Connect ESET PROTECT
ESET PROTECT is ESET's cloud security-management platform, exposed to StackJack through the ESET Connect API. It covers endpoint protection, EDR/XDR (ESET Inspect), quarantine, policies, installers,…
Written By Christopher Scaminaci
Last updated 6 days ago
ESET PROTECT is ESET's cloud security-management platform, exposed to StackJack through the ESET Connect API. It covers endpoint protection, EDR/XDR (ESET Inspect), quarantine, policies, installers, patch and vulnerability management, and automation across your managed devices.
Connecting ESET PROTECT to StackJack gives your AI assistant a broad family of eset_ MCP tools — MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:
- Inventory managed devices, the customer device-group tree, installers, and observed executables
- Investigate detections, incidents, and EDR rules and exclusions — the EDR/XDR surface
- Audit patch status, OS and application vulnerabilities, and quarantined objects
- Review policies and their assignments, plus network-access and web-access rules
- Act (on Pro plans) — run device tasks (scans, isolation, uninstall), restore or delete quarantine, write EDR rules and policies, manage device groups, roles, and users
- Download (on Pro plans) quarantined binaries as short-lived, read-only SAS URLs
How StackJack authenticates to ESET PROTECT
ESET Connect authenticates through an OAuth 2.0 password grant using a dedicated API User. You enter that user's username and password. StackJack exchanges them at ESET's token endpoint (https://{region}.business-account.iam.eset.systems/oauth/token) for a short-lived (one-hour) access token plus a rotating refresh token, caches the access token, and rotates the refresh token automatically. There is nothing for you to refresh manually.
The access token inherits exactly the API User's access rights — everything your AI can see or change in ESET is bounded by what that API User can. A 403 from a tool means the API User lacks that specific right, not an account-wide block.
Regions
ESET Connect has no single global host — each region is a separate deployment. StackJack shows a Region dropdown (US / EU / DE / CA / JPN) that sets the base host https://{region}.esetconnect.eset.systems; every API call then targets a per-domain host derived from that region. Pick the region your ESET Business Account lives in. Choosing the wrong region fails fast at save.
Japan (JPN) region gap. The JPN deployment does not expose the quarantine family, the user-management family, or
eset_list_detections(the v2 detections list; the v1 list still works). They work normally in US, EU, DE, and CA. Affected tools surface ESET's upstream not-found; there is no StackJack-side block.
Before you begin
- In StackJack: you need a role that can manage connectors (tenant Owner, a co-owner, or an Administrator).
- In ESET: a Root or Superuser must create the dedicated user. ESET does not allow the Root/Superuser account itself to receive API access.
- Know your region — the ESET Business Account region you'll select in StackJack.
- Review ESET's current Create API user account, authentication, and rate-limit guidance.
Step 1 — Create a dedicated API User in ESET
- Sign in as the Root or Superuser to ESET Business Account, ESET MSP Administrator, or ESET PROTECT Hub.
- Create a separate user for StackJack. Do not use a personal administrator whose departure or password changes could interrupt the integration.
- Enable Integrations under that user's Access Rights (ESET Business Account / MSP Administrator) or Permissions (ESET PROTECT Hub).
- Assign the access rights the selected tools need: read access for reads and the corresponding write rights for devices, policies, quarantine, incidents/EDR, automation, and other actions you enable.
- Complete the invitation sent to the new user. For ESET PROTECT Hub, sign in as that user at least once before using the API.
- Record the API User's username and password.
Step 2 — Add the credentials in StackJack
- In the StackJack portal, open Connectors.
- Select the ESET PROTECT tile to open its details. Choose How To Connect to review the inline setup guide, or Configure to reveal the credential form in the drawer.
- Choose your Region from the dropdown (US / EU / DE / CA / JPN). The Instance URL field auto-fills from your choice — leave it as shown.
- Enter the API User Username and the API User Password.
- Click Save.
What happens when you save
- The username and password are stored encrypted in Azure Key Vault — never in the StackJack database, and never shown back to you.
- If this is the first time you configure ESET PROTECT, a Free-tier subscription for the connector is created automatically so its Free tools work right away.
- StackJack immediately live-validates the credentials by acquiring a token and calling an ESET IAM permissions endpoint. Validation never blocks the save.
- After saving, the form collapses and the connector drawer stays open. It shows Connected / Valid on success, or Needs Attention with Re-test and recovery guidance if validation failed.
How ESET's customer hierarchy works
ESET has no companyId parameter. The customer hierarchy is a device-group tree whose nodes carry entity types (MSP / COMPANY / SITE). Your AI enumerates companies and sites with eset_list_device_groups and manages membership through the group tools — there's no separate per-company credential to configure.
Plans and available tools
- Free includes list/get/count/search operations across devices, device groups, detections, incidents, EDR rules, policies, quarantine, installers, executables, patches, vulnerabilities, users, and IAM.
- Pro adds create/update/delete operations, policy assignment, quarantine restore/delete/purge, device tasks (scans, isolation, uninstall), EDR-rule and exclusion management, role assignment, and automations — plus the quarantine binary-download tools.
- Business offers the same tool set as Pro with a higher monthly call quota.
See the generated ESET PROTECT tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.
ESET has no per-user OAuth (the Connect API offers only the password grant), so there is no per-user attribution — all AI traffic authenticates as the single dedicated API User. Current pricing and quotas are shown in the portal's Billing page and at checkout.
Safety note — malware egress.
eset_download_quarantined_objectsandeset_batch_download_quarantined_objectsreturn short-lived, read-only SAS URLs to quarantined binaries in blob storage rather than plain JSON. Because those payloads are live malware samples by nature, both tools are Pro-gated. Scope your AI's access to them deliberately: use the tool selections on the MCP Setup page and the Permissions page to enable only the actions you want an AI to take.
Rate limits
ESET publishes a limit of 10 API calls per second for each combination of API credentials, account, and originating IP. It also applies a Fair Use policy to very large bursts. StackJack uses a more conservative 300 calls per minute per tenant and records upstream 429 backoff. Other traffic sharing the same account or source IP can still contribute to ESET's limit.
Rotating or replacing the credentials
The API User's username and password are the recovery secret. If you change or reset the API User's password in ESET — or delete and recreate the API User — the stored credential becomes invalid. To restore access, open Connectors → ESET PROTECT → Configure in StackJack and enter the new password (re-select the region and username if needed), then Save.
Disconnecting ESET PROTECT
StackJack's Disconnect action removes the stored API User credential and stops future calls; it does not disable or delete that user in ESET. If the account is dedicated to StackJack and no longer needed, disable or remove it in the appropriate ESET account console as a separate, deliberate step. ESET notes that an already-issued access token can remain usable until its one-hour expiry after the user is removed. Subscription changes are separate from credential removal.
Several customers
Some MSPs need one ESET PROTECT connection per customer, console or region. StackJack can hold several named connections of one connector, and your AI names the one it wants on each call. See Several connections of one connector.
Troubleshooting
ESET PROTECT tools
eset_ · 102 tools · Free 51 · Pro 51
Executables
Groups (Asset Management)
Device Tasks (Automation)
Device Groups
Devices
IAM (Roles & Permissions)
Detections
Detection Groups
EDR Rules & Exclusions
Incidents
Installers
Mobile Devices
Network Access Protection
Patch Management
Policies
Quarantine
Users
Vulnerabilities
Web Access Protection
Async Continuation
More in Connector guides
Connect Acronis Cyber Protect CloudConnect Action1Connect AddigyConnect AlertOpsStill need help? Ask the team