Cork Tools
Written By Christopher Scaminaci
Last updated 7 days ago
Cork Tools
cork_ · 30 tools · Free 24 · Pro 6
Cyber warranty and compliance monitoring for MSPs. The credential is an API key sent as a bearer against a fixed host. Cork keys expire on a timeframe the operator chooses and cannot be renewed programmatically, so a 401 on a connection that used to work usually means an expired key. A key also inherits the permissions of the user who created it rather than carrying its own scopes, so a 403 is that user's access gap - the distributor tools need a key created by a distributor user. Paging is page and page size, default 10 and maximum 100, apart from a handful of unpaginated reads. Only integrations created through the API can be updated, deleted or have their credentials read, and an update that supplies credentials must supply all of them. Integration raw data comes back as a ten-minute link to fetch rather than inline bytes.
All connector tools · Cork setup guide
Cork tool groups
- Clients — 4 tools
- Compliance — 3 tools
- Vulnerabilities — 2 tools
- Distributor — 2 tools
- Integrations — 11 tools
- Invoices — 2 tools
- Account — 1 tool
- Software Installer — 4 tools
- Warranties — 1 tool
Clients
cork_list_client_devices details
cork_list_client_devices details
[Cork] List the devices Cork observed for one client across every connected integration. Each item carries uuid, name, created_at, can_install_software and associated_endpoints — each endpoint being {name, integration, integration_identifier, last_seen, ip_addresses:{internal[], external[]}, properties[]} where a property is {type, values} and type is HOSTNAME | IP_ADDRESS | MAC_ADDRESS | SERIAL. can_install_software is true only when the device has at least one RMM endpoint whose vendor + OS combination Cork's installer executors support, and it must be true before the device can be passed to cork_install_software. The returned uuid is the deviceUuid filter for cork_list_compliance_events and cork_list_software_vulnerabilities. Requires a client UUID from cork_list_clients. Paginated envelope {items:[...], pagination:{page, page_size, total_items, total_pages}}.
cork_list_client_domains details
cork_list_client_domains details
[Cork] List the email domains Cork observed for one client. Each item carries uuid, domain and created_at. The returned uuid is the domainUuid filter for cork_list_compliance_events and cork_list_compliance_notification_settings. Requires a client UUID from cork_list_clients. Paginated envelope {items:[...], pagination:{page, page_size, total_items, total_pages}}.
cork_list_client_inboxes details
cork_list_client_inboxes details
[Cork] List the email inboxes (user mailboxes and shared mailboxes) Cork observed for one client. Each item carries uuid, name, email, created_at, inbox_type (unknown | user | shared | group), associated_domains (a string array) and associated_users (each {name, email, integration} — the integration that sourced the inbox). The returned uuid is the inboxUuid filter for cork_list_compliance_events and cork_list_compliance_notification_settings. Requires a client UUID from cork_list_clients. Paginated envelope {items:[...], pagination:{page, page_size, total_items, total_pages}}.
cork_list_clients details
cork_list_clients details
[Cork] List the MSP's clients (end customers) — the ENTRY POINT for this connector. Each item carries uuid, name, hidden, created_at, warranty_status (active | unwarranted), score_history (an array of {score, created_at} Cork Cyber Scores, score maximum 1000) and associated_tenants (each {uuid, name, integration}). The returned uuid is the client UUID required by cork_list_client_devices, cork_list_client_domains, cork_list_client_inboxes, cork_list_compliance_events and cork_list_compliance_notification_settings, and is also the clientUuid filter on cork_list_software_vulnerabilities / cork_get_software_vulnerability_summary. Hidden/archived clients are EXCLUDED unless showHidden=true. Paginated envelope {items:[...], pagination:{page, page_size, total_items, total_pages}}. partnerUuid scoping is DISTRIBUTOR-ONLY — Cork API keys inherit the permissions of the user who created them, so a partner-level key 403s on it; get partner UUIDs from cork_list_partners.
Compliance
cork_list_compliance_event_types details
cork_list_compliance_event_types details
[Cork] List every compliance event type Cork can raise. Each entry carries event_type, description, cure_period_hours (how long the MSP has to remediate before coverage is affected; null when the type has no cure period) and provisional. Takes NO parameters and is UNPAGINATED — the response is a TOP-LEVEL JSON ARRAY, not the {items, pagination} envelope the paginated Cork reads return. This is the discovery call for valid eventType values on cork_list_compliance_events, so call it first rather than guessing an event type string.
cork_list_compliance_events details
cork_list_compliance_events details
[Cork] List the policy violations and risk events Cork detected for one client's assets — the compliance failures that can affect cyber-warranty coverage. Each item carries uuid, client_uuid, event_type, device_uuid, inbox_uuid, domain_uuid, at_risk, at_risk_at, resolved_at, silenced, created_at and evidence (each {reason, metadata}). TWO DOCUMENTED INTERLOCKS: (1) resolved events are EXCLUDED by default — pass showResolved=true to include them; (2) resolvedAfter / resolvedBefore REQUIRE showResolved=true. Silenced/suppressed events are likewise excluded unless showSilenced=true, and atRisk=true narrows to currently active (unresolved, unsuppressed) risks only. Discover valid eventType values with cork_list_compliance_event_types; the client UUID comes from cork_list_clients and the device / inbox / domain UUIDs from cork_list_client_devices, cork_list_client_inboxes and cork_list_client_domains. Paginated envelope {items:[...], pagination:{page, page_size, total_items, total_pages}}.
cork_list_compliance_notification_settings details
cork_list_compliance_notification_settings details
[Cork] List the notification and alerting rules configured for compliance events on one client's assets — which event types alert and how they are routed. Each item carries event_description, device_uuid, inbox_uuid, domain_uuid, configured_by, reason, notes, excluded_from_coverage, needs_review, review_on, review_duration_days and created_at. excluded_from_coverage flags an asset deliberately carved out of warranty coverage; needs_review together with review_on / review_duration_days shows when a temporary exclusion is due for re-review. Requires a client UUID from cork_list_clients; the optional device / inbox / domain UUID filters come from cork_list_client_devices, cork_list_client_inboxes and cork_list_client_domains. Paginated envelope {items:[...], pagination:{page, page_size, total_items, total_pages}}.
Vulnerabilities
cork_get_software_vulnerability_summary details
cork_get_software_vulnerability_summary details
[Cork] Get CVEs rolled up by software product — the triage view. Each item carries sw_vendor, sw_product, num_impacted_devices (devices running a vulnerable version), num_impacted_versions (distinct vulnerable versions seen) and highest_priority (critical | accelerated | routine | unclassified). Use clientUuid (from cork_list_clients) to scope to a single client, then follow up with cork_list_software_vulnerabilities filtered by swVendor to drill into the individual CVEs. On THIS endpoint sortBy additionally accepts num_impacted_devices and num_impacted_versions on top of sw_vendor and sw_product — the detail list accepts only the latter two, so do not cross-wire them; sortDirection is asc or desc. This endpoint has NO CVSS / EPSS / priority / device filters — use cork_list_software_vulnerabilities for those. partnerUuid is DISTRIBUTOR-ONLY — Cork API keys inherit the permissions of the user who created them, so a partner-level key 403s on it; partner UUIDs come from cork_list_partners. Paginated envelope {items:[...], pagination:{page, page_size, total_items, total_pages}}.
cork_list_software_vulnerabilities details
cork_list_software_vulnerabilities details
[Cork] List individual software vulnerabilities with full CVE detail. Each item carries client_uuid, device_uuid, sw_vendor, sw_product and cves[] of {cve_id, cvss, epss, impacted_version, is_kev, priority}. Narrow to the highest-risk findings with onlyKnownExploited=true (is_kev — known exploited in the wild), minimumCvssScore (0-10), minimumEpssScore (0-1) or minimumPriority (critical | accelerated | routine). Scope with clientUuid (from cork_list_clients) or deviceUuid (from cork_list_client_devices). On THIS endpoint sortBy accepts sw_vendor or sw_product ONLY — the roll-up cork_get_software_vulnerability_summary accepts two more values, so do not cross-wire them; sortDirection is asc or desc. partnerUuid is DISTRIBUTOR-ONLY — Cork API keys inherit the permissions of the user who created them, so a partner-level key 403s on it; partner UUIDs come from cork_list_partners. Paginated envelope {items:[...], pagination:{page, page_size, total_items, total_pages}}. For triage, start with cork_get_software_vulnerability_summary to find the worst products, then drill in here filtered by swVendor.
Distributor
cork_list_partners details
cork_list_partners details
[Cork] List the partner (MSP) sub-accounts managed by this distributor. Each partner carries uuid, name and created_at. This is the DISCOVERY TOOL for partner UUIDs: the uuid returned here is the partnerUuid filter accepted by cork_list_clients, cork_list_connected_integrations, cork_list_invoices, cork_list_installer_history, cork_list_warranties and the vulnerability reads. DISTRIBUTOR KEYS ONLY — a partner-level API key returns 403, as do all partnerUuid filters (a Cork key inherits the permissions of the user who created it, so the creating user must be a distributor user). Paginated (page from 1; pageSize default 10, max 100 — StackJack clamps out-of-range values).
cork_provision_partner details
cork_provision_partner details
[Cork] DESTRUCTIVE / IRREVERSIBLE: provision a brand-new partner (MSP) account under this distributor. The Cork API exposes NO delete-partner endpoint, so a partner created here cannot be removed through the API — confirm the details before calling. By default it also SENDS A WELCOME EMAIL TO A REAL PERSON at primaryContactEmail (pass sendWelcomeEmail=false to suppress it). DISTRIBUTOR KEYS ONLY — a partner-level key returns 403. Returns 200 with the new partner ({uuid, name, created_at}); the uuid is immediately usable as the partnerUuid filter on cork_list_clients, cork_list_invoices and friends. A partner that already exists returns 409 Conflict — check cork_list_partners first.
Integrations
cork_connect_integration details
cork_connect_integration details
[Cork] Connect a new API-based integration, which begins syncing data immediately. Provide a JSON object body. Required: vendor_key (string — from a vendor.key in cork_list_available_integrations) and credential_fields (object — its shape is PER-VENDOR: read that same discovery call's credential_fields schema and use each entry's payload_key as the key here, supplying every field marked required). Optional: display_name (string), partner_uuid (UUID — DISTRIBUTOR KEYS ONLY, from cork_list_partners). Returns 201 with the new integration ({uuid, display_name, vendor, connection_status, installer, partner_uuid, created_at, last_synced_at}); keep the uuid — it is what the other integration tools take. Additive and reversible: the result can be removed later with cork_delete_integration.
cork_delete_integration details
cork_delete_integration details
[Cork] DESTRUCTIVE: delete an integration and stop ALL data collection from it. Provide integrationUuid from cork_list_connected_integrations. RESTRICTION: only integrations CREATED VIA THE API can be deleted; an integration wired up in the Cork UI returns 403. Cork replies 202 Accepted with no body, which StackJack surfaces as — the removal is asynchronous, so re-read cork_list_connected_integrations to confirm (connection_status transitions through deleting). Losing an integration removes the data feed behind Cork Cyber Scores, compliance events and installer routing for its clients; there is no undo other than re-connecting it with cork_connect_integration and re-entering the credentials.
cork_get_integration_credentials details
cork_get_integration_credentials details
[Cork] Get one integration's stored credentials. SENSITIVE: the credentials are returned IN PLAINTEXT, as {uuid, credentials:{<payload_key>: <value>, ...}} — the payload_key names come from that vendor's credential_fields schema in cork_list_available_integrations. RESTRICTION: only integrations CREATED VIA THE API expose their credentials; an integration wired up in the Cork UI returns 403. Provide integrationUuid from cork_list_connected_integrations. Unpaginated. Use this to read the current field set before cork_update_integration, which requires ALL credential fields to be supplied together.
cork_get_integration_raw_data details
cork_get_integration_raw_data details
[Cork] Get a presigned download URL for one integration's RAW synced data. This does NOT return the data inline: the response is JSON {download_url, expires_in, uuid}, where expires_in is seconds and the URL expires after 10 MINUTES — the caller must fetch download_url itself, promptly. TWO RESTRICTIONS: it requires DISTRIBUTOR PRIVILEGES (a partner-level key returns 403), and only integrations CREATED VIA THE API are eligible (a UI-created integration also returns 403). Provide integrationUuid from cork_list_connected_integrations. Unpaginated. Treat the dump as sensitive — it is the full unfiltered vendor payload.
cork_list_available_integrations details
cork_list_available_integrations details
[Cork] List the integration types that CAN be connected to Cork, each with its vendor block ({key, name, type}) and its credential_fields schema. Read this FIRST before cork_connect_integration: every credential field carries name, payload_key, field_type, required, is_secret, dropdown_values and description — and payload_key is the exact key you place inside the connect call's credential_fields object. vendor.key is also the vendorKey that cork_get_installer_setup takes. Optionally filter by vendorType (e.g. rmm, edr, mfa). Paginated (page from 1; pageSize default 10, max 100 — StackJack clamps out-of-range values).
cork_list_connected_integrations details
cork_list_connected_integrations details
[Cork] List the integrations already connected to Cork. This is the DISCOVERY TOOL for integration UUIDs — the uuid returned here is the integrationUuid taken by cork_list_integration_devices/tenants/users, cork_get_integration_credentials, cork_get_integration_raw_data, cork_update_integration, cork_delete_integration and cork_resync_integration. Each item carries uuid, display_name, vendor ({key, name, type}), partner_uuid, created_at, last_synced_at, connection_status (ok|degraded|down|queued|fetching|deleting) and an installer block ({capable, authorized, requires_manual_setup, configured_package_managers}) that says whether software installs can route through this RMM. partnerUuid filters to one partner and is DISTRIBUTOR-KEY ONLY (a partner-level key 403s); get partner UUIDs from cork_list_partners. Paginated (page from 1; pageSize default 10, max 100).
cork_list_integration_devices details
cork_list_integration_devices details
[Cork] List the devices observed from ONE integration (the vendor's own view, before Cork maps them onto clients — use cork_list_client_devices for the client-side view). Provide integrationUuid from cork_list_connected_integrations. Each device carries uuid, name, operating_system, integration_identifier, integration_last_seen, tenant_uuid and a properties array. Optionally narrow to one upstream tenant with tenantUuid (from cork_list_integration_tenants). Paginated (page from 1; pageSize default 10, max 100).
cork_list_integration_tenants details
cork_list_integration_tenants details
[Cork] List the customer tenants observed from ONE integration — the upstream vendor's own tenant/organisation records (e.g. an RMM's client list), which Cork maps onto its own clients. Provide integrationUuid from cork_list_connected_integrations. Each tenant carries uuid, name, integration_identifier, integration_last_seen and created_at; the uuid is the tenantUuid filter accepted by cork_list_integration_devices and cork_list_integration_users. Paginated (page from 1; pageSize default 10, max 100).
cork_list_integration_users details
cork_list_integration_users details
[Cork] List the users observed from ONE integration (e.g. the identity/MFA/M365 accounts the vendor reports). Provide integrationUuid from cork_list_connected_integrations. Each user carries uuid, name, email, tenant_uuid and created_at. Optionally narrow to one upstream tenant with tenantUuid (from cork_list_integration_tenants). Paginated (page from 1; pageSize default 10, max 100).
cork_resync_integration details
cork_resync_integration details
[Cork] Manually trigger a data refresh for ONE integration — useful when last_synced_at from cork_list_connected_integrations is stale or connection_status has recovered from degraded/down. Provide integrationUuid from cork_list_connected_integrations. Takes no request body. Cork replies 202 Accepted with no body, which StackJack surfaces as ; the resync runs asynchronously, so poll cork_list_connected_integrations for last_synced_at / connection_status. VENDOR-THROTTLED: calling it too often returns 429 Too Many Requests — back off rather than retrying immediately. Only refreshes data Cork already owns; it changes nothing upstream.
cork_update_integration details
cork_update_integration details
[Cork] Update an API-created integration's display name and/or credentials. Provide integrationUuid (from cork_list_connected_integrations) plus a JSON object body with the optional fields display_name (string) and credential_fields (object). Do NOT put integration_uuid in the body — StackJack fills it in from the integrationUuid argument, and a body carrying a DIFFERENT UUID is rejected locally before the request is sent. DESTRUCTIVE, in place: when credential_fields is supplied, ALL of that vendor's credential fields must be supplied — a partial object REPLACES the whole set and breaks the live integration (read the current set with cork_get_integration_credentials, and the required keys with cork_list_available_integrations). RESTRICTION: only integrations CREATED VIA THE API can be updated; a UI-created integration returns 403. Returns 200 with the updated integration.
Invoices
cork_list_invoice_line_items details
cork_list_invoice_line_items details
[Cork] List the billed, TOP-LEVEL line items for one invoice. Provide invoiceUuid from cork_list_invoices. Each item carries name, item_type, client_name, client_uuid, quantity, unit_price, total_billed, prorated, billing_start_date, notes and children. Three semantics that change how you read the numbers: (1) only items with a NONZERO total_billed are returned, so a line you expect may legitimately be absent; (2) discount line items ARE included and carry a NEGATIVE total_billed; (3) sub-items billed as part of a parent (e.g. individual licences inside a bundle) are nested under that parent's children array and ALWAYS carry total_billed: 0, because their amount is already rolled into the parent — sum only the top-level total_billed values, never the children, or you will double-count. Paginated (page from 1; pageSize default 10, max 100).
cork_list_invoices details
cork_list_invoices details
[Cork] List Cork billing invoices. Each invoice carries uuid, billing_period_start, created_at, currency, payment_status and total_billed. This is the DISCOVERY TOOL for invoice UUIDs: pass a returned uuid as invoiceUuid to cork_list_invoice_line_items for the per-item breakdown. partnerUuid scopes results to a single partner and is DISTRIBUTOR-KEY ONLY (a partner-level key 403s); get partner UUIDs from cork_list_partners. Paginated (page from 1; pageSize default 10, max 100 — StackJack clamps out-of-range values).
Account
cork_who_am_i details
cork_who_am_i details
[Cork] Return information on the Cork user the API key authenticates as — the response carries name. Takes NO parameters and is unpaginated. This is the cheapest "is my API key alive?" check and the same probe StackJack's Test Connection uses: a 200 means the key is valid, while a 401 means it is wrong, revoked, or EXPIRED. Cork API keys expire on a timeframe the operator picks when minting them and there is no programmatic renewal, so an expired key is the most likely cause of a 401 on a connector that used to work — mint a new key in Cork and re-enter it in StackJack. This endpoint needs no role or scope, so it behaves identically for partner-level and distributor-level keys and is the right first call when diagnosing whether a failure is auth or permissions.
Software Installer
cork_get_installer_setup details
cork_get_installer_setup details
[Cork] Get the ONE-TIME setup steps for an RMM vendor that needs manual setup before Cork software installs work through it. BOTH parameters are REQUIRED (Cork's only two required query params in this connector). Use it when a connected integration from cork_list_connected_integrations reports installer.requires_manual_setup = true AND the package manager you want is missing from installer.configured_package_managers, or when cork_install_software / cork_list_installer_history reports setup_required or not_authorized. Vendors that auto-provision their script (e.g. Intune) report requires_manual_setup = false and need no setup at all. Returns {vendor_display_name, script_name (the EXACT name to give the script/component in the RMM, e.g. "Cork - WinGet"), script_content (the script body to paste), script_language, required_settings[] ({label, value} settings to match in the RMM UI), parameters[] ({name, description, required, default} variables to declare so Cork can set them per install), parameter_storage_label (the vendor's own term for script inputs, e.g. "Script Variable"), setup_guide_url}. Unpaginated. Read-only — it returns instructions and changes nothing; the MSP performs the setup inside the RMM.
cork_install_software details
cork_install_software details
[Cork] DESTRUCTIVE: install a software package on a SINGLE mapped device by dispatching the job through that device's RMM integration (Intune, NinjaRMM, Datto RMM). This changes state on a customer's real endpoint and cannot be undone through this API. PRECONDITION: the target device must report can_install_software = true in cork_list_client_devices — take mappedDeviceUuid from there. Get packageId and the matching packageManagerKey from cork_list_software_packages. ASYNCHRONOUS: Cork replies 202 Accepted with no body (StackJack surfaces ), so there is no result to read here — poll cork_list_installer_history, where state is queued|running|success|partial|error|unknown and 'success' means THE RMM ACCEPTED THE JOB, not that the on-device install finished. If the attempt comes back setup_required or not_authorized (as errors[].code in the history), the routing RMM integration needs its one-time setup — call cork_get_installer_setup for the vendor and package manager. A 422 means Cork could not route the install for the device/package combination you gave.
cork_list_installer_history details
cork_list_installer_history details
[Cork] List past software-install attempts, MOST RECENT FIRST — this is how you follow up an asynchronous cork_install_software call, which returns 202 with no body. Every dispatched install appears here with state (queued|running|success|partial|error|unknown), requested_at, completed_at, software_name, software_publisher, package_manager_key, client_name/client_uuid, device_name/device_uuid, device_count, queued_count, queue_failure_count and an errors array of {code, integration_uuid, vendor_key}. IMPORTANT: Cork tracks RMM DISPATCH, not on-device completion, so state: success means the RMM ACCEPTED THE JOB — not that the software finished installing. An errors[].code of setup_required or not_authorized means the routing RMM integration needs cork_get_installer_setup. Filter with clientUuid (from cork_list_clients) or deviceUuid (from cork_list_client_devices). partnerUuid is DISTRIBUTOR-KEY ONLY (from cork_list_partners) and is required IN ADDITION when a distributor is scoping to a child partner's client or device — clientUuid/deviceUuid alone stay scoped to your own partner's installs. Paginated (page from 1; pageSize default 10, max 100).
cork_list_software_packages details
cork_list_software_packages details
[Cork] List the software packages available to install across the supported package managers (WinGet and Chocolatey). Each package carries name, publisher, package_manager_key, package_id and versions. This is the DISCOVERY TOOL for cork_install_software: pass a returned package_id as packageId and the matching package_manager_key as packageManagerKey. Filter with packageManagerKey (WINGET or CHOC) to scope to one manager, and/or search for a CASE-INSENSITIVE SUBSTRING match against both the package name AND the publisher. Paginated (page from 1; pageSize default 10, max 100 — StackJack clamps out-of-range values).
Warranties
cork_list_warranties details
cork_list_warranties details
[Cork] List ACTIVE cyber-warranty packages. Each item carries uuid, client_uuid, client_name, package, start_date and active. Only active warranties are returned, so an empty or short page does NOT by itself identify which clients are uncovered — to find uncovered clients read warranty_status from cork_list_clients, where 'unwarranted' means no active warranty and 'active' means covered. Use client_uuid here to join a warranty back to its client record. partnerUuid is DISTRIBUTOR-ONLY — Cork API keys inherit the permissions of the user who created them, so a partner-level key 403s on it; partner UUIDs come from cork_list_partners. Paginated envelope {items:[...], pagination:{page, page_size, total_items, total_pages}}.
More in Tools Reference
Atera ToolsAuvik ToolsAvanan (Check Point Harmony Email) ToolsD&H Distributing ToolsStill need help? Ask the team