Connect Datto BCDR
Datto BCDR (Business Continuity and Disaster Recovery) is Datto's backup and continuity line — the SIRIS, ALTO and NAS appliances that sit on a client's network taking image-based backups, plus…
Written By Christopher Scaminaci
Last updated 6 days ago
Datto BCDR (Business Continuity and Disaster Recovery) is Datto's backup and continuity line — the SIRIS, ALTO and NAS appliances that sit on a client's network taking image-based backups, plus Datto's Direct-to-Cloud agents that back up straight to Datto's cloud with no appliance at all. StackJack talks to it through the Datto REST API.
Connecting Datto BCDR to StackJack gives your AI assistant a family of dattobcdr_ MCP tools — MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:
- Check backup health across every client — appliances and their service plans and storage use, the protected machines and file shares on each one, and when each last backed up successfully
- Investigate failures — open alerts per appliance, and the screenshot-verification image Datto captures when it boots a backup to prove it is restorable
- Audit activity — who changed what and when, filtered by client, by person, or by the object they touched
- Track Direct-to-Cloud — cloud-backed assets per client, their agent versions and check-in times, and cloud storage consumption by pool
- Adjust a Direct-to-Cloud bandwidth limit (on Pro plans) — the connector's only setting change
What this connector cannot do
Worth knowing up front, because it shapes what you should ask your AI for. The Datto REST API is a monitoring and reporting interface, not a control panel. It can tell you everything about the state of your backups; it cannot start a backup, run a restore, or virtualize a machine. Those remain actions you take in the Datto portal or on the appliance itself. The tool that lists "VM restores" reports virtualizations that already exist — it cannot create one.
This is a limit of what Datto offers through the API, not a StackJack restriction.
Datto BCDR and Datto SaaS Protection share one key
Datto serves both products from the same API behind the same pair of keys. StackJack lists them as two separate connectors because they are separately sold and many partners own only one — so if you use both, create one key pair and enter the same two values in each connector. Connecting one does not connect the other.
The other consequence of sharing an API: Datto's request allowance is counted per account, across both products. Heavy use of one connector can slow the other down. StackJack paces its own requests to stay well within the allowance and backs off automatically if Datto ever pushes back.
How StackJack authenticates to Datto
Datto uses a pair of static keys — a public key and a secret key — created together in the Datto Partner Portal. StackJack sends both on every request. There is no sign-in redirect, no expiry, and nothing to refresh: the pair stays valid until someone regenerates it.
Two things are worth understanding before you create one:
The secret key is shown exactly once. Datto displays it at the moment you create the pair and never again. If you navigate away without copying it, you cannot recover it — you have to generate a replacement pair, which immediately invalidates the old one. Because both Datto connectors use the same pair, regenerating breaks both until you re-enter the new values in each.
The keys carry no individual permissions. There are no per-key permission checkboxes: a key reaches whatever your partner account is entitled to. If a Direct-to-Cloud tool is refused while appliance tools work, the usual cause is that the product is not entitled on your account, or the device belongs to a child reseller whose data your account cannot see.
Datto serves this API from one global address (https://api.datto.com/v1), so there is no region to choose and no URL to enter.
Before you begin
- In StackJack: you need a role that can manage connectors (tenant Owner, a co-owner, or an Administrator).
- In Datto: you need Partner Portal access with administrator rights, so you can create API keys.
Step 1 — Create a key pair in the Datto Partner Portal
- Sign in to the Datto Partner Portal as an administrator.
- Open Admin, then Integrations, then API Keys.
- Create a new API key. Datto generates a public key and a secret key together — they are one pair and only work together.
- Copy the secret key immediately and store it securely, treating it like a password. This is the only time it is shown.
Step 2 — Add the credential in StackJack
- In the StackJack portal, open Connectors.
- Find the Datto BCDR card. Click How To Connect for the same steps inline, or Configure to enter the keys.
- Paste your public key and your secret key. There is no URL to enter — the address is fixed.
- Click Save.
What happens when you save
- Both keys are stored encrypted in Azure Key Vault — never in the StackJack database, and never shown back to you.
- If this is the first time you configure Datto BCDR, a Free-tier subscription for the connector is created automatically so its Free tools work right away.
- StackJack immediately live-validates the pair by making a cheap authenticated read against your Datto account. Validation never blocks the save: you will either see a success confirmation or a "saved but validation failed" warning with the reason.
- StackJack re-checks the credential periodically afterwards, so an expired or regenerated key shows up as a connector health warning rather than as a mysterious tool failure.
What your AI can do at each plan
Free — all seventeen read tools. Everything described at the top of this page except the bandwidth change: appliances, protected machines and shares, alerts, screenshot-verification images, existing restore records, the activity log, and the whole Direct-to-Cloud read surface.
Pro — adds the one write. Updating a Direct-to-Cloud agent's bandwidth limit. StackJack marks it as a change; whether your AI application asks you to confirm first depends on that application's own settings — see Destructive tools and confirmation.
Business — the same tools as Pro, with a higher monthly call allowance.
Datto issues keys at the partner level rather than per person, so all activity authenticates as your partner account and there is no per-user attribution.
Working with identifiers
Datto uses two different kinds of identifier that are not interchangeable, and mixing them is the most common cause of a "not found" result:
- Appliances are identified by serial number. Start with the device list to get them.
- Direct-to-Cloud assets and agents are identified by UUID. Start with the Direct-to-Cloud asset list to get them.
Ask your AI to list first and then drill in, rather than supplying an identifier copied from another system.
Troubleshooting
Every Datto tool suddenly fails with an authorization error. The key pair was almost certainly regenerated in the Partner Portal — remember Datto shows a secret key only once, so anyone who lost it and made a replacement has invalidated the old pair. Check the public key shown in the Partner Portal against the one saved in StackJack, and if it has changed, paste the current pair into the connector and run Test Connection. If you also use Datto SaaS Protection, re-enter it there too.
Some tools work and others are refused. Datto keys carry no individual permissions, so this is an entitlement gap rather than a permissions problem. Direct-to-Cloud tools need Direct-to-Cloud on your account; a device belonging to a child reseller will not be visible to a parent account that cannot see it in the portal either.
A tool reports "not found" for something you can see in Datto. Check you are using the right kind of identifier — serial number for appliances, UUID for Direct-to-Cloud. Ask your AI to list the devices or assets first and use what that returns.
Requests are being slowed down. Datto's allowance is counted per account and shared with Datto SaaS Protection, so a busy period on either connector can throttle both. StackJack paces itself and backs off automatically; asking for smaller pages of results also helps.
A screenshot tool returns an error instead of an image. Screenshot images are handed back as a short-lived download link rather than being embedded in the response. If file storage is unavailable the tool fails clearly rather than returning a link that would not work — that is deliberate. The link expires after about ten minutes, so fetch it promptly.
Full tool list
See the generated Datto BCDR tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.
Datto BCDR tools
dattobcdr_ · 18 tools · Free 17 · Pro 1
Devices
Agents
Assets
Screenshots
Alerts
Restores
Reporting
Direct-to-Cloud
More in Connector guides
Connect Acronis Cyber Protect CloudConnect Action1Connect AddigyConnect AlertOpsStill need help? Ask the team