Connect DefensX
DefensX is a web and DNS security platform (secure web gateway, DNS filtering, credential-theft and browser-extension protection, and remote browser isolation) that MSPs run across their customers.…
Written By Christopher Scaminaci
Last updated 6 days ago
DefensX is a web and DNS security platform (secure web gateway, DNS filtering, credential-theft and browser-extension protection, and remote browser isolation) that MSPs run across their customers. StackJack connects to the DefensX Partner API, so your AI assistant works across every customer under your DefensX Partner account.
Connecting DefensX to StackJack gives your AI assistant a focused family of dfx_ MCP tools — MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:
- Discover your customer roster, the partner product/message/policy-template catalogs, and billing usage
- Inventory each customer's agents, deployments, groups, users, and detected browser extensions (including the low-reputation ones)
- Review web-filter categories, policy groups, and custom URL allow/block groups
- Investigate security event logs — URL access, credential submissions, file transfers, user consents, DNS queries, and remote-browser-isolation sessions
- Report on the top visited and blocked categories and hostnames, credential-theft hotspots, and a customer's overall cyber-resilience score
- Act (on Pro plans) — create customers, and create, update, or delete policy groups and custom URL groups/entries
How StackJack authenticates to DefensX
DefensX uses a Partner API token. You generate it in the DefensX Partner Dashboard under API Keys, and paste it into StackJack. StackJack sends it as an Authorization: Bearer header on every call — there is no client ID, OAuth sign-in, or refresh-token flow.
DefensX documents the key as a partner credential for customer management, security monitoring, policies, analytics, agents, and usage. Its public Partner API guide does not document selectable per-key permission scopes or a token expiration schedule. Treat the token as high privilege, create a dedicated integration key, and scope what your AI can do with the tool selections on the MCP Setup page and the Permissions page.
DefensX can apply IP Restrictions when you create a key. Only enable that control after StackJack support has given you the current outbound addresses for your region (they are not published, and a region move changes them); an incomplete allowlist blocks save-time validation and every later tool call.
One fixed address
DefensX is a global SaaS with a single Partner API address — there are no regional endpoints and no URL to enter. StackJack fills the base address in for you.
Working across customers
Almost every DefensX tool is customer-scoped: it needs a customerId (a UUID) to say which customer to act on. Your AI discovers those ids first:
dfx_list_customerslists every customer under your Partner account, each with its id, name, and domains.dfx_get_self_customerreturns your own partner tenant's customer record.
From there it passes the id into the inventory, policy, log, and reporting tools. A good first prompt is simply "list my DefensX customers" — then work from that list.
What is not included
DefensX also offers SIEM event streaming and External Notification callbacks. Both are push mechanisms — DefensX sends events out to a destination you register in the DefensX dashboard, rather than an address StackJack can call. They are configured in DefensX and are not exposed as MCP tools. The connector covers the Partner API's request/response operations only.
Before you begin
- In StackJack: you need a role that can manage connectors (tenant Owner, a co-owner, or an Administrator).
- In DefensX: you need access to your DefensX Partner Dashboard sufficient to generate a token under API Keys.
Step 1 — Generate a Partner API token in DefensX
- Sign in to your DefensX Partner Dashboard at
https://cloud.defensx.com. - Open API Keys and generate a new Partner API token.
- If you use IP Restrictions, allow the StackJack outbound addresses for your region. StackJack does not publish them: open a support ticket to get them, and leave the restriction off until you have them.
- Copy the token — you'll paste it into StackJack. Treat it like a password; it authenticates every call on its own.
Step 2 — Add the credentials in StackJack
- In the StackJack portal, open Connectors.
- Select the DefensX tile to open its details drawer.
- Use How To Connect to review the inline vendor steps, then choose Configure in the drawer footer.
- Paste your Partner API token. There is no URL or client ID to enter.
- Click Save.
What happens when you save
- The token is stored encrypted in Azure Key Vault — never in the StackJack database, and never shown back to you.
- If this is the first time you configure DefensX, a Free-tier subscription for the connector is created automatically so its Free tools work right away.
- StackJack immediately live-validates the token by making a low-cost authenticated read. The credential remains saved if the upstream check fails so you can correct vendor access without re-entering every field.
- The Configure form collapses while the details drawer stays open. The drawer shows Connected and Valid after success, or Needs Attention with the vendor error and a Re-test action after failure.
Plans and available tools
See the generated DefensX tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.
DefensX has no per-user sign-in, so there is no per-user attribution — all AI traffic authenticates as the single Partner API token. Current pricing and quotas are shown in the portal's Billing page and at checkout.
Safety note — irreversible deletes. The Pro delete tools permanently remove configuration and are flagged for consent in AI clients that support it:
dfx_delete_policy(users/devices in that group fall back to the default policy),dfx_delete_custom_url_group(also deletes every custom URL inside it), anddfx_delete_custom_url. Enable them only when you want an AI to take those actions.
Rate limits
DefensX publishes no numeric API quota. StackJack applies a conservative per-tenant pace and honors any 429 backoff, so a long multi-page log or stats read is usually just slower. Pacing is not a guarantee: retries are bounded, so a wide enough read can still come back throttled or time out. Narrow the read, honour any retry delay the vendor sends, and check whether a write landed before repeating it — see Retrying a failed or timed-out write.
Rotating or replacing the token
DefensX does not publish a token-expiration or automatic-rotation contract. If the key is revoked, expires, or its IP restriction changes, create a replacement in Partner Dashboard → API Keys. In StackJack, open the DefensX details drawer, choose Configure, paste the replacement, save, and use Re-test.
Disconnecting DefensX
Choose Disconnect in the DefensX details drawer and confirm. StackJack deletes its stored Key Vault credential and stops making DefensX calls. Disconnecting does not revoke the upstream DefensX key, so revoke it separately in Partner Dashboard → API Keys when it should no longer work. Connector subscription changes are separate from credential disconnection.
Troubleshooting
DefensX tools
dfx_ · 46 tools · Free 38 · Pro 8
Partner Account & Usage
Customer Inventory
Web Filter Policies
Custom URLs
Event Logs
Reporting Stats
Cyber Resilience
More in Connector guides
Connect Acronis Cyber Protect CloudConnect Action1Connect AddigyConnect AlertOpsStill need help? Ask the team