Connect Autotask PSA
Autotask PSA (by Kaseya/Datto) is a professional services automation suite for service desk, CRM, projects, contracts, and time tracking. Connecting it to StackJack lets your AI assistant work with…
Written By Christopher Scaminaci
Last updated 6 days ago
Autotask PSA (by Kaseya/Datto) is a professional services automation suite for service desk, CRM, projects, contracts, and time tracking. Connecting it to StackJack lets your AI assistant work with that data through StackJack's tool catalog. Tool results are passed through as raw Autotask API responses.
The Autotask integration provides tools with the at_ prefix spanning:
See the generated Autotask tool reference for the current inventory, input schemas, plan tiers, and safety notes.
Tool availability depends on your Autotask connector plan tier — the in-portal tool selector and the Permissions page (/permissions) show exactly which tools your plan includes.
How authentication works
StackJack authenticates every request with Autotask's static API headers: the API integration code (Autotask's tracking identifier), the API-only user's username, and its Secret. There is no OAuth flow and no token to manage. This is a shared credential for the whole StackJack tenant, so Autotask attributes its activity to that API-only user — unless you give your team members their Autotask resource ids, in which case their own changes are recorded under their names. See Autotask identity.
You also never enter a server URL: StackJack auto-discovers your Autotask datacenter zone from the API username when you save.
Prerequisites in Autotask
- Create an API-only user. In Autotask, go to Admin > Resources (Users) and create a new API-only resource dedicated to StackJack, rather than reusing another integration's account.
- Give it a least-privilege security level. Copy the API User (system) security level and reduce it to the modules, features, roles, lines of business, and protected data your workflows actually need. Keep the Not required to change password exemption — an API-only user cannot sign in to change an expired password.
- Generate the credentials. Note the API user's username (in email format) and generate its Secret. Save the Secret immediately; Autotask does not redisplay it.
- Get the API integration code. Autotask calls this the tracking identifier — it is issued when you register the integration in the Autotask admin console or the Datto partner portal, and it is what StackJack sends on the
ApiIntegrationCodeheader.
Autotask permissions
The API user's security level determines which entities and operations StackJack can use:
Tip: the StackJack Permissions page (/permissions) maps every StackJack tool to the Autotask access it needs, so you can scope the security level to least privilege.
Set up the connector in StackJack
- In the StackJack portal, go to Connectors and find the Autotask PSA card.
- Optional: click How To Connect for the in-portal version of this guide.
- Click Configure and fill in the fields:
- Click Save. StackJack contacts Autotask's global zone-information service with the API username and stores the discovered zone URL.
What happens when you save
- Zone discovery runs first; a failure aborts the save, so nothing incorrect is stored.
- Your credentials are stored in Azure Key Vault — never in the StackJack database, and never shown back to you.
- A Free-tier connector subscription is created automatically if you don't already have one (upgrade any time from the connector card).
- StackJack immediately test-calls your Autotask zone with an authenticated request. Success shows a confirmation toast; a failed or timed-out test shows a warning toast but does not block the save — StackJack retries validation in the background.
- Credentials are re-validated automatically in the background. After 3 consecutive definitive failures the credential is auto-disabled, tool calls stop, and the tenant owner is emailed. The connector card then offers Re-enable and Update Credentials; an invalid-but-enabled card offers Re-test.
Rotating the API Secret
- Record the current connector health and run a low-risk read tool so you have a before-state.
- Generate the replacement Secret on the API-only user in Autotask and store it securely; Autotask does not redisplay it.
- In StackJack, use Update Credentials and re-enter the integration code, username, and new Secret together — the username drives zone discovery on every save, so all three go in at once.
- Save, then run Re-test and repeat the low-risk read to confirm the expected data boundary. Test write tools only against a designated test record if your plan and permissions expose them.
- Once the replacement has been healthy for your observation window, retire the old Secret under your credential policy.
Region / instance URL guidance
None needed — this is the one PSA connector with no URL or region field. Autotask operates multiple datacenter zones worldwide, and each account lives in exactly one; StackJack discovers yours automatically from the API username at save time and re-uses it for all requests. If your instance is ever migrated to a different zone by Kaseya, simply re-save the connector to re-run discovery.
Per-user connections
Not supported for this connector — everyone shares the one API user's credentials. What you can do is have Autotask record each person's changes under their own name, using Autotask identity below.
Autotask identity (who a change is recorded as)
By default every ticket, note and time entry StackJack creates is recorded in Autotask as the API-only user. If you would rather see the person who actually asked for the change, give each team member their Autotask resource id and StackJack will write as them.
Set it up in Autotask first. In your API-only user's security level, allow it to impersonate resources on the entities you care about, and allow the resources being impersonated to be impersonated. Without both, Autotask refuses the call.
Then set the ids in StackJack.
- Each person can set their own on Connectors — the "My Autotask identity" card, which appears once Autotask is connected.
- An administrator can set anyone's on Team, using the Autotask Identity button on that person's row.
To find a resource id, run the at_list_resources tool, look for the resource whose email address matches the person, and use its id. Resource ids are numbers.
Which changes this covers: creating and updating tickets, ticket notes, time entries and task notes, and creating company notes.
Signed-in people get it automatically; endpoints do not. When someone is signed in through their own StackJack account, their stored id is applied to every Autotask change they make. A connection that uses a client ID and secret is not one person, so it is never assigned an identity automatically — those tools take an optional impersonationResourceId argument for the AI to pass instead. Leave it out and the change is recorded as the API user, exactly as before.
Limits and behavior
Troubleshooting
Disconnecting: the Disconnect button deletes the stored credentials from Key Vault and immediately stops all Autotask tool calls. Note that disconnecting does not cancel a paid connector subscription — cancel the plan separately from the connector card if you no longer want it.
Autotask tools
at_ · 458 tools · Free 298 · Pro 160
Service Tickets
Ticket Notes and Checklists
Ticket Charges
Service Calls
Ticket Sub-Resources
Companies
Company Sub-Resources
Contacts
Configuration Items (Assets)
CI Sub-Resources
Contracts
Contract Sub-Resources
Projects
Project Sub-Resources
Time Entries
Resources (Technicians)
Opportunities (Sales)
Quotes and Sales Orders
Scheduling and Calendar
Expenses and Purchase Orders
Invoices and Billing
Products and Services
Documents and Attachments
Attachments
Knowledge Base
Surveys and CSAT
Discovery and Entity Info
Lookups and Reference Data
Analytics
Advanced Analytics
Premium Analytics
Intelligence
Cross-Domain
Resource Sub-Resources
Time Off Requests
Task Sub-Resources
Webhooks
Change Management
Document Sub-Resources
Knowledge Base Sub-Resources
Contract Extended
Invoice Extended
Inventory
Tags
Opportunity/Sales Sub-Resources
Org Structure
Financial Config
Admin
Expense Extended
More in Connector guides
Connect Acronis Cyber Protect CloudConnect Action1Connect AddigyConnect AlertOpsStill need help? Ask the team