
Automox MCP Server
com.automoxv2.2.9更新於 Sep 29, 2026
Official MCP server for Automox. Manage devices, patches, and policies in natural language.
安裝
在 SourceWeft 中
- 開啟 儀表板中的 Automox MCP Server,將其新增到工作區。
- 為需要使用其工具的對話啟用該服務。
Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。
其他 MCP 客戶端
參照 儲存庫 中的啟動說明。
README
Automox MCP Server
[CI] [Security Scans] [Publish Release] [PyPI version]
The official MCP server for Automox. Talk to your Automox console using natural language — this MCP server connects AI assistants like Claude to your Automox environment so you can manage devices, check compliance, run policies, and more, just by asking.
[!IMPORTANT] For bug reports or feature requests, use help.automox.com or your typical escalation paths.
[!CAUTION] AI assistants can make mistakes. Responses produced by the MCP server may be incorrect or incomplete. If you see this happening consistently, please let us know.
Table of Contents
- What's New in 3.0
- Self-Hosted vs. Hosted
- Quick Start
- What Can I Ask?
- Configuration
- Security
- Privacy Policy
- Alternative Installation
- Updating
- Migrating to the Hosted Server
- Troubleshooting
- Frequently Asked Questions
- Development
- Versioning
- License
- Support
What's New in 3.0
Automox MCP Server 3.0 adds a centrally hosted option to replace the legacy self-hosted solution. The hosted server supports all the functionality you're already using, plus one new capability.
- Hosted server: Automox now runs and maintains a version of this same server for you. Nothing to install, connect your AI client to
https://console.automox.com/api/mcpwith your existing API key. See Self-Hosted vs. Hosted below. - Policy Catalog templates (hosted only): The hosted service can search Automox's library of best-practice policy templates and create a policy directly from one, so you have a starting point without building a policy from scratch. This is separate from asking about the policies already deployed in your org, this is Automox's own recommended template library.
- No capability loss: The hosted service exposes the same tool coverage you already have through this repository.
- No forced migration: This self-hosted server and the Claude Desktop extension keep working exactly as they do today. Moving to the hosted service is currently optional (but recommended), see Migrating to the Hosted Server.
- Auth is unchanged for now: Both versions use the same Automox API key. SSO is planned for a future release.
Self-Hosted vs. Hosted
Both run the same open-source server code. The difference is who installs and runs it, and one capability that's currently hosted-only.
For self-hosted setup, see Quick Start below. For the hosted server, see Migrating to the Hosted Server, which also covers connecting fresh with no prior install.
Quick Start
1. Get your Automox credentials
You need three values from the Automox Console:
Automox has two API key types, and the difference matters here:
Symptom:
403on the search tools while reads work everywhere else usually means the key, not your permissions — switch to an org-scoped key for the target org. API Key and Account UUID are always required. Org ID is recommended but optional — some tools that don't require org context will work without it.
2. Create a .env file
3. Connect to your AI assistant
Claude Desktop (recommended) — one-click MCPB install:
New: Automox MCP is now also listed directly in Claude's Connectors Directory. Open Claude Desktop, go to Settings > Connectors, and search "Automox" to connect without leaving the app. The manual steps below still work too, nothing about them has changed.
- Download the latest
automox-mcp-<version>.mcpbfrom the GitHub Releases page. - Open Claude Desktop → Settings → Extensions.
- Drag the
.mcpbfile into the Extensions window. - Paste your API key, Account UUID, and (optionally) Org ID into the prompts.
No .env file, no terminal — credentials are stored in Claude Desktop's secure config. The bundle pulls the matching automox-mcp release from PyPI on first run.
Claude Code (CLI):
Cursor / any other MCP client — add to your MCP config:
That's it. Start asking questions.
What Can I Ask?
The server exposes 130+ tools across devices, policies, patches, groups, webhooks, worklets, vulnerability sync, maintenance windows, and more. You don't need to know the tool names — just describe what you want:
For the full list of tools, parameters, and MCP resources, see the Tool Reference.
Tip: You can also ask the server itself — the
discover_capabilitiestool returns all available tools organized by domain.
Configuration
Environment Variables
Applies only to self-hosted 2.x servers. Not applicable to the hosted 3.0+ server.
Read-Only Mode
Disables all write operations. Only read-only tools are registered (85 of 133). Useful for auditing and monitoring.
Modular Loading
Load only the tool modules you need:
Available modules: audit, audit_v2, devices, device_search, policies, policy_history, users, groups, events, reports, packages, webhooks, worklets, data_extracts, vuln_sync, compound, policy_windows
Both settings can be combined:
HTTP Transport
For non-stdio deployments:
Endpoint Authentication
When deploying over HTTP or SSE, you can require authentication on the MCP endpoint (separate from the Automox API key). Two strategies are supported:
Static API keys (simple):
OAuth 2.1 / JWT (enterprise IdP integration):
Clients must include Authorization: Bearer <token> on every request. Unauthenticated requests receive 401 Unauthorized with proper WWW-Authenticate headers. No effect on stdio transport.
Security
The Automox MCP server is designed for enterprise deployment with defense-in-depth security controls.
Highlights:
- Read-only mode (
AUTOMOX_MCP_READ_ONLY) disables all 48 write tools - Module filtering (
AUTOMOX_MCP_MODULES) for least-privilege tool loading - Correlation IDs on every tool call, forwarded to Automox API as
X-Correlation-ID - Rate limiting (30 calls/60s) with token budget estimation and auto-truncation
- API key isolation — stored as private attribute with per-request auth injection (no header storage)
- Generic error responses — no internal paths, connection strings, or API keys in error output
- Prompt injection mitigation — API response sanitization with Unicode normalization, homoglyph defense, HTML tag/script stripping, and reference-style markdown stripping
- Webhook secret handling — secrets stripped from idempotency cache after creation
- Structured JSON logging (
AUTOMOX_MCP_LOG_FORMAT=json) for SIEM integration - Tool name prefixing (
AUTOMOX_MCP_TOOL_PREFIX) to prevent cross-server collisions - Sigstore-signed releases with CycloneDX SBOM
- SSRF prevention — webhook URLs validated against private/loopback IPs and cloud metadata endpoints
- MCP endpoint authentication — static API keys or OAuth 2.1/JWT with audience binding and RFC 9728 Protected Resource Metadata
- DNS rebinding protection — Origin and Host header validation on all HTTP/SSE connections per the MCP transport spec
- Security response headers —
X-Content-Type-Options,X-Frame-Options,CSP,Cache-Control: no-store,Strict-Transport-Securityon all HTTP responses - Authentication rate limiting — blocks IPs after repeated auth failures to mitigate brute-force attacks
- Remote bind protection — non-loopback HTTP/SSE binding requires explicit
--allow-remote-bindopt-in - MCP Tool Annotations on all 130+ tools —
readOnlyHint,destructiveHint,idempotentHint, andopenWorldHintper the MCP Protocol specification, enabling client-side confirmation dialogs and safety guardrails - Interactive MCP Apps (
io.modelcontextprotocol/ui) — inline review/approval surfaces for consequential flows: compliance triage, patch approval, policy blast-radius, remediation apply, and RBAC access certification. Apps-capable hosts render them inline; other hosts degrade gracefully to the structured tool output. Write-flow Apps drive the existing gated tools through the host's confirmation — no new tools, no new gates — and ship under the host's deny-all CSP (self-contained, no external/CDN loads) - 61 security hardening items (V-001 through V-182, S-001 through S-006) documented in CHANGELOG and SECURITY.md
Capability model. The server wraps 100% of the published Automox Console API and Webhooks API, with a single deliberate exception — secret-exposing endpoints are never wrapped (API-key decrypt, password-setting). Every destructive operation is either ask-first (host confirmation) or gated behind a default-off env flag. Concretely, three categorical rules:
- Secrets are never handled — the server never returns secret material and never lets the model set it. Credentials enter only via environment/config; decrypt endpoints are not wrapped, password-setting is excluded, and secret fields are redacted from every projection. This is the only intentional omission.
- Destructive operations are two-tier. Single-target, recoverable actions are ask-first (
destructiveHint: true, surfaced as a host confirmation dialog, disabled entirely by read-only mode). Operations where per-call confirmation can't protect you — fleet-scale, self-lockout, or arbitrary model-authored code execution — are gated behind explicit, default-off env flags (AUTOMOX_MCP_ALLOW_APPLY_REMEDIATION_ACTIONS,AUTOMOX_MCP_ALLOW_SPLASHTOP_BULK_INSTALL_UNINSTALL,AUTOMOX_MCP_ALLOW_DELETE_DEVICE). Device deletion is gated, not omitted.
The full coverage map, the gating principle, and every intentional omission are documented in API Coverage & Intentional Omissions.
For vulnerability reporting and the full threat model, see SECURITY.md. For deployment hardening (containers, Kubernetes, MCP gateways, TLS, authentication), see the Deployment Security Guide. Security posture is benchmarked against the Wiz MCP Security Best Practices cheat sheet.
Note: For network-accessible deployments, enable endpoint authentication (static keys via
AUTOMOX_MCP_API_KEYSor JWT viaAUTOMOX_MCP_OAUTH_ISSUER) and/or place the server behind an MCP gateway or authenticating reverse proxy. TLS termination is the deployer's responsibility.
Privacy Policy
The Automox MCP server acts as a stateless proxy between your AI assistant and the Automox API.
Data collection: The server does not collect, store, or transmit any user data beyond what is required to fulfill API requests to the Automox platform. API credentials are read from environment variables at startup and used solely for authenticating requests to the Automox API.
Data usage: All data retrieved from the Automox API is returned directly to the AI assistant that initiated the request. The server performs response sanitization (Unicode normalization, HTML stripping) for prompt injection defense, but does not analyze, aggregate, or repurpose API data for any other purpose.
Third-party sharing: The server does not share data with any third parties. It communicates exclusively with the Automox API (console.automox.com) using the credentials you provide. No telemetry, analytics, or usage data is sent to the server authors or any other service.
Data retention: The server retains no persistent data between sessions. In-memory caches (idempotency keys, rate-limit counters) are cleared when the process exits. Structured logs, when enabled, are written to stderr and are the deployer's responsibility to manage and retain.
See the Automox MCP Server Privacy Policy for the full privacy policy (mirrored in PRIVACY.md).
Alternative Installation
The Quick Start above uses uvx which requires no installation. If you prefer a persistent install:
Then set the environment variables in your shell and run automox-mcp.
Updating
If you already have the server installed, update to the latest version:
Note:
uvxautomatically refreshes its cache roughly every 7 days, so most users will pick up new releases without action. Runuvx --refreshto get the latest immediately.
Migrating to the Hosted Server
Automox MCP Server 3.0 (hosted) runs the same tools as this repository, just without a local install to maintain. Migrating is two steps: remove your local server, then connect to the hosted one. There's no in-place upgrade and nothing to convert, no config file to move and no data to port. If you've never run the Automox MCP server before, skip straight to Step 2, there's no package to install.
Step 1: Remove the local server
Claude Code:
Cursor or other config-based clients: remove the automox-mcp entry from your MCP config file. Claude Desktop extension removal steps are still being finalized and will be added here once confirmed. In the meantime, it's safe to leave the extension installed and running while you set up and test the hosted connection separately.
Step 2: Connect to the hosted server
Claude Code:
Open a new session and ask something like, "What's our compliance posture?"
MCP Inspector (for evaluation or debugging):
In the UI: Transport Type = Streamable HTTP, URL = https://console.automox.com/api/mcp, Authentication → Bearer Token = your API key (paste the raw key). Click Connect, then Tools → List Tools.
Other MCP clients (Cursor and similar), any client that supports streamable HTTP with custom headers:
Your permissions in Automox apply exactly as they do in the console and API. The MCP acts as you. Your self-hosted installation will keep working during a transition period — there's no rush to switch.
Troubleshooting
Frequently Asked Questions
Does my self-hosted 2.x server stop working? No. Your existing self-hosted installation continues to work, there's no change to it or to how you get it. The hosted service is simply a new option if you'd like to use it, on your own timeline, with no requirement to switch.
Do I lose any capabilities by moving to the hosted service? No. The hosted service runs the same tools you already have access to today.
Will I need to switch to SSO? Not yet. The hosted service uses the same API key model you use today. SSO and per-user authentication are planned for a future release, and we'll provide clear migration guidance when that happens.
I use Claude Desktop. What should I do? Keep using the Automox MCP desktop extension for now. Claude Desktop's native connector option requires OAuth, which the hosted service doesn't support yet.
Need help? Reach out through help.automox.com.
Development
Testing
Interactive debugging with MCP Inspector:
Run unit tests:
Run production smoke tests (requires Automox credentials):
MCP Scanner
Static analysis with Cisco's MCP Scanner:
Versioning
Follows Semantic Versioning. Update pyproject.toml, commit, tag (e.g., v0.1.0), and push — the release workflow publishes to PyPI automatically.
License
MIT License. See LICENSE.
Support
The official Automox MCP server. For questions, bugs, or feature requests use help.automox.com.
To report a security vulnerability, see SECURITY.md — please do not open a public issue.
來源:README.md,提交 270e892
工具
0版本歷史
1- v2.2.9最新Sep 16, 2026


