Connect ConnectWise Platform (Asio)
ConnectWise Platform — the product MSPs still call Asio — is ConnectWise's RMM platform. It is where your endpoints report in, where policies, patching and automation run, and where ConnectWise's NOC…
Written By Christopher Scaminaci
Last updated 6 days ago
ConnectWise Platform — the product MSPs still call Asio — is ConnectWise's RMM platform. It is where your endpoints report in, where policies, patching and automation run, and where ConnectWise's NOC and SOC services open tickets and security cases on your behalf. StackJack talks to it through the ConnectWise Platform Partner API.
This is a different connector from ConnectWise PSA (Manage) and ConnectWise Automate. They use different credentials and reach different products, and you can connect any combination of them.
Connecting ConnectWise Platform to StackJack gives your AI assistant a family of cwp_ MCP tools —
MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through
StackJack. With them, your AI can:
- Find and inventory endpoints — search across every endpoint category, read an endpoint's details, services, installed applications, users, heartbeat, disk, memory and CPU, and the remote sessions open against it
- Check patching — OS and third-party patch compliance by company, site or endpoint, patch detail and the patch inventory
- Read policies — policies, policy groups and packages, where each is assigned, and the effective policy an endpoint actually runs
- Run automation (on Pro plans) — list scripts and tasks, schedule a task on endpoints, and read the results of each run
- Manage companies and sites — list and read them, and create or change them on Pro plans, along with custom field definitions and values
- Work NOC tickets — search tickets with filters, read notes and the ticketing lookups, and create and update tickets and notes on Pro plans
- Investigate security cases — Security Dashboard cases, their alerts, indicators of compromise, impacted entities, MITRE techniques, timelines and comments, and endpoint vulnerabilities
- Look after backups — Cloud Backup subscriptions, retention, storage, mailboxes and alerts, and the Backup Dashboard's jobs, disaster-recovery readiness and alarms
How StackJack authenticates to ConnectWise Platform
You generate an API key in ConnectWise Platform. It gives you a Client ID and a Client Secret, and you paste both into StackJack along with the region your account lives in. StackJack exchanges the pair for a token that lasts about an hour and reuses it until it expires. You never see it.
What the key may do is decided in ConnectWise, not in StackJack
When you generate the key, ConnectWise asks you to tick its scopes — for example Platform - Devices
- Read or Platform - Tickets - Update. Those scopes are the real limit on what StackJack can do: a key with only Read scopes produces read-only behavior no matter what an AI assistant is asked to do. That is a useful safety control, and it is the one we recommend you start with.
Each tool's description names the scope it needs. If a tool comes back saying your key's scopes do not cover it, add that scope to the key in ConnectWise — the Client ID and Client Secret are fine and do not need regenerating. A token StackJack already holds keeps the scopes it was issued with until it expires, so a newly added scope can take up to an hour to start working.
Give StackJack a key of its own
ConnectWise issues one token per key and refuses a new one until the current one expires. If another integration or script uses the same key, one of them will be locked out for up to an hour at a time. Generate a key just for StackJack.
If a connection ever reports that ConnectWise is refusing a new token, it recovers on its own once the old token expires. Do not regenerate the key for that — regenerating replaces both the Client ID and the Client Secret, and every integration using the old pair stops.
Pick your region
ConnectWise Platform runs in three regions — North America, Europe and Australia — and your account lives in exactly one of them. There is no default: a key only works in its own region, and the wrong region is refused in exactly the same way as a wrong secret. If Test Connection fails and the secret is right, check the region first.
Steps
- Check your permissions. You need Primary Admin or Primary Super Admin in ConnectWise Platform, or an application role that holds both API Access - Update and API Access - View.
- Open API Access. In ConnectWise Platform, go to Integrations, then API Access, and use the API Keys tab. The PSA API Members tab on the same screen is for the separate ConnectWise PSA connector.
- Generate the key. Click Generate API Access, give it a name and a description, tick the scopes StackJack should have, tick the consent box and generate.
- Copy both values immediately. ConnectWise shows the Client Secret exactly once. Copy it and the Client ID before you close the panel, and treat the secret as a password.
- Enter the details in StackJack. Open Connectors, choose ConnectWise Platform (Asio), pick your region, and paste the Client ID and Client Secret. Leave the optional Scopes box empty unless your ConnectWise documentation tells you to name the scopes when requesting a token; if it does, paste the scope IDs separated by spaces.
- Run a Test Connection. A failure here is almost always the secret truncated on copy, or the wrong region.
When you come back to edit a saved connection, the Client Secret box starts blank on purpose; leaving it blank keeps the secret you already stored.
Tiers
- Free — every read: endpoint search and detail, patching, policies, automation history, companies, sites and custom fields, tickets and notes, security cases, vulnerabilities, Cloud Backup and the Backup Dashboard.
- Pro — every change: creating and changing companies, sites, contacts, custom fields, tickets, notes and tags, renaming endpoints, and changing a security case's status; and equally the changes that reach people, spend money or act on live machines.
- Business — the same tool set as Pro with a higher monthly call quota.
These changes are marked destructive, and whether your AI application asks you to confirm before running one depends on that application's own settings — see Destructive tools and confirmation:
- Anything that reaches ConnectWise staff. Creating a ticket, adding a ticket note and commenting on a security case are read and acted on by ConnectWise's NOC and SOC teams, and cannot be recalled.
- Anything that acts on live machines. Uninstalling the agent from endpoints, moving endpoints to another company or site, and scheduling an automation task.
- The agent install token. It hands back a live credential that enrolls a machine into your ConnectWise account. Treat what it returns as a password.
- Cloud Backup orders and access. Creating a subscription, placing, activating, suspending or cancelling an order, granting or revoking a customer's portal access, moving a subscription's storage, and completing an alert (ConnectWise cannot reopen one).
- Wholesale replacements and deletes. Replacing a company, site, ticket, note, tag or custom field definition, changing a company or site with a patch that can remove fields, deleting a tag, and deleting a custom field definition — which removes every value stored against it.
See the generated ConnectWise Platform (Asio) tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.
Paging and limits
Most lists come back complete. The larger ones are paged:
- Endpoints, companies, patch compliance and the Backup Dashboard return up to 500 records per page. ConnectWise puts the marker for the next page outside the data it returns, so these tools take an optional switch that hands your assistant that marker beside the page. Left off, the answer is exactly what ConnectWise sent.
- Security Dashboard lists return up to 100 records per page (comments, up to 50) with the next-page marker inside the page.
- The ticket list is paged by page size and page number together; start at page 1 and use the total count it returns.
ConnectWise does not publish a request quota, so StackJack paces requests conservatively and backs off on
its own if ConnectWise throttles it. cwp_get_rate_limits shows each of your current limits and when it
resets. When nothing matches a Security Dashboard filter, ConnectWise answers "no records found", which
means an empty result, not a broken connection.
Troubleshooting
- "ConnectWise Platform did not accept the Client ID and Client Secret." Check the pair and the region. If the key was regenerated or disabled in ConnectWise, both values changed; paste the new pair.
- "ConnectWise Platform refused a new token because the current one has not expired yet." Another integration is using the same key, or a token is still live from a moment ago. It recovers on its own within the hour; give StackJack a key of its own if it keeps happening.
- "ConnectWise Platform accepted the API key but its scopes do not cover this operation." Add the scope the tool names to the key in ConnectWise. It can take up to an hour to apply to a token StackJack already holds. If the Scopes box on your StackJack connection lists scopes, add the scope there too.
The term 'ConnectWise' is a trademark of ConnectWise, LLC. This application uses the ConnectWise API but is not endorsed or certified by ConnectWise.
ConnectWise Platform (Asio) tools
cwp_ · 144 tools · Free 105 · Pro 39
Companies & Sites
Contacts
Custom Field Values
Custom Field Definitions
Devices
Remote Sessions
Agent Install Tokens
Device Groups
Policies
Automation
Patching
Tickets
Alert Suspensions
Vulnerabilities
Security Cases
Cloud Backup
Cloud Backup Orders
Backup Dashboard
Platform
More in Connector guides
Connect Acronis Cyber Protect CloudConnect Action1Connect AddigyConnect AlertOpsStill need help? Ask the team