Skip to main content
Connector guides

Connect ThreatLocker

ThreatLocker is a Zero Trust endpoint protection platform built around deny-by-default allowlisting. StackJack connects to it through the ThreatLocker PortalAPI — the same API the ThreatLocker Portal…

Written By Christopher Scaminaci

Last updated 6 days ago

ThreatLocker is a Zero Trust endpoint protection platform built around deny-by-default allowlisting. StackJack connects to it through the ThreatLocker PortalAPI — the same API the ThreatLocker Portal itself uses — covering Application Control, application and file rules, approval requests, policies and ringfencing, network access policies, computers and computer groups, maintenance modes, override codes, Config Manager, DAC analysis, the Unified Audit, reports, organizations, and users and roles.

Connecting ThreatLocker to StackJack gives your AI assistant a broad family of tl_ MCP tools — MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:

  • Search the Unified Audit and the System Audit — every permit, deny, ringfence, and configuration event, filtered by action type, host, path, date range, and more
  • Investigate approvals — list pending approval requests, read the requested file's details, find matching applications, and pull research data
  • Inventory endpoints — search computers and check-in history, see which devices are online, and read computer groups and their members
  • Review policies — search and read policies, see which policies apply to an application, and read Config Manager policies and DAC analysis findings
  • Read organizations, reports, override codes, users, and roles across the managed organization and its children
  • Act (on Pro plans) — create and update applications, file rules, policies and network access policies, computer groups, and child organizations; approve requests; schedule agent version updates; invite users
  • Change protection state (on Pro plans) — enable or disable protection, start or end maintenance modes, deploy pending policies, restart endpoints, mint or revoke override codes, and delete applications, policies, groups, or computers

How StackJack authenticates to ThreatLocker

ThreatLocker uses a static API User token — there is no OAuth login and nothing to refresh. Authentication needs two values:

  • API User token — created by adding an API User in the ThreatLocker Portal. StackJack sends it as the request's Authorization value exactly as issued.
  • Instance URL — ThreatLocker runs many instances, and yours determines the API host. Find your instance under Help in the ThreatLocker Portal, then use the matching PortalAPI host (see Instances below).

An API User's reach is bounded by the User Roles you assign it: a role can be scoped to a single organization or to every organization you manage. Everything your AI can see or change is bounded by that role — assign the least privilege that covers the work you want StackJack to do.

Token visibility. ThreatLocker shows the generated token only while the creation panel is still open. Copy it before closing, or you'll have to reset the token to get a new one.

Expiry is an inactivity window, not a fixed lifetime. ThreatLocker renews the token's expiration each time it is used. A ThreatLocker connector that sits unused past the expiration you chose will stop working and need a new token.

Organizations and child organizations

ThreatLocker scopes every call to one managed organization — the API equivalent of switching the managed organization in the Portal. StackJack handles this in two layers:

  • The organization you enter when configuring the connector is the default for every tool call.
  • Every ThreatLocker tool also accepts an optional organization id, so your AI can target a specific child organization for a single call without changing the default. tl_search_child_organizations lists the ids available to your API User.

Getting this wrong is not a silent no-op in the other direction: pointing a call at the wrong organization either fails or succeeds against that organization. If you manage customers as child organizations, set the default deliberately.

Instances

Replace the instance label with the one shown under Help in your Portal:

InstancePortalAPI host
Ahttps://portalapi.threatlocker.com
B – Hhttps://portalapi.b.threatlocker.com … https://portalapi.h.threatlocker.com
AU1 / AE1 / CA1 / EU1 / SA1 / QA1https://portalapi.au1.threatlocker.com (and the matching regional label)
FR1 / FedRAMPhttps://portalapi.fr1.threatlocker.com or https://portalapi.threatlockerfed.com

StackJack accepts any host on ThreatLocker's own domains and rejects anything else, so a mistyped host fails immediately rather than sending your token somewhere it doesn't belong.

Before you begin

  • In StackJack: you need a role that can manage connectors (tenant Owner, a co-owner, or an Administrator).
  • In ThreatLocker: you need access to create an API User and assign it a User Role.
  • Know your instance — the label under Help in the ThreatLocker Portal.
  • Know your organization id — the GUID of the organization the connector should act on by default.
  • Outbound HTTPS (TCP 443) to your PortalAPI host.
  • If your ThreatLocker account restricts logins by IP address or geolocation, StackJack's servers must be on the allow list. StackJack does not publish its outbound addresses: open a support ticket to get the current addresses for your region before you enable the restriction, and ask again after a region move, because they change.

Step 1 — Create an API User in ThreatLocker

  1. Sign in to the ThreatLocker Portal.
  2. Open Manage → Users → API Users, then choose New API User.
  3. Assign it at least one User Role — an API User with no role cannot call anything. Scope the role to one organization, or leave the organization unselected to cover every organization you manage.
  4. Choose a token expiration. Remember it behaves as an inactivity window.
  5. Accept the EULA on behalf of the API User — ThreatLocker requires this before the token works.
  6. Copy the token while the panel is still open. If you lose it, reset the token from the API Users grid and copy the new one.

Step 2 — Find your instance and organization id

  1. Open Help in the ThreatLocker Portal and note your instance label.
  2. Build your PortalAPI host from the table above.
  3. Note the GUID of the organization StackJack should act on by default.

Step 3 — Add the credentials in StackJack

  1. In the StackJack portal, open Connectors.
  2. Find the ThreatLocker card. Click How To Connect for the same steps inline, or Configure to enter the credentials.
  3. Enter your Instance URL, the API User token, and the default organization id.
  4. Click Save.

What happens when you save

  • The token and organization id are stored encrypted in Azure Key Vault — never in the StackJack database, and never shown back to you.
  • If this is the first time you configure ThreatLocker, a Free-tier subscription for the connector is created automatically so its Free tools work right away.
  • StackJack immediately live-validates the credentials with a small read that ThreatLocker documents as needing no special permission — so a validation failure means the token or the instance is wrong, not that a role is missing. Validation never blocks the save: you'll either see a success confirmation or a "saved but validation failed" warning with the reason.
  • The connector card shows the connection and validity status from then on.

How ThreatLocker returns results

Tools return the ThreatLocker response body as-is. Two things are worth knowing:

  • Searches are paged. List and search tools take a page number and a page size. ThreatLocker doesn't publish a maximum page size, so StackJack caps how large a single page can be — enough that one call can't run away with an unbounded result set. Ask for the next page to continue through a long result.
  • The Unified Audit search has a large-result flow. Run the first search, then feed the total-item count it reports back into the search's total-rows input for later pages. Your AI does this on its own when it walks a long audit range.

Plans and available tools

  • Free includes the Unified and System Audit searches, application and file-rule reads, approval-request reads, computer and computer-group reads, policy and Config Manager reads, DAC analysis, maintenance-mode history, organization and override-code reads, reports, users and roles, and tag/agent-version lookups.
  • Pro adds actions to create and update applications, file rules, policies, network access policies, computer groups, child organizations and users; approve requests; change protection and maintenance modes; deploy policies; restart endpoints and change agent versions; mint or revoke override codes; and delete records.
  • Business offers the same tool set as Pro with a higher monthly call quota.

See the generated ThreatLocker tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.

ThreatLocker issues account-level API User tokens rather than per-user logins, so there is no per-user attribution — all AI traffic authenticates as the API User you created. Current pricing and quotas are shown in the portal's Billing page and at checkout.

Safety note — powerful tools. StackJack marks the Pro operations that are irreversible or change your security posture as destructive: deleting applications, file rules, policies, computer groups, or computers; disabling protection; starting a maintenance, monitor-only, learning, isolation, or lockdown mode; deploying policies to endpoints; restarting one computer or every computer in an organization; changing the installed agent version; moving computers between organizations; minting or revoking an override code (an override code lets someone bypass protection); and rotating an organization's auth key, which invalidates the existing key and breaks agent installs still using it. Sensitive reads that return deployment scripts or an installation auth key also require care. Whether your AI application asks you to confirm before running any of these depends on that application's own settings — see Destructive tools and confirmation. Review those settings, and scope your AI's access deliberately: use the tool selections on the MCP Setup page and the Permissions page to enable only the actions you want an AI to take.

Rate limits

ThreatLocker publishes no API rate limit. StackJack paces ThreatLocker tool calls conservatively per tenant and honors any throttling response, so a long multi-page audit read is usually just slower. Retries are bounded, so a wide enough read can still come back throttled or time out — narrow the read and honour any retry delay ThreatLocker sends. StackJack does not automatically retry a write or a protection change, so check whether one landed before you repeat it: see Retrying a failed or timed-out write.

Rotating or replacing the credentials

The API User token is the only secret. If you reset it in ThreatLocker, delete the API User, change its User Roles, or let it lapse past its inactivity window, the stored credential stops working. To restore access, open Connectors → ThreatLocker → Configure in StackJack, paste the new token, and Save.

Troubleshooting

SymptomLikely causeWhat to do
"Saved but validation failed" right after savingWrong instance host, a mis-typed token, or the EULA was never accepted for the API UserRe-check the instance under Help in the Portal, re-copy the token (reset it if you no longer have it), and confirm the EULA acceptance
Tools worked, then all of them started failingThe token was reset or deleted, or it lapsed past its inactivity windowCreate or reset the token and update it in Connectors → ThreatLocker → Configure
One tool fails with a permission error while others succeedThreatLocker returns a 401 when the API User's User Role lacks that specific operation's permissionAdd the missing permission to the API User's role. tl_get_administrator_permissions returns the API User's own effective permissions, which is the fastest way to see what's missing
Everything fails with an authorization errorThreatLocker returns a 403 when the token itself is wrong, expired, or revoked, or the instance host doesn't matchVerify the instance and re-enter the token — note that ThreatLocker's 401 and 403 meanings are the reverse of most APIs
Results come back for the wrong customerThe call used the connector's default organization instead of a child organizationPass the child organization id on the tool call, or change the default in Configure. tl_search_child_organizations lists the ids
A deployment-script tool fails with a content-type errorThreatLocker doesn't publish what these three endpoints return, and some instances may answer with a file rather than dataDownload the script from the ThreatLocker Portal instead, and let StackJack support know which instance you're on so the tool can be finished against your instance's contract
Write or action tools missing from your AI's tool listConnector is on the Free tier, or the tools aren't selected for your clientUpgrade the ThreatLocker connector plan and check your tool selections on the MCP Setup page

ThreatLocker tools

tl_ · 93 tools · Free 53 · Pro 40

Unified Audit

ToolWhat it does
tl_search_unified_audit
Free · Read-only
Search the Unified Audit — the activity log behind the Portal's Audit page.

System Audit

ToolWhat it does
tl_get_system_audit_health_center
Free · Read-only
Get the Health Center view of the System Audit — the recent-activity rollup the Portal shows over a trailing number of days.
tl_search_system_audit
Free · Read-only
Search the System Audit — the record of administrative and configuration changes in the ThreatLocker Portal.

Applications

ToolWhat it does
tl_confirm_delete_applications
Pro · Destructive
DESTRUCTIVE: step 2 of ThreatLocker's two-step application delete — confirms the deletion marked by tl_delete_applications.
tl_create_application
Pro · Write
Create a custom Application Control application.
tl_delete_applications
Pro · Destructive
DESTRUCTIVE: step 1 of ThreatLocker's two-step application delete — marks the selected applications for deletion.
tl_get_application
Free · Read-only
Get one Application Control application by its GUID, as shown on the Portal's Applications page.
tl_get_application_research_details
Free · Read-only
Get ThreatLocker's research data for one application — the vendor's own analysis shown on an application that has research available.
tl_get_matching_applications
Free · Read-only
Find existing applications that already match a requested file — the check the Portal runs when you open an Application Control approval request.
tl_list_applications_for_add_to_application
Free · Read-only
List the applications a requested file can be added to — the pick-list used in the approval-processing workflow.
tl_list_applications_for_maintenance_mode
Free · Read-only
List the applications selectable when starting a maintenance mode on a computer (the pick-list on the computer sidebar's Maintenance tab).
tl_search_applications
Free · Read-only
Search Application Control applications.
tl_update_application
Pro · Write
Update one of your organization's custom applications (name, description, OS type) — the Save action on an application's Information tab.

Application Files

ToolWhat it does
tl_create_application_file_rule
Pro · Destructive
Add a file rule to an application (the Add Rule action on its Application Files tab).
tl_delete_application_file_rule
Pro · Destructive
DESTRUCTIVE: permanently delete one file rule from an application (the trash-can action on its Application Files tab, confirmed).
tl_list_application_files
Free · Read-only
List the file rules inside one application — the Application Files tab.
tl_update_application_file_rule
Pro · Destructive
Update an existing file rule inside an application (the Save action after editing a rule).

Approval Requests

ToolWhat it does
tl_authorize_approval_request_permit
Pro · Destructive
Authorize an approval request that the Cyber Hero team escalated to a customer administrator for a decision.
tl_get_approval_request_count
Free · Read-only
Get the number of PENDING approval requests — the badge the Portal shows on the Response Center.
tl_get_approval_request_file_download_details
Free · Read-only
Get the download details ThreatLocker holds for the file behind an approval request — the metadata shown when inspecting the requested file.
tl_get_approval_request_permit_application
Free · Read-only
Get the full detail behind one approval request — what the Portal loads when you click a request in the Response Center, including the requested file's identity and the permit options available.
tl_permit_approval_request_application
Pro · Destructive
Process an Execute or Elevate approval request into a permit — the Response Center's approve action.
tl_search_approval_requests
Free · Read-only
Search Application Control approval requests (the Response Center's Approval tab).

Config Manager

ToolWhat it does
tl_list_config_manager_configurations
Free · Read-only
List the available Config Manager configurations with their categories — the settings catalog the Portal offers when creating or editing a Config Manager policy.
tl_search_config_manager_policies
Free · Read-only
Search Config Manager policies.

Computers

ToolWhat it does
tl_delete_computers
Pro · Destructive
DESTRUCTIVE: delete a computer from ThreatLocker.
tl_disable_computer_protection
Pro · Destructive
DESTRUCTIVE: disable ThreatLocker protection on one or more computers for a window.
tl_enable_computer_protection
Pro · Write
Enable (secure) ThreatLocker protection on one or more computers — the hardening direction, moving devices back to Secure.
tl_get_computer
Free · Read-only
Get one computer's editable detail by GUID — what the Portal loads when you open a device for editing (name, group, proxy settings, options).
tl_get_new_computer_defaults
Free · Read-only
Get the defaults and options the Portal offers when adding a new computer to the organization.
tl_get_sample_deployment_path
Free · Read-only
Get the sample deployment path for a brand, using an organization auth key.
tl_get_signed_deployment_script
Free · Read-only
Get the SIGNED ThreatLocker agent deployment script for a brand.
tl_get_unsigned_deployment_script
Free · Read-only
Get the UNSIGNED ThreatLocker agent deployment script for a brand.
tl_move_computers_to_organization
Pro · Destructive
DESTRUCTIVE: move computers to a different organization and computer group.
tl_remove_duplicate_computers
Pro · Destructive
DESTRUCTIVE: remove duplicate computer records in the managed organization.
tl_rescan_computer_baseline
Pro · Destructive
Trigger a baseline rescan on one or more computers, optionally enabling learning while it runs.
tl_restart_computers
Pro · Destructive
DESTRUCTIVE: flag a computer to restart.
tl_restart_organization_computers
Pro · Destructive
DESTRUCTIVE and ORG-WIDE: flag EVERY computer in the managed organization to restart.
tl_search_computers
Free · Read-only
Search computers (the Devices page).
tl_set_computer_maintenance_mode
Pro · Destructive
DESTRUCTIVE: put a computer into a maintenance mode.
tl_update_computer
Pro · Destructive
Update a computer's editable settings — name, computer group, and proxy configuration.
tl_update_computer_agent_version
Pro · Destructive
DESTRUCTIVE: change the installed ThreatLocker agent version on specific computers.

Device Activity

ToolWhat it does
tl_list_online_devices
Free · Read-only
List the devices currently online in the managed organization.
tl_search_computer_checkins
Free · Read-only
List one computer's agent check-in history.

Computer Groups

ToolWhat it does
tl_create_computer_group
Pro · Write
Create a computer group.
tl_delete_computer_group
Pro · Destructive
DESTRUCTIVE: delete a computer group.
tl_get_computer_group
Free · Read-only
Get one computer group by GUID, including its baseline, exclusion, and monitor-mode configuration.
tl_list_computer_group_options_by_organization
Free · Read-only
List the computer group dropdown options for the managed organization.
tl_list_computer_group_options_with_organization
Free · Read-only
List computer group dropdown options together with their organization.
tl_list_computer_groups_and_computers
Free · Read-only
List computer groups together with their member computers — the combined tree the Portal uses for group-and-device pickers.
tl_list_computer_groups_for_download
Free · Read-only
List the computer groups offered when downloading an agent installer — the group a newly installed device would join.
tl_list_computer_groups_for_permit_application
Free · Read-only
List the computer groups selectable when permitting an application (the group-level choice in the approval flow).
tl_search_computer_groups
Free · Read-only
Search computer groups.
tl_update_computer_group
Pro · Destructive
Update a computer group.

DAC Analysis

ToolWhat it does
tl_get_dac_analysis_item
Free · Read-only
Get one DAC analysis item by its numeric id — the detail behind a single finding returned by tl_search_dac_analysis_results.
tl_search_dac_analysis_results
Free · Read-only
Search DAC analysis results — configuration findings with their criticality.

Policies

ToolWhat it does
tl_copy_policies
Pro · Write
Copy existing policies from one scope to one or more target scopes.
tl_create_network_access_policy
Pro · Destructive
Create a Network Control access policy for a computer group.
tl_create_policy
Pro · Write
Create an Application Control policy.
tl_delete_policies
Pro · Destructive
DESTRUCTIVE: delete a policy.
tl_get_policy
Free · Read-only
Get one policy by GUID, including its conditions, schedule, and ringfencing configuration.
tl_list_policies_for_application
Free · Read-only
List the policies that reference one application — answers 'what would break if I delete or change this application'.
tl_search_policies
Free · Read-only
Search policies for a computer group.
tl_update_policy
Pro · Destructive
Update an existing Application Control policy (a PUT — it replaces the policy body).

Policy Deployment

ToolWhat it does
tl_deploy_policies
Pro · Destructive
DESTRUCTIVE and ORG-WIDE: deploy all pending policy changes to every endpoint in the managed organization.
tl_deploy_policies_for_computer
Pro · Destructive
DESTRUCTIVE: deploy pending policy changes to ONE computer — the narrower alternative to tl_deploy_policies, and the safer way to verify a policy change before rolling it out.

Maintenance Modes

ToolWhat it does
tl_create_maintenance_mode
Pro · Destructive
DESTRUCTIVE: start a maintenance mode on a computer.
tl_end_maintenance_mode
Pro · Write
End an active maintenance mode on a computer now, restoring normal enforcement.
tl_list_computer_maintenance_modes
Free · Read-only
List the maintenance modes on one computer — current and historical windows, with their types and end times.
tl_update_maintenance_mode_end_date
Pro · Destructive
Change when a computer's maintenance mode ends.

Organizations

ToolWhat it does
tl_create_child_organization
Pro · Destructive
Create a child organization (onboard a customer).
tl_get_organization_auth_key
Free · Read-only
Get the organization's agent installation auth key.
tl_list_organizations_for_move_computers
Free · Read-only
List the organizations a computer can be moved into — the destination pick-list for tl_move_computers_to_organization.
tl_rotate_organization_auth_key
Pro · Destructive
DESTRUCTIVE: rotate the organization's agent installation auth key.
tl_search_child_organizations
Free · Read-only
Search the child organizations under the managed organization — your customer list.

Override Codes

ToolWhat it does
tl_create_override_code
Pro · Destructive
DESTRUCTIVE: mint an override code — a code that lets an end user BYPASS ThreatLocker protection on the target scope.
tl_revoke_override_code
Pro · Destructive
DESTRUCTIVE: revoke override codes for the managed organization.
tl_search_override_codes
Free · Read-only
Search the override codes issued for a scope — use this to audit which protection bypasses currently exist and how long they last.

Scheduled Agent Actions

ToolWhat it does
tl_abort_scheduled_agent_action
Pro · Destructive
DESTRUCTIVE: abort a scheduled agent action.
tl_create_scheduled_agent_action
Pro · Destructive
Schedule an agent action — in practice a batched agent version rollout, and the safer alternative to forcing versions immediately.
tl_get_scheduled_agent_action
Free · Read-only
Get one scheduled agent action's full configuration by its GUID — the hydration read the Portal uses when reopening a schedule for editing.
tl_list_scheduled_action_applies_to
Free · Read-only
List the organizations, groups, and computers a scheduled agent action can target.
tl_list_scheduled_agent_actions
Free · Read-only
List the scheduled agent actions of a given type — currently only Version Update=1 is documented.
tl_search_scheduled_agent_actions
Free · Read-only
Search the detail of one scheduled agent action — its targets and their progress.

Reports

ToolWhat it does
tl_get_report_data
Free · Read-only
Get one report's data by its GUID (from tl_list_reports).
tl_list_reports
Free · Read-only
List the reports available to the managed organization.
tl_list_research_categories
Free · Read-only
List the research categories ThreatLocker classifies applications under — the vocabulary behind application research data and the category filter on application search.

Users & Roles

ToolWhat it does
tl_get_administrator_permissions
Free · Read-only
Get the effective permissions of the API User this connector authenticates as.
tl_invite_user
Pro · Destructive
Invite a user to the ThreatLocker Portal with one or more roles.
tl_list_timezones
Free · Read-only
List the timezones ThreatLocker recognizes, with their ids — the values tl_create_child_organization needs.
tl_search_user_roles
Free · Read-only
Search the organization's user roles.

Lookups

ToolWhat it does
tl_list_agent_versions
Free · Read-only
List the ThreatLocker agent versions available for deployment, as shown in the Portal's version dropdown.
tl_list_tag_options
Free · Read-only
List the tag dropdown options available in the managed organization.