Connect Cork
Cork is a cyber-warranty and risk-management platform for MSPs. It pulls data from the tools you already run — RMM, EDR, MFA, Microsoft 365 — scores each client's security posture (the Cork Cyber…
Written By Christopher Scaminaci
Last updated 6 days ago
Cork is a cyber-warranty and risk-management platform for MSPs. It pulls data from the tools you already run — RMM, EDR, MFA, Microsoft 365 — scores each client's security posture (the Cork Cyber Score), tracks the compliance events that can affect warranty coverage, surfaces software vulnerabilities, and issues cyber-warranty packages per client. Newer Cork accounts can also push software installs to endpoints through a connected RMM. StackJack talks to Cork through the Cork public API.
Connecting Cork to StackJack gives your AI assistant a focused family of cork_ MCP tools — MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:
- Review risk — client Cyber Score history and warranty status, compliance events (including which are actively at risk), and software vulnerabilities with CVE detail: CVSS and EPSS scores, known-exploited flags, and impacted versions
- Inventory assets — the devices, email domains and inboxes Cork observes for each client, and the devices, tenants and users behind each connected integration
- Audit coverage and billing — active warranty packages, invoices, and invoice line items
- Manage integrations (on Pro plans) — connect a new integration, update or remove one, and trigger a data refresh
- Install software (on Pro plans) — dispatch a package to a single device through its RMM, and review the history of past install attempts
How StackJack authenticates to Cork
Cork uses a single API key. You create the key in the Cork platform and StackJack sends it on every request as a bearer credential. There is no client ID, no sign-in redirect, and nothing to refresh.
Two things about Cork keys are worth understanding before you create one, because both shape what your AI can do:
Keys expire, and cannot renew themselves. When you create a Cork API key you choose a timeframe after which it expires. Cork has no way to renew it automatically and StackJack cannot extend it, so when the key lapses every Cork tool starts failing with an authorization error until you create a replacement and paste it in. Choose the longest expiry your security policy allows, and put the expiry date in your calendar.
A key inherits the permissions of the person who created it. Cork has no per-key permission checkboxes. Whatever the creating user can see and do in Cork is exactly what the key — and therefore your AI — can see and do. This matters most for distributor features: if you manage partner sub-accounts, the partner tools, the partner-scoped filters, and integration raw-data downloads all require a key created by a distributor user. A 403 from one tool while others succeed is almost always this, not a StackJack-side block.
Cork is a global service with one address (https://api.corkinc.com/api/v1) — there are no regional endpoints, so there is no region to choose.
Before you begin
- In StackJack: you need a role that can manage connectors (tenant Owner, a co-owner, or an Administrator).
- In Cork: you need access to the Cork platform with permission to create an API key — and, if you want the distributor tools, you need to be signed in as a distributor user when you create it.
Step 1 — Create an API key in Cork
- Sign in to the Cork platform. Sign in as the user whose access you want the key to carry — a distributor user if you manage partner sub-accounts.
- Open the Admin tab and select API Keys.
- Click Add API Key.
- Give the key a name (something that identifies StackJack) and choose the timeframe after which it should expire. Pick the longest expiry your policy allows — Cork cannot renew it for you.
- Generate the key, then copy it immediately and store it securely — treat it like a password. Anyone with the key can read and act on your Cork account.
Step 2 — Add the credential in StackJack
- In the StackJack portal, open Connectors.
- Find the Cork card. Click How To Connect for the same steps inline, or Configure to enter the key.
- Paste your API key. There is no client ID or URL to enter — the address is fixed.
- Click Save.
What happens when you save
- The key is stored encrypted in Azure Key Vault — never in the StackJack database, and never shown back to you.
- If this is the first time you configure Cork, a Free-tier subscription for the connector is created automatically so its Free tools work right away.
- StackJack immediately live-validates the key by making a cheap authenticated read against your Cork account. Validation never blocks the save: you'll either see a success confirmation or a "saved but validation failed" warning with the reason.
- The connector card shows the current connection and validity status from then on.
Plans and available tools
- Free includes reads for clients and their devices, domains and inboxes; compliance events, notification settings and event types; software vulnerabilities and the product-level vulnerability summary; available and connected integrations plus each integration's devices, tenants and users; integration credentials and raw-data downloads; invoices and line items; partners; software-installer packages, history and setup instructions; warranties; and an account check.
- Pro adds actions to connect, update, delete and resync an integration; provision a partner; and install software on a device.
- Business offers the same tool set as Pro with a higher monthly call quota.
See the generated Cork tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.
Cork has no per-user sign-in for the API (the key is a single account credential), so all AI traffic authenticates as that one key — there is no per-user attribution. Current pricing and quotas are shown in the portal's Billing page and at checkout.
A note on the sensitive tools. Four Pro tools change real state outside StackJack, and StackJack marks them as sensitive: installing software on a customer's device through its RMM; updating an integration, which replaces its stored credentials in place; deleting an integration, which stops all data collection from it; and provisioning a partner, which creates a permanent billable account and by default emails the contact you name. Two read tools also deserve deliberate scoping: one returns a connected integration's credentials in plain text, and one produces a download link to an integration's full raw synced data. Cork documents that raw-data link as expiring after 10 minutes; treat it as a short-lived secret and fetch it only when needed. Both reads are separated into their own permissions so you can allow ordinary integration reads without allowing them. Whether your AI application asks you to confirm before running a sensitive tool depends on that application's own settings — see Destructive tools and confirmation. Review those settings, and use the tool selections on the MCP Setup page and the Permissions page to enable only what you want an AI to reach.
Integrations created in the Cork interface are protected. Reading, updating or deleting an integration's credentials, and downloading its raw data, only work for integrations that were created through the API. If you set an integration up in the Cork interface, Cork refuses those requests — that is Cork protecting it, not a StackJack limitation.
Software installs are asynchronous, and "success" is not "installed". An install is handed off to the device's RMM and completes on its own schedule. The install history reports the dispatch state, where
successmeans the RMM accepted the job — not that the software finished installing on the device. A device must also be marked as install-capable in Cork before it can be targeted, and some RMM vendors need a one-time setup step in the RMM first; the setup-instructions tool returns exactly what to create.
Rate limits
Cork does not publish a numeric request limit. StackJack paces Cork requests conservatively and backs off automatically if Cork signals a rate-limit response, so a long multi-page inventory read is usually just slower. Pacing is not a guarantee: retries are bounded, so a wide enough read can still come back throttled or time out. Narrow the read, honour any retry delay the vendor sends, and check whether a write landed before repeating it — see Retrying a failed or timed-out write. Cork's API publishes a possible 429 response for manual integration refreshes but no numeric refresh quota. Cork already refreshes integrations on its own schedule, so repeated manual resyncs are normally unnecessary.
Rotating or replacing the key
The API key is the only credential, so replacing it is the whole recovery path. You will need to do this at least once, when the key reaches the expiry you chose. To replace it: create a new key in the Cork platform under Admin → API Keys, then open Connectors → Cork → Configure in StackJack, paste the new key, and Save. Nothing else needs changing.
Troubleshooting
Cork tools
cork_ · 30 tools · Free 24 · Pro 6
Clients
Compliance
Vulnerabilities
Distributor
Integrations
Invoices
Account
Software Installer
Warranties
More in Connector guides
Connect Acronis Cyber Protect CloudConnect Action1Connect AddigyConnect AlertOpsStill need help? Ask the team