Skip to main content
Connector guides

Connect Datto RMM

Datto RMM is a remote monitoring and management platform for MSPs. Connecting Datto RMM to StackJack gives your AI assistant tools for sites, devices, alerts, jobs, audits, variables, and activity…

Written By Christopher Scaminaci

Last updated 6 days ago

Datto RMM is a remote monitoring and management platform for MSPs. Connecting Datto RMM to StackJack gives your AI assistant tools for sites, devices, alerts, jobs, audits, variables, and activity logs through StackJack's MCP endpoint. See the generated Datto RMM tool reference for the current inventory, input schemas, plan tiers, and safety notes. (MCP, the Model Context Protocol, is the open standard that lets AI assistants like Claude, ChatGPT, and Copilot call your MSP tools securely.)

Datto RMM uses an API key pair (API Key + API Secret Key) generated under a specific Datto RMM user. That user owns the key lifecycle: deactivating or deleting the user invalidates the pair. On Datto RMM 15.1 and later, the key's separate API Security Level and API Component Level control its reach; do not assume the user's ordinary interactive role or site visibility confines API access.

Before you begin

  • You need the Owner, co-owner, or Administrator role in StackJack to configure connectors.
  • You need administrator access to Datto RMM (to enable API access and generate keys).
  • Know which platform (pod) your Datto RMM account runs on: Pinotage, Merlot, Concord, Vidal, Zinfandel, or Syrah. If you're not sure, check the web address you use to sign in to Datto RMM — it begins with the platform name (for example, a Merlot account signs in at an address starting with merlot.).
  • Connecting a connector automatically activates it on the Free plan. You can upgrade to a paid plan at any time from the Connectors page — current pricing is shown in the portal.

Tip: The same steps below are always available in-app — open Connectors, find the Datto RMM card, and click How To Connect.

Step 1: Generate API keys in Datto RMM

  1. Log in to Datto RMM as an administrator.
  2. Navigate to Setup > Global Settings > Access Control and enable the API Access toggle for the account.
  3. Navigate to Setup > Users and select a dedicated active user to own the StackJack key pair. The user is a lifecycle owner, not a reliable API permission boundary.

⚠ Configure the API-specific controls. On Datto RMM 15.1 and later, select the least-privilege API Security Level and API Component Level for this key. Datto added these specifically to restrict API access independently of ordinary user Security Level memberships. Older Datto releases documented account-wide API access; if these fields are absent, upgrade or confirm the effective scope with Datto before connecting.

  1. Confirm the API Security Level covers the sites, devices, and operations you intend to expose. Confirm the API Component Level permits only the components/jobs you intend agents to run.
  2. Click Generate API Keys on the user. Datto RMM returns an API Key (access key) and an API Secret Key.
  3. Copy both immediately.

⚠ The API Secret Key is shown exactly once — it cannot be retrieved later. If you lose it, regenerate the keys (which invalidates the old pair).

Step 2: Add the credentials to StackJack

  1. In the StackJack portal, go to Connectors and click Configure on the Datto RMM card.

  2. Fill in the fields:

    StackJack fieldValue
    PlatformThe Datto RMM platform (pod) that matches where the keys were generated — Pinotage, Merlot, Concord, Vidal, Zinfandel, or Syrah. The Instance URL fills in automatically and can't be edited.
    API KeyThe access key from Step 1
    API Secret KeyThe secret key from Step 1
  3. Click Save.

⚠ The platform must match where the keys were generated. A Merlot key fails authentication against Pinotage or Zinfandel, even though all are valid Datto RMM platforms.

Datto RMM setup-field example with the platform dropdown open showing the six pods
Field-layout example from the earlier centered setup shell. The current Portal presents these controls in the connector's right-side drawer.

What happens when you save

  • Your key pair is stored encrypted in Azure Key Vault. It is never stored in StackJack's database, and the portal never re-displays a saved secret.
  • StackJack immediately test-calls Datto RMM to validate the credentials. If validation fails or times out, your credentials are still saved and you'll see a warning — validation retries automatically in the background.
  • A Free plan subscription for Datto RMM is activated automatically if you don't already have one.
  • If validation keeps failing (three consecutive definitive failures), StackJack auto-disables the connection, emails the tenant owner, and shows Re-enable and Update Credentials buttons on the card.

What StackJack can access in Datto RMM

Everything is bounded by the API-specific controls on the key (on Datto RMM 15.1+). StackJack's own plan tier and per-tool selections are a second gate. The tool families cover:

AreaAccess
AccountRead
SitesRead/write
DevicesRead/write
AlertsRead/write
AuditRead
JobsRead/write
VariablesRead/write
Activity LogsRead
SystemRead

Pagination, tokens, and rate limits

BehaviorWhat to expect
Access tokensDatto access tokens expire after 100 hours. StackJack exchanges the saved key pair for access tokens and renews them automatically.
PaginationList tools use 0-based pages: the first page is 0, and a list tool reads it when you leave the page number out. They default to 50 results and cap each request at Datto's 250-result maximum. Request later pages until the response has no next page.
Read quotaDatto allows 600 query requests per rolling 60 seconds per account. StackJack applies the same per-tenant read pacing.
Write quotaDatto allows 100 write requests per rolling 60 seconds per account. StackJack applies the same per-tenant write pacing.
ThrottlingDatto returns 429 after a quota is exceeded; persistent retrying can cause a temporary 403 IP block. Let StackJack back off instead of immediately retrying in a loop. Traffic from other integrations counts against the same Datto account quota.

Troubleshooting

SymptomLikely cause and fix
Authentication fails (401) right after setupThe selected platform doesn't match where the keys were generated, or the keys were copied incorrectly. Re-check the platform and re-paste the keys.
Authentication fails (401) after working beforeThe keys were regenerated, deleted, or disabled in Datto RMM — or the API user's account was deactivated. Generate a fresh key pair and click Update on the card (Update Credentials if the card has been auto-disabled).
Tools return 403 (forbidden) errorsThe key's API Security Level or API Component Level does not permit the resource/action, or Datto temporarily blocked the calling IP after persistent over-limit retries. Review the API-specific controls first; if all calls failed after heavy traffic, wait at least five minutes before retrying.
Some sites or devices are missingThe key's API Security Level does not include them. Adjust that API-specific level rather than relying on the user's ordinary role.
Card shows DisabledStackJack auto-disabled the credential after repeated failures. The card shows the exact error plus a recommended action — fix the cause, then click Re-enable (or Update Credentials first if you regenerated keys).

Disconnecting

Click Disconnect on the Datto RMM card to delete the stored credentials from Key Vault. Any AI tools using the connector stop working immediately.

⚠ Disconnecting does not cancel a paid plan — billing continues until you cancel it separately. The plan controls only appear while the connector is connected, so end the plan before disconnecting. On a paid connector that button reads Manage on Billing and opens this connector's removal dialog on the Billing page; a legacy website subscription still reads Cancel Plan. If you've already disconnected, save your credentials again to bring the plan controls back, then end the plan.

Datto RMM tools

datto_ · 58 tools · Free 38 · Pro 20

Account

ToolWhat it does
datto_get_account
Free · Read-only
Get account information including account name, total device counts, active device counts, currency, and plan details.
datto_get_dnet_mappings
Free · Read-only
List Datto Network (DNET) to site mappings.
datto_list_users
Free · Read-only
List all users in the Datto RMM account.

Sites

ToolWhat it does
datto_create_site
Pro · Write
Create a new site.
datto_delete_site_proxy
Pro · Destructive
Remove proxy settings from a site.
datto_get_site
Free · Read-only
Get detailed information for a specific site including name, description, notes, device counts, on-demand status, and proxy settings.
datto_get_site_settings
Free · Read-only
Get settings for a specific site including proxy configuration, Splashtop auto-install preference, and other site-level configuration.
datto_list_site_filters
Free · Read-only
List device filters configured for a specific site.
datto_list_sites
Free · Read-only
List all sites in the account.
datto_set_site_proxy
Pro · Destructive
Configure proxy settings for a site.
datto_update_site
Pro · Write
Update an existing site.

Devices

ToolWhat it does
datto_find_device_by_mac
Free · Read-only
Find a device by its MAC address.
datto_get_device
Free · Read-only
Get detailed information for a single device by its UID.
datto_get_device_by_id
Free · Read-only
Get detailed information for a single device by its numeric ID (not UID).
datto_list_devices
Free · Read-only
List all managed devices across all sites.
datto_list_site_devices
Free · Read-only
List devices belonging to a specific site.
datto_list_site_devices_network
Free · Read-only
List devices in a site with network interface details including IP addresses, MAC addresses, and NIC names.
datto_move_device
Pro · Destructive
Move a device from its current site to a different site.
datto_set_device_udf
Pro · Write
Set user-defined fields (UDF) on a device.
datto_set_device_warranty
Pro · Write
Set the warranty expiration date on a device.

Alerts

ToolWhat it does
datto_get_alert
Free · Read-only
Get detailed information for a specific alert including alert type, priority, message, device info, timestamp, and resolution status.
datto_list_device_open_alerts
Free · Read-only
List open (unresolved) alerts for a specific device.
datto_list_device_resolved_alerts
Free · Read-only
List resolved alerts for a specific device.
datto_list_open_alerts
Free · Read-only
List all open (unresolved) alerts across all sites and devices.
datto_list_resolved_alerts
Free · Read-only
List all resolved alerts across all sites and devices.
datto_list_site_open_alerts
Free · Read-only
List open (unresolved) alerts for a specific site.
datto_list_site_resolved_alerts
Free · Read-only
List resolved alerts for a specific site.
datto_resolve_alert
Pro · Destructive
Resolve (close) an open alert.

Audit

ToolWhat it does
datto_get_audit_by_mac
Free · Read-only
Get device audit by MAC address.
datto_get_device_audit
Free · Read-only
Get full device audit including hardware, NICs, disks, and memory.
datto_get_device_software
Free · Read-only
Get software inventory for a device.
datto_get_esxi_audit
Free · Read-only
Get ESXi host audit (VMs, datastores, CPUs).
datto_get_printer_audit
Free · Read-only
Get printer audit (supply levels, page counts).

Jobs

ToolWhat it does
datto_create_quick_job
Pro · Destructive
Run a component as a quick job on one device via PUT /v2/device/{deviceUid}/quickjob.
datto_get_job
Free · Read-only
Get a job's data and status via GET /v2/job/{jobUid} — name, status (active or completed) and creation time.
datto_get_job_components
Free · Read-only
List components associated with a job.
datto_get_job_results
Free · Read-only
Get one device's execution results for a job via GET /v2/job/{jobUid}/results/{deviceUid}.
datto_get_job_stderr
Free · Read-only
Get the error output a job produced on one device via GET /v2/job/{jobUid}/results/{deviceUid}/stderr.
datto_get_job_stdout
Free · Read-only
Get the standard output a job produced on one device via GET /v2/job/{jobUid}/results/{deviceUid}/stdout.

Filters

ToolWhat it does
datto_list_custom_filters
Free · Read-only
List custom device filters created in your Datto RMM account.
datto_list_default_filters
Free · Read-only
List default device filters provided by Datto RMM.

Components

ToolWhat it does
datto_list_components
Free · Read-only
List available components (scripts and monitors).

Variables

ToolWhat it does
datto_create_account_variable
Pro · Write
Create a new account-level variable.
datto_create_site_variable
Pro · Write
Create a new variable for a specific site.
datto_delete_account_variable
Pro · Destructive
Delete an account-level variable.
datto_delete_site_variable
Pro · Destructive
Delete a variable from a specific site.
datto_list_account_variables
Free · Read-only
List all account-level variables.
datto_list_site_variables
Free · Read-only
List variables for a specific site.
datto_update_account_variable
Pro · Write
Update an existing account-level variable.
datto_update_site_variable
Pro · Write
Update an existing variable for a specific site.

Activity Logs

ToolWhat it does
datto_list_activity_logs
Free · Read-only
Fetch activity logs with optional date range and filters.

System

ToolWhat it does
datto_rate_status
Free · Read-only
Get current API rate limit status (requests remaining).
datto_system_status
Free · Read-only
Get system status and API version info.

Analytics

ToolWhat it does
datto_alert_trend_analysis
Pro · Read-only
Open vs resolved alert counts per site.
datto_fleet_health_dashboard
Pro · Read-only
Aggregate device online/offline/suspended counts across all sites.
datto_patch_compliance_report
Pro · Read-only
Patch management status summary across all devices.
datto_software_inventory_summary
Pro · Read-only
Cross-device software inventory for a specific site.
datto_stale_device_report
Pro · Read-only
Devices not seen for N days.