Connect Ingram Micro
Ingram Micro is one of the world's largest technology distributors. StackJack connects to it through the Xvantage Integration reseller APIs — the product catalog, live pricing and availability,…
Written By Christopher Scaminaci
Last updated 6 days ago
Ingram Micro is one of the world's largest technology distributors. StackJack connects to it through the Xvantage Integration reseller APIs — the product catalog, live pricing and availability, orders, quotes, invoices, renewals, deals, returns and freight estimates — and, optionally, through the Cloud Marketplace, Ingram's separate platform for subscription cloud services.
Connecting Ingram Micro gives your AI assistant a broad family of ingram_ MCP tools — MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:
- Search the catalog by keyword, vendor, part number or category, and pull full product detail
- Quote live pricing and availability for up to 50 products at a time, including per-warehouse stock and your discounts
- Track orders — search by PO number, date range, serial or tracking number, and read full order detail with line items and shipments
- Work quotes — search and read quotes, validate one against the vendor's mandatory fields, and create new ones
- Look up invoices, renewals and deals, including special-bid (deal) pricing
- Follow returns and open new return claims
- Estimate freight before committing to an order
- Place and manage orders (on Pro plans) — create, modify, release and cancel
- Manage Cloud Marketplace (optional, on Pro plans) — customers, sub-resellers, subscriptions, pricing and rated-usage reports
How StackJack authenticates to Ingram Micro
Ingram Micro uses OAuth 2.0 client credentials. You register an application in the Ingram Micro Developer Portal and give StackJack its client ID and client secret; StackJack exchanges them for a short-lived access token and refreshes it automatically. There is no refresh token to rotate and no per-user sign-in.
Ingram also requires two pieces of account context on every request, so StackJack stores them with the credentials and attaches them for you:
- Customer number — your Ingram Micro account number, e.g.
20-222222 - Country code — the two-letter ISO code for your account's country, e.g.
US
Both are required. Ingram rejects requests without them, so StackJack cannot test the connection until you have filled them in.
Three further fields are optional and each covers a specific set of endpoints:
- Sender ID — identifies your system to Ingram on each transaction
- Contact email — Ingram requires a user email on quote search and freight estimates
- Application ID — Ingram requires this on invoice and deal lookups; leave it blank and StackJack reuses your Sender ID
Leave any of them blank and only the few tools that need it will report a missing setting. Everything else keeps working.
Sandbox and production
Ingram serves both environments from one host — the sandbox simply adds a /sandbox path. StackJack shows an Environment choice:
- Production —
https://api.ingrammicro.com - Sandbox —
https://api.ingrammicro.com/sandbox
Your client ID and secret are issued per environment, so the credentials you enter must match the environment you pick. Start in sandbox while you test, then switch to production.
Sandbox and production are two separate apps in the Developer Portal, each with its own keys, and they are granted very differently:
- Sandbox is immediate. As soon as your developer account is approved you get a sandbox app and its keys, and the environment comes preloaded with test data — SKUs, orders and invoices — so you can exercise the tools without touching a real account.
- Production is a separate request that Ingram reviews by hand. Ingram documents the approval as taking two to four business days; your Ingram sales or account representative can expedite it. The keys appear in your developer account once the app is approved.
So a brand-new integration usually cannot go straight to production. Connect the sandbox first, confirm the tools you need actually return data, then repeat this page against production once those keys arrive.
Cloud Marketplace (optional)
Cloud Marketplace is a separate Ingram platform with its own credentials, used for selling subscription cloud services such as Microsoft 365. It is entirely optional: if you only sell hardware and licences through distribution, leave these fields blank and the Cloud Marketplace tools will simply report that they are not configured. The distribution tools are unaffected either way.
Cloud Marketplace needs four values together, all found in your Cloud Marketplace control panel under SimpleAPI:
- Base URL — unique to your account; Ingram does not publish a shared one
- Username and password — your Cloud Marketplace API user
- Subscription key — sent on every request and sets your call quota
A fifth field, the marketplace code (e.g. us), is optional; leave it blank to use your account default.
Before you begin
- In StackJack: you need a role that can manage connectors (tenant Owner, a co-owner, or an Administrator).
- In Ingram Micro: you need Developer Portal access with API enablement for your account. Ingram controls both sandbox enrollment and production access, so if you do not have it yet, request it from your Ingram representative first.
- Know your customer number and country code.
- For order creation: your Ingram account needs net terms. Ingram extends trade credit for API ordering and bills on those terms.
Step 1 — Create an application in the Developer Portal
Sign in to the Ingram Micro Developer Portal. Signing up authorizes your existing Ingram reseller account for API access.
In your Developer Console, create an app. Ingram asks you to specify which APIs the app needs access to, plus a short description of the app and what you will use it for.
Choose the APIs. This is the step most often missed, and it is the one that decides which StackJack tools work. Ingram groups its reseller APIs into eight families, and StackJack's tools map onto them one for one:
Add every family you want your AI to use. An app can only call the APIs it was registered for, so leaving one out does not stop StackJack connecting — the connection tests fine and most tools work, and only that family's tools fail later with a permission error. If you are not sure, ask for all eight; you can still restrict what your AI may actually do from StackJack's own Permissions page and tool selections. The exact wording of each entry may differ slightly in the portal.
Open the app to read its client ID and client secret.
Step 2 — Find your customer number and country code
- Your customer number appears on your Ingram invoices and in the Xvantage portal (for example
20-222222). - Your country code is the two-letter ISO code for your Ingram account's country, such as
USorGB.
Step 3 — Optional: collect your Cloud Marketplace credentials
Skip this step unless you also sell subscription cloud services.
- Open your Cloud Marketplace control panel and go to the SimpleAPI section.
- Copy the base URL, the subscription key and your API username. You will also need that user's password.
Step 4 — Add the credentials in StackJack
- In the StackJack portal, open Connectors.
- Find the Ingram Micro card. Click How To Connect for the same steps inline, or Configure to enter the credentials.
- Choose your Environment — Production or Sandbox.
- Enter your client ID, client secret, customer number and country code.
- Optionally add the Sender ID, contact email and application ID.
- Optionally fill in the five Cloud Marketplace fields.
- Click Save.
What happens when you save
- Every credential is stored encrypted in Azure Key Vault — never in the StackJack database, and never shown back to you.
- If this is the first time you configure Ingram Micro, a Free-tier subscription for the connector is created automatically so its Free tools work right away.
- StackJack immediately live-validates the credentials by running a small order search. That confirms the client ID, secret, customer number, country code and environment all work together. Validation checks the distribution APIs only — absent Cloud Marketplace fields will never fail it. Validation also never blocks the save: you'll either see a success confirmation or a "saved but validation failed" warning with the reason.
- The connector card shows the connection and validity status from then on.
Working with orders safely
Order and return tools act on your real Ingram trade-credit account, so it is worth knowing Ingram's own rules:
- Creating an order commits a purchase and bills you on your net terms.
- Modifying an order only works if it was created with the customer-hold flag, and only within 24 hours of placement. After 24 hours an unreleased held order is voided automatically, and an order placed without the hold flag cannot be modified at all.
- Cancelling only works before the order reaches the warehouse, and the order must be on customer hold. Once released, cancellation is no longer possible through the API — you must contact Ingram.
- Opening a return creates a real return claim that has to be withdrawn through Ingram support rather than the API.
There are two order-creation tools. The v6 tool places the order and returns the result immediately. The v7 tool submits it asynchronously and returns only an acknowledgement — Ingram reports the outcome to a webhook, so the order number is not in the response; search your orders by your own PO number to find it. The v7 tool also accepts an existing quote in "Ready to Order" status, and configure-to-order quotes.
Freight estimates and price-and-availability lookups commit nothing, so they are safe read-only ways to price work before ordering.
Plans and available tools
- Free includes catalog search and product detail, price and availability, order/quote/invoice/renewal/deal/return search and detail, quote validation, freight estimates, and Cloud Marketplace reads (customers, resellers, orders, catalog, subscriptions, reports, order estimates and parameter validation).
- Pro adds actions for creating, modifying and cancelling orders, creating quotes and returns, and Cloud Marketplace writes (customers, sub-resellers, orders, subscriptions, pricing and report scheduling).
- Business offers the same tool set as Pro with a higher monthly call quota.
See the generated Ingram Micro tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.
Ingram Micro has no per-user sign-in, so there is no per-user attribution — all AI traffic authenticates as your single registered application, scoped to your customer number. Current pricing and quotas are shown in the portal's Billing page and at checkout.
Safety note — powerful tools. StackJack marks the Pro actions that move real money or alter live commercial records as destructive: creating, modifying, updating, or cancelling an order; opening a return; changing a Cloud Marketplace subscription or its special pricing; and updating a Cloud Marketplace customer or sub-reseller. Customer and sub-reseller status changes can put an account on credit hold, suspend it, or cancel it — and doing that to a sub-reseller also stops every customer beneath it from ordering. Whether your AI application asks you to confirm before running one depends on that application's own settings — see Destructive tools and confirmation. Review those settings, and scope your AI's access deliberately — use the tool selections on the MCP Setup page and the Permissions page to enable only the actions you want an AI to take. Note that some order tools accept sandbox-only parameters; those are labelled as such and should not be used against production.
Rate limits
For the Xvantage reseller APIs, Ingram Micro publishes 60 GET calls per minute per endpoint, with limits allocated per API app. Responses expose X-RateLimit-Limit, X-RateLimit-Remaining, and X-RateLimit-Reset; a 429 tells the client when to retry. Cloud Marketplace's separate allowance is tied to your subscription key. StackJack applies one shared per-tenant budget across both surfaces and backs off when Ingram signals throttling. That pacing smooths a burst; it does not guarantee that every call arrives, and a retry budget is bounded rather than open-ended. That shared budget is 50 calls per minute, below the published per-endpoint ceiling. Ask for narrower reads, honour the Retry-After value Ingram sends, and check whether a write actually landed before you retry it — see Retrying a failed or timed-out write.
Page sizes are capped for you. Catalog, order, invoice and deal searches return at most 100 records per page, which is Ingram's documented maximum. Quote search is lower — Ingram allows at most 25 there — and renewals and returns are capped at 100 by StackJack, since Ingram publishes no maximum for those.
Rotating or replacing the credentials
The client secret is the recovery secret. If you rotate or delete it in the Developer Portal, the stored credential stops working. To restore access, open Connectors → Ingram Micro → Configure in StackJack, paste the new secret, and Save.
The two Cloud Marketplace secrets — the password and the subscription key — are never shown back to you. Leave them blank when re-saving and StackJack keeps the stored values; enter a new one to replace it.
Troubleshooting
Ingram Micro tools
ingram_ · 51 tools · Free 35 · Pro 16
Product Catalog
Orders
Quotes
Invoices
Renewals
Deals
Returns
Freight
Cloud Marketplace Customers
Cloud Marketplace Orders
Cloud Marketplace Resellers
Cloud Marketplace Catalog
Cloud Marketplace Subscriptions
Cloud Marketplace Reports
Cloud Marketplace Validation
More in Connector guides
Connect Acronis Cyber Protect CloudConnect Action1Connect AddigyConnect AlertOpsStill need help? Ask the team