avanan-mcp
# Avanan (Check Point) MCP Server
[](https://opensource.org/licenses/Apache-2.0)
[](https://nodejs.org/)
A Model Context Protocol (MCP) server for Check Point Avanan (Harmony Email & Collaboration). Enables AI assistants to manage security events, investigate threats, and handle multi-tenant MSP operations across your email security environment.
This is a [Model Context Protocol (MCP)](https://modelcontextprotocol.io/) server that connects Claude (or any MCP-compatible AI) to your Check Point Avanan environment.
> **Part of the [MSP Claude Plugins](https://github.com/WYRE-AI) ecosystem** — a growing suite of AI integrations for the MSP stack. Built by MSPs, for MSPs.
## Features
- **Interactive Security Event Card (MCP Apps)**: `hec_get_event` renders as a read-only interactive card in MCP Apps hosts (Claude Desktop/web) showing severity, state, platform, and remediation status; neutral by default, brandable via `window.__BRAND__` injection or `MCP_BRAND_*` env vars; plain-JSON behavior is unchanged in other hosts
## Installation
```bash
npm install @wyre-ai/avanan-mcp
```
## Configuration
Set the following environment variables:
| Variable | Required | Description |
|----------|----------|-------------|
| `CHECKPOINT_CLIENT_ID` | Yes | Your Checkpoint/Avanan OAuth2 client ID |
| `CHECKPOINT_CLIENT_SECRET` | Yes | Your Checkpoint/Avanan OAuth2 client secret |
| `CHECKPOINT_REGION` | No | API region (default: us) |
| `MCP_TRANSPORT` | No | Transport mode: stdio (default) or http |
## Usage
### Running with Claude Desktop
Add to your Claude Desktop `claude_desktop_config.json`:
```json
{
"mcpServers": {
"avanan-mcp": {
"command": "npx",
"args": ["@wyre-ai/avanan-mcp"],
"env": {
"CHECKPOINT_CLIENT_ID": "your-checkpoint-client-id"
"CHECKPOINT_CLIENT_SECRET": "your-checkpoint-client-secret"
}
}
}
}
```
### Running with Claude Code (CLI)
```bash
claude mcp add avanan-mcp \
-e CHECKPOINT_CLIENT_ID=your-value \
-e CHECKPOINT_CLIENT_SECRET=your-value \
-- npx -y @wyre-ai/avanan-mcp
```
### Docker
```bash
docker build -t avanan-mcp .
docker run \
-e CHECKPOINT_CLIENT_ID=your-value \
-e CHECKPOINT_CLIENT_SECRET=your-value \
-p 8080:8080 avanan-mcp
```
## Available Domains
### Events
Security event retrieval and investigation
### Actions
Take action on threats (quarantine, release, etc.)
### Exceptions
Manage email exceptions and allowlists
### Search
Search across email security data
## Development
```bash
# Clone the repository
git clone https://github.com/WYRE-AI/avanan-mcp.git
cd avanan-mcp
# Install dependencies
npm install
# Build
npm run build
# Run tests
npm test
```
## Contributing
Contributions are welcome! Please see [CONTRIBUTING.md](CONTRIBUTING.md) if present, or open an issue to discuss changes.
## License
Licensed under the Apache License, Version 2.0. See [LICENSE](LICENSE) for details.
TDQS
Scored across 13 tools
Each tool targets a distinct resource and action: events vs emails vs exceptions, with separate query/get, quarantine/restore, and CRUD operations. There is no ambiguity between tools, as their purposes are clearly differentiated.
All tools follow a consistent 'hec_verb_noun' snake_case pattern. Verbs like query/get/search, quarantine/restore, and list/add/update/delete are used predictably across the tool set.
With 13 tools, the set is well-scoped for a security email management server. It covers events, emails, quarantine actions, task tracking, and exception management without being overloaded or too sparse.
The tool surface covers querying, retrieving, quarantining, and restoring events and emails, plus full CRUD for exceptions. A minor gap is the lack of tools to update event properties (e.g., severity), but the core workflows are complete.