Skip to main content
Connector guides

Connect Lexful

Lexful is an IT documentation platform for MSPs — the place your team records what a client's environment actually looks like. Despite the name, it is not an AI or legal product: it is documentation…

Written By Christopher Scaminaci

Last updated 6 days ago

Lexful is an IT documentation platform for MSPs — the place your team records what a client's environment actually looks like. Despite the name, it is not an AI or legal product: it is documentation tooling in the same category as Hudu and IT Glue. You define your own asset types with whatever properties you need, file assets under client organizations, keep revision history on everything, and store credentials as secure properties. StackJack talks to Lexful through the Lexful public API.

Connecting Lexful to StackJack gives your AI assistant a large family of lexful_ MCP tools — MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:

  • Read your documentation — client organizations and their hierarchy, assets of any type with full filtering, related assets, revision history, attached files and cross-entity search
  • Understand your schema — the asset types you have defined, their properties and the relationships between them
  • See who can access what — access grants on assets and tags, groups and their membership, users and roles, and your SSO configuration
  • Write documentation (on Pro plans) — create and update organizations, assets and asset types; tag and relate records; manage groups, users and access
  • Read stored secrets (on Pro plans, and only if you grant it) — documented passwords and keys, behind their own separate permission

It is a large connector, because Lexful's API is large. Most of them are writes, so the tier and permission settings matter more here than on a read-only connector.

How StackJack authenticates to Lexful

Lexful needs three values, which is one more than most connectors:

What you needWhere it goes
Account IDSent with every request, alongside the key
API Key IDThe identifier half of your API key
API Key SecretThe secret half — treat it as a password

All three come from the same place: the Lexful dashboard, under Account Settings → APIs.

The Account ID is the one people miss. It is not part of the API key and cannot be worked out from it, and Lexful requires it on every single request. A connector saved with a valid key but a missing or wrong Account ID will authenticate and then fail every tool — which looks like a broken key even though the key is fine. It is also easy to transpose with the API Key ID, so check them against the dashboard when you paste them in.

StackJack handles the rest automatically. It exchanges your key ID and secret for a short-lived access token, renews the token before it expires, and re-authenticates if Lexful ever rejects it. There is nothing to refresh by hand and no expiry to diarise.

Lexful currently publishes one address (https://api.us.lexful.app), which StackJack uses by default. The connector has an optional API Base URL field for the day Lexful adds another; leave it blank unless Lexful has told you your account is elsewhere. Anything that is not a recognised Lexful address is rejected.

Before you begin

  • In StackJack: you need a role that can manage connectors (tenant Owner, a co-owner, or an Administrator).
  • In Lexful: you need access to Account Settings → APIs, which is where both the Account ID and API keys live.

Step 1 — Collect your credentials in Lexful

  1. Sign in to the Lexful dashboard.
  2. Go to Account Settings → APIs.
  3. Note the Account ID shown on that page.
  4. Create an API key. Lexful gives you an ID and a secret as a pair — you need both.
  5. Copy the secret immediately and store it securely. Treat it as a password: anyone holding it, together with the Account ID, can read everything you have documented, including stored credentials.

Step 2 — Add the connector in StackJack

  1. In StackJack, open Connectors.
  2. Find the Lexful card and select Configure.
  3. Enter the Account ID, API Key ID and API Key Secret.
  4. Leave API Base URL blank unless Lexful told you otherwise.
  5. Save, then use Test Connection.

The connection test deliberately exercises the whole authentication path — the token exchange and both required values — so a green result means your AI can genuinely reach your data, not merely that the key is well-formed.

What your AI can do, by plan

PlanWhat it can do
FreeEvery read tool: organizations, assets, asset types, revisions, related assets, files, tags, groups, users, SSO configuration and search
ProEverything in Free, plus every write tool — and, separately grantable, the two tools that read stored secrets
BusinessThe same tools as Pro, with a higher monthly call allowance

Reading stored secrets is a separate decision

Lexful can store credentials as secure properties on an asset — a client's router password, a service account key. Two tools read those values in plaintext.

Those two tools are deliberately kept apart from everything else. They require the Pro tier, and they sit under their own permission rather than the general asset-read permission. That means you can let an AI read all your documentation while withholding the passwords inside it. Ordinary asset reads never include secure values, so nothing leaks by accident through the general tools.

Grant it only if you specifically intend your AI to retrieve credentials. One of the two can also read a secret as it was at an earlier revision, which can return a password that has since been changed — useful for recovering something overwritten by mistake, and worth understanding before you grant it.

Tools that change a lot at once

Most Lexful writes affect one record and are easy to undo. A few are much wider, and StackJack marks these as sensitive. Whether your AI application asks you to confirm before running one depends on that application's own settings — see Destructive tools and confirmation. Review those settings, and know what each one reaches:

  • Deleting a property from an asset type removes that property's data from every asset of that type, not just from the schema. This is the widest-reaching call in the connector — wider than deleting an asset — and if the property held a secure value, that secret goes with it.
  • Restoring an asset to an earlier revision overwrites the current record, so anything written since that revision is lost. This is different from restoring a deleted asset, which simply brings it back.
  • Archiving an asset type takes the type and the visibility of everything filed under it out of service in one call.
  • Bulk delete and bulk update exist for assets, organizations and tags, and reach as many records as you name.
  • Deleting a user, a group or an SSO connection removes people's access — an SSO connection especially, since everyone who signs in through it loses their way in at once.

Most deletions are recoverable. Lexful soft-deletes, so deleted assets and organizations can be restored and still appear in reads that include deleted items. Files are the exception: there is no restore for them, and StackJack cannot upload a replacement, so re-attaching a document means doing it in Lexful.

Tagging, relating and group membership are not deletions. Removing a tag from an asset, unlinking related assets, or taking someone out of a group changes only the association — the records survive and the matching "add" tool puts things back exactly. Those tools are not treated as destructive, though removing an access grant does take someone's access away until it is restored.

Finding things

Asset properties are whatever you defined, so your AI filters with a flexible expression rather than fixed fields — for example, matching a name that starts with "Acme", a status that is one of several values, or a date range. It can also sort, expand relationships, include deleted records, restrict results to one client organization, and ask for only the properties it needs, which keeps large asset types readable.

If your AI does not know which asset type holds what it is looking for, the search tool covers assets and organizations together. Search returns up to 100 results per page; every other list returns up to 1000.

Troubleshooting

"Every Lexful tool fails, but the API key is definitely right." Check the Account ID. Lexful needs it on every request alongside the key, so a missing or mistyped Account ID fails everything while the key itself is perfectly good. It is a different value from the API Key ID and the two are easy to swap.

"Lexful refuses the credentials." Confirm the API key still exists under Account Settings → APIs. If it was removed, create a new one and paste both halves into StackJack along with the Account ID — and check all three come from the same Lexful environment.

"A record cannot be found." On this connector that is usually the asset type name rather than a missing record — asset paths include the type name, and those are specific to your account. Have your AI list the asset types to confirm the exact name. If the record was deleted, remember Lexful keeps deleted rows recoverable, so a read that includes deleted records may still find it.

"API calls started failing from a new location." Check the IP allowlist. Lexful can restrict which networks reach its API, and StackJack's requests have to come from an allowed one. StackJack does not publish its outbound addresses: open a support ticket to get the current addresses for your region before you enable the restriction, and ask again after a region move, because they change.

Several customers

Some MSPs need one Lexful connection per customer, console or region. StackJack can hold several named connections of one connector, and your AI names the one it wants on each call. See Several connections of one connector.

Full tool list

See the generated Lexful tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.

Lexful tools

lexful_ · 90 tools · Free 30 · Pro 60

Assets

ToolWhat it does
lexful_add_related_assets
Pro · Write
Link assets to one asset.
lexful_bulk_delete_assets
Pro · Destructive
Delete MANY assets of one type in a single call; the ids ride in the body.
lexful_create_asset
Pro · Write
Create an asset of one type.
lexful_delete_asset
Pro · Destructive
Delete one asset.
lexful_get_asset
Free · Read-only
Get one asset by id.
lexful_get_asset_counts
Free · Read-only
Get asset counts by type — the cheapest way to see what a Lexful account actually contains and which asset types are worth reading.
lexful_get_asset_revision
Free · Read-only
Get one historical revision of an asset — the record as it stood at that point in time.
lexful_list_asset_revisions
Free · Read-only
List an asset's revision history — what changed and when.
lexful_list_assets
Free · Read-only
List assets of one type, with the full filter grammar.
lexful_list_related_assets
Free · Read-only
List the assets related to one asset — the documentation graph around a record, for example the contacts and devices attached to a site.
lexful_remove_related_assets
Pro · Write
Unlink related assets from one asset.
lexful_restore_asset_to_revision
Pro · Destructive
Roll an asset back to an earlier revision.
lexful_restore_assets
Pro · Write
Restore soft-deleted assets.
lexful_update_asset
Pro · Write
Update one asset's properties.
lexful_update_related_assets
Pro · Write
Update the related-asset links on one asset.

Secure Values

ToolWhat it does
lexful_get_secure_value
Pro · Read-only
Read a stored secret in PLAINTEXT from an asset property — a documented password, key or other credential.
lexful_get_secure_value_from_revision
Pro · Read-only
Read a stored secret in PLAINTEXT as it was at an earlier revision — which by construction can return a credential that has SINCE BEEN ROTATED out of the current record.

Asset Types

ToolWhat it does
lexful_add_asset_type_property
Pro · Write
Add a property to an asset type.
lexful_add_asset_type_reference
Pro · Write
Add a reference to an asset type — a defined relationship to another type, which is what makes cross-linking assets possible.
lexful_archive_asset_type
Pro · Destructive
Archive an asset type.
lexful_create_asset_type
Pro · Write
Create a new asset type.
lexful_delete_asset_type_property
Pro · Destructive
Delete a property from an asset type.
lexful_delete_asset_type_reference
Pro · Destructive
Delete a reference definition from an asset type.
lexful_get_asset_type
Free · Read-only
Get one asset type, including its property definitions and its references (relationships to other types).
lexful_list_asset_types
Free · Read-only
List asset types — the schemas defined in this Lexful account.
lexful_update_asset_type
Pro · Write
Update an asset type's own attributes, such as its name or description.
lexful_update_asset_type_property
Pro · Write
Update a property definition on an asset type — for example its label or its options.
lexful_update_asset_type_reference
Pro · Write
Update a reference definition on an asset type.

Asset Files

ToolWhat it does
lexful_delete_asset_file
Pro · Destructive
Delete a file attached to an asset.
lexful_get_asset_file
Free · Read-only
Get one attached file's metadata — name, size, content type and timestamps.
lexful_get_asset_file_download_url
Free · Read-only
Get a time-limited download URL for an attached file.
lexful_list_asset_files
Free · Read-only
List the files attached to an asset — their names, sizes and metadata, not their contents.
lexful_update_asset_file
Pro · Write
Update an attached file's metadata, such as its display name.

Access Grants

ToolWhat it does
lexful_add_asset_access_grants
Pro · Write
Grant access to one asset.
lexful_add_tag_access_grants
Pro · Write
Grant access through a tag, which reaches everything currently carrying that tag and everything tagged with it later.
lexful_bulk_add_asset_access_grants
Pro · Write
Grant access across EVERY asset of one type at once.
lexful_list_asset_access_grants
Free · Read-only
List who has been granted access to one asset.
lexful_list_tag_access_grants
Free · Read-only
List who has been granted access through one tag.
lexful_remove_asset_access_grants
Pro · Write
Revoke access to one asset.
lexful_remove_tag_access_grants
Pro · Write
Revoke a tag-based grant.

Organizations

ToolWhat it does
lexful_bulk_delete_organizations
Pro · Destructive
Delete MANY organizations in one call; the ids ride in the body.
lexful_bulk_update_organizations
Pro · Destructive
Update MANY organizations in one call.
lexful_create_organization
Pro · Write
Create one or more organizations.
lexful_delete_organization
Pro · Destructive
Delete one organization.
lexful_delete_organization_logo
Pro · Destructive
Delete an organization's logo.
lexful_get_organization
Free · Read-only
Get one organization by id.
lexful_list_organizations
Free · Read-only
List organizations — the client companies documented in this account.
lexful_restore_organizations
Pro · Write
Restore soft-deleted organizations.
lexful_update_organization
Pro · Write
Update one organization's fields.

Tags

ToolWhat it does
lexful_add_tag_to_assets
Pro · Write
Apply a tag to assets.
lexful_add_tag_to_entities
Pro · Write
Apply a tag to entities.
lexful_add_tag_to_organizations
Pro · Write
Apply a tag to organizations.
lexful_bulk_delete_tags
Pro · Destructive
Delete MANY tags in one call; the ids ride in the body.
lexful_create_tag
Pro · Write
Create a tag.
lexful_delete_tag
Pro · Destructive
Delete one tag.
lexful_get_tag
Free · Read-only
Get one tag by id.
lexful_list_tags
Free · Read-only
List tags.
lexful_remove_tag_from_assets
Pro · Write
Remove a tag from assets.
lexful_remove_tag_from_entities
Pro · Write
Remove a tag from entities.
lexful_remove_tag_from_organizations
Pro · Write
Remove a tag from organizations.
lexful_update_tag
Pro · Write
Update a tag's own attributes, such as its name or colour.

Groups

ToolWhat it does
lexful_add_users_to_group
Pro · Write
Add users to a group.
lexful_create_group
Pro · Write
Create a group.
lexful_delete_group
Pro · Destructive
Delete a group.
lexful_get_group
Free · Read-only
Get one group by id.
lexful_list_group_users
Free · Read-only
List the users in a group — the membership behind whatever that group has been granted.
lexful_list_groups
Free · Read-only
List groups.
lexful_remove_users_from_group
Pro · Write
Remove users from a group.
lexful_update_group
Pro · Write
Update a group's own attributes, such as its name.

Users

ToolWhat it does
lexful_create_user
Pro · Write
Create a user, provisioning a real person into the platform.
lexful_delete_user
Pro · Destructive
Delete a user.
lexful_get_user
Free · Read-only
Get one user by id.
lexful_list_user_roles
Free · Read-only
List the roles a user can be assigned.
lexful_list_users
Free · Read-only
List users.
lexful_update_user
Pro · Write
Update one user's details or role.

SSO Connections

ToolWhat it does
lexful_create_sso_connection
Pro · Write
Create an SSO connection.
lexful_delete_sso_connection
Pro · Destructive
Delete an SSO connection.
lexful_get_sso_connection
Free · Read-only
Get one SSO connection's configuration.
lexful_get_sso_connection_mappings
Free · Read-only
Get an SSO connection's attribute mappings — how fields from the identity provider translate into Lexful user attributes.
lexful_list_sso_connections
Free · Read-only
List the SSO connections configured for this account — the identity providers people sign in through.
lexful_update_sso_connection
Pro · Write
Update an SSO connection's configuration.
lexful_update_sso_connection_mappings
Pro · Write
Update how identity-provider attributes map onto Lexful user fields.

Account

ToolWhat it does
lexful_create_allowed_ip
Pro · Write
Add an IP address or CIDR range to the account's allowlist.
lexful_delete_allowed_ip
Pro · Destructive
Remove an entry from the IP allowlist.
lexful_get_account_settings
Free · Read-only
Get account-wide settings.
lexful_get_allowed_ip
Free · Read-only
Get one IP allowlist entry.
lexful_list_allowed_ips
Free · Read-only
List the account's IP allowlist — the addresses and CIDR ranges permitted to reach the Lexful API.
lexful_update_account_settings
Pro · Destructive
Update account-wide settings.
lexful_update_allowed_ip
Pro · Write
Update one IP allowlist entry.
ToolWhat it does
lexful_search
Free · Read-only
Search across assets and organizations at once.