Skip to main content
Connector guides

Connect DefensX

DefensX is a web and DNS security platform (secure web gateway, DNS filtering, credential-theft and browser-extension protection, and remote browser isolation) that MSPs run across their customers.…

Written By Christopher Scaminaci

Last updated 6 days ago

DefensX is a web and DNS security platform (secure web gateway, DNS filtering, credential-theft and browser-extension protection, and remote browser isolation) that MSPs run across their customers. StackJack connects to the DefensX Partner API, so your AI assistant works across every customer under your DefensX Partner account.

Connecting DefensX to StackJack gives your AI assistant a focused family of dfx_ MCP tools — MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:

  • Discover your customer roster, the partner product/message/policy-template catalogs, and billing usage
  • Inventory each customer's agents, deployments, groups, users, and detected browser extensions (including the low-reputation ones)
  • Review web-filter categories, policy groups, and custom URL allow/block groups
  • Investigate security event logs — URL access, credential submissions, file transfers, user consents, DNS queries, and remote-browser-isolation sessions
  • Report on the top visited and blocked categories and hostnames, credential-theft hotspots, and a customer's overall cyber-resilience score
  • Act (on Pro plans) — create customers, and create, update, or delete policy groups and custom URL groups/entries

How StackJack authenticates to DefensX

DefensX uses a Partner API token. You generate it in the DefensX Partner Dashboard under API Keys, and paste it into StackJack. StackJack sends it as an Authorization: Bearer header on every call — there is no client ID, OAuth sign-in, or refresh-token flow.

DefensX documents the key as a partner credential for customer management, security monitoring, policies, analytics, agents, and usage. Its public Partner API guide does not document selectable per-key permission scopes or a token expiration schedule. Treat the token as high privilege, create a dedicated integration key, and scope what your AI can do with the tool selections on the MCP Setup page and the Permissions page.

DefensX can apply IP Restrictions when you create a key. Only enable that control after StackJack support has given you the current outbound addresses for your region (they are not published, and a region move changes them); an incomplete allowlist blocks save-time validation and every later tool call.

One fixed address

DefensX is a global SaaS with a single Partner API address — there are no regional endpoints and no URL to enter. StackJack fills the base address in for you.

Working across customers

Almost every DefensX tool is customer-scoped: it needs a customerId (a UUID) to say which customer to act on. Your AI discovers those ids first:

  • dfx_list_customers lists every customer under your Partner account, each with its id, name, and domains.
  • dfx_get_self_customer returns your own partner tenant's customer record.

From there it passes the id into the inventory, policy, log, and reporting tools. A good first prompt is simply "list my DefensX customers" — then work from that list.

What is not included

DefensX also offers SIEM event streaming and External Notification callbacks. Both are push mechanisms — DefensX sends events out to a destination you register in the DefensX dashboard, rather than an address StackJack can call. They are configured in DefensX and are not exposed as MCP tools. The connector covers the Partner API's request/response operations only.

Before you begin

  • In StackJack: you need a role that can manage connectors (tenant Owner, a co-owner, or an Administrator).
  • In DefensX: you need access to your DefensX Partner Dashboard sufficient to generate a token under API Keys.

Step 1 — Generate a Partner API token in DefensX

  1. Sign in to your DefensX Partner Dashboard at https://cloud.defensx.com.
  2. Open API Keys and generate a new Partner API token.
  3. If you use IP Restrictions, allow the StackJack outbound addresses for your region. StackJack does not publish them: open a support ticket to get them, and leave the restriction off until you have them.
  4. Copy the token — you'll paste it into StackJack. Treat it like a password; it authenticates every call on its own.

Step 2 — Add the credentials in StackJack

  1. In the StackJack portal, open Connectors.
  2. Select the DefensX tile to open its details drawer.
  3. Use How To Connect to review the inline vendor steps, then choose Configure in the drawer footer.
  4. Paste your Partner API token. There is no URL or client ID to enter.
  5. Click Save.

What happens when you save

  • The token is stored encrypted in Azure Key Vault — never in the StackJack database, and never shown back to you.
  • If this is the first time you configure DefensX, a Free-tier subscription for the connector is created automatically so its Free tools work right away.
  • StackJack immediately live-validates the token by making a low-cost authenticated read. The credential remains saved if the upstream check fails so you can correct vendor access without re-entering every field.
  • The Configure form collapses while the details drawer stays open. The drawer shows Connected and Valid after success, or Needs Attention with the vendor error and a Re-test action after failure.

Plans and available tools

See the generated DefensX tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.

DefensX has no per-user sign-in, so there is no per-user attribution — all AI traffic authenticates as the single Partner API token. Current pricing and quotas are shown in the portal's Billing page and at checkout.

Safety note — irreversible deletes. The Pro delete tools permanently remove configuration and are flagged for consent in AI clients that support it: dfx_delete_policy (users/devices in that group fall back to the default policy), dfx_delete_custom_url_group (also deletes every custom URL inside it), and dfx_delete_custom_url. Enable them only when you want an AI to take those actions.

Rate limits

DefensX publishes no numeric API quota. StackJack applies a conservative per-tenant pace and honors any 429 backoff, so a long multi-page log or stats read is usually just slower. Pacing is not a guarantee: retries are bounded, so a wide enough read can still come back throttled or time out. Narrow the read, honour any retry delay the vendor sends, and check whether a write landed before repeating it — see Retrying a failed or timed-out write.

Rotating or replacing the token

DefensX does not publish a token-expiration or automatic-rotation contract. If the key is revoked, expires, or its IP restriction changes, create a replacement in Partner Dashboard → API Keys. In StackJack, open the DefensX details drawer, choose Configure, paste the replacement, save, and use Re-test.

Disconnecting DefensX

Choose Disconnect in the DefensX details drawer and confirm. StackJack deletes its stored Key Vault credential and stops making DefensX calls. Disconnecting does not revoke the upstream DefensX key, so revoke it separately in Partner Dashboard → API Keys when it should no longer work. Connector subscription changes are separate from credential disconnection.

Troubleshooting

SymptomLikely causeWhat to do
The drawer shows Needs Attention after savingThe token is mis-typed, expired/revoked, lacks access, or its IP restriction excludes StackJackCheck Partner Dashboard → API Keys, correct the allowlist or create a replacement, save it, and choose Re-test
Tools worked, then started failingThe token was revoked or regenerated in DefensXUpdate the credential in Connectors → DefensX → Configure with the current token
A tool returns "not found" for a customerThe customerId doesn't belong to your Partner account, or was mis-copiedRe-list ids with dfx_list_customers (or dfx_get_self_customer) and use one from that response
One tool returns a 403 while others succeedDefensX denied the endpoint, customer, or source IPRe-list the customer, then check the key's IP Restrictions and partner access in DefensX
Write tools missing from your AI's tool listConnector is on the Free tier, or the tools aren't selected for your clientUpgrade the DefensX connector plan and check your tool selections on the MCP Setup page
DNS logs are empty for a customerDNS logs exist only for the DefensX agent (fat-client) deployments, and by default log only blocked/warned queriesUse dfx_get_url_logs for extension/mobile activity; expect DNS logs only where the agent is deployed

DefensX tools

dfx_ · 46 tools · Free 38 · Pro 8

Partner Account & Usage

ToolWhat it does
dfx_create_customer
Pro · Write
Create a new customer under the partner account.
dfx_get_current_usage
Free · Read-only
Get the current, not-yet-billed usage in the current subscription term window.
dfx_get_self_customer
Free · Read-only
Get the partner's own ('self') customer record.
dfx_get_status
Free · Read-only
Health/authentication check for the DefensX Partner API.
dfx_get_usage
Free · Read-only
Get calculated billing usage across customer subscriptions.
dfx_get_usage_details
Free · Read-only
Get per-user usage detail for a specific subscription usage record.
dfx_list_customers
Free · Read-only
List all customers under the partner account.
dfx_list_message_templates
Free · Read-only
List the message templates available for customers.
dfx_list_policy_templates
Free · Read-only
List the policy templates available for customers.
dfx_list_products
Free · Read-only
List all subscription products available to the partner.

Customer Inventory

ToolWhat it does
dfx_list_agents
Free · Read-only
List the DefensX agents installed under a customer.
dfx_list_agents_with_children
Free · Read-only
List the DefensX agents under a customer, including each agent's child elements (the expanded agent hierarchy).
dfx_list_browser_extension_users
Free · Read-only
List the users who have a specific browser extension installed, under a customer.
dfx_list_browser_extensions
Free · Read-only
List the browser extensions detected across a customer's users.
dfx_list_deployments
Free · Read-only
List the deployments configured under a customer (the installer/deployment definitions used to roll out DefensX agents).
dfx_list_groups
Free · Read-only
List the groups defined under a customer.
dfx_list_low_reputation_browser_extensions
Free · Read-only
List only the low-reputation (risky) browser extensions detected across a customer's users — the security-relevant subset of dfx_list_browser_extensions.
dfx_list_users
Free · Read-only
List the users under a customer.

Web Filter Policies

ToolWhat it does
dfx_create_policy
Pro · Write
Create a policy group for a customer.
dfx_delete_policy
Pro · Destructive
Permanently delete a policy group by its id (from dfx_list_policies) for a customer.
dfx_get_policy
Free · Read-only
Get the full configuration of a single policy group by its id (from dfx_list_policies) for a customer.
dfx_list_policies
Free · Read-only
List the policy groups configured for a customer.
dfx_list_webfilter_categories
Free · Read-only
List every web-filter category DefensX can classify (a map of category key -> display name, e.g. CAT_MALWARE -> "Malware", CAT_PHISHING_SITES -> "Phishing Sites").
dfx_update_policy
Pro · Write
Partially update a policy group by its id (from dfx_list_policies) for a customer.

Custom URLs

ToolWhat it does
dfx_create_custom_url_group
Pro · Write
Create a custom URL group under a customer (the customer must have a valid subscription).
dfx_create_custom_urls
Pro · Write
Add one or more custom URLs to a custom URL group (from dfx_list_custom_url_groups) for a customer.
dfx_delete_custom_url
Pro · Destructive
Permanently delete a single custom URL entry from a custom URL group for a customer.
dfx_delete_custom_url_group
Pro · Destructive
Permanently delete a custom URL group AND ALL of its custom URLs (cascade) by the group id (from dfx_list_custom_url_groups) for a customer.
dfx_list_custom_url_groups
Free · Read-only
List the custom URL groups for a customer.
dfx_list_custom_urls
Free · Read-only
List the custom URL entries inside a custom URL group (from dfx_list_custom_url_groups) for a customer, optionally filtered by a search string q.
dfx_search_custom_url_groups
Free · Read-only
Search a customer's custom URL groups for a given hostname — returns the groups that contain a matching custom-URL entry.

Event Logs

ToolWhat it does
dfx_get_consent_logs
Free · Read-only
Get user-consent logs for a customer — occasions where a user acknowledged a warning and proceeded to a flagged site/action.
dfx_get_credential_logs
Free · Read-only
Get credential-submission (password-theft protection) logs for a customer from browser-extension and mobile endpoints — where users entered credentials on external sites.
dfx_get_dns_logs
Free · Read-only
Get DNS query logs for a customer produced by the DefensX agent.
dfx_get_file_transfer_logs
Free · Read-only
Get file-transfer (upload/download) logs for a customer.
dfx_get_rbi_logs
Free · Read-only
Get Remote Browser Isolation (RBI) session logs for a customer — isolated-browsing sessions where risky sites were rendered remotely.
dfx_get_url_logs
Free · Read-only
Get URL access logs for a customer from browser-extension, mobile, and RBI sessions.

Reporting Stats

ToolWhat it does
dfx_get_top_blocked_categories
Free · Read-only
Get the top 20 most-blocked web-filter categories for a customer.
dfx_get_top_blocked_credential_hostnames
Free · Read-only
Get the top 20 hostnames or IP addresses where a customer's users attempted to submit credentials and were blocked by policy.
dfx_get_top_blocked_hostnames
Free · Read-only
Get the top 20 most-blocked hostnames or IP addresses for a customer.
dfx_get_top_categories
Free · Read-only
Get the top 20 most-visited web-filter categories for a customer.
dfx_get_top_category_hostnames
Free · Read-only
Get the top 20 most-visited hostnames within a specific web-filter category for a customer.
dfx_get_top_credential_consent_hostnames
Free · Read-only
Get the top 20 hostnames or IP addresses where a customer's users gave consent and then submitted credentials.
dfx_get_top_credential_hostnames
Free · Read-only
Get the top 20 hostnames or IP addresses where a customer's users submitted credentials.
dfx_get_top_uncategorized_hostnames
Free · Read-only
Get the top 20 most-visited uncategorized hostnames or IP addresses for a customer (sites DefensX could not classify).

Cyber Resilience

ToolWhat it does
dfx_get_cyber_resilience
Free · Read-only
Get a customer's cyber-resilience score over a time range, including the top 10 riskiest users.