Skip to main content
Connector guides

Connect Avanan (Check Point Harmony Email)

Check Point's Harmony Email & Collaboration protects email and the files people share in Microsoft 365, Google Workspace, Teams, Slack, Box, Dropbox and ShareFile. It scans messages and attachments…

Written By Christopher Scaminaci

Last updated 3 days ago

Check Point's Harmony Email & Collaboration protects email and the files people share in Microsoft 365, Google Workspace, Teams, Slack, Box, Dropbox and ShareFile. It scans messages and attachments for phishing, malware and data leaks, quarantines what it judges dangerous, and keeps the allow and block lists that tune all of that.

Connecting it gives your AI a set of avanan_ MCP tools — MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:

  • Investigate email — search protected messages and files across a time window, and pull the full detail of any one of them
  • Work security events — search the events Check Point raised, read one in full, and dismiss the ones you have handled
  • Remediate — quarantine a message that got through, or restore one that was caught by mistake
  • Tune the allow and block lists — read and edit the exceptions for anti-phishing, spam, click-time URL protection, anti-malware, URL reputation, DLP and anomaly detection
  • Spot likely-compromised senders — report the mail that passed its sender checks and was quarantined or flagged anyway, across one customer or all of them, as data or as a spreadsheet

A naming note before you go looking

Check Point has renamed this product twice. You may know it as Avanan, which is the company Check Point acquired; the product was then Harmony Email & Collaboration, and Check Point's current documentation calls it Email Security. They are all the same thing. StackJack lists it as "Avanan (Check Point Harmony Email)" so you can find it under either name.

If you manage Avanan in the Avanan portal at portal.avanan.net rather than in the Check Point Infinity Portal — for example because your Avanan licensing comes through a distributor — use the Avanan SmartAPI sign-in method described below. Avanan Support issues the SmartAPI key; ask them for it.

Two ways to sign in

StackJack can sign in to Avanan in one of two ways. You choose on the Avanan card, under How StackJack signs in.

  • Check Point Infinity Portal — an API key you create yourself in the Infinity Portal. This is the usual way, and the sections below up to "Connect with Avanan SmartAPI" describe it.
  • Avanan SmartAPI — the MSP API key that Avanan Support issues. Use it if you manage Avanan without access to the Check Point Infinity Portal, for example when your Avanan licensing comes through a distributor.

The MSP tools, which manage your customers' tenants, licences, add-ons, sub-partners, portal users and usage, always sign in with a SmartAPI key. On an Infinity Portal connection you can add the SmartAPI values as an optional section to turn those tools on.

The one thing to get right: your region

This is the single most important part of the setup, and it is the cause of nearly every failed connection.

Check Point runs Harmony Email in seven separate regions — USA, Europe, Canada, Australia, United Kingdom, United Arab Emirates and India — and runs them as genuinely independent services. They cannot see each other's data, and, crucially, the credentials themselves are regional. A Client ID and Secret Key created in the European region will never work against the Canadian one, no matter how many times you re-type them.

So when StackJack asks which region you are in, that is not a preference or a performance setting. It is part of the credential. If your connection fails and you are confident the key is correct, check the region before you regenerate anything — regenerating a perfectly good key is the most common wasted step here.

What you need

  • A Check Point Infinity Portal account that administers your Harmony Email tenant
  • Permission to create API keys in that portal
  • To know which of the seven regions your tenant is in

Create the credentials

  1. Sign in to the Check Point Infinity Portal at portal.checkpoint.com with an account that administers your Harmony Email tenant. Note the region while you are there.

  2. Open Global Settings, then API Keys, and choose to create a new key.

    These credentials live at the portal level, not inside the Harmony Email product screens. This trips people up constantly — if you are hunting through the Email Security interface for an API section, you are in the wrong place.

  3. Give the key access to Email Security. When creating the key, select the Email Security (Harmony Email & Collaboration) service so the key can reach the email API.

  4. Copy both values. Check Point shows the Secret Key once. Store it somewhere safe before you leave the page — if you lose it, you have to create a new key.

Connect it in StackJack

  1. Open Connectors in StackJack and choose Avanan (Check Point Harmony Email).
  2. Paste the Client ID and the Secret Key.
  3. Choose the region — the same one the key was created in.
  4. Save. StackJack tests the connection straight away. To test it again later, click Test on the connection's row on the Avanan card, or Re-test when the card shows Needs Attention.

If the test fails mentioning authorization, go back and check the region first.

Connect with Avanan SmartAPI

Avanan Support issues a SmartAPI key as four values: a client ID, a client secret, an MSP name and a list of scopes. StackJack supports the six SmartAPI regions: USA, Europe, Australia, Canada, United Kingdom and India. Avanan offers no SmartAPI in the United Arab Emirates region.

  1. Open Connectors in StackJack and choose Avanan (Check Point Harmony Email).
  2. Under How StackJack signs in, choose Avanan SmartAPI, and choose the region your SmartAPI key was issued for.
  3. Enter the four values: SmartAPI client ID (CLIENT_ID), SmartAPI client secret (CLIENT_SECRET), MSP name (NAME) and Scopes (SCOPES). Paste the scopes exactly as Avanan sent them, brackets and quotes included.
  4. Save. StackJack signs in to Avanan with the key before it stores anything, and shows Avanan's own message if the key is refused.
  5. StackJack then tests the connection. To test it again later, click Test on the connection's row on the Avanan card, or Re-test when the card shows Needs Attention.

Like the Infinity Portal key, the SmartAPI values are re-entered every time you save.

To add the MSP tools to an Infinity Portal connection instead, keep Check Point Infinity Portal selected and fill in the four values in the optional SmartAPI credentials section. Fill in all four or none.

The same two sign-in methods are offered when you give an automation its own Avanan credential.

What your AI can and cannot do

Searching always needs a time window

Check Point has no "search everything" query. Every search takes a start and an end date, and asking without one returns an error rather than all your mail. In practice this is fine — just tell your AI the period you care about ("phishing events in the last 48 hours"). It is worth knowing so an empty-handed result reads as "narrow window" rather than "nothing found".

Results come back in batches, and Check Point decides how large each batch is — you cannot ask for a specific page size. Your AI follows the batches automatically when it needs more.

Quarantine and restore are real, and people will notice

Quarantining a message removes it from the recipient's mailbox. Restoring puts it back. Both are immediately visible to the people involved, so both require the Pro tier and are marked destructive. Whether your AI application asks you to confirm before running one depends on that application's own settings — see Destructive tools and confirmation. Review those settings before you grant them.

These actions are also asynchronous: Check Point accepts the request and works on it in the background, returning a reference per message rather than a final answer. Ask your AI to check the status if you need confirmation it completed — it has a tool for exactly that.

Allow-listing weakens a control on purpose

Adding an allow-list entry tells Check Point to stop blocking something. That is sometimes exactly right — a legitimate sender caught repeatedly, a business tool flagged as risky. But it is a security decision, not a quick fix, and it is worth removing the entry once the underlying problem is solved. StackJack's tool descriptions say so explicitly, so your AI treats allow-listing as deliberate rather than routine.

The tools that delete all exceptions in a list clear the entire list in one call. Prefer the single-entry delete tools unless wiping the list is genuinely what you want.

Downloading raw message files is not available

Check Point can hand back the original .eml file for a message. StackJack does not expose that today — it returns a file rather than data your AI can read directly. Everything about the message that Check Point holds as data is available through the detail tools.

Audit logs are somewhere else

Check Point does not serve audit or system logs from this API at all; they come from the Infinity Portal's own separate APIs. If you need audit-log access, this connector is not where it will come from.

Find likely-compromised senders across your customers

Mail that fails its sender checks and gets quarantined is ordinary spoofing. Mail that passes those checks and gets quarantined anyway is different: the message really did come from the mailbox it claims, which usually means that mailbox is being used by someone else. That is the report this connector builds.

Ask for it in plain language ("show me authenticated mail that was still quarantined this week"). You get one row per message with the customer, the sender, the recipient, the subject, what Check Point decided, the sender-check results and a link to the message in Check Point. Rows are grouped per customer with a count, so the customers worth calling first are the ones at the top.

Two things to know before you rely on it.

Only the SPF result is available. Check Point's API publishes an SPF result on a message and does not publish DKIM or DMARC at all. StackJack will not guess at those: it reports them as unavailable, and an unavailable check never counts as a pass. Because the tool asks for all three by default, the first run comes back empty and tells you why. Ask for SPF only and it works: "authenticated by SPF, still quarantined, last 7 days".

Covering several customers depends on what your key can see. Check Point does not publish how a partner key targets one managed customer, so StackJack asks per customer and then checks the answer: every row is labelled with the customer the message itself belongs to, not the one that was asked about. If two customers come back holding the same customer's mail, the whole run is refused rather than published — a hot list that names the wrong companies is worse than no hot list. If that happens, run it one customer at a time.

A run is capped at about a minute of Check Point requests. If it comes back marked as truncated, narrow it — fewer days, or one customer at a time.

Ask for it as a spreadsheet ("...as CSV") and you get a download link instead of rows in the chat. The link is short-lived, so save the file when you get it; re-running the report mints a fresh one.

Plans

TierWhat you get
FreeAll searching and reading — messages, events, action status, and every exception list
ProEverything above, plus quarantine and restore, dismissing events, creating, editing and deleting exceptions, and the authenticated-but-quarantined mail report
BusinessThe Pro tool set with a higher monthly call allowance

Troubleshooting

"Authorization" errors on a key you know is correct. The region. Almost always the region. Check that the region selected in StackJack matches the region the key was created in, then re-test before regenerating anything.

Avanan refused the SmartAPI credentials when you saved. Check all four values against what Avanan Support sent, character for character, and check that the region matches your key. The message shown is Avanan's own.

An MSP tool says the SmartAPI credentials are missing. The MSP tools always sign in with a SmartAPI key. Add the four values to the Avanan card, or switch the card to Avanan SmartAPI.

You cannot find where to create an API key. You are probably inside the Harmony Email product. Go up to the Infinity Portal itself — Global Settings, then API Keys.

A search returns nothing. Widen the time window. There is no all-time search, so a narrow window is the usual cause.

An identifier "does not exist". Message and event identifiers are not portable between Check Point regions, and older items age out of retention. Run a fresh search to get a current identifier rather than reusing one from an old conversation.

A quarantine seemed to do nothing. It is asynchronous — Check Point accepted the request and is working on it. Ask your AI to check the action status.

Several customers

Some MSPs need one Avanan connection per customer, console or region. StackJack can hold several named connections of one connector, and your AI names the one it wants on each call. See Several connections of one connector.

Full tool list

See the generated Avanan (Check Point Harmony Email) tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.

Avanan (Check Point Harmony Email) tools

avanan_ · 79 tools · Free 35 · Pro 44

Secured Entities

ToolWhat it does
avanan_action_entity
Pro · Destructive
Take a remediation action on one or many secured entities.
avanan_get_entity
Free · Read-only
Get full details for one secured entity (an email, file or message) by its entity id — ids come from avanan_search_entities.
avanan_get_task_status
Free · Read-only
Poll the outcome of an asynchronous action.
avanan_search_entities
Free · Read-only
Search secured entities (emails, files, messages).

Security Events

ToolWhat it does
avanan_action_event
Pro · Destructive
Take an action on one or many security events — the documented action includes dismiss, which permanently closes out a real detection in the customer's Check Point console and removes it from the analyst queue.
avanan_get_event
Free · Read-only
Get full details for one security event by its event id — ids come from avanan_search_events.
avanan_search_events
Free · Read-only
Search security events (detections).

Exceptions

ToolWhat it does
avanan_create_antiphishing_exception
Pro · Write
Add one entry to an Anti-Phishing list.
avanan_create_ap_blacklist
Pro · Write
Add one entry to the Anti-Phishing BLOCK list, which makes matching mail always be treated as malicious.
avanan_create_ap_whitelist
Pro · Write
Add one entry to the Anti-Phishing ALLOW list.
avanan_create_spam_exception
Pro · Write
Add one entry to the Spam allow list.
avanan_delete_antiphishing_exception
Pro · Destructive
Permanently remove one entry from an Anti-Phishing list.
avanan_delete_ap_exception
Pro · Destructive
Permanently remove one Anti-Phishing exception entry.
avanan_delete_spam_exception
Pro · Destructive
Permanently remove one entry from the Spam allow list.
avanan_get_antiphishing_exception
Free · Read-only
Get one Anti-Phishing exception entry.
avanan_get_ap_exception
Free · Read-only
Get one Anti-Phishing exception entry by list and entry id, optionally narrowed to a Check Point scope.
avanan_get_exception
Free · Read-only
Get one exception entry by list slug and entry id.
avanan_get_spam_exception
Free · Read-only
Get one Spam allow-list entry by its id (from avanan_list_spam_exceptions).
avanan_list_antiphishing_exceptions
Free · Read-only
List the Anti-Phishing exception entries.
avanan_list_ap_exceptions
Free · Read-only
List one Anti-Phishing exception list, optionally narrowed to a single entry id or a Check Point scope.
avanan_list_exceptions
Free · Read-only
List every entry in one exception list, chosen by excType.
avanan_list_spam_exceptions
Free · Read-only
List every entry in the Spam allow list.
avanan_update_antiphishing_exception
Pro · Write
Edit one existing Anti-Phishing exception entry in place.
avanan_update_ap_blacklist
Pro · Write
Edit one Anti-Phishing BLOCK-list entry in place.
avanan_update_ap_whitelist
Pro · Write
Edit one Anti-Phishing ALLOW-list entry in place.
avanan_update_spam_exception
Pro · Write
Edit one existing Spam allow-list entry in place.

Click-Time Protection

ToolWhat it does
avanan_add_click_time_exception_item
Pro · Write
Add one URL/pattern to the Click-Time Protection exception list.
avanan_delete_all_click_time_exceptions
Pro · Destructive
Removes ALL Click-Time Protection exceptions — this wipes the entire list in one call, not a single entry.
avanan_delete_click_time_exception_item
Pro · Destructive
Permanently remove ONE Click-Time Protection exception item, by its item id (from avanan_list_click_time_exception_items).
avanan_get_click_time_exception_item
Free · Read-only
Get one Click-Time Protection exception ITEM by its id (from avanan_list_click_time_exception_items) — a single URL/pattern excluded from click-time rewriting.
avanan_get_click_time_exception_list
Free · Read-only
Get one Click-Time Protection exception LIST by its id (from avanan_list_click_time_exception_lists).
avanan_list_click_time_exception_items
Free · Read-only
List the individual Click-Time Protection exception ITEMS — the actual URLs/patterns that are excluded from click-time rewriting and re-scanning.
avanan_list_click_time_exception_lists
Free · Read-only
List the Click-Time Protection exception LISTS (the containers, not their entries).
avanan_update_all_click_time_exception_items
Pro · Destructive
Replace/update ALL Click-Time Protection exception items in ONE call — a MASS MUTATION across the whole list, not a single-record edit.
avanan_update_click_time_exception_item
Pro · Write
Edit ONE Click-Time Protection exception item in place, by its item id (from avanan_list_click_time_exception_items).

Anti-Malware Exceptions

ToolWhat it does
avanan_create_malware_exception
Pro · Write
Create an Anti-Malware exception.
avanan_create_malware_exception_by_type
Pro · Write
Create an Anti-Malware exception with a specific exception TYPE.
avanan_delete_all_malware_exceptions
Pro · Destructive
Removes ALL Anti-Malware exceptions — this wipes the entire list in one call, not a single entry.
avanan_delete_malware_exception
Pro · Destructive
Permanently remove ONE Anti-Malware exception, identified in the body (for this family by its MD5 exception string).
avanan_get_malware_exception
Free · Read-only
Get one Anti-Malware exception by its exception string.
avanan_list_malware_exceptions
Free · Read-only
List every Anti-Malware exception — the files/hashes the Anti-Malware engine has been told not to block.
avanan_update_malware_exception
Pro · Write
Update an existing Anti-Malware exception.

URL Reputation Exceptions

ToolWhat it does
avanan_create_url_exception
Pro · Write
Create a URL-Reputation exception.
avanan_create_url_exception_by_type
Pro · Write
Create a URL-Reputation exception with a specific exception TYPE.
avanan_delete_all_url_exceptions
Pro · Destructive
Removes ALL URL-Reputation exceptions — this wipes the entire list in one call, not a single entry.
avanan_delete_url_exception
Pro · Destructive
Permanently remove ONE URL-Reputation exception, identified in the body by its exception string.
avanan_get_url_exception
Free · Read-only
Get one URL-Reputation exception by its exception string.
avanan_list_url_exceptions
Free · Read-only
List every URL-Reputation exception — the URLs/domains the URL-Reputation engine has been told not to flag.
avanan_update_url_exception
Pro · Write
Update an existing URL-Reputation exception.

DLP Exceptions

ToolWhat it does
avanan_create_dlp_exception
Pro · Write
Create a DLP exception.
avanan_create_dlp_exception_by_type
Pro · Write
Create a DLP exception with a specific exception TYPE.
avanan_delete_all_dlp_exceptions
Pro · Destructive
Removes ALL DLP exceptions — this wipes the entire list in one call, not a single entry.
avanan_delete_dlp_exception
Pro · Destructive
Permanently remove ONE DLP exception, identified in the body by its MD5 exception string.
avanan_get_dlp_exception
Free · Read-only
Get one DLP exception by its exception string.
avanan_list_dlp_exceptions
Free · Read-only
List every DLP exception — the content the Data Loss Prevention engine has been told not to flag on its way out of the organization.
avanan_update_dlp_exception
Pro · Write
Update an existing DLP exception.

Anomaly Exceptions

ToolWhat it does
avanan_create_anomaly_exception
Pro · Write
Create an anomaly exception.
avanan_delete_anomaly_exception
Pro · Destructive
Permanently remove one anomaly exception, identified in the body — read the exact entry from avanan_list_anomaly_exceptions first, since there is no get-by-id route in this family.
avanan_list_anomaly_exceptions
Free · Read-only
List every anomaly exception — the users, behaviours or patterns the anomaly engine has been told not to raise events for.

MSP

ToolWhat it does
avanan_msp_create_partner
Pro · Write
Create a sub-partner under this MSP account.
avanan_msp_create_tenant
Pro · Write
Provision a new managed tenant under this MSP account.
avanan_msp_create_user
Pro · Write
Create a Check Point portal user under this MSP account.
avanan_msp_delete_partner
Pro · Destructive
Permanently remove a sub-partner from this MSP account.
avanan_msp_delete_tenant
Pro · Destructive
Permanently remove a managed tenant from this MSP account.
avanan_msp_delete_user
Pro · Destructive
Permanently remove an MSP portal user.
avanan_msp_get_tenant
Free · Read-only
Describe one managed tenant by its numeric id (ids come from avanan_msp_list_tenants).
avanan_msp_get_user
Free · Read-only
Describe one MSP portal user by numeric id (ids come from avanan_msp_list_users).
avanan_msp_list_addons
Free · Read-only
List the licence add-ons this MSP account can attach to a tenant.
avanan_msp_list_daily_usage
Free · Read-only
Read this MSP account's licensed-seat usage for ONE DAY.
avanan_msp_list_licenses
Free · Read-only
List the licence types this MSP account can assign.
avanan_msp_list_monthly_usage
Free · Read-only
Read this MSP account's licensed-seat usage for one calendar month.
avanan_msp_list_partners
Free · Read-only
List the sub-partners under this MSP account.
avanan_msp_list_tenants
Free · Read-only
List the tenants this Check Point MSP account manages.
avanan_msp_list_users
Free · Read-only
List the Check Point portal users of this MSP account.
avanan_msp_update_user
Pro · Write
Edit one MSP portal user in place.
avanan_msp_upsert_tenant_license
Pro · Write
Set a managed tenant's licence, creating it if the tenant has none.

Reports

ToolWhat it does
avanan_report_authenticated_threats
Pro · Read-only
Report the mail that PASSED sender authentication and was quarantined or judged a threat anyway, across every tenant your Check Point MSP account manages.

Platform

ToolWhat it does
avanan_get_scopes
Free · Read-only
Read the scopes the connection's key is granted.
avanan_health_check
Free · Read-only
Read the Check Point Harmony Email API root to confirm the region is answering.