Connect ImmyBot
ImmyBot is a Windows and macOS software-deployment and endpoint-automation platform for MSPs. Connecting it to StackJack gives your AI assistant a broad family of immy_ MCP tools — MCP (Model Context…
Written By Christopher Scaminaci
Last updated About 22 hours ago
ImmyBot is a Windows and macOS software-deployment and endpoint-automation platform for MSPs. Connecting it to StackJack gives your AI assistant a broad family of immy_ MCP tools — MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:
- Inventory managed computers, their software and detected applications, agent status, and per-tenant fleet counts
- Manage software and scripts — global and local software packages and versions, PowerShell scripts and metascripts, Chocolatey lookups, and software licenses
- Run deployments and maintenance — deployments (target assignments), maintenance sessions and actions, maintenance and inventory tasks, and schedules
- Organize customers — tenants, tags, persons, users, and role-based access (RBAC)
- Wire up integrations — provider links (RMM/PSA), provider clients and agents, and dynamic provider types
- Act (on Pro plans) — create, update, and delete across those areas; run scripts and maintenance on endpoints; onboard and offboard computers; and manage tenants, deployments, and RBAC
How StackJack authenticates to ImmyBot
You have two ways to connect, and you pick one on the Configure form. Both work with every tool; the difference is only how the credential is created.
- Personal access token — a long-lived token you create inside ImmyBot on your own profile page. StackJack sends it on every call. Apart from the token, the only value StackJack needs is your instance URL. There is no Microsoft setup at all, and no person or user mapping to do inside ImmyBot. This is the simpler path, and the one to choose if you have no reason to prefer the other.
- Entra app registration — app-only access through your own Microsoft Entra ID (Azure AD). You register an application, create a client secret, and represent its Enterprise application as a person/user in ImmyBot. StackJack mints a short-lived access token from Microsoft on each call.
Neither method uses a refresh token.
Which one should I use?
Choose the personal access token if you want the shortest setup, or if the Entra path is producing intermittent permission errors — ImmyBot resolves a personal access token to its owning ImmyBot user directly, without the sign-in step that an Entra application has to go through.
Choose the Entra app registration if your organization requires API access to run under an Entra application identity rather than a named user, or if you already have it working and see no reason to change.
Switching between the two later is just a re-save: open Connectors → ImmyBot → Configure, pick the other method, enter its values, and save. Your connector plan, tool selections and MCP setup are untouched.
Option A — Connect with a personal access token
- In ImmyBot, open your profile page and create an API token.
- Give it a label so you can recognize it later, and (optionally) an expiration date. If you set one, put a reminder in your calendar — StackJack cannot renew it for you.
- Copy the token value immediately. ImmyBot shows it exactly once.
- In the StackJack portal, open Connectors, select the ImmyBot tile, then Configure.
- Choose Personal access token.
- Paste the token and enter your Instance URL (
https://your-subdomain.immy.bot, or your custom / self-hosted host). - Click Save.
A few things worth knowing about tokens:
- The token carries the permissions of the ImmyBot user who created it. Create it as a user with the access you want StackJack to have, and no more.
- Revoking the token in ImmyBot cuts StackJack off immediately. That is the fastest way to stop access without touching StackJack.
- ImmyBot allows a limited number of active tokens per user, so clean up ones you no longer use.
- An ImmyBot administrator can review and revoke tokens across the organization from the personal-access-tokens settings page, if their role allows it.
If you use a personal access token, you can skip the rest of the Entra setup below.
Option B — Connect with an Entra app registration
The four values StackJack needs:
- Azure Tenant (ID or domain) — your Microsoft tenant, entered as either the tenant ID (a GUID) or your Azure domain (e.g.
contoso.onmicrosoft.com). - Application (Client) ID — the Entra app registration's Application (client) ID.
- Client Secret — a client secret value from that app registration.
- Instance URL — your ImmyBot instance URL. This is usually
https://your-subdomain.immy.bot, but if your instance is on a custom domain or a self-hosted host (for examplehttps://immy.yourcompany.com), enter that host instead. StackJack accepts any well-formedhttps://host — it does not have to end in.immy.bot— as long as it uses HTTPS and carries no embedded username/password.
StackJack honors the token endpoint's returned expires_in, caches the token for a safe fraction of that lifetime, and re-mints it automatically. ImmyBot's published API setup tells you to create a user for the Enterprise application's Object ID and grant that user admin privileges. Treat this as a high-privilege service identity and narrow what agents can call through StackJack's tool selections and Permissions page.
Before you begin (Entra path)
- In StackJack: you need a role that can manage connectors (tenant Owner, a co-owner, or an Administrator).
- In Microsoft Entra ID: access to the same Microsoft tenant your ImmyBot instance uses, sufficient to create an app registration and client secret and inspect its Enterprise application.
- In ImmyBot: access to create a person, create a user from that person, and grant the user admin privileges.
- Your ImmyBot instance URL — usually
https://your-subdomain.immy.bot, or your custom / self-hosted host if you use one.
Step 1 — Register an application in Microsoft Entra ID
- In the Azure portal for the same Microsoft tenant your ImmyBot instance uses, go to Microsoft Entra ID → App registrations → New registration.
- Give it a name (for example, "StackJack") and register it.
Step 2 — Create a client secret
- On the app registration, go to Certificates & secrets → New client secret.
- Copy the secret VALUE immediately — Azure shows it only once.
Step 3 — Create the ImmyBot API user
- In Microsoft Entra ID, open Enterprise Apps and select the API application you just created.
- Copy the Enterprise application's Object ID. This is not the App Registration Object ID and not the Application (Client) ID.
- In ImmyBot, go to Show More → People → New.
- Paste the Enterprise application Object ID into AD External ID, fill in the rest of the person record, and save it.
- From the People list, create a user for that person. Then go to Show More → Users, edit the user, select Admin, and update it.
Step 4 — Add the credentials in StackJack
- In the StackJack portal, open Connectors.
- Select the ImmyBot tile to open its details drawer.
- Use How To Connect to review the inline setup, then choose Configure in the drawer footer.
- Choose Entra app registration, then fill in the four fields:
- Azure Tenant (ID or domain) — the tenant GUID or your Azure domain.
- Application (Client) ID — the app registration's Application (client) ID.
- Client Secret — the secret value you copied.
- Instance URL —
https://your-subdomain.immy.bot.
- Click Save.
What happens when you save
- If you chose the Entra path and entered an Azure domain, StackJack looks up its tenant ID for you. If the domain can't be resolved, the save is rejected so a bad value is never stored — re-check the domain and try again. The personal-access-token path has no Azure lookup.
- The credentials are stored encrypted in Azure Key Vault — never in the StackJack database, and never shown back to you.
- If this is the first time you configure ImmyBot, a Free-tier subscription for the connector is created automatically so its Free tools work right away.
- StackJack live-validates the credentials by minting a token and making a low-cost authenticated read. The credential remains saved if the upstream check fails so you can correct Entra or ImmyBot access without re-entering every field.
- The Configure form collapses while the details drawer stays open. The drawer shows Connected and Valid after success, or Needs Attention with the vendor error and a Re-test action after failure.
Plans and available tools
See the generated ImmyBot tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.
ImmyBot API access has no per-user sign-in, so all AI traffic authenticates as the one credential you stored — the registered Entra application, or the ImmyBot user whose personal access token you entered — and there is no per-user attribution. Current pricing and quotas are shown in the portal's Billing page and at checkout.
Safety note — endpoint actions. Some ImmyBot tools run scripts on, reboot, or re-image managed endpoints, run maintenance, or change instance-wide settings — for example running a script (
immy_scripts_run), running maintenance (immy_run_immy_service), or restarting the backend (immy_system_restart_backend). StackJack marks these as write or destructive. Whether your AI application asks you to confirm before running one depends on that application's own settings — see Destructive tools and confirmation. Review those settings, and scope your AI's access deliberately: use the tool selections on the MCP Setup page and the Permissions page to enable only the actions you want an AI to take.
Spreadsheet exports. Export tools return a read-only StackJack download link rather than putting the spreadsheet bytes in the tool response. The link expires after 15 minutes. Open it promptly; re-run the tool to get a fresh link after it expires.
Rate limits
ImmyBot publishes no numeric API quota. StackJack applies a conservative per-tenant pace (about 300 requests per minute) and honors any rate-limit backoff, so a long multi-page inventory read is usually just slower. Pacing is not a guarantee: retries are bounded, so a wide enough read can still come back throttled or time out. Narrow the read, honour any retry delay the vendor sends, and check whether a write landed before repeating it — see Retrying a failed or timed-out write.
Rotating or replacing the credentials
Personal access token. If the token expires or you revoke it, create a new one in ImmyBot, open the ImmyBot details drawer, choose Configure, paste the new token, save, and choose Re-test. Deleting the old token in ImmyBot is what stops it working; StackJack keeps only the value you last saved.
Entra app registration. If the client secret is rotated, removed, or expires, open the ImmyBot details drawer, choose Configure, enter the new secret value, save, and choose Re-test. Keep the ImmyBot person/user mapped to the same Enterprise application Object ID; replacing the app registration requires updating both that mapping and the StackJack Client ID.
Switching between the two methods is the same operation: choose the other option on the Configure form and enter its values. Nothing else about the connector changes — same plan, same tool selections, same MCP setup. The secret box is never pre-filled, so whichever method you switch to needs its secret or token typed in.
Disconnecting ImmyBot
Choose Disconnect in the ImmyBot details drawer and confirm. StackJack deletes its stored credentials and stops calling ImmyBot. Disconnecting does not revoke the personal access token in ImmyBot, and it does not delete the Entra app registration, its secret, the Enterprise application, or the ImmyBot person/user. Revoke the token, or remove or disable those upstream identities, separately when they should no longer work. Connector subscription changes are separate from credential disconnection.
Troubleshooting
| Symptom | Likely cause | What to do |
|---|---|---|
| Save is rejected with a domain-resolution error | The Azure domain couldn't be looked up (typo, or not a valid Microsoft domain) | Re-check the domain, or enter the tenant ID (GUID) directly instead |
| Save asks for an Azure tenant you don't have | The form is on Entra app registration | Choose Personal access token on the Configure form; that method asks only for the token and the instance URL |
| The drawer shows Needs Attention after saving (Entra) | Wrong tenant/URL, mis-typed Client ID or secret, or the Enterprise application is not mapped to an ImmyBot admin user | Re-check the four values; then verify Enterprise Apps → Object ID matches the ImmyBot person's AD External ID, the person has a user, and that user is Admin |
| The drawer shows Needs Attention after saving (token) | Mis-pasted token, wrong instance URL, or the token was revoked or has expired | Re-copy the token in ImmyBot (the value is shown only at creation, so create a new one if you no longer have it), confirm the instance URL, save and Re-test |
| Tools worked, then started failing | The client secret was rotated, removed, or expired in Entra — or the personal access token was revoked or reached its expiry date | Update the credential in Connectors → ImmyBot → Configure with the current secret or a new token |
| Permission errors that come and go for no obvious reason | The Entra application's sign-in step is not resolving to a known ImmyBot user reliably | Switch to a personal access token, which is tied to an ImmyBot user directly |
| One tool returns a permissions error while others succeed | The mapped ImmyBot user (Entra) or the token's owning user cannot perform that operation | For Entra, verify the Enterprise app Object ID mapping and the user's Admin setting; for a token, re-create it as a user with the access you need |
| Write or action tools missing from your AI's tool list | Connector is on the Free tier, or the tools aren't selected for your client | Upgrade the ImmyBot connector plan and check your tool selections on the MCP Setup page |
| A spreadsheet export link no longer works | The 15-minute read-only link expired | Re-run the export tool to get a fresh link |
ImmyBot tools
immy_ · 555 tools · Free 264 · Pro 291
Computers
| Tool | What it does |
|---|---|
immy_Pro · Write | Add one or more tags to a set of computers (bulk). |
immy_Pro · Destructive | Permanently delete multiple computers (bulk). |
immy_Pro · Write | Move one or more computers to a different tenant. |
immy_Pro · Write | Exclude a computer from maintenance (it will be skipped by maintenance sessions). |
immy_Pro · Write | Set/update the notes on a computer. |
immy_Pro · Write | Trigger a reinventory of a computer (re-collect its software/inventory data). |
immy_Pro · Write | Restore previously (soft-)deleted computers. |
immy_Pro · Write | Flag a computer as needing onboarding (re-enters the onboarding pipeline). |
immy_Pro · Write | Mark computers to skip onboarding. |
immy_Pro · Write | Update the additional (secondary) persons associated with a computer. |
immy_Pro · Write | Update the primary person associated with a computer (its main user). |
immy_Free · Read-only | Get a single computer by id, including its default detail (sessions, primary/additional persons and provider-agent data as ImmyBot resolves them). |
immy_Free · Read-only | List managed computers (basic view). |
immy_Free · Read-only | List computers with their agent connectivity/health status (DevExtreme grid feed). |
immy_Free · Read-only | Get the device-update form data for a computer (the fields/options used to drive a device update). |
immy_Free · Read-only | List computers via the raw DevExtreme grid feed. |
immy_Free · Read-only | List the event history for a computer. |
immy_Free · Read-only | Export the computers grid to an XLSX spreadsheet. |
immy_Free · Read-only | List the computers scoped to the calling identity/session. |
immy_Free · Read-only | List computers currently in the onboarding pipeline (awaiting or undergoing onboarding). |
immy_Free · Read-only | List computers with DevExtreme server-side paging, filtering and sorting — the richer counterpart to immy_list_computers. |
immy_Free · Read-only | Get the parent-tenant information for a computer (the tenant hierarchy context the computer belongs to). |
immy_Free · Read-only | Get the current status of a single computer (online/agent/maintenance state). |
immy_Pro · Write | Remove one or more tags from a set of computers (bulk). |
immy_Free · Read-only | Resolve the onboarding target-assignments (deployments) that can be overridden for a computer — a preview used before onboarding. |
immy_Pro · Write | Update a computer (PUT). |
Computer Inventory
| Tool | What it does |
|---|---|
immy_Pro · Write | Exclude a single computer from user-affinity tracking. |
immy_Pro · Write | Bulk set whether a set of computers are excluded from user-affinity tracking. |
immy_Free · Read-only | Get the results of a specific inventory script for a computer, keyed by inventoryKey. |
immy_Free · Read-only | List the detected (installed) software for a single computer. |
immy_Free · Read-only | List the collected computer inventory (DevExtreme grid feed). |
immy_Free · Read-only | Export the computer-inventory grid to an XLSX spreadsheet. |
immy_Free · Read-only | Search the software inventory across computers by (partial) product name. |
immy_Free · Read-only | Search the software inventory across computers by MSI upgrade code. |
immy_Free · Read-only | List computer↔user affinities (which persons are associated with which computers, inferred from usage). |
immy_Free · Read-only | Export the computer user-affinity grid to an XLSX spreadsheet. |
Computer Agents
| Tool | What it does |
|---|---|
immy_Pro · Write | Reset the ephemeral-agent circuit breaker for a computer (clears the tripped state so agent launches are retried). |
immy_Free · Read-only | Enumerate the registry sub-keys under a supplied path on a computer (read-only; POST is used to carry the query path). |
immy_Free · Read-only | Read the registry values under a supplied key on a computer (read-only; POST is used to carry the query key). |
immy_Pro · Destructive | End (terminate) the live ephemeral-agent session on a computer. |
immy_Pro · Destructive | Launch a short-lived ephemeral agent on a computer (an ACTION despite the GET verb — it establishes a live agent session, so it is NOT read-only). |
immy_Free · Read-only | Get the current ephemeral-agent state for a computer (whether a short-lived agent session is active and its details). |
immy_Free · Read-only | Get the ephemeral-agent circuit-breaker state for a computer (whether repeated agent-launch failures have tripped the breaker). |
immy_Free · Read-only | Get the provider-link screen-share (remote-control) URL for a computer through a specific provider integration. |
Software
| Tool | What it does |
|---|---|
immy_Pro · Destructive | Delete a global software item by softwareIdentifier, including all its versions. |
immy_Pro · Destructive | Delete a local software item by softwareIdentifier, including all its versions. |
immy_Free · Read-only | Get a single global software item by softwareIdentifier (from immy_list_software_global). |
immy_Free · Read-only | Get a single local software item by softwareIdentifier (from immy_list_software_local). |
immy_Free · Read-only | List global (shared/vendor-maintained) software items, optionally filtered with a Sieve `filters` expression. |
immy_Free · Read-only | Get the latest version of a global software item by softwareIdentifier (from immy_list_software_global). |
immy_Free · Read-only | List local (instance-authored) software items, optionally filtered with a Sieve `filters` expression. |
immy_Free · Read-only | Get the authorization (tenant/scope access) configuration for a local software item by softwareIdentifier. |
immy_Free · Read-only | Get the latest version of a local software item by softwareIdentifier (from immy_list_software_local). |
immy_Free · Read-only | Preview (what-if) migrating a local software item to the global catalog by softwareIdentifier — reports what would change WITHOUT migrating. |
immy_Pro · Write | Partially update a global software item by softwareIdentifier. |
immy_Pro · Write | Partially update a local software item by softwareIdentifier. |
immy_Pro · Write | Create a global software item. |
immy_Free · Read-only | Analyze a global software definition WITHOUT saving it — a read-only preview that returns detection/install evaluation for the supplied definition. |
immy_Pro · Write | Fast-create a global software item from a minimal definition (ImmyBot infers install/detection defaults). |
immy_Pro · Write | Upload an installer binary for global software (multipart/form-data). |
immy_Pro · Write | Create a local (instance-authored) software item. |
immy_Free · Read-only | Analyze a local software definition WITHOUT saving it — a read-only preview returning detection/install evaluation for the supplied definition. |
immy_Pro · Write | Set the authorization (tenant/scope access) for a local software item by softwareIdentifier. |
immy_Pro · Write | Fast-create a local software item from a minimal definition (ImmyBot infers install/detection defaults). |
immy_Pro · Write | Migrate a local software item to the global catalog by softwareIdentifier, making it shared across the instance. |
immy_Pro · Write | Upload an installer binary for local software (multipart/form-data). |
Software Versions
| Tool | What it does |
|---|---|
immy_Pro · Write | Add a new version to a global software item (softwareIdentifier from immy_list_software_global). |
immy_Pro · Write | Add a new version to a local software item (softwareIdentifier from immy_list_software_local). |
immy_Pro · Destructive | Delete a version from a global software item (softwareIdentifier + semanticVersion). |
immy_Pro · Destructive | Delete a version from a local software item (softwareIdentifier + semanticVersion). |
immy_Free · Read-only | Get a single global software version by softwareIdentifier + semanticVersion (both from immy_list_software_global_versions). |
immy_Free · Read-only | Get a single local software version by softwareIdentifier + semanticVersion (both from immy_list_software_local_versions). |
immy_Free · Read-only | List the versions of a global (shared/vendor) software item by its softwareIdentifier (from immy_list_software_global / immy_get_software_global). |
immy_Free · Read-only | Request a download URL for a global software version's install payload by softwareIdentifier + semanticVersion. |
immy_Free · Read-only | List the versions of a local (per-instance) software item by its softwareIdentifier (from immy_list_software_local / immy_get_software_local). |
immy_Free · Read-only | Request a download URL for a local software version's install payload by softwareIdentifier + semanticVersion. |
immy_Pro · Write | Partially update a global software version (softwareIdentifier + semanticVersion). |
immy_Pro · Write | Partially update a local software version (softwareIdentifier + semanticVersion). |
Licenses
| Tool | What it does |
|---|---|
immy_Pro · Destructive | Delete a software license by id (from immy_list_licenses). |
immy_Free · Read-only | Get a single software license by id (from immy_list_licenses). |
immy_Pro · Write | Create a software license. |
immy_Pro · Write | Upload a license file (multipart/form-data). |
immy_Free · Read-only | Look up Chocolatey community-feed packages by exact package id (e.g. "googlechrome", "7zip"). |
immy_Free · Read-only | Fuzzy-search the Chocolatey community feed by term (matches package id/title). |
immy_Free · Read-only | List software licenses, optionally filtered with a Sieve `filters` expression (e.g. "name@=Adobe"). |
immy_Free · Read-only | DevExtreme grid feed for the licenses table (skip/take paging plus DevExtreme filter/sort). |
immy_Free · Read-only | Request a download URL for a license's uploaded file by license id (from immy_list_licenses). |
immy_Pro · Destructive | Update (full replace) a software license by id (from immy_list_licenses). |
Script Catalog & Functions
| Tool | What it does |
|---|---|
immy_Free · Read-only | List the metascript catalog with full descriptions — the reusable ImmyBot metascript building blocks available to compose scripts and maintenance tasks. |
immy_Free · Read-only | Search the metascript catalog by keyword. |
immy_Free · Read-only | List the PowerShell/metascript functions exposed to scripts (the built-in function library scripts can call). |
immy_Free · Read-only | Get the language/analysis state for an active script language-service terminal. |
immy_Free · Read-only | Analyze the syntax of a script function (read-only static analysis — a POST that inspects, not a write). |
immy_Pro · Write | Start a script language-service session (editor/analysis backend), returning a terminalId used by immy_list_scripts_language_service_language. |
Script Execution
| Tool | What it does |
|---|---|
immy_Pro · Destructive | Cancel an in-progress debug script run identified by cancellationId. |
immy_Free · Read-only | List the preflight scripts currently disabled (preflight scripts run before maintenance to decide applicability). |
immy_Free · Read-only | Resolve the default variables ImmyBot would supply for a script (a POST that computes/reads defaults — it does not run the script or change state). |
immy_Free · Read-only | Inspect a script and report whether it declares a PowerShell param() block (read-only static analysis via POST). |
immy_Pro · Destructive | Execute a script against target computers/tenants. |
immy_Pro · Destructive | Execute an ad-hoc metascript (inline PowerShell/metascript code, not a saved script) against targets. |
immy_Pro · Write | Enable or disable a preflight script. |
immy_Free · Read-only | Static syntax check of a script (a POST that parses and returns diagnostics — it does not run the script). |
immy_Free · Read-only | Validate a set of parameters against a script's param() block (read-only validation via POST — it checks, it does not persist anything). |
Scripts
| Tool | What it does |
|---|---|
immy_Pro · Write | Create a new global script (shared platform-wide). |
immy_Pro · Write | Create a new local script (tenant-scoped). |
immy_Pro · Destructive | Permanently delete a global script. |
immy_Pro · Destructive | Permanently delete a local script. |
immy_Free · Read-only | Get a single global script by id, including its script text (action) and settings. |
immy_Free · Read-only | Get a single local script by id, including its script text (action) and settings. |
immy_Free · Read-only | List scripts via the DevExtreme grid feed (the data source behind the ImmyBot scripts grid). |
immy_Free · Read-only | List global scripts (shared platform-wide). |
immy_Free · Read-only | List the audit history (change events) for a global script. |
immy_Free · Read-only | List rolled-up audit summaries for a global script (aggregated change events). |
immy_Free · Read-only | List just the id+name pairs of global scripts (a lightweight pick-list for referencing scripts). |
immy_Free · Read-only | List the entities (maintenance tasks, deployments, etc.) that reference a global script. |
immy_Free · Read-only | List local scripts (tenant-scoped). |
immy_Free · Read-only | List the audit history (change events) for a local script. |
immy_Free · Read-only | List rolled-up audit summaries for a local script (aggregated change events). |
immy_Free · Read-only | Get the authorization (who may view/run/edit) for a local script. |
immy_Free · Read-only | Preview what would happen if a local script were migrated to a global script (a read-only what-if — nothing is migrated). |
immy_Free · Read-only | List just the id+name pairs of local scripts (a lightweight tenant-scoped pick-list). |
immy_Free · Read-only | List the entities that reference a local script. |
immy_Free · Read-only | Get the reference counts for scripts (how many maintenance tasks/deployments reference each script). |
immy_Free · Read-only | Search across scripts (global + local) by keyword. |
immy_Pro · Write | Duplicate an existing script into a new script. |
immy_Pro · Write | Set the authorization (who may view/run/edit) for a local script. |
immy_Pro · Write | Migrate a local (tenant-scoped) script to a global (platform-wide) script. |
immy_Pro · Write | Update an existing global script (POST-based update, not a PATCH). |
immy_Pro · Write | Update an existing local script (POST-based update, not a PATCH). |
Deployments
| Tool | What it does |
|---|---|
immy_Pro · Destructive | Permanently delete a deployment (target assignment) by its id (from immy_list_target_assignments). |
immy_Pro · Destructive | Permanently delete a global (cross-tenant) deployment by its id (from immy_list_target_assignments_global). |
immy_Free · Read-only | Get the optional (opt-in) deployment approvals available for a specific computer, by computerId (from immy_list_computers). |
immy_Free · Read-only | Get a single deployment (target assignment) by its id (from immy_list_target_assignments). |
immy_Free · Read-only | Get a single global (cross-tenant) deployment by its id (from immy_list_target_assignments_global). |
immy_Free · Read-only | List deployments (target assignments) across the ImmyBot instance. |
immy_Free · Read-only | List global (cross-tenant) deployments — target assignments that apply across every tenant rather than to a single one. |
immy_Free · Read-only | Get the maintenance-item type (software / maintenance task / script) of a global deployment by its id (from immy_list_target_assignments_global). |
immy_Free · Read-only | List the ordering of maintenance items as resolved by deployments — the sequence in which items run during maintenance. |
immy_Free · Read-only | List recommended deployment approvals — deployments ImmyBot recommends approving based on current state. |
immy_Free · Read-only | Get the maintenance-item type (software / maintenance task / script) of a deployment by its id (from immy_list_target_assignments). |
immy_Pro · Write | Batch-update multiple deployments in one call. |
immy_Free · Read-only | Preview (what-if, no changes made) migrating deployments onto a superseding target assignment — shows what would happen without applying it. |
immy_Pro · Write | Create a new deployment (target assignment). |
immy_Pro · Write | Duplicate a single deployment (target assignment) into a new one. |
immy_Pro · Write | Duplicate multiple deployments (target assignments) in one call. |
immy_Pro · Write | Create a new global (cross-tenant) deployment. |
immy_Pro · Write | Set or update the notes on a global (cross-tenant) deployment by its id (from immy_list_target_assignments_global). |
immy_Pro · Write | Apply an override to a global (cross-tenant) deployment by its id (from immy_list_target_assignments_global). |
immy_Pro · Write | Migrate deployments so their targeting is driven by provider-link (RMM/PSA integration) data instead of legacy targeting. |
immy_Pro · Write | Migrate deployments onto a superseding target assignment (applies the change). |
immy_Pro · Write | Set or update the notes on a deployment (target assignment) by its id (from immy_list_target_assignments). |
immy_Pro · Write | Approve (opt in) an optional deployment for a target, by the optional-approval id. |
immy_Pro · Write | Apply an override to a deployment (target assignment) by its id (from immy_list_target_assignments). |
immy_Free · Read-only | Preview which persons a deployment target would resolve to (no changes made). |
immy_Pro · Write | Apply recommended deployment approvals. |
immy_Free · Read-only | Preview which computers a deployment target would resolve to (no changes made). |
immy_Free · Read-only | Preview which tenants a deployment target would resolve to (no changes made). |
immy_Pro · Write | Update the run order of maintenance items resolved by deployments. |
immy_Pro · Write | Set the visibility of deployments (e.g. hide/show in tenant-facing views). |
immy_Pro · Write | Update (replace) a deployment (target assignment) by its id (from immy_list_target_assignments). |
immy_Pro · Write | Update (replace) a global (cross-tenant) deployment by its id (from immy_list_target_assignments_global). |
Deployment Change Requests
| Tool | What it does |
|---|---|
immy_Pro · Write | Apply a deployment change request by its changeRequestId (from immy_list_target_assignment_change_requests) — commits the proposed deployment edits. |
immy_Pro · Write | Create an instance-wide deployment change request — a reviewable proposal of deployment edits. |
immy_Pro · Write | Create a change request scoped to a single deployment, by deploymentId (from immy_list_target_assignments). |
immy_Free · Read-only | Get a single deployment change request by its changeRequestId (from immy_list_target_assignment_change_requests). |
immy_Free · Read-only | List the change requests scoped to a single deployment, by deploymentId (from immy_list_target_assignments). |
immy_Free · Read-only | List deployment change requests across the instance. |
immy_Free · Read-only | Get the diff of a deployment change request by its changeRequestId (from immy_list_target_assignment_change_requests) — the before/after of what applying it would change. |
immy_Pro · Write | Update an existing change request scoped to a deployment, by deploymentId and changeRequestId (both from immy_list_deployment_change_requests). |
Maintenance Actions
| Tool | What it does |
|---|---|
immy_Free · Read-only | DevExtreme grid feed of maintenance actions scoped to a single computer. |
immy_Free · Read-only | Get the latest maintenance actions for a single computer (from immy_list_computers). |
immy_Free · Read-only | Get the latest maintenance actions for a single tenant (from immy_list_tenants). |
immy_Free · Read-only | Get the latest non-compliant maintenance actions (action still required) for a single tenant (from immy_list_tenants). |
immy_Free · Read-only | List the maintenance actions on one computer that currently need attention (non-compliant / action required). |
immy_Free · Read-only | DevExtreme grid feed of maintenance actions across the instance. |
immy_Free · Read-only | List the execution logs for a single maintenance action. |
immy_Free · Read-only | List maintenance actions grouped/filtered by maintenance item (software or task). |
immy_Free · Read-only | Get the maintenance-actions version/metadata record used by the ImmyBot UI grid. |
immy_Free · Read-only | Look up the latest maintenance action for a set of computers for one software item or maintenance task. |
immy_Free · Read-only | Look up the latest maintenance action for a set of tenants for one software item or maintenance task. |
Maintenance Sessions
| Tool | What it does |
|---|---|
immy_Pro · Destructive | Cancel ALL currently-running maintenance sessions across the instance. |
immy_Pro · Destructive | Cancel a single maintenance session by sessionId. |
immy_Pro · Destructive | Cancel a specific set of running maintenance sessions. |
immy_Pro · Destructive | Cancel all maintenance sessions that were started by a given schedule. |
immy_Free · Read-only | Get a single maintenance session by sessionId (from immy_list_maintenance_sessions_dx), including its status, target, and actions. |
immy_Free · Read-only | DevExtreme grid feed of maintenance sessions across the instance. |
immy_Free · Read-only | Get the most recent log line for a maintenance session by sessionId — a lightweight way to poll live progress. |
immy_Free · Read-only | List the full log stream for a maintenance session by sessionId. |
immy_Free · Read-only | List the archived/old log stream for a maintenance session by sessionId (the pre-rollover logs not returned by immy_list_maintenance_sessions_logs). |
immy_Free · Read-only | List the phases (detection, resolution, follow-up, etc.) of a maintenance session by sessionId, with each phase's status and timing. |
immy_Free · Read-only | Get the count of maintenance sessions in each status (e.g. running, completed, cancelled, failed). |
immy_Pro · Destructive | Re-run a single action within a maintenance session (re-executes just that one maintenance action). |
immy_Pro · Destructive | Resume a paused/waiting maintenance session by sessionId (e.g. one that stalled awaiting a reboot or user response). |
immy_Pro · Destructive | Re-run a single maintenance session by sessionId (re-executes maintenance against its original target). |
immy_Pro · Destructive | Re-run a set of maintenance sessions (re-executes maintenance against their original targets). |
immy_Pro · Destructive | Enqueue one or more maintenance sessions and SYNCHRONOUSLY return the started session IDs. |
immy_Pro · Destructive | Enqueue one or more maintenance sessions in the BACKGROUND and return immediately (202 Accepted) without waiting for the session IDs. |
Maintenance Tasks
| Tool | What it does |
|---|---|
immy_Pro · Write | Create a new GLOBAL (cross-tenant) maintenance task. |
immy_Pro · Write | Create a new LOCAL (tenant-scoped) maintenance task. |
immy_Pro · Destructive | Permanently delete the global maintenance task identified by id — this cannot be undone and every deployment/target-assignment referencing it will lose that task. |
immy_Pro · Destructive | Permanently delete the local maintenance task identified by id — this cannot be undone and any deployment referencing it will lose that task. |
immy_Free · Read-only | Get a single global maintenance task by id, including its script/metascript body and parameter definitions. |
immy_Free · Read-only | Get a single local maintenance task by id, including its script/metascript body and parameter definitions. |
immy_Free · Read-only | Get the authorization/access configuration for the maintenance task identified by id (which tenants/roles may see or run it). |
immy_Free · Read-only | List global (cross-tenant) maintenance tasks. |
immy_Free · Read-only | List local (tenant-scoped) maintenance tasks. |
immy_Free · Read-only | Return the count of references to maintenance tasks (how many deployments/other objects point at each task) — used to gauge blast radius before editing or deleting a task. |
immy_Free · Read-only | Search across both global and local maintenance tasks. |
immy_Free · Read-only | Preview (dry-run) what promoting the local maintenance task identified by id to a global task would do — surfaces conflicts, references, and the resulting shape without making any change. |
immy_Pro · Write | Set the authorization/access configuration for the maintenance task identified by id (which tenants/roles may see or run it). |
immy_Pro · Write | Duplicate an existing maintenance task, creating an editable copy. |
immy_Free · Read-only | Generate the PowerShell param() block text for the global maintenance task identified by id from a set of parameter definitions. |
immy_Pro · Write | Promote the local maintenance task identified by id to a GLOBAL (cross-tenant) task, making it available to all tenants. |
immy_Free · Read-only | Generate the PowerShell param() block text for the local maintenance task identified by id from a set of parameter definitions. |
immy_Free · Read-only | Validate a set of param-block parameter definitions for a maintenance task — checks types, required-ness, and default consistency and returns validation results. |
immy_Pro · Destructive | Update the global maintenance task identified by id. |
immy_Pro · Destructive | Update the local maintenance task identified by id. |
Inventory Tasks
| Tool | What it does |
|---|---|
immy_Pro · Write | Create a new LOCAL (tenant-authored) inventory task. |
immy_Pro · Destructive | Permanently delete the local inventory task identified by id, along with its collection scripts — this cannot be undone and any detection/deployment logic referencing its inventory keys will lose that data source. |
immy_Pro · Destructive | Permanently remove a single collection script (identified by inventoryKey) from the local inventory task identified by taskId — this cannot be undone. |
immy_Pro · Write | Add or update a collection script on the local inventory task identified by id. |
immy_Free · Read-only | List all inventory tasks (global vendor + local tenant-authored) that collect custom inventory data from managed computers. |
immy_Pro · Destructive | Update the local inventory task identified by id. |
Tags
| Tool | What it does |
|---|---|
immy_Pro · Write | Create a tag. |
immy_Pro · Destructive | Permanently delete a tag by id (from immy_list_tags). |
immy_Free · Read-only | Get a single tag by id (from immy_list_tags). |
immy_Free · Read-only | List tags defined in the ImmyBot instance. |
immy_Free · Read-only | Get the authorization (RBAC) settings for a tag by id (from immy_list_tags) — which roles/groups may act on resources carrying this tag. |
immy_Pro · Write | Set the authorization (RBAC) settings for a tag by id (from immy_list_tags) — which roles/groups may act on resources carrying this tag. |
immy_Pro · Write | Update a tag by id (from immy_list_tags). |
Tenants
| Tool | What it does |
|---|---|
immy_Pro · Write | Add one or more tags to one or more tenants. |
immy_Free · Read-only | Get a single tenant by id (from immy_list_tenants). |
immy_Free · Read-only | Get a single Azure (Entra) group for a tenant by tenant id (from immy_list_tenants) and group id (from immy_list_tenants_azure_groups). |
immy_Free · Read-only | Get a single software-from-inventory record by id (from immy_list_tenants_software_from_inventory_dx). |
immy_Free · Read-only | List the tenants (managed customer organizations) in the ImmyBot instance. |
immy_Free · Read-only | List the Azure (Entra) groups for a tenant by tenant id (from immy_list_tenants). |
immy_Free · Read-only | List tenants with their managed-computer counts. |
immy_Free · Read-only | List a tenant's computers that are excluded from maintenance, by tenant id (from immy_list_tenants). |
immy_Free · Read-only | List tenants that are excluded from cross-tenant (global) deployments. |
immy_Free · Read-only | List software discovered across tenants from inventory, as a DevExtreme grid feed. |
immy_Free · Read-only | Export the cross-tenant software-from-inventory report as an XLSX spreadsheet. |
immy_Pro · Write | Activate a tenant by id (from immy_list_tenants). |
immy_Pro · Write | Deactivate a tenant by id (from immy_list_tenants). |
immy_Pro · Write | Remove one or more tags from one or more tenants. |
immy_Pro · Write | Create a tenant (managed customer organization). |
immy_Pro · Write | Create multiple tenants in one call. |
immy_Pro · Destructive | Permanently delete multiple tenants in one call — irreversible. |
immy_Pro · Destructive | Merge tenants together — consolidates source tenants into a target and removes the sources; irreversible. |
immy_Pro · Write | Remove the parent-tenant link from one or more tenants, flattening them out of a parent/child hierarchy. |
immy_Free · Read-only | Resolve which tenants a given maintenance item's deployments apply to (a read-only what-resolves query, sent as an HTTP POST). |
immy_Pro · Write | Set the parent-tenant link on one or more tenants, placing them under a parent in the tenant hierarchy. |
immy_Pro · Write | Link (or update the link for) an ImmyBot tenant to a Microsoft Azure (Entra) tenant, enabling Azure-group inspection (immy_list_tenants_azure_groups) and Azure-scoped automation. |
immy_Pro · Write | Update a tenant by id (from immy_list_tenants). |
Provider Links
| Tool | What it does |
|---|---|
immy_Pro · Destructive | Permanently delete a provider link by its id (from immy_list_provider_links). |
immy_Free · Read-only | Get a single provider link by its id (from immy_list_provider_links). |
immy_Free · Read-only | Get a single ticket from the PSA provider behind a provider link (from immy_list_provider_links), identified by the provider's ticket id. |
immy_Free · Read-only | Get a single RMM link by its id (from immy_list_rmm_links) — the RMM-scoped view of a provider link. |
immy_Pro · Write | Request a rekey of an ImmyBot agent installer (rotate the agent's key material for re-enrollment). |
immy_Free · Read-only | List the provider links (integrations to external RMM / PSA / documentation providers) configured in this ImmyBot instance. |
immy_Free · Read-only | List the audit-log entries for a provider link (from immy_list_provider_links) — configuration changes, sync events, and errors over time. |
immy_Free · Read-only | List sample values for the ImmyBot-side fields available when configuring asset field mappings on a provider link (from immy_list_provider_links). |
immy_Free · Read-only | List provider links that still have external clients not yet mapped to an ImmyBot tenant. |
immy_Free · Read-only | List provider links filtered to the RMM-capable providers only (a filtered alias view over immy_list_provider_links). |
immy_Free · Read-only | Open-world proxy: forward a GET request to a provider plugin's own API under the given provider link (from immy_list_provider_links). |
immy_Pro · Destructive | Open-world proxy: forward a POST request to a provider plugin's own API under the given provider link (from immy_list_provider_links). |
immy_Pro · Write | Create a provider link (a new integration to an external RMM / PSA / documentation provider). |
immy_Pro · Write | Create a provider link from an existing external provider reference (e.g. an Azure/partner reference already known to ImmyBot). |
immy_Pro · Write | Reload a provider link by its id (from immy_list_provider_links) — reinitialize the plugin/integration and refresh its cached state. |
immy_Pro · Write | Verify that an external provider reference resolves and can back a provider link, WITHOUT creating anything. |
immy_Pro · Write | Create an RMM provider link (the RMM-scoped create path; a provider link whose provider is an RMM). |
immy_Pro · Destructive | Update a provider link by its id (from immy_list_provider_links). |
immy_Pro · Destructive | Update an RMM link by its id (from immy_list_rmm_links). |
Provider Link Assets
| Tool | What it does |
|---|---|
immy_Pro · Destructive | Permanently delete an asset field mapping from a provider link. |
immy_Pro · Destructive | Permanently delete an asset match field from a provider link. |
immy_Free · Read-only | List the asset field mappings configured on a provider link (from immy_list_provider_links) — each mapping ties an external provider field to an ImmyBot field. |
immy_Free · Read-only | List the external asset fields exposed by the provider behind a provider link (from immy_list_provider_links) — the source side of an asset field mapping. |
immy_Free · Read-only | List sample values for a single external asset field on a provider link — helps you preview what data a field carries before mapping it. |
immy_Free · Read-only | List the asset match fields configured on a provider link (from immy_list_provider_links) — the fields used to match external assets to ImmyBot computers during sync. |
immy_Free · Read-only | List the recommended asset match fields for a provider link (from immy_list_provider_links) — ImmyBot's suggested matchers based on the provider's field schema. |
immy_Free · Read-only | List the synced assets for a provider link (from immy_list_provider_links) as a DevExtreme grid feed. |
immy_Free · Read-only | Get the current asset-sync job state for a provider link (from immy_list_provider_links) — whether a sync is running, queued, or idle, plus progress/last-result metadata. |
immy_Free · Read-only | Get the asset-sync schedule for a provider link (from immy_list_provider_links) — the cadence at which ImmyBot re-syncs assets from the external provider. |
immy_Free · Read-only | Get the external provider URL for a single synced asset — the deep link into the provider's UI for that asset. |
immy_Pro · Write | Create an asset field mapping on a provider link (from immy_list_provider_links) — tie one external provider field to one ImmyBot field. |
immy_Pro · Write | Create an asset match field on a provider link (from immy_list_provider_links) — a field used to match external assets to ImmyBot computers during sync. |
immy_Pro · Write | Trigger an on-demand asset sync for a provider link (from immy_list_provider_links) — pull the latest assets from the external provider now instead of waiting for the schedule. |
immy_Pro · Destructive | Update an existing asset field mapping on a provider link. |
immy_Pro · Destructive | Update an existing asset match field on a provider link. |
Provider Agents
| Tool | What it does |
|---|---|
immy_Free · Read-only | List the identification logs for a single provider agent, by agentId (from immy_list_provider_agents_pending). |
immy_Free · Read-only | List provider agents that are pending identification — agents discovered through a provider link (RMM/PSA integration) that ImmyBot has not yet matched to a managed computer/tenant. |
immy_Free · Read-only | List the pending provider-agent conflicts for a specific computer, by computerId (from immy_list_computers). |
immy_Free · Read-only | Get the count of provider agents pending identification, broken down (e.g. per provider link). |
immy_Pro · Destructive | Permanently delete a set of pending (unidentified) provider agents in one call. |
immy_Pro · Write | Identify one or more pending provider agents — match each discovered agent to a managed computer/tenant so ImmyBot can manage it. |
immy_Pro · Write | Resolve a single provider-agent identification failure, by failureId. |
immy_Pro · Write | Resolve all identification failures for one provider agent, by agentId (from immy_list_provider_agents_pending). |
immy_Pro · Write | Resolve provider-agent identification failures in bulk. |
Provider Clients & Agents
| Tool | What it does |
|---|---|
immy_Pro · Destructive | Permanently delete a provider-link cross-reference, by provider-link id (from immy_list_provider_links) and externalLinkId. |
immy_Free · Read-only | List the external clients a provider link exposes, by provider-link id (from immy_list_provider_links, S8). |
immy_Free · Read-only | List the linking status of each client on a provider link, by provider-link id (from immy_list_provider_links). |
immy_Free · Read-only | List the client types a provider link supports, by provider-link id (from immy_list_provider_links). |
immy_Pro · Write | Generate a PowerShell (Windows) install script for the provider link's agent that also triggers ImmyBot onboarding on first run, by provider-link id (from immy_list_provider_links). |
immy_Pro · Write | Get a download URI for a Windows provisioning-package (.ppkg) installer for the provider link's agent that also triggers ImmyBot onboarding on first run, by provider-link id (from immy_list_provider_links). |
immy_Pro · Write | Generate a bash (macOS/Linux) install script for the provider link's agent, by provider-link id (from immy_list_provider_links). |
immy_Pro · Write | Generate a bash (macOS/Linux) install script for the provider link's agent that also triggers ImmyBot onboarding on first run, by provider-link id (from immy_list_provider_links). |
immy_Pro · Destructive | Permanently remove an offline provider agent from a computer, by provider-link id (from immy_list_provider_links) and agentId. |
immy_Pro · Write | Get a download URI for the provider link's agent executable installer, by provider-link id (from immy_list_provider_links). |
immy_Pro · Write | Get a download URI for the provider link's agent executable installer that also triggers ImmyBot onboarding on first run, by provider-link id (from immy_list_provider_links). |
immy_Pro · Write | Get the external RMM/PSA console URL for a computer's agent, by provider-link id (from immy_list_provider_links) and computerId (from immy_list_computers). |
immy_Pro · Destructive | Install the provider link's agent directly onto a specific managed computer, by provider-link id (from immy_list_provider_links) and computerId (from immy_list_computers). |
immy_Pro · Write | Generate a PowerShell (Windows) install script for the provider link's agent, by provider-link id (from immy_list_provider_links). |
immy_Pro · Write | Get a download URI for a Windows provisioning-package (.ppkg) installer for the provider link's agent, by provider-link id (from immy_list_provider_links). |
immy_Pro · Write | Refresh the online/offline status of a provider agent's device, by provider-link id (from immy_list_provider_links) and agentId. |
immy_Pro · Write | Trigger a sync of the provider link's agents, by provider-link id (from immy_list_provider_links). |
immy_Pro · Write | Automatically link a provider link's external clients to ImmyBot tenants using ImmyBot's matching heuristics, by provider-link id (from immy_list_provider_links). |
immy_Pro · Write | Link only the provider clients whose names exactly match an existing ImmyBot tenant, by provider-link id (from immy_list_provider_links). |
immy_Pro · Write | Create a new ImmyBot tenant and link a provider client to it in one step, by provider-link id (from immy_list_provider_links). |
immy_Pro · Write | Link a provider client to a specific existing ImmyBot tenant, by provider-link id (from immy_list_provider_links). |
immy_Pro · Write | Trigger a sync of the provider link's clients, by provider-link id (from immy_list_provider_links). |
immy_Pro · Write | Sync the agents belonging to the provider link's linked clients, by provider-link id (from immy_list_provider_links). |
immy_Pro · Write | Unlink provider clients from their ImmyBot tenants, by provider-link id (from immy_list_provider_links). |
immy_Pro · Write | Create a cross-reference on a provider link — an external link that ties another provider/system's records to this provider link, by provider-link id (from immy_list_provider_links). |
immy_Pro · Write | Disable client linking for a provider-link cross-reference, by provider-link id (from immy_list_provider_links) and externalLinkId. |
immy_Pro · Write | Enable client linking for a provider-link cross-reference, by provider-link id (from immy_list_provider_links) and externalLinkId. |
immy_Pro · Write | Sync the clients associated with a provider-link cross-reference, by provider-link id (from immy_list_provider_links) and externalLinkId. |
Provider Types
| Tool | What it does |
|---|---|
immy_Free · Read-only | Get the option set for a provider-type configuration-form dropdown, by its key. |
immy_Free · Read-only | List the available provider types — the kinds of external RMM/PSA integration a provider link can be created against (e.g. the supported vendor integrations). |
immy_Free · Read-only | List the client groups available for a given client-group-type, by clientGroupTypeId (from immy_list_provider_types metadata). |
immy_Free · Read-only | List the device groups available for a given device-group-type, by deviceGroupTypeId (from immy_list_provider_types metadata). |
immy_Free · Read-only | Preview how a set of configuration parameters binds for a given provider type, by providerType. |
Personal Access Tokens
| Tool | What it does |
|---|---|
immy_Pro · Destructive | Permanently revoke the personal access token identified by id (from immy_list_personal_access_tokens / immy_list_personal_access_tokens_all). |
immy_Free · Read-only | List the personal access tokens (PATs) belonging to the current user. |
immy_Free · Read-only | List ALL personal access tokens across every user in the instance (administrator view) — use this to audit outstanding API tokens. |
immy_Pro · Write | Create a new personal access token (PAT). |
Persons
| Tool | What it does |
|---|---|
immy_Pro · Write | Add one or more tags to one or more persons in bulk. |
immy_Pro · Destructive | Permanently delete the person identified by id (from immy_list_persons). |
immy_Free · Read-only | Get a single person by id (from immy_list_persons). |
immy_Free · Read-only | List persons (managed end-users) known to the ImmyBot instance. |
immy_Free · Read-only | List the software detected across the computers associated with the person identified by personId (from immy_list_persons). |
immy_Free · Read-only | List persons via the DevExtreme grid feed (the shape the ImmyBot UI person grid consumes). |
immy_Free · Read-only | List persons who have requested self-service portal access and are awaiting a decision. |
immy_Free · Read-only | Get the self-service view for the person identified by id (from immy_list_persons) — the software and actions this person is entitled to run themselves through the ImmyBot self-service portal. |
immy_Pro · Write | Create a person (managed end-user). |
immy_Pro · Write | Deny or revoke self-service portal access for the person identified by personId (from immy_list_persons / immy_list_persons_requesting_access). |
immy_Pro · Write | Grant self-service portal access to the person identified by personId (from immy_list_persons / immy_list_persons_requesting_access). |
immy_Pro · Write | Remove one or more tags from one or more persons in bulk. |
immy_Pro · Destructive | Update the person identified by id (from immy_list_persons). |
Users
| Tool | What it does |
|---|---|
immy_Pro · Destructive | Permanently delete multiple ImmyBot console users in one call. |
immy_Pro · Destructive | Permanently delete the ImmyBot console user identified by userId (from immy_list_users). |
immy_Free · Read-only | Get a single ImmyBot console user by userId (from immy_list_users). |
immy_Free · Read-only | List ImmyBot console users (operators/technicians). |
immy_Free · Read-only | Get the identity claims for the currently authenticated caller — the claim set the ImmyBot backend associates with this session/token. |
immy_Free · Read-only | List the RBAC groups the user identified by userId (from immy_list_users) belongs to. |
immy_Pro · Write | Update the ImmyBot console user identified by userId (from immy_list_users). |
immy_Pro · Write | Create multiple ImmyBot console users in one call. |
immy_Pro · Destructive | Begin impersonating the ImmyBot console user identified by userId (from immy_list_users) — subsequent actions are performed as that user, for support/troubleshooting. |
immy_Pro · Write | Invalidate the server-side user/permission cache so identity and RBAC changes take effect immediately. |
immy_Pro · Write | End the current user-impersonation session started by immy_users_impersonate, returning to the caller's own identity. |
immy_Pro · Write | Submit product feedback to ImmyBot on behalf of the current user. |
immy_Pro · Write | Set or change the expiration for one or more ImmyBot console users. |
Roles, Groups & Permissions
| Tool | What it does |
|---|---|
immy_Pro · Destructive | Permanently delete an RBAC group by id (from immy_list_groups). |
immy_Pro · Destructive | Remove a user from a group. |
immy_Pro · Destructive | Permanently delete a role by id (from immy_list_roles). |
immy_Free · Read-only | Evaluate the effective permissions a group would have across ALL of its role assignments (POST-as-read what-if — nothing is changed). |
immy_Free · Read-only | Evaluate a group's effective permissions against a specific resource (POST-as-read what-if — nothing is changed). |
immy_Free · Read-only | Evaluate a group's effective permissions within a specific tenant (POST-as-read what-if — nothing is changed). |
immy_Free · Read-only | Evaluate the effective permissions a user would have across ALL of their role assignments (POST-as-read what-if — nothing is changed). |
immy_Free · Read-only | Evaluate a user's effective permissions against a specific resource (POST-as-read what-if — nothing is changed). |
immy_Free · Read-only | Evaluate a user's effective permissions within a specific tenant (POST-as-read what-if — nothing is changed). |
immy_Free · Read-only | Get a single RBAC group by id (from immy_list_groups). |
immy_Free · Read-only | Get a single role by id (from immy_list_roles). |
immy_Pro · Write | Create an RBAC group. |
immy_Pro · Write | Add a member to a group by id (from immy_list_groups). |
immy_Pro · Write | Add multiple members to a group by id (from immy_list_groups) in one call. |
immy_Free · Read-only | List RBAC groups. |
immy_Free · Read-only | List the users that belong to a group by id (from immy_list_groups). |
immy_Free · Read-only | List the role assignments attached to a group by id (from immy_list_groups) — which roles the group grants and at what scope. |
immy_Free · Read-only | List RBAC roles. |
immy_Free · Read-only | List the assignments of a role by id (from immy_list_roles) — which users/groups hold this role and at what scope. |
immy_Free · Read-only | List the full catalog of permissions that roles can grant (the building blocks referenced when creating/updating a role with immy_roles / immy_update_roles). |
immy_Pro · Write | Create an RBAC role. |
immy_Pro · Write | Clone an existing role by id (from immy_list_roles) into a new role. |
immy_Pro · Write | Update a group by id (from immy_list_groups) via HTTP PUT. |
immy_Pro · Write | Update a role by id (from immy_list_roles) via HTTP PUT. |
User Role Assignments
| Tool | What it does |
|---|---|
immy_Pro · Destructive | Delete (revoke) a user-role assignment. |
immy_Free · Read-only | Get all role assignments for a single user by id (from immy_list_users). |
immy_Free · Read-only | List user-role assignments across the instance — the bindings of roles to users/groups at their scopes. |
immy_Free · Read-only | Get the number of role assignments a single user has, by user id (from immy_list_users). |
immy_Pro · Write | Create a role assignment scoped to a CATEGORY of resources — grants a role to a user/group over an entire resource category. |
immy_Pro · Write | Create an MSP-WIDE role assignment — grants a role to a user/group across the entire MSP (all tenants). |
immy_Pro · Write | Create an OWNER-scoped role assignment — grants a role to a user/group at the owner (instance-owner) scope. |
immy_Pro · Write | Create a role assignment scoped to a SPECIFIC resource — grants a role to a user/group on one identified resource only. |
immy_Pro · Write | Create a role assignment scoped to a SPECIFIC tenant — grants a role to a user/group within one tenant only. |
immy_Pro · Write | Create a role assignment scoped to every resource carrying a given TAG — grants a role to a user/group over all resources with that tag. |
immy_Pro · Write | Create a role assignment scoped to every tenant carrying a given TAG — grants a role to a user/group across all tenants with that tag. |
immy_Pro · Write | Create a user-tenant role assignment — associates a user with a tenant and grants the accompanying role. |
Identity & Azure
| Tool | What it does |
|---|---|
immy_Pro · Destructive | Permanently remove the stored Azure/Entra auth details (app registration link + consent) for one or more Azure tenants. |
immy_Pro · Write | Submit an access request for the calling identity (e.g. to gain access to a tenant/resource requiring approval). |
immy_Pro · Write | Create or update the stored Azure/Entra auth details for an Azure tenant (app registration, client credentials reference, delegated scopes). |
immy_Pro · Write | Resolve/record whether an Azure tenant is a partner (CSP) tenant, a customer tenant, or standalone — used when ImmyBot cannot infer the tenant type automatically. |
immy_Pro · Write | Preconsent ImmyBot's app registration into one or more CSP customer tenants (grants the app the permissions it needs without visiting each tenant's consent screen). |
immy_Pro · Write | Trigger a sync of tenant detail/metadata from the linked Azure/Entra tenants into ImmyBot. |
immy_Pro · Write | Trigger a sync of user accounts from the linked Azure/Entra tenants into ImmyBot persons. |
immy_Pro · Write | Notify ImmyBot that an Azure/Entra tenant has completed admin consent for its app registration (the callback that finalizes the consent handshake). |
immy_Free · Read-only | Get the stored Azure/Entra auth details (app registration, consent state, delegated permissions) for a single Azure tenant, keyed by its Azure tenant principal id. |
immy_Free · Read-only | List the CSP customer tenants under a partner (reseller) Azure tenant, keyed by the partner's Azure principal id. |
immy_Free · Read-only | List the auth context / linked Azure-tenant auth records for the ImmyBot instance. |
immy_Free · Read-only | List the outbound IP addresses the ImmyBot instance uses when calling Azure/Entra and other external services — useful for allow-listing on customer firewalls or conditional-access policies. |
immy_Free · Read-only | List the tenants the calling identity holds a given permission type against (i.e. the scope of one permission across tenants). |
immy_Free · Read-only | List the available Azure app-registration options / templates ImmyBot can use when wiring up Azure/Entra integration for a tenant (e.g. the permission sets and consent URLs it offers). |
immy_Free · Read-only | List Azure/Entra integration errors across all tenants as a DevExtreme grid feed (failed consents, throttled Graph calls, sync failures). |
immy_Free · Read-only | List Azure/Entra integration errors for a single tenant (by Azure tenant principal id) as a DevExtreme grid feed. |
immy_Free · Read-only | List the partner (CSP/reseller) Azure tenants known to ImmyBot. |
immy_Free · Read-only | Get the effective permission map for the calling identity (the Entra app registration, or the ImmyBot user whose personal access token the connector holds). |
OAuth & Syncs
| Tool | What it does |
|---|---|
immy_Free · Read-only | Hit the host-rooted /auth/login endpoint (initiates the interactive sign-in redirect). |
immy_Free · Read-only | Hit the host-rooted /auth/logout endpoint. |
immy_Free · Read-only | Hit the host-rooted /auth/me endpoint — returns the current caller's identity as ImmyBot sees it (the Entra app registration, or the ImmyBot user whose personal access token the connector holds). |
immy_Pro · Destructive | Permanently revoke/delete an OAuth access-token record by id (from immy_list_oauth_oauth_access_tokens). |
immy_Free · Read-only | Get a single OAuth access-token record by its composite key (id + accessTokenId, both from immy_list_oauth_oauth_access_tokens). |
immy_Free · Read-only | List the OAuth access tokens ImmyBot holds for its provider integrations (metadata: provider, scopes, expiry, status — not the raw secret). |
immy_Pro · Write | Begin an OAuth authorization-code flow so ImmyBot can obtain a delegated token from a third-party provider. |
immy_Pro · Write | Report that an in-progress OAuth authorization-code flow failed or was aborted (records the error and clears the pending flow state). |
immy_Pro · Write | Complete an OAuth authorization-code flow by redeeming the returned code for a token (the success callback). |
immy_Pro · Write | Refresh (renew) an OAuth access token by id (from immy_list_oauth_oauth_access_tokens) using its stored refresh token. |
immy_Pro · Write | Trigger an Azure/Entra user sync job (pulls users from linked Azure tenants into ImmyBot persons). |
immy_Pro · Write | Trigger the housekeeping job that expires stale pending maintenance sessions (clears sessions stuck in a pending state). |
immy_Pro · Write | Trigger a user-affinity sync (recomputes which persons are associated with which computers, e.g. primary/additional users). |
Media
| Tool | What it does |
|---|---|
immy_Pro · Destructive | Delete a GLOBAL media asset by id (from immy_list_media_global). |
immy_Pro · Destructive | Delete a LOCAL media asset by id (from immy_list_media_local). |
immy_Free · Read-only | Get a single GLOBAL media asset by id (from immy_list_media_global). |
immy_Free · Read-only | Get a single LOCAL media asset by id (from immy_list_media_local). |
immy_Free · Read-only | List GLOBAL media assets (shared across every tenant on the instance) via the DevExtreme grid feed. |
immy_Free · Read-only | Resolve a download URL for a GLOBAL media asset's file by id (from immy_list_media_global). |
immy_Free · Read-only | List LOCAL media assets (owned by a single tenant) via the DevExtreme grid feed. |
immy_Free · Read-only | Get the authorization/access scope for a LOCAL media asset by id (from immy_list_media_local) — which tenants/roles may use it. |
immy_Free · Read-only | Resolve a download URL for a LOCAL media asset's file by id (from immy_list_media_local). |
immy_Free · Read-only | Search media assets with a Sieve page window (Page/pageSize/Filters/Sorts), optionally restricted to global-scope assets via globalOnly. |
immy_Pro · Write | Update a GLOBAL media asset's metadata by id (from immy_list_media_global). |
immy_Pro · Write | Upload a GLOBAL media asset (multipart/form-data) — shared across every tenant on the instance. |
immy_Pro · Write | Update a LOCAL media asset's metadata by id (from immy_list_media_local). |
immy_Pro · Write | Set the authorization/access scope for a LOCAL media asset by id (from immy_list_media_local) — which tenants/roles may use it. |
immy_Pro · Write | Upload a LOCAL media asset (multipart/form-data) — owned by a single tenant. |
immy_Free · Read-only | Request a download URL for a media file (POST-as-read). |
immy_Pro · Write | Upload a SUPPORT media file (multipart/form-data) — e.g. a screenshot or log attached to an ImmyBot support request. |
Schedules
| Tool | What it does |
|---|---|
immy_Pro · Destructive | Cancel a running maintenance schedule by id (from immy_list_schedules or immy_list_schedules_running_schedule_ids), stopping its in-flight maintenance session. |
immy_Pro · Destructive | Delete a maintenance schedule by id (from immy_list_schedules). |
immy_Free · Read-only | Get a single maintenance schedule by id (from immy_list_schedules). |
immy_Free · Read-only | List maintenance schedules, optionally filtered to a single tenant. |
immy_Free · Read-only | List the ids of schedules that are currently executing (have a maintenance session in flight). |
immy_Pro · Write | Bulk enable/disable schedules. |
immy_Pro · Write | Create a maintenance schedule. |
immy_Pro · Destructive | Bulk-cancel running maintenance schedules, stopping their in-flight maintenance sessions. |
immy_Pro · Destructive | Bulk-delete maintenance schedules. |
immy_Pro · Destructive | Trigger multiple maintenance schedules to run immediately. |
immy_Pro · Write | Duplicate a maintenance schedule by id (from immy_list_schedules), creating a new schedule copied from it. |
immy_Pro · Destructive | Trigger a maintenance schedule to run immediately by id (from immy_list_schedules), starting its maintenance session now instead of at the next scheduled time. |
immy_Pro · Destructive | Update (full replace) a maintenance schedule by id (from immy_list_schedules). |
Dynamic Provider Types
| Tool | What it does |
|---|---|
immy_Pro · Write | Create a new GLOBAL (cross-tenant) dynamic provider type. |
immy_Pro · Write | Create a new LOCAL (tenant-scoped) dynamic provider type. |
immy_Pro · Destructive | Permanently delete the GLOBAL dynamic provider type identified by id — this cannot be undone and any provider link built on it will break. |
immy_Pro · Destructive | Permanently delete the LOCAL dynamic provider type identified by id — this cannot be undone and any provider link built on it will break. |
immy_Pro · Destructive | Tear down (dispose) the interactive terminal test environment identified by terminalId, releasing its terminal/session resources. |
immy_Free · Read-only | Bind (render/evaluate) the configuration form for a dynamic provider type inside an interactive terminal test environment. |
immy_Pro · Write | Reload (recompile/re-evaluate) the GLOBAL dynamic provider type identified by id so running provider links pick up its latest definition. |
immy_Pro · Write | Reload (recompile/re-evaluate) the LOCAL dynamic provider type identified by id so running provider links pick up its latest definition. |
immy_Pro · Write | Reload ALL dynamic provider types on the instance (recompile/re-evaluate every dynamic integration definition). |
immy_Pro · Write | Start (provision) an interactive terminal test environment for developing/debugging a dynamic provider type, and get back its terminalId. |
immy_Pro · Destructive | Invoke a named provider method inside the interactive terminal test environment while developing a dynamic provider type. |
immy_Free · Read-only | Get a single GLOBAL (cross-tenant) dynamic provider type by id (from immy_list_dynamic_provider_types), including its definition/script and configuration schema. |
immy_Free · Read-only | Get a single LOCAL (tenant-scoped) dynamic provider type by id (from immy_list_dynamic_provider_types), including its definition/script and configuration schema. |
immy_Free · Read-only | List the dynamic (code-defined) integration provider types configured on the instance (both global and local). |
immy_Pro · Destructive | Update the GLOBAL dynamic provider type identified by id (from immy_list_dynamic_provider_types). |
immy_Pro · Destructive | Update the LOCAL dynamic provider type identified by id (from immy_list_dynamic_provider_types). |
Diagnostics & Metrics
| Tool | What it does |
|---|---|
immy_Pro · Write | Request cancellation of the operation holding an application lock (a cooperative cancel — it signals the running operation to stop, releasing its lock). |
immy_Pro · Write | Set (override) the minimum log level for one application-log source context — raise verbosity on a subsystem while diagnosing, e.g. to Debug/Verbose. |
immy_Pro · Write | Clear the log-level override for a single application-log source context, returning it to the instance default. |
immy_Pro · Write | Clear ALL application-log source-context level overrides at once, returning every subsystem to the instance default log level. |
immy_Pro · Write | Start/stop or configure live application-log streaming (the diagnostic log tail the ImmyBot UI opens). |
immy_Free · Read-only | List the currently held application locks (the concurrency guards ImmyBot uses to serialize instance-level operations). |
immy_Free · Read-only | Get the realtime event-stream snapshot for application locks — the feed the ImmyBot UI subscribes to for live lock acquire/release events. |
immy_Free · Read-only | List the known application-log source contexts (the logger source-context categories, e.g. per subsystem) and their current log-level overrides. |
immy_Free · Read-only | DevExtreme grid feed of GLOBAL (instance-wide) audit records — who changed what across the instance. |
immy_Free · Read-only | DevExtreme grid feed of LOCAL (tenant-scoped) audit records — who changed what within the current tenant scope. |
immy_Free · Read-only | List the provider-link circuit breakers and their current state (closed/open/half-open) — ImmyBot opens a breaker to stop hammering a failing integration. |
immy_Free · Read-only | List per-provider-link metrics (throughput, error, and rate-limit health for each integration link). |
immy_Free · Read-only | Get the rate-limit statistics for a single provider link (requests, throttles, and backoff windows) by providerLinkId (from immy_list_provider_links or immy_list_metrics_provider_links). |
immy_Pro · Destructive | Force a provider-link circuit breaker OPEN (isolate it), immediately halting all traffic to that integration until it is reset. |
immy_Pro · Write | Reset a provider-link circuit breaker back to closed (healthy), resuming traffic to the integration — the counterpart to immy_metrics_circuit_breakers_isolate and the recovery for a breaker that tripped on failures. |
Brandings
| Tool | What it does |
|---|---|
immy_Pro · Write | Create a new branding profile. |
immy_Pro · Write | Promote a branding profile (by id, from immy_list_brandings) to the system-wide default used when no more-specific branding applies. |
immy_Pro · Destructive | Send a preview email using the supplied branding values WITHOUT persisting them — useful to visually verify a branding before creating/updating it. |
immy_Free · Read-only | Validate a .NET date-time format string by formatting the current time with it, and return the formatted result. |
immy_Pro · Destructive | Permanently delete a branding profile by id (from immy_list_brandings). |
immy_Free · Read-only | Fetch a single branding profile by id (from immy_list_brandings). |
immy_Free · Read-only | List all branding profiles visible to the caller. |
immy_Free · Read-only | Fetch the support-sidebar branding override published by the active dynamic provider (the branding shown to end users in the support experience). |
immy_Pro · Destructive | Replace a branding profile by id (from immy_list_brandings). |
Maintenance Email Jobs
| Tool | What it does |
|---|---|
immy_Pro · Destructive | Reboot the target computer immediately for a maintenance email (the 'reboot now' link recipients click). |
immy_Pro · Write | Postpone the scheduled maintenance linked to a maintenance email (the 'postpone' link recipients click). |
immy_Pro · Destructive | Trigger the scheduled maintenance action linked to a maintenance email to run immediately (the 'run now' link recipients click). |
Notifications
| Tool | What it does |
|---|---|
immy_Pro · Destructive | Remove one of the current user's notification silences by its silence id (from immy_list_notifications) — future notifications of that type/object will alert again. |
immy_Free · Read-only | List the current user's ACTIVE notification silences (the notification types/objects currently muted). |
immy_Free · Read-only | List notifications visible to the current user, formatted for the DevExtreme data grid. |
immy_Free · Read-only | List the current user's unacknowledged, unresolved notifications, newest first. |
immy_Pro · Write | Acknowledge a batch of notifications on behalf of the current user. |
immy_Pro · Write | Silence future notifications of a given type for the current user, optionally narrowed to a specific object. |
Notification Preferences
| Tool | What it does |
|---|---|
immy_Free · Read-only | Fetch the preferences for a specific tenant by tenant id (from immy_list_tenants). |
immy_Free · Read-only | Fetch the bundled application, tenant, and user preferences for the current user. |
immy_Pro · Write | Apply a JSON Patch document to the application-wide (instance) preferences. |
immy_Pro · Write | Apply a JSON Patch document to the calling user's own preferences. |
immy_Pro · Write | Apply a JSON Patch document to a specific tenant's preferences (tenant id from immy_list_tenants). |
SMTP Configuration
| Tool | What it does |
|---|---|
immy_Pro · Write | Create the SMTP configuration for a tenant. |
immy_Pro · Destructive | Remove the SMTP configuration for a specific tenant (by tenant id from immy_list_tenants). |
immy_Free · Read-only | Fetch the SMTP configuration for a specific tenant by tenant id (from immy_list_tenants). |
immy_Free · Read-only | List all SMTP configurations visible to the caller (per-tenant outbound mail settings). |
immy_Free · Read-only | List SMTP delivery logs for a specific tenant (by tenant id from immy_list_tenants), formatted for the DevExtreme data grid. |
immy_Pro · Destructive | Replace the SMTP configuration for a specific tenant (by tenant id from immy_list_tenants). |
immy_Pro · Destructive | Send a test email using the supplied SMTP settings to verify connectivity — settings are used for the test only. |
Billing
| Tool | What it does |
|---|---|
immy_Pro · Write | Update the billing contact/account information for this ImmyBot instance (billing address, contact, tax details). |
immy_Pro · Destructive | Cancel this ImmyBot instance's subscription — a billing state change that can end service at the term boundary or immediately depending on the options. |
immy_Pro · Destructive | Reactivate a cancelled/paused subscription for this ImmyBot instance. |
immy_Pro · Destructive | Add, remove, or change the quantity of a subscription add-on for this ImmyBot instance. |
immy_Pro · Destructive | Change this ImmyBot instance's subscription (plan/term/quantities). |
immy_Pro · Destructive | Permanently remove a payment source (credit card) from this ImmyBot instance's billing account, by payment-source id (from immy_list_billing_credit_cards). |
immy_Free · Read-only | Get the billing-platform details for this ImmyBot instance (which billing provider/platform backs the subscription and its configuration). |
immy_Free · Read-only | List the credit cards / payment sources on file for this ImmyBot instance's subscription. |
immy_Free · Read-only | Get a download reference for a billing invoice. |
immy_Free · Read-only | Get the metered feature-usage counts for this ImmyBot instance (the quantities that drive add-on / subscription billing). |
immy_Free · Read-only | Get the billing contact/account information on file for this ImmyBot instance (billing address, contact, tax details). |
immy_Free · Read-only | Get the billing product catalog — the plans/products available for this ImmyBot instance's subscription. |
immy_Free · Read-only | List the individual items in the billing product catalog (the purchasable products/add-ons and their pricing). |
immy_Free · Read-only | Get the current subscription details for this ImmyBot instance (plan, status, term, add-ons, renewal). |
System
| Tool | What it does |
|---|---|
immy_Pro · Write | Approve a deployment change-request by id (from immy_list_change_requests_dx), applying the proposed target-assignment edit. |
immy_Pro · Write | Add a comment to a deployment change-request by id (from immy_list_change_requests_dx) without changing its approval state. |
immy_Pro · Write | Deny (reject) a deployment change-request by id (from immy_list_change_requests_dx), declining to apply the proposed edit. |
immy_Pro · Write | Send a deployment change-request back for revision by id (from immy_list_change_requests_dx) — neither approving nor denying, but requesting changes from the submitter. |
immy_Pro · Destructive | Permanently delete a deployment change-request by id (from immy_list_change_requests_dx), discarding the proposed change without applying it. |
immy_Free · Read-only | Get the state of a specific ephemeral-agent session, keyed by ephemeral-session id, agent-instance id, and provider-agent id (all from the ephemeral-agent launch flow — see immy_launch_ephemeral_agent / immy_list_computers_ephemeral_agent). |
immy_Free · Read-only | Get a webhook configuration by id. |
immy_Free · Read-only | List deployment change-requests (proposed edits to target-assignments awaiting approval) as a DevExtreme grid feed. |
immy_Free · Read-only | Get the count of open (pending) deployment change-requests. |
immy_Free · Read-only | Get metadata for the latest development ephemeral-agent binary (version/hash/reference used to launch ephemeral agents). |
immy_Free · Read-only | Get the current Immy-agent binary hash/metadata (the version fingerprint managed endpoints are expected to run). |
immy_Free · Read-only | Get the details of any current Immy (vendor) support-access grant on this instance — who was granted access and until when. |
immy_Free · Read-only | List the available ImmyBot platform releases (versions on the update channels). |
immy_Free · Read-only | List the timezones known to this ImmyBot instance (the valid identifiers used by schedules and maintenance windows). |
immy_Pro · Write | Revoke Immy (vendor) support access to this instance. |
immy_Pro · Write | Grant Immy (vendor) support access to this instance, letting ImmyBot support staff assist. |
immy_Free · Read-only | Check whether Immy (vendor) support access is currently granted on this instance (a read-only status check, sent as an HTTP POST — it makes no changes). |
immy_Pro · Destructive | Trigger this ImmyBot instance to pull and apply a platform update — a disruptive maintenance action that can restart backend services and briefly interrupt the instance. |
immy_Pro · Destructive | Submit a support request via the in-product support form. |
immy_Pro · Destructive | Request a live support session (interactive assistance) from ImmyBot support. |
immy_Pro · Destructive | Restart this ImmyBot instance's backend services — disruptive: in-flight maintenance sessions and API calls can be interrupted while services cycle. |
immy_Pro · Write | Change which release channel this ImmyBot instance follows (e.g. stable vs preview). |
immy_Pro · Write | Update a webhook configuration by id (sent as an HTTP POST to /webhooks/{id}). |
More in Connector guides
Connect Acronis Cyber Protect CloudConnect Action1Connect AddigyConnect AlertOpsStill need help? Ask the team