Connect CyberCNS (ConnectSecure)
CyberCNS — now branded ConnectSecure — is a vulnerability-management and attack-surface platform built for MSPs. It scans your managed companies for vulnerabilities, inventories assets and installed…
Written By Christopher Scaminaci
Last updated 6 days ago
CyberCNS — now branded ConnectSecure — is a vulnerability-management and attack-surface platform built for MSPs. It scans your managed companies for vulnerabilities, inventories assets and installed software, monitors external attack surface, runs compliance assessments, and reports on Active Directory and Azure posture. StackJack connects to its V4 API.
Connecting CyberCNS to StackJack gives your AI assistant a broad family of cns_ MCP tools — MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:
- Inventory managed companies, agents, assets, installed software, hardware detail, firewall configuration, ports, and certificates
- Assess vulnerabilities, attack-surface findings, compliance posture, and security baselines across your clients
- Report on remediation plans and velocity, problem summaries, and AD/Azure directory posture through the built-in report queries
- Manage (on Pro plans) companies, credentials, discovery settings, scan schedules, tags, EDR and PII settings, integrations, and vulnerability suppressions
- Build (on Pro plans) standard report jobs and manage report templates and cover pages
How StackJack authenticates to CyberCNS
CyberCNS V4 uses a bespoke token exchange rather than standard OAuth. You provide three things — your Tenant Name, a Client ID, and a Client Secret — and StackJack presents them to your pod's authorize endpoint to receive a short-lived access token. StackJack caches that token and re-mints a fresh one automatically when it expires. There is no refresh token and nothing for you to rotate beyond the API key itself.
The Client ID and Client Secret are a per-user API key. In the current ConnectSecure portal, create it under Global → Settings → Users → the user's three-dot action menu → API Key. Every tool call runs with that user's permissions — a 403 from a tool means the key's user lacks access to that resource, not an account-wide block. Create the key on a dedicated user whose access matches what you want your AI to see and do.
Your pod host
CyberCNS has no single global address — each tenant lives on a numbered pod (for example https://pod401.myconnectsecure.com), which you can read from your browser's address bar while signed in to ConnectSecure. On-premises installations use your own ConnectSecure host with the same API. You enter this host as the Pod URL; it must match where the API key was created. The ConnectSecure sign-in address https://portal.myconnectsecure.com is not a pod host — it carries no API, so saving it fails with a 405 even when your Tenant Name, Client ID and Client Secret are correct.
Before you begin
- In StackJack: you need a role that can manage connectors (tenant Owner, a co-owner, or an Administrator).
- In ConnectSecure: access sufficient to view Global → Settings → Users and create an API key for a user.
- Know your pod host — the
https://podNNN.myconnectsecure.com(or on-prem) address shown in the portal. - Review ConnectSecure's current API FAQ. Your pod's live Swagger documentation is available under Profile → API Documentation.
Step 1 — Find your pod host and tenant name
- Sign in to ConnectSecure.
- Note the host in your browser's address bar — that is your Pod URL (for example
https://pod401.myconnectsecure.com). - Note your Tenant Name — the account/company identifier your ConnectSecure account is known by. It is the first component of the API authorization and is required.
Step 2 — Create an API key
- Go to Global → Settings → Users.
- Find the user the API should act as. Prefer a dedicated user whose access matches what you want your AI to do rather than a personal admin login.
- Open that user's three-dot action menu, choose API Key, and generate the credential. This yields a Client ID and Client Secret.
Step 3 — Add the credentials in StackJack
- In the StackJack portal, open Connectors.
- Select the CyberCNS (ConnectSecure) tile to open its details. Choose How To Connect to review the inline setup guide, or Configure to reveal the credential form in the drawer.
- Enter the Pod URL (your pod or on-prem host, no trailing path).
- Enter the Tenant Name, the Client ID, and the Client Secret.
- Click Save.
What happens when you save
- The Tenant Name, Client ID, and Client Secret are stored encrypted in Azure Key Vault — never in the StackJack database, and never shown back to you.
- If this is the first time you configure CyberCNS, a Free-tier subscription for the connector is created automatically so its Free tools work right away.
- StackJack immediately live-validates the credentials by minting a token and requesting a one-record company list. Validation never blocks the save.
- After saving, the form collapses and the connector drawer stays open. It shows Connected / Valid on success, or Needs Attention with Re-test and recovery guidance if validation failed.
Plans and available tools
- Free includes list/get operations across companies, agents, assets, hardware, firewall, ports and certificates; plus the report-query surface — inventory, AD/Azure directory, problems and remediation plans, application and environment-wide vulnerabilities, and compliance.
- Pro adds write and delete operations for companies, credentials, discovery settings, scan schedules, tags, EDR, PII and custom profiles, integrations, and vulnerability suppressions; external scan starts; and report-builder writes (create report jobs, upload templates, set cover pages).
- Business offers the same tool set as Pro with a higher monthly call quota.
See the generated ConnectSecure (CyberCNS) tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.
Safety note — destructive tools. StackJack marks these irreversible Pro operations as destructive: the
cns_delete_*tools (delete a company, credential, asset, tag, suppression, and so on), pluscns_reset_agentsandcns_remove_schedule. Whether your AI application asks you to confirm before running one depends on that application's own settings — see Destructive tools and confirmation. Review those settings, and scope your AI's access deliberately — use the tool selections on the MCP Setup page and the Permissions page to enable only the actions you want an AI to take.
CyberCNS has no per-user OAuth, so there is no per-user attribution — all AI traffic authenticates as the single API-key user. Current pricing and quotas are shown in the portal's Billing page and at checkout.
Rate limits
CyberCNS allows up to 300 requests per minute (and 2,000 per hour, 30,000 per day). StackJack paces requests towards the per-minute limit and backs off automatically if the API signals it is busy, so a long multi-page inventory or report read is usually just slower. Pacing is not a guarantee: retries are bounded, so a wide enough read can still come back throttled or time out. Narrow the read, honour any retry delay the vendor sends, and check whether a write landed before repeating it — see Retrying a failed or timed-out write.
Filtering and paging results
Most list and report tools accept a condition filter and an order_by sort in ConnectSecure's query language (for example condition=name:startswith:acme or order_by=created:desc), and page with skip and limit. ConnectSecure documents a default limit of 100 and recommends larger supported pages when high call counts cause 429 responses. Ask your AI to narrow a large query by company, severity, or date and continue paging until complete.
Rotating or replacing the credentials
The API key is the recovery secret. If you regenerate or delete the API key in ConnectSecure — or the key's user loses access — the stored credential becomes invalid. To restore access, create a new key and open Connectors → CyberCNS (ConnectSecure) → Configure in StackJack, enter the new Client ID and Client Secret (re-enter the Pod URL and Tenant Name if needed), then Save.
Disconnecting ConnectSecure
StackJack's Disconnect action removes the stored tenant name and API credential and stops future calls. It does not delete the per-user API key or disable its user in ConnectSecure. Revoke that key from the user's three-dot menu, and disable the dedicated user if it is no longer needed anywhere else. Subscription changes are separate from credential removal.
Troubleshooting
CyberCNS (ConnectSecure) tools
cns_ · 295 tools · Free 243 · Pro 52
Companies
Agents & Credentials
Scheduling & Events
Baselines
Security Posture
Tags & Domains
Asset Inventory
Asset Hardware
Firewall & Vulnerabilities
Integrations
Report Queries — Inventory
Report Queries — System (Linux/Windows)
Report Queries — Directory (AD/Azure)
Reports: Remediation
Reports: Problems
Reports: Directory Detail
Application Vulnerability Reports
Compliance & Vulnerability Reports
Report Builder
More in Connector guides
Connect Acronis Cyber Protect CloudConnect Action1Connect AddigyConnect AlertOpsStill need help? Ask the team