Castle

io.usefulapiv1.0.0Updated Sep 29, 2026

Investigate security events and manage the allow/deny lists an analyst acts on.

VerifiedStreamable HTTPWeb executableSecurity & Monitoring

Overview

AI-generated overview

A hosted MCP server that lets an assistant search security events and manage the allow and deny lists an analyst works from.

What it does
Castle exposes read tools for security work: fetching the event schema, searching and grouping security events, and searching, counting, and reading lists and their items. It also exposes write tools that create or update lists, add list items, edit an item's comment, and archive or unarchive items. It is a hosted endpoint, so no local package is installed.
When to use it
Use it when an assistant should help triage security events or maintain the allow and deny lists an analyst acts on, without leaving the chat client. It suits analysts who already work with Castle data and want conversational search and list maintenance.
Requirements
A remote MCP endpoint at no local runtime or package. Castle credentials are pasted on first connect and stored per user. The free plan allows 100 tool calls per month; Pro is $9 per month or $90 per year for unlimited calls.
Before you install
Write tools create or update lists, add items, edit comments, and archive or unarchive items, so changes should be confirmed before they run. Castle credentials are entered on first connect and stored per user. The free plan caps usage at 100 tool calls per month, and Pro is a paid subscription.

Installation

In SourceWeft

  1. Open Castle in the dashboard and add it to a workspace.
  2. Enable the server for the chats that should use its tools.

Web executable via Streamable HTTP. Remote servers run from the web runtime once configured in a workspace.

Other MCP clients

Add this to your client's mcpServers config.

{
  "mcpServers": {
    "castle": {
      "type": "http",
      "url": "https://castle.usefulapi.io/mcp"
    }
  }
}

README

Castle MCP by usefulapi

Investigate security events and manage the allow/deny lists an analyst acts on. Hosted, no local install.

Live endpoint: https://castle.usefulapi.io/mcp · Homepage: https://usefulapi.io

Add to Claude

json
{  "mcpServers": {    "castle": {      "url": "https://castle.usefulapi.io/mcp"    }  }}

On first connect you'll paste your Castle credentials. They are validated, stored per-user, and scoped to you — no keys in config files.

Tools

ToolTypeWhat it does
castle_get_events_schemareadGet the event schema
castle_search_eventsreadSearch security events
castle_group_eventsreadGroup security events
castle_search_listsreadSearch lists
castle_get_listreadGet one list
castle_search_list_itemsreadSearch items in a list
castle_count_list_itemsreadCount items in a list
castle_get_list_itemreadGet one list item
castle_create_listwriteCreate a list
castle_update_listwriteUpdate a list
castle_create_list_itemwriteAdd an item to a list
castle_update_list_itemwriteUpdate a list item's comment
castle_archive_list_itemwriteArchive a list item
castle_unarchive_list_itemwriteUnarchive a list item

read tools are read-only; write tools mutate data (clients should confirm them); meta tools report usage or manage your subscription.

Pricing

PlanPriceLimit
Free$0100 tool calls / month
Pro$9/mo or $90/yr (2 months free)Unlimited

License

MIT

Source: servers/castle/README.md at commit e28f9c1

Tools

0
Tool metadata has not been indexed yet.

Version history

1
  1. v1.0.0LatestSep 29, 2026