Connect CyberQP
CyberQP (formerly QuickPass) is a privileged-access management (PAM) platform for MSPs, exposed to StackJack through the CyberQP Public API. Its core is just-in-time (JIT) privileged accounts —…
Written By Christopher Scaminaci
Last updated 6 days ago
CyberQP (formerly QuickPass) is a privileged-access management (PAM) platform for MSPs, exposed to StackJack through the CyberQP Public API. Its core is just-in-time (JIT) privileged accounts — on-demand local, Active Directory, and Microsoft 365 admin accounts that exist only while they're needed — plus the policies that govern them, per-customer account inventory, and technician identity verification.
Connecting CyberQP to StackJack gives your AI assistant a focused family of qp_ MCP tools — MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:
- Inventory your customers and their JIT privileged accounts (per customer or across the whole tenant), and check whether an account already exists before creating one
- Review the JIT policies that define duration and elevation rules for each directory type
- Retrieve a JIT account's current password or one-time passcode when a technician needs privileged access
- Provision (on Pro plans) — create JIT accounts, enable or disable them for a bounded window, and delete them when they're no longer needed
- Manage (on Pro plans) an account's stored one-time-passcode (OTP) secret
- Verify (on Pro plans) an end user's identity from a support ticket, and submit events for CyberQP to process
How StackJack authenticates to CyberQP
CyberQP has no machine-to-machine login. A Primary or Super admin generates the API credential once through a one-time browser sign-in, which returns a refresh token. You paste that refresh token into StackJack; from then on StackJack exchanges it for short-lived access tokens automatically and saves the newly issued refresh token each time — there is nothing for you to refresh manually.
CyberQP currently allows only a Primary or Super role holder to generate API credentials, and its current guidance states that credentials generated by either role can access all data in the tenant. CyberQP recommends a dedicated System User technician for integrations. Use that dedicated identity rather than a personal administrator, then narrow agent access with StackJack's tool selection and permissions.
The refresh token is valid for six months or until used. It rotates on each use, so the value you copy from the browser is only good until StackJack consumes it. If the stored credential is lost, expires, is revoked, or you move to a different region, repeat browser consent to generate a new one.
Regions
CyberQP is region-partitioned, and each region is a separate deployment. StackJack stores the regional host you choose:
- United States —
https://us.getquickpass.com - Europe —
https://eu.getquickpass.com - Canada —
https://ca.cyberqp.com(note the different domain)
All three expose the same tool set. Pick the region that matches where your CyberQP account is hosted.
Before you begin
- In StackJack: you need a role that can manage connectors (tenant Owner, a co-owner, or an Administrator).
- In CyberQP: create or choose a dedicated System User technician with the Primary or Super role. Those are the only roles CyberQP currently permits to generate API credentials.
- Know your region — US, EU, or Canada.
- Review CyberQP's current API getting-started guide, including its credential lifetime and revocation guidance.
Step 1 — Generate the refresh token in CyberQP
- In your browser, go to your region's sign-in URL — for example
https://us.getquickpass.com/api/v1/auth/login(useeu.getquickpass.comorca.cyberqp.comfor those regions). - Sign in as the dedicated System User with its Primary or Super role when the CyberQP Dashboard prompts you.
- On success CyberQP returns an access token and a refresh token. Copy the refresh token — that's the value StackJack stores.
Step 2 — Add the credentials in StackJack
- In the StackJack portal, open Connectors.
- Select the CyberQP tile to open its details. Choose How To Connect to review the inline setup guide, or Configure to reveal the credential form in the drawer.
- Choose your Region (US / EU / Canada). The Instance URL field fills in from your choice — leave it as shown.
- Paste the Refresh Token you copied from the browser.
- Click Save.
What happens when you save
- The refresh token is stored encrypted in Azure Key Vault — never in the StackJack database, and never shown back to you.
- If this is the first time you configure CyberQP, a Free-tier subscription for the connector is created automatically so its Free tools work right away.
- StackJack immediately live-validates the credential by acquiring an access token and calling the CyberQP auth-status endpoint. This first validation consumes the pasted refresh token and stores the rotated replacement. Validation never blocks the save.
- After saving, the form collapses and the connector drawer stays open. It shows Connected / Valid on success, or Needs Attention with Re-test and recovery guidance if validation failed.
Working with customers and directory types
Many CyberQP tools are scoped to a customer (a managed organization) and a directory type — one of AD (on-prem Active Directory), OFFICE (Microsoft 365 / Entra ID), or LOCAL (local machine accounts). Your AI lists customers with qp_list_customers, which requires a directory type, and then uses the returned customer id with the JIT account and policy tools. Account ids come from qp_list_customer_jit_accounts or qp_list_tenant_jit_accounts.
Plans and available tools
- Free includes reads for customers and their account counts, JIT accounts per customer or tenant-wide, account existence, JIT policies, auth status, tenant install-token and company data — plus retrieval of a JIT account's current password and one-time passcode.
- Pro adds actions to create, enable, disable, and delete JIT accounts; save and delete an account's OTP secret; trigger identity verification; and submit events.
- Business offers the same tool set as Pro with a higher monthly call quota.
See the generated CyberQP tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.
CyberQP does not offer a separate OAuth consent for each StackJack user, so all AI traffic authenticates as the dedicated consenting System User. Current pricing and quotas are shown in the portal's Billing page and at checkout.
Safety note — privileged secrets.
qp_get_jit_account_passwordreturns a live cleartext admin password andqp_get_jit_account_otpreturns live one-time passcodes. These ship as Free read tools by design — but any AI with access to the CyberQP connector can call them. Grant the connector only to trusted agents, and use the tool selections on the MCP Setup page and the Permissions page to enable only the actions you want an AI to take.
Rate limits
CyberQP publishes no fixed numeric quota. Its current guidance says the limit is per source IP, shared by users behind the same NAT/VPN, and returns X-RateLimit-* plus Retry-After headers with HTTP 429. StackJack applies a conservative per-tenant pace and honors upstream backoff, but other traffic from the same egress IP can still consume the shared allowance.
Rotating or replacing the credential
The stored refresh token is the recovery secret and rotates on use. If it is lost, expired, revoked, desynchronized, or you switch regions, repeat browser consent as the dedicated System User, then open Connectors → CyberQP → Configure, paste the new value, and save. Confirm Valid before assuming the replacement chain is healthy.
Disconnecting CyberQP
StackJack's Disconnect action deletes its stored rotating credential and stops future calls, but it does not revoke the CyberQP System User's upstream tokens. If the credential must be invalidated, use CyberQP's documented token-revocation process (or disable the dedicated System User) before disconnecting, while you still have a usable credential. Subscription changes are separate from credential removal.
Troubleshooting
CyberQP tools
qp_ · 19 tools · Free 11 · Pro 8
JIT Accounts & Policies
Platform
More in Connector guides
Connect Acronis Cyber Protect CloudConnect Action1Connect AddigyConnect AlertOpsStill need help? Ask the team