Skip to main content
Connector guides

Connect Cork

Cork is a cyber-warranty and risk-management platform for MSPs. It pulls data from the tools you already run — RMM, EDR, MFA, Microsoft 365 — scores each client's security posture (the Cork Cyber…

Written By Christopher Scaminaci

Last updated 6 days ago

Cork is a cyber-warranty and risk-management platform for MSPs. It pulls data from the tools you already run — RMM, EDR, MFA, Microsoft 365 — scores each client's security posture (the Cork Cyber Score), tracks the compliance events that can affect warranty coverage, surfaces software vulnerabilities, and issues cyber-warranty packages per client. Newer Cork accounts can also push software installs to endpoints through a connected RMM. StackJack talks to Cork through the Cork public API.

Connecting Cork to StackJack gives your AI assistant a focused family of cork_ MCP tools — MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:

  • Review risk — client Cyber Score history and warranty status, compliance events (including which are actively at risk), and software vulnerabilities with CVE detail: CVSS and EPSS scores, known-exploited flags, and impacted versions
  • Inventory assets — the devices, email domains and inboxes Cork observes for each client, and the devices, tenants and users behind each connected integration
  • Audit coverage and billing — active warranty packages, invoices, and invoice line items
  • Manage integrations (on Pro plans) — connect a new integration, update or remove one, and trigger a data refresh
  • Install software (on Pro plans) — dispatch a package to a single device through its RMM, and review the history of past install attempts

How StackJack authenticates to Cork

Cork uses a single API key. You create the key in the Cork platform and StackJack sends it on every request as a bearer credential. There is no client ID, no sign-in redirect, and nothing to refresh.

Two things about Cork keys are worth understanding before you create one, because both shape what your AI can do:

Keys expire, and cannot renew themselves. When you create a Cork API key you choose a timeframe after which it expires. Cork has no way to renew it automatically and StackJack cannot extend it, so when the key lapses every Cork tool starts failing with an authorization error until you create a replacement and paste it in. Choose the longest expiry your security policy allows, and put the expiry date in your calendar.

A key inherits the permissions of the person who created it. Cork has no per-key permission checkboxes. Whatever the creating user can see and do in Cork is exactly what the key — and therefore your AI — can see and do. This matters most for distributor features: if you manage partner sub-accounts, the partner tools, the partner-scoped filters, and integration raw-data downloads all require a key created by a distributor user. A 403 from one tool while others succeed is almost always this, not a StackJack-side block.

Cork is a global service with one address (https://api.corkinc.com/api/v1) — there are no regional endpoints, so there is no region to choose.

Before you begin

  • In StackJack: you need a role that can manage connectors (tenant Owner, a co-owner, or an Administrator).
  • In Cork: you need access to the Cork platform with permission to create an API key — and, if you want the distributor tools, you need to be signed in as a distributor user when you create it.

Step 1 — Create an API key in Cork

  1. Sign in to the Cork platform. Sign in as the user whose access you want the key to carry — a distributor user if you manage partner sub-accounts.
  2. Open the Admin tab and select API Keys.
  3. Click Add API Key.
  4. Give the key a name (something that identifies StackJack) and choose the timeframe after which it should expire. Pick the longest expiry your policy allows — Cork cannot renew it for you.
  5. Generate the key, then copy it immediately and store it securely — treat it like a password. Anyone with the key can read and act on your Cork account.

Step 2 — Add the credential in StackJack

  1. In the StackJack portal, open Connectors.
  2. Find the Cork card. Click How To Connect for the same steps inline, or Configure to enter the key.
  3. Paste your API key. There is no client ID or URL to enter — the address is fixed.
  4. Click Save.

What happens when you save

  • The key is stored encrypted in Azure Key Vault — never in the StackJack database, and never shown back to you.
  • If this is the first time you configure Cork, a Free-tier subscription for the connector is created automatically so its Free tools work right away.
  • StackJack immediately live-validates the key by making a cheap authenticated read against your Cork account. Validation never blocks the save: you'll either see a success confirmation or a "saved but validation failed" warning with the reason.
  • The connector card shows the current connection and validity status from then on.

Plans and available tools

  • Free includes reads for clients and their devices, domains and inboxes; compliance events, notification settings and event types; software vulnerabilities and the product-level vulnerability summary; available and connected integrations plus each integration's devices, tenants and users; integration credentials and raw-data downloads; invoices and line items; partners; software-installer packages, history and setup instructions; warranties; and an account check.
  • Pro adds actions to connect, update, delete and resync an integration; provision a partner; and install software on a device.
  • Business offers the same tool set as Pro with a higher monthly call quota.

See the generated Cork tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.

Cork has no per-user sign-in for the API (the key is a single account credential), so all AI traffic authenticates as that one key — there is no per-user attribution. Current pricing and quotas are shown in the portal's Billing page and at checkout.

A note on the sensitive tools. Four Pro tools change real state outside StackJack, and StackJack marks them as sensitive: installing software on a customer's device through its RMM; updating an integration, which replaces its stored credentials in place; deleting an integration, which stops all data collection from it; and provisioning a partner, which creates a permanent billable account and by default emails the contact you name. Two read tools also deserve deliberate scoping: one returns a connected integration's credentials in plain text, and one produces a download link to an integration's full raw synced data. Cork documents that raw-data link as expiring after 10 minutes; treat it as a short-lived secret and fetch it only when needed. Both reads are separated into their own permissions so you can allow ordinary integration reads without allowing them. Whether your AI application asks you to confirm before running a sensitive tool depends on that application's own settings — see Destructive tools and confirmation. Review those settings, and use the tool selections on the MCP Setup page and the Permissions page to enable only what you want an AI to reach.

Integrations created in the Cork interface are protected. Reading, updating or deleting an integration's credentials, and downloading its raw data, only work for integrations that were created through the API. If you set an integration up in the Cork interface, Cork refuses those requests — that is Cork protecting it, not a StackJack limitation.

Software installs are asynchronous, and "success" is not "installed". An install is handed off to the device's RMM and completes on its own schedule. The install history reports the dispatch state, where success means the RMM accepted the job — not that the software finished installing on the device. A device must also be marked as install-capable in Cork before it can be targeted, and some RMM vendors need a one-time setup step in the RMM first; the setup-instructions tool returns exactly what to create.

Rate limits

Cork does not publish a numeric request limit. StackJack paces Cork requests conservatively and backs off automatically if Cork signals a rate-limit response, so a long multi-page inventory read is usually just slower. Pacing is not a guarantee: retries are bounded, so a wide enough read can still come back throttled or time out. Narrow the read, honour any retry delay the vendor sends, and check whether a write landed before repeating it — see Retrying a failed or timed-out write. Cork's API publishes a possible 429 response for manual integration refreshes but no numeric refresh quota. Cork already refreshes integrations on its own schedule, so repeated manual resyncs are normally unnecessary.

Rotating or replacing the key

The API key is the only credential, so replacing it is the whole recovery path. You will need to do this at least once, when the key reaches the expiry you chose. To replace it: create a new key in the Cork platform under Admin → API Keys, then open Connectors → Cork → Configure in StackJack, paste the new key, and Save. Nothing else needs changing.

Troubleshooting

SymptomLikely causeWhat to do
"Saved but validation failed" right after savingThe key was mis-pasted, or it has already expired or been revokedRe-copy the key from Admin → API Keys and paste it again in Connectors → Cork → Configure
Tools worked for weeks, then all started failing with an auth errorThe key reached the expiry chosen when it was created — this is the most common Cork failureCreate a new key in Admin → API Keys and update the credential in Connectors → Cork → Configure
One tool returns a 403 while others succeedThe Cork user who created the key lacks access to that areaRe-create the key as a Cork user who has that access — and as a distributor user if you need the partner or raw-data tools
Partner tools, partnerUuid filters, or the raw-data download are refusedThe key was not created by a distributor userCreate a replacement key while signed in as a distributor user
Reading, updating or deleting an integration's credentials is refusedThat integration was created in the Cork interface, not through the APIOnly API-created integrations support those operations; manage the others in Cork directly
An integration update appeared to succeed but the integration stopped syncingCredentials were updated with only some fields supplied — a partial set replaces the whole setRe-run the update supplying every credential field for that vendor
A raw-data download link stopped workingCork's signed link expired after its documented 10-minute lifetimeRun the raw-data download tool again and use the new link promptly; do not store or forward an old URL
An install reported success but the software isn't on the devicesuccess means the RMM accepted the job, not that the install finishedCheck the install history again shortly, then check the job in the RMM itself
An install is refused as needing setup or not authorizedThe RMM integration that would route the install needs its one-time setupRun the installer setup-instructions tool for that vendor and package manager, then create what it returns in the RMM
Write tools missing from your AI's tool listConnector is on the Free tier, or the tools aren't selected for your clientUpgrade the Cork connector plan and check your tool selections on the MCP Setup page
Tool calls slow down under heavy useStackJack is pacing requests towards Cork's limitsExpected under bursts. Narrow the request or reduce parallelism if it does not finish.

Cork tools

cork_ · 30 tools · Free 24 · Pro 6

Clients

ToolWhat it does
cork_list_client_devices
Free · Read-only
List the devices Cork observed for one client across every connected integration.
cork_list_client_domains
Free · Read-only
List the email domains Cork observed for one client.
cork_list_client_inboxes
Free · Read-only
List the email inboxes (user mailboxes and shared mailboxes) Cork observed for one client.
cork_list_clients
Free · Read-only
List the MSP's clients (end customers) — the ENTRY POINT for this connector.

Compliance

ToolWhat it does
cork_list_compliance_event_types
Free · Read-only
List every compliance event type Cork can raise.
cork_list_compliance_events
Free · Read-only
List the policy violations and risk events Cork detected for one client's assets — the compliance failures that can affect cyber-warranty coverage.
cork_list_compliance_notification_settings
Free · Read-only
List the notification and alerting rules configured for compliance events on one client's assets — which event types alert and how they are routed.

Vulnerabilities

ToolWhat it does
cork_get_software_vulnerability_summary
Free · Read-only
Get CVEs rolled up by software product — the triage view.
cork_list_software_vulnerabilities
Free · Read-only
List individual software vulnerabilities with full CVE detail.

Distributor

ToolWhat it does
cork_list_partners
Free · Read-only
List the partner (MSP) sub-accounts managed by this distributor.
cork_provision_partner
Pro · Destructive
DESTRUCTIVE / IRREVERSIBLE: provision a brand-new partner (MSP) account under this distributor.

Integrations

ToolWhat it does
cork_connect_integration
Pro · Write
Connect a new API-based integration, which begins syncing data immediately.
cork_delete_integration
Pro · Destructive
DESTRUCTIVE: delete an integration and stop ALL data collection from it.
cork_get_integration_credentials
Free · Read-only
Get one integration's stored credentials.
cork_get_integration_raw_data
Free · Read-only
Get a presigned download URL for one integration's RAW synced data.
cork_list_available_integrations
Free · Read-only
List the integration types that CAN be connected to Cork, each with its vendor block ({key, name, type}) and its credential_fields schema.
cork_list_connected_integrations
Free · Read-only
List the integrations already connected to Cork.
cork_list_integration_devices
Free · Read-only
List the devices observed from ONE integration (the vendor's own view, before Cork maps them onto clients — use cork_list_client_devices for the client-side view).
cork_list_integration_tenants
Free · Read-only
List the customer tenants observed from ONE integration — the upstream vendor's own tenant/organisation records (e.g. an RMM's client list), which Cork maps onto its own clients.
cork_list_integration_users
Free · Read-only
List the users observed from ONE integration (e.g. the identity/MFA/M365 accounts the vendor reports).
cork_resync_integration
Pro · Write
Manually trigger a data refresh for ONE integration — useful when last_synced_at from cork_list_connected_integrations is stale or connection_status has recovered from degraded/down.
cork_update_integration
Pro · Destructive
Update an API-created integration's display name and/or credentials.

Invoices

ToolWhat it does
cork_list_invoice_line_items
Free · Read-only
List the billed, TOP-LEVEL line items for one invoice.
cork_list_invoices
Free · Read-only
List Cork billing invoices.

Account

ToolWhat it does
cork_who_am_i
Free · Read-only
Return information on the Cork user the API key authenticates as — the response carries name.

Software Installer

ToolWhat it does
cork_get_installer_setup
Free · Read-only
Get the ONE-TIME setup steps for an RMM vendor that needs manual setup before Cork software installs work through it.
cork_install_software
Pro · Destructive
DESTRUCTIVE: install a software package on a SINGLE mapped device by dispatching the job through that device's RMM integration (Intune, NinjaRMM, Datto RMM).
cork_list_installer_history
Free · Read-only
List past software-install attempts, MOST RECENT FIRST — this is how you follow up an asynchronous cork_install_software call, which returns 202 with no body.
cork_list_software_packages
Free · Read-only
List the software packages available to install across the supported package managers (WinGet and Chocolatey).

Warranties

ToolWhat it does
cork_list_warranties
Free · Read-only
List ACTIVE cyber-warranty packages.