Huntress
Run Huntress managed security conversationally - fleet health, SOC-reviewed incident triage, usage and billing - without dashboard hopping.
Dex connects to the Huntress public API v1 so admins can run managed security in plain language - inventory the agent (endpoint) fleet and spot machines that have stopped checking in, triage SOC-reviewed incident reports and raw signals, and pull usage and billing figures. The API is read-only apart from two organization-lifecycle writes: creating a new customer partition and deleting one (deletion is irreversible and unregisters that organization's agents, so it requires approval). Available as an MSP global app: one shared API key pair on the master, with each Dex tenant scoped to its numeric Huntress Organization id, so agents, incidents, signals and reports stay locked to that customer.
What Dex does with Huntress
Dex handles both admin workflows and employee self-service — all policy-guardrailed and audit-logged.
For admins (Dex Pro)
- Inventory the Huntress agent fleet per organization and spot offline, outdated, or isolated machines using Huntress's own usage counts
- Triage incident reports worst-first by status, severity, platform, and indicator type, and read the SOC's narrative and recommended remediations in full
- Review raw pre-triage signals when asked about unreviewed detections, flagged plainly as not SOC-reviewed
- Read per-organization posture from actual_usages - billable, unresponsive, outdated, and isolated agent counts
- Pull the account record, licensed-product summary, generated reports, and account-wide billing reports (master connection only)
- Create a new Huntress organization, or delete one with approval - the only two writes the API allows
- Deploy as an MSP global app - one shared API key pair, each customer tenant scoped to its numeric Huntress Organization id
For employees (self-service)
- Check whether the machine you are using is protected by Huntress and when it last checked in
- See the agent version and which OS Huntress has on file for your machine
Just ask Dex
Your team types a request in plain language. Dex investigates, plans, and executes — with the right guardrails.
Admin prompts
- >How many agents at Contoso are offline or outdated right now?
- >Show me the open critical incident reports for Acme Corp and what Huntress recommends
- >Read incident report 48213 in full - body, details, and remediations
- >What products does our Huntress account license, and what's the platform mix across the fleet?
- >Create a Huntress organization for "Northwind Traders" with key northwind-traders
Employee prompts
- >Is Huntress installed on my laptop, and is it checking in?
- >What agent version does Huntress have on file for my machine?
Policy actions
Every action Dex can take on Huntress is declared, scoped, and guardrailed. Admins control which apply, who approves them, and whether they're limited to self-service.
| Action | What it does |
|---|---|
huntress_list_agents | List Huntress agents (endpoints) for an organization, with platform and check-in health |
huntress_view_agent | Read one Huntress agent by id - hostname, platform, version, last callback |
huntress_list_incident_reports | List Huntress incident reports, filterable by status, severity, platform, and indicator type |
huntress_view_incident_report | Read one Huntress incident report in full - body, details, and recommended remediations |
huntress_list_signals | List raw pre-triage Huntress signals for an organization |
huntress_list_reports | List generated Huntress summary reports |
huntress_view_report | Read one generated Huntress report by id |
huntress_view_organization | Read one Huntress organization by id, including per-product usage counts (billable, unresponsive, outdated, isolated agents) |
huntress_list_organizations | List every Huntress organization in the account (account-wide; refused on a tenant-scoped connection) |
huntress_view_account | Read the Huntress account record and licensed-product summary (account-wide; refused on a tenant-scoped connection) |
huntress_list_billing_reports | List Huntress billing reports (account-wide; there is no per-organization billing filter) |
huntress_create_organization | Create a new Huntress organization (customer partition). Billable, and the key slug is immutable afterwards. |
huntress_delete_organization | Delete a Huntress organization. Irreversible - removes the organization and unregisters its agents. |
How to configure Huntress
Onboarding takes minutes. Dex validates your credentials before saving them.
Setup steps
- 1In the Huntress dashboard, click your account name (top right) and open API Credentials, then create an API key pair (requires an owner/admin role).
- 2Copy the public key (starts with hk_) and the secret key (starts with hs_) - the secret is shown only once, so regenerate the pair if it is lost.
- 3In Dex, enable the Huntress integration and paste the api_key and api_secret.
- 4Leave organization_id empty on the MSP master connection for account-wide access.
- 5Dex validates the credentials with a live call to /v1/account before saving. For MSPs, map each child tenant to the numeric Organization id from GET /v1/organizations - not the organization key slug.
Credentials required
- api_key
- Huntress API public key, starts with hk_ (Huntress dashboard > account name > API Credentials)
- api_secret
- Huntress API secret key, starts with hs_ - shown once at creation; regenerate the pair if lost
- organization_id
- Numeric Huntress Organization id for this tenant. Leave empty on the MSP master for account-wide access (per-customer MSP isolation)
Requirements
- •A Huntress account with an owner/admin role able to create an API key pair
- •The Huntress API is read-only apart from organization create and delete - incident status changes, remediation approval, host isolation, and agent install/uninstall are dashboard-only
- •The organization_id must be the numeric id from GET /v1/organizations, not the organization key slug
- •For MSPs, deploy as a global app - one shared key pair on the master, each child tenant confined to its Organization id
Related integrations
- Security & Backup
CrowdStrike Falcon
Triage Falcon detections and respond to hosts conversationally - inventory sensors, isolate compromised machines, and run Real Time Response.
Learn more → - Security & Backup
DNSFilter
Run protective DNS from chat - review and change filtering policies, allow/block lists, sites, and roaming clients, with every change held for approval.
Learn more → - Security & Backup
Acronis Cyber Protect
Manage Acronis tenants, devices, backups, and protection plans from chat.
Learn more →
See Dex run Huntress
Book a 30-minute walkthrough with our team and see how autonomous IT works in your environment — or get started for free.