Skip to main content
Glama
WYRE-AI

datto-saas-protection-mcp

by WYRE-AI

Datto SaaS Protection MCP Server

CI License: Apache 2.0

A Model Context Protocol server exposing the Datto SaaS Protection (Backupify) API to Claude and other MCP clients.

What it does

Surfaces SaaS backup posture for your Microsoft 365 and Google Workspace customers to AI assistants, using the documented Datto REST API (https://api.datto.com/v1/saas/...): list protected customers/domains, inspect seats and their protection state, review backup status per application, and (with confirmation) license, pause or unlicense seats in bulk.

  • Interactive Seat Card (MCP Apps): datto_saas_get_seat renders as an interactive card in MCP Apps hosts (Claude Desktop/web) — read-only, showing seat type and Datto seat state; neutral by default, brandable via window.__BRAND__ injection or MCP_BRAND_* env vars; plain-JSON behavior is unchanged in other hosts

Related MCP server: action1-mcp

Tools

Tool

Datto endpoint

Annotations

datto_saas_list_domains

GET /v1/saas/domains

read-only

datto_saas_list_seats

GET /v1/saas/{saasCustomerId}/seats

read-only

datto_saas_get_seat

GET /v1/saas/{saasCustomerId}/seats (filtered to one seat)

read-only

datto_saas_list_applications

GET /v1/saas/{saasCustomerId}/applications

read-only

datto_saas_get_backup_stats

GET /v1/saas/{saasCustomerId}/detailedBackupStats

read-only

datto_saas_bulk_seat_change

PUT /v1/saas/{saasCustomerId}/{externalSubscriptionId}/bulkSeatChange

write, destructive (asks for confirmation)

Start with datto_saas_list_domains: it returns the saasCustomerId and externalSubscriptionId every other tool needs.

Earlier versions exposed list_clients, list_backups, queue_restore, get_restore_status, list_activity and get_license_usage. Those were built on routes Datto does not serve (/v1/saas/clients, /restores, …) and always returned 404, so they are removed.

Credentials

Create an API key in the Datto Partner Portal (Admin > Integrations > API Keys). The API uses HTTP Basic auth with the public/secret key pair. There is a single API host (api.datto.com); there is no regional (EU) API host.

Local (env mode)

export DATTO_SAAS_PUBLIC_KEY="..."
export DATTO_SAAS_SECRET_KEY="..."

Hosted (gateway mode)

The WYRE MCP Gateway injects credentials per request via headers:

  • X-Datto-SaaS-Public-Key (required, secret)

  • X-Datto-SaaS-Secret-Key (required, secret)

  • X-Datto-SaaS-Region (accepted for backward compatibility; ignored)

Run

npm install
npm run build
npm start                       # stdio
MCP_TRANSPORT=http npm start    # HTTP on :8080

License

Apache 2.0 — see LICENSE.

Related MCP Connectors

Related MCP Servers

  • A
    license
    Not graded
    quality
    A
    maintenance
    An MCP server for Datto BCDR (Business Continuity and Disaster Recovery), enabling management of backup jobs, restore points, and disaster recovery operations through Datto's API.
    Apache 2.0
  • A
    license
    A
    quality
    A
    maintenance
    An MCP server for Action1, a cloud-native RMM platform, enabling remote monitoring, patch management, and endpoint management through Action1's API.
    6
    3
    Apache 2.0
  • F
    license
    B
    quality
    A
    maintenance
    An MCP server for CIPP (Community IT Professionals Platform), enabling MSPs to manage Microsoft 365 tenants, users, policies, and security settings through CIPP's API.
    47
    11
    -
  • A
    license
    Not graded
    quality
    A
    maintenance
    An MCP server for Blackpoint Cyber MDR platform, enabling management of security monitoring, threat detection, and incident response through Blackpoint's API.
    Apache 2.0