackJack (ThreatLocker documents no maximum).
startDatestringyesRequired. Start of the search window, UTC ISO-8601 (e.g. 2026-07-30T00:00:00Z).
viewChildOrganizationsbooleannonullOptional. Include changes made in child organizations.

Applications

ToolPlanAccessSummary
tl_confirm_delete_applicationsProDestructiveDESTRUCTIVE: step 2 of ThreatLocker's two-step application delete — confirms the deletion marked by tl_delete_applications.
tl_create_applicationProWriteCreate a custom Application Control application.
tl_delete_applicationsProDestructiveDESTRUCTIVE: step 1 of ThreatLocker's two-step application delete — marks the selected applications for deletion.
tl_get_applicationFreeRead-onlyGet one Application Control application by its GUID, as shown on the Portal's Applications page.
tl_get_application_research_detailsFreeRead-onlyGet ThreatLocker's research data for one application — the vendor's own analysis shown on an application that has research available.
tl_get_matching_applicationsFreeRead-onlyFind existing applications that already match a requested file — the check the Portal runs when you open an Application Control approval request.
tl_list_applications_for_add_to_applicationFreeRead-onlyList the applications a requested file can be added to — the pick-list used in the approval-processing workflow.
tl_list_applications_for_maintenance_modeFreeRead-onlyList the applications selectable when starting a maintenance mode on a computer (the pick-list on the computer sidebar's Maintenance tab).
tl_search_applicationsFreeRead-onlySearch Application Control applications.
tl_update_applicationProWriteUpdate one of your organization's custom applications (name, description, OS type) — the Save action on an application's Information tab.

[ThreatLocker] DESTRUCTIVE: step 2 of ThreatLocker's two-step application delete — confirms the deletion marked by tl_delete_applications. This is the irreversible step: the applications and their file rules are removed, and anything only permitted through them stops running. Send the same applicationsJson array ({applicationId, name, organizationId, osType}). This operation additionally requires the Edit Application Control Policies permission. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
applicationsJsonstringyesRequired. JSON array of applications to delete — each item {applicationId, name, organizationId, osType}.
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector. Discover child organization ids with tl_search_child_organizations.

[ThreatLocker] Create a custom Application Control application. Requires a name and osType (Windows=1, MAC=2, Linux=3, Windows XP=5). Optionally seed its file rules with applicationFileUpdatesJson — a JSON array whose items are either {fullPath, processPath, installedBy, cert, notes, updateStatus} or {hash, notes, updateStatus}. An application on its own grants nothing until a policy references it. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
applicationFileUpdatesJsonstringnonullOptional. JSON array of initial file rules — items are {fullPath, processPath, installedBy, cert, notes, updateStatus} or {hash, notes, updateStatus}.
descriptionstringnonullOptional. A description for the application.
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector. Discover child organization ids with tl_search_child_organizations.
namestringyesRequired. The application name.
osTypeintegeryesRequired OS type: Windows=1, MAC=2, Linux=3, Windows XP=5.

[ThreatLocker] DESTRUCTIVE: step 1 of ThreatLocker's two-step application delete — marks the selected applications for deletion. Follow with tl_confirm_delete_applications to complete it. Deleting an application removes the allowlist definition, so anything only permitted through it stops running. Requires applicationsJson: a JSON array whose items are {applicationId, name, organizationId, osType}. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
applicationsJsonstringyesRequired. JSON array of applications to delete — each item {applicationId, name, organizationId, osType}.
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector. Discover child organization ids with tl_search_child_organizations.

[ThreatLocker] Get one Application Control application by its GUID, as shown on the Portal's Applications page. Find ids with tl_search_applications. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
applicationIdstringyesRequired. The application GUID.
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector. Discover child organization ids with tl_search_child_organizations.

[ThreatLocker] Get ThreatLocker's research data for one application — the vendor's own analysis shown on an application that has research available. Useful when deciding whether to permit an unfamiliar application. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
applicationIdstringyesRequired. The application GUID.
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector. Discover child organization ids with tl_search_child_organizations.

[ThreatLocker] Find existing applications that already match a requested file — the check the Portal runs when you open an Application Control approval request. Supply the file's identity from the approval request: certificates, creators, TLHash, OS type, path, process path, and SHA256. Use this before approving so an existing application can be reused instead of creating a duplicate. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
certsJsonstringyesRequired. JSON array of certificates, each {sha, subject, validCert} — sha is the certificate's SHA256, subject its name.
createdBysJsonstringyesRequired. JSON array of strings naming who created the file.
hashstringyesRequired. The file's ThreatLocker hash (TLHash).
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector. Discover child organization ids with tl_search_child_organizations.
osTypeintegeryesRequired OS type: Windows=1, MAC=2, Linux=3, Windows XP=5.
pathstringyesRequired. The file's full path.
processPathstringyesRequired. The parent process path.
sha256stringyesRequired. The file's SHA256 hash.

[ThreatLocker] List the applications a requested file can be added to — the pick-list used in the approval-processing workflow. Pass the osType of the requesting computer; searchText filters by application name. Note: ThreatLocker documents this operation only inside the approval workflow article, so its required/optional split is inferred from that text rather than a formal reference. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector. Discover child organization ids with tl_search_child_organizations.
osTypeintegeryesRequired OS type, matching the requesting computer: Windows=1, MAC=2, Linux=3, Windows XP=5.
searchTextstringnonullOptional. Filter by application name.

[ThreatLocker] List the applications selectable when starting a maintenance mode on a computer (the pick-list on the computer sidebar's Maintenance tab). Optionally filter by osType: Windows=1, MAC=2, Linux=3, Windows XP=5. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector. Discover child organization ids with tl_search_child_organizations.
osTypeintegernonullOptional OS filter: Windows=1, MAC=2, Linux=3, Windows XP=5.

[ThreatLocker] Search Application Control applications. Requires orderBy, paging, and searchBy, which selects WHICH field searchText matches: app=Application Name, full=Full Path, process=Process Path, hash=Hash, cert=Certificate, created=Created By, categories=Category, countries=Where Code is Compiled. Optional category (0=All Applications, 1=My Applications/custom, 2=Built-In, 4=Patch Supported), osType (All=0, Windows=1, MAC=2, Linux=3, Windows XP=5), isAscending, isHidden, permittedApplications, includeChildOrganizations. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
categoriesJsonstringnonullOptional. JSON array of category names to include.
categoryintegernonullOptional application category: 0=All Applications, 1=My Applications (custom), 2=Built-In Applications, 4=Patch Supported.
countriesJsonstringnonullOptional. JSON array of country codes (where the code was compiled).
includeChildOrganizationsbooleannonullOptional. Include applications from child organizations.
isAscendingbooleannonullOptional. Sort ascending when true.
isHiddenbooleannonullOptional. Include hidden applications.
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector. Discover child organization ids with tl_search_child_organizations.
orderBystringyesRequired. Field to order by.
osTypeintegernonullOptional OS filter: All=0, Windows=1, MAC=2, Linux=3, Windows XP=5.
pageNumberintegeryesRequired. 1-based page number.
pageSizeintegeryesRequired. Rows per page. Capped at 500 by StackJack (ThreatLocker documents no maximum).
permittedApplicationsbooleannonullOptional. Restrict to applications that are currently permitted.
searchBystringyesRequired. Which field searchText matches: app, full, process, hash, cert, created, categories, or countries.
searchTextstringnonullOptional. The text to match against the field named by searchBy.

[ThreatLocker] Update one of your organization's custom applications (name, description, OS type) — the Save action on an application's Information tab. Built-in ThreatLocker applications cannot be edited. All four fields are required by the vendor, so read the current values with tl_get_application first and resend the ones you are not changing. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
applicationIdstringyesRequired. The application GUID to update.
descriptionstringyesRequired. The description (resend the current value if unchanged).
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector. Discover child organization ids with tl_search_child_organizations.
namestringyesRequired. The application name (resend the current value if unchanged).
osTypeintegeryesRequired OS type: Windows=1, MAC=2, Linux=3, Windows XP=5.

Application Files

ToolPlanAccessSummary
tl_create_application_file_ruleProDestructiveAdd a file rule to an application (the Add Rule action on its Application Files tab).
tl_delete_application_file_ruleProDestructiveDESTRUCTIVE: permanently delete one file rule from an application (the trash-can action on its Application Files tab, confirmed).
tl_list_application_filesFreeRead-onlyList the file rules inside one application — the Application Files tab.
tl_update_application_file_ruleProDestructiveUpdate an existing file rule inside an application (the Save action after editing a rule).

[ThreatLocker] Add a file rule to an application (the Add Rule action on its Application Files tab). This widens what the application matches, so it widens what any policy permitting that application allows. The vendor requires every field: pass an empty string for conditions you are not using, and set isHashOnly true for a hash-only rule. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
applicationIdstringyesRequired. The application GUID to add the rule to.
applicationNamestringyesRequired. The application's name.
certstringyesRequired. Certificate condition (empty string when unused).
fullPathstringyesRequired. Full-path condition (empty string when unused).
hashstringyesRequired. Hash condition (empty string when unused).
installedBystringyesRequired. Installed-by condition (empty string when unused).
isHashOnlybooleanyesRequired. True when this rule matches on hash alone.
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector.
notesstringyesRequired. Notes for the rule (empty string when unused).
osTypeintegeryesRequired OS type: Windows=1, MAC=2, Linux=3, Windows XP=5.
processPathstringyesRequired. Process-path condition (empty string when unused).

[ThreatLocker] DESTRUCTIVE: permanently delete one file rule from an application (the trash-can action on its Application Files tab, confirmed). Removing a rule narrows what the application matches, so files that relied on it stop being permitted. Requires the numeric applicationFileId plus the rule's identifying fields — read them with tl_list_application_files first. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
applicationFileIdintegeryesRequired. The numeric application file rule id to delete (from tl_list_application_files).
applicationIdstringyesRequired. The application GUID the rule belongs to.
applicationNamestringyesRequired. The application's name.
certstringyesRequired. The rule's certificate condition (empty string when unused).
fullPathstringyesRequired. The rule's full-path condition (empty string when unused).
hashstringyesRequired. The rule's hash condition (empty string when unused).
installedBystringyesRequired. The rule's installed-by condition (empty string when unused).
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector.
osTypeintegeryesRequired OS type: Windows=1, MAC=2, Linux=3, Windows XP=5.
processPathstringyesRequired. The rule's process-path condition (empty string when unused).

[ThreatLocker] List the file rules inside one application — the Application Files tab. Requires the application GUID and paging; optionally restrict to hash-only rules, to custom (non-built-in) rules, or filter by text. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
applicationIdstringyesRequired. The application GUID whose file rules to list (from tl_search_applications).
hashOnlybooleannonullOptional. Restrict to hash-only rules.
isCustomRulebooleannonullOptional. Restrict to custom rules (excluding built-ins).
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector.
pageNumberintegeryesRequired. 1-based page number.
pageSizeintegeryesRequired. Rows per page. Capped at 500 by StackJack (ThreatLocker documents no maximum).
searchTextstringnonullOptional. Free-text filter.

[ThreatLocker] Update an existing file rule inside an application (the Save action after editing a rule). Requires the numeric applicationFileId from tl_list_application_files plus every condition field — read the current rule first and resend the values you are not changing. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
applicationFileIdintegeryesRequired. The numeric application file rule id (from tl_list_application_files).
applicationIdstringyesRequired. The application GUID the rule belongs to.
certstringyesRequired. Certificate condition (empty string when unused).
fullPathstringyesRequired. Full-path condition (empty string when unused).
hashstringyesRequired. Hash condition (empty string when unused).
installedBystringyesRequired. Installed-by condition (empty string when unused).
isHashOnlybooleanyesRequired. True when this rule matches on hash alone.
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector.
notesstringyesRequired. Notes for the rule (empty string when unused).
osTypeintegeryesRequired OS type: Windows=1, MAC=2, Linux=3, Windows XP=5.
processPathstringyesRequired. Process-path condition (empty string when unused).

Approval Requests

ToolPlanAccessSummary
tl_authorize_approval_request_permitProDestructiveAuthorize an approval request that the Cyber Hero team escalated to a customer administrator for a decision.
tl_get_approval_request_countFreeRead-onlyGet the number of PENDING approval requests — the badge the Portal shows on the Response Center.
tl_get_approval_request_file_download_detailsFreeRead-onlyGet the download details ThreatLocker holds for the file behind an approval request — the metadata shown when inspecting the requested file.
tl_get_approval_request_permit_applicationFreeRead-onlyGet the full detail behind one approval request — what the Portal loads when you click a request in the Response Center, including the requested file's identity and the permit options available.
tl_permit_approval_request_applicationProDestructiveProcess an Execute or Elevate approval request into a permit — the Response Center's approve action.
tl_search_approval_requestsFreeRead-onlySearch Application Control approval requests (the Response Center's Approval tab).

[ThreatLocker] Authorize an approval request that the Cyber Hero team escalated to a customer administrator for a decision. Requires the approval request GUID; an optional message is recorded with the authorization. This grants the request's permit — review it with tl_get_approval_request_permit_application first. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
approvalRequestIdstringyesRequired. The escalated approval request GUID.
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector. Discover child organization ids with tl_search_child_organizations.
messagestringnonullOptional. A message recorded with the authorization.

[ThreatLocker] Get the number of PENDING approval requests — the badge the Portal shows on the Response Center. Requires includeChildOrganizations, so pass false for this organization only or true to count across child organizations. Cheap way to check whether there is a queue before searching it. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
includeChildOrganizationsbooleanyesRequired. True to count pending requests across child organizations too.
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector. Discover child organization ids with tl_search_child_organizations.

[ThreatLocker] Get the download details ThreatLocker holds for the file behind an approval request — the metadata shown when inspecting the requested file. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
approvalRequestIdstringyesRequired. The approval request GUID (from tl_search_approval_requests).
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector. Discover child organization ids with tl_search_child_organizations.

[ThreatLocker] Get the full detail behind one approval request — what the Portal loads when you click a request in the Response Center, including the requested file's identity and the permit options available. Read this before calling tl_permit_approval_request_application. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
approvalRequestIdstringyesRequired. The approval request GUID (from tl_search_approval_requests).
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector. Discover child organization ids with tl_search_child_organizations.

[ThreatLocker] Process an Execute or Elevate approval request into a permit — the Response Center's approve action. This CREATES a permit policy, so review the request first (tl_get_approval_request_permit_application) and check for an application to reuse (tl_get_matching_applications). ThreatLocker's request body is deeply nested, so pass it as JSON: required top-level fields are approvalRequest {approvalRequestId, comments, json, requestorEmailAddress, ticketApprovalManager, ticketId}, computerId, computerGroupId, fileDetails , isElevationRequest, matchingApplications {useMatchingApplication, matchingApplication, useExistingApplication, existingApplication, useNewApplication, newApplicationName}, organizationHasElevation, organizationId, organizationIds, osType, policyConditions {useExistingPolicy, manualOptions, ruleId}, policyLevel {toEntireOrganization, toComputerGroup, selectedComputerGroup, toComputer}, and ringfenceActionId. Optional groups add elevationStatus/elevationExpiration, networkExclusions, policyExpirationDate, and ringfencingOptions. See ThreatLocker's approval-processing article for the full template. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The complete request body as JSON, per ThreatLocker's documented ApprovalRequestPermitApplication template (see the tool description for the required top-level fields).
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector. Discover child organization ids with tl_search_child_organizations.

[ThreatLocker] Search Application Control approval requests (the Response Center's Approval tab). Requires statusId — Pending=1, Approved=4, Not Learned=6, Rejected=10, Added to Application=12, Escalated from the Cyber Heroes=13, Self-Approved=16 — plus paging. Optional searchText, orderBy, isAscending, and showChildOrganizations. Start here to find the approvalRequestId the other approval tools need. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
isAscendingbooleannonullOptional. Sort ascending when true.
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector. Discover child organization ids with tl_search_child_organizations.
orderBystringnonullOptional. Field to order by.
pageNumberintegeryesRequired. 1-based page number.
pageSizeintegeryesRequired. Rows per page. Capped at 500 by StackJack (ThreatLocker documents no maximum).
searchTextstringnonullOptional. Free-text filter.
showChildOrganizationsbooleannonullOptional. Include requests from child organizations.
statusIdintegeryesRequired status: Pending=1, Approved=4, Not Learned=6, Rejected=10, Added to Application=12, Escalated from the Cyber Heroes=13, Self-Approved=16.

Config Manager

ToolPlanAccessSummary
tl_list_config_manager_configurationsFreeRead-onlyList the available Config Manager configurations with their categories — the settings catalog the Portal offers when creating or editing a Config Manager policy.
tl_search_config_manager_policiesFreeRead-onlySearch Config Manager policies.

[ThreatLocker] List the available Config Manager configurations with their categories — the settings catalog the Portal offers when creating or editing a Config Manager policy. Takes no inputs beyond the organization scope. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector.

[ThreatLocker] Search Config Manager policies. Requires appliesTo (the GUID of the organization, computer group, or computer the policies apply to), paging, and status — Not Configured=-1, Disabled=0, Enabled=1, All=99. Optional searchText filters by name. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
appliesTostringyesRequired. The GUID the policies apply to (organization, computer group, or computer).
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector.
pageNumberintegeryesRequired. 1-based page number.
pageSizeintegeryesRequired. Rows per page. Capped at 500 by StackJack (ThreatLocker documents no maximum).
searchTextstringnonullOptional. Free-text filter on the policy name.
statusintegeryesRequired status filter: Not Configured=-1, Disabled=0, Enabled=1, All=99.

Computers

ToolPlanAccessSummary
tl_delete_computersProDestructiveDESTRUCTIVE: delete a computer from ThreatLocker.
tl_disable_computer_protectionProDestructiveDESTRUCTIVE: disable ThreatLocker protection on one or more computers for a window.
tl_enable_computer_protectionProWriteEnable (secure) ThreatLocker protection on one or more computers — the hardening direction, moving devices back to Secure.
tl_get_computerFreeRead-onlyGet one computer's editable detail by GUID — what the Portal loads when you open a device for editing (name, group, proxy settings, options).
tl_get_new_computer_defaultsFreeRead-onlyGet the defaults and options the Portal offers when adding a new computer to the organization.
tl_get_sample_deployment_pathFreeRead-onlyGet the sample deployment path for a brand, using an organization auth key.
tl_get_signed_deployment_scriptFreeRead-onlyGet the SIGNED ThreatLocker agent deployment script for a brand.
tl_get_unsigned_deployment_scriptFreeRead-onlyGet the UNSIGNED ThreatLocker agent deployment script for a brand.
tl_move_computers_to_organizationProDestructiveDESTRUCTIVE: move computers to a different organization and computer group.
tl_remove_duplicate_computersProDestructiveDESTRUCTIVE: remove duplicate computer records in the managed organization.
tl_rescan_computer_baselineProDestructiveTrigger a baseline rescan on one or more computers, optionally enabling learning while it runs.
tl_restart_computersProDestructiveDESTRUCTIVE: flag a computer to restart.
tl_restart_organization_computersProDestructiveDESTRUCTIVE and ORG-WIDE: flag EVERY computer in the managed organization to restart.
tl_search_computersFreeRead-onlySearch computers (the Devices page).
tl_set_computer_maintenance_modeProDestructiveDESTRUCTIVE: put a computer into a maintenance mode.
tl_update_computerProDestructiveUpdate a computer's editable settings — name, computer group, and proxy configuration.
tl_update_computer_agent_versionProDestructiveDESTRUCTIVE: change the installed ThreatLocker agent version on specific computers.

[ThreatLocker] DESTRUCTIVE: delete a computer from ThreatLocker. The device stops being managed and its history is removed from the Portal's device list. Requires the computer GUID and its organization GUID — verify both with tl_search_computers first. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
computerIdstringyesRequired. The computer GUID to delete.
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector. Discover child organization ids with tl_search_child_organizations.
organizationIdstringyesRequired. The organization GUID the computer belongs to.

[ThreatLocker] DESTRUCTIVE: disable ThreatLocker protection on one or more computers for a window. This REMOVES enforcement — during the window the endpoints are not protected by the allowlist. Requires computerDetailDtosJson (a JSON array of {computerGroupId, computerId, organizationId}), the start and end of the window as UTC ISO-8601, permitEnd, an applicationId (empty string when not scoping to one application), and maintenanceModeType: Application Control Monitor Only=1, Application Control Learning Mode=3, Disable Tamper Protection=6. Prefer the shortest window that does the job. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
applicationIdstringyesRequired. Application GUID to scope the window to, or an empty string for all applications.
computerDetailDtosJsonstringyesRequired. JSON array of target computers — each item {computerGroupId, computerId, organizationId}.
endDatestringyesRequired. Window end, UTC ISO-8601.
maintenanceModeTypeintegeryesRequired mode: Application Control Monitor Only=1, Application Control Learning Mode=3, Disable Tamper Protection=6.
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector. Discover child organization ids with tl_search_child_organizations.
permitEndbooleanyesRequired. Whether the window may be ended early.
startDatestringyesRequired. Window start, UTC ISO-8601 (e.g. 2026-07-30T18:00:00Z).

[ThreatLocker] Enable (secure) ThreatLocker protection on one or more computers — the hardening direction, moving devices back to Secure. Requires computerDetailDtosJson: a JSON array whose items are {computerId, organizationId}. Use tl_disable_computer_protection for the reverse. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
computerDetailDtosJsonstringyesRequired. JSON array of target computers — each item {computerId, organizationId}.
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector. Discover child organization ids with tl_search_child_organizations.

[ThreatLocker] Get one computer's editable detail by GUID — what the Portal loads when you open a device for editing (name, group, proxy settings, options). Read this before tl_update_computer so you can resend the fields you are not changing. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
computerIdstringyesRequired. The computer GUID (from tl_search_computers).
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector. Discover child organization ids with tl_search_child_organizations.

[ThreatLocker] Get the defaults and options the Portal offers when adding a new computer to the organization. Takes no inputs beyond the organization scope. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector. Discover child organization ids with tl_search_child_organizations.

[ThreatLocker] Get the sample deployment path for a brand, using an organization auth key. SENSITIVE: this call both takes and returns installation material — the auth key it needs is the organization's agent installation key (see tl_get_organization_auth_key), and anyone holding it can install agents into the organization. ThreatLocker does not document this endpoint's media type, so the call may fail with a content-type error on some instances. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
authKeystringyesRequired. The organization's agent installation auth key (from tl_get_organization_auth_key).
brandstringyesRequired. The brand whose sample deployment path to fetch.
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector. Discover child organization ids with tl_search_child_organizations.

[ThreatLocker] Get the SIGNED ThreatLocker agent deployment script for a brand. SENSITIVE: the response is deployment material for installing agents into this organization — handle it like a secret and do not paste it into shared channels. Note ThreatLocker does not document what media type this endpoint returns, so on some instances the call may fail with a content-type error; download the script from the Portal in that case. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
brandstringyesRequired. The brand whose deployment script to fetch.
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector. Discover child organization ids with tl_search_child_organizations.

[ThreatLocker] Get the UNSIGNED ThreatLocker agent deployment script for a brand. SENSITIVE: the response is deployment material for installing agents into this organization — handle it like a secret. ThreatLocker does not document this endpoint's media type, so the call may fail with a content-type error on some instances; download the script from the Portal in that case. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
brandstringyesRequired. The brand whose deployment script to fetch.
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector. Discover child organization ids with tl_search_child_organizations.

[ThreatLocker] DESTRUCTIVE: move computers to a different organization and computer group. This re-scopes which policies apply to those devices, so protection can change immediately. Requires computerDetailDtosJson — a JSON array whose items are {computerGroupId, computerId, computerName, group, hostname, maintenanceTypeId, operatingSystem, organization, organizationId, osType} — plus the target organization and group GUIDs and whether to run a learning rescan after the move. Discover targets with tl_list_organizations_for_move_computers. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
computerDetailDtosJsonstringyesRequired. JSON array of computers to move — each item {computerGroupId, computerId, computerName, group, hostname, maintenanceTypeId, operatingSystem, organization, organizationId, osType}.
enableLearningRescanbooleanyesRequired. True to run a learning rescan after the move.
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector. Discover child organization ids with tl_search_child_organizations.
targetComputerGroupIdstringyesRequired. The destination computer group GUID.
targetOrganizationIdstringyesRequired. The destination organization GUID (from tl_list_organizations_for_move_computers).

[ThreatLocker] DESTRUCTIVE: remove duplicate computer records in the managed organization. The only input is whether to include child organizations — there is no per-computer selection and no preview, so ThreatLocker decides which records are duplicates. Run tl_search_computers first if you need to know what is currently registered. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
includeChildOrganizationsbooleanyesRequired. True to also remove duplicates in child organizations, false for this organization only.
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector. Discover child organization ids with tl_search_child_organizations.

[ThreatLocker] Trigger a baseline rescan on one or more computers, optionally enabling learning while it runs. Requires computerDetailDtosJson — a JSON array whose items are {computerId, organizationId, computerGroupId}. A rescan re-inventories what is installed so the allowlist reflects current software. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
computerDetailDtosJsonstringyesRequired. JSON array of target computers — each item {computerId, organizationId, computerGroupId}.
enableLearningbooleanyesRequired. True to enable learning mode during the rescan.
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector. Discover child organization ids with tl_search_child_organizations.

[ThreatLocker] DESTRUCTIVE: flag a computer to restart. This interrupts whoever is using the endpoint — confirm the target before running it. Requires the computer GUID and its organization GUID. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
computerIdstringyesRequired. The computer GUID to restart.
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector. Discover child organization ids with tl_search_child_organizations.
organizationIdstringyesRequired. The organization GUID the computer belongs to.

[ThreatLocker] DESTRUCTIVE and ORG-WIDE: flag EVERY computer in the managed organization to restart. There are no parameters — the target is whichever organization this call is scoped to, so double-check managedOrganizationId (or the connector's default) before running it. This interrupts every user in that organization. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector. Discover child organization ids with tl_search_child_organizations.

[ThreatLocker] Search computers (the Devices page). Requires orderBy and paging. Optional filters: searchBy selects the field searchText matches (Computer and Asset Name=1, Username=2, Computer Group Name=3, Last Check-in IP Address=4, Organization Name=5); action filters by current mode or update channel (Secure, Installation, Learning, MonitorOnly, Manual Update, Pre-Releases, Regular, Expedited, Slow and Steady); kindOfAction selects which grouping the action applies to (Computer Mode, TamperProtectionDisabled, NeedsReview, ReadyToSecure, BaselineNotUploaded, Update Channel); plus computerId, computerGroup, childOrganizations, and isAscending. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
actionstringnonullOptional mode/update-channel filter: Secure, Installation, Learning, MonitorOnly, Manual Update, Pre-Releases, Regular, Expedited, or Slow and Steady.
childOrganizationsbooleannonullOptional. Include computers in child organizations.
computerGroupstringnonullOptional. Filter to one computer group GUID.
computerIdstringnonullOptional. Filter to one computer GUID.
isAscendingbooleannonullOptional. Sort ascending when true.
kindOfActionstringnonullOptional. Which grouping `action` applies to: Computer Mode, TamperProtectionDisabled, NeedsReview, ReadyToSecure, BaselineNotUploaded, or Update Channel.
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector. Discover child organization ids with tl_search_child_organizations.
orderBystringyesRequired. Field to order by.
pageNumberintegeryesRequired. 1-based page number.
pageSizeintegeryesRequired. Rows per page. Capped at 500 by StackJack (ThreatLocker documents no maximum).
searchByintegernonullOptional. Which field searchText matches: Computer and Asset Name=1, Username=2, Computer Group Name=3, Last Check-in IP Address=4, Organization Name=5.
searchTextstringnonullOptional. The text to match against the field named by searchBy.

[ThreatLocker] DESTRUCTIVE: put a computer into a maintenance mode. Several of these modes weaken enforcement (monitor-only, learning, tamper protection disabled) or cut the device off (isolation, lockdown), so treat it as a protection-state change. Note this operation takes the SINGULAR nested object computerDetailDtoJson = {computerId, maintenanceEndDate, maintenanceTypeId, organizationId, startDateTime} (dates UTC ISO-8601), unlike its sibling actions which take an array. maintenanceTypeId: Application Control Monitor Only=1, Application Control Learning=3, Elevation Mode=4, Secured=8, Disable ThreatLocker Detect=16, Network Control Monitor Only=17, Storage Control Monitor Only=18, Installation Legacy=19. applicationId accepts an application GUID or one of the documented literals autocomp, autogroup, autosystem, or an empty string. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
applicationIdstringyesRequired. An application GUID, or one of the literals autocomp, autogroup, autosystem, or an empty string.
computerDetailDtoJsonstringyesRequired. The SINGULAR computer detail object as JSON: {computerId, maintenanceEndDate, maintenanceTypeId, organizationId, startDateTime}.
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector. Discover child organization ids with tl_search_child_organizations.

[ThreatLocker] Update a computer's editable settings — name, computer group, and proxy configuration. The vendor requires every field, so read the current values with tl_get_computer first and resend the ones you are not changing. proxyServerOption is the scheme ("http://" or "https://"); optionsJson is the computer's options array. Moving a computer to a different group changes which policies apply to it. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
computerGroupIdstringyesRequired. The computer group GUID the computer should belong to.
computerIdstringyesRequired. The computer GUID to update.
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector. Discover child organization ids with tl_search_child_organizations.
namestringyesRequired. The computer name.
optionsJsonstringyesRequired. JSON array of the computer's options (send the current array to leave options unchanged).
proxyServerOptionstringyesRequired. Proxy scheme, e.g. "http://" or "https://" (empty string when unused).
proxyURLstringyesRequired. Full proxy URL (empty string when unused).
proxyUrlEntrystringyesRequired. Proxy host entry (empty string when unused).
useProxyServerbooleanyesRequired. Whether the agent should use a proxy server.

[ThreatLocker] DESTRUCTIVE: change the installed ThreatLocker agent version on specific computers. An agent update touches the security software on managed endpoints and can require a restart. Resolve the version and version id with tl_list_agent_versions. Requires computerDetailDtosJson — a JSON array whose items are {computerId, organizationId, osType}. For a scheduled, batched rollout use tl_create_scheduled_agent_action instead. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
computerDetailDtosJsonstringyesRequired. JSON array of target computers — each item {computerId, organizationId, osType}.
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector. Discover child organization ids with tl_search_child_organizations.
threatLockerVersionstringyesRequired. The target agent version string (from tl_list_agent_versions).
threatLockerVersionIdstringyesRequired. The target agent version GUID (from tl_list_agent_versions).

Device Activity

ToolPlanAccessSummary
tl_list_online_devicesFreeRead-onlyList the devices currently online in the managed organization.
tl_search_computer_checkinsFreeRead-onlyList one computer's agent check-in history.

[ThreatLocker] List the devices currently online in the managed organization. Paging is optional — omit both parameters to take ThreatLocker's own defaults. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector.
pageNumberintegernonullOptional. 1-based page number. Omit for ThreatLocker's default.
pageSizeintegernonullOptional. Rows per page. Capped at 500 by StackJack; omit for ThreatLocker's default.

[ThreatLocker] List one computer's agent check-in history. Requires the computer GUID, paging, and hideHeartbeat — pass true to suppress routine heartbeat rows and see only meaningful check-ins. Use this to diagnose an agent that has stopped reporting. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
computerIdstringyesRequired. The computer GUID (from tl_search_computers).
hideHeartbeatbooleanyesRequired. True to hide routine heartbeat entries.
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector.
pageNumberintegeryesRequired. 1-based page number.
pageSizeintegeryesRequired. Rows per page. Capped at 500 by StackJack (ThreatLocker documents no maximum).

Computer Groups

ToolPlanAccessSummary
tl_create_computer_groupProWriteCreate a computer group.
tl_delete_computer_groupProDestructiveDESTRUCTIVE: delete a computer group.
tl_get_computer_groupFreeRead-onlyGet one computer group by GUID, including its baseline, exclusion, and monitor-mode configuration.
tl_list_computer_group_options_by_organizationFreeRead-onlyList the computer group dropdown options for the managed organization.
tl_list_computer_group_options_with_organizationFreeRead-onlyList computer group dropdown options together with their organization.
tl_list_computer_groups_and_computersFreeRead-onlyList computer groups together with their member computers — the combined tree the Portal uses for group-and-device pickers.
tl_list_computer_groups_for_downloadFreeRead-onlyList the computer groups offered when downloading an agent installer — the group a newly installed device would join.
tl_list_computer_groups_for_permit_applicationFreeRead-onlyList the computer groups selectable when permitting an application (the group-level choice in the approval flow).
tl_search_computer_groupsFreeRead-onlySearch computer groups.
tl_update_computer_groupProDestructiveUpdate a computer group.

[ThreatLocker] Create a computer group. Requires a name and osType — Windows=1, MAC=2, Linux=3, Windows XP=5, Ingester=6, iOS=10, Android=11. Optional settings shape how devices in the group behave: autoCreatePolicies, baselineAllPaths, baselineOptionsJson (a JSON string array), cyberHeroUseOrgSettings, exclusionsJson (a JSON array of {exclusionType, filePath, value}; one documented variant omits filePath), initialMonitorModeHours, optionsJson (a JSON string array), policyRefreshIntervalSeconds, and tlInstructions. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
autoCreatePoliciesintegernonullOptional. Auto-create-policies setting.
baselineAllPathsbooleannonullOptional. Baseline every path rather than a subset.
baselineOptionsJsonstringnonullOptional. JSON string array of baseline options.
cyberHeroUseOrgSettingsbooleannonullOptional. Use the organization's Cyber Hero settings for this group.
exclusionsJsonstringnonullOptional. JSON array of exclusions — each {exclusionType, filePath, value} (filePath omitted in one documented variant).
initialMonitorModeHoursintegernonullOptional. Hours a newly added device spends in monitor mode.
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector.
namestringyesRequired. The group name.
optionsJsonstringnonullOptional. JSON string array of group options.
osTypeintegeryesRequired OS type: Windows=1, MAC=2, Linux=3, Windows XP=5, Ingester=6, iOS=10, Android=11.
policyRefreshIntervalSecondsintegernonullOptional. How often agents refresh policy, in seconds.
tlInstructionsstringnonullOptional. Free-text instructions stored on the group.

[ThreatLocker] DESTRUCTIVE: delete a computer group. Policies attached at the group level go with it, so any device that relied on them loses that protection or permission — check membership with tl_list_computer_groups_and_computers first. Requires the group GUID, its name, and its organization GUID. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
computerGroupIdstringyesRequired. The computer group GUID to delete.
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector.
namestringyesRequired. The group's name.
organizationIdstringyesRequired. The organization GUID the group belongs to.

[ThreatLocker] Get one computer group by GUID, including its baseline, exclusion, and monitor-mode configuration. Read this before tl_update_computer_group so you can resend the settings you are not changing. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
computerGroupIdstringyesRequired. The computer group GUID (from tl_search_computer_groups).
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector.

[ThreatLocker] List the computer group dropdown options for the managed organization. Optionally filter by computerGroupOSTypeId (Windows=1, MAC=2, Linux=3, Windows XP=5) or by the string computerOSType ("windows", "mac", "linux", "windows xp"). Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
computerGroupOSTypeIdintegernonullOptional numeric OS filter: Windows=1, MAC=2, Linux=3, Windows XP=5.
computerOSTypestringnonullOptional string OS filter: "windows", "mac", "linux", or "windows xp".
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector.

[ThreatLocker] List computer group dropdown options together with their organization. Note: ThreatLocker documents the includeAvailableOrganizations parameter's NAME but neither its type nor its accepted values, so StackJack forwards whatever literal you pass without interpreting it — omit it unless your instance's own API documentation tells you what to send. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
includeAvailableOrganizationsstringnonullOptional. Forwarded verbatim — ThreatLocker publishes no type or accepted value for this parameter.
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector.

[ThreatLocker] List computer groups together with their member computers — the combined tree the Portal uses for group-and-device pickers. Optional includeGlobal, includeOrganizations, includeParentGroups, and includeLoggedInObjects control how much of the tree comes back. NOTE the osType parameter: ThreatLocker labels it a boolean while documenting integer values (All=0, Windows=1, MAC=2, Linux=3, Windows XP=5), so StackJack forwards your literal without interpreting it rather than guessing which type is right. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
includeGlobalbooleannonullOptional. Include global groups.
includeLoggedInObjectsbooleannonullOptional. Include the objects the signed-in user is scoped to.
includeOrganizationsbooleannonullOptional. Include organizations in the tree.
includeParentGroupsbooleannonullOptional. Include parent groups.
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector.
osTypestringnonullOptional, forwarded verbatim. The vendor documents integer values (All=0, Windows=1, MAC=2, Linux=3, Windows XP=5) but types the parameter as a boolean — pass the value your instance expects.

[ThreatLocker] List the computer groups offered when downloading an agent installer — the group a newly installed device would join. Takes no inputs beyond the organization scope. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector.

[ThreatLocker] List the computer groups selectable when permitting an application (the group-level choice in the approval flow). Optionally filter by osType: Windows=1, MAC=2, Linux=3, Windows XP=5. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector.
osTypeintegernonullOptional OS filter: Windows=1, MAC=2, Linux=3, Windows XP=5.

[ThreatLocker] Search computer groups. Requires paging; optional searchText, showAllGroups, and an osType filter — All=0, Windows=1, MAC=2, Linux=3, Windows XP=5, Ingester=6, iOS=10, Android=11. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector.
osTypeintegernonullOptional OS filter: All=0, Windows=1, MAC=2, Linux=3, Windows XP=5, Ingester=6, iOS=10, Android=11.
pageNumberintegeryesRequired. 1-based page number.
pageSizeintegeryesRequired. Rows per page. Capped at 500 by StackJack (ThreatLocker documents no maximum).
searchTextstringnonullOptional. Free-text filter on the group name.
showAllGroupsbooleannonullOptional. Include all groups rather than only those in scope.

[ThreatLocker] Update a computer group. Requires its GUID, name, and osType (Windows=1, MAC=2, Linux=3, Windows XP=5, Ingester=6, iOS=10, Android=11.); the optional settings match tl_create_computer_group. Group settings apply to every device in the group, so read the current values with tl_get_computer_group first and resend what you are not changing. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
autoCreatePoliciesintegernonullOptional. Auto-create-policies setting.
baselineAllPathsbooleannonullOptional. Baseline every path rather than a subset.
baselineOptionsJsonstringnonullOptional. JSON string array of baseline options.
computerGroupIdstringyesRequired. The computer group GUID to update.
cyberHeroUseOrgSettingsbooleannonullOptional. Use the organization's Cyber Hero settings for this group.
exclusionsJsonstringnonullOptional. JSON array of exclusions — each {exclusionType, filePath, value}.
initialMonitorModeHoursintegernonullOptional. Hours a newly added device spends in monitor mode.
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector.
namestringyesRequired. The group name (resend the current value if unchanged).
optionsJsonstringnonullOptional. JSON string array of group options.
osTypeintegeryesRequired OS type: Windows=1, MAC=2, Linux=3, Windows XP=5, Ingester=6, iOS=10, Android=11.
policyRefreshIntervalSecondsintegernonullOptional. How often agents refresh policy, in seconds.
tlInstructionsstringnonullOptional. Free-text instructions stored on the group.

DAC Analysis

ToolPlanAccessSummary
tl_get_dac_analysis_itemFreeRead-onlyGet one DAC analysis item by its numeric id — the detail behind a single finding returned by tl_search_dac_analysis_results.
tl_search_dac_analysis_resultsFreeRead-onlySearch DAC analysis results — configuration findings with their criticality.

[ThreatLocker] Get one DAC analysis item by its numeric id — the detail behind a single finding returned by tl_search_dac_analysis_results. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
analysisItemIdintegeryesRequired. The numeric analysis item id (from tl_search_dac_analysis_results).
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector.

[ThreatLocker] Search DAC analysis results — configuration findings with their criticality. Requires paging. Optional filters: criticalityId (Low=1, Moderate=2, High=3, Critical=4); entityTypeId (organization=1, computer group=2, computer=3) with appliesToId naming the entity; categoryId (Network Policy=1, Storage Policy=2, Application Control=3, Registry Policy=4, Group Policy=6, Account and Authentication=7, Advanced Audit Configuration=8, Local Security=9, Patch Management=10, Remote Desktop and Access Control=11, User Rights Assignment=12, Detect and Response=13); plus includeChildOrgs, searchText, and sortBy. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
appliesToIdstringnonullOptional. The GUID of the entity the findings apply to (pair with entityTypeId).
categoryIdintegernonullOptional category: Network Policy=1, Storage Policy=2, Application Control=3, Registry Policy=4, Group Policy=6, Account and Authentication=7, Advanced Audit Configuration=8, Local Security=9, Patch Management=10, Remote Desktop and Access Control=11, User Rights Assignment=12, Detect and Response=13.
criticalityIdintegernonullOptional criticality: Low=1, Moderate=2, High=3, Critical=4.
entityTypeIdintegernonullOptional entity type: organization=1, computer group=2, computer=3.
includeChildOrgsbooleannonullOptional. Include findings from child organizations.
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector.
pageNumberintegeryesRequired. 1-based page number.
pageSizeintegeryesRequired. Rows per page. Capped at 500 by StackJack (ThreatLocker documents no maximum).
searchTextstringnonullOptional. Free-text filter.
sortBystringnonullOptional. Field to sort by.

Policies

ToolPlanAccessSummary
tl_copy_policiesProWriteCopy existing policies from one scope to one or more target scopes.
tl_create_network_access_policyProDestructiveCreate a Network Control access policy for a computer group.
tl_create_policyProWriteCreate an Application Control policy.
tl_delete_policiesProDestructiveDESTRUCTIVE: delete a policy.
tl_get_policyFreeRead-onlyGet one policy by GUID, including its conditions, schedule, and ringfencing configuration.
tl_list_policies_for_applicationFreeRead-onlyList the policies that reference one application — answers 'what would break if I delete or change this application'.
tl_search_policiesFreeRead-onlySearch policies for a computer group.
tl_update_policyProDestructiveUpdate an existing Application Control policy (a PUT — it replaces the policy body).

[ThreatLocker] Copy existing policies from one scope to one or more target scopes. Requires osType (Windows=1, MAC=2, Linux=3, Windows XP=5), policiesJson (a JSON array of ), the source scope and organization GUIDs, and targetAppliesToIdsJson (a JSON array of destination scope GUIDs). The copies land at the target scopes and take effect once deployed. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector.
osTypeintegeryesRequired OS type: Windows=1, MAC=2, Linux=3, Windows XP=5.
policiesJsonstringyesRequired. JSON array of policies to copy — each item .
sourceAppliesToIdstringyesRequired. The source scope GUID the policies currently belong to.
sourceOrganizationIdstringyesRequired. The source organization GUID.
targetAppliesToIdsJsonstringyesRequired. JSON array of destination scope GUIDs.

[ThreatLocker] Create a Network Control access policy for a computer group. ThreatLocker documents every field as required. Enums: direction (Inbound=1, Outbound=2); protocol (Only TCP=1, Only UDP=2, Both TCP and UDP=3); policyActionId (Permit=1, Deny=2); policyScheduleStatus (No schedule/expiration=0, Expiration=1, Schedule=2); status (Active=1, Inactive=3). Array fields: sourceLocationsJson and destinationLocationsJson are JSON arrays of {ruleLocationTypeId, text, value}; networkAccessRulePortDtosJson is a JSON string array of ports; policySchedulesJson is a JSON array of {dayoftheWeek, startTime, durationHours, durationMinutes} — note the vendor's spelling of dayoftheWeek — and is used when policyScheduleStatus is 2. Pass an empty array for a group you are not scoping and set the matching allSources / allDestinations / allPorts flag instead. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
allDestinationsbooleanyesRequired. True to match any destination (then send an empty destinationLocationsJson array).
allPortsbooleanyesRequired. True to match any port (then send an empty networkAccessRulePortDtosJson array).
allSourcesbooleanyesRequired. True to match any source (then send an empty sourceLocationsJson array).
computerGroupIdstringyesRequired. The computer group GUID the policy applies to.
descriptionstringyesRequired. The policy description.
destinationLocationsJsonstringyesRequired. JSON array of destination locations — each {ruleLocationTypeId, text, value}. Empty array when allDestinations is true.
directionintegeryesRequired direction: Inbound=1, Outbound=2.
endDatestringyesRequired. Expiration timestamp, UTC ISO-8601 (used when policyScheduleStatus is 1).
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector.
namestringyesRequired. The policy name.
networkAccessRulePortDtosJsonstringyesRequired. JSON string array of ports. Empty array when allPorts is true.
policyActionIdintegeryesRequired action: Permit=1, Deny=2.
policyScheduleStatusintegeryesRequired schedule status: No schedule/expiration=0, Expiration=1, Schedule=2.
policySchedulesJsonstringyesRequired. JSON array of schedules — each {dayoftheWeek, startTime, durationHours, durationMinutes}. Empty array unless policyScheduleStatus is 2.
protocolintegeryesRequired protocol: Only TCP=1, Only UDP=2, Both TCP and UDP=3.
sourceLocationsJsonstringyesRequired. JSON array of source locations — each {ruleLocationTypeId, text, value}. Empty array when allSources is true.
statusintegeryesRequired status: Active=1, Inactive=3.

[ThreatLocker] Create an Application Control policy. A policy is what actually permits, denies, or ringfences an application, so review the effect before creating one — and remember it does not reach endpoints until deployed (tl_deploy_policies). ThreatLocker's body is deeply nested, so pass it as JSON: required fields are applicationIdList (array of application GUIDs), computerGroupId, name, osType (Windows=1, MAC=2, Linux=3, Windows XP=5), and policyActionId: Permit=1, Deny=2, Permit with Ringfence=6. Optional groups include a schedule (policyScheduleStatus + policySchedules with dayoftheWeek / startTime / durationHours / durationMinutes), networkExclusions (tagPrefixTypeId: Domain=1, IPv4=2, IPv6=3), elevationStatus (Do not Elevate=0, Elevate to run as local administrator=1), killRunningProcesses, monitorMode, and ringfencingOptions with rfFilePolicy / rfNetworkPolicy / rfRegistryPolicy / rfAssociatedApplicationPolicy. See ThreatLocker's Policy article for the full template. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The complete policy body as JSON, per ThreatLocker's documented PolicyInsert template (required: applicationIdList, computerGroupId, name, osType, policyActionId).
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector.

[ThreatLocker] DESTRUCTIVE: delete a policy. Whatever that policy permitted stops being permitted (or whatever it denied stops being denied), so check its effect with tl_get_policy first. ThreatLocker implements this deletion as a PUT rather than a DELETE — that is the vendor's design, not a mistake. Requires the policy and organization GUIDs; name is optional. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector.
namestringnonullOptional. The policy name.
organizationIdstringyesRequired. The organization GUID the policy belongs to.
policyIdstringyesRequired. The policy GUID to delete.

[ThreatLocker] Get one policy by GUID, including its conditions, schedule, and ringfencing configuration. Read this before tl_update_policy — an update replaces the policy body, so start from the current one. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector.
policyIdstringyesRequired. The policy GUID (from tl_search_policies).

[ThreatLocker] List the policies that reference one application — answers 'what would break if I delete or change this application'. Requires the application and organization GUIDs plus paging; optional appliesToId narrows to one scope and includeDenies adds deny policies. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
applicationIdstringyesRequired. The application GUID.
appliesToIdstringnonullOptional. Narrow to one scope GUID (organization, computer group, or computer).
includeDeniesbooleannonullOptional. Include deny policies as well as permits.
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector.
organizationIdstringyesRequired. The organization GUID the application belongs to.
pageNumberintegeryesRequired. 1-based page number.
pageSizeintegeryesRequired. Rows per page. Capped at 500 by StackJack (ThreatLocker documents no maximum).

[ThreatLocker] Search policies for a computer group. Requires the computer group GUID, a filter string, and paging. Optional activeOnly, showAllPolicies, searchText, and osType (Windows=1, MAC=2, Linux=3, Windows XP=5). Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
activeOnlybooleannonullOptional. Restrict to currently-active policies.
computerGroupIdstringyesRequired. The computer group GUID whose policies to search (from tl_search_computer_groups).
filterstringyesRequired. The filter string the Portal's policy list uses.
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector.
osTypeintegernonullOptional OS filter: Windows=1, MAC=2, Linux=3, Windows XP=5.
pageNumberintegeryesRequired. 1-based page number.
pageSizeintegeryesRequired. Rows per page. Capped at 500 by StackJack (ThreatLocker documents no maximum).
searchTextstringnonullOptional. Free-text filter on the policy name.
showAllPoliciesbooleannonullOptional. Include policies inherited from other levels.

[ThreatLocker] Update an existing Application Control policy (a PUT — it replaces the policy body). Read the current policy with tl_get_policy first and send it back with your changes applied, or you may drop conditions, schedules, or ringfencing you did not mean to remove. Required fields are applicationIdList, computerGroupId, name, osType, policyActionId: Permit=1, Deny=2, Permit with Ringfence=6. and policyId. Optional groups match tl_create_policy, with elevationStatus adding Elevate (Do Not Notify User)=2. Changes reach endpoints only after deployment. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The complete policy body as JSON, per ThreatLocker's documented PolicyUpdateById template (required: applicationIdList, computerGroupId, name, osType, policyActionId, policyId).
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector.

Policy Deployment

ToolPlanAccessSummary
tl_deploy_policiesProDestructiveDESTRUCTIVE and ORG-WIDE: deploy all pending policy changes to every endpoint in the managed organization.
tl_deploy_policies_for_computerProDestructiveDESTRUCTIVE: deploy pending policy changes to ONE computer — the narrower alternative to tl_deploy_policies, and the safer way to verify a policy change before rolling it out.

[ThreatLocker] DESTRUCTIVE and ORG-WIDE: deploy all pending policy changes to every endpoint in the managed organization. This is the moment policy edits start being enforced, so anything staged by someone else deploys too — check what is pending before running it. There are no parameters: the target is whichever organization this call is scoped to, so verify managedOrganizationId (or the connector's default) first. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector. Discover child organization ids with tl_search_child_organizations.

[ThreatLocker] DESTRUCTIVE: deploy pending policy changes to ONE computer — the narrower alternative to tl_deploy_policies, and the safer way to verify a policy change before rolling it out. Requires both the computer GUID and its name (ThreatLocker documents both as query parameters for this endpoint). Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
computerIdstringyesRequired. The computer GUID to deploy to (from tl_search_computers).
computerNamestringyesRequired. That computer's name, as ThreatLocker knows it.
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector. Discover child organization ids with tl_search_child_organizations.

Maintenance Modes

ToolPlanAccessSummary
tl_create_maintenance_modeProDestructiveDESTRUCTIVE: start a maintenance mode on a computer.
tl_end_maintenance_modeProWriteEnd an active maintenance mode on a computer now, restoring normal enforcement.
tl_list_computer_maintenance_modesFreeRead-onlyList the maintenance modes on one computer — current and historical windows, with their types and end times.
tl_update_maintenance_mode_end_dateProDestructiveChange when a computer's maintenance mode ends.

[ThreatLocker] DESTRUCTIVE: start a maintenance mode on a computer. Several of the documented modes WEAKEN enforcement (monitor-only, installation, learning, tamper protection disabled) and two cut the device off (isolation, lockdown), so this changes the device's security state for the whole window — prefer the shortest window that does the job. maintenanceTypeId: Application Control Monitor Only=1, Application Control Installation Mode=2, Learning=3, Elevation=4, Tamper Protection Disabled=6, Isolation=14, Lockdown=15, Disable Ops Alerts=16, Network Control Monitor Only=17, Storage Control Monitor Only=18. automaticApplicationType: empty=0, Automatic Computer=1, Automatic Group=2, Automatic System=3. All fields are documented required: dates are UTC ISO-8601 (computerDateTime is the device's own local time), existingApplicationJson is {applicationId, name}, newApplicationJson is {applicationId, applicationName, createApplicationOnly, appliesToId}, and usersListJson is a JSON array of users (empty array when allUsers is true). Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
allUsersbooleanyesRequired. True to apply to all users on the device (then send an empty usersListJson array).
automaticApplicationbooleanyesRequired. Whether ThreatLocker should build the application automatically.
automaticApplicationTypeintegeryesRequired automatic-application type: empty=0, Automatic Computer=1, Automatic Group=2, Automatic System=3.
computerDateTimestringyesRequired. The computer's own local date/time, UTC ISO-8601.
computerIdstringyesRequired. The computer GUID to put into maintenance.
createNewApplicationbooleanyesRequired. Whether to create a new application for what is installed during the window.
endDateTimestringyesRequired. Window end, UTC ISO-8601.
existingApplicationJsonstringyesRequired. The existing application as JSON: {applicationId, name}. Send an empty object when useExistingApplication is false.
maintenanceTypeIdintegeryesRequired. maintenanceTypeId: Application Control Monitor Only=1, Application Control Installation Mode=2, Learning=3, Elevation=4, Tamper Protection Disabled=6, Isolation=14, Lockdown=15, Disable Ops Alerts=16, Network Control Monitor Only=17, Storage Control Monitor Only=18.
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector.
newApplicationJsonstringyesRequired. The new application as JSON: {applicationId, applicationName, createApplicationOnly, appliesToId}. Send an empty object when createNewApplication is false.
permitEndbooleanyesRequired. Whether the window may be ended early.
startDateTimestringyesRequired. Window start, UTC ISO-8601.
useExistingApplicationbooleanyesRequired. Whether to add what is installed to an existing application.
usersListJsonstringyesRequired. JSON array of users the window applies to. Empty array when allUsers is true.

[ThreatLocker] End an active maintenance mode on a computer now, restoring normal enforcement. This is the hardening direction, which is why it is not flagged destructive — but note that ending an installation window early can leave a half-installed application unlearned. Requires the computer GUID, the maintenance mode GUID (from tl_list_computer_maintenance_modes), and the mode's type. maintenanceTypeId: Application Control Monitor Only=1, Application Control Installation Mode=2, Learning=3, Elevation=4, Tamper Protection Disabled=6, Isolation=14, Lockdown=15, Disable Ops Alerts=16, Network Control Monitor Only=17, Storage Control Monitor Only=18. This operation also documents Installation Legacy=19. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
computerIdstringyesRequired. The computer GUID.
maintenanceModeIdstringyesRequired. The maintenance mode GUID to end (from tl_list_computer_maintenance_modes).
maintenanceTypeIdintegeryesRequired. The mode's type. maintenanceTypeId: Application Control Monitor Only=1, Application Control Installation Mode=2, Learning=3, Elevation=4, Tamper Protection Disabled=6, Isolation=14, Lockdown=15, Disable Ops Alerts=16, Network Control Monitor Only=17, Storage Control Monitor Only=18. Installation Legacy=19 is also documented here.
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector.

[ThreatLocker] List the maintenance modes on one computer — current and historical windows, with their types and end times. Use this to see whether a device is currently in a relaxed state before troubleshooting a block, and to find the maintenanceModeId that tl_end_maintenance_mode needs. Requires the computer GUID and paging. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
computerIdstringyesRequired. The computer GUID (from tl_search_computers).
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector.
pageNumberintegeryesRequired. 1-based page number.
pageSizeintegeryesRequired. Rows per page. Capped at 500 by StackJack (ThreatLocker documents no maximum).

[ThreatLocker] Change when a computer's maintenance mode ends. Shortening the window restores enforcement sooner; EXTENDING it keeps the device in a relaxed (or isolated) state for longer, so check the mode type before extending. Requires the computer GUID, the new end date as UTC ISO-8601, and the mode's type. maintenanceTypeId: Application Control Monitor Only=1, Application Control Installation Mode=2, Learning=3, Elevation=4, Tamper Protection Disabled=6, Isolation=14, Lockdown=15, Disable Ops Alerts=16, Network Control Monitor Only=17, Storage Control Monitor Only=18. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
computerIdstringyesRequired. The computer GUID.
maintenanceEndDatestringyesRequired. The new end date/time, UTC ISO-8601.
maintenanceTypeIdintegeryesRequired. The mode's type. maintenanceTypeId: Application Control Monitor Only=1, Application Control Installation Mode=2, Learning=3, Elevation=4, Tamper Protection Disabled=6, Isolation=14, Lockdown=15, Disable Ops Alerts=16, Network Control Monitor Only=17, Storage Control Monitor Only=18.
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector.

Organizations

ToolPlanAccessSummary
tl_create_child_organizationProDestructiveCreate a child organization (onboard a customer).
tl_get_organization_auth_keyFreeRead-onlyGet the organization's agent installation auth key.
tl_list_organizations_for_move_computersFreeRead-onlyList the organizations a computer can be moved into — the destination pick-list for tl_move_computers_to_organization.
tl_rotate_organization_auth_keyProDestructiveDESTRUCTIVE: rotate the organization's agent installation auth key.
tl_search_child_organizationsFreeRead-onlySearch the child organizations under the managed organization — your customer list.

[ThreatLocker] Create a child organization (onboard a customer). Requires a displayName and timezoneId — list valid timezone ids with tl_list_timezones. Optional: name, domainsJson (a JSON string array of email domains), itarCompliant, hasDisabledEmailNotifications, optionsJson (a JSON string array), proxy settings, elevationDefaultHours (0, 1, 2, 6, 12, or 24), and timeoutOnLogin (15, 30, 60, 120, 240, 480, or 1440 minutes). Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
displayNamestringyesRequired. The organization's display name.
domainsJsonstringnonullOptional. JSON string array of the organization's email domains.
elevationDefaultHoursintegernonullOptional default elevation duration in hours: 0, 1, 2, 6, 12, or 24.
hasDisabledEmailNotificationsbooleannonullOptional. Disable ThreatLocker email notifications for this organization.
itarCompliantbooleannonullOptional. Mark the organization ITAR compliant.
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector. This is the PARENT the new organization is created under.
namestringnonullOptional. The internal organization name, when it differs from the display name.
optionsJsonstringnonullOptional. JSON string array of organization options.
proxyServerOptionstringnonullOptional proxy scheme: "http://" or "https://".
proxyUrlEntrystringnonullOptional. Proxy host entry.
timeoutOnLoginintegernonullOptional Portal login timeout in minutes: 15, 30, 60, 120, 240, 480, or 1440.
timezoneIdstringyesRequired. A timezone id (from tl_list_timezones).
useProxyServerbooleannonullOptional. Whether agents should use a proxy server.

[ThreatLocker] Get the organization's agent installation auth key. SENSITIVE: the response IS a secret — anyone holding this key can install ThreatLocker agents into the organization, so do not paste it into tickets or shared channels. There are no parameters: the key returned belongs to whichever organization this call is scoped to, so be deliberate about managedOrganizationId — a wrong value returns a DIFFERENT customer's key. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector. This selects WHICH organization's installation key is returned.

[ThreatLocker] List the organizations a computer can be moved into — the destination pick-list for tl_move_computers_to_organization. Optional searchText filters by name. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector.
searchTextstringnonullOptional. Filter by organization name.

[ThreatLocker] DESTRUCTIVE: rotate the organization's agent installation auth key. The existing key stops working immediately, so any deployment script, RMM package, or pending install still carrying the old key WILL FAIL until it is updated with the new one. There are no parameters — the key rotated belongs to whichever organization this call is scoped to, so verify managedOrganizationId (or the connector's default) before running it. Read the current key first with tl_get_organization_auth_key if you need to compare. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector. This selects WHICH organization's installation key is rotated.

[ThreatLocker] Search the child organizations under the managed organization — your customer list. The GUIDs returned here are what you pass as managedOrganizationId on any other ThreatLocker tool to act on a specific customer. Requires orderBy and paging; optional includeAllChildren walks the whole tree, plus isAscending and searchText. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
includeAllChildrenbooleannonullOptional. Include descendants at every level, not just direct children.
isAscendingbooleannonullOptional. Sort ascending when true.
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector.
orderBystringyesRequired. Field to order by.
pageNumberintegeryesRequired. 1-based page number.
pageSizeintegeryesRequired. Rows per page. Capped at 500 by StackJack (ThreatLocker documents no maximum).
searchTextstringnonullOptional. Free-text filter on the organization name.

Override Codes

ToolPlanAccessSummary
tl_create_override_codeProDestructiveDESTRUCTIVE: mint an override code — a code that lets an end user BYPASS ThreatLocker protection on the target scope.
tl_revoke_override_codeProDestructiveDESTRUCTIVE: revoke override codes for the managed organization.
tl_search_override_codesFreeRead-onlySearch the override codes issued for a scope — use this to audit which protection bypasses currently exist and how long they last.

[ThreatLocker] DESTRUCTIVE: mint an override code — a code that lets an end user BYPASS ThreatLocker protection on the target scope. Treat it as handing out a temporary key: prefer the narrowest scope (a single computer over a whole organization) and the shortest usage limit. Requires appliesToId, appliesToType (Organization=1, Computer Group=2, Computer=3), noTimeLimit, and usageLimitMinutes. Setting noTimeLimit true creates a code that does not expire on its own — avoid it unless you have a specific reason, and revoke it when done. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
appliesToIdstringyesRequired. The scope GUID the code applies to.
appliesToTypeintegeryesRequired scope type: Organization=1, Computer Group=2, Computer=3.
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector.
noTimeLimitbooleanyesRequired. True for a code with no time limit (prefer false).
usageLimitMinutesintegeryesRequired. How many minutes the code remains usable (ignored when noTimeLimit is true).

[ThreatLocker] DESTRUCTIVE: revoke override codes for the managed organization. Anyone currently relying on a revoked code loses their bypass immediately. There are no parameters — the revoke applies to whichever organization this call is scoped to, so check what exists with tl_search_override_codes and verify managedOrganizationId (or the connector's default) first. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector.

[ThreatLocker] Search the override codes issued for a scope — use this to audit which protection bypasses currently exist and how long they last. Requires appliesToId (the organization, computer group, or computer GUID) and paging; optional includeChildOrganizations, searchText, and showOnlyCustomerCodes. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
appliesToIdstringyesRequired. The scope GUID the codes apply to (organization, computer group, or computer).
includeChildOrganizationsbooleannonullOptional. Include codes from child organizations.
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector.
pageNumberintegeryesRequired. 1-based page number.
pageSizeintegeryesRequired. Rows per page. Capped at 500 by StackJack (ThreatLocker documents no maximum).
searchTextstringnonullOptional. Free-text filter.
showOnlyCustomerCodesbooleannonullOptional. Show only customer-issued codes.

Scheduled Agent Actions

ToolPlanAccessSummary
tl_abort_scheduled_agent_actionProDestructiveDESTRUCTIVE: abort a scheduled agent action.
tl_create_scheduled_agent_actionProDestructiveSchedule an agent action — in practice a batched agent version rollout, and the safer alternative to forcing versions immediately.
tl_get_scheduled_agent_actionFreeRead-onlyGet one scheduled agent action's full configuration by its GUID — the hydration read the Portal uses when reopening a schedule for editing.
tl_list_scheduled_action_applies_toFreeRead-onlyList the organizations, groups, and computers a scheduled agent action can target.
tl_list_scheduled_agent_actionsFreeRead-onlyList the scheduled agent actions of a given type — currently only Version Update=1 is documented.
tl_search_scheduled_agent_actionsFreeRead-onlySearch the detail of one scheduled agent action — its targets and their progress.

[ThreatLocker] DESTRUCTIVE: abort a scheduled agent action. The queued work is destroyed — devices that already acted keep their new version, so an aborted rollout can leave the fleet on mixed versions. Requires the scheduledId, abortAll (true to abort every target), and appliesToJson (a JSON array of {appliesToId, appliesToTypeId} — appliesToTypeId: Organization=1, Computer Group=2, Computer=3, Global Computer Group=6.) naming the targets to abort when abortAll is false. Check progress with tl_search_scheduled_agent_actions first. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
abortAllbooleanyesRequired. True to abort every target of the schedule.
appliesToJsonstringyesRequired. JSON array of targets to abort — each {appliesToId, appliesToTypeId}. appliesToTypeId: Organization=1, Computer Group=2, Computer=3, Global Computer Group=6.
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector.
scheduledIdstringyesRequired. The scheduled action GUID to abort.

[ThreatLocker] Schedule an agent action — in practice a batched agent version rollout, and the safer alternative to forcing versions immediately. Requires appliesToJson (a JSON array of {appliesToId, appliesToTypeId} — appliesToTypeId: Organization=1, Computer Group=2, Computer=3, Global Computer Group=6. note the create article types appliesToId as a string while the abort article types it as a GUID), scheduledType (Version Update=1), and scheduledTypePayload (the type-specific payload, e.g. the target version). Optional batchAmount limits how many devices act at once, and startDate / windowStartTime / windowEndTime confine the rollout to a maintenance window. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
appliesToJsonstringyesRequired. JSON array of targets — each {appliesToId, appliesToTypeId}. appliesToTypeId: Organization=1, Computer Group=2, Computer=3, Global Computer Group=6.
batchAmountintegernonullOptional. How many devices to act on per batch.
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector.
scheduledTypeintegeryesRequired schedule type: Version Update=1.
scheduledTypePayloadstringyesRequired. The type-specific payload (for a version update, the target version).
startDatestringnonullOptional. When the schedule starts, UTC ISO-8601.
windowEndTimestringnonullOptional. Daily window end time.
windowStartTimestringnonullOptional. Daily window start time.

[ThreatLocker] Get one scheduled agent action's full configuration by its GUID — the hydration read the Portal uses when reopening a schedule for editing. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector.
scheduledIdstringyesRequired. The scheduled action GUID.

[ThreatLocker] List the organizations, groups, and computers a scheduled agent action can target. Requires osType — note this operation's enum differs from the rest of the API: Windows=1, MAC=2, Linux=3, Red Hat Enterprise Linux 6=7. Optional includeChildren and searchText. Use the ids returned here to build the appliesTo array for tl_create_scheduled_agent_action. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
includeChildrenbooleannonullOptional. Include targets in child organizations.
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector.
osTypeintegeryesRequired OS type for this operation: Windows=1, MAC=2, Linux=3, Red Hat Enterprise Linux 6=7.
searchTextstringnonullOptional. Free-text filter.

[ThreatLocker] List the scheduled agent actions of a given type — currently only Version Update=1 is documented. Optional includeChildren includes schedules in child organizations. Start here to find a scheduledId. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
includeChildrenbooleannonullOptional. Include schedules from child organizations.
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector.
scheduledTypeintegeryesRequired schedule type: Version Update=1.

[ThreatLocker] Search the detail of one scheduled agent action — its targets and their progress. Requires the scheduledId; optional computerGroupIdsJson and organizationIdsJson (JSON arrays of GUIDs) narrow the view, and paging, ordering, and searchText are all optional. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
computerGroupIdsJsonstringnonullOptional. JSON array of computer group GUIDs to narrow to.
isAscendingbooleannonullOptional. Sort ascending when true.
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector.
orderBystringnonullOptional. Field to order by.
organizationIdsJsonstringnonullOptional. JSON array of organization GUIDs to narrow to.
pageNumberintegernonullOptional. 1-based page number. Omit for ThreatLocker's default.
pageSizeintegernonullOptional. Rows per page. Capped at 500 by StackJack; omit for ThreatLocker's default.
scheduledIdstringyesRequired. The scheduled action GUID (from tl_list_scheduled_agent_actions).
searchTextstringnonullOptional. Free-text filter.

Reports

ToolPlanAccessSummary
tl_get_report_dataFreeRead-onlyGet one report's data by its GUID (from tl_list_reports).
tl_list_reportsFreeRead-onlyList the reports available to the managed organization.
tl_list_research_categoriesFreeRead-onlyList the research categories ThreatLocker classifies applications under — the vocabulary behind application research data and the category filter on application search.

[ThreatLocker] Get one report's data by its GUID (from tl_list_reports). Only reportId is required. ThreatLocker documents four further fields — data, startDate, endDate, and id — without explaining what they mean for a given report, so pass them only if your instance's own documentation tells you to; they are forwarded as given. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
datastringnonullOptional. Report-specific data value; semantics are not documented by the vendor.
endDatestringnonullOptional. End of the report window, UTC ISO-8601 (where the report supports one).
idstringnonullOptional. Report-specific id value; semantics are not documented by the vendor.
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector.
reportIdstringyesRequired. The report GUID (from tl_list_reports).
startDatestringnonullOptional. Start of the report window, UTC ISO-8601 (where the report supports one).

[ThreatLocker] List the reports available to the managed organization. Takes no inputs beyond the organization scope; use the report ids it returns with tl_get_report_data. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector.

[ThreatLocker] List the research categories ThreatLocker classifies applications under — the vocabulary behind application research data and the category filter on application search. Optional getStoreCategories includes store categories. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
getStoreCategoriesbooleannonullOptional. Include store categories as well.
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector.

Users & Roles

ToolPlanAccessSummary
tl_get_administrator_permissionsFreeRead-onlyGet the effective permissions of the API User this connector authenticates as.
tl_invite_userProDestructiveInvite a user to the ThreatLocker Portal with one or more roles.
tl_list_timezonesFreeRead-onlyList the timezones ThreatLocker recognizes, with their ids — the values tl_create_child_organization needs.
tl_search_user_rolesFreeRead-onlySearch the organization's user roles.

[ThreatLocker] Get the effective permissions of the API User this connector authenticates as. Run this first when another ThreatLocker tool returns 401 — ThreatLocker uses 401 for a MISSING PERMISSION (403 is the bad-credential case), so this read shows whether the API User's role is short and what to add in the Portal. Takes no inputs beyond the organization scope. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector.

[ThreatLocker] Invite a user to the ThreatLocker Portal with one or more roles. Requires the username (their email address) and rolesJson — a JSON array of {organizationId, userRoleId}, so one invitation can grant roles in several organizations. Resolve role GUIDs with tl_search_user_roles. The roles you grant decide what that person can see and change, so grant the least that fits. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector.
rolesJsonstringyesRequired. JSON array of role grants — each {organizationId, userRoleId} (role ids from tl_search_user_roles).
usernamestringyesRequired. The invitee's username (email address).

[ThreatLocker] List the timezones ThreatLocker recognizes, with their ids — the values tl_create_child_organization needs. ThreatLocker documents this read as requiring no specific permission beyond a valid token, so it is also the cheapest way to confirm the connector's credentials are alive. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector.

[ThreatLocker] Search the organization's user roles. Requires paging; optional searchText filters by name. The role GUIDs returned here are what tl_invite_user needs. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector.
pageNumberintegeryesRequired. 1-based page number.
pageSizeintegeryesRequired. Rows per page. Capped at 500 by StackJack (ThreatLocker documents no maximum).
searchTextstringnonullOptional. Free-text filter on the role name.

Lookups

ToolPlanAccessSummary
tl_list_agent_versionsFreeRead-onlyList the ThreatLocker agent versions available for deployment, as shown in the Portal's version dropdown.
tl_list_tag_optionsFreeRead-onlyList the tag dropdown options available in the managed organization.

[ThreatLocker] List the ThreatLocker agent versions available for deployment, as shown in the Portal's version dropdown. Use the returned version and version id with tl_update_computer_agent_version or tl_create_scheduled_agent_action. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector.

[ThreatLocker] List the tag dropdown options available in the managed organization. Tags name reusable network locations (domains, IPv4/IPv6 values) that policy and ringfencing rules reference. Returns raw ThreatLocker JSON.

ParamTypeRequiredDefaultDescription
includeBuiltInsbooleannonullOptional. Include ThreatLocker's built-in tags alongside the organization's own tags.
managedOrganizationIdstringnonullOptional ThreatLocker organization GUID for this call (the managedOrganizationId header). Omit to use the organization configured on the StackJack connector. Discover child organization ids with tl_search_child_organizations.