Connect Bitdefender GravityZone
Bitdefender GravityZone is the console behind Bitdefender's endpoint protection. It runs antivirus and anti-ransomware on your customers' machines, adds EDR and XDR incident detection on top, patches…
Written By Christopher Scaminaci
Last updated 6 days ago
Bitdefender GravityZone is the console behind Bitdefender's endpoint protection. It runs antivirus and anti-ransomware on your customers' machines, adds EDR and XDR incident detection on top, patches third-party software, hardens applications, and holds the quarantine that suspicious files land in. MSPs usually reach it through the partner Control Center, where each customer is a company you manage under your own account.
Connecting GravityZone to StackJack gives your AI assistant a family of gravityzone_ MCP tools — MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:
- See the estate — every managed endpoint with its protection status, agent version, policy and label, plus the group and company structure around it
- Work the incident queue — endpoint and organization incidents, the evidence behind each, the blocklist, and the custom detection rules in force
- Report on patching — which updates are installed across the fleet and which are missing, filtered to a company or a set of endpoints
- Check the quarantine — what is being held for both endpoints and Exchange mail, and why
- Audit licensing and companies — license status, monthly usage, company details, and the custom fields attached to each
- Review hardening — the PHASR rules being monitored, the recommendations waiting on a decision, and who has asked for an exception
- Respond to a threat (on Pro plans) — isolate a compromised endpoint from the network, kill a running process, collect an investigation package, run a scan, and lift isolation again
- Change protection (on Pro plans) — assign policies, switch protection modules on or off, add and remove blocklist entries, and create or update custom detection rules
- Manage the estate (on Pro plans) — create, suspend and delete companies, move endpoints and seats between them, build installation packages, and schedule maintenance windows
How StackJack authenticates to GravityZone
GravityZone uses a single long-lived API key. There is no client ID, no second secret, and nothing that expires on a schedule. You generate the key once in Control Center and paste it into StackJack along with your console's Access URL.
The Access URL and the key are a pair
This is the one thing worth getting right before anything else. GravityZone cloud consoles are completely separate from one another, and a key created on one console is meaningless on another. Always copy both values from the same place, in the same sitting.
You will find both in Control Center under My Account: the Access URL under Control Center API, and the key under API keys.
If you run GravityZone on-premises, enter the address of your own console instead of a Bitdefender cloud address. It must be reachable over HTTPS with a valid certificate.
Choose the API groups carefully — you cannot widen them later
When you create the key, GravityZone asks which API groups it may reach. That choice is fixed at creation. There is no way to add a group to an existing key afterward, from the console or from StackJack.
Tick General. It is the group StackJack's connection test runs on: the test asks GravityZone which groups the key holds, and that question is itself a General call. A key without General cannot be verified at all, so the connector never reports as connected no matter how many other groups you ticked.
Beyond General, pick the groups matching the work you want your AI to do. The narrower this choice, the less any later mistake can reach — and it cannot be widened afterwards, so a key that reaches only what you need is the strongest control available here. If you would rather not decide now, enabling all of them and relying on StackJack's plan tiers and your own tool selection is the simpler path.
A key that is missing one of those other groups is not broken. Tools in that group will report that GravityZone refused them, everything else keeps working, and the connection test still shows as connected.
Steps
- Sign in to Control Center as an administrator whose account holds the Manage Networks, Manage Users, Manage Company, and View and analyze data rights. An account without those rights can create a key that silently sees nothing.
- Copy your Access URL from My Account, under Control Center API.
- Create the API key under My Account, choosing the API groups it may reach. Include General, or the connection test in step 6 cannot run.
- Copy the key immediately. GravityZone shows it exactly once. It cannot be read back afterward — if you lose it, create a replacement and delete the old one.
- Paste both values into StackJack. Open Connectors, choose Bitdefender GravityZone, and enter the Access URL and the key.
- Run a Test Connection. A successful test confirms the key works — it needs the General group to do that — but it does not list your API groups back to you. To see the granted list, ask your agent for Get API Key Details (
gravityzone_get_api_key_details) once the connector is saved; it is read-only and available on Free.
What to know before your AI uses this connector
Every GravityZone action is a request that looks the same
GravityZone does not distinguish a read from a change at the network level — reading the endpoint list and isolating a machine are the same shape of request. Nothing in the protocol protects you, so StackJack labels each tool by what it actually does, and that label is what your AI application reads.
Seventy of the tools are marked destructive, and every one of them requires the Pro tier. Whether your AI application asks you to confirm before running one depends on that application's own settings — see Destructive tools and confirmation. Review that setting, and grant only what you want an AI to reach.
Some tools take a machine off the network
- Isolating an endpoint cuts it off from everything except GravityZone itself. It is the right response to a live compromise, and it will also stop a person working. Restoring from isolation is a separate tool.
- Running a command on an endpoint, killing a process, and collecting an investigation package all act on a live machine while someone may be using it.
- Running a live search query reaches every endpoint in a company at once and writes its results to storage you nominate.
Some tools change protection itself
- Switching a protection module off leaves the agent installed and reporting, so nothing looks broken, while that layer of protection stops running.
- Assigning a policy replaces the settings on every endpoint it reaches.
- Adding a custom rule as an exclusion tells GravityZone to stop detecting something. That is sometimes exactly right and always worth reading twice.
- Removing a blocklist entry allows something that was previously blocked estate-wide.
Some tools affect billing and customer access
- Creating, suspending and deleting companies changes who exists in your console. Deleting one removes its endpoints and history with it.
- Moving endpoints between companies moves the seats that go with them, and therefore the billing.
- Setting a license key or a monthly subscription changes what a customer is charged.
Quarantine releases put a file back
Restoring a quarantined file returns it to the machine it came from, and releasing a quarantined Exchange item delivers that message to a real person's inbox. Emptying the quarantine discards everything held in it, and there is no undo.
Anything asynchronous returns a task, not a result
Scans, isolation, package collection, log gathering and command execution all hand back a task identifier rather than a finished outcome. Ask your AI to check the task status before it reports what happened — a dispatched task is not a completed one.
Filters can be silently ignored
Two GravityZone filtering behaviors are worth knowing, because both produce a confidently wrong answer rather than an error:
- A name filter matches by prefix unless the value starts with
*, which switches it to a contains match. - A filter whose underlying GravityZone license is not active is ignored rather than refused, so the result set comes back looking complete.
If a filtered count looks surprising, confirm the license before trusting it.
Plans and limits
Read tools are available on the Free tier. Everything that writes, responds, isolates, or changes licensing is Pro. Business reaches the same tools as Pro and differs by monthly call quota.
See the generated Bitdefender GravityZone tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.
Bitdefender limits an API key to 10 requests a second by default. Some areas are slower on purpose: licensing and company changes allow 5 a second, and the blocklist, custom-rule, notification and maintenance-window changes allow only 5 a minute. StackJack paces requests and backs off automatically when GravityZone throttles, which usually makes a large sweep slower rather than failed. Pacing smooths a burst; it does not guarantee that every call arrives. Retries are bounded, so a wide enough read can still come back throttled or time out. Narrow the read, honour any retry delay the vendor sends, and check whether a write landed before repeating it — see Retrying a failed or timed-out write.
Several customers
Some MSPs need one Bitdefender GravityZone connection per customer, console or region. StackJack can hold several named connections of one connector, and your AI names the one it wants on each call. See Several connections of one connector.
Troubleshooting
"GravityZone rejected the credentials" — the key is wrong for this console, or it has been deleted. Because the Access URL and the key are a pair, the most common cause is a key copied from a different console than the URL. Re-copy both from the same Control Center and run a Test Connection.
"This API key was not granted that group" — the key is valid and the group it needs was not enabled when it was created. Groups cannot be widened on an existing key: create a replacement key with the groups you need, paste it into StackJack, then delete the old one.
A company shows no endpoints — check that the account behind the key can actually see that company. A partner account sees the companies it manages; a company-level account sees one. A key with narrower reach than you expect returns an empty list rather than an error.
A filtered list looks too short — see the note on filters above. A prefix match and a silently-ignored filter both look like a small result rather than a mistake.
An action reported success but nothing happened — check whether the tool dispatches a task. Scans, isolation, package collection and command execution all return a task identifier first; the work happens afterward and can still fail.
Reports and packages seem to vanish — GravityZone holds generated reports and installation packages on its own schedule. If a download link no longer resolves, regenerate the report rather than retrying the old link.
Bitdefender GravityZone tools
gravityzone_ · 138 tools · Free 56 · Pro 82
Accounts
Companies
General
Incidents
Integrations
Investigation
Licensing
Maintenance Windows
Network
Packages
Patch Management
PHASR
Policies
Event Push Service
Quarantine
Reports
More in Connector guides
Connect Acronis Cyber Protect CloudConnect Action1Connect AddigyConnect AlertOpsStill need help? Ask the team