Connect TD SYNNEX
TD SYNNEX is a global technology distributor, and it runs two separate systems with two separate logins. StackJack connects to both:
Written By Christopher Scaminaci
Last updated 3 days ago
TD SYNNEX is a global technology distributor, and it runs two separate systems with two separate logins. StackJack connects to both:
- StreamOne ION — the cloud marketplace for resellers. Create end customers, browse the cloud product catalog, build carts, place and manage orders, track subscriptions, and pull reporting.
- Hardware XML — the hardware distribution business. Look up reseller pricing and warehouse stock for physical products, quote freight, submit purchase orders, and check their status.
They are entitled separately by TD SYNNEX, so set up whichever you use — one, or both. Each has its own tab in the Configure dialog, and the other can stay empty.
Connecting TD SYNNEX gives your AI assistant two families of MCP tools — MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. The tds_ion_ tools cover the cloud marketplace; the tds_xml_ tools cover hardware.
With the StreamOne ION tools, your AI can:
- Inventory your end customers, their cloud profiles, and the linked cloud providers behind them
- Browse the product catalog, including individual products, verticals, and categories
- Track orders across your whole account or for one customer, and read a single order's full detail
- Review subscriptions across the account and drill into one customer's subscription
- Read provisioning templates and pull reports (report list, metadata, and report data)
- Create and update (on Pro plans) end customers, carts, and the items in a cart
- Transact (on Pro plans) — submit an order (the same call also amends and renews existing subscriptions), cancel an order, and check a cart out
With the Hardware XML tools, your AI can:
- Price and stock-check hardware in one batched request, with a per-warehouse stock breakdown
- Quote freight for a prospective shipment, and discover which ship methods are available for it
- Check the status of a purchase order you placed
- Submit (on Pro plans) a hardware purchase order
Scope note. This connector covers the StreamOne ION Partner API and the hardware XML API. TD SYNNEX also publishes a separate Digital Bridge API for reseller product catalogue and order tracking; it is not covered yet, because its public documentation does not include the details needed to sign in to it. If Digital Bridge matters to you, let us know — the remaining piece is a documentation gap on the vendor's side, not a large build.
On the hardware side, returns are not covered: TD SYNNEX publishes no usable schema for creating an RMA or reading a credit memo on this API, so there is nothing to build against. There is also no full catalogue download — hardware pricing is looked up per product, not bulk-exported.
Two StreamOne ION actions are not available yet: creating a new cloud tenant for a customer, and linking an existing one. Reading a customer's cloud profiles and their linked provider works normally.
How StackJack authenticates to TD SYNNEX
StreamOne ION has no machine-to-machine login. You request an OAuth credential once in the ION portal, which gives you a refresh token. You paste that refresh token into StackJack; from then on StackJack exchanges it for short-lived access tokens automatically and saves the newly issued refresh token each time — there is nothing for you to refresh manually.
The credential inherits exactly the ION user's access — everything your AI can see or change is bounded by that user's entitlements and customer visibility. A 403 from a tool means that ION user isn't entitled to the action, not that the credential is broken.
The refresh token is single-use. It rotates every time it's used, so the value you copy from the ION portal is only good until StackJack consumes it. Don't paste the same token into another tool or script — whichever one uses it first invalidates it for the other. If the stored credential is ever lost or gets out of sync, request new OAuth credentials in the ION portal.
Refresh tokens also expire after 32 days of disuse. A TD SYNNEX connector that sits idle for over a month will need new OAuth credentials.
Your account ID
Nearly every StreamOne ION request is made on behalf of a reseller account, so StackJack stores your account ID alongside the refresh token. It's the numeric id shown for your account in the ION portal, and it also appears in ION API URLs immediately after /accounts/. If you're unsure which value it is, your TD SYNNEX contact can confirm it.
Your AI can override the account ID on an individual tool call if you work across more than one ION account, but the stored value is what every tool uses by default.
There's no region or URL to choose — StreamOne ION is served from a single fixed endpoint.
Before you begin
- In StackJack: you need a role that can manage connectors (tenant Owner, a co-owner, or an Administrator).
- In StreamOne ION: you need access to the ION portal's Settings → Users area so you can request OAuth credentials, and you should decide which ION user the connector should act as — its entitlements become your AI's reach.
- Know your account ID (see above).
Step 1 — Request OAuth credentials in StreamOne ION
- Sign in to the StreamOne ION portal.
- Click the Settings icon in the top-right corner.
- Click Users.
- Select the user you want the connector to act as, then click Edit.
- Under OAuth credentials, click Request New Credentials.
- Copy the Refresh Token that's generated — that's the value StackJack stores.
You'll see more values than StackJack asks for. The credentials panel also generates a Client ID and Client Secret — StackJack doesn't need them. The ION V3 API authenticates with the refresh token alone; there is no machine-to-machine login that would use the client id and secret. Likewise, the API Key and API Secret under Settings → Account Information belong to TD SYNNEX's older v1 API and aren't used here either.
Step 2 — Add the credentials in StackJack
- In the StackJack portal, open Connectors.
- Find the TD SYNNEX card. Click How To Connect for the same steps inline, or Configure to enter the credential.
- Enter your Account ID.
- Paste the Refresh Token you copied from the ION portal.
- Click Save.
Setting up Hardware XML
The hardware distribution system is configured on the Hardware XML tab of the same Configure dialog, and it is entirely independent of StreamOne ION — different credentials, different login, separate entitlement. You can set it up on its own without ever entering an ION refresh token.
What you need
Your ECExpress account: the customer number TD SYNNEX invoices you under, plus the username and password you sign in to the ECExpress website with. All three are required together.
⚠️ An ECExpress login is not enough on its own. TD SYNNEX must also switch on XML / Price & Availability API access for your account. Email your TD SYNNEX helpdesk or ask your sales representative to enable it. Until that's done, credentials that work perfectly on the ECExpress website can still be refused here — so if setup fails and you're sure the password is right, this is almost always why.
Hardware credential validation may not catch a wrong password. TD SYNNEX's hardware system has been seen accepting an incorrect password and answering normally, so a successful validation on save or later Re-test confirms StackJack reached the service and your customer number is recognised — it does not prove the password is right. A bad password can first surface later, on a live call. Check it against the ECExpress website rather than relying on the validation alone. (The StreamOne ION tab has no such caveat: a wrong refresh token fails its validation immediately.)
Region and environment
Two dropdowns select which TD SYNNEX system your hardware account lives on:
- Region — United States or Canada.
- Environment — Production or Test (UAT). Leave this on Production unless TD SYNNEX has specifically given you test credentials. Orders placed against Production are real.
Both are remembered when you edit the connector later, so rotating your ION refresh token won't disturb them.
How the hardware tools fit together
The hardware API has no lookup tables — the values one tool needs come from another tool's response, so the order matters:
- Price and availability first. As well as prices, this returns a per-warehouse stock breakdown. The warehouse numbers in that response are the only place warehouse numbers come from — there is no warehouse list.
- Freight quote second. It requires a warehouse to ship from, which is why price and availability comes first. Its response is also the only published source of ship-method codes, and those codes are specific to that warehouse, destination and weight rather than a fixed list.
- Purchase order last, using the warehouse number and ship-method code you gathered.
Two behaviours are worth knowing about, because they surprise people:
- Results come back in a different order than you asked for them. The system groups them by outcome (found, discontinued, not found) rather than keeping your order. Every line carries back the line number you gave it, and that's what your AI matches on — so this is handled, but it's why a response won't read top-to-bottom against your request.
- Errors arrive as a successful response. This API reports problems in the body rather than as a failure, so a "successful" call can still contain an error message. Your AI sees the message either way.
What happens when you save
- The refresh token is stored encrypted in Azure Key Vault — never in the StackJack database, and never shown back to you. Your account ID is stored the same way.
- If this is the first time you configure TD SYNNEX, a Free-tier subscription for the connector is created automatically so its Free tools work right away.
- StackJack immediately live-validates the credential by acquiring an access token and calling a cheap read (the product categories list for your account). Because the refresh token is single-use, this first validation is what consumes the pasted value and stores the rotated replacement. Validation never blocks the save: you'll either see a success confirmation or a "saved but validation failed" warning with the reason.
- The connector card shows the current connection and validity status from then on.
Re-test is safe to use, but don't hammer it. Every check reuses the access token StackJack already holds, so repeated tests normally cost nothing. When that token has expired, the next call has to renew it — which rotates your refresh token. That's routine and handled automatically; just avoid running Re-test from several browser tabs at the same moment.
Working with accounts, customers and carts
Most tools take a customer id, which your AI discovers with tds_ion_list_customers. From a customer id it can reach that customer's orders, subscriptions, cloud profiles, and cloud providers.
Carts work slightly differently: a cart belongs to a customer, and cart items belong to a cart. The usual sequence your AI follows is create a cart, add items to it, then check the cart out — checkout is the step that actually places the order. Your AI can also submit an order directly without building a cart first.
When you edit the connector later, both fields support leave blank to keep the current value — so you can replace just the refresh token without re-entering your account ID, or vice versa.
Plans and available tools
- Free includes reads from StreamOne ION for end customers, cloud profiles and providers, products, verticals, categories, orders, subscriptions, provisioning templates, carts, and reports. From Hardware XML it includes price and availability, freight quotes, and purchase-order status.
- Pro adds StreamOne ION actions to create and update end customers and carts, add and update cart items, check out a cart, and submit or cancel an order. From Hardware XML it adds purchase-order submission.
- Business offers the same tool set as Pro with a higher monthly call quota.
See the generated TD SYNNEX tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.
Neither TD SYNNEX system offers per-user attribution, so all AI traffic authenticates as the single user whose credentials you saved on each tab. Current pricing and quotas are shown in the portal's Billing page and at checkout.
Safety note — these tools spend money. On StreamOne ION, checking a cart out and submitting an order place real, billable orders. The submit-order call is also how ION amends orders, so it can change or cancel live subscriptions, and cancelling an order can terminate the services it provisioned. Updating a cart counts too: a cart's status is one of the fields you can write and "checked out" is one of its values, so an update can complete a purchase.
Submitting a hardware purchase order is the most serious of all of them, because it cannot be undone. It buys real physical goods, and unlike the cloud side there is no cancellation available through the API at all — if an order is placed in error, the only remedy is to contact TD SYNNEX directly. Two further points: your purchase order number must be unique, because it's the only way to look the order up afterwards; and every line states the price you expect to pay, so prices should be read immediately beforehand.
Card payment is deliberately not available through StackJack. Hardware orders placed here are account-terms orders only — card details must never pass through an AI interface. Use ECExpress directly for a card order.
StackJack marks all five of these as write or destructive actions. Whether your AI application asks you to confirm before running one depends on that application's own settings — see Destructive tools and confirmation. Grant the connector only to trusted agents, and use the tool selections on the MCP Setup page and the Permissions page to enable only the actions you want an AI to take.
Rate limits
StreamOne ION publishes no fixed API quota. StackJack applies a conservative per-tenant pace and honors any 429 backoff, so a long multi-page catalog or order read is usually just slower. Pacing is not a guarantee: retries are bounded, so a wide enough read can still come back throttled or time out. Narrow the read, honour any retry delay the vendor sends, and check whether a write landed before repeating it — see Retrying a failed or timed-out write.
Rotating or replacing the credential
The stored refresh token is the recovery secret, and it is single-use. If it's lost, gets out of sync, or expires from disuse, request new OAuth credentials in the ION portal (Settings → Users → Edit → OAuth credentials → Request New Credentials), then open Connectors → TD SYNNEX → Configure in StackJack, paste the new refresh token, and Save. Leave the Account ID field as-is unless it changed.
Troubleshooting
TD SYNNEX tools
tds_ · 37 tools · Free 27 · Pro 10
End Customers
Products & Catalog
Orders
Subscriptions
Cloud Providers & Provisioning
Carts & Checkout
Reports
XML Hardware
More in Connector guides
Connect Acronis Cyber Protect CloudConnect Action1Connect AddigyConnect AlertOpsStill need help? Ask the team