Skip to main content
Connector guides

Connect Telivy

Telivy is a security platform for MSPs covering external attack-surface scans, deep-scan risk assessments, Microsoft 365 / Google Workspace MFA analysis, PII discovery, and breach data. Connecting it…

Written By Christopher Scaminaci

Last updated 6 days ago

Telivy is a security platform for MSPs covering external attack-surface scans, deep-scan risk assessments, Microsoft 365 / Google Workspace MFA analysis, PII discovery, and breach data. Connecting it to StackJack lets your AI assistant work with your Telivy assessments through MCP tools — the standardized tool calls (Model Context Protocol) that AI harnesses like Claude or ChatGPT use to act on your behalf. Once connected, your AI can review scans and risk assessments, pull findings, devices, breach data and PII summaries, and download generated reports.

The Telivy tool family uses the telivy_ prefix. The full tool set is available on every plan — paid plans for this connector differ only in the monthly usage allowance. See the generated Telivy tool reference for the current inventory, input schemas, plan tiers, and safety notes.

Before you begin

You will need:

  • A StackJack role that can manage connectors: tenant Owner, co-owner, or Administrator. Plain Members cannot add or edit connector credentials.
  • Access to your Telivy MSP portal account.

There is no URL or region to configure — Telivy is a global SaaS and StackJack talks to its fixed API endpoint (api-v1.telivy.com).

Read this before connecting: the API key sees everything. A Telivy API key grants access to all assessments visible to your MSP agent account — there is no per-key role restriction. And Telivy responses contain genuinely sensitive material: leaked credentials from breach data, PII counts, and M365 / Google Workspace user inventories, which StackJack passes through to your AI verbatim. Connect Telivy only if the team members whose AI sessions will use it are people you'd already trust with full visibility in the Telivy portal, and make sure your tenant's tool permissions reflect that.

Step 1: Get your API key from Telivy

  1. Sign in to your Telivy MSP portal at portal.telivy.com.
  2. Go to Account → Integrations.
  3. Copy the API key shown on the Integrations page. If no key exists yet, generate one there.
  4. Treat the key like a password — anyone holding it can read all your scans, devices, and PII data.

Telivy also documents this location in its current partner-integration example.

Step 2: Add the key in StackJack

  1. In the StackJack portal, go to Connectors.
  2. Find the Telivy card. Click How To Connect for the guided walkthrough of Step 1, or go straight to Configure.
  3. In the configuration dialog:
FieldWhat to enter
API KeyThe key from Telivy's Account → Integrations page. The key alone authenticates every call — there is no client ID.
  1. Click Save.

Telivy credential-field example showing the fixed base URL note and the single API Key field.
Field-layout example from the earlier centered setup shell. The current Portal presents this field in the connector's right-side drawer.

What happens when you save

  • Your API key is stored encrypted in Azure Key Vault — it is never written to the StackJack database.
  • StackJack immediately tests the key against Telivy. If the test fails, the key is still saved and you'll see a "saved, but validation failed" message with the reason so you can correct it.
  • A Free subscription for the Telivy connector is created automatically, so its tools appear in your AI harness right away. Upgrade from the connector card whenever you're ready — current pricing is shown in the portal at checkout.

Health monitoring

StackJack periodically re-validates the connection. If it fails definitively three times in a row (for example, because the key was regenerated in Telivy), the connector is automatically disabled and the tenant owner is emailed. The connector card then shows the error details along with Re-enable and Update Credentials buttons. (A card that is failing validation but not yet disabled shows a Re-test button instead.)

What your AI can do once connected

All Telivy tools are available on every plan tier. The family covers two resource groups plus general helpers:

  • External scans — attack-surface scan runs, their findings, breach data, devices, and reports.
  • Risk assessments — deep-scan assessments and their devices (each device carries its own deep-scan findings, encryption status, open ports, and browser-saved-password inventory), plus PII summaries, scan status, monitoring settings, reports, and M365 / Google Workspace user and MFA analysis. (Breach data is surfaced through the external-scan tools.)
  • General — agent versions, finding-slug lookups, and risk progress.

Two usage notes worth passing to whoever drives the AI:

  • Report downloads are time-limited links. Report tools (PDF/DOCX/CSV/XLSX) don't return the file inline — the binary is uploaded to StackJack's storage and the tool returns a read-only download link that expires after 3 minutes. The AI (or you) must fetch the file within that window; if it expires, just run the report tool again.
  • Usage caps. Each connector subscription has a monthly tool-call allowance (currently 100 calls on Free, 5,000 on Pro, 50,000 on Business per billing cycle). There is no per-minute burst limit on your MCP calls — the monthly cap is the enforcement point. Your usage bar is on the connector card and Dashboard.

Rate limits toward Telivy

Telivy does not publish an API rate limit, so StackJack conservatively paces outbound requests to Telivy at 60 requests per minute per tenant.

Sensitive data handling

StackJack follows a strict passthrough model: connector responses go to your AI exactly as the vendor returned them, with nothing added or stripped. For Telivy this means breach records (including leaked credentials), PII summaries, and user inventories flow into the AI conversation when those tools are called. Anything an AI harness receives may be retained by that harness per its own policies — so scope which team members and MCP clients can call Telivy tools using StackJack's tool permissions, and treat Telivy tool output as confidential data in your own handling policies.

Troubleshooting

SymptomLikely cause and fix
Validation fails right after savingThe key was mistyped or truncated when pasting, or it was regenerated in Telivy after you copied it. Re-copy from Account → Integrations and save again.
Tools suddenly return authentication errorsThe key was regenerated or revoked in Telivy. Update the connector with the new key.
Connector shows DisabledThree consecutive validation failures — usually a regenerated key. Update the key via Update Credentials on the card, then Re-enable.
A report link no longer worksReport download links expire after 3 minutes. Run the report tool again to get a fresh link.

Per-user access

Telivy does not support per-user sign-in through StackJack — the connector uses one shared API key for the whole tenant, and every tool call sees everything that key sees. (Per-user connector credentials are only available for HaloPSA, NinjaOne, and N-able N-central.)

Disconnecting

Disconnect on the Telivy card deletes the stored key from Key Vault, and Telivy calls on that connection stop working immediately. Where the card holds several connections, the others keep working and the connector stays connected until you remove the last one.

Whether Telivy's tools disappear from your AI's tool list is a separate choice rather than an automatic consequence. On the last connection of a Free connector the dialog offers to remove them, with the box selected by default. On a paid connector the tools stay listed and billing continues: disconnecting does not cancel a paid subscription. The plan controls only appear while the connector is connected, so end the plan before disconnecting. On a paid connector that button reads Manage on Billing and opens this connector's removal dialog on the Billing page; a legacy website subscription still reads Cancel Plan. If you've already disconnected, save your credentials again to bring the plan controls back, then end the plan. See Disconnecting a Connector for what else a removal reaches.

If you're disconnecting for security reasons, also regenerate the key in Telivy so the old value is dead everywhere.

Telivy tools

telivy_ · 28 tools · Free 28

General

ToolWhat it does
telivy_get_agent_versions
Free · Read-only
Returns the latest published Telivy deep-scan agent versions for Windows and macOS.
telivy_get_finding_details
Free · Read-only
Looks up a finding by its short slug (e.g. "open-port", "weak-mfa") and returns the canonical name, description, risk explanation, remediation recommendation, severity, and reference links.
telivy_get_risk_progress_report
Free · Read-only
Returns a time-windowed findings progress report for an assessment, optionally comparing two timestamp groups.

External Scans

ToolWhat it does
telivy_create_external_scan
Free · Write
Create a new external (attack-surface) scan for a domain.
telivy_get_external_scan
Free · Read-only
Returns the full external-scan record including security grades, scan status, last-scan timestamp, and assessment details.
telivy_get_external_scan_breach_data
Free · Read-only
Returns dark-web/breach data exposures associated with the assessment's domain — leaked passwords, exposed accounts, breach dates, and source of disclosure.
telivy_get_external_scan_finding_detail
Free · Read-only
Returns the per-target detail records for a specific finding slug on an external scan (e.g. all hosts/ports affected by an "open-port" finding).
telivy_get_external_scan_findings
Free · Read-only
Returns all security findings discovered by the external scan (open ports, weak TLS, expired certs, exposed services, breach data, etc.).
telivy_get_external_scan_report
Free · Read-only
Generates and downloads the external scan report (PDF or DOCX).
telivy_list_external_scans
Free · Read-only
List external (attack-surface) scan assessments.
telivy_rescan_external_scan_devices
Free · Write
Marks all devices associated with the assessment for rescan.
telivy_uninstall_external_scan_devices
Free · Destructive
DESTRUCTIVE: marks all devices associated with the assessment for agent uninstall.
telivy_update_external_scan
Free · Write
Update an external scan's organization metadata (name, domain, client category/status).

Risk Assessments

ToolWhat it does
telivy_convert_to_risk_assessment
Free · Destructive
Convert a Telivy 'application' (incomplete/partial assessment) into a full risk assessment.
telivy_create_risk_assessment
Free · Write
Create a new deep-scan risk assessment.
telivy_get_risk_assessment
Free · Read-only
Returns a single risk assessment with full scan status, monitoring config, executive summary, and assessment details.
telivy_get_risk_assessment_device
Free · Read-only
Returns full details for a single deep-scan device — OS, deep-scan findings, encryption status, open ports, security grades, browser-saved passwords, and PII inventory.
telivy_get_risk_assessment_domain_change_preview
Free · Read-only
Returns a preview of what would change if the assessment's primary domain were updated — affected scans, agents, and findings.
telivy_get_risk_assessment_gws_users
Free · Read-only
Returns the Google Workspace user inventory for the assessment, including login status, last login timestamps, and 2-Step Verification enrollment per user.
telivy_get_risk_assessment_m365_users
Free · Read-only
Returns the Microsoft 365 user inventory for the assessment, including login status, MFA enrollment per user, and recent login failure events.
telivy_get_risk_assessment_pii_summary
Free · Read-only
Returns the PII exposure summary across all deep-scanned devices — counts of SSNs, credit cards, financial records, health records, etc., and per-device distribution.
telivy_get_risk_assessment_report
Free · Read-only
Generates and downloads a risk assessment report.
telivy_get_risk_assessment_scan_status
Free · Read-only
Returns scan completion status across all devices in a risk assessment — counts by status (queued, scanning, completed, failed) and per-device summaries.
telivy_list_risk_assessment_devices
Free · Read-only
List all deep-scan devices (endpoints with the Telivy agent installed) belonging to a risk assessment.
telivy_list_risk_assessments
Free · Read-only
List risk assessments (deep-scan agent-based assessments).
telivy_rescan_risk_assessment_device
Free · Write
Triggers an out-of-band rescan on a single deep-scan device.
telivy_update_risk_assessment
Free · Write
Update a risk assessment's organization metadata.
telivy_update_risk_assessment_monitoring_settings
Free · Write
Update the monitoring frequency for a risk assessment.