Connect Lexful
Lexful is an IT documentation platform for MSPs — the place your team records what a client's environment actually looks like. Despite the name, it is not an AI or legal product: it is documentation…
Written By Christopher Scaminaci
Last updated 6 days ago
Lexful is an IT documentation platform for MSPs — the place your team records what a client's environment actually looks like. Despite the name, it is not an AI or legal product: it is documentation tooling in the same category as Hudu and IT Glue. You define your own asset types with whatever properties you need, file assets under client organizations, keep revision history on everything, and store credentials as secure properties. StackJack talks to Lexful through the Lexful public API.
Connecting Lexful to StackJack gives your AI assistant a large family of lexful_ MCP tools — MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:
- Read your documentation — client organizations and their hierarchy, assets of any type with full filtering, related assets, revision history, attached files and cross-entity search
- Understand your schema — the asset types you have defined, their properties and the relationships between them
- See who can access what — access grants on assets and tags, groups and their membership, users and roles, and your SSO configuration
- Write documentation (on Pro plans) — create and update organizations, assets and asset types; tag and relate records; manage groups, users and access
- Read stored secrets (on Pro plans, and only if you grant it) — documented passwords and keys, behind their own separate permission
It is a large connector, because Lexful's API is large. Most of them are writes, so the tier and permission settings matter more here than on a read-only connector.
How StackJack authenticates to Lexful
Lexful needs three values, which is one more than most connectors:
All three come from the same place: the Lexful dashboard, under Account Settings → APIs.
The Account ID is the one people miss. It is not part of the API key and cannot be worked out from it, and Lexful requires it on every single request. A connector saved with a valid key but a missing or wrong Account ID will authenticate and then fail every tool — which looks like a broken key even though the key is fine. It is also easy to transpose with the API Key ID, so check them against the dashboard when you paste them in.
StackJack handles the rest automatically. It exchanges your key ID and secret for a short-lived access token, renews the token before it expires, and re-authenticates if Lexful ever rejects it. There is nothing to refresh by hand and no expiry to diarise.
Lexful currently publishes one address (https://api.us.lexful.app), which StackJack uses by default. The connector has an optional API Base URL field for the day Lexful adds another; leave it blank unless Lexful has told you your account is elsewhere. Anything that is not a recognised Lexful address is rejected.
Before you begin
- In StackJack: you need a role that can manage connectors (tenant Owner, a co-owner, or an Administrator).
- In Lexful: you need access to Account Settings → APIs, which is where both the Account ID and API keys live.
Step 1 — Collect your credentials in Lexful
- Sign in to the Lexful dashboard.
- Go to Account Settings → APIs.
- Note the Account ID shown on that page.
- Create an API key. Lexful gives you an ID and a secret as a pair — you need both.
- Copy the secret immediately and store it securely. Treat it as a password: anyone holding it, together with the Account ID, can read everything you have documented, including stored credentials.
Step 2 — Add the connector in StackJack
- In StackJack, open Connectors.
- Find the Lexful card and select Configure.
- Enter the Account ID, API Key ID and API Key Secret.
- Leave API Base URL blank unless Lexful told you otherwise.
- Save, then use Test Connection.
The connection test deliberately exercises the whole authentication path — the token exchange and both required values — so a green result means your AI can genuinely reach your data, not merely that the key is well-formed.
What your AI can do, by plan
Reading stored secrets is a separate decision
Lexful can store credentials as secure properties on an asset — a client's router password, a service account key. Two tools read those values in plaintext.
Those two tools are deliberately kept apart from everything else. They require the Pro tier, and they sit under their own permission rather than the general asset-read permission. That means you can let an AI read all your documentation while withholding the passwords inside it. Ordinary asset reads never include secure values, so nothing leaks by accident through the general tools.
Grant it only if you specifically intend your AI to retrieve credentials. One of the two can also read a secret as it was at an earlier revision, which can return a password that has since been changed — useful for recovering something overwritten by mistake, and worth understanding before you grant it.
Tools that change a lot at once
Most Lexful writes affect one record and are easy to undo. A few are much wider, and StackJack marks these as sensitive. Whether your AI application asks you to confirm before running one depends on that application's own settings — see Destructive tools and confirmation. Review those settings, and know what each one reaches:
- Deleting a property from an asset type removes that property's data from every asset of that type, not just from the schema. This is the widest-reaching call in the connector — wider than deleting an asset — and if the property held a secure value, that secret goes with it.
- Restoring an asset to an earlier revision overwrites the current record, so anything written since that revision is lost. This is different from restoring a deleted asset, which simply brings it back.
- Archiving an asset type takes the type and the visibility of everything filed under it out of service in one call.
- Bulk delete and bulk update exist for assets, organizations and tags, and reach as many records as you name.
- Deleting a user, a group or an SSO connection removes people's access — an SSO connection especially, since everyone who signs in through it loses their way in at once.
Most deletions are recoverable. Lexful soft-deletes, so deleted assets and organizations can be restored and still appear in reads that include deleted items. Files are the exception: there is no restore for them, and StackJack cannot upload a replacement, so re-attaching a document means doing it in Lexful.
Tagging, relating and group membership are not deletions. Removing a tag from an asset, unlinking related assets, or taking someone out of a group changes only the association — the records survive and the matching "add" tool puts things back exactly. Those tools are not treated as destructive, though removing an access grant does take someone's access away until it is restored.
Finding things
Asset properties are whatever you defined, so your AI filters with a flexible expression rather than fixed fields — for example, matching a name that starts with "Acme", a status that is one of several values, or a date range. It can also sort, expand relationships, include deleted records, restrict results to one client organization, and ask for only the properties it needs, which keeps large asset types readable.
If your AI does not know which asset type holds what it is looking for, the search tool covers assets and organizations together. Search returns up to 100 results per page; every other list returns up to 1000.
Troubleshooting
"Every Lexful tool fails, but the API key is definitely right." Check the Account ID. Lexful needs it on every request alongside the key, so a missing or mistyped Account ID fails everything while the key itself is perfectly good. It is a different value from the API Key ID and the two are easy to swap.
"Lexful refuses the credentials." Confirm the API key still exists under Account Settings → APIs. If it was removed, create a new one and paste both halves into StackJack along with the Account ID — and check all three come from the same Lexful environment.
"A record cannot be found." On this connector that is usually the asset type name rather than a missing record — asset paths include the type name, and those are specific to your account. Have your AI list the asset types to confirm the exact name. If the record was deleted, remember Lexful keeps deleted rows recoverable, so a read that includes deleted records may still find it.
"API calls started failing from a new location." Check the IP allowlist. Lexful can restrict which networks reach its API, and StackJack's requests have to come from an allowed one. StackJack does not publish its outbound addresses: open a support ticket to get the current addresses for your region before you enable the restriction, and ask again after a region move, because they change.
Several customers
Some MSPs need one Lexful connection per customer, console or region. StackJack can hold several named connections of one connector, and your AI names the one it wants on each call. See Several connections of one connector.
Full tool list
See the generated Lexful tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.
Lexful tools
lexful_ · 90 tools · Free 30 · Pro 60
Assets
Secure Values
Asset Types
Asset Files
Access Grants
Organizations
Tags
Groups
Users
SSO Connections
Account
Search
More in Connector guides
Connect Acronis Cyber Protect CloudConnect Action1Connect AddigyConnect AlertOpsStill need help? Ask the team