Connect Field Effect
Field Effect (its product is Field Effect MDR, which many MSPs still call Covalence) is a managed detection and response service. Its agent runs on your clients' endpoints, and its security operations…
Written By Christopher Scaminaci
Last updated About 2 hours ago
Field Effect (its product is Field Effect MDR, which many MSPs still call Covalence) is a managed detection and response service. Its agent runs on your clients' endpoints, and its security operations team watches them around the clock. Most MSPs resell it as the endpoint and cloud protection layer under their own service.
Connecting Field Effect to StackJack gives your AI assistant a small family of fe_ MCP tools. MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:
- Find your clients - every client organization your key can see, with the ids the other questions need
- Review your devices - the endpoints Field Effect protects, with their risk level and score, narrowed to one client or one hostname, plus the antivirus status Field Effect has recorded for a device
- Follow response activity - Active Response actions, such as a device being isolated
- Check agent protection - which endpoints carry a feature override, for example agent protection switched off
- Change agent protection (on Pro plans) - create or update an override on one endpoint
- Prepare an installer (on Pro plans) - generate an agent installer bundle for one client organization
How StackJack authenticates to Field Effect
Field Effect gives you a single API key. You create it yourself in the Field Effect portal and paste it into StackJack. There is no client ID, no second secret, nothing to renew on a schedule, and no web address to enter: Field Effect is one global service.
Use a key from a full administrator
A Field Effect API key acts as the portal account that created it. Field Effect support can lock an account down to the agent installer endpoints only, which is how some MSPs hand a key to a deployment script. A key from such an account passes StackJack's connection test, because the installer needs the organization list too, and then every other question is refused. If a connection tests green but cannot list devices, the account is almost certainly restricted. Create the key from a full administrator account instead.
Steps
- Sign in to the Field Effect MDR Portal (or to Vision) as a full administrator.
- Open Account Settings and select the Sign in & Security tab. In Vision, open Account Settings from the sidebar.
- Create the key. In the API Keys card, choose Create API Key (Vision calls it Generate API Key), give it a memorable name such as StackJack, and choose Create.
- Copy it now. Field Effect shows the full key only once. Treat it like a password: anyone holding it can read your clients' device data.
- Paste it into StackJack. Open Connectors, choose Field Effect, and paste the key. Paste the key only, without the word Bearer in front of it: StackJack adds that itself. There is nothing else to enter.
- Run a Test Connection. StackJack checks the key by listing the organizations it can see, which reads no device data and changes nothing.
Field Effect lets you deactivate or delete a key at any time from the same card. A connection that worked yesterday and now fails with an authorization error usually means the key was switched off. Create a new key and paste it again.
What to know before your AI uses this connector
One partner key covers every client
If your key belongs to a partner account, it sees every client organization under it, so one StackJack connection covers your whole book. Questions that can be narrowed to one client take that client's organization id, and the organization list is where you get it. A key from a direct customer's own account should list only that customer's organization, but Field Effect does not document that case, so the organization list is the place to check what a key really sees.
The ids come from the lists
A device is identified by an opaque id, not its hostname. Ask for the device list first, then use the id from the answer for the antivirus read and for the override tools. An override has its own id, which the override list returns.
Switching agent protection off is the risky tool
Field Effect's own uninstall script creates an override that sets agent protection to Disabled, which turns off the agent's tamper protection on that endpoint so it can be removed. Both override tools are marked destructive for that reason: on a live, monitored device it leaves the agent open to being stopped, and it can undo the protection your client is paying for. Field Effect documents only the Disabled value, so that is the only value StackJack's description names.
Whether your AI application asks you to confirm before running a destructive tool depends on that application's own settings. See Destructive tools and confirmation. Review that setting before you let an assistant near the override tools.
The installer answer is a credential
The installer tool returns a download link and the name of the zip it points to. The zip holds the organization's agent enrollment key, so anyone with the link can fetch an installer and enroll a machine into that client. StackJack returns the answer to your assistant only and never turns it into a stored file link. Treat it as a credential: do not paste it into tickets or chat. Generating an installer changes nothing on any device.
The three writes are built from Field Effect's public descriptions
Field Effect publishes its API reference only inside its portal, so StackJack builds the two override tools and the installer tool from Field Effect's own public installer script and its help articles. The values the script uses are the ones StackJack documents: the Disabled protection setting, the 64 bit and 32 bit architectures, and the Windows platform. If Field Effect refuses a value you expected to work, read its response text and tell StackJack support, so the shape can be corrected.
Alerts, reports and vulnerability exports are not here yet
Field Effect names alert objects (it calls them AROs), SEAS reports and vulnerability exports as things its API can do, but it does not publish how to ask for them outside the portal. They are not part of this connector. What is here is the device, organization, Active Response and agent protection side.
Lists come back in pages
The device and Active Response lists answer one page at a time. Ask for a page number from 1 and a page size of up to 100, and keep going while the answer says there is another page. Field Effect does not publish a maximum, so 100 is StackJack's own ceiling, and Field Effect may choose the page size itself. Narrow a device list to one client with its organization id instead of paging through your whole book.
Plans and limits
Reading is available on the Free tier. Creating or updating an override and generating an installer are Pro. Business reaches the same tools as Pro and differs by monthly call quota.
See the generated Field Effect tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.
Field Effect publishes no rate limit, so StackJack paces requests conservatively and backs off on its own if Field Effect throttles, which usually makes a large read slower rather than failed. If your Field Effect account limits API access to approved IP addresses, ask StackJack support, by ticket, for the addresses to allow.
Several connections
If you hold keys for separate Field Effect accounts, add one connection per account from the connector's card, name each one after the account, and your AI names it on each call. Omit the name and the call runs against your default connection. See Several connections of one connector.
Troubleshooting
"Field Effect did not receive the API key (400)" - the connection sent no key, or the value was malformed. Open the connector, paste the key again without the word Bearer in front of it, and save.
"Field Effect rejected the API key (401)" - the key is wrong, was deleted, or was deactivated in the portal. Check the toggle on the key's card first, because a switched-off key looks exactly like a wrong one. Create a new key and paste it again.
"This key's account is restricted (403)" - the key is live, but the account that created it cannot use that part of the API. Create the key from a full administrator account.
"Field Effect returned not-found (404)" - the organization, device or override id does not exist or this key cannot see it. List first and use the id from the answer, and remember a device id is an opaque value, not the hostname.
An antivirus read comes back as an empty object - Field Effect has no antivirus data recorded for that device. It is not an error.
A write is refused (400 or 422) - Field Effect did not accept an argument. Read its response text for which one, and see the note above about how these three tools are built.
The connection tests green but every other question fails - the key usually belongs to a restricted account. See the first section on this page.
Field Effect tools
fe_ · 8 tools · Free 5 · Pro 3
Organizations
Endpoint Devices
Active Response
Endpoint Feature Overrides
Agent Installer
Was this helpful?
More in Connector guides
Connect Acronis Cyber Protect CloudConnect Action1Connect AddigyConnect AlertOpsStill need help? Ask the team