Skip to main content
Tools Reference

Cork Tools

Written By Christopher Scaminaci

Last updated 7 days ago

Cork Tools

cork_ · 30 tools · Free 24 · Pro 6 Cyber warranty and compliance monitoring for MSPs. The credential is an API key sent as a bearer against a fixed host. Cork keys expire on a timeframe the operator chooses and cannot be renewed programmatically, so a 401 on a connection that used to work usually means an expired key. A key also inherits the permissions of the user who created it rather than carrying its own scopes, so a 403 is that user's access gap - the distributor tools need a key created by a distributor user. Paging is page and page size, default 10 and maximum 100, apart from a handful of unpaginated reads. Only integrations created through the API can be updated, deleted or have their credentials read, and an update that supplies credentials must supply all of them. Integration raw data comes back as a ten-minute link to fetch rather than inline bytes.

All connector tools · Cork setup guide

Cork tool groups

Clients

ToolPlanAccessSummary
cork_list_client_devicesFreeRead-onlyList the devices Cork observed for one client across every connected integration.
cork_list_client_domainsFreeRead-onlyList the email domains Cork observed for one client.
cork_list_client_inboxesFreeRead-onlyList the email inboxes (user mailboxes and shared mailboxes) Cork observed for one client.
cork_list_clientsFreeRead-onlyList the MSP's clients (end customers) — the ENTRY POINT for this connector.

[Cork] List the devices Cork observed for one client across every connected integration. Each item carries uuid, name, created_at, can_install_software and associated_endpoints — each endpoint being {name, integration, integration_identifier, last_seen, ip_addresses:{internal[], external[]}, properties[]} where a property is {type, values} and type is HOSTNAME | IP_ADDRESS | MAC_ADDRESS | SERIAL. can_install_software is true only when the device has at least one RMM endpoint whose vendor + OS combination Cork's installer executors support, and it must be true before the device can be passed to cork_install_software. The returned uuid is the deviceUuid filter for cork_list_compliance_events and cork_list_software_vulnerabilities. Requires a client UUID from cork_list_clients. Paginated envelope {items:[...], pagination:{page, page_size, total_items, total_pages}}.

ParamTypeRequiredDefaultDescription
clientUuidstringyesThe client's UUID, from cork_list_clients.
pageintegerno1Page number, 1-based (default 1).
pageSizeintegerno10Results per page (1-100, default 10). Cork's maximum page size is 100; larger values are clamped.

[Cork] List the email domains Cork observed for one client. Each item carries uuid, domain and created_at. The returned uuid is the domainUuid filter for cork_list_compliance_events and cork_list_compliance_notification_settings. Requires a client UUID from cork_list_clients. Paginated envelope {items:[...], pagination:{page, page_size, total_items, total_pages}}.

ParamTypeRequiredDefaultDescription
clientUuidstringyesThe client's UUID, from cork_list_clients.
pageintegerno1Page number, 1-based (default 1).
pageSizeintegerno10Results per page (1-100, default 10). Cork's maximum page size is 100; larger values are clamped.

[Cork] List the email inboxes (user mailboxes and shared mailboxes) Cork observed for one client. Each item carries uuid, name, email, created_at, inbox_type (unknown | user | shared | group), associated_domains (a string array) and associated_users (each {name, email, integration} — the integration that sourced the inbox). The returned uuid is the inboxUuid filter for cork_list_compliance_events and cork_list_compliance_notification_settings. Requires a client UUID from cork_list_clients. Paginated envelope {items:[...], pagination:{page, page_size, total_items, total_pages}}.

ParamTypeRequiredDefaultDescription
clientUuidstringyesThe client's UUID, from cork_list_clients.
pageintegerno1Page number, 1-based (default 1).
pageSizeintegerno10Results per page (1-100, default 10). Cork's maximum page size is 100; larger values are clamped.

[Cork] List the MSP's clients (end customers) — the ENTRY POINT for this connector. Each item carries uuid, name, hidden, created_at, warranty_status (active | unwarranted), score_history (an array of {score, created_at} Cork Cyber Scores, score maximum 1000) and associated_tenants (each {uuid, name, integration}). The returned uuid is the client UUID required by cork_list_client_devices, cork_list_client_domains, cork_list_client_inboxes, cork_list_compliance_events and cork_list_compliance_notification_settings, and is also the clientUuid filter on cork_list_software_vulnerabilities / cork_get_software_vulnerability_summary. Hidden/archived clients are EXCLUDED unless showHidden=true. Paginated envelope {items:[...], pagination:{page, page_size, total_items, total_pages}}. partnerUuid scoping is DISTRIBUTOR-ONLY — Cork API keys inherit the permissions of the user who created them, so a partner-level key 403s on it; get partner UUIDs from cork_list_partners.

ParamTypeRequiredDefaultDescription
pageintegerno1Page number, 1-based (default 1).
pageSizeintegerno10Results per page (1-100, default 10). Cork's maximum page size is 100; larger values are clamped.
partnerUuidstringnonullScope results to one partner (MSP) by UUID, from cork_list_partners. DISTRIBUTOR keys only — a partner-level key 403s. Omit for the key's own scope.
showHiddenbooleannonullSet true to include hidden/archived clients. Omit or false to exclude them (Cork's default).

Compliance

ToolPlanAccessSummary
cork_list_compliance_event_typesFreeRead-onlyList every compliance event type Cork can raise.
cork_list_compliance_eventsFreeRead-onlyList the policy violations and risk events Cork detected for one client's assets — the compliance failures that can affect cyber-warranty coverage.
cork_list_compliance_notification_settingsFreeRead-onlyList the notification and alerting rules configured for compliance events on one client's assets — which event types alert and how they are routed.

[Cork] List every compliance event type Cork can raise. Each entry carries event_type, description, cure_period_hours (how long the MSP has to remediate before coverage is affected; null when the type has no cure period) and provisional. Takes NO parameters and is UNPAGINATED — the response is a TOP-LEVEL JSON ARRAY, not the {items, pagination} envelope the paginated Cork reads return. This is the discovery call for valid eventType values on cork_list_compliance_events, so call it first rather than guessing an event type string.

[Cork] List the policy violations and risk events Cork detected for one client's assets — the compliance failures that can affect cyber-warranty coverage. Each item carries uuid, client_uuid, event_type, device_uuid, inbox_uuid, domain_uuid, at_risk, at_risk_at, resolved_at, silenced, created_at and evidence (each {reason, metadata}). TWO DOCUMENTED INTERLOCKS: (1) resolved events are EXCLUDED by default — pass showResolved=true to include them; (2) resolvedAfter / resolvedBefore REQUIRE showResolved=true. Silenced/suppressed events are likewise excluded unless showSilenced=true, and atRisk=true narrows to currently active (unresolved, unsuppressed) risks only. Discover valid eventType values with cork_list_compliance_event_types; the client UUID comes from cork_list_clients and the device / inbox / domain UUIDs from cork_list_client_devices, cork_list_client_inboxes and cork_list_client_domains. Paginated envelope {items:[...], pagination:{page, page_size, total_items, total_pages}}.

ParamTypeRequiredDefaultDescription
atRiskbooleannonullSet true to return ONLY currently active (unresolved, unsuppressed) risk events. Omit for all matching events.
clientUuidstringyesThe client's UUID, from cork_list_clients.
createdAfterstringnonullOnly events created at or after this RFC3339 / ISO-8601 date-time. Omit for no lower bound.
createdBeforestringnonullOnly events created at or before this RFC3339 / ISO-8601 date-time. Omit for no upper bound.
deviceUuidstringnonullFilter to events on one device, by UUID from cork_list_client_devices. Omit for all devices.
domainUuidstringnonullFilter to events on one email domain, by UUID from cork_list_client_domains. Omit for all domains.
eventTypestringnonullFilter to one compliance event type. Use cork_list_compliance_event_types to discover valid values. Omit for all types.
inboxUuidstringnonullFilter to events on one inbox, by UUID from cork_list_client_inboxes. Omit for all inboxes.
pageintegerno1Page number, 1-based (default 1).
pageSizeintegerno10Results per page (1-100, default 10). Cork's maximum page size is 100; larger values are clamped.
resolvedAfterstringnonullOnly events resolved at or after this RFC3339 / ISO-8601 date-time. REQUIRES showResolved=true. Omit for no lower bound.
resolvedBeforestringnonullOnly events resolved at or before this RFC3339 / ISO-8601 date-time. REQUIRES showResolved=true. Omit for no upper bound.
showResolvedbooleannonullSet true to include resolved events. Omit or false to exclude them (Cork's default). MUST be true to use resolvedAfter or resolvedBefore.
showSilencedbooleannonullSet true to include silenced/suppressed events. Omit or false to exclude them (Cork's default).

[Cork] List the notification and alerting rules configured for compliance events on one client's assets — which event types alert and how they are routed. Each item carries event_description, device_uuid, inbox_uuid, domain_uuid, configured_by, reason, notes, excluded_from_coverage, needs_review, review_on, review_duration_days and created_at. excluded_from_coverage flags an asset deliberately carved out of warranty coverage; needs_review together with review_on / review_duration_days shows when a temporary exclusion is due for re-review. Requires a client UUID from cork_list_clients; the optional device / inbox / domain UUID filters come from cork_list_client_devices, cork_list_client_inboxes and cork_list_client_domains. Paginated envelope {items:[...], pagination:{page, page_size, total_items, total_pages}}.

ParamTypeRequiredDefaultDescription
clientUuidstringyesThe client's UUID, from cork_list_clients.
deviceUuidstringnonullFilter to settings for one device, by UUID from cork_list_client_devices. Omit for all devices.
domainUuidstringnonullFilter to settings for one email domain, by UUID from cork_list_client_domains. Omit for all domains.
inboxUuidstringnonullFilter to settings for one inbox, by UUID from cork_list_client_inboxes. Omit for all inboxes.
pageintegerno1Page number, 1-based (default 1).
pageSizeintegerno10Results per page (1-100, default 10). Cork's maximum page size is 100; larger values are clamped.

Vulnerabilities

ToolPlanAccessSummary
cork_get_software_vulnerability_summaryFreeRead-onlyGet CVEs rolled up by software product — the triage view.
cork_list_software_vulnerabilitiesFreeRead-onlyList individual software vulnerabilities with full CVE detail.

[Cork] Get CVEs rolled up by software product — the triage view. Each item carries sw_vendor, sw_product, num_impacted_devices (devices running a vulnerable version), num_impacted_versions (distinct vulnerable versions seen) and highest_priority (critical | accelerated | routine | unclassified). Use clientUuid (from cork_list_clients) to scope to a single client, then follow up with cork_list_software_vulnerabilities filtered by swVendor to drill into the individual CVEs. On THIS endpoint sortBy additionally accepts num_impacted_devices and num_impacted_versions on top of sw_vendor and sw_product — the detail list accepts only the latter two, so do not cross-wire them; sortDirection is asc or desc. This endpoint has NO CVSS / EPSS / priority / device filters — use cork_list_software_vulnerabilities for those. partnerUuid is DISTRIBUTOR-ONLY — Cork API keys inherit the permissions of the user who created them, so a partner-level key 403s on it; partner UUIDs come from cork_list_partners. Paginated envelope {items:[...], pagination:{page, page_size, total_items, total_pages}}.

ParamTypeRequiredDefaultDescription
clientUuidstringnonullScope to one client by UUID, from cork_list_clients. Omit for all clients the key can see.
pageintegerno1Page number, 1-based (default 1).
pageSizeintegerno10Results per page (1-100, default 10). Cork's maximum page size is 100; larger values are clamped.
partnerUuidstringnonullScope to one partner (MSP) by UUID, from cork_list_partners. DISTRIBUTOR keys only — a partner-level key 403s. Omit for the key's own scope.
sortBystringnonullSort field. On this endpoint the accepted values are sw_vendor, sw_product, num_impacted_devices and num_impacted_versions. Omit for Cork's default ordering.
sortDirectionstringnonullSort direction: asc or desc. Omit for Cork's default ordering.
swVendorstringnonullFilter by software vendor. Omit for all vendors.

[Cork] List individual software vulnerabilities with full CVE detail. Each item carries client_uuid, device_uuid, sw_vendor, sw_product and cves[] of {cve_id, cvss, epss, impacted_version, is_kev, priority}. Narrow to the highest-risk findings with onlyKnownExploited=true (is_kev — known exploited in the wild), minimumCvssScore (0-10), minimumEpssScore (0-1) or minimumPriority (critical | accelerated | routine). Scope with clientUuid (from cork_list_clients) or deviceUuid (from cork_list_client_devices). On THIS endpoint sortBy accepts sw_vendor or sw_product ONLY — the roll-up cork_get_software_vulnerability_summary accepts two more values, so do not cross-wire them; sortDirection is asc or desc. partnerUuid is DISTRIBUTOR-ONLY — Cork API keys inherit the permissions of the user who created them, so a partner-level key 403s on it; partner UUIDs come from cork_list_partners. Paginated envelope {items:[...], pagination:{page, page_size, total_items, total_pages}}. For triage, start with cork_get_software_vulnerability_summary to find the worst products, then drill in here filtered by swVendor.

ParamTypeRequiredDefaultDescription
clientUuidstringnonullScope to one client by UUID, from cork_list_clients. Omit for all clients the key can see.
deviceUuidstringnonullScope to one device by UUID, from cork_list_client_devices. Omit for all devices.
minimumCvssScorenumbernonullMinimum CVSS score, 0-10 (Cork's default is 0 = no floor). Omit for no floor.
minimumEpssScorenumbernonullMinimum EPSS (exploit-prediction) score, 0-1 (Cork's default is 0 = no floor). Omit for no floor.
minimumPrioritystringnonullMinimum Cork priority: critical, accelerated, or routine. Omit for all priorities.
onlyKnownExploitedbooleannonullSet true to return only known-exploited vulnerabilities (is_kev). Omit for all vulnerabilities.
pageintegerno1Page number, 1-based (default 1).
pageSizeintegerno10Results per page (1-100, default 10). Cork's maximum page size is 100; larger values are clamped.
partnerUuidstringnonullScope to one partner (MSP) by UUID, from cork_list_partners. DISTRIBUTOR keys only — a partner-level key 403s. Omit for the key's own scope.
sortBystringnonullSort field. On this endpoint the ONLY accepted values are sw_vendor and sw_product. Omit for Cork's default ordering.
sortDirectionstringnonullSort direction: asc or desc. Omit for Cork's default ordering.
swVendorstringnonullFilter by software vendor (the sw_vendor value from cork_get_software_vulnerability_summary). Omit for all vendors.

Distributor

ToolPlanAccessSummary
cork_list_partnersFreeRead-onlyList the partner (MSP) sub-accounts managed by this distributor.
cork_provision_partnerProDestructiveDESTRUCTIVE / IRREVERSIBLE: provision a brand-new partner (MSP) account under this distributor.

[Cork] List the partner (MSP) sub-accounts managed by this distributor. Each partner carries uuid, name and created_at. This is the DISCOVERY TOOL for partner UUIDs: the uuid returned here is the partnerUuid filter accepted by cork_list_clients, cork_list_connected_integrations, cork_list_invoices, cork_list_installer_history, cork_list_warranties and the vulnerability reads. DISTRIBUTOR KEYS ONLY — a partner-level API key returns 403, as do all partnerUuid filters (a Cork key inherits the permissions of the user who created it, so the creating user must be a distributor user). Paginated (page from 1; pageSize default 10, max 100 — StackJack clamps out-of-range values).

ParamTypeRequiredDefaultDescription
pageintegerno1Page number, starting at 1 (default 1).
pageSizeintegerno10Results per page (default 10, maximum 100).

[Cork] DESTRUCTIVE / IRREVERSIBLE: provision a brand-new partner (MSP) account under this distributor. The Cork API exposes NO delete-partner endpoint, so a partner created here cannot be removed through the API — confirm the details before calling. By default it also SENDS A WELCOME EMAIL TO A REAL PERSON at primaryContactEmail (pass sendWelcomeEmail=false to suppress it). DISTRIBUTOR KEYS ONLY — a partner-level key returns 403. Returns 200 with the new partner ({uuid, name, created_at}); the uuid is immediately usable as the partnerUuid filter on cork_list_clients, cork_list_invoices and friends. A partner that already exists returns 409 Conflict — check cork_list_partners first.

ParamTypeRequiredDefaultDescription
enableDefaultNotificationsbooleannonullOptional. Whether to enable Cork's default notifications for the new partner. Cork defaults this to TRUE when omitted; pass false to start with notifications off.
partnerNamestringyesRequired. Name of the new partner (MSP) account.
primaryContactEmailstringyesRequired. Email address of the partner's primary contact. A welcome email is sent here unless sendWelcomeEmail is false.
primaryContactNamestringyesRequired. Full name of the partner's primary contact.
sendWelcomeEmailbooleannonullOptional. Whether to send a welcome email to the primary contact. Cork defaults this to TRUE when omitted — pass false to provision silently and avoid emailing a real person.

Integrations

ToolPlanAccessSummary
cork_connect_integrationProWriteConnect a new API-based integration, which begins syncing data immediately.
cork_delete_integrationProDestructiveDESTRUCTIVE: delete an integration and stop ALL data collection from it.
cork_get_integration_credentialsFreeRead-onlyGet one integration's stored credentials.
cork_get_integration_raw_dataFreeRead-onlyGet a presigned download URL for one integration's RAW synced data.
cork_list_available_integrationsFreeRead-onlyList the integration types that CAN be connected to Cork, each with its vendor block ({key, name, type}) and its credential_fields schema.
cork_list_connected_integrationsFreeRead-onlyList the integrations already connected to Cork.
cork_list_integration_devicesFreeRead-onlyList the devices observed from ONE integration (the vendor's own view, before Cork maps them onto clients — use cork_list_client_devices for the client-side view).
cork_list_integration_tenantsFreeRead-onlyList the customer tenants observed from ONE integration — the upstream vendor's own tenant/organisation records (e.g. an RMM's client list), which Cork maps onto its own clients.
cork_list_integration_usersFreeRead-onlyList the users observed from ONE integration (e.g. the identity/MFA/M365 accounts the vendor reports).
cork_resync_integrationProWriteManually trigger a data refresh for ONE integration — useful when last_synced_at from cork_list_connected_integrations is stale or connection_status has recovered from degraded/down.
cork_update_integrationProDestructiveUpdate an API-created integration's display name and/or credentials.

[Cork] Connect a new API-based integration, which begins syncing data immediately. Provide a JSON object body. Required: vendor_key (string — from a vendor.key in cork_list_available_integrations) and credential_fields (object — its shape is PER-VENDOR: read that same discovery call's credential_fields schema and use each entry's payload_key as the key here, supplying every field marked required). Optional: display_name (string), partner_uuid (UUID — DISTRIBUTOR KEYS ONLY, from cork_list_partners). Returns 201 with the new integration ({uuid, display_name, vendor, connection_status, installer, partner_uuid, created_at, last_synced_at}); keep the uuid — it is what the other integration tools take. Additive and reversible: the result can be removed later with cork_delete_integration.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body. Required: vendor_key (string — a vendor.key from cork_list_available_integrations), credential_fields (object keyed by each credential field's payload_key from that same call — supply every field marked required). Optional: display_name (string), partner_uuid (UUID, distributor keys only, from cork_list_partners).

[Cork] DESTRUCTIVE: delete an integration and stop ALL data collection from it. Provide integrationUuid from cork_list_connected_integrations. RESTRICTION: only integrations CREATED VIA THE API can be deleted; an integration wired up in the Cork UI returns 403. Cork replies 202 Accepted with no body, which StackJack surfaces as — the removal is asynchronous, so re-read cork_list_connected_integrations to confirm (connection_status transitions through deleting). Losing an integration removes the data feed behind Cork Cyber Scores, compliance events and installer routing for its clients; there is no undo other than re-connecting it with cork_connect_integration and re-entering the credentials.

ParamTypeRequiredDefaultDescription
integrationUuidstringyesUUID of the integration to delete (from cork_list_connected_integrations). Must be an API-created integration, or Cork returns 403.

[Cork] Get one integration's stored credentials. SENSITIVE: the credentials are returned IN PLAINTEXT, as {uuid, credentials:{<payload_key>: <value>, ...}} — the payload_key names come from that vendor's credential_fields schema in cork_list_available_integrations. RESTRICTION: only integrations CREATED VIA THE API expose their credentials; an integration wired up in the Cork UI returns 403. Provide integrationUuid from cork_list_connected_integrations. Unpaginated. Use this to read the current field set before cork_update_integration, which requires ALL credential fields to be supplied together.

ParamTypeRequiredDefaultDescription
integrationUuidstringyesUUID of the integration whose credentials to read (from cork_list_connected_integrations). Must be an API-created integration, or Cork returns 403.

[Cork] Get a presigned download URL for one integration's RAW synced data. This does NOT return the data inline: the response is JSON {download_url, expires_in, uuid}, where expires_in is seconds and the URL expires after 10 MINUTES — the caller must fetch download_url itself, promptly. TWO RESTRICTIONS: it requires DISTRIBUTOR PRIVILEGES (a partner-level key returns 403), and only integrations CREATED VIA THE API are eligible (a UI-created integration also returns 403). Provide integrationUuid from cork_list_connected_integrations. Unpaginated. Treat the dump as sensitive — it is the full unfiltered vendor payload.

ParamTypeRequiredDefaultDescription
integrationUuidstringyesUUID of the integration whose raw synced data to download (from cork_list_connected_integrations). Must be an API-created integration, and the API key must belong to a distributor user.

[Cork] List the integration types that CAN be connected to Cork, each with its vendor block ({key, name, type}) and its credential_fields schema. Read this FIRST before cork_connect_integration: every credential field carries name, payload_key, field_type, required, is_secret, dropdown_values and description — and payload_key is the exact key you place inside the connect call's credential_fields object. vendor.key is also the vendorKey that cork_get_installer_setup takes. Optionally filter by vendorType (e.g. rmm, edr, mfa). Paginated (page from 1; pageSize default 10, max 100 — StackJack clamps out-of-range values).

ParamTypeRequiredDefaultDescription
pageintegerno1Page number, starting at 1 (default 1).
pageSizeintegerno10Results per page (default 10, maximum 100).
vendorTypestringnonullOptional vendor-type filter, e.g. "rmm", "edr", "mfa". Omit to list every available integration type.

[Cork] List the integrations already connected to Cork. This is the DISCOVERY TOOL for integration UUIDs — the uuid returned here is the integrationUuid taken by cork_list_integration_devices/tenants/users, cork_get_integration_credentials, cork_get_integration_raw_data, cork_update_integration, cork_delete_integration and cork_resync_integration. Each item carries uuid, display_name, vendor ({key, name, type}), partner_uuid, created_at, last_synced_at, connection_status (ok|degraded|down|queued|fetching|deleting) and an installer block ({capable, authorized, requires_manual_setup, configured_package_managers}) that says whether software installs can route through this RMM. partnerUuid filters to one partner and is DISTRIBUTOR-KEY ONLY (a partner-level key 403s); get partner UUIDs from cork_list_partners. Paginated (page from 1; pageSize default 10, max 100).

ParamTypeRequiredDefaultDescription
pageintegerno1Page number, starting at 1 (default 1).
pageSizeintegerno10Results per page (default 10, maximum 100).
partnerUuidstringnonullOptional partner UUID to scope results to one partner (from cork_list_partners). DISTRIBUTOR KEYS ONLY — a partner-level key is rejected with 403.

[Cork] List the devices observed from ONE integration (the vendor's own view, before Cork maps them onto clients — use cork_list_client_devices for the client-side view). Provide integrationUuid from cork_list_connected_integrations. Each device carries uuid, name, operating_system, integration_identifier, integration_last_seen, tenant_uuid and a properties array. Optionally narrow to one upstream tenant with tenantUuid (from cork_list_integration_tenants). Paginated (page from 1; pageSize default 10, max 100).

ParamTypeRequiredDefaultDescription
integrationUuidstringyesUUID of the integration whose devices to list (from cork_list_connected_integrations).
pageintegerno1Page number, starting at 1 (default 1).
pageSizeintegerno10Results per page (default 10, maximum 100).
tenantUuidstringnonullOptional upstream tenant UUID to narrow the results to one of the integration's customer tenants (from cork_list_integration_tenants).

[Cork] List the customer tenants observed from ONE integration — the upstream vendor's own tenant/organisation records (e.g. an RMM's client list), which Cork maps onto its own clients. Provide integrationUuid from cork_list_connected_integrations. Each tenant carries uuid, name, integration_identifier, integration_last_seen and created_at; the uuid is the tenantUuid filter accepted by cork_list_integration_devices and cork_list_integration_users. Paginated (page from 1; pageSize default 10, max 100).

ParamTypeRequiredDefaultDescription
integrationUuidstringyesUUID of the integration whose customer tenants to list (from cork_list_connected_integrations).
pageintegerno1Page number, starting at 1 (default 1).
pageSizeintegerno10Results per page (default 10, maximum 100).
tenantUuidstringnonullOptional upstream tenant UUID to fetch a single tenant instead of the whole list.

[Cork] List the users observed from ONE integration (e.g. the identity/MFA/M365 accounts the vendor reports). Provide integrationUuid from cork_list_connected_integrations. Each user carries uuid, name, email, tenant_uuid and created_at. Optionally narrow to one upstream tenant with tenantUuid (from cork_list_integration_tenants). Paginated (page from 1; pageSize default 10, max 100).

ParamTypeRequiredDefaultDescription
integrationUuidstringyesUUID of the integration whose users to list (from cork_list_connected_integrations).
pageintegerno1Page number, starting at 1 (default 1).
pageSizeintegerno10Results per page (default 10, maximum 100).
tenantUuidstringnonullOptional upstream tenant UUID to narrow the results to one of the integration's customer tenants (from cork_list_integration_tenants).

[Cork] Manually trigger a data refresh for ONE integration — useful when last_synced_at from cork_list_connected_integrations is stale or connection_status has recovered from degraded/down. Provide integrationUuid from cork_list_connected_integrations. Takes no request body. Cork replies 202 Accepted with no body, which StackJack surfaces as ; the resync runs asynchronously, so poll cork_list_connected_integrations for last_synced_at / connection_status. VENDOR-THROTTLED: calling it too often returns 429 Too Many Requests — back off rather than retrying immediately. Only refreshes data Cork already owns; it changes nothing upstream.

ParamTypeRequiredDefaultDescription
integrationUuidstringyesUUID of the integration to resync (from cork_list_connected_integrations).

[Cork] Update an API-created integration's display name and/or credentials. Provide integrationUuid (from cork_list_connected_integrations) plus a JSON object body with the optional fields display_name (string) and credential_fields (object). Do NOT put integration_uuid in the body — StackJack fills it in from the integrationUuid argument, and a body carrying a DIFFERENT UUID is rejected locally before the request is sent. DESTRUCTIVE, in place: when credential_fields is supplied, ALL of that vendor's credential fields must be supplied — a partial object REPLACES the whole set and breaks the live integration (read the current set with cork_get_integration_credentials, and the required keys with cork_list_available_integrations). RESTRICTION: only integrations CREATED VIA THE API can be updated; a UI-created integration returns 403. Returns 200 with the updated integration.

ParamTypeRequiredDefaultDescription
fieldsJsonstringyesJSON object body. Optional: display_name (string), credential_fields (object keyed by payload_key — supply EVERY field for that vendor; a partial object replaces the whole set). Do NOT include integration_uuid: it is filled in from the integrationUuid argument, and a conflicting value is rejected before the request is sent.
integrationUuidstringyesUUID of the integration to update (from cork_list_connected_integrations). Must be an API-created integration, or Cork returns 403.

Invoices

ToolPlanAccessSummary
cork_list_invoice_line_itemsFreeRead-onlyList the billed, TOP-LEVEL line items for one invoice.
cork_list_invoicesFreeRead-onlyList Cork billing invoices.

[Cork] List the billed, TOP-LEVEL line items for one invoice. Provide invoiceUuid from cork_list_invoices. Each item carries name, item_type, client_name, client_uuid, quantity, unit_price, total_billed, prorated, billing_start_date, notes and children. Three semantics that change how you read the numbers: (1) only items with a NONZERO total_billed are returned, so a line you expect may legitimately be absent; (2) discount line items ARE included and carry a NEGATIVE total_billed; (3) sub-items billed as part of a parent (e.g. individual licences inside a bundle) are nested under that parent's children array and ALWAYS carry total_billed: 0, because their amount is already rolled into the parent — sum only the top-level total_billed values, never the children, or you will double-count. Paginated (page from 1; pageSize default 10, max 100).

ParamTypeRequiredDefaultDescription
invoiceUuidstringyesUUID of the invoice whose line items to list (from cork_list_invoices).
pageintegerno1Page number, starting at 1 (default 1).
pageSizeintegerno10Results per page (default 10, maximum 100).

[Cork] List Cork billing invoices. Each invoice carries uuid, billing_period_start, created_at, currency, payment_status and total_billed. This is the DISCOVERY TOOL for invoice UUIDs: pass a returned uuid as invoiceUuid to cork_list_invoice_line_items for the per-item breakdown. partnerUuid scopes results to a single partner and is DISTRIBUTOR-KEY ONLY (a partner-level key 403s); get partner UUIDs from cork_list_partners. Paginated (page from 1; pageSize default 10, max 100 — StackJack clamps out-of-range values).

ParamTypeRequiredDefaultDescription
pageintegerno1Page number, starting at 1 (default 1).
pageSizeintegerno10Results per page (default 10, maximum 100).
partnerUuidstringnonullOptional partner UUID to scope the invoices to one partner (from cork_list_partners). DISTRIBUTOR KEYS ONLY — a partner-level key is rejected with 403.

Account

ToolPlanAccessSummary
cork_who_am_iFreeRead-onlyReturn information on the Cork user the API key authenticates as — the response carries name.

[Cork] Return information on the Cork user the API key authenticates as — the response carries name. Takes NO parameters and is unpaginated. This is the cheapest "is my API key alive?" check and the same probe StackJack's Test Connection uses: a 200 means the key is valid, while a 401 means it is wrong, revoked, or EXPIRED. Cork API keys expire on a timeframe the operator picks when minting them and there is no programmatic renewal, so an expired key is the most likely cause of a 401 on a connector that used to work — mint a new key in Cork and re-enter it in StackJack. This endpoint needs no role or scope, so it behaves identically for partner-level and distributor-level keys and is the right first call when diagnosing whether a failure is auth or permissions.

Software Installer

ToolPlanAccessSummary
cork_get_installer_setupFreeRead-onlyGet the ONE-TIME setup steps for an RMM vendor that needs manual setup before Cork software installs work through it.
cork_install_softwareProDestructiveDESTRUCTIVE: install a software package on a SINGLE mapped device by dispatching the job through that device's RMM integration (Intune, NinjaRMM, Datto RMM).
cork_list_installer_historyFreeRead-onlyList past software-install attempts, MOST RECENT FIRST — this is how you follow up an asynchronous cork_install_software call, which returns 202 with no body.
cork_list_software_packagesFreeRead-onlyList the software packages available to install across the supported package managers (WinGet and Chocolatey).

[Cork] Get the ONE-TIME setup steps for an RMM vendor that needs manual setup before Cork software installs work through it. BOTH parameters are REQUIRED (Cork's only two required query params in this connector). Use it when a connected integration from cork_list_connected_integrations reports installer.requires_manual_setup = true AND the package manager you want is missing from installer.configured_package_managers, or when cork_install_software / cork_list_installer_history reports setup_required or not_authorized. Vendors that auto-provision their script (e.g. Intune) report requires_manual_setup = false and need no setup at all. Returns {vendor_display_name, script_name (the EXACT name to give the script/component in the RMM, e.g. "Cork - WinGet"), script_content (the script body to paste), script_language, required_settings[] ({label, value} settings to match in the RMM UI), parameters[] ({name, description, required, default} variables to declare so Cork can set them per install), parameter_storage_label (the vendor's own term for script inputs, e.g. "Script Variable"), setup_guide_url}. Unpaginated. Read-only — it returns instructions and changes nothing; the MSP performs the setup inside the RMM.

ParamTypeRequiredDefaultDescription
packageManagerKeystringyesREQUIRED. Package manager the setup is for. Allowed values: WINGET, CHOC.
vendorKeystringyesREQUIRED. RMM vendor key to set up, e.g. NINJA_RMM or DATTO_RMM. Take it from a connected integration's vendor.key in cork_list_connected_integrations where installer.requires_manual_setup is true.

[Cork] DESTRUCTIVE: install a software package on a SINGLE mapped device by dispatching the job through that device's RMM integration (Intune, NinjaRMM, Datto RMM). This changes state on a customer's real endpoint and cannot be undone through this API. PRECONDITION: the target device must report can_install_software = true in cork_list_client_devices — take mappedDeviceUuid from there. Get packageId and the matching packageManagerKey from cork_list_software_packages. ASYNCHRONOUS: Cork replies 202 Accepted with no body (StackJack surfaces ), so there is no result to read here — poll cork_list_installer_history, where state is queued|running|success|partial|error|unknown and 'success' means THE RMM ACCEPTED THE JOB, not that the on-device install finished. If the attempt comes back setup_required or not_authorized (as errors[].code in the history), the routing RMM integration needs its one-time setup — call cork_get_installer_setup for the vendor and package manager. A 422 means Cork could not route the install for the device/package combination you gave.

ParamTypeRequiredDefaultDescription
interpreterKeystringyesREQUIRED. Interpreter to run the install with. The ONLY valid value is PS (PowerShell).
mappedDeviceUuidstringyesREQUIRED. UUID of the mapped device to install on (from cork_list_client_devices). That device's can_install_software field MUST be true.
packageIdstringyesREQUIRED. Package identifier within the package manager (the package_id field from cork_list_software_packages).
packageManagerKeystringyesREQUIRED. Package manager to install through. Allowed values: WINGET, CHOC. Must match the chosen package's package_manager_key from cork_list_software_packages.
runAsstringnonullOptional. Execution context for the install. Allowed values: user, system. Omit for the vendor default.
scopestringnonullOptional. Install scope — WinGet-specific. Allowed values: user, machine. Omit for the vendor default.
versionstringnonullOptional. Specific version to install (one of the package's versions from cork_list_software_packages). Omit to let the package manager pick its default version.

[Cork] List past software-install attempts, MOST RECENT FIRST — this is how you follow up an asynchronous cork_install_software call, which returns 202 with no body. Every dispatched install appears here with state (queued|running|success|partial|error|unknown), requested_at, completed_at, software_name, software_publisher, package_manager_key, client_name/client_uuid, device_name/device_uuid, device_count, queued_count, queue_failure_count and an errors array of {code, integration_uuid, vendor_key}. IMPORTANT: Cork tracks RMM DISPATCH, not on-device completion, so state: success means the RMM ACCEPTED THE JOB — not that the software finished installing. An errors[].code of setup_required or not_authorized means the routing RMM integration needs cork_get_installer_setup. Filter with clientUuid (from cork_list_clients) or deviceUuid (from cork_list_client_devices). partnerUuid is DISTRIBUTOR-KEY ONLY (from cork_list_partners) and is required IN ADDITION when a distributor is scoping to a child partner's client or device — clientUuid/deviceUuid alone stay scoped to your own partner's installs. Paginated (page from 1; pageSize default 10, max 100).

ParamTypeRequiredDefaultDescription
clientUuidstringnonullOptional client UUID to scope to installs targeting one client (from cork_list_clients).
deviceUuidstringnonullOptional mapped-device UUID to scope to installs targeting one device (from cork_list_client_devices).
pageintegerno1Page number, starting at 1 (default 1).
pageSizeintegerno10Results per page (default 10, maximum 100).
partnerUuidstringnonullOptional partner UUID (from cork_list_partners). DISTRIBUTOR KEYS ONLY — a partner-level key is rejected with 403. A distributor scoping to a CHILD partner's client or device must set this as well; clientUuid/deviceUuid alone stay scoped to your own partner's installs.

[Cork] List the software packages available to install across the supported package managers (WinGet and Chocolatey). Each package carries name, publisher, package_manager_key, package_id and versions. This is the DISCOVERY TOOL for cork_install_software: pass a returned package_id as packageId and the matching package_manager_key as packageManagerKey. Filter with packageManagerKey (WINGET or CHOC) to scope to one manager, and/or search for a CASE-INSENSITIVE SUBSTRING match against both the package name AND the publisher. Paginated (page from 1; pageSize default 10, max 100 — StackJack clamps out-of-range values).

ParamTypeRequiredDefaultDescription
packageManagerKeystringnonullOptional package-manager filter. Allowed values: WINGET, CHOC. Omit to list packages from every supported manager.
pageintegerno1Page number, starting at 1 (default 1).
pageSizeintegerno10Results per page (default 10, maximum 100).
searchstringnonullOptional case-insensitive substring match against the package name AND publisher, e.g. "7zip" or "Mozilla".

Warranties

ToolPlanAccessSummary
cork_list_warrantiesFreeRead-onlyList ACTIVE cyber-warranty packages.

[Cork] List ACTIVE cyber-warranty packages. Each item carries uuid, client_uuid, client_name, package, start_date and active. Only active warranties are returned, so an empty or short page does NOT by itself identify which clients are uncovered — to find uncovered clients read warranty_status from cork_list_clients, where 'unwarranted' means no active warranty and 'active' means covered. Use client_uuid here to join a warranty back to its client record. partnerUuid is DISTRIBUTOR-ONLY — Cork API keys inherit the permissions of the user who created them, so a partner-level key 403s on it; partner UUIDs come from cork_list_partners. Paginated envelope {items:[...], pagination:{page, page_size, total_items, total_pages}}.

ParamTypeRequiredDefaultDescription
pageintegerno1Page number, 1-based (default 1).
pageSizeintegerno10Results per page (1-100, default 10). Cork's maximum page size is 100; larger values are clamped.
partnerUuidstringnonullScope results to one partner (MSP) by UUID, from cork_list_partners. DISTRIBUTOR keys only — a partner-level key 403s. Omit for the key's own scope.