Connect Action1
Action1 is a cloud-native patch management, vulnerability scanning, and endpoint automation platform. Connecting it to StackJack lets your AI assistant work with your Action1 enterprise through MCP…
Written By Christopher Scaminaci
Last updated About 22 hours ago
Action1 is a cloud-native patch management, vulnerability scanning, and endpoint automation platform. Connecting it to StackJack lets your AI assistant work with your Action1 enterprise through MCP tools — the standardized tool calls (Model Context Protocol) that AI harnesses like Claude or ChatGPT use to act on your behalf. Once connected, your AI can list endpoints, review vulnerabilities and patch status, inspect automations, and (on paid plans) run write operations such as managing automation schedules and deploying agents.
The Action1 tool family uses the action1_ prefix. Read and reporting tools are available on the Free plan; write tools (including automation management) and composite analytics tools (fleet-wide summaries and rollups) require a Pro or Business plan for the Action1 connector. See the generated Action1 tool reference for the current inventory, input schemas, plan tiers, and safety notes.
Before you begin
You will need:
- A StackJack role that can manage connectors: tenant Owner, co-owner, or Administrator. Plain Members cannot add or edit connector credentials.
- Permission to manage Users & API Credentials and assign Action1 roles.
- To know which region your Action1 account is hosted in: US (
app.action1.com), EU (app.eu.action1.com), or AU (app.au.action1.com). Check the address bar when you log in to Action1 — the credentials you create only work against their home region.
Action1 API credentials are non-interactive identities, separate from human user accounts. Assign the credential a least-privilege role when you create it; you can assign additional roles later if your StackJack workflows need them.
Step 1: Create API credentials in Action1
- Log in to the Action1 console as an administrator, in your home region.
- Go to Configuration > Users & API Credentials.
- Click + New API Credentials, enter a recognizable name, and select the least-privilege role that covers the tools you intend to enable. Action1 lets you assign additional roles later.
- Action1 generates two values:
- a Client ID in email format (it looks like
api-key-...@action1.com— this is normal, it is an identifier, not a mailbox), and - a Client Secret.
- a Client ID in email format (it looks like
- Copy both values immediately. The secret is not shown after the pop-up closes — if you lose it, create new credentials.
Step 2: Add the credentials in StackJack
- In the StackJack portal, go to Connectors.
- Find the Action1 card. Click How To Connect if you want the guided walkthrough of Step 1, or go straight to Configure.
- In the configuration dialog:
- Click Save.

What happens when you save
- Your credentials are stored encrypted in Azure Key Vault — they are never written to the StackJack database.
- StackJack immediately tests the credentials against Action1. If the test fails, your credentials are still saved and you'll see a "saved, but validation failed" message with the reason so you can correct it.
- A Free subscription for the Action1 connector is created automatically, so the Free-tier tools appear in your AI harness right away. Upgrade from the connector card whenever you're ready — current pricing is shown in the portal at checkout.
Ongoing token handling — nothing for you to do
Action1 uses short-lived access tokens (about an hour) with rotating refresh tokens behind the scenes. StackJack refreshes these automatically and safely in the background — you never re-enter credentials unless you revoke or regenerate them inside Action1.
Health monitoring
StackJack periodically re-validates the connection. If it fails definitively three times in a row (for example, because the credentials were revoked in Action1), the connector is automatically disabled and the tenant owner is emailed. The connector card then shows the error details along with Re-enable and Update Credentials buttons. (A card that is failing validation but not yet disabled shows a Re-test button instead.)
What your AI can do once connected
- Free plan: read and reporting tools — list organizations, endpoints, endpoint groups, installed software, updates, vulnerabilities, automations, scripts, reports, and the audit trail.
- Pro / Business plans: everything in Free, plus write tools (create/update/delete automation schedules, apply automations, manage deployment settings and deployers, and more) and composite analytics tools such as vulnerability summaries, patch-compliance rollups, and endpoint health rollups.
- Business includes the same tool set as Pro; higher plans mainly raise your monthly usage allowance.
Two usage notes worth passing to whoever drives the AI:
- Organizations first. Action1 supports multiple organizations inside one enterprise, and almost every operational tool needs an organization ID. The AI should call
action1_list_organizationsfirst to discover them. - Usage caps. Each connector subscription has a monthly tool-call allowance. The connector card, Dashboard, and checkout show the current allowance for your plan. There is no separate per-minute StackJack burst limit on MCP calls; the monthly allowance is the StackJack-side enforcement point.
Rate limits toward Action1
Action1 does not publish an API rate limit, so StackJack conservatively paces outbound requests to Action1 at 60 requests per minute per tenant. Heavy multi-step AI sessions are slowed by that pacing, which keeps an AI session from flooding your Action1 enterprise. Pacing is not a guarantee: retries are bounded, so a wide enough read can still come back throttled or time out. Narrow the read, honour any retry delay the vendor sends, and check whether a write landed before repeating it — see Retrying a failed or timed-out write.
Troubleshooting
Per-user access
Action1 does not support per-user sign-in through StackJack — the connector uses one shared API-credential identity for the whole tenant, and all tool calls run under that credential's assigned roles. See Shared vs. per-user credentials for the current list of connectors that support personal attribution.
Disconnecting
Disconnect on the Action1 card deletes the stored credentials from Key Vault, and Action1 calls on that connection stop working immediately. Where the card holds several connections, the others keep working and the connector stays connected until you remove the last one.
Whether Action1's tools disappear from your AI's tool list is a separate choice rather than an automatic consequence. On the last connection of a Free connector the dialog offers to remove them, with the box selected by default. On a paid connector the tools stay listed and billing continues: disconnecting does not cancel a paid Action1 subscription. The plan controls only appear while the connector is connected, so end the plan before disconnecting. On a paid connector that button reads Manage on Billing and opens this connector's removal dialog on the Billing page; a legacy website subscription still reads Cancel Plan. If you've already disconnected, save your credentials again to bring the plan controls back, then end the plan. See Disconnecting a Connector for what else a removal reaches.
Action1 tools
action1_ · 144 tools · Free 73 · Pro 71
Organizations
Enterprise
Users
Roles & Permissions
Endpoints
Endpoint Groups
Remote Sessions
Agent Deployment
Data Sources
Scripts
Settings
Report Definitions
Report Data
Software Repository
Updates / Patches
Installed Software
Action Templates
Automations
Vulnerabilities & CVEs
Audit Trail
Subscription & Usage
Report Subscriptions
Search
Diagnostics
Analytics
More in Connector guides
Connect AlertOpsConnect Alloy NavigatorConnect AteraConnect Autotask PSAStill need help? Ask the team