Connect Sherweb
Sherweb is a cloud marketplace and distribution platform for MSPs, exposed to StackJack through Sherweb's public APIs. It covers your customers, their product catalogs and pricing, platform…
Written By Christopher Scaminaci
Last updated 6 days ago
Sherweb is a cloud marketplace and distribution platform for MSPs, exposed to StackJack through Sherweb's public APIs. It covers your customers, their product catalogs and pricing, platform provisioning (such as Microsoft), subscriptions, orders, and billing.
Connecting Sherweb to StackJack gives your AI assistant a focused family of sher_ MCP tools — MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:
- Review billing — the Distributor payable-charges report (what you owe Sherweb) and per-customer receivable charges (what you bill your customers)
- List customers and read their configured vendor platforms, platform details, and metered usage
- Explore catalogs and pricing — a customer's purchasable catalog, item pricing, the platform directory, platform-required parameters, and product-to-SKU mapping
- Inspect subscriptions — subscription details, pricing, and meters
- Act (on Pro plans) — configure customer platforms, amend or cancel subscriptions, and place orders (always after a no-side-effect validation)
How StackJack authenticates to Sherweb
Sherweb uses OAuth 2.0 client_credentials together with a static subscription key. Sherweb's public guide directs partners to Partner Portal → Security → APIs for API keys, and StackJack's shipping integration requires three values from that registration:
- Client ID and Client Secret — the OAuth credentials StackJack exchanges for a bearer token. StackJack caches and renews bearer tokens automatically; you never paste an access token.
- Subscription Key — an API gateway key sent on every call as the
Ocp-Apim-Subscription-Keyheader, in addition to the OAuth token. A missing or wrong subscription key fails authentication even with a valid Client ID and Secret.
There is no per-user sign-in — all AI traffic authenticates with this single partner credential set.
Two API families: Distributor and Service Provider
Sherweb splits its API into two scope families. The token endpoint requires distributor, service-provider, or both, and the APIs available to your application depend on its Sherweb configuration and partner agreement:
- Distributor (production) — the payable-charges billing report (
sher_get_payable_charges). - Service Provider (Beta) — everything else: customers, catalogs, platforms, subscriptions, and orders.
StackJack automatically requests the matching scope for each tool. If a tool returns a 403, the application or partner account most likely lacks that API family or operation; contact Sherweb to confirm access. A credential set that works for only one family can still validate and use that family's tools.
Service Provider is in Sherweb Beta. Sherweb labels the Service Provider API as Beta, so its response shapes may change over time.
Before you begin
- In StackJack: you need a role that can manage connectors (tenant Owner, a co-owner, or an Administrator).
- In Sherweb: you need administrator access to the Sherweb Partner Portal sufficient to create an API application under Security → APIs.
Step 1 — Create API credentials in Sherweb
- Sign in to the Sherweb Partner Portal as an administrator and go to Security → APIs.
- Create or open the API registration that StackJack should use and collect its Client ID, Client Secret, and Subscription Key.
- Confirm whether the registration can request the
distributorscope, theservice-providerscope, or both. This determines which tool families can succeed. - Store all three values securely. Sherweb's public guide does not document whether an existing client secret can be displayed again; if the portal no longer reveals it, issue a replacement instead of guessing.
Step 2 — Add the credentials in StackJack
- In the StackJack portal, open Connectors.
- Select the Sherweb card. Choose How To Connect for the inline checklist or Configure to enter credentials.
- Enter the Client ID, Client Secret, and Subscription Key. No URL is required — Sherweb's API host is fixed.
- Click Save.
What happens when you save
- All three values are stored encrypted in Azure Key Vault — never in the StackJack database, and never shown back to you.
- If this is the first time you configure Sherweb, a Free-tier subscription for the connector is created automatically so its Free tools work right away.
- StackJack performs side-effect-free validation by acquiring a token and reading Service Provider platforms. If that family rejects the credential, StackJack tries the Distributor payable-charges read so a Distributor-only credential can still validate.
- Validation does not discard a credential that Sherweb rejects. A successful probe shows Connected. A failed probe shows Needs Attention with the upstream reason and a Re-test action.
Asynchronous operations
Some Service Provider actions — subscription amendments, subscription cancellations, and orders — complete asynchronously. They return a tracking id. Your AI polls sher_track_request with that id until the status reaches Success or Failure (the intermediate states are Queued and Processing).
Collection and language behavior
Sherweb's published endpoints do not expose a common page, offset, or cursor parameter, so StackJack does not invent one: list operations return the collection Sherweb sends in that response. Avoid scheduling multiple full-customer or catalog inventories at the same time.
Where a tool offers acceptLanguage, use en or fr. StackJack sends it as Accept-Language; omitting it leaves Sherweb's default language in effect.
Plans and available tools
- Free includes billing reports, customer and platform reads, catalog and pricing lookups, and subscription details, pricing, and meters. (Several of these are query endpoints that take a request body but only read data.)
- Pro adds actions to configure customer platforms, amend subscriptions, cancel subscriptions, and place orders.
- Business offers the same tool set as Pro with a higher monthly call quota.
See the generated Sherweb tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.
Sherweb has no per-user OAuth, so there is no per-user attribution — all AI traffic authenticates as the single partner credential set. Current pricing and quotas are shown in the portal's Billing page and at checkout.
Safety note — cancelling subscriptions.
sher_cancel_subscriptionsis marked destructive: cancelling may end a customer's service and cannot be undone through this API. Scope your AI's access to write tools deliberately — use the tool selections on the MCP Setup page and the Permissions page to enable only the actions you want an AI to take. Always runsher_validate_place_orderbeforesher_place_orderto catch cart problems without placing a real, billable order.
Rate limits
Sherweb's public API documentation does not publish one general numeric quota. StackJack applies an aggregate limit of about 120 requests per minute per tenant and records API-gateway 429 responses so later calls back off. That local guard is not a promise of Sherweb capacity: reduce concurrency and retry after a short delay if the gateway continues throttling.
Rotating or replacing the credentials
The Client ID, Client Secret, and Subscription Key are the recovery secret. If you regenerate any of them in the Sherweb Partner Portal, the stored credential becomes invalid. To restore access, open Connectors → Sherweb → Configure in StackJack, enter the new values, and Save.
Disconnecting Sherweb
Use Disconnect in the Sherweb drawer to remove StackJack's stored Client ID, Client Secret, and Subscription Key and stop future Sherweb API calls. Disconnecting does not revoke the API registration in Sherweb and does not reverse platform configuration, subscription amendments/cancellations, or orders already submitted. Disable or rotate the keys separately in Sherweb if they should no longer work anywhere.
For a Free subscription, the confirmation can also remove Sherweb tools from tool lists. A paid connector plan remains separate billing state; use Manage on Billing on the connector card if you also want to end it — it opens this connector's removal dialog on the Billing page. A legacy website subscription reads Cancel Plan instead.
Troubleshooting
Sherweb tools
sher_ · 21 tools · Free 17 · Pro 4
Billing
Customers
Catalog & Platforms
Subscriptions
Orders
More in Connector guides
Connect Acronis Cyber Protect CloudConnect Action1Connect AddigyConnect AlertOpsStill need help? Ask the team