Skip to main content
Connector guides

Connect Huntress

Huntress is a managed security platform for SMBs and the MSPs that serve them. It combines managed EDR (endpoint detection and response), identity threat detection for Microsoft 365 (ITDR), External…

Written By Christopher Scaminaci

Last updated 6 days ago

Huntress is a managed security platform for SMBs and the MSPs that serve them. It combines managed EDR (endpoint detection and response), identity threat detection for Microsoft 365 (ITDR), External Recon, and a 24/7 human Security Operations Center (SOC) that investigates suspicious activity and writes actionable Incident Reports.

Connecting Huntress to StackJack gives your AI assistant huntress_ MCP tools. See the generated Huntress tool reference for the current inventory, input schemas, plan tiers, and safety notes. MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:

  • Inventory deployed agents and protected identities across all your organizations
  • Review SOC-authored Incident Reports and the remediations they recommend
  • Triage Escalations and Platform Actions that need a human decision
  • Investigate raw Signals (the detections that feed investigations)
  • Audit organizations, user memberships and roles, External Recon exposed ports, and Unwanted Access rules
  • Reconcile billing — invoices and summary reports, plus reseller usage if you're a reseller
  • Act (on Pro plans) — isolate or uninstall agents, approve or reject remediations, resolve incident reports and escalations, manage organizations and memberships, and run SIEM queries

How StackJack authenticates to Huntress

Huntress issues API credentials as a pair: an API Key (the public half) and an API Secret Key (the private half). StackJack sends them with every request; there is no OAuth flow and nothing to refresh. The base URL is fixed (Huntress is a global SaaS with no regional endpoints), so the key pair is all you enter.

The key pair inherits the visibility of the Huntress account it was generated in — it can see all organizations and agents visible to that account.

Before you begin

  • In StackJack: you need a role that can manage connectors (tenant Owner, a co-owner, or an Administrator).
  • In Huntress: you need administrator access to your Huntress portal and a dedicated user whose permissions match what StackJack should be allowed to do.
  • Decide whether you need write access. Huntress recommends user-based credentials, which mirror the selected user's permissions. See "Read-only vs write-capable keys" below before generating.

Step 1 — Generate API credentials in Huntress

  1. Sign in to your Huntress portal as an administrator.
  2. Open the hamburger menu in the upper-right corner and choose API Credentials.
  3. In User API Credentials, click Add.
  4. Select the dedicated least-privilege user, enter a descriptive Key Name such as StackJack, and click Add.
  5. Copy both the API Key and Secret from the new credential box and store them securely. Huntress shows the full credential only once; if you lose it, delete that credential and create a replacement.

Read-only vs write-capable keys

Huntress's recommended User API Key mirrors the selected user's permissions. It can support read-only or write APIs depending on that user's role. To use Pro write tools — isolating hosts, approving remediations, resolving escalations, managing organizations and memberships, or SIEM queries — the selected user must have the corresponding Huntress permission. A key calling an operation its user cannot perform gets an authorization error from Huntress, even on a Pro plan.

The older Account API Key is deprecated, limited to one per account, and read-only. Existing account keys continue to suit read-only use, but create a least-privilege user key for new StackJack setups.

Reseller accounts

If you are a Huntress reseller (you manage billing and a portfolio of downstream accounts), generate the credentials from your reseller account. Reseller credentials unlock two extra tool families:

  • Managed Accounts — read a downstream account's agents, signals, incident reports and remediations, External Recon ports, invoices, organizations, memberships, and summary reports by passing its account ID (discover IDs with huntress_list_managed_accounts).
  • Reseller Billing — read reseller invoices, usage line items, and subscriptions.

A standard (non-reseller) key still works for every regular tool; it just can't call the Managed-Account or Reseller-Billing tools.

Step 2 — Add the credentials in StackJack

  1. In the StackJack portal, open Connectors.
  2. Find the Huntress card. Click How To Connect for the same steps inline, or Configure to enter the credentials.
  3. Paste the API Key (Public) and the API Secret Key (Private). There is no URL to enter — the base URL is fixed at https://api.huntress.io.
  4. Click Save.

What happens when you save

  • The keys are stored encrypted in Azure Key Vault — never in the StackJack database, and they are never shown back to you.
  • If this is the first time you configure Huntress, a Free-tier subscription for the connector is created automatically so its Free tools work right away.
  • StackJack immediately live-validates the credentials by calling the Huntress account endpoint. Validation never blocks the save: you'll either see a success confirmation or a "saved but validation failed" warning with the reason.
  • The connector card shows the current connection and validity status from then on.

Plans and available tools

  • Free includes the read tools: agents, identities, incident reports and remediations, escalations, platform actions, signals, organizations, memberships, invoices, External Recon ports, and summary reports — plus the Managed-Account and Reseller-Billing read families if you're a reseller.
  • Pro adds the write/action tools: isolate and release agents, update agent tags, uninstall agents, resolve incident reports, approve/reject remediations, resolve escalations, create/update/delete organizations and memberships, manage Unwanted Access rules, run SIEM queries, and (for resellers) manage downstream accounts and subscriptions.
  • Business offers the same tool set as Pro with a higher monthly call quota.

Huntress has no per-user sign-in flow, so there is no per-user attribution — all AI traffic uses the shared key pair. Current pricing and quotas are shown in the portal's Billing page and at checkout.

Safety note: some Pro actions change security state irreversibly. In particular, uninstalling an agent removes the Huntress sensor from the endpoint and stops monitoring — reinstalling requires a fresh deployment. Scope your AI's access deliberately: use the tool selections on the MCP Setup page and the Permissions page to enable only the actions you want an AI to take, and consider keeping a read-only key unless you specifically need response actions.

Rate limits

StackJack paces Huntress calls at 50 requests per minute per tenant and backs off when Huntress throttles, so a burst is slowed rather than sent all at once and a long multi-page inventory read is usually just slower. Pacing is not a guarantee: retries are bounded, so a wide enough read can still come back throttled or time out. Narrow the read, honour any retry delay the vendor sends, and check whether a write landed before repeating it — see Retrying a failed or timed-out write.

For the code-derived inventory of currently shipping Huntress tools, parameters, plan tiers, and safety flags, see the generated Huntress tools reference. It is the canonical tool list; this setup guide intentionally does not duplicate it.

Rotating or replacing the keys

Huntress allows multiple user-based credentials, so rotate without a gap:

  1. In API Credentials → User API Credentials, add a replacement credential for the same dedicated user and copy both values.
  2. Update Connectors → Huntress → Configure in StackJack with the replacement pair and run Re-test.
  3. After validation succeeds, delete the old Huntress credential.

Troubleshooting

SymptomLikely causeWhat to do
"Saved but validation failed" right after savingKey or Secret mis-pasted, deleted credential, or mismatched valuesCreate a replacement user credential if needed and paste both values from the same credential box
Every Huntress call fails after working previouslyThe saved Huntress credential was deletedAdd a replacement user credential and update StackJack
Write tools return an authorization error while reads workThe key is a deprecated read-only account key, or the selected user lacks that write permissionCreate or update a least-privilege Huntress user with the required permission, then create a user API credential for it
Managed-Account or Reseller-Billing tools failThe credentials come from a standard (non-reseller) accountGenerate credentials from your reseller account
Write tools missing from your AI's tool listConnector is on the Free tier, or the tools aren't selected for your clientUpgrade the Huntress connector plan and check your tool selections on the MCP Setup page
A tool reports the SIEM query is unavailableThe Huntress SIEM product isn't enabled on your accountEnable SIEM in Huntress or skip huntress_query_siem

Huntress tools

huntress_ · 92 tools · Free 55 · Pro 37

Account

ToolWhat it does
huntress_get_account
Free · Read-only
Get the Huntress account associated with the current API credentials — name, subdomain, status, and high-level account metadata.
huntress_get_actor
Free · Read-only
Get the actor for the current API credentials — the set of entities (account, organizations, permissions) the key is authorized to act as.

Agents

ToolWhat it does
huntress_get_agent
Free · Read-only
Get a single Huntress agent by its numeric ID — full host detail, OS, platform, version, last-seen, and organization.
huntress_isolate_agent
Pro · Destructive
Network-isolate a Huntress agent's endpoint, cutting it off from the network except for Huntress communication.
huntress_list_agents
Free · Read-only
List Huntress agents (deployed endpoint sensors) across the account.
huntress_release_agent_isolation
Pro · Destructive
Release network isolation on a Huntress agent's endpoint, restoring normal network connectivity.
huntress_uninstall_agent
Pro · Destructive
Uninstall the Huntress agent from an endpoint.
huntress_update_agent
Pro · Write
Update a Huntress agent — set its tags and/or tamper-protection-configured flag.

Identities

ToolWhat it does
huntress_get_identity
Free · Read-only
Get a single ITDR identity by its numeric ID — full user detail, risk level, MFA status, and tenant.
huntress_list_identities
Free · Read-only
List ITDR identities (Microsoft 365 / Google Workspace users) monitored by Huntress.

Incident Reports

ToolWhat it does
huntress_approve_remediations
Pro · Destructive
Approve the remediations recommended for a Huntress incident report, authorizing Huntress to apply them.
huntress_get_incident_report
Free · Read-only
Get a single incident report by its numeric ID — full threat detail, indicators, severity, status, and SOC narrative.
huntress_get_remediation
Free · Read-only
Get a single remediation by its ID, scoped to its parent incident report — full remediation detail, type, and status.
huntress_list_incident_reports
Free · Read-only
List incident reports — confirmed threats triaged by the Huntress SOC.
huntress_list_remediations
Free · Read-only
List the remediations attached to a specific incident report — the recommended or applied remediation steps (assisted, manual, or containment).
huntress_reject_remediations
Pro · Destructive
Reject the remediations recommended for a Huntress incident report, declining to apply them.
huntress_resolve_incident_report
Pro · Destructive
Resolve a Huntress incident report.

Escalations

ToolWhat it does
huntress_get_escalation
Free · Read-only
Get a single escalation by its numeric ID — full detail, severity, status, due date, and the related organization.
huntress_list_escalations
Free · Read-only
List escalations — items the Huntress SOC has escalated to the partner for action.
huntress_resolve_escalation
Pro · Destructive
Resolve a Huntress escalation by recording a determination (expected vs unauthorized) and the scope it applies to (account, organization, or identity).

Platform Actions

ToolWhat it does
huntress_get_platform_action
Free · Read-only
Get a single platform action by its numeric ID — full detail, severity, status, and the related organization.
huntress_list_platform_actions
Free · Read-only
List platform actions — actions requested or taken on the Huntress platform.

Signals

ToolWhat it does
huntress_get_signal
Free · Read-only
Get a single security signal by its numeric ID — full detail, type, status, related entity, and investigation timeline.
huntress_list_signals
Free · Read-only
List security signals — investigated detections tied to entities (users, mailboxes, agents, identities).

Organizations

ToolWhat it does
huntress_create_organization
Pro · Write
Create a new organization within the Huntress account.
huntress_delete_organization
Pro · Destructive
Delete a Huntress organization.
huntress_get_organization
Free · Read-only
Get a single organization by its numeric ID — full detail, name, key, and metadata.
huntress_list_organizations
Free · Read-only
List the customer organizations under the account.
huntress_update_organization
Pro · Write
Update a Huntress organization — rename it.

Memberships

ToolWhat it does
huntress_create_membership
Pro · Write
Invite a user to the Huntress account by creating a membership.
huntress_delete_membership
Pro · Destructive
Delete a Huntress membership, revoking the member's access to the account.
huntress_get_membership
Free · Read-only
Get a single membership by its numeric ID — full detail, the user, organization, and permission role.
huntress_list_memberships
Free · Read-only
List memberships — the user-to-organization access grants and their permission roles.
huntress_update_membership
Pro · Write
Update a Huntress membership — change the member's permissions.

Invoices

ToolWhat it does
huntress_get_invoice
Free · Read-only
Get a single invoice by its numeric ID — full billing detail, status, line items, and amounts.
huntress_list_invoices
Free · Read-only
List billing invoices for the account.

External Recon

ToolWhat it does
huntress_get_external_port
Free · Read-only
Get a single External Recon port finding by its numeric ID — full detail, protocol, port, service, and risk classification.
huntress_list_external_ports
Free · Read-only
List externally-discovered open ports and exposed services found by Huntress External Recon.

Summary Reports

ToolWhat it does
huntress_get_report
Free · Read-only
Get a single summary report by its numeric ID — full report detail, type, period, and the related organization.
huntress_list_reports
Free · Read-only
List summary reports — periodic monthly/quarterly/yearly account and organization summaries.

Unwanted Access Rules

ToolWhat it does
huntress_create_unwanted_access_rule
Pro · Write
Create an unwanted-access rule that classifies identity sign-ins as expected or unauthorized.
huntress_delete_unwanted_access_rule
Pro · Destructive
Delete an unwanted-access rule.
huntress_get_unwanted_access_rule
Free · Read-only
Get a single unwanted access rule by its numeric ID — full detail, type, status, scope, category, and matching logic.
huntress_list_known_vpns
Free · Read-only
List the reference catalog of known VPN providers recognized by Huntress ITDR.
huntress_list_unwanted_access_rules
Free · Read-only
List unwanted access rules — ITDR location/VPN access policies that flag expected vs. unauthorized sign-in sources.
huntress_update_unwanted_access_rule
Pro · Write
Update an unwanted-access rule.

Managed Accounts (Reseller)

ToolWhat it does
huntress_approve_managed_account_remediations
Pro · Destructive
Approve remediations for an incident report within a reseller-managed account selected by accountId.
huntress_create_managed_account
Pro · Destructive
Create a new reseller-managed account.
huntress_create_managed_account_membership
Pro · Write
Invite a user (create a membership) within a reseller-managed account selected by accountId.
huntress_create_managed_account_organization
Pro · Write
Create an organization within a reseller-managed account selected by accountId.
huntress_delete_managed_account_membership
Pro · Destructive
Delete a user membership within a reseller-managed account selected by accountId.
huntress_delete_managed_account_organization
Pro · Destructive
Delete an organization within a reseller-managed account selected by accountId.
huntress_disable_managed_account
Pro · Destructive
PERMANENTLY disable a reseller-managed account.
huntress_get_managed_account
Free · Read-only
Get a single reseller-managed account by accountId (discoverable via huntress_list_managed_accounts).
huntress_get_managed_account_agent
Free · Read-only
Get a single agent within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts).
huntress_get_managed_account_external_port
Free · Read-only
Get a single external-recon open port within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts).
huntress_get_managed_account_incident_report
Free · Read-only
Get a single incident report within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts).
huntress_get_managed_account_invoice
Free · Read-only
Get a single invoice for a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts).
huntress_get_managed_account_membership
Free · Read-only
Get a single membership within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts).
huntress_get_managed_account_organization
Free · Read-only
Get a single organization within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts).
huntress_get_managed_account_remediation
Free · Read-only
Get a single remediation for an incident report within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts).
huntress_get_managed_account_report
Free · Read-only
Get a single summary report within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts).
huntress_get_managed_account_signal
Free · Read-only
Get a single investigation signal within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts).
huntress_isolate_managed_account_agent
Pro · Destructive
Network-isolate an agent within a reseller-managed account selected by accountId.
huntress_list_managed_account_agents
Free · Read-only
List deployed agents within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts).
huntress_list_managed_account_external_ports
Free · Read-only
List external-recon open ports discovered within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts).
huntress_list_managed_account_incident_reports
Free · Read-only
List incident reports within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts).
huntress_list_managed_account_invoices
Free · Read-only
List invoices for a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts).
huntress_list_managed_account_memberships
Free · Read-only
List user memberships within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts).
huntress_list_managed_account_organizations
Free · Read-only
List organizations within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts).
huntress_list_managed_account_remediations
Free · Read-only
List remediations for an incident report within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts).
huntress_list_managed_account_reports
Free · Read-only
List summary reports within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts).
huntress_list_managed_account_signals
Free · Read-only
List investigation signals within a reseller-managed account selected by accountId (discoverable via huntress_list_managed_accounts).
huntress_list_managed_accounts
Free · Read-only
List the reseller-managed accounts available to the current credentials.
huntress_reject_managed_account_remediations
Pro · Destructive
Reject remediations for an incident report within a reseller-managed account selected by accountId.
huntress_release_managed_account_agent_isolation
Pro · Destructive
Release network isolation on an agent within a reseller-managed account selected by accountId.
huntress_resolve_managed_account_incident_report
Pro · Destructive
Resolve an incident report within a reseller-managed account selected by accountId.
huntress_uninstall_managed_account_agent
Pro · Destructive
Uninstall an agent within a reseller-managed account selected by accountId.
huntress_update_managed_account
Pro · Write
Update a reseller-managed account.
huntress_update_managed_account_agent
Pro · Write
Update an agent within a reseller-managed account selected by accountId (tags, tamper-protection config).
huntress_update_managed_account_membership
Pro · Write
Update a user membership's permissions within a reseller-managed account selected by accountId.
huntress_update_managed_account_organization
Pro · Write
Update an organization within a reseller-managed account selected by accountId.

Reseller Billing

ToolWhat it does
huntress_create_reseller_subscription
Pro · Destructive
Create a new reseller subscription.
huntress_get_reseller_invoice
Free · Read-only
Get a single reseller invoice by id; these require reseller-level API credentials.
huntress_get_reseller_subscription
Free · Read-only
Get a single reseller subscription by id; these require reseller-level API credentials.
huntress_list_reseller_account_usage_line_items
Free · Read-only
List per-account usage line items for a reseller invoice; these require reseller-level API credentials.
huntress_list_reseller_invoices
Free · Read-only
List reseller invoices; these require reseller-level API credentials.
huntress_list_reseller_organization_usage_line_items
Free · Read-only
List per-organization usage line items for a reseller invoice; these require reseller-level API credentials.
huntress_list_reseller_subscriptions
Free · Read-only
List reseller subscriptions; these require reseller-level API credentials.
huntress_update_reseller_subscription
Pro · Destructive
Update a reseller subscription.
huntress_upgrade_reseller_subscription
Pro · Destructive
Upgrade a reseller subscription (e.g. raise the seat minimum).

SIEM

ToolWhat it does
huntress_query_siem
Pro · Write
Query SIEM logs with ES|QL.