Connect Huntress
Huntress is a managed security platform for SMBs and the MSPs that serve them. It combines managed EDR (endpoint detection and response), identity threat detection for Microsoft 365 (ITDR), External…
Written By Christopher Scaminaci
Last updated 6 days ago
Huntress is a managed security platform for SMBs and the MSPs that serve them. It combines managed EDR (endpoint detection and response), identity threat detection for Microsoft 365 (ITDR), External Recon, and a 24/7 human Security Operations Center (SOC) that investigates suspicious activity and writes actionable Incident Reports.
Connecting Huntress to StackJack gives your AI assistant huntress_ MCP tools. See the generated Huntress tool reference for the current inventory, input schemas, plan tiers, and safety notes. MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:
- Inventory deployed agents and protected identities across all your organizations
- Review SOC-authored Incident Reports and the remediations they recommend
- Triage Escalations and Platform Actions that need a human decision
- Investigate raw Signals (the detections that feed investigations)
- Audit organizations, user memberships and roles, External Recon exposed ports, and Unwanted Access rules
- Reconcile billing — invoices and summary reports, plus reseller usage if you're a reseller
- Act (on Pro plans) — isolate or uninstall agents, approve or reject remediations, resolve incident reports and escalations, manage organizations and memberships, and run SIEM queries
How StackJack authenticates to Huntress
Huntress issues API credentials as a pair: an API Key (the public half) and an API Secret Key (the private half). StackJack sends them with every request; there is no OAuth flow and nothing to refresh. The base URL is fixed (Huntress is a global SaaS with no regional endpoints), so the key pair is all you enter.
The key pair inherits the visibility of the Huntress account it was generated in — it can see all organizations and agents visible to that account.
Before you begin
- In StackJack: you need a role that can manage connectors (tenant Owner, a co-owner, or an Administrator).
- In Huntress: you need administrator access to your Huntress portal and a dedicated user whose permissions match what StackJack should be allowed to do.
- Decide whether you need write access. Huntress recommends user-based credentials, which mirror the selected user's permissions. See "Read-only vs write-capable keys" below before generating.
Step 1 — Generate API credentials in Huntress
- Sign in to your Huntress portal as an administrator.
- Open the hamburger menu in the upper-right corner and choose API Credentials.
- In User API Credentials, click Add.
- Select the dedicated least-privilege user, enter a descriptive Key Name such as
StackJack, and click Add. - Copy both the API Key and Secret from the new credential box and store them securely. Huntress shows the full credential only once; if you lose it, delete that credential and create a replacement.
Read-only vs write-capable keys
Huntress's recommended User API Key mirrors the selected user's permissions. It can support read-only or write APIs depending on that user's role. To use Pro write tools — isolating hosts, approving remediations, resolving escalations, managing organizations and memberships, or SIEM queries — the selected user must have the corresponding Huntress permission. A key calling an operation its user cannot perform gets an authorization error from Huntress, even on a Pro plan.
The older Account API Key is deprecated, limited to one per account, and read-only. Existing account keys continue to suit read-only use, but create a least-privilege user key for new StackJack setups.
Reseller accounts
If you are a Huntress reseller (you manage billing and a portfolio of downstream accounts), generate the credentials from your reseller account. Reseller credentials unlock two extra tool families:
- Managed Accounts — read a downstream account's agents, signals, incident reports and remediations, External Recon ports, invoices, organizations, memberships, and summary reports by passing its account ID (discover IDs with
huntress_list_managed_accounts). - Reseller Billing — read reseller invoices, usage line items, and subscriptions.
A standard (non-reseller) key still works for every regular tool; it just can't call the Managed-Account or Reseller-Billing tools.
Step 2 — Add the credentials in StackJack
- In the StackJack portal, open Connectors.
- Find the Huntress card. Click How To Connect for the same steps inline, or Configure to enter the credentials.
- Paste the API Key (Public) and the API Secret Key (Private). There is no URL to enter — the base URL is fixed at
https://api.huntress.io. - Click Save.
What happens when you save
- The keys are stored encrypted in Azure Key Vault — never in the StackJack database, and they are never shown back to you.
- If this is the first time you configure Huntress, a Free-tier subscription for the connector is created automatically so its Free tools work right away.
- StackJack immediately live-validates the credentials by calling the Huntress account endpoint. Validation never blocks the save: you'll either see a success confirmation or a "saved but validation failed" warning with the reason.
- The connector card shows the current connection and validity status from then on.
Plans and available tools
- Free includes the read tools: agents, identities, incident reports and remediations, escalations, platform actions, signals, organizations, memberships, invoices, External Recon ports, and summary reports — plus the Managed-Account and Reseller-Billing read families if you're a reseller.
- Pro adds the write/action tools: isolate and release agents, update agent tags, uninstall agents, resolve incident reports, approve/reject remediations, resolve escalations, create/update/delete organizations and memberships, manage Unwanted Access rules, run SIEM queries, and (for resellers) manage downstream accounts and subscriptions.
- Business offers the same tool set as Pro with a higher monthly call quota.
Huntress has no per-user sign-in flow, so there is no per-user attribution — all AI traffic uses the shared key pair. Current pricing and quotas are shown in the portal's Billing page and at checkout.
Safety note: some Pro actions change security state irreversibly. In particular, uninstalling an agent removes the Huntress sensor from the endpoint and stops monitoring — reinstalling requires a fresh deployment. Scope your AI's access deliberately: use the tool selections on the MCP Setup page and the Permissions page to enable only the actions you want an AI to take, and consider keeping a read-only key unless you specifically need response actions.
Rate limits
StackJack paces Huntress calls at 50 requests per minute per tenant and backs off when Huntress throttles, so a burst is slowed rather than sent all at once and a long multi-page inventory read is usually just slower. Pacing is not a guarantee: retries are bounded, so a wide enough read can still come back throttled or time out. Narrow the read, honour any retry delay the vendor sends, and check whether a write landed before repeating it — see Retrying a failed or timed-out write.
For the code-derived inventory of currently shipping Huntress tools, parameters, plan tiers, and safety flags, see the generated Huntress tools reference. It is the canonical tool list; this setup guide intentionally does not duplicate it.
Rotating or replacing the keys
Huntress allows multiple user-based credentials, so rotate without a gap:
- In API Credentials → User API Credentials, add a replacement credential for the same dedicated user and copy both values.
- Update Connectors → Huntress → Configure in StackJack with the replacement pair and run Re-test.
- After validation succeeds, delete the old Huntress credential.
Troubleshooting
Huntress tools
huntress_ · 92 tools · Free 55 · Pro 37
Account
Agents
Identities
Incident Reports
Escalations
Platform Actions
Signals
Organizations
Memberships
Invoices
External Recon
Summary Reports
Unwanted Access Rules
Managed Accounts (Reseller)
Reseller Billing
SIEM
More in Connector guides
Connect Acronis Cyber Protect CloudConnect Action1Connect AddigyConnect AlertOpsStill need help? Ask the team