Skip to main content
Glama
Decian-Inc

connectsecure-mcp

by Decian-Inc
README.md
# ConnectSecure MCP

An MCP server exposing every operation in the supplied ConnectSecure OpenAPI specification for vulnerability management, assets, assessments, integrations, and reporting.

## Install

```bash
pip install connectsecure-mcp
```

Or, from this checkout:

```bash
pip install -e ".[dev]"
```

## Configure

```bash
export CONNECTSECURE_BASE_URL="https://your-connectsecure-api-host"
export CONNECTSECURE_ACCESS_TOKEN="your-jwt-access-token"
export CONNECTSECURE_USER_ID="your-connectsecure-user-id"
# Required only for authorize_connectsecure:
export CONNECTSECURE_CLIENT_AUTH_TOKEN="base64(tenant+client_id:client_secret)"
```

`CONNECTSECURE_BASE_URL` is required because the supplied API specification does not declare a server URL. For ordinary endpoints the server sends `Authorization: Bearer <CONNECTSECURE_ACCESS_TOKEN>` and, when configured, `X-USER-ID`. The authorization endpoint sends `Client-Auth-Token`.

## Connect an MCP client

```json
{
  "mcpServers": {
    "connectsecure": {
      "command": "connectsecure-mcp",
      "env": {
        "CONNECTSECURE_BASE_URL": "https://your-connectsecure-api-host",
        "CONNECTSECURE_ACCESS_TOKEN": "your-jwt-access-token",
        "CONNECTSECURE_USER_ID": "your-connectsecure-user-id"
      }
    }
  }
}
```

Every API operation is an MCP tool. Put URI IDs in `path_params`, filtering/pagination in `query`, required per-call HTTP headers in `headers`, and JSON payloads in `body`.

See [TOOLS.md](TOOLS.md) for the complete catalog.

## Safety

The specification includes create, update, delete, and action endpoints. Those tools make the API call immediately; agents should confirm intent before invoking them.

TDQS

C2.4/5.0

Scored across 359 tools

Disambiguation2/5

Many tools are distinguished only by long report-query route suffixes (e.g., the many application_vulnerabilities_* variants), and numerous descriptions are generic 'Retrieve records' or copy-pasted like 'Update schedule' for remove_schedule. This makes misselection highly likely despite technically unique names.

Naming Consistency3/5

Most tools follow a consistent {method}_{route} snake_case pattern with get_r_, post_w_, patch_w_, and delete_d_ prefixes. However, conventions are mixed: some routes drop the r_ prefix (get_report_queries_*), there are double verbs like get_r_user_get_users, and typos like suppres and unqouted break uniformity.

Tool Count1/5

359 tools is an extreme count for an MCP server and far beyond a well-scoped toolset; this is a raw REST API dump rather than a curated agent surface. Such a large tool list overwhelms context and makes reliable tool selection impractical.

Completeness4/5

The surface provides broad CRUD coverage for core entities such as companies, assets, credentials, integrations, and tags, plus scanning, patching, remediation, and extensive reporting queries. Minor gaps exist for some read-only subresources, but the API surface is comprehensive enough to avoid dead ends in most workflows.

Maintenance

ActivityMaintained
ResponsivenessNo issues