Connect Avanan (Check Point Harmony Email)
Check Point's Harmony Email & Collaboration protects email and the files people share in Microsoft 365, Google Workspace, Teams, Slack, Box, Dropbox and ShareFile. It scans messages and attachments…
Written By Christopher Scaminaci
Last updated 3 days ago
Check Point's Harmony Email & Collaboration protects email and the files people share in Microsoft 365, Google Workspace, Teams, Slack, Box, Dropbox and ShareFile. It scans messages and attachments for phishing, malware and data leaks, quarantines what it judges dangerous, and keeps the allow and block lists that tune all of that.
Connecting it gives your AI a set of avanan_ MCP tools — MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:
- Investigate email — search protected messages and files across a time window, and pull the full detail of any one of them
- Work security events — search the events Check Point raised, read one in full, and dismiss the ones you have handled
- Remediate — quarantine a message that got through, or restore one that was caught by mistake
- Tune the allow and block lists — read and edit the exceptions for anti-phishing, spam, click-time URL protection, anti-malware, URL reputation, DLP and anomaly detection
- Spot likely-compromised senders — report the mail that passed its sender checks and was quarantined or flagged anyway, across one customer or all of them, as data or as a spreadsheet
A naming note before you go looking
Check Point has renamed this product twice. You may know it as Avanan, which is the company Check Point acquired; the product was then Harmony Email & Collaboration, and Check Point's current documentation calls it Email Security. They are all the same thing. StackJack lists it as "Avanan (Check Point Harmony Email)" so you can find it under either name.
If you manage Avanan in the Avanan portal at portal.avanan.net rather than in the Check Point Infinity Portal — for example because your Avanan licensing comes through a distributor — use the Avanan SmartAPI sign-in method described below. Avanan Support issues the SmartAPI key; ask them for it.
Two ways to sign in
StackJack can sign in to Avanan in one of two ways. You choose on the Avanan card, under How StackJack signs in.
- Check Point Infinity Portal — an API key you create yourself in the Infinity Portal. This is the usual way, and the sections below up to "Connect with Avanan SmartAPI" describe it.
- Avanan SmartAPI — the MSP API key that Avanan Support issues. Use it if you manage Avanan without access to the Check Point Infinity Portal, for example when your Avanan licensing comes through a distributor.
The MSP tools, which manage your customers' tenants, licences, add-ons, sub-partners, portal users and usage, always sign in with a SmartAPI key. On an Infinity Portal connection you can add the SmartAPI values as an optional section to turn those tools on.
The one thing to get right: your region
This is the single most important part of the setup, and it is the cause of nearly every failed connection.
Check Point runs Harmony Email in seven separate regions — USA, Europe, Canada, Australia, United Kingdom, United Arab Emirates and India — and runs them as genuinely independent services. They cannot see each other's data, and, crucially, the credentials themselves are regional. A Client ID and Secret Key created in the European region will never work against the Canadian one, no matter how many times you re-type them.
So when StackJack asks which region you are in, that is not a preference or a performance setting. It is part of the credential. If your connection fails and you are confident the key is correct, check the region before you regenerate anything — regenerating a perfectly good key is the most common wasted step here.
What you need
- A Check Point Infinity Portal account that administers your Harmony Email tenant
- Permission to create API keys in that portal
- To know which of the seven regions your tenant is in
Create the credentials
Sign in to the Check Point Infinity Portal at portal.checkpoint.com with an account that administers your Harmony Email tenant. Note the region while you are there.
Open Global Settings, then API Keys, and choose to create a new key.
These credentials live at the portal level, not inside the Harmony Email product screens. This trips people up constantly — if you are hunting through the Email Security interface for an API section, you are in the wrong place.
Give the key access to Email Security. When creating the key, select the Email Security (Harmony Email & Collaboration) service so the key can reach the email API.
Copy both values. Check Point shows the Secret Key once. Store it somewhere safe before you leave the page — if you lose it, you have to create a new key.
Connect it in StackJack
- Open Connectors in StackJack and choose Avanan (Check Point Harmony Email).
- Paste the Client ID and the Secret Key.
- Choose the region — the same one the key was created in.
- Save. StackJack tests the connection straight away. To test it again later, click Test on the connection's row on the Avanan card, or Re-test when the card shows Needs Attention.
If the test fails mentioning authorization, go back and check the region first.
Connect with Avanan SmartAPI
Avanan Support issues a SmartAPI key as four values: a client ID, a client secret, an MSP name and a list of scopes. StackJack supports the six SmartAPI regions: USA, Europe, Australia, Canada, United Kingdom and India. Avanan offers no SmartAPI in the United Arab Emirates region.
- Open Connectors in StackJack and choose Avanan (Check Point Harmony Email).
- Under How StackJack signs in, choose Avanan SmartAPI, and choose the region your SmartAPI key was issued for.
- Enter the four values: SmartAPI client ID (CLIENT_ID), SmartAPI client secret (CLIENT_SECRET), MSP name (NAME) and Scopes (SCOPES). Paste the scopes exactly as Avanan sent them, brackets and quotes included.
- Save. StackJack signs in to Avanan with the key before it stores anything, and shows Avanan's own message if the key is refused.
- StackJack then tests the connection. To test it again later, click Test on the connection's row on the Avanan card, or Re-test when the card shows Needs Attention.
Like the Infinity Portal key, the SmartAPI values are re-entered every time you save.
To add the MSP tools to an Infinity Portal connection instead, keep Check Point Infinity Portal selected and fill in the four values in the optional SmartAPI credentials section. Fill in all four or none.
The same two sign-in methods are offered when you give an automation its own Avanan credential.
What your AI can and cannot do
Searching always needs a time window
Check Point has no "search everything" query. Every search takes a start and an end date, and asking without one returns an error rather than all your mail. In practice this is fine — just tell your AI the period you care about ("phishing events in the last 48 hours"). It is worth knowing so an empty-handed result reads as "narrow window" rather than "nothing found".
Results come back in batches, and Check Point decides how large each batch is — you cannot ask for a specific page size. Your AI follows the batches automatically when it needs more.
Quarantine and restore are real, and people will notice
Quarantining a message removes it from the recipient's mailbox. Restoring puts it back. Both are immediately visible to the people involved, so both require the Pro tier and are marked destructive. Whether your AI application asks you to confirm before running one depends on that application's own settings — see Destructive tools and confirmation. Review those settings before you grant them.
These actions are also asynchronous: Check Point accepts the request and works on it in the background, returning a reference per message rather than a final answer. Ask your AI to check the status if you need confirmation it completed — it has a tool for exactly that.
Allow-listing weakens a control on purpose
Adding an allow-list entry tells Check Point to stop blocking something. That is sometimes exactly right — a legitimate sender caught repeatedly, a business tool flagged as risky. But it is a security decision, not a quick fix, and it is worth removing the entry once the underlying problem is solved. StackJack's tool descriptions say so explicitly, so your AI treats allow-listing as deliberate rather than routine.
The tools that delete all exceptions in a list clear the entire list in one call. Prefer the single-entry delete tools unless wiping the list is genuinely what you want.
Downloading raw message files is not available
Check Point can hand back the original .eml file for a message. StackJack does not expose that today — it returns a file rather than data your AI can read directly. Everything about the message that Check Point holds as data is available through the detail tools.
Audit logs are somewhere else
Check Point does not serve audit or system logs from this API at all; they come from the Infinity Portal's own separate APIs. If you need audit-log access, this connector is not where it will come from.
Find likely-compromised senders across your customers
Mail that fails its sender checks and gets quarantined is ordinary spoofing. Mail that passes those checks and gets quarantined anyway is different: the message really did come from the mailbox it claims, which usually means that mailbox is being used by someone else. That is the report this connector builds.
Ask for it in plain language ("show me authenticated mail that was still quarantined this week"). You get one row per message with the customer, the sender, the recipient, the subject, what Check Point decided, the sender-check results and a link to the message in Check Point. Rows are grouped per customer with a count, so the customers worth calling first are the ones at the top.
Two things to know before you rely on it.
Only the SPF result is available. Check Point's API publishes an SPF result on a message and does not publish DKIM or DMARC at all. StackJack will not guess at those: it reports them as unavailable, and an unavailable check never counts as a pass. Because the tool asks for all three by default, the first run comes back empty and tells you why. Ask for SPF only and it works: "authenticated by SPF, still quarantined, last 7 days".
Covering several customers depends on what your key can see. Check Point does not publish how a partner key targets one managed customer, so StackJack asks per customer and then checks the answer: every row is labelled with the customer the message itself belongs to, not the one that was asked about. If two customers come back holding the same customer's mail, the whole run is refused rather than published — a hot list that names the wrong companies is worse than no hot list. If that happens, run it one customer at a time.
A run is capped at about a minute of Check Point requests. If it comes back marked as truncated, narrow it — fewer days, or one customer at a time.
Ask for it as a spreadsheet ("...as CSV") and you get a download link instead of rows in the chat. The link is short-lived, so save the file when you get it; re-running the report mints a fresh one.
Plans
Troubleshooting
"Authorization" errors on a key you know is correct. The region. Almost always the region. Check that the region selected in StackJack matches the region the key was created in, then re-test before regenerating anything.
Avanan refused the SmartAPI credentials when you saved. Check all four values against what Avanan Support sent, character for character, and check that the region matches your key. The message shown is Avanan's own.
An MSP tool says the SmartAPI credentials are missing. The MSP tools always sign in with a SmartAPI key. Add the four values to the Avanan card, or switch the card to Avanan SmartAPI.
You cannot find where to create an API key. You are probably inside the Harmony Email product. Go up to the Infinity Portal itself — Global Settings, then API Keys.
A search returns nothing. Widen the time window. There is no all-time search, so a narrow window is the usual cause.
An identifier "does not exist". Message and event identifiers are not portable between Check Point regions, and older items age out of retention. Run a fresh search to get a current identifier rather than reusing one from an old conversation.
A quarantine seemed to do nothing. It is asynchronous — Check Point accepted the request and is working on it. Ask your AI to check the action status.
Several customers
Some MSPs need one Avanan connection per customer, console or region. StackJack can hold several named connections of one connector, and your AI names the one it wants on each call. See Several connections of one connector.
Full tool list
See the generated Avanan (Check Point Harmony Email) tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.
Avanan (Check Point Harmony Email) tools
avanan_ · 79 tools · Free 35 · Pro 44
Secured Entities
Security Events
Exceptions
Click-Time Protection
Anti-Malware Exceptions
URL Reputation Exceptions
DLP Exceptions
Anomaly Exceptions
MSP
Reports
Platform
More in Connector guides
Connect Acronis Cyber Protect CloudConnect Action1Connect AddigyConnect AlertOpsStill need help? Ask the team