blumira-mcp
Blumira MCP Server
A Model Context Protocol (MCP) server that provides AI assistants with structured access to Blumira SIEM platform data and operations.
Note: This project is maintained by Wyre Technology.
Quick Start
Claude Desktop — download, open, done:
Download
blumira-mcp.mcpbfrom the latest releaseOpen the file (double-click or drag into Claude Desktop)
Enter your Blumira JWT token when prompted
No terminal, no JSON editing, no Node.js install required.
Claude Code (CLI):
claude mcp add blumira-mcp \
-e BLUMIRA_JWT_TOKEN=your-jwt-token \
-- npx -y github:WYRE-AI/blumira-mcpSee Installation for Docker and from-source methods.
Related MCP server: abnormal-mcp
Features
🔌 MCP Protocol Compliance: Full support for MCP resources and tools
🛡️ Comprehensive SIEM Coverage: Tools spanning findings, agents/devices, users, resolutions, and MSP account management
🔍 Decision-Tree Navigation: Start with
blumira_navigateto explore domains, then dynamically load domain-specific tools🏢 MSP Multi-Tenant Support: Full MSP endpoint coverage for managing findings, agents, and users across accounts
🔒 Secure Authentication: JWT token or API key (
pax8ApiTokenV1) authentication🌐 Dual Transport: Supports both stdio (local) and HTTP Streamable (remote/Docker) transports
📦 MCPB Packaging: One-click installation via MCP Bundle for desktop clients
🐳 Docker Ready: Containerized deployment with HTTP transport and health checks
⚡ Rate Limiting: Built-in rate limiter respects Blumira API limits
🔎 Rich Filtering: Support for
.eq,.in,.gt,.lt,.contains,.regex, and negation operators
Installation
Option 1: MCPB Bundle (Claude Desktop)
The simplest method — no terminal, no JSON editing, no Node.js install required.
Download
blumira-mcp.mcpbfrom the latest releaseOpen the file (double-click or drag into Claude Desktop)
Enter your Blumira JWT token when prompted
For Claude Code (CLI), one command:
claude mcp add blumira-mcp \
-e BLUMIRA_JWT_TOKEN=your-jwt-token \
-- npx -y github:WYRE-AI/blumira-mcpOption 2: Docker
docker compose upOr pull the pre-built image:
docker run -d \
-e BLUMIRA_JWT_TOKEN=your-token \
-p 8080:8080 \
ghcr.io/wyre-ai/blumira-mcp:latestOption 3: From Source
git clone https://github.com/WYRE-AI/blumira-mcp.git
cd blumira-mcp
npm ci
npm run buildConfiguration
Variable | Description | Default |
| JWT token for authentication | — |
| Transport mode ( |
|
| HTTP server port |
|
| Auth mode ( |
|
| Log level ( |
|
Domains
The server uses decision-tree navigation. Start with blumira_navigate to pick a domain:
Domain | Tools |
findings | List findings, get finding, get finding details, resolve finding, assign owners, list/add comments |
agents | List devices, get device, list agent keys, get agent key |
users | List users |
resolutions | List available resolutions |
msp | List/get accounts, list/get/resolve findings, assign owners, comments, list devices/keys, list users |
Filtering
Blumira supports rich query filtering on list endpoints:
status.eq=10 # Exact match
severity.in=HIGH,CRITICAL # Multiple values
created_at.gt=2026-01-01 # Greater than
name.contains=malware # Substring match
!status.eq=30 # NegationPass filters as tool input parameters — the server handles query string construction.
Docker Deployment
Copy .env.example to .env and fill in your credentials:
cp .env.example .env
# Edit .env with your Blumira JWT token
docker compose up -dDevelopment
npm ci
npm run build # Build the project
npm run dev # Watch mode
npm run test # Run tests
npm run lint # Type-check
npm run clean # Remove dist/Contributing
See CONTRIBUTING.md for guidelines.
License
Apache 2.0 — Copyright WYRE Technology
This server cannot be deployed
Maintenance
Related MCP Connectors
Hosted MCP servers for MSP tools: ConnectWise, NinjaOne, Microsoft 365, SentinelOne, Pax8 and more.
An MCP server that provides an API to LLMs to manage their JumpCloud resources.
MCP server for Appcircle mobile CI/CD platform.
Cybersecurity MCP server for URL scanning, threat intelligence, and domain reputation.
Related MCP Servers
- AlicenseNot gradedqualityAmaintenanceAn MCP server for Datto BCDR (Business Continuity and Disaster Recovery), enabling management of backup jobs, restore points, and disaster recovery operations through Datto's API.Apache 2.0
- AlicenseAqualityAmaintenanceAn MCP server for Abnormal Security, enabling management of threat detection, email security cases, and AI-powered attack protection through Abnormal's API.10Apache 2.0
- FlicenseBqualityAmaintenanceAn MCP server for CIPP (Community IT Professionals Platform), enabling MSPs to manage Microsoft 365 tenants, users, policies, and security settings through CIPP's API.4711-
- AlicenseNot gradedqualityAmaintenanceAn MCP server for Blackpoint Cyber MDR platform, enabling management of security monitoring, threat detection, and incident response through Blackpoint's API.Apache 2.0