Connect ConnectWise Automate
ConnectWise Automate is a remote monitoring and management (RMM) platform for endpoint management, patching, and scripting. Connecting it to StackJack lets your AI assistant query and act on managed…
Written By Christopher Scaminaci
Last updated About 22 hours ago
ConnectWise Automate is a remote monitoring and management (RMM) platform for endpoint management, patching, and scripting. Connecting it to StackJack lets your AI assistant query and act on managed computers, clients, scripts, patches, and monitors. Tool results are passed through as raw Automate API responses.
The integration provides tools with the cwa_ prefix spanning:
See the generated ConnectWise Automate tool reference for the current inventory, input schemas, plan tiers, and safety notes. Tool availability depends on your Automate plan tier — the in-portal tool selector and the Permissions page (/permissions) show exactly which tools your plan includes.
How authentication works
Automate authentication combines three things:
- A tenant-specific Integrator or local API account, whose username and password StackJack exchanges for a bearer token. Tokens are cached and renewed before expiry; a rejected token is refreshed and retried once.
- A ConnectWise client ID request header, which identifies the calling application to ConnectWise and has been required on every Automate API request since Automate v2020 Patch 11. New connections use StackJack's own client ID, so there is nothing to enter; if your company already uses its own client ID for this integration, you can enter it under Advanced instead. Existing connections keep the client ID they were set up with. A connection that was set up without a client ID opens on StackJack's client ID when you edit it; to keep it without one, choose your own client ID under Advanced and leave the box blank.
- An optional base32 TOTP seed, if the account uses authenticator-app MFA.
This is a single shared credential for your whole team — Automate attributes all activity to the account you create. There is no per-user sign-in for this connector.
Prerequisites in ConnectWise Automate
- Create an Integrator account. In Automate, create a dedicated Integrator or local API user account for StackJack. The account may optionally use authenticator-app MFA (TOTP); push-based MFA such as Duo push, Microsoft Authenticator number matching, or security keys is not supported.
- Capture the TOTP seed (only if MFA is enabled). When you scan the enrollment QR code, capture the base32 secret it encodes. That seed — not a six-digit code — is what StackJack stores, and it generates a fresh code for each token request.
- Record the credentials: the Integrator username, its password, and the authenticator seed if applicable.
Set up the connector in StackJack
- In the StackJack portal, go to Connectors and find the ConnectWise Automate card.
- Optional: click How To Connect for the in-portal version of this guide.
- Click Configure and fill in the fields:
- Click Save.
What happens when you save
- Your credentials are stored in Azure Key Vault — never in the StackJack database, and never shown back to you.
- A Free-tier connector subscription is created automatically if you don't already have one.
- StackJack immediately test-calls your Automate server. A failed or timed-out test shows a warning but does not block the save — StackJack retries validation in the background.
- If you paste what looks like the current six-digit code instead of the base32 seed, the save is blocked before anything is stored, with an explanation of the difference.
TOTP behavior
- Once a seed is stored, the Authenticator Secret field shows "(currently configured — leave blank to keep)", so you can change the username or password without re-typing it.
- Use the explicit clear control when MFA has been removed from the account — a blank field keeps the stored seed rather than removing it.
- Never send the seed to support; it is equivalent to the second factor itself.
Instance URL guidance
- ConnectWise-Cloud installs (
https://yourcompany.hostedrmm.com) typically use the bare host with no path suffix. - Partner-hosted and on-premises installs often need a
/cwasuffix, for examplehttps://yourserver.example.com/cwa. - Never include
/api,/api/v1, or/api/v1/APIToken; StackJack appends API paths automatically.
If the bare host returns a 404 at validation, try appending /cwa before changing anything else.
Per-user connections
Not supported for this connector. All team activity in Automate is attributed to the Integrator account you configured.
Limits and behavior
Troubleshooting
The term 'ConnectWise' is a trademark of ConnectWise, LLC. This application uses the ConnectWise API but is not endorsed or certified by ConnectWise.
Disconnecting: the Disconnect button deletes the stored credentials from Key Vault and immediately stops all Automate tool calls. It does not disable the Automate account upstream — do that separately if you are retiring the integration. Disconnecting also does not cancel a paid connector plan; cancel that from the connector card first.
ConnectWise Automate tools
cwa_ · 207 tools · Free 123 · Pro 84
System & Configuration
Users & Access
User Classes
Auditing
Clients
Client Sub-Resources
Locations
Location Extra Fields
Computers
Alert Suspensions
Computer Hardware
Computer Software & Services
Computer OS & Networking
Computer Patching
Third-Party Patches
Computer Scripts
Computer Maintenance
Fleet-Wide Queries
Alerts
Contacts
Tickets
Scripts
Script Folders
Groups
Group Policies
Monitors
Patching
Network Devices
Batch Operations
Probes
Probe Lookups
Searches
Remote Agents
Data Views & Misc
More in Connector guides
Connect Acronis Cyber Protect CloudConnect Action1Connect AddigyConnect AlertOpsStill need help? Ask the team