datto-saas-protection-mcp
Provides tools to manage Datto SaaS Protection backups, including listing customers, domains, seats, backup history, queuing restores, and auditing activity logs and license usage.
Datto SaaS Protection MCP Server
A Model Context Protocol server exposing the Datto SaaS Protection (Backupify) API to Claude and other MCP clients.
What it does
Surfaces SaaS backup posture for your Microsoft 365 and Google Workspace
customers to AI assistants, using the documented Datto REST API
(https://api.datto.com/v1/saas/...): list protected customers/domains,
inspect seats and their protection state, review backup status per
application, and (with confirmation) license, pause or unlicense seats in bulk.
Interactive Seat Card (MCP Apps):
datto_saas_get_seatrenders as an interactive card in MCP Apps hosts (Claude Desktop/web) — read-only, showing seat type and Datto seat state; neutral by default, brandable viawindow.__BRAND__injection orMCP_BRAND_*env vars; plain-JSON behavior is unchanged in other hosts
Related MCP server: action1-mcp
Tools
Tool | Datto endpoint | Annotations |
|
| read-only |
|
| read-only |
|
| read-only |
|
| read-only |
|
| read-only |
|
| write, destructive (asks for confirmation) |
Start with datto_saas_list_domains: it returns the saasCustomerId and
externalSubscriptionId every other tool needs.
Earlier versions exposed
list_clients,list_backups,queue_restore,get_restore_status,list_activityandget_license_usage. Those were built on routes Datto does not serve (/v1/saas/clients,/restores, …) and always returned 404, so they are removed.
Credentials
Create an API key in the Datto Partner Portal (Admin > Integrations > API
Keys). The API uses HTTP Basic auth with the public/secret key pair. There is a
single API host (api.datto.com); there is no regional (EU) API host.
Local (env mode)
export DATTO_SAAS_PUBLIC_KEY="..."
export DATTO_SAAS_SECRET_KEY="..."Hosted (gateway mode)
The WYRE MCP Gateway injects credentials per request via headers:
X-Datto-SaaS-Public-Key(required, secret)X-Datto-SaaS-Secret-Key(required, secret)X-Datto-SaaS-Region(accepted for backward compatibility; ignored)
Run
npm install
npm run build
npm start # stdio
MCP_TRANSPORT=http npm start # HTTP on :8080License
Apache 2.0 — see LICENSE.
This server cannot be deployed
Maintenance
Related MCP Connectors
Hosted MCP servers for MSP tools: ConnectWise, NinjaOne, Microsoft 365, SentinelOne, Pax8 and more.
Cloud-hosted MCP server for secure AI access to enterprise data sources via CData Connect AI.
MCP server for querying and analyzing data from ad platforms, analytics tools, and spreadsheets
Unified MCP Server is a remote MCP connector for AI agents and vertical AI products that provides access to 22,000+ authorized SaaS tools across 400+ integrations and 24 categories directly inside LLMs (Claude, GPT, Gemini, Cohere). Tools operate only on explicitly authorized customer connections, enabling agents to safely read and write against live third-party systems.
Related MCP Servers
- AlicenseNot gradedqualityAmaintenanceAn MCP server for Datto BCDR (Business Continuity and Disaster Recovery), enabling management of backup jobs, restore points, and disaster recovery operations through Datto's API.Apache 2.0
- AlicenseAqualityAmaintenanceAn MCP server for Action1, a cloud-native RMM platform, enabling remote monitoring, patch management, and endpoint management through Action1's API.63Apache 2.0
- FlicenseBqualityAmaintenanceAn MCP server for CIPP (Community IT Professionals Platform), enabling MSPs to manage Microsoft 365 tenants, users, policies, and security settings through CIPP's API.4711-
- AlicenseNot gradedqualityAmaintenanceAn MCP server for Blackpoint Cyber MDR platform, enabling management of security monitoring, threat detection, and incident response through Blackpoint's API.Apache 2.0