Connect ThreatLocker
ThreatLocker is a Zero Trust endpoint protection platform built around deny-by-default allowlisting. StackJack connects to it through the ThreatLocker PortalAPI — the same API the ThreatLocker Portal…
Written By Christopher Scaminaci
Last updated 6 days ago
ThreatLocker is a Zero Trust endpoint protection platform built around deny-by-default allowlisting. StackJack connects to it through the ThreatLocker PortalAPI — the same API the ThreatLocker Portal itself uses — covering Application Control, application and file rules, approval requests, policies and ringfencing, network access policies, computers and computer groups, maintenance modes, override codes, Config Manager, DAC analysis, the Unified Audit, reports, organizations, and users and roles.
Connecting ThreatLocker to StackJack gives your AI assistant a broad family of tl_ MCP tools — MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:
- Search the Unified Audit and the System Audit — every permit, deny, ringfence, and configuration event, filtered by action type, host, path, date range, and more
- Investigate approvals — list pending approval requests, read the requested file's details, find matching applications, and pull research data
- Inventory endpoints — search computers and check-in history, see which devices are online, and read computer groups and their members
- Review policies — search and read policies, see which policies apply to an application, and read Config Manager policies and DAC analysis findings
- Read organizations, reports, override codes, users, and roles across the managed organization and its children
- Act (on Pro plans) — create and update applications, file rules, policies and network access policies, computer groups, and child organizations; approve requests; schedule agent version updates; invite users
- Change protection state (on Pro plans) — enable or disable protection, start or end maintenance modes, deploy pending policies, restart endpoints, mint or revoke override codes, and delete applications, policies, groups, or computers
How StackJack authenticates to ThreatLocker
ThreatLocker uses a static API User token — there is no OAuth login and nothing to refresh. Authentication needs two values:
- API User token — created by adding an API User in the ThreatLocker Portal. StackJack sends it as the request's
Authorizationvalue exactly as issued. - Instance URL — ThreatLocker runs many instances, and yours determines the API host. Find your instance under Help in the ThreatLocker Portal, then use the matching PortalAPI host (see Instances below).
An API User's reach is bounded by the User Roles you assign it: a role can be scoped to a single organization or to every organization you manage. Everything your AI can see or change is bounded by that role — assign the least privilege that covers the work you want StackJack to do.
Token visibility. ThreatLocker shows the generated token only while the creation panel is still open. Copy it before closing, or you'll have to reset the token to get a new one.
Expiry is an inactivity window, not a fixed lifetime. ThreatLocker renews the token's expiration each time it is used. A ThreatLocker connector that sits unused past the expiration you chose will stop working and need a new token.
Organizations and child organizations
ThreatLocker scopes every call to one managed organization — the API equivalent of switching the managed organization in the Portal. StackJack handles this in two layers:
- The organization you enter when configuring the connector is the default for every tool call.
- Every ThreatLocker tool also accepts an optional organization id, so your AI can target a specific child organization for a single call without changing the default.
tl_search_child_organizationslists the ids available to your API User.
Getting this wrong is not a silent no-op in the other direction: pointing a call at the wrong organization either fails or succeeds against that organization. If you manage customers as child organizations, set the default deliberately.
Instances
Replace the instance label with the one shown under Help in your Portal:
StackJack accepts any host on ThreatLocker's own domains and rejects anything else, so a mistyped host fails immediately rather than sending your token somewhere it doesn't belong.
Before you begin
- In StackJack: you need a role that can manage connectors (tenant Owner, a co-owner, or an Administrator).
- In ThreatLocker: you need access to create an API User and assign it a User Role.
- Know your instance — the label under Help in the ThreatLocker Portal.
- Know your organization id — the GUID of the organization the connector should act on by default.
- Outbound HTTPS (TCP 443) to your PortalAPI host.
- If your ThreatLocker account restricts logins by IP address or geolocation, StackJack's servers must be on the allow list. StackJack does not publish its outbound addresses: open a support ticket to get the current addresses for your region before you enable the restriction, and ask again after a region move, because they change.
Step 1 — Create an API User in ThreatLocker
- Sign in to the ThreatLocker Portal.
- Open Manage → Users → API Users, then choose New API User.
- Assign it at least one User Role — an API User with no role cannot call anything. Scope the role to one organization, or leave the organization unselected to cover every organization you manage.
- Choose a token expiration. Remember it behaves as an inactivity window.
- Accept the EULA on behalf of the API User — ThreatLocker requires this before the token works.
- Copy the token while the panel is still open. If you lose it, reset the token from the API Users grid and copy the new one.
Step 2 — Find your instance and organization id
- Open Help in the ThreatLocker Portal and note your instance label.
- Build your PortalAPI host from the table above.
- Note the GUID of the organization StackJack should act on by default.
Step 3 — Add the credentials in StackJack
- In the StackJack portal, open Connectors.
- Find the ThreatLocker card. Click How To Connect for the same steps inline, or Configure to enter the credentials.
- Enter your Instance URL, the API User token, and the default organization id.
- Click Save.
What happens when you save
- The token and organization id are stored encrypted in Azure Key Vault — never in the StackJack database, and never shown back to you.
- If this is the first time you configure ThreatLocker, a Free-tier subscription for the connector is created automatically so its Free tools work right away.
- StackJack immediately live-validates the credentials with a small read that ThreatLocker documents as needing no special permission — so a validation failure means the token or the instance is wrong, not that a role is missing. Validation never blocks the save: you'll either see a success confirmation or a "saved but validation failed" warning with the reason.
- The connector card shows the connection and validity status from then on.
How ThreatLocker returns results
Tools return the ThreatLocker response body as-is. Two things are worth knowing:
- Searches are paged. List and search tools take a page number and a page size. ThreatLocker doesn't publish a maximum page size, so StackJack caps how large a single page can be — enough that one call can't run away with an unbounded result set. Ask for the next page to continue through a long result.
- The Unified Audit search has a large-result flow. Run the first search, then feed the total-item count it reports back into the search's total-rows input for later pages. Your AI does this on its own when it walks a long audit range.
Plans and available tools
- Free includes the Unified and System Audit searches, application and file-rule reads, approval-request reads, computer and computer-group reads, policy and Config Manager reads, DAC analysis, maintenance-mode history, organization and override-code reads, reports, users and roles, and tag/agent-version lookups.
- Pro adds actions to create and update applications, file rules, policies, network access policies, computer groups, child organizations and users; approve requests; change protection and maintenance modes; deploy policies; restart endpoints and change agent versions; mint or revoke override codes; and delete records.
- Business offers the same tool set as Pro with a higher monthly call quota.
See the generated ThreatLocker tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.
ThreatLocker issues account-level API User tokens rather than per-user logins, so there is no per-user attribution — all AI traffic authenticates as the API User you created. Current pricing and quotas are shown in the portal's Billing page and at checkout.
Safety note — powerful tools. StackJack marks the Pro operations that are irreversible or change your security posture as destructive: deleting applications, file rules, policies, computer groups, or computers; disabling protection; starting a maintenance, monitor-only, learning, isolation, or lockdown mode; deploying policies to endpoints; restarting one computer or every computer in an organization; changing the installed agent version; moving computers between organizations; minting or revoking an override code (an override code lets someone bypass protection); and rotating an organization's auth key, which invalidates the existing key and breaks agent installs still using it. Sensitive reads that return deployment scripts or an installation auth key also require care. Whether your AI application asks you to confirm before running any of these depends on that application's own settings — see Destructive tools and confirmation. Review those settings, and scope your AI's access deliberately: use the tool selections on the MCP Setup page and the Permissions page to enable only the actions you want an AI to take.
Rate limits
ThreatLocker publishes no API rate limit. StackJack paces ThreatLocker tool calls conservatively per tenant and honors any throttling response, so a long multi-page audit read is usually just slower. Retries are bounded, so a wide enough read can still come back throttled or time out — narrow the read and honour any retry delay ThreatLocker sends. StackJack does not automatically retry a write or a protection change, so check whether one landed before you repeat it: see Retrying a failed or timed-out write.
Rotating or replacing the credentials
The API User token is the only secret. If you reset it in ThreatLocker, delete the API User, change its User Roles, or let it lapse past its inactivity window, the stored credential stops working. To restore access, open Connectors → ThreatLocker → Configure in StackJack, paste the new token, and Save.
Troubleshooting
ThreatLocker tools
tl_ · 93 tools · Free 53 · Pro 40
Unified Audit
System Audit
Applications
Application Files
Approval Requests
Config Manager
Computers
Device Activity
Computer Groups
DAC Analysis
Policies
Policy Deployment
Maintenance Modes
Organizations
Override Codes
Scheduled Agent Actions
Reports
Users & Roles
Lookups
More in Connector guides
Connect Acronis Cyber Protect CloudConnect Action1Connect AddigyConnect AlertOpsStill need help? Ask the team