Connect Acronis Cyber Protect Cloud
Acronis Cyber Protect Cloud is the platform most MSPs buy for backup and then end up running half their customer estate on: backup and recovery, disaster recovery with cloud failover, endpoint…
Written By Christopher Scaminaci
Last updated 6 days ago
Acronis Cyber Protect Cloud is the platform most MSPs buy for backup and then end up running half their customer estate on: backup and recovery, disaster recovery with cloud failover, endpoint detection and response, file sync and share, and a full customer tenant tree with its own users, licensing and usage. StackJack talks to all of it through one set of credentials.
Connecting Acronis to StackJack gives your AI assistant a family of acronis_ MCP tools — MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:
- Answer "what broke last night" — the alert roll-up across every customer you manage, alert counts per customer, the resources with the most severe alerts, and the backup tasks and activities behind them
- Check protection coverage — which endpoints have an agent, which agents are stale, what each agent is running on, which resources are protected and by which policy, and where policies have drifted
- See the backup estate — vaults, archives, individual backups and their timestamps, storage usage, geo-replication status, antimalware scan results, and whether the last restore point actually validated
- Investigate security incidents — the endpoint detection and response incident list, the full detail behind one, and the response actions already taken
- Answer billing and licensing questions — the customer tenant tree, each tenant's usage against its quotas, the offering items enabled for a customer, and the pricing applied to them
- Read your price lists and the platform event stream
- Manage alerts and agents (on Pro plans) — dismiss handled alerts, mark a false positive, and force an agent update on managed endpoints
- Author and apply protection (on Pro plans) — build a protection policy through its draft workflow, apply it to resources, and revoke it
- Provision customers (on Pro plans) — create and update tenants and users, set offering items and pricing, switch a tenant edition, manage branding and multi-factor status, and issue registration tokens
- Run continuity operations (on Pro plans) — start a test failover, start a production failover, and stop one
- Work Acronis's own PSA and file sync (on Pro plans) — tickets, contracts, products, taxes and invoices in Advanced Automation, and folders, members, share links and devices in File Sync and Share
How StackJack authenticates to Acronis
You create an API client inside your Acronis management console. Acronis gives you three things at that moment, and StackJack needs all three:
- a Client ID
- a Client Secret, shown only once
- your data center URL
The Client ID and Client Secret work like a username and password for an application rather than a person. StackJack exchanges them for a short-lived access token, keeps it fresh, and gets a new one automatically when it expires. You never see the token and there is nothing to renew on a schedule.
The data center URL is not optional
This is the part that trips people up, so it is worth being blunt about it. Every Acronis account lives in exactly one data center, and there is no access between them. The URL Acronis shows you when you create the API client is the address of your data center — something like https://eu2.acronis.cloud — and it is not the address you type into a browser to sign in to the console. If you enter a different one, the credentials will not work, and the failure looks like a bad password rather than a wrong address.
StackJack checks that what you enter is a genuine Acronis address before it saves anything, so a typo is caught at the form rather than three days later.
What the API client can see
An Acronis API client has no permission list of its own. It inherits the roles of the administrator and the tenant it was created under. That has one practical consequence worth planning for:
- Create it under your partner tenant, signed in as an administrator who can see every customer you manage, and the connector reaches all of them.
- Create it inside a single customer tenant, and the connector sees that customer only.
- Create it under a read-only administrator, and every read tool works while every Pro write tool is refused.
If you later find that a write tool is refused, this is almost always why. The fix is to re-create the API client under an administrator with the rights you need, not to re-enter the secret.
Steps
- Sign in to the Acronis management console as an administrator of the tenant whose customers you want StackJack to reach.
- Go to Settings, then API clients, and create a new API client. Name it so it is obvious later which integration it belongs to — that is what lets you revoke it cleanly.
- Copy the Client ID, the Client Secret and the data center URL from the confirmation screen. The secret is shown once and cannot be retrieved afterwards.
- Paste all three into StackJack. Open Connectors, choose Acronis Cyber Protect Cloud, and fill in the data center URL, Client ID and Client Secret.
- Run a Test Connection to confirm StackJack can reach your data center with the credentials.
What your AI can do
See the generated Acronis tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.
Most tools take an optional Acronis tenant id so you can scope a question to one customer. Ask your assistant to list your tenants first if you do not know the id — it will find it and use it.
Acronis does not publish a request limit, so StackJack paces requests conservatively and backs off whenever Acronis asks it to. A large report across a big estate is usually slower rather than failed. Pacing smooths a burst; it does not guarantee that every call arrives. Retries are bounded, so a wide enough read can still come back throttled or time out. Narrow the read, honour any retry delay the vendor sends, and check whether a write landed before repeating it — see Retrying a failed or timed-out write.
Before you turn on the write tools
This connector reaches further than most. Its Pro tools can delete a customer tenant, delete a user, switch a tenant's edition, change what a customer is charged, delete backups and whole archives, change the password on an encrypted vault, remove agents from endpoints, isolate or shut down a machine from a security incident, mark invoices as exported, and start or stop a production failover. Every one of those is labeled as a destructive action. Whether your AI application stops to ask you before running one depends on that application's own settings — StackJack does not enforce a confirmation step on an ordinary AI connection, so check that setting and restrict the tools you grant before you allow any of these. See Destructive tools and confirmation. Where your AI does ask, read what it says rather than approving on autopilot, particularly for anything touching vaults, archives or failover, where there is no undo on the Acronis side either.
Where Acronis itself requires you to name what a call applies to — the machine whose archives are being deleted, the agent being removed, the invoices being exported — StackJack requires it too, and refuses the call before it reaches Acronis if it is left blank. There is no unscoped form of those tools.
If you only want your assistant answering questions, the Free plan tools are all reads and none of them can change anything.
Several customers
Some MSPs need one Acronis Cyber Protect Cloud connection per customer, console or region. StackJack can hold several named connections of one connector, and your AI names the one it wants on each call. See Several connections of one connector.
Troubleshooting
"Acronis rejected the API client credentials" — the Client ID or Client Secret is wrong, or the API client was deleted in the console. Create a new API client, copy all three values again, and update them in StackJack. The secret cannot be recovered from Acronis, so a lost one always means a new client.
"Acronis could not find that tenant in the configured data center" — nearly always the wrong data center URL. Confirm it against the one Acronis showed when the API client was created. Acronis keeps each account in one data center with no access between them, so an address from another region reaches a service that has never heard of your customers.
"Acronis denied this action for the API client's role" — the credentials are fine and the API client authenticated; it simply lacks the right. Re-create it under an administrator with the needed role, or under the parent tenant whose customers you need to reach.
"Acronis reported that a purchased quota is exhausted" — also not a credential problem. Storage, seats or another entitlement you bought has filled up. Review the customer's usage and offering items, raise the quota or free space in Acronis, then retry. Retrying without changing anything will keep failing, and StackJack will not disable the connection over it.
A customer shows no alerts at all — check that the API client can actually see that customer before assuming it has been a quiet week. An API client created inside one tenant sees only that tenant, and a customer it cannot see looks exactly like a customer with nothing wrong.
Acronis Cyber Protect Cloud tools
acronis_ · 272 tools · Free 136 · Pro 136
Alerts
Tasks and Activities
Protection Agents
Protection Policies and Resources
Endpoint Detection and Response
Tenants, Users and Licensing
Vaults, Archives and Backups
Disaster Recovery
Event Stream
Price Lists
Advanced Automation (PSA)
File Sync and Share
More in Connector guides
Connect AddigyConnect AlertOpsConnect Alloy NavigatorConnect AteraStill need help? Ask the team