Connect RoboShadow
RoboShadow is a vulnerability management and endpoint security platform built for MSPs. An agent on each Windows device reports what is installed, what is missing and what is exposed, and RoboShadow…
Written By Christopher Scaminaci
Last updated 6 days ago
RoboShadow is a vulnerability management and endpoint security platform built for MSPs. An agent on each Windows device reports what is installed, what is missing and what is exposed, and RoboShadow turns that into the reports you actually present at a client review: which CVEs affect which machines, whether antivirus is really running everywhere, what Defender is configured to do, which updates are outstanding, and what was remediated. It also scans your customers' external addresses for perimeter exposure and reports on Microsoft 365 multi-factor authentication coverage.
Connecting RoboShadow to StackJack gives your AI assistant a family of roboshadow_ MCP tools — MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:
- Answer vulnerability questions — which CVEs are present across a client, which products and versions are causing the exposure, which devices are worst affected, and what fixes close a specific CVE
- Report on antivirus and Defender — the organization-wide protection summary, the per-device breakdown, what threats were caught, ransomware protection state, and Defender's configuration on every machine
- Track patching — the missing-update totals, a per-device breakdown filtered by update type, device role or reboot state, and the remediation history that shows what was actually fixed
- Inventory the estate — devices, hardware specifications, disks and their encryption state, network shares, Windows services, local user accounts and user profiles, and firewall configuration
- Read external scan results — the status of each perimeter scan, its findings, and the addresses it covered
- Check Microsoft 365 MFA coverage — each user's registered authentication methods, their MFA status, and who holds the Global Administrator role
RoboShadow is a read-only connector
Every RoboShadow tool reports. None of them changes a device, deploys an update, dispatches a remediation, launches a scan or edits a setting — because RoboShadow's API offers no operation that does. Nothing here is marked destructive, and nothing here can act on a customer's machines.
Read-only is not the same as harmless. These tools return your customers' vulnerability findings, device inventories and security posture, so treat what comes back as sensitive and grant the connector to the assistants that need it.
If RoboShadow adds action endpoints in future, they would arrive as a separate, clearly marked set of tools. Today the connector is a reporting surface.
How StackJack authenticates to RoboShadow
RoboShadow issues three values from its portal, and StackJack needs one of them: the refresh token.
That is worth being precise about, because it is the easiest thing to get wrong. The portal shows a Bearer Token next to the Refresh Token, and the bearer token expires within about an hour with no way to renew it. StackJack exchanges the refresh token for a fresh bearer whenever it needs one and keeps it current for you, so pasting the bearer token instead would give you a connector that works for an hour and then stops.
One credential covers several client organizations
Nearly every RoboShadow report is scoped to an organization, and a single API token typically reaches all the organizations the account that generated it can see. StackJack treats that as the normal case: the tools take an organization on each request rather than being locked to one, so a single RoboShadow connection can report across your whole client base.
The Organisation ID field on the setup form is therefore optional. It is stored only as a convenience value you can copy from. Ask your AI to list organizations to see which ones your token actually reaches.
Steps
- Sign in to RoboShadow with an account that can see the organizations you want StackJack to report on. The API token inherits that account's organization access, so a narrowly-scoped account produces a narrowly-scoped token.
- Go to Reports, then API Token. RoboShadow shows an Organisation ID, a Bearer Token and a Refresh Token.
- Copy the Refresh Token — not the Bearer Token. Treat it as a password: anyone holding it can read everything your RoboShadow account can see.
- Paste it into StackJack. Open Connectors, choose RoboShadow, and paste the refresh token. Optionally paste the Organisation ID as a default. There is no URL to enter: RoboShadow is a single global service with no regional endpoints, so the address is fixed.
- Run a Test Connection to confirm StackJack can reach RoboShadow and see which organizations the token covers.
If you ever need to replace the token, paste a new one over the old. Leaving the field blank when you edit an existing connection keeps the stored token rather than clearing it.
What to know before your AI uses this connector
Ask for an organization, or ask which ones exist
Because one token spans several organizations, most tools need to know which one you mean. In practice your AI will call "list organizations" first and work from there, but if you already know the client you want, naming it in your question saves a step.
The reports are agent data, so coverage follows the agent
Everything under devices, antivirus, updates, disks, services and vulnerabilities comes from the RoboShadow agent on each Windows machine. A device with no agent, or one that has not checked in recently, does not appear as a problem — it simply does not appear. When a client's numbers look suspiciously healthy, the device count is the thing to sanity-check first.
The external scanner and the Microsoft 365 MFA report are different: they do not depend on the agent at all.
The MFA report works differently from everything else
The Microsoft 365 MFA report returns users in large fixed blocks and is paged by a "skip pages" number starting at zero, rather than by the page size the other tools use. Your AI handles that automatically; it is worth knowing only if you are comparing a count against the RoboShadow portal.
Plans and limits
Every RoboShadow tool is available on the Free tier, because the whole surface is reads and read tools are Free. Pro and Business reach the same tools and differ by monthly call quota.
Reports return up to 100 rows per page. RoboShadow does not publish a rate limit, so StackJack paces requests conservatively and backs off automatically if it is ever throttled, which usually makes a large report slower rather than failed. Pacing smooths a burst; it does not guarantee that every call arrives. Retries are bounded, so a wide enough read can still come back throttled or time out. Narrow the read, honour any retry delay the vendor sends, and check whether a write landed before repeating it — see Retrying a failed or timed-out write.
See the generated RoboShadow tool reference for the current inventory, plan assignment and input schemas.
Troubleshooting
"RoboShadow rejected the request's access token" — StackJack renews access tokens automatically and retries once, so a single failure usually clears itself. If it keeps happening, the stored refresh token has expired or been revoked. Sign in to RoboShadow, open Reports then API Token, copy a new refresh token, paste it into the connector and run a Test Connection.
"RoboShadow refused access to that organization" — the token reached RoboShadow but does not cover the organization you asked for. Ask your AI to list organizations to see which ones it can reach. If one that should be there is missing, have a RoboShadow administrator grant the account access to it and generate a new token.
A report comes back empty for a client you know has devices — check the device list for that organization first. An organization whose agents have never checked in returns empty reports everywhere, and that looks the same as a genuinely clean estate.
The connection works but you only see one client — the token's reach is set by the RoboShadow account that created it. Generate the token from an account that can see all the organizations you manage, rather than from inside a single one.
Device identifiers look unusual — RoboShadow device identifiers are plain text strings rather than the long identifiers you may be used to from other tools. That is normal; pass them through as they are returned.
RoboShadow tools
roboshadow_ · 40 tools · Free 40
Vulnerabilities
Antivirus & Ransomware
Updates & Remediation
Devices & Inventory
Platform
More in Connector guides
Connect Acronis Cyber Protect CloudConnect Action1Connect AddigyConnect AlertOpsStill need help? Ask the team