Skip to main content
Connector guides

Connect CyberFOX AutoElevate

CyberFOX AutoElevate is a privileged access management product for MSPs and lean IT teams. It removes standing local admin rights from your customers' computers, then lets a technician approve or deny…

Written By Christopher Scaminaci

Last updated About 2 hours ago

CyberFOX AutoElevate is a privileged access management product for MSPs and lean IT teams. It removes standing local admin rights from your customers' computers, then lets a technician approve or deny each request to run something as admin, with rules that decide the repeat requests for you. Each customer is a company, each company has locations, and each location has computers running the AutoElevate agent.

Connecting AutoElevate to StackJack gives your AI assistant a family of ae_ MCP tools. MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:

  • Work the approval queue: list the elevation requests waiting for a decision, read one, and approve or deny it, optionally turning the decision into an automatic rule at the computer, location, company or MSP level
  • Explain a decision: the elevation events the agent raised and the rules (auto-approve, auto-deny and audit-mode) that matched them
  • Review who held admin: elevated sessions, newest first, with the computer, the company and the scheduled length
  • Map your fleet: companies, locations and computers, including each computer's elevation mode and when it last checked in
  • Report on usage and change: the partner's usage figures (the active agent count you reconcile your CyberFOX bill against) and the audit log of user and setting changes
  • Send AutoElevate events where people work: list, create, change, delete and test the webhooks that post events to Microsoft Teams, Slack or your automation platform, and read their recent delivery attempts

How StackJack authenticates to AutoElevate

AutoElevate uses a Bearer API key that you create on a service user in the AutoElevate Admin Portal. One key covers every company you manage, so you connect AutoElevate once for your whole MSP, not once per customer. There is no client ID, no sign-in and no refresh: the key alone authenticates every call.

AutoElevate keys expire. You choose the expiration when you create the key, and CyberFOX does not publish a longest one. Choose the longest your policy allows and put a reminder on the date. An expired key stops working, StackJack switches the connection off after repeated failed checks and does not retry it, and the only fix is a new key saved in StackJack.

The Partner API is in beta. CyberFOX says it may change without notice, and it makes every request carry a fixed acknowledgment header, which StackJack sends for you. If CyberFOX changes what it accepts, some tools can fail until StackJack ships the matching change.

What you need on the AutoElevate side

  • An AutoElevate partner account. The Partner API reads the MSP you manage, so the key has to come from your own partner account. CyberFOX does not publish pricing, and no edition or plan is documented as gating the Partner API.
  • A user whose role carries the permissions you want. A key can never grant more than the role of the user it is created on.
  • The Administrator role, for webhooks. The four webhook permissions exist only on that role, and custom roles need CyberFOX Support.
  • Audit Logs enrollment, for the audit log. It is rolled out to partners gradually and is permission-based.

Steps

  1. Sign in to the AutoElevate Admin Portal. A key can never grant more than the role of the user it is created on, and the four webhook permissions exist only on the Administrator role. Use an Administrator if you want StackJack to manage webhooks. The key's permission picker only offers what that role already holds, so a permission that is missing from the picker means the role lacks it.
  2. Open a service user and add an API key. Create the key on a Service user rather than on a person, so it does not depend on one technician staying in your account.
  3. Choose the Bearer scheme. Pick the API Token (AE-BEARER) scheme. StackJack does not sign requests, so an HMAC key (the one that starts with aeh_) is refused with a 401. CyberFOX's own articles disagree on whether Bearer is supported, and StackJack has not checked that against a live account. This setup follows the current API reference, which recommends Bearer. If Test Connection answers a 401 on a key you just made, check the scheme first.
  4. Tick the permissions. Every key needs computerView, because Test Connection reads the partner's usage figures through it. Then add the read permission for each area you want your AI to see: companyView, locationView, requestView, elevatedSessionView, eventView, ruleView and auditLogView. Add requestEdit if your AI should approve or deny requests, and webhookView, webhookAdd, webhookEdit and webhookDelete if it should manage webhooks. CyberFOX publishes the picker labels of five of these: companyView appears as Read companies, webhookView as Read webhooks, webhookAdd as Create webhooks, webhookEdit as Update and test webhooks (one permission that covers both changing a webhook and sending its test message) and webhookDelete as Delete webhooks. It does not publish the labels of the others, so match those by meaning.
  5. Set the longest expiration your policy allows. AutoElevate offers presets down to 15 minutes. Vendor advice favors short keys for ad-hoc use, but a connection that stops every day is not useful.
  6. Copy the key. AutoElevate shows it once.
  7. Enter it in StackJack. Open Connectors, choose CyberFOX AutoElevate, paste the key and save. The address is fixed, so there is nothing else to enter. A key that starts with aeh_ is flagged on the form before you save.
  8. Test the connection. StackJack reads the partner's usage figures, which proves the key and the computerView permission without changing anything.

The key is stored encrypted and is not shown again. Enter it again whenever you edit this connector.

What to know before your AI uses this connector

Approving and denying change real machines

Approving a request grants admin (or user) elevation on a customer's computer, and it cannot be undone. Only a request that is still pending can be decided: if someone or something decided it first, AutoElevate refuses and the tool says the request is no longer pending. Both tools can also create a rule from the decision. A rule at the MSP level applies to every company you manage, so one approval can become a standing auto-approval, or one denial a standing auto-deny, across all of your customers. A denial reason is shown to the end user on their own computer, so the AI is writing to a person's screen.

Both tools are labeled as changes that need approval. An AI assistant that honors that label shows you the action and waits for you to confirm. The confirmation is the assistant's, not StackJack's. A StackJack automation cannot run one of these at all until somebody signs off that it may take consequential actions on its own.

Webhooks send your event stream somewhere

A webhook sends the events you subscribe to, for one company or for all of them, to an address you choose. It is live the moment it is created and it outlives the key that created it. Creating, changing and deleting a webhook are labeled as changes that need approval, and testing one sends a single test message to the destination, for example a Teams or Slack channel.

  • The signing secret is shown once. The create answer carries the webhook's signing secret and AutoElevate cannot show it again. Record it from that answer. Teams and Slack deliveries are not signed.
  • The address is write-only. For Teams, Slack and most automation platforms the address itself is the credential that posts to the channel, so AutoElevate only ever shows its origin back. StackJack never records the address or the secret, and it refuses to turn an oversized webhook answer into a stored file.
  • Changing the address. To keep the stored address, leave it out of the change. Sending back the shortened form a read returns is rejected. To widen a webhook to every company, pass the text null as the company.
  • Rotating the secret. The secret cannot be changed. Create a new webhook and delete the old one.
  • Brand-new webhooks. A read, change or test within a few seconds of creating a webhook can answer "not found". Wait a moment and retry once.
  • Deleting is soft. Deliveries stop within seconds, though attempts already in flight can keep retrying for several minutes, and the delivery logs are no longer reachable afterwards.

One key covers the whole MSP, and it can be narrowed

Lists cover every company the key can see, and most take an optional company id to narrow them. A key that was restricted to some companies sees only those companies, and AutoElevate may answer "not permitted" instead of "not found" for something outside them. Such a key also cannot create a webhook that covers every company, or widen one to every company: AutoElevate answers "not permitted" until the webhook names a company the key can access.

The computer list is the active fleet

The computer list only holds machines that checked in during the last 30 days. A machine missing from it may still exist. A lookup of a computer that does not exist is reported as not found.

Time filters use epoch milliseconds

The elevation requests, elevation events and audit log take a start and an end as a whole number of milliseconds since 1970, not seconds and not a date. Your AI knows this from the tool descriptions.

Lists come in pages

Most lists take a page size up to 200 and an offset. Total counts read zero once the offset is past the end, so a loop should stop when a page comes back empty. The audit log pages with a cursor instead: pass the cursor from each answer back for the next page. Webhook delivery logs are never paged: you get the 50 most recent attempts.

The audit log needs a rollout

The audit log covers user and setting changes for the last 30 days. AutoElevate is rolling it out to partners gradually, so a correctly scoped key can still be refused until CyberFOX enrolls your account. The entries carry a before and after copy of the changed record, and CyberFOX does not specify the fields inside it.

Rate limits are shared with your own scripts

AutoElevate allows about 20 requests a minute for each route across your whole MSP. Any other script or tool using the Partner API on your account draws on the same budget, and StackJack keeps itself below it and backs off when AutoElevate asks. Filter lists by company instead of paging the whole MSP.

Plans

Reading is free. Approving, denying and every webhook change need the Pro plan on this connector.

Tool reference

See the generated CyberFOX AutoElevate tool reference for the current inventory, plan assignment, input schemas and destructive-action labels.

AutoElevate answers some changes slowly or not at all when it is busy, and pacing smooths a burst without guaranteeing that every call arrives. Check whether a change landed before repeating it. See Retrying a failed or timed-out write.

Troubleshooting

"CyberFOX AutoElevate rejected the API key" (401). The key is missing, wrong, expired or revoked, or it is an HMAC key. Keys expire on the date chosen when they were created. Create a new Bearer key, saved with the permissions your tools need, and enter it in StackJack. If the connection was switched off after repeated failures, saving a new key brings it back.

"CyberFOX AutoElevate accepted the key but refused the connection check" (403). The key works but lacks the computerView permission, or it is not scoped to an MSP. Edit the key's permissions, or create a new key with computerView ticked, and save it again. This does not count toward switching the connection off.

"The key lacks the ... permission this action needs" (403). Each tool names the permission it needs in its description, and the error names the one that is missing. Four things look alike: a missing permission, a key restricted to certain companies asking for something outside them, a webhook action on a key that is not on an Administrator's service user, and a key restricted to certain companies creating or changing a webhook so that it covers every company (name a company for the webhook, or use a key whose user can see every company). The audit log can also be refused until CyberFOX enrolls your account in its Early Access rollout.

"That elevation request is no longer PENDING" (409). Someone or something decided the request first: another technician, a rule, or the end user withdrawing it. Read it again to see its current state.

"CyberFOX AutoElevate did not find that record" (404). Check the id with the matching list tool. A webhook created moments ago can answer 404 for a few seconds.

"CyberFOX AutoElevate refused a request header" (400). This is a StackJack-side problem, not a problem with your key, and there is nothing for you to change. The beta API may have changed what it accepts. Contact support if it persists for more than a day.

"CyberFOX AutoElevate is rate limiting requests" (429). This is transient. Wait a few seconds and try again, and filter lists by company.

The connector worked and then stopped, with no change on your side. The most likely cause is an expired key. Check the expiry date of the key in the AutoElevate Admin Portal.

CyberFOX AutoElevate tools

ae_ · 23 tools · Free 17 · Pro 6

Account and Audit

ToolWhat it does
ae_get_usage
Free · Read-only
Get the partner's usage: the MSP's id and name, whether application blocking and just-in-time admin login are in use on any computer, and the number of agents seen in the last 30 days (a periodically refreshed snapshot, not a live count).
ae_list_audit_logs
Free · Read-only
List audit log entries for the MSP: user and setting changes from the last 30 days only.

Companies and Computers

ToolWhat it does
ae_get_company
Free · Read-only
Get one company by id.
ae_get_computer
Free · Read-only
Get one computer by id.
ae_get_location
Free · Read-only
Get one location by id.
ae_list_companies
Free · Read-only
List the customer companies the key can see.
ae_list_computers
Free · Read-only
List computers.
ae_list_locations
Free · Read-only
List locations across the companies the key can see, oldest first.

Elevation

ToolWhat it does
ae_approve_elevation_request
Pro · Destructive
DESTRUCTIVE: approve a pending elevation request.
ae_deny_elevation_request
Pro · Destructive
DESTRUCTIVE: deny a pending elevation request.
ae_get_elevated_session
Free · Read-only
Get one elevated session by id.
ae_get_elevation_request
Free · Read-only
Get one elevation request by id.
ae_list_elevated_sessions
Free · Read-only
List elevated technician sessions, newest first: who held admin on which machine and for how long.
ae_list_elevation_events
Free · Read-only
List elevation events the AutoElevate agent emitted, for the whole MSP: why something was blocked or auto-approved, and which rule matched.
ae_list_elevation_requests
Free · Read-only
List elevation requests: the asks end users make to run something as admin.
ae_list_elevation_rules
Free · Read-only
List elevation rules: auto-approval, auto-deny and audit-mode (ignore) rules, each applying at one level (msp, company, location or computer).

Webhooks

ToolWhat it does
ae_create_webhook
Pro · Destructive
DESTRUCTIVE: create a webhook.
ae_delete_webhook
Pro · Destructive
DESTRUCTIVE: delete a webhook.
ae_get_webhook
Free · Read-only
Get one webhook configuration by id.
ae_list_webhook_delivery_logs
Free · Read-only
List the most recent delivery attempts for a webhook, newest first, to debug an endpoint that is not receiving events.
ae_list_webhooks
Free · Read-only
List the MSP's webhook configurations, newest first.
ae_test_webhook
Pro · Write
Send ONE test delivery to a webhook and report whether the receiving endpoint accepted it (success true for a 2xx).
ae_update_webhook
Pro · Destructive
DESTRUCTIVE: update a webhook.