Connect Alloy Navigator
Alloy Navigator is IT service management and IT asset management in one product. It runs the service desk — incidents, service requests, problems, change requests and work orders — on top of a…
Written By Christopher Scaminaci
Last updated 6 days ago
Alloy Navigator is IT service management and IT asset management in one product. It runs the service desk — incidents, service requests, problems, change requests and work orders — on top of a configuration management database that tracks computers, hardware, networks, software licenses, contracts, purchase orders and stock. It is sold as software you install on your own server and as a cloud service Alloy hosts for you, and StackJack connects to either one the same way.
Connecting Alloy Navigator to StackJack gives your AI assistant a family of alloy_ MCP tools — MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:
- Work the service desk — list and search incidents, service requests, work orders, problems and change requests, plus the two combined ticket views, filtered on status, priority, assignee, customer or due date
- Answer asset questions — computers, hardware, general configuration items, networks, documents and the combined configuration item view
- Track software — installed software found by discovery, license records, the software catalog and the products those licenses cover
- Follow purchasing and stock — purchase orders and their line items, vendors, vendor products, consumables, stock rooms, stock rules and equipment reservations
- Read people and structure — persons, organizations, groups, locations, services and service level agreements
- Use the knowledge base and admin records — articles, announcements, projects, tasks, contracts, library items, approval requests and approval stages, and the service catalog
- Open one record in full — every field of a single record, its complete activity log, and the legal values of a status, priority or other classification field before you filter on one
- See attachments — the files and links on a record, and the content of one attachment
- Add to a record (on Pro plans) — attach a file, attach a link, or correct an attachment's description
- Run your own workflow actions (on Pro plans) — create a record, run a step action on a record, or invoke a global workflow function
How StackJack authenticates to Alloy Navigator
Alloy Navigator issues an Application ID and a Secret on what it calls an application account. You create that account, copy the two values into StackJack, and StackJack exchanges them for an access token that lasts eight hours and renews itself. Nothing needs re-entering unless the Secret is regenerated.
Check one setting first
Alloy Navigator's API module can be set to accept access tokens or to use Windows authentication, and only the first works with StackJack. Open the Web Configuration tool on your Alloy Navigator web server, select the API module, and look at its User Authentication Type page. If it says Windows authentication, change it to access token authentication before you go any further — no credential you paste into StackJack will connect otherwise.
Steps
- Confirm access token authentication is on, as above.
- Copy the API URL from the same Web Configuration tool. It appears in the main pane when the API module is selected. Copy the whole address including its virtual directory, which is usually
/api— for examplehttps://navigator.example.com/api. The server name on its own is not enough. - Create an application account in the desktop Settings App, under Services. Name it for StackJack so you can recognize it later. Every call StackJack makes runs as this account.
- Copy the Application ID and the Secret that Alloy Navigator issues for the account. Treat the Secret as a password.
- Paste all three into StackJack. Open Connectors, choose Alloy Navigator, and enter the API URL, the Application ID and the Secret.
- Run a Test Connection. StackJack confirms the credential by reading a single record from your Persons list. An empty Persons list still passes — the check proves the credential works, not that you have data.
What to know before your AI uses this connector
The credential has full access, and that is Alloy Navigator's design
An application account carries unrestricted access to every record and every workflow action, regardless of security roles. That is stated in Alloy Navigator's own documentation, and there is no read-only credential to hand StackJack instead. The practical consequence: control what StackJack can do with the tool permissions on this page, not with the credential. Turning off a permission group here is the boundary that actually holds.
The one exception is narrow and worth knowing. Three tools accept an optional person identifier that downgrades the call to self-service portal rights for that call only. It is useful when you want an action attributed to a requester rather than to the integration account.
There are no create or update commands — only your own workflow actions
This is the single most surprising thing about Alloy Navigator's API, and it shapes every write tool. The API does not create or update records directly. It runs workflow actions, which are defined in your own system and identified by a number.
That means StackJack cannot offer you a tool called "close incident". What that action does, what it is called, and what number it carries are all yours, not ours, and they differ between two customers running the same product. So the write half of this connector is three general-purpose tools that run an action you name by number:
- Create a record by running a create action.
- Run a step action on an existing record. This is the only update path in the whole API, and it is the same route whether the action closes a ticket, reassigns it, cancels it or emails somebody.
- Invoke a global workflow function, which has no record scope at all.
You find the numbers in the desktop Settings App, under Workflow and Business Logic. StackJack cannot list them for you, because Alloy Navigator does not publish them over the API.
Three tools can change a great deal in one call
All three workflow tools are marked destructive and require the Pro tier. Whether your AI application asks you to confirm before running one depends on that application's own settings — see Destructive tools and confirmation. Review that setting, because the marking on its own is not caution for its own sake:
- A create action commonly emails people. Raising a ticket through workflow typically notifies the requester and the assignee, because that is what your workflow is built to do.
- A step action does whatever the action number says. Passing the wrong number does not fail safely; it runs a different action.
- A global function has no scope. Alloy Navigator's own worked example of one closes every ticket resolved more than a set number of days ago, across the whole system.
There is one more consequence worth passing on to whoever reviews these prompts: a workflow action form can be submitted with a mandatory field left unfilled and still report success, if that field already had a default or a current value. So a write that came back clean did not necessarily do what was intended. Ask your AI to read the record back after a workflow write.
Attachments behave normally
Adding a file and adding a link only ever add to a record. Correcting an attachment's description replaces the text that was there, and an empty description clears it — a one-field cosmetic change that can never remove the attachment or its contents, so all three are marked the same way. Deleting an attachment is permanent and has no undo, so it is marked destructive too.
Two record types can only be listed
Software Catalog and Stock Rooms can be listed and searched, but Alloy Navigator refuses to open, log or act on an individual record of either. The affected tools say so in their descriptions, so an assistant that tries will be told why rather than looping.
Enterprise, not Express
These tools were built against Alloy Navigator Enterprise. Alloy Navigator Express has a smaller set of record types, so on an Express installation some tools will report that a record type is not recognized. That is the product difference, not a fault in the connection.
Plans and limits
Read tools are available on the Free tier. Everything that writes — the three workflow tools and the four attachment tools — is Pro. Business reaches the same tools as Pro and differs by monthly call quota.
See the generated Alloy Navigator tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.
Alloy Navigator publishes no request limits, and many installations run on a single server that is also serving your own technicians. StackJack therefore paces its calls conservatively and returns at most 200 records per page, so a large report is spread out rather than crowding out your service desk. Pacing is not a guarantee: retries are bounded, so a wide enough report can still time out. Narrow it, and check whether a write landed before repeating it — see Retrying a failed or timed-out write.
Reading a list result
List results arrive in a compact form worth knowing about if you are reading raw output: the response names its columns once and then returns rows as plain arrays of values in that same column order, rather than repeating every field name on every row. Your AI assistant is told how to read it. Lists also carry no total count and no next-page link, so a page shorter than the size you asked for is the end of the results.
Several customers
Every customer has their own Alloy Navigator server. Add one connection per customer from the connector's card, name it after the customer, and your AI names it on each call. Omit the name and the call runs against your default connection. Pin an endpoint to one connection when an AI should never reach past a single customer. See Several connections of one connector.
Troubleshooting
"Authorization has been denied for this request" — the access token was refused. StackJack gets a fresh one and retries on its own, so a failure that reaches you generally means the Application Secret was regenerated or the application account was disabled. Create or copy the credential again, paste it into StackJack, and run a Test Connection.
Test Connection fails immediately and nothing looks wrong with the credential — check the API URL. The most common mistake is entering the server name without the virtual directory. StackJack needs the whole address the Web Configuration tool shows you, /api included. The second most common is that the API module is still set to Windows authentication.
"Requested object is of unknown class" — that record type does not exist on your installation. It is the expected answer on Alloy Navigator Express, and on an Enterprise installation where a record type has been removed.
A list comes back with column names but no rows — the credential cannot see that record type, which is a different situation from the record type being empty. Check the API module configuration and the application account before concluding the customer has no records.
A workflow action was accepted but nothing seems to have changed — check the result detail rather than the top-level success flag, and read the record back. A form submitted with an unfilled mandatory field can still report success when the field carried a default or the record's current value.
A write is refused for Software Catalog or Stock Rooms — that is Alloy Navigator, not StackJack. Those two record types support listing only.
Alloy Navigator tools
alloy_ · 56 tools · Free 49 · Pro 7
Service Desk
People and Organizations
Assets and Configuration
Software Assets
Procurement and Stock
Knowledge and Administration
Objects and Metadata
Attachments
Workflow Actions
More in Connector guides
Connect Acronis Cyber Protect CloudConnect Action1Connect AddigyConnect Autotask PSAStill need help? Ask the team