Connect MSP360
MSP360 is a backup and endpoint-management platform built for MSPs. MSP360 Managed Backup protects your customers' servers, workstations and cloud workloads into storage you own — Amazon S3, Azure,…
Written By Christopher Scaminaci
Last updated 6 days ago
MSP360 is a backup and endpoint-management platform built for MSPs. MSP360 Managed Backup protects your customers' servers, workstations and cloud workloads into storage you own — Amazon S3, Azure, Wasabi, Backblaze, Google Cloud, MinIO and more — and MSP360 RMM adds endpoint telemetry on the same agent and in the same console.
Connecting MSP360 to StackJack gives your AI assistant a family of msp360_ MCP tools — MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:
- Answer "whose backups failed last night?" — the latest plan-run status across every company, user and endpoint in one call, with the error message on each row, plus per-plan run history when you need to see how far back a failure goes
- Work the endpoint inventory — managed computers and their disks, the backup and restore plans on each one, plan detail and plan history
- Run the customer hierarchy — companies, the backup end-users inside them, and the computers each user owns
- Manage storage — storage accounts across all nine supported providers, their destinations, and the per-user destination view
- Reconcile the month — billing for the reporting month, billing totals filtered by date and company, and per-operation backup and restore detail
- Handle licenses and packages — what licenses exist, which are free, and the storage and restore packages you sell against
- Read RMM telemetry — hardware, installed software, drives and SMART data, memory, services, printers, Hyper-V guests, running processes, event-log counts, operating-system updates and the antivirus and alert summary, either across the whole fleet in one paginated call or for a single device
- Change things (on Pro plans) — create and update companies, users, administrators, storage accounts, destinations, packages and backup plans; grant licenses; request custom-branded agent builds; and, where you intend to, start or stop a plan, remove an endpoint's authorization, release or revoke a license, and delete a customer, user, package or destination
How StackJack authenticates to MSP360
MSP360 has two APIs and they take two different credentials. StackJack carries both on one connection, and only the first is required.
Managed Backup takes an API Login and an API Password that you generate in the MSP360 console. StackJack exchanges that pair for a short-lived access token on your behalf, keeps it fresh, and gets a new one automatically when it expires. You never see it.
MSP360 RMM takes its own RMM API token, generated separately in the same console and issued against one of your administrators. It is optional: leave it blank and every backup tool works exactly as it should, while the RMM telemetry tools report that the RMM half is not set up. StackJack will not mark your connection unhealthy for a missing RMM token.
There is no address to enter. MSP360 serves both APIs from fixed addresses, with no regional variants.
Before you start
- Generate the Managed Backup credentials from your main administrative account — that is where MSP360 puts the option.
- If you want the RMM tools, your MSP360 account needs a valid RMM license. MSP360 offers RMM API tokens only to licensed accounts, and the Community Edition has no API access at all. If you cannot find the RMM API tokens panel, that is why.
Steps
- Sign in to MSP360 with your main administrative account at mspbackups.com.
- Go to Settings > General > API, choose Add credentials, then Generate. MSP360 creates a Login and a Password.
- Copy both immediately. MSP360 shows them once. Treat them as a password: they reach every company, user and endpoint in your account.
- Optional — go to Settings > General > RMM API tokens, choose Add RMM API token, and pick the administrator the token belongs to. Copy the token.
- In StackJack, open the MSP360 connector, paste the API Login and API Password, paste the RMM API token if you have one, and save.
- Select the tools you want your AI assistant to reach on the same connector page, then use Test Connection to confirm everything works.
Regenerating your credentials
Generating a new Managed Backup credential pair in MSP360 expires the previous pair immediately. There is no grace period and no warning: every MSP360 tool starts failing the moment you regenerate, until the new Login and Password are saved in StackJack. Do both in the same sitting.
An RMM API token behaves the same way when you revoke it in the console — and because it is static, StackJack cannot renew it for you. Issue a new one and save it.
If your connector stops working after somebody regenerated credentials, re-save the new pair and use Test Connection. StackJack also re-checks connections on its own every half hour, so a connector that is briefly unhealthy for an unrelated reason recovers without you doing anything.
One credential sees every customer
MSP360 has no way to scope an API credential to a single customer. Your MSP360 connection in StackJack is therefore always whole-book: it reaches every company in the account. That is a property of MSP360, not of StackJack.
Two things narrow what an AI assistant can actually do with it:
- Tool selection on the connector page decides which
msp360_tools an assistant may call at all. - Per-tool filters — the customer-scoped tools take a company or user identifier, so an assistant can be pointed at one customer for a given task.
If you run more than one MSP360 tenancy, add a second named MSP360 connection rather than swapping credentials.
What the RMM tools can and cannot do
The MSP360 RMM tools are telemetry only. MSP360 publishes no API for remote reboot, Wake-on-LAN, PowerShell or script execution, patch approval or the registry editor, even though the RMM console has all of those. Alert status is available as part of the RMM summary read.
So an AI assistant can report on endpoints through this connector — build a QBR asset list, find machines missing operating-system updates, spot a failing drive from its SMART data, list where a piece of software is installed — and then hand off to a person in the MSP360 console to act.
Two more things worth knowing:
- MSP360 refreshes RMM alert data every 10 minutes and all other statistics every 60 minutes. Polling faster returns the same values, so schedule recurring agent runs to match.
- The software and update reads may take a little while to come back, and the update reads cover operating-system updates only — third-party application updates are not included. For those, read the software inventory and look for an available-version property on applications managed by Winget on Windows or Homebrew on macOS.
Tools that delete a customer's backups
Three MSP360 tools delete backup data, not just a record. In MSP360's own words, one deletes "the user account metadata along with the backup data", one deletes "computer metadata along with backup data", and one deletes a plan where "backup data will be deleted along with the backup plan". They destroy the customer's restore points, and nothing in MSP360 undoes them.
They are marked destructive, they say so in their own descriptions, and each one names the safer alternative in the same breath — there is a separate tool that removes a user account and explicitly leaves the backups in storage.
Whether your AI application asks you to confirm before running a destructive tool depends on that application's own settings — see Destructive tools and confirmation. Review that setting before you give an assistant these tools, and consider leaving them out of your tool selection until you have a reason to include them.
The other destructive MSP360 tools start or stop a backup plan on a live endpoint, grant or remove an endpoint's authorization, release or revoke a license from a user, and delete a company, administrator, package or destination.
Plans
Every MSP360 read is on the Free tier. Every write is on Pro. Business reaches the same MSP360 tools as Pro and differs by monthly call allowance only — MSP360 has no per-user sign-in for its API, so every call acts as the one credential you configured, and MSP360's own audit trail attributes it to the administrator who generated that credential.
See the generated MSP360 tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.
Large reads and rate limits
MSP360 publishes no rate limit for either API, so StackJack paces requests conservatively and backs off on its own if it is throttled, which usually makes a large report slower rather than failed. Pacing smooths a burst; it does not guarantee that every call arrives. Retries are bounded, so a wide enough read can still come back throttled or time out. Narrow the read, and check whether a write landed before repeating it — see Retrying a failed or timed-out write.
Two of the MSP360 reads page in large books: the computer list and the RMM fleet-wide statistics. StackJack caps each page at 200 rows, so a large estate comes back over several calls. MSP360 reports no total and no "more pages" marker, so an assistant keeps asking until a short page comes back.
Prefer the fleet-wide RMM reads over the per-device ones for anything covering more than a handful of machines. That is MSP360's own guidance: one fleet-wide call replaces one call per device.
Troubleshooting
"MSP360 rejected the API Login and Password." Somebody almost certainly regenerated the credentials in MSP360, which expires the previous pair at once. Add credentials again under Settings > General > API and save the new pair here.
The RMM tools say the RMM half is not set up. No RMM API token is stored on the connection. Add one if you license MSP360 RMM. The backup tools are unaffected.
"The MSP360 RMM API token was rejected." Your Managed Backup credentials are fine — only the RMM token is the problem. It was revoked in MSP360, or the account's RMM license lapsed. Issue a new token under Settings > General > RMM API tokens, or clear the stored one to run on Managed Backup alone.
There is no RMM API tokens panel in my console. The account has no valid RMM license. MSP360 does not offer API access on the Community Edition.
A tool asks for a computer HID. That is MSP360's own unique identifier for a managed endpoint. Get one from the computer list or from the backup-status read; the same HID identifies the device on both the backup and the RMM side, so it is also how an assistant joins the two.
MSP360 tools
msp360_ · 95 tools · Free 61 · Pro 34
Computers and Plans
Users
Storage Accounts
User Destinations
Companies
Administrators
Licenses
Packages
Monitoring
Billing
Builds
Microsoft 365 and Google Workspace Storage
RMM Fleet Statistics
RMM Device Statistics
More in Connector guides
Connect Acronis Cyber Protect CloudConnect Action1Connect AddigyConnect AlertOpsStill need help? Ask the team