Connect SentinelOne
SentinelOne is an endpoint protection platform — EDR — that runs an agent on your customers' laptops, desktops and servers. The agent detects and stops threats on the machine itself, and the…
Written By Christopher Scaminaci
Last updated 6 days ago
SentinelOne is an endpoint protection platform — EDR — that runs an agent on your customers' laptops, desktops and servers. The agent detects and stops threats on the machine itself, and the management console gives you one place to see every agent, every threat and every policy across all of the customers you manage. SentinelOne also extends past the endpoint into cloud and identity asset inventory, so the same console answers "what do we protect" as well as "what happened". StackJack talks to SentinelOne through its management API.
Connecting SentinelOne to StackJack gives your AI assistant a family of s1_ MCP tools — MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:
- Work the threat queue — list threats across every customer or one site, read the full detection detail behind each, follow the activity log, and see which alerts the detection rules raised
- Answer questions about the fleet — which machines have an agent, which are out of date, which are disconnected, what is installed on them, and how many machines a filter actually matches before anyone acts on it
- Report on protection — agent versions and health, policy assignment, exclusions and blocklist entries, firewall and device-control rules, and the endpoints network discovery found with no agent at all
- See the wider estate — the cloud, identity, container, data-store and application asset inventories, their saved filters, and the security-posture findings that go with them
- Run the customer structure — sites, accounts, groups, tags, users and roles, console settings, scheduled reports and saved views
- Respond to an incident (on Pro plans) — isolate a machine from the network, start a scan, mitigate or blocklist a threat, collect logs and forensic evidence, and reconnect it when you are done
- Change protection (on Pro plans) — exclusions, blocklist entries, detection rules, firewall and device-control rules, policies, and threat-intelligence indicators
- Manage endpoints at scale (on Pro plans) — move machines between groups or sites, approve or reject uninstalls, push agent upgrades, run remote scripts, and decommission a machine that has left the business
How StackJack authenticates to SentinelOne
SentinelOne uses a single API token that you create in your own console. There is no sign-in flow, no client ID and no second secret — you paste the token into StackJack and that is the whole credential.
The one thing to plan for is expiry. SentinelOne creates tokens with a fixed lifetime that you choose when you generate them, and nothing renews them automatically. When a token expires or you rotate it, you paste the new one into StackJack. Put the expiry date in your calendar, because the connector stops working on that day.
Create the token against a service user
Generate the token from a dedicated service user rather than from your own profile. A token that belongs to a person stops working the day that person leaves or changes role, and every action StackJack takes is attributed to whoever owns the token.
What the token is allowed to do comes entirely from the role you give that service user. Give it the reach you actually want your AI to have.
Steps
- Find your console address. Sign in to SentinelOne and look at your browser's address bar. It looks like
https://usea1-yourcompany.sentinelone.net— the first part identifies the region your data lives in. Copy the whole address up to and including.sentinelone.net. - Create a service user. In the SentinelOne console, go to Settings, then Users, then Service Users, and create one for StackJack.
- Give it a role. The role decides what StackJack can do. A role that can read everything and act on endpoints gives your AI the full set; a narrower role simply means some tools are refused.
- Generate the API token for that service user. SentinelOne asks how long it should last — note the date.
- Copy the token straight away and store it securely. Treat it as a password: anyone holding it can read and act on your SentinelOne console.
- Paste both into StackJack. Open Connectors, choose SentinelOne, and enter the console address and the token.
- Run a Test Connection to confirm StackJack can reach your console with the token.
Your console address is specific to your tenant and your region, and there is no shared SentinelOne address. Copy it from your browser rather than typing one from memory. If you run consoles in more than one region, each one is a separate connection — SentinelOne does not look across regions.
What to know before your AI uses this connector
Endpoint actions are chosen by filter, not one machine at a time
This is the most important thing about the SentinelOne connector. SentinelOne's own API takes a filter for actions on endpoints, and it acts on everything the filter matches. Isolate, shut down, scan, uninstall, decommission — each of them applies to every machine that matched, and SentinelOne answers with success whether that was one laptop or the whole fleet.
Two things reduce the risk, and it is worth knowing both:
- Every one of these tools requires the Pro tier and is marked destructive. Whether your AI application asks you to confirm before running one depends on that application's own settings — see Destructive tools and confirmation. Check that setting before you grant these tools, because the marking alone does not stop a call.
- Each of their descriptions tells your AI to run the matching count first, so it can report how many machines a filter selects before it acts. If you are asking for something broad, ask for the count.
The same caution applies to reading the result. A successful response from SentinelOne carries a count of how many machines were affected, and that count can be zero. Success does not prove the action landed — ask your AI to re-read the machines afterwards.
Some tools change protection itself
- Adding an exclusion stops SentinelOne acting on something it would otherwise catch, everywhere in the scope you gave it. Nothing looks broken afterwards; the threat simply stops being caught.
- Detection rules can quarantine automatically. A rule that matches more than you intended acts on every machine in scope without waiting for anyone.
- Blocklist entries and threat-intelligence indicators apply across the scope too, and can block software your customer relies on.
- Firewall, device-control and network-quarantine rules change what a machine is allowed to do on the network. A location is part of this: SentinelOne picks which firewall rules an agent enforces from its location, so adding or editing one re-points live machines at a different rule set.
- Uninstalling or decommissioning an agent removes protection from that machine. Decommissioning also removes it from the console, so it stops appearing in your reports.
- Scheduled reports mail console data to whoever is on the recipient list. Creating or editing one can send information about your customers to an address outside your business.
Every one of these is marked as destructive and requires the Pro tier. Whether your AI application asks you to confirm first depends on that application's own settings.
A refused tool is usually the role, not a fault
SentinelOne checks permissions for each operation separately, against the role of the service user whose token you pasted. So reads can work perfectly while one specific action is refused, and that is not a broken connection — the connection test will still show as connected.
When a tool reports that SentinelOne refused it, widen the service user's role in the SentinelOne console, or point it at a role that already has that permission. Also check that the service user's scope covers the account or site you are asking about. Nothing needs changing in StackJack.
Plans and limits
Read tools are available on the Free tier. Everything that acts on an endpoint, changes protection, edits the customer structure or runs a script is Pro. Business reaches the same tools as Pro and differs by monthly call quota.
See the generated SentinelOne tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.
SentinelOne does not publish a request quota. StackJack paces requests and backs off automatically if you are throttled, which usually makes a large report slower rather than failed. Pacing smooths a burst; it does not guarantee that every call arrives. Retries are bounded, so a wide enough read can still come back throttled or time out. Narrow the read, honour any retry delay the vendor sends, and check whether a write landed before repeating it — see Retrying a failed or timed-out write.
Long lists are read a page at a time. Each page comes back with a marker for the next one, and your AI passes that marker back to read the following page. SentinelOne stops returning results past a certain depth when a caller jumps to a position rather than following the pages in order, so if you need a complete list, ask for the whole list rather than for "the next thousand".
Several customers
Every customer has their own SentinelOne console. Add one connection per console from the connector's card, name it after the customer, and your AI names it on each call. Omit the name and the call runs against your default connection. Pin an endpoint to one connection when an AI should never reach past a single customer. See Several connections of one connector.
Troubleshooting
"SentinelOne did not accept the API token" — the usual cause is that the token expired. SentinelOne tokens are created with a fixed lifetime and nothing renews them, so this is a normal end state rather than a fault. It can also mean the token was revoked, or copied incompletely. Generate a new token for the service user in your console, paste it into StackJack, and run a Test Connection.
"SentinelOne accepted the token but refused this operation" — the service user's role is missing the permission that one operation needs, or its scope does not cover the account or site in question. Widen the role in SentinelOne and try again. Your other SentinelOne tools are unaffected, which is the signal that the credential itself is fine.
"SentinelOne could not find what the request asked for" — check the id being used. SentinelOne ids are long numeric strings, and an id from the threats view is not interchangeable with one from the alerts view. Also confirm the record belongs to a site or account the service user's scope includes.
A customer's machines are missing from a report — check which site or account the report was scoped to before assuming the agents are gone. Everything in SentinelOne hangs off accounts and sites, and a report scoped to the wrong one looks exactly like a customer with no machines.
An action reported success but nothing changed — read the affected count in the response. SentinelOne returns success for a filter that matched nothing, so a count of zero means the filter selected no machines, not that the action failed. Ask your AI to run the matching count first and to re-read afterwards.
A machine shows as disconnected but the customer says it is fine — that is the agent's connection to the console, not the machine's connection to the internet. It usually means the agent is not running or cannot reach your console, and it is worth checking before treating the machine as offline.
SentinelOne tools
s1_ · 696 tools · Free 367 · Pro 329
Activity Log
Agent Deployment and Updates
Alerts
Detection Rules
Endpoint Actions
Endpoints
Network Discovery
Network Quarantine
Tasks
Threat Intelligence
Threats
Accounts and Licensing
Console Settings
Graph Explorer
Groups and Tags
Log Collection
Policies
Reports
Saved Views
Sites
Users and Roles
Application Management
Device Control
Exclusions and Blocklist
Firewall Control
Integrations
Marketplace
PowerQuery
Remote Forensics
Remote Scripts
Account
AI ML
Application Integration
Asset Inventory
Cloud Application
Cloud Surface
Container
Data Analysis
Data Store
Developer Tool
Device
Endpoint Surface
Filters
Function
Governance
Identity
Identity Surface
Network
Network Discovery Surface
Notes
Security Posture
Server
Storage
Tags
Unified Actions
Workstation
More in Connector guides
Connect Acronis Cyber Protect CloudConnect Action1Connect AddigyConnect AlertOpsStill need help? Ask the team