Connect IRONSCALES
IRONSCALES is an email security platform built for MSPs. It sits on top of your customers' Microsoft 365 or Google Workspace mail, catches phishing that got past the native filters, lets employees…
Written By Christopher Scaminaci
Last updated 6 days ago
IRONSCALES is an email security platform built for MSPs. It sits on top of your customers' Microsoft 365 or Google Workspace mail, catches phishing that got past the native filters, lets employees report suspicious messages, and removes a confirmed threat from every inbox that received it. It also runs the other half of the problem: phishing-simulation campaigns and security awareness training, so you can measure whether people actually spot a fake. StackJack talks to IRONSCALES through its partner API.
Connecting IRONSCALES to StackJack gives your AI assistant a family of ironscales_ MCP tools — MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:
- Work the phishing queue — list incidents and the ones still unclassified, read the full evidence behind each, and see which messages a retro-scan re-flagged after delivery
- Report on protection — mitigation statistics, email volume and verdicts, impersonation incidents, and the departments and individual people being targeted most
- Watch for account takeover — the suspicious sign-in activity IRONSCALES flagged, with the events behind each verdict
- Track training — campaign results, per-person performance over time, and the compliance report showing who has finished their assigned training
- Audit coverage — protected mailboxes, licensed domains, licence consumption per company, and whether each company's mail integration is actually connected
- Triage and remediate (on Pro plans) — classify an incident so IRONSCALES removes the threat fleet-wide, split or re-group clustered incidents, and run account-takeover remediation
- Build and run training (on Pro plans) — compose a campaign as a draft, launch it, stop one that is going badly, and manage allow-lists, alert recipients and detection sensitivity
- Manage companies and licensing (on Pro plans) — provision companies, add mailboxes and licensed domains, and adjust licences
How StackJack authenticates to IRONSCALES
IRONSCALES uses a single long-lived API key. You generate it once in the IRONSCALES console and paste it into StackJack — there is no client ID, no second secret, and nothing to renew on a schedule.
Behind the scenes IRONSCALES does not accept that key directly on each request: it exchanges it for a short-lived access token first. StackJack handles that exchange for you, keeps the token fresh, and gets a new one automatically when it expires. You never see it.
Choose the right kind of key first
This is the one decision worth making carefully, because it determines what works:
- A partner key sees every company you manage. It can list, create, license and configure them, and it is what you want if you are managing customers through IRONSCALES.
- A company key sees one company only. Everything scoped to that company works normally, but the partner-wide tools — listing companies, provisioning, licensing — are refused.
If you use a company key, tools like "list companies" will report that IRONSCALES refused the request. That is expected and does not mean the connection is broken; the connection test will still show as connected.
Steps
- Decide partner or company scope, as above. If you want partner-wide reach, generate the key from your partner account rather than from inside a single company.
- Generate the API key in the IRONSCALES console, signed in as an administrator, from the API settings area.
- Copy the key straight away and store it securely. Treat it as a password — anyone holding it can read and act on your IRONSCALES account.
- Paste it into StackJack. Open Connectors, choose IRONSCALES, and paste the key. There is no URL to enter: IRONSCALES is a single global service with no regional endpoints, so the address is fixed.
- Run a Test Connection to confirm StackJack can reach IRONSCALES with the key.
What to know before your AI uses this connector
Some tools send real email to real people
This is the most important thing about the IRONSCALES connector, and it is easy to miss because the vendor's own naming understates it:
- Approving a campaign launches it. IRONSCALES calls the step "approve a draft campaign", which sounds like a paperwork state change. It is not — approving sends the simulated phishing or training messages to your employees, and there is no way to unsend them.
- A "test send" is a small live send. The three test-send tools deliver to up to ten real mailboxes. They are for checking how a message renders with willing colleagues, not for rehearsing without sending anything.
All of these require the Pro tier and are marked destructive. Whether your AI application asks you to confirm before running one depends on that application's own settings — see Destructive tools and confirmation. Review those settings before you grant a launch or a test send.
Building a campaign sends nothing. Creating one leaves it as a draft that sends nothing at all. Launching is a separate, clearly-marked step. That split is deliberate: your AI can assemble an entire campaign — templates, training, audience, schedule — and leave the decision to actually send it to a person. You can also ask it to calculate how many people an audience filter would reach before anything is launched.
Some tools change protection itself
- Disconnecting a mail integration ends protection for that whole company. Mail keeps flowing, so nothing looks broken to the customer — it simply stops being inspected. Reconnecting is not something StackJack can do on its own: the customer's own administrator has to go through the consent flow again.
- Classifying an incident triggers remediation. Marking a cluster malicious removes those messages from every inbox that received them; marking a real threat safe leaves it in place.
- Account-takeover remediation acts on a real person's account, and can disable it or force a password reset.
- Cancelling licences and removing licensed domains affect both billing and coverage. Mailboxes on a removed domain stop being protected.
- Turning off directory sync breaks nothing immediately, but the mailbox list stops tracking the customer's directory, so coverage drifts as staff join and leave.
Every one of these is marked as destructive and requires the Pro tier. Whether your AI application asks you to confirm first depends on that application's own settings.
Plans and limits
Read tools are available on the Free tier. Everything that writes, remediates, launches a campaign or changes licensing is Pro. Business reaches the same tools as Pro and differs by monthly call quota.
See the generated IRONSCALES tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.
IRONSCALES allows 120 API calls a minute per company, and a few individual operations are throttled harder than that. StackJack paces requests and backs off automatically if you are throttled, which usually turns a large report into a slower one rather than a failed one. Pacing is not a guarantee: retries are bounded, so a wide enough report can still come back throttled or time out. Narrow the window or the audience, and check whether a write landed before repeating it — see Retrying a failed or timed-out write.
Several customers
Some MSPs need one IRONSCALES connection per customer, console or region. StackJack can hold several named connections of one connector, and your AI names the one it wants on each call. See Several connections of one connector.
Troubleshooting
"IRONSCALES rejected the access token" — the API key is no longer valid. StackJack gets a fresh token and retries automatically, so a failure that reaches you generally means the key itself was revoked or replaced. Generate a new key in the IRONSCALES console, paste it into StackJack and run a Test Connection.
One thing worth knowing if you are comparing notes with IRONSCALES support: this API reports an authentication failure with the same status code most services use for a malformed request. An error that mentions authentication really is about the key, even if it looks like a request problem.
"IRONSCALES accepted the key but refused this operation" — almost always the key's reach rather than a fault. A company-scoped key cannot use the partner-wide company, provisioning and licensing tools. If you need those, generate the key from your partner account and re-enter it.
A company shows no incidents at all — check the integration status before assuming it has been a quiet week. A mail integration that was never completed, or has since been disconnected, looks exactly the same as no threats.
Some of a customer's mail is not being inspected — check the licensed domains for that company. A mailbox on a domain that is not licensed is not covered, and nothing about it looks like an error.
IRONSCALES tools
ironscales_ · 100 tools · Free 56 · Pro 44
Companies
Incidents
Mitigation
Security Awareness Training
Phishing Campaigns
Settings
Mailboxes
Licensing
Integrations
Threat Feeds
More in Connector guides
Connect Acronis Cyber Protect CloudConnect Action1Connect AddigyConnect AlertOpsStill need help? Ask the team