Skip to main content
Connector guides

Connect N-able N-central

N-able N-central is a remote monitoring and management (RMM) platform. Connecting it to StackJack gives your AI assistant ncentral_ MCP tools covering devices and customers, scheduled tasks,…

Written By Christopher Scaminaci

Last updated 3 days ago

N-able N-central is a remote monitoring and management (RMM) platform. Connecting it to StackJack gives your AI assistant ncentral_ MCP tools covering devices and customers, scheduled tasks, maintenance windows, custom properties, active issues, asset and lifecycle information, and more. See the generated N-able N-central tool reference for the current inventory, input schemas, plan tiers, and safety notes. MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack.

N-central is unusual among StackJack connectors in two ways:

  • It authenticates with a User-API Token (JWT) instead of a simple API key.
  • It supports per-user attribution: each team member can supply their own token so that actions their AI performs show up under their identity in N-central's audit trail.

How StackJack authenticates to N-central

Your N-central credential is a User-API Token — a JSON Web Token (JWT) that N-central generates for one specific N-central user. StackJack exchanges that token at runtime for a short-lived access token and keeps the session refreshed automatically; you never need to re-enter the token on a schedule.

Two things follow from this design:

  • The token inherits the N-central user's role and visibility. Everything your AI can see or change in N-central is bounded by what that user can see or change.
  • The token is the recovery secret. If it is revoked or regenerated inside N-central, StackJack's refreshed session eventually becomes invalid and you must paste the new token into StackJack.

Two ways to run the connector

Mode 1 — SharedMode 2 — Per-user attribution
Who enters the tokenThe tenant Owner, a co-owner, or an Administrator, on the Connectors pageEach team member, in their Your personal sign-ins section on the Connectors page
Whose N-central identity is usedOne dedicated API-only service account, for everyone's trafficA distinct API-only identity assigned to that member
N-central audit trail showsThe service account for every AI actionThe individual member who triggered the action
RequirementA configured N-central connectorAn active N-central connector subscription (any tier)

Most teams start with Mode 1 and add Mode 2 for members who need their AI activity attributed to them individually. The two modes coexist: when a member has saved their own token, their AI traffic uses it; everyone else's traffic uses the shared token.

Per-user tokens require an active subscription of any tier — the automatically-created Free subscription counts. There is no paid-plan requirement for per-user attribution.

Before you begin

  • In StackJack: you need a role that can manage connectors (tenant Owner, a co-owner, or an Administrator) for the shared setup. For a per-user token (Mode 2), any member can act for themselves once the connector is set up and assigned to them.
  • In N-central: you need to sign in as a user who can reach Administration → User Management. Create dedicated API-only identities instead of using interactive human accounts. N-central requires MFA/Two-Factor Authentication to be disabled for JWT-only API access; keeping that constraint on identities that cannot sign in to the UI avoids weakening a person's normal login.
  • Your N-central server URL — every MSP has their own (for example https://your-ncentral.example.com). There is no regional default.

Step 1 — Generate a User-API Token (JWT) in N-central

  1. Sign in to your N-central server with User Management permissions and navigate to Administration → User Management → Users.
  2. Create a dedicated user for API access. For shared Mode 1, use one service identity. For Mode 2, create a distinct API identity named for each StackJack member so audit attribution stays unambiguous.
  3. Assign the least-privilege Role and Access Group covering only the customers, sites, devices, and actions that identity needs.
  4. Under User Details → User Information → Access, turn off Use Two-Factor Authentication as required by N-central's JWT-only API flow, then save.
  5. Reopen the user, switch to API Access, and select API-Only User so the identity cannot sign in to the N-central UI.
  6. Click GENERATE JSON WEB TOKEN and copy the token. If you later regenerate it, N-central revokes the previous JWT plus its access and refresh tokens; revocation can take up to five minutes.

See N-able's current API-access prerequisites, API-only user procedure, and API role-permission matrix.

Step 2 — Add the shared credential in StackJack

  1. In the StackJack portal, open Connectors.
  2. Find the N-able N-central card. Click How To Connect for the same steps inline, or Configure to enter the credential.
  3. Enter your N-central Server URL. It must start with https:// — use the base URL exactly as you would in a browser.
  4. Paste the JWT into the User-API Token (JWT) field.
  5. Click Save.

When you edit an already-connected N-central credential later, you can leave the token field blank to keep the current token — useful when only the server URL changes.

N-able N-central credential-field example showing the Server URL and User-API Token fields
Field-layout example from the earlier centered setup shell. The current Portal presents these fields in the connector's right-side drawer.

What happens when you save

  • The token is stored encrypted in Azure Key Vault — never in the StackJack database, and it is never shown back to you.
  • If this is the first time you configure N-central, a Free-tier subscription for the connector is created automatically so its Free tools work right away.
  • StackJack immediately live-validates the credential against your N-central server. Validation never blocks the save: you'll either see a success confirmation or a "saved but validation failed" warning with the reason. If validation can't complete (for example, a timeout), it retries automatically in the background.
  • The connector card shows the current connection and validity status from then on.

Per-user attribution (Mode 2)

Each team member who wants their AI activity attributed to their own N-central identity supplies their own token:

  1. Generate a JWT for the dedicated API-only N-central identity assigned to you, following Step 1 above. Do not disable MFA on your normal interactive N-central account just to use StackJack.
  2. In the StackJack portal, open the Connectors page and find the N-central card in your Your personal sign-ins section.
  3. On the N-able N-central card, click Set JWT. (If you've saved a token before, the button reads Update JWT instead.)
  4. In the dialog, the server URL is pre-filled from the shared credential — adjust it only if your admin tells you to. Paste your JWT and click Save.
  5. StackJack validates the token immediately and confirms, or warns you if the token didn't validate.

Once saved, the card also offers a Test button that re-checks your saved token against N-central at any time, without re-pasting it.

Requirements and notes:

  • Per-user tokens require an active N-central connector subscription of any tier. If there is none, the save is rejected with a clear message — ask your admin to set up the connector first.
  • The N-central connector must be among the tools assigned to you for the card to appear in your personal sign-ins.
  • If a member can't self-serve, StackJack support can enter a token on a member's behalf — contact support.

Which N-central permissions do the tools need

The token inherits the role and visibility of the N-central user it was generated for:

  • Read tools work with any user role that has at least read access to the relevant entities.
  • Full read-write coverage (devices, customers, scheduled tasks, maintenance windows, active issues) typically needs the Administrator role in N-central.

The tool families and the access they exercise:

Tool familyAccess used
Devices & Customersread / edit
Scheduled Tasksread / edit
Maintenance Windowsread / edit
Custom Propertiesread / edit
Active Issues & Notificationsread
Asset & Lifecycle Inforead / edit
Reports & Audit Logread
PSA Integrationsread

Use the Permissions page in the StackJack portal to see, per selected tool, exactly which access your N-central user needs.

Plans and available tools

  • Free includes the read tools, including StackJack's Search and Get-All (automatic pagination walking) convenience tools.
  • Pro adds the write tools plus two more StackJack convenience families: Premium Reports and Composite Overviews.
  • Business offers the same tool set as Pro with a higher monthly call quota.

All four convenience families (Search, Get-All, Premium Reports, Composite Overviews) are built by StackJack on top of N-central's standard list endpoints — N-central itself has no native search or reports API.

Per-user attribution is available whenever the connector subscription is active, on any tier. Current pricing and quotas are shown in the portal's Billing page and at checkout.

Rotating or replacing the token

Regenerating the User-API Token inside N-central invalidates the previous token for that user and breaks the refreshed session StackJack holds. The connector will surface a clear re-authorization prompt when this happens. To restore access:

  • Shared credential: open Connectors → N-able N-central → Configure and paste the new token.
  • Per-user credential: open the Connectors page → personal sign-ins and use Update JWT.

N-central applies endpoint-specific concurrent-call limits, currently ranging from 3 to 50 calls, and returns 429 when an endpoint is saturated. StackJack also applies an aggregate per-tenant pace and honors backoff responses. If a wide report is throttled, retry it after a short delay rather than starting overlapping crawls.

Troubleshooting

SymptomLikely causeWhat to do
"Saved but validation failed" right after savingWrong server URL, mis-pasted token, or the N-central user lacks API accessRe-check the URL (must start with https://), regenerate the token, and paste it again
Tools worked, then started failingThe token was regenerated or revoked in N-central, invalidating StackJack's sessionPaste the new token (Configure for shared, Update JWT for per-user). A member's card shows Token Refused in this state.
Your N-central card shows Can't reach itStackJack has not been able to reach your N-central server for several days; the token was not refusedCheck that the server is running and reachable from the internet. A new token does not help; use Test to check again.
Per-user save rejected with a subscription messageNo active N-central connector subscriptionHave an admin configure the connector (a Free subscription is created automatically) or reactivate the subscription
N-central card missing from your personal sign-insThe connector isn't set up yet, or isn't among your assigned toolsAsk your admin to configure the connector and assign it to you
Writes fail while reads succeedThe N-central user behind the token doesn't have a sufficient roleUse a token from a user with the Administrator role (or the needed edit rights)
JWT authentication fails even though the token was copied correctlyThe N-central identity still has MFA/Two-Factor Authentication enabled, or lacks the required Role/Access GroupUse a dedicated API-only identity, disable Two-Factor Authentication on that non-interactive identity, and assign the required least-privilege Role and Access Group

N-able N-central tools

ncentral_ · 104 tools · Free 70 · Pro 34

Server Info

ToolWhat it does
ncentral_get_health
Free · Read-only
Get the N-central API health status.
ncentral_get_server_info
Free · Read-only
Get N-central server identification and version metadata.
ncentral_get_server_info_extra
Free · Read-only
Get extended server metadata (preview endpoint).
ncentral_get_server_info_extra_authenticated
Free · Read-only
Get authenticated server metadata (preview endpoint).

Devices

ToolWhat it does
ncentral_get_appliance_task_info
Free · Read-only
Get the execution detail for an appliance task by its taskId — used to inspect direct-support task results, AMP runs, or other appliance-side jobs.
ncentral_get_device_asset_info
Free · Read-only
Get hardware and OS asset details for a device (manufacturer, model, serial, OS version, CPU, RAM, disks).
ncentral_get_device_by_id
Free · Read-only
Get a single device by its deviceId.
ncentral_get_device_lifecycle_info
Free · Read-only
Get lifecycle/warranty metadata for a device (purchase date, warranty expiration, vendor contract, retirement date, asset tag, cost).
ncentral_get_device_service_monitor_status
Free · Read-only
Get a device's service-monitor health status (NORMAL/WARNING/FAILED).
ncentral_list_devices
Free · Read-only
List monitored devices.
ncentral_list_devices_by_org_unit_id
Free · Read-only
List devices belonging to a specific organization unit (SO/Customer/Site).
ncentral_patch_asset_lifecycle_info
Pro · Write
Partial update of a device's lifecycle-info object.
ncentral_replace_asset_lifecycle_info
Pro · Destructive
Replace the entire lifecycle-info object for a device (PUT semantics).

Organization Units

ToolWhat it does
ncentral_create_customer
Pro · Write
Create a new customer under a specific service organization.
ncentral_create_service_organization
Pro · Write
Create a new service organization.
ncentral_create_site
Pro · Write
Create a new site under a specific customer.
ncentral_get_customer
Free · Read-only
Get a single customer by ID.
ncentral_get_organization_unit
Free · Read-only
Get a single organization unit (SO/Customer/Site) by ID — useful when you only have a unit ID and don't yet know its tier.
ncentral_get_service_organization
Free · Read-only
Get a single service organization by ID.
ncentral_get_site
Free · Read-only
Get a single site by ID.
ncentral_list_customers
Free · Read-only
List all customers across every service organization the caller can see.
ncentral_list_customers_under_so
Free · Read-only
List customers belonging to a specific service organization.
ncentral_list_organization_unit_children
Free · Read-only
List the direct children of an organization unit (e.g. customers under an SO, sites under a customer).
ncentral_list_organization_units
Free · Read-only
List ALL organization units across all tiers (Service Organizations + Customers + Sites) as a flat list.
ncentral_list_service_organizations
Free · Read-only
List service organizations (SOs) — the top of the orgUnit tree.
ncentral_list_sites
Free · Read-only
List all sites across every customer the caller can see.
ncentral_list_sites_under_customer
Free · Read-only
List sites belonging to a specific customer.

Device Filters

ToolWhat it does
ncentral_list_device_filters
Free · Read-only
List device filters available to the caller.

Custom Properties

ToolWhat it does
ncentral_get_device_custom_property
Free · Read-only
Get the current value of a single custom property on a device.
ncentral_get_device_custom_property_default_at_org_unit
Free · Read-only
Get the default value of a DEVICE custom property as defined at a specific orgUnit.
ncentral_get_org_unit_custom_property
Free · Read-only
Get the current value of a single custom property on an organization unit.
ncentral_get_org_unit_custom_property_default
Free · Read-only
Get the default value for a single org-unit-level custom property.
ncentral_list_device_custom_properties
Free · Read-only
List all custom properties (and their current values) for a single device.
ncentral_list_org_unit_custom_properties
Free · Read-only
List custom properties defined on an organization unit (SO/Customer/Site).
ncentral_update_device_custom_property
Pro · Destructive
Update (PUT) the value of a single custom property on a device.
ncentral_update_org_unit_custom_property_defaults
Pro · Destructive
Update (PUT) the default-value set for org-unit custom properties at a given orgUnit.
ncentral_update_org_unit_custom_property_value
Pro · Destructive
Update (PUT) the value of a single custom property on an organization unit.

Scheduled Tasks

ToolWhat it does
ncentral_create_direct_support_task
Pro · Destructive
DESTRUCTIVE: this executes immediately against the target device — it is run now, NOT scheduled for later — and can change endpoint state (it runs an Automation Policy / Script / MacScript on the endpoint).
ncentral_get_scheduled_task
Free · Read-only
Get a scheduled-task definition by taskId.
ncentral_get_scheduled_task_status
Free · Read-only
Get the current aggregate status of a scheduled task (queued / running / complete / failed).
ncentral_list_scheduled_task_status_details
Free · Read-only
List per-device execution detail for a scheduled task — useful when the task targeted multiple devices and you need a per-device pass/fail breakdown.

Maintenance Windows

ToolWhat it does
ncentral_add_maintenance_windows_bulk
Pro · Write
Add the same set of maintenance windows to a list of devices in one call.
ncentral_delete_maintenance_windows_bulk
Pro · Destructive
WARNING: Permanently remove one or more maintenance windows by schedule ID.
ncentral_get_maintenance_windows_for_device
Free · Read-only
List the maintenance windows currently configured on a single device.

Users

ToolWhat it does
ncentral_list_users_for_org_unit
Free · Read-only
List users with access to a specific organization unit (SO/Customer/Site).

User Roles

ToolWhat it does
ncentral_add_user_role
Pro · Write
Create a new user role at a specific organization unit.
ncentral_get_user_role
Free · Read-only
Get a single user role by ID — returns the role's name, permission set, and assigned users count.
ncentral_list_user_roles
Free · Read-only
List user roles defined at an organization unit (SO/Customer/Site).

Access Groups

ToolWhat it does
ncentral_create_device_access_group
Pro · Write
Create a device-based access group.
ncentral_create_org_unit_access_group
Pro · Write
Create an organization-unit-based access group.
ncentral_get_access_group
Free · Read-only
Get a single access group by ID — returns name, type (orgUnit or device based), and member list.
ncentral_list_access_groups
Free · Read-only
List access groups defined at an organization unit.

Job Statuses

ToolWhat it does
ncentral_list_job_statuses
Free · Read-only
List currently-tracked job statuses for an organization unit.

Active Issues

ToolWhat it does
ncentral_list_active_issues
Free · Read-only
List active issues (open alarms / monitoring notifications) for an organization unit.

Registration Tokens

ToolWhat it does
ncentral_get_customer_registration_token
Free · Read-only
Get the appliance-registration token for a specific customer.
ncentral_get_org_unit_registration_token
Free · Read-only
Generic registration-token lookup for an organization unit — supports Customer or Site tier only (SO tier is not supported and will 400).
ncentral_get_site_registration_token
Free · Read-only
Get the appliance-registration token for a specific site.

Device Tasks

ToolWhat it does
ncentral_list_scheduled_tasks_for_device
Free · Read-only
List scheduled tasks targeted at a specific device.

PSA

ToolWhat it does
ncentral_get_custom_psa_ticket_info
Free · Read-only
Get information about a custom-PSA ticket.
ncentral_validate_standard_psa_credentials
Pro · Write
Validate a set of PSA credentials against a standard PSA integration.

Walk Pagination (Get All)

ToolWhat it does
ncentral_get_all_access_groups
Free · Read-only
Walk every page of /api/org-units/{orgUnitId}/access-groups until exhausted or `maxItems` reached.
ncentral_get_all_active_issues
Free · Read-only
Walk every page of /api/org-units/{orgUnitId}/active-issues until exhausted or `maxItems` reached.
ncentral_get_all_customers
Free · Read-only
Walk every page of /api/customers until exhausted or `maxItems` reached.
ncentral_get_all_customers_under_so
Free · Read-only
Walk every page of /api/service-orgs/{soId}/customers until exhausted or `maxItems` reached.
ncentral_get_all_device_filters
Free · Read-only
Walk every page of /api/device-filters until exhausted or `maxItems` reached.
ncentral_get_all_devices
Free · Read-only
Walk every page of /api/devices until exhausted or `maxItems` reached, returning a combined envelope {data, totalItems, totalPagesWalked, hadMore, timeBudget}.
ncentral_get_all_devices_for_org_unit
Free · Read-only
Walk every page of /api/org-units/{orgUnitId}/devices until exhausted or `maxItems` reached.
ncentral_get_all_org_unit_custom_properties
Free · Read-only
Walk every page of /api/org-units/{orgUnitId}/custom-properties until exhausted or `maxItems` reached.
ncentral_get_all_organization_unit_children
Free · Read-only
Walk every page of /api/org-units/{orgUnitId}/children until exhausted or `maxItems` reached.
ncentral_get_all_organization_units
Free · Read-only
Walk every page of /api/org-units (flat list across all tiers) until exhausted or `maxItems` reached.
ncentral_get_all_service_organizations
Free · Read-only
Walk every page of /api/service-orgs until exhausted or `maxItems` reached.
ncentral_get_all_sites
Free · Read-only
Walk every page of /api/sites until exhausted or `maxItems` reached.
ncentral_get_all_sites_under_customer
Free · Read-only
Walk every page of /api/customers/{customerId}/sites until exhausted or `maxItems` reached.
ncentral_get_all_user_roles
Free · Read-only
Walk every page of /api/org-units/{orgUnitId}/user-roles until exhausted or `maxItems` reached.
ncentral_get_all_users_for_org_unit
Free · Read-only
Walk every page of /api/org-units/{orgUnitId}/users until exhausted or `maxItems` reached.

Search & Filter

ToolWhat it does
ncentral_list_active_issues_for_customer
Free · Read-only
Ergonomic alias for ncentral_list_active_issues scoped to a Customer ID.
ncentral_list_active_issues_for_site
Free · Read-only
Ergonomic alias for ncentral_list_active_issues scoped to a Site ID.
ncentral_list_offline_devices
Free · Read-only
Walks /api/devices and returns devices where `online == false`.
ncentral_list_online_devices
Free · Read-only
Walks /api/devices and returns devices where `online == true`.
ncentral_list_overdue_devices
Free · Read-only
Walks /api/devices and returns devices whose `lastApplianceCheckinTime` is older than N hours (default 24).
ncentral_search_customers_by_name
Free · Read-only
Walks /api/customers and returns customers whose `customerName` contains the supplied substring (case-insensitive).
ncentral_search_devices_by_class
Free · Read-only
Walks /api/devices and returns devices whose `deviceClass` exactly equals the supplied class (case-insensitive) — e.g. WINDOWS_SERVER, WORKSTATION, LINUX, MACOS.
ncentral_search_devices_by_name
Free · Read-only
Walks /api/devices and returns devices whose `longName` contains the supplied substring (case-insensitive).
ncentral_search_sites_by_name
Free · Read-only
Walks /api/sites and returns sites whose `siteName` contains the supplied substring (case-insensitive).
ncentral_search_users_by_email
Free · Read-only
Walks /api/org-units/{orgUnitId}/users and returns users whose `email` contains the supplied substring (case-insensitive).

Composite Overviews

ToolWhat it does
ncentral_get_customer_overview
Pro · Read-only
Fan-out composite for a single customer: combines GetCustomer + ListSitesUnderCustomer + ListActiveIssues + ListJobStatuses + GetCustomerRegistrationToken into one envelope {customer, sites, activeIssues, jobStatuses, registrationToken}.
ncentral_get_device_overview
Pro · Read-only
Fan-out composite for a single device: combines GetDeviceById + ServiceMonitorStatus + AssetInfo + LifecycleInfo + MaintenanceWindows + ScheduledTasks into one envelope {device, serviceMonitorStatus, assetInfo, lifecycle, maintenanceWindows, scheduledTasks}.
ncentral_get_org_unit_overview
Pro · Read-only
Fan-out composite for a single organization unit: combines GetOrganizationUnit + ListOrganizationUnitChildren + ListOrgUnitCustomProperties, plus ListActiveIssues for CUSTOMER/SITE units only, into one envelope {orgUnit, children, activeIssues, customProperties}.
ncentral_get_scheduled_task_overview
Pro · Read-only
Fan-out composite for a single scheduled task: combines GetScheduledTask + GetScheduledTaskStatus + ListScheduledTaskStatusDetails into one envelope {task, status, details}.
ncentral_get_site_overview
Pro · Read-only
Fan-out composite for a single site: combines GetSite + walked-devices-for-site + ListActiveIssues into one envelope {site, devices, activeIssues, timeBudget, itemCap}.
ncentral_list_device_asset_details
Pro · Read-only
One page of devices WITH their per-device asset and lifecycle records joined in — serial number, manufacturer/model, OS, plus warranty expiry, lease expiry, expected replacement, purchase date, cost, location and asset tag.

Task Type Wrappers

ToolWhat it does
ncentral_run_automation_policy_on_device
Pro · Destructive
DESTRUCTIVE: executes immediately on the target device and can change endpoint state.
ncentral_run_mac_script_on_device
Pro · Destructive
DESTRUCTIVE: executes immediately on the target macOS device and can change endpoint state.
ncentral_run_script_on_device
Pro · Destructive
DESTRUCTIVE: executes immediately on the target device and can change endpoint state.

Premium Reports

ToolWhat it does
ncentral_report_active_issues_summary_by_severity
Pro · Read-only
Walks active issues for a Customer/Site orgUnit and produces a severity-grouped count.
ncentral_report_appliance_health_summary
Pro · Read-only
Walks every device in the account, or in the given organization unit, and pulls service-monitor status.
ncentral_report_asset_inventory_summary
Pro · Read-only
Walks every device in the account, or in the given organization unit, fetches asset info, and produces an OS / manufacturer distribution.
ncentral_report_compliance_custom_property_coverage
Pro · Read-only
For a given device custom-property ID, walks every device in the account, or in the given organization unit, and returns the % populated (non-null/non-empty value).
ncentral_report_devices_offline_summary
Pro · Read-only
Walks every device in the account, or in the given organization unit, and produces an offline-device count grouped by customerId and siteId.
ncentral_report_maintenance_window_coverage
Pro · Read-only
Walks every device in the account, or in the given organization unit, fetches each one's maintenance windows, and returns the % of devices with at least one window configured.
ncentral_report_overdue_check_ins
Pro · Read-only
Walks every device in the account, or in the given organization unit, and returns those whose `lastApplianceCheckinTime` is older than N hours (default 24), grouped by customer.
ncentral_report_scheduled_task_recent_failures
Pro · Read-only
Walks the scheduled tasks of every device in the account, or in the given organization unit, pulls status detail for each, and returns failed entries from the last N hours (default 24).
ncentral_report_user_access_audit
Pro · Read-only
For a given orgUnit, walks users + user roles + access groups and returns a per-user record listing their role assignments and any access-group memberships.
ncentral_report_warranty_expiring_in_days
Pro · Read-only
Walks every device in the account, or in the given organization unit, fetches lifecycle info, and returns devices whose warranty expires within N days (default 60).