Connect SuperOps
SuperOps is a unified PSA + RMM platform for MSPs, exposed to StackJack through the SuperOps MSP GraphQL API. It covers tickets, assets and monitoring, clients/sites/users/contracts, tasks and…
Written By Christopher Scaminaci
Last updated 6 days ago
SuperOps is a unified PSA + RMM platform for MSPs, exposed to StackJack through the SuperOps MSP GraphQL API. It covers tickets, assets and monitoring, clients/sites/users/contracts, tasks and worklogs, invoicing, the service catalog, knowledge base, IT documentation, and RMM scripts.
Connecting SuperOps to StackJack gives your AI assistant a broad family of superops_ MCP tools — MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:
- Inventory managed assets — hardware, software, disks, patch status, and activity — plus alerts and available scripts
- Manage clients and their sites, users, contracts, custom fields, and stages
- Work tickets — read and create tickets, conversations, notes, and custom fields; triage against categories, priorities, statuses, and SLAs
- Track time with tasks, worklog entries, and work statuses
- Review invoices, taxes, and payment terms; the service catalog; knowledge base; and IT documentation
- Act (on Pro plans) — create and update records, run a script on an asset, resolve alerts, and delete or restore items where SuperOps allows it
- Run advanced GraphQL (on Pro plans) — two passthrough tools let your AI send a raw GraphQL query or mutation for anything the discrete tools don't cover
How StackJack authenticates to SuperOps
SuperOps uses a static, user-scoped API token — there is no OAuth login and nothing to refresh. Authentication needs two values, both required on every request:
- API token — sent as a Bearer token. Generate it in SuperOps under Settings → My Profile → API token. Each user holds only one token at a time; regenerating replaces the previous one.
- MSP subdomain — sent as the
CustomerSubDomainvalue. Find it under Settings → MSP Information. A missing or wrong subdomain fails even when the token itself is valid.
The token inherits exactly the role of the SuperOps user who generated it — everything your AI can see or change is bounded by that user's permissions. Generate the token from a user whose access covers the data StackJack should reach.
Regions
SuperOps runs two data centers. StackJack shows a Region choice that sets the API host:
- US —
https://api.superops.ai/msp - EU —
https://euapi.superops.ai/msp
Pick the region where your SuperOps account is hosted. The Instance URL field fills in from your choice — leave it as shown.
Before you begin
- In StackJack: you need a role that can manage connectors (tenant Owner, a co-owner, or an Administrator).
- In SuperOps: you need a user account that can generate an API token and whose role covers the data you want your AI to work with.
- Know your region — US or EU, matching your SuperOps account.
Step 1 — Generate an API token in SuperOps
- Sign in to SuperOps.
- Go to Settings → My Profile → API token and click Generate.
- Copy the token. Remember: each user holds only one API token at a time — regenerating invalidates the old one.
Step 2 — Find your MSP subdomain
- Go to Settings → MSP Information.
- Copy your subdomain (the
CustomerSubDomainvalue). You'll paste this alongside the token.
Step 3 — Add the credentials in StackJack
- In the StackJack portal, open Connectors.
- Find the SuperOps card. Click How To Connect for the same steps inline, or Configure to enter the credentials.
- Choose your Region (US or EU). The Instance URL field auto-fills — leave it as shown.
- Enter your MSP subdomain and the API token.
- Click Save.
What happens when you save
- The subdomain and token are stored encrypted in Azure Key Vault — never in the StackJack database, and never shown back to you.
- If this is the first time you configure SuperOps, a Free-tier subscription for the connector is created automatically so its Free tools work right away.
- StackJack immediately live-validates the credentials by running a small technician-list query. This confirms all three of the token, the subdomain, and the region are correct together. Validation never blocks the save: you'll either see a success confirmation or a "saved but validation failed" warning with the reason.
- The connector card shows the connection and validity status from then on.
How SuperOps returns results
SuperOps is a GraphQL API. Tools return the SuperOps response body as-is. Two things are worth knowing:
- Errors come back in the body, not as a failure. When SuperOps can't fulfil a request (a bad filter, a missing record, a permission gap), it still returns a normal response containing an
errorslist describing the problem. Your AI reads that and can adjust — it is not a StackJack outage. - Clearing a field vs. leaving it alone. On update tools, leaving a field out keeps its current value; explicitly setting it to empty clears it. The write tools expose a way to name the fields you want cleared, so your AI won't wipe data it simply didn't mention.
Plans and available tools
- Free includes reads across assets, alerts, scripts, clients, sites, users, contracts, tickets, tasks, worklogs, fields, the service catalog, invoices and taxes, knowledge base, IT documentation, ticket reference data, technicians, and business setup.
- Pro adds create, update, delete/soft-delete/restore, script execution on an asset, alert resolution, and the advanced GraphQL passthrough tools.
- Business offers the same tool set as Pro with a higher monthly call quota.
See the generated SuperOps tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.
SuperOps issues a single account-scoped API token (no per-user OAuth), so there is no per-user attribution — all AI traffic authenticates as the token's generating user. Current pricing and quotas are shown in the portal's Billing page and at checkout.
Safety note — powerful tools. A handful of Pro tools are irreversible or high-impact: deleting or soft-deleting clients, tickets, sites, users, fields, knowledge-base and IT-documentation items; and running a script on an asset, which executes code on the managed device. The two advanced GraphQL passthrough tools (
superops_run_queryandsuperops_run_mutation) can reach anything the token can, so they are Pro-gated and flagged as requiring confirmation. Scope your AI's access deliberately — use the tool selections on the MCP Setup page and the Permissions page to enable only the actions you want an AI to take.
Rate limits
SuperOps publishes an account-wide limit of 100 requests per minute for both its MSP and IT platforms. StackJack paces tool calls per tenant and honors any 429 backoff, so a long multi-page read is usually just slower. Pacing is not a guarantee: retries are bounded, so a wide enough read can still come back throttled or time out. Narrow the read, honour any retry delay the vendor sends, and check whether a write landed before repeating it — see Retrying a failed or timed-out write. StackJack's own pacing budget is 90 requests per minute per organization, below SuperOps' published ceiling, and a 429 backoff still covers traffic from anything else that uses the same token.
Rotating or replacing the credentials
The API token is the recovery secret. If you regenerate the token in SuperOps (or the generating user's access changes), the stored credential becomes invalid. To restore access, open Connectors → SuperOps → Configure in StackJack, paste the new token (re-select the region and re-enter the subdomain if needed), and Save.
Troubleshooting
SuperOps tools
superops_ · 139 tools · Free 76 · Pro 63
Assets & Monitoring
Alerts & Scripts
Clients
Client Custom Fields
Client Stages
Client Sites
Client Users
Client Contracts
Tickets
Tasks & Worklogs
Fields
Service Catalog
Financial
Knowledge Base
IT Documentation
Ticket Reference Data
Technicians & Teams
Business Setup
GraphQL Passthrough
More in Connector guides
Connect Acronis Cyber Protect CloudConnect Action1Connect AddigyConnect AlertOpsStill need help? Ask the team