Connect Axcient
Axcient builds backup and continuity products for MSPs, and one Axcient API key reaches four of them through StackJack:
Written By Christopher Scaminaci
Last updated 6 days ago
Axcient builds backup and continuity products for MSPs, and one Axcient API key reaches four of them through StackJack:
- x360Recover — business continuity and disaster recovery. It backs your customers' servers and workstations up to an on-premises appliance, to the Axcient cloud, or straight to the cloud with no appliance at all, which Axcient calls direct-to-cloud. It also verifies that what it backed up can actually be restored, by booting a recovery point and checking that the machine comes up.
- x360Cloud — cloud-to-cloud backup of your customers' Microsoft 365 and Google Workspace data: mailboxes, OneDrive, SharePoint sites and shared drives.
- x360Sync — file sync and share: synced folders, the people and guests who use them, the machines that sync, and the share links that hand files to people outside the organization.
- Billing — the usage Axcient counts for you and each of your customers across the suite.
Connecting Axcient to StackJack gives your AI assistant a family of axcient_ MCP tools — MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:
- Find failed backups — read an x360Recover backup job's run history filtered to failures, or list the x360Cloud customers whose latest Microsoft 365 or Google Workspace backup failed, so "which backups failed last night, and for whom" is one question rather than an afternoon in two consoles
- Check that backups are restorable — read AutoVerify results, which answer whether a recovery point actually boots, not just whether the job finished
- See how far back you can recover — list a protected system's restore points, grouped by the cloud vault each one replicated to, or a cloud customer's backup history day by day
- Audit the estate — protected systems across the whole organization or per client, the Microsoft 365 and Google Workspace users selected for protection, and the SharePoint sites and shared drives Axcient backs up
- Review file sharing — which files and folders an x360Sync organization shares by link, who created each link, and who has had files shared with them
- Watch the plumbing — appliance tunnel status and health, vault state, the connectivity thresholds that decide when Axcient warns you, and the machines syncing with x360Sync
- Report on storage and usage — per-client local and cloud consumption, x360Sync space usage, and Axcient's own actual and billable usage for you and each customer, for capacity planning and for checking a bill against reality
- Change vault alerting (on Pro plans) — set a vault's connectivity threshold
- Enroll direct-to-cloud agents (on Pro plans) — create the token a new direct-to-cloud agent uses to register itself against a client's vault
Everything except those last two is a read.
How StackJack authenticates to Axcient
Axcient uses a single API key that you generate in x360Portal and paste into StackJack. The same key reaches x360Recover, x360Cloud, x360Sync and Billing — there is no second key for any of them. There is no client ID, no second secret, no sign-in redirect, and nothing that expires on a schedule — the key stays valid until an administrator deletes it.
There is one address for everyone. Axcient does not run regional instances and does not give you a subdomain of your own, so there is no URL for you to enter or get wrong.
Before you generate a key, know what it reaches
Axcient API keys carry no scopes and no roles. One key reaches everything your organization can see in every Axcient product: every client, protected system, backup job and vault, every cloud customer and their users, every x360Sync organization and its share links, and your usage figures. There is no way to create a read-only key, or a key limited to one client or one product.
Two consequences worth planning around:
- Create a key just for StackJack. If you ever need to cut StackJack off, or you suspect a key was exposed, you want to delete one key rather than the key your other integrations are also using.
- Other administrators can see it. Any administrator in your Axcient organization can view or delete a key that any other administrator created. Treat the key as shared organizational property, not as personal to you.
Steps
- Sign in to x360Portal as an organization administrator. Only an administrator can create API keys.
- Go to Settings, then API Keys. This page lists every key in your organization and is where new ones are created.
- Generate a key with a descriptive name, for example "StackJack Integration", so a future administrator can tell what it is for before deciding whether to delete it.
- Copy the key and treat it as a password.
- Paste it into StackJack on the Axcient connector, and run a Test Connection.
- If you use x360Sync, add your x360Sync company ID in the optional field on the same form. See the next section for why and how to find it.
The connection test reads your x360Recover organization record, which is the smallest call the API offers. If your organization only has x360Cloud and x360Recover refuses the key, the test tries x360Cloud instead. If either answers, your key is live. The test never touches x360Sync or Billing, so a product you do not license cannot make a good key look broken.
Your x360Sync company ID
Every x360Sync list is organized by company, and Axcient offers no call that lists your companies without already knowing one of them. So the x360Sync tools need your x360Sync company ID — a whole number, such as 12345. It is not the same as your x360Recover client numbers or your x360Cloud client names.
You can give it to StackJack in either of two ways:
- Save it on the connector, in the optional "x360Sync company ID" field. The x360Sync tools then use it whenever a request does not name another company.
- Let your AI assistant pass it on each request. This is how you reach a customer's own x360Sync organization rather than yours.
To find it, ask your AI assistant to look up your own x360Sync account by your x360Sync admin email address. The answer includes a company ID, and that is your organization. If you use x360Recover or x360Cloud only, leave the field blank — nothing else needs it.
Working with Axcient through your AI assistant
A few things about this API shape how a request should be phrased, and all of them are worth knowing before you wonder why an answer came back empty.
Each product has its own identifiers. x360Recover clients, devices, vaults, appliances, users and jobs are whole numbers. x360Cloud client organizations are short text names such as sandmanandpartners, and x360Cloud users can be looked up by email address. x360Sync organizations, accounts, guests, machines and groups are whole numbers of their own, and accounts and guests can also be looked up by email. None of these line up with each other — the same customer has a different identifier in each product. Naming the customer and the product in your request lets your assistant look the right identifier up first.
x360Recover devices do not know which client they belong to. The organization-wide list of protected systems does not carry a client identifier, but every backup-job tool needs one. So the path from "a device I found" to "that device's backup history" runs through the client list: ask for the clients, then that client's devices, then that device's jobs. Your AI assistant will normally do this on its own, but a question phrased as "show me the backup history for FILESERVER01" may need the customer's name in it too.
Dates are written differently per product. x360Recover filters use Unix timestamps, x360Cloud backup history takes calendar dates or date-times such as 2025-01-11, and Billing takes calendar dates. Your assistant handles the conversion; it only matters if you are reading the raw answers yourself.
Long lists come in pages. x360Cloud lists return 20 results at a time by default, and StackJack asks for at most 100 at once. x360Sync lists come in pages Axcient sizes itself. Either way, your assistant asks for the next page when it needs more.
Direct-to-cloud machines are not a separate product or a separate connection. They are protected systems with a flag set, so they appear in the same lists, and you can ask for only those.
x360Sync share links are live links
A share link is a URL that opens a file or folder, and some x360Sync share links open without signing in at all — a few even allow editing. The tools that list or read share links return those URLs, so treat what they return the way you would treat the link itself: do not paste it into a ticket, a chat, or anywhere it will be logged or forwarded. The same goes for the list of x360Sync root folders, whose entries carry the same kind of code a share link is built from.
StackJack never saves these answers to a temporary download link and never keeps them in test recordings. If a share-link answer is too large to return in one piece, StackJack refuses it rather than storing it.
What each plan reaches
Read tools are available on the Free tier — that includes every x360Cloud, x360Sync and Billing tool. The two tools that change your Axcient configuration are Pro, and both are x360Recover tools. Business reaches the same tools as Pro and differs by monthly call quota.
See the generated Axcient tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.
The two tools that change something
Both are labeled destructive. Whether your AI application asks you to confirm before either one runs depends on that application's own settings — see Destructive tools and confirmation. Review that setting before you grant them.
Setting a vault connectivity threshold replaces the current value rather than adjusting it. The threshold is how long a vault may go without contact before Axcient warns you it has lost connectivity, so raising it makes Axcient quieter — and a large enough value suppresses the warning that tells you backups have stopped arriving. Read the current value first so you can put it back.
Creating a direct-to-cloud agent token mints a new enrollment credential and hands it back. Anyone holding that token can enroll a machine into that client's vault, so treat the result the way you would treat a password: do not paste it into a ticket, a chat, or anywhere it will be logged. Ask for one when you are about to install an agent, not to see what one looks like.
Axcient names this operation as though it only reads an existing token. It does not — it creates one. StackJack names it "create" for that reason.
Rate limits
Axcient publishes no rate limit for any of its products. StackJack paces requests conservatively — one shared allowance across all four products, because it is one key — and backs off if Axcient throttles it, which usually turns a large report into a slower one. Pacing is not a guarantee: retries are bounded, so a wide enough report can still come back throttled or time out. Narrow the report, honour any retry delay Axcient sends, and check whether a write landed before repeating it — see Retrying a failed or timed-out write. If you see throttling in normal use, tell us — we would like to know the real number too.
Troubleshooting
"Axcient rejected the API key" — the key is wrong, or it was deleted in x360Portal. Remember that another administrator can delete a key you created, so a connection that worked yesterday and fails today is worth checking against the API Keys page before you assume anything is broken. Generate a new key, paste it into StackJack, and run a Test Connection. Because one key serves every product, this answer means the same thing whichever product you asked about.
"Axcient accepted the request but refused it" — on an x360Recover request, this is not a verdict on your key, and there are two causes rather than one. Either something in front of the Axcient API blocked the request before it arrived, or your Axcient organization is suspended or out of contract. In x360Portal, check that the organization is active and that the key still exists. If both are fine, the refusal came from Axcient's side rather than from anything you can change, so contact Axcient support.
"Axcient refused access to that x360Cloud client organization" — the key works, but your account has no access to the cloud customer you named. List your x360Cloud customers and use a name from that list; x360Cloud customer names are short text names, not x360Recover client numbers.
"Axcient could not find that x360Cloud record" or "…x360Sync record" — either the identifier does not exist, or that product is not licensed on your x360Portal account. If one request fails this way, check the identifier. If every request to that product fails this way, your organization probably does not have it.
"x360Sync needs a company ID" — no company was named in the request and none is saved on the connector. Save your x360Sync company ID on the Axcient connector, or name the company in the request. See Your x360Sync company ID.
A request failed saying an identifier is not a number — an identifier was passed as a name. Name the customer or the machine and let your assistant look the number up first. On x360Recover the one exception is the ASIO endpoint identifier, which really is a GUID rather than a number, and is there for estates that also use Kaseya tooling. On x360Sync, check that the identifier is an x360Sync one rather than an x360Recover number.
Backup jobs come back empty for a device you can see — you almost certainly reached the device through the organization-wide list, which carries no client identifier. Start from the client instead.
A client's backups stopped and nothing looks wrong — check the appliance tunnel status for an on-premises client, and the vault for a direct-to-cloud one. A tunnel that is down and a vault that has lost connectivity both look like a quiet night from the job list alone.
AutoVerify results are missing for a machine that backs up fine — AutoVerify is a separate feature from the backup itself and is not enabled on every protected system. A backup that runs is not automatically a backup that has been tested.
Billing shows no x360Sync figures — Axcient's usage reports cover x360Recover and x360Cloud today; Axcient says x360Sync figures are coming later. Use the x360Sync usage tool for an organization's x360Sync storage in the meantime.
A note on the rest of the Axcient product family
Axcient also publishes an API for distributors. This connector does not include it: it has no published address, it is meant for distributor accounts rather than MSPs, and Axcient's own AI connector leaves it out too. If it would be useful to you, tell us.
Axcient tools
axcient_ · 53 tools · Free 51 · Pro 2