Skip to main content
Connector guides

Connect CyberQP

CyberQP (formerly QuickPass) is a privileged-access management (PAM) platform for MSPs, exposed to StackJack through the CyberQP Public API. Its core is just-in-time (JIT) privileged accounts —…

Written By Christopher Scaminaci

Last updated 6 days ago

CyberQP (formerly QuickPass) is a privileged-access management (PAM) platform for MSPs, exposed to StackJack through the CyberQP Public API. Its core is just-in-time (JIT) privileged accounts — on-demand local, Active Directory, and Microsoft 365 admin accounts that exist only while they're needed — plus the policies that govern them, per-customer account inventory, and technician identity verification.

Connecting CyberQP to StackJack gives your AI assistant a focused family of qp_ MCP tools — MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:

  • Inventory your customers and their JIT privileged accounts (per customer or across the whole tenant), and check whether an account already exists before creating one
  • Review the JIT policies that define duration and elevation rules for each directory type
  • Retrieve a JIT account's current password or one-time passcode when a technician needs privileged access
  • Provision (on Pro plans) — create JIT accounts, enable or disable them for a bounded window, and delete them when they're no longer needed
  • Manage (on Pro plans) an account's stored one-time-passcode (OTP) secret
  • Verify (on Pro plans) an end user's identity from a support ticket, and submit events for CyberQP to process

How StackJack authenticates to CyberQP

CyberQP has no machine-to-machine login. A Primary or Super admin generates the API credential once through a one-time browser sign-in, which returns a refresh token. You paste that refresh token into StackJack; from then on StackJack exchanges it for short-lived access tokens automatically and saves the newly issued refresh token each time — there is nothing for you to refresh manually.

CyberQP currently allows only a Primary or Super role holder to generate API credentials, and its current guidance states that credentials generated by either role can access all data in the tenant. CyberQP recommends a dedicated System User technician for integrations. Use that dedicated identity rather than a personal administrator, then narrow agent access with StackJack's tool selection and permissions.

The refresh token is valid for six months or until used. It rotates on each use, so the value you copy from the browser is only good until StackJack consumes it. If the stored credential is lost, expires, is revoked, or you move to a different region, repeat browser consent to generate a new one.

Regions

CyberQP is region-partitioned, and each region is a separate deployment. StackJack stores the regional host you choose:

  • United States — https://us.getquickpass.com
  • Europe — https://eu.getquickpass.com
  • Canada — https://ca.cyberqp.com (note the different domain)

All three expose the same tool set. Pick the region that matches where your CyberQP account is hosted.

Before you begin

  • In StackJack: you need a role that can manage connectors (tenant Owner, a co-owner, or an Administrator).
  • In CyberQP: create or choose a dedicated System User technician with the Primary or Super role. Those are the only roles CyberQP currently permits to generate API credentials.
  • Know your region — US, EU, or Canada.
  • Review CyberQP's current API getting-started guide, including its credential lifetime and revocation guidance.

Step 1 — Generate the refresh token in CyberQP

  1. In your browser, go to your region's sign-in URL — for example https://us.getquickpass.com/api/v1/auth/login (use eu.getquickpass.com or ca.cyberqp.com for those regions).
  2. Sign in as the dedicated System User with its Primary or Super role when the CyberQP Dashboard prompts you.
  3. On success CyberQP returns an access token and a refresh token. Copy the refresh token — that's the value StackJack stores.

Step 2 — Add the credentials in StackJack

  1. In the StackJack portal, open Connectors.
  2. Select the CyberQP tile to open its details. Choose How To Connect to review the inline setup guide, or Configure to reveal the credential form in the drawer.
  3. Choose your Region (US / EU / Canada). The Instance URL field fills in from your choice — leave it as shown.
  4. Paste the Refresh Token you copied from the browser.
  5. Click Save.

What happens when you save

  • The refresh token is stored encrypted in Azure Key Vault — never in the StackJack database, and never shown back to you.
  • If this is the first time you configure CyberQP, a Free-tier subscription for the connector is created automatically so its Free tools work right away.
  • StackJack immediately live-validates the credential by acquiring an access token and calling the CyberQP auth-status endpoint. This first validation consumes the pasted refresh token and stores the rotated replacement. Validation never blocks the save.
  • After saving, the form collapses and the connector drawer stays open. It shows Connected / Valid on success, or Needs Attention with Re-test and recovery guidance if validation failed.

Working with customers and directory types

Many CyberQP tools are scoped to a customer (a managed organization) and a directory type — one of AD (on-prem Active Directory), OFFICE (Microsoft 365 / Entra ID), or LOCAL (local machine accounts). Your AI lists customers with qp_list_customers, which requires a directory type, and then uses the returned customer id with the JIT account and policy tools. Account ids come from qp_list_customer_jit_accounts or qp_list_tenant_jit_accounts.

Plans and available tools

  • Free includes reads for customers and their account counts, JIT accounts per customer or tenant-wide, account existence, JIT policies, auth status, tenant install-token and company data — plus retrieval of a JIT account's current password and one-time passcode.
  • Pro adds actions to create, enable, disable, and delete JIT accounts; save and delete an account's OTP secret; trigger identity verification; and submit events.
  • Business offers the same tool set as Pro with a higher monthly call quota.

See the generated CyberQP tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.

CyberQP does not offer a separate OAuth consent for each StackJack user, so all AI traffic authenticates as the dedicated consenting System User. Current pricing and quotas are shown in the portal's Billing page and at checkout.

Safety note — privileged secrets. qp_get_jit_account_password returns a live cleartext admin password and qp_get_jit_account_otp returns live one-time passcodes. These ship as Free read tools by design — but any AI with access to the CyberQP connector can call them. Grant the connector only to trusted agents, and use the tool selections on the MCP Setup page and the Permissions page to enable only the actions you want an AI to take.

Rate limits

CyberQP publishes no fixed numeric quota. Its current guidance says the limit is per source IP, shared by users behind the same NAT/VPN, and returns X-RateLimit-* plus Retry-After headers with HTTP 429. StackJack applies a conservative per-tenant pace and honors upstream backoff, but other traffic from the same egress IP can still consume the shared allowance.

Rotating or replacing the credential

The stored refresh token is the recovery secret and rotates on use. If it is lost, expired, revoked, desynchronized, or you switch regions, repeat browser consent as the dedicated System User, then open Connectors → CyberQP → Configure, paste the new value, and save. Confirm Valid before assuming the replacement chain is healthy.

Disconnecting CyberQP

StackJack's Disconnect action deletes its stored rotating credential and stops future calls, but it does not revoke the CyberQP System User's upstream tokens. If the credential must be invalidated, use CyberQP's documented token-revocation process (or disable the dedicated System User) before disconnecting, while you still have a usable credential. Subscription changes are separate from credential removal.

Troubleshooting

SymptomLikely causeWhat to do
Needs Attention immediately after savingWrong region, or the pasted refresh token was already used, expired, or revokedRe-check the region, perform fresh browser consent as the System User, paste the new value, and use Re-test
Tools worked, then all CyberQP tools started failingThe stored rotating token chain was revoked, expired, or lost, or the System User was disabledRestore the dedicated Primary/Super System User if appropriate, repeat browser consent, and save the new refresh token
One tool returns a 403 while others succeedThe feature may not be enabled for this tenant, or the System User no longer has a Primary/Super roleConfirm the role and product entitlement. CyberQP's current model does not expose a per-customer visibility scope for API credentials
qp_list_customers returns an error about a missing fieldThe required directory type wasn't suppliedAsk your AI to specify the directory type (AD, OFFICE, or LOCAL)
Write tools missing from your AI's tool listConnector is on the Free tier, or the tools aren't selected for your clientUpgrade the CyberQP connector plan and check your tool selections on the MCP Setup page

CyberQP tools

qp_ · 19 tools · Free 11 · Pro 8

JIT Accounts & Policies

ToolWhat it does
qp_check_jit_account_exists
Free · Read-only
Check whether a JIT account already exists for a customer and directory type before creating one.
qp_create_jit_account
Pro · Write
Create a just-in-time privileged admin account for a customer.
qp_delete_jit_account
Pro · Destructive
Permanently delete a JIT privileged admin account.
qp_delete_jit_account_otp_secret
Pro · Destructive
Delete the stored OTP (TOTP) secret from a JIT account.
qp_disable_jit_account
Pro · Write
Disable (de-elevate) a JIT privileged admin account.
qp_enable_jit_account
Pro · Write
Enable (elevate) a JIT privileged admin account for a bounded window.
qp_get_jit_account_otp
Free · Read-only
Retrieve the current TOTP code(s) for a JIT privileged admin account's stored OTP secret.
qp_get_jit_account_password
Free · Read-only
Retrieve the CURRENT CLEARTEXT password for a JIT privileged admin account.
qp_list_customer_jit_accounts
Free · Read-only
List the just-in-time (JIT) privileged admin accounts for a single customer.
qp_list_jit_policies
Free · Read-only
List the JIT account policies available for a customer and account type.
qp_list_tenant_jit_accounts
Free · Read-only
List every JIT privileged admin account across the whole tenant (all customers).
qp_save_jit_account_otp_secret
Pro · Write
Store/replace the OTP (TOTP) secret for a JIT account so its live codes can later be read with qp_get_jit_account_otp.

Platform

ToolWhat it does
qp_get_auth_status
Free · Read-only
Get the authenticated technician's auth/session status for the connected CyberQP tenant.
qp_get_customer_account_counts
Free · Read-only
Get the account counts for a single customer (managed organization), identified by its customer id from qp_list_customers.
qp_get_install_token
Free · Read-only
Get the CyberQP agent install token for the connected tenant.
qp_get_tenant_company_data
Free · Read-only
Get the connected CyberQP tenant's company/branding metadata (company name, and related tenant profile data).
qp_list_customers
Free · Read-only
List the customers (managed organizations) in your CyberQP tenant.
qp_process_event
Pro · Write
Submit an event to CyberQP for processing.
qp_trigger_identity_verification
Pro · Write
Trigger a self-serve identity-verification notification for an end user.