ironscales-mcp
by WYRE-AI
README.md
# Ironscales MCP Server
[](https://opensource.org/licenses/Apache-2.0)
[](https://nodejs.org/)
A Model Context Protocol (MCP) server for Ironscales email security. Enables AI assistants to investigate phishing incidents, manage email classification, execute remediations, and view security statistics.
This is a [Model Context Protocol (MCP)](https://modelcontextprotocol.io/) server that connects Claude (or any MCP-compatible AI) to your Ironscales environment.
> **Part of the [MSP Claude Plugins](https://github.com/WYRE-AI) ecosystem** — a growing suite of AI integrations for the MSP stack. Built by MSPs, for MSPs.
## Interactive Incident Card (MCP Apps)
`ironscales_incidents_get` renders as an interactive card in MCP Apps hosts
(Claude Desktop/web) showing the phishing incident's subject, status, severity,
sender, affected recipients, and threat indicators; plain-JSON behavior is
unchanged in other hosts. The card is read-only — remediation stays with the
model-driven remediation tools. It is neutral by default and brandable via
`window.__BRAND__` injection or `MCP_BRAND_*` env vars (`MCP_BRAND_NAME`,
`MCP_BRAND_LOGO_URL`, `MCP_BRAND_PRIMARY_COLOR`, `MCP_BRAND_ACCENT_COLOR`,
`MCP_BRAND_BG`, `MCP_BRAND_TEXT`) — no rebuild needed.
## Installation
```bash
npm install @wyre-ai/ironscales-mcp
```
## Configuration
Set the following environment variables:
| Variable | Required | Description |
|----------|----------|-------------|
| `IRONSCALES_API_KEY` | Yes | Your Ironscales API key |
| `IRONSCALES_COMPANY_ID` | Yes | Your Ironscales company ID |
| `MCP_TRANSPORT` | No | Transport mode: stdio (default) or http |
## Usage
### Running with Claude Desktop
Add to your Claude Desktop `claude_desktop_config.json`:
```json
{
"mcpServers": {
"ironscales-mcp": {
"command": "npx",
"args": ["@wyre-ai/ironscales-mcp"],
"env": {
"IRONSCALES_API_KEY": "your-ironscales-api-key"
"IRONSCALES_COMPANY_ID": "your-ironscales-company-id"
}
}
}
}
```
### Running with Claude Code (CLI)
```bash
claude mcp add ironscales-mcp \
-e IRONSCALES_API_KEY=your-value \
-e IRONSCALES_COMPANY_ID=your-value \
-- npx -y @wyre-ai/ironscales-mcp
```
### Docker
```bash
docker build -t ironscales-mcp .
docker run \
-e IRONSCALES_API_KEY=your-value \
-e IRONSCALES_COMPANY_ID=your-value \
-p 8080:8080 ironscales-mcp
```
## Available Domains
### Allowlist
Manage email allowlists and blocklists
### Email
Email investigation and classification
### Incidents
Phishing incident management and triage
### Remediation
Execute email remediations and quarantine
### Stats
Security statistics and reporting
## Development
```bash
# Clone the repository
git clone https://github.com/WYRE-AI/ironscales-mcp.git
cd ironscales-mcp
# Install dependencies
npm install
# Build
npm run build
# Run tests
npm test
```
## Contributing
Contributions are welcome! Please see [CONTRIBUTING.md](CONTRIBUTING.md) if present, or open an issue to discuss changes.
## License
Licensed under the Apache License, Version 2.0. See [LICENSE](LICENSE) for details.
TDQS
A3.6/5.0
Scored across 2 tools
Disambiguation5/5
The two tools have clearly distinct purposes: one navigates to specific domains to view their tools, and the other checks API connection status. No ambiguity.
Naming Consistency4/5
Both tools share the consistent 'ironscales_' prefix and use snake_case. However, one is a verb ('navigate') and the other is a noun ('status'), which is a minor inconsistency.
Tool Count2/5
With only 2 tools for a server that claims to cover multiple domains (incidents, email, remediation, stats, allowlist), the count is far too low to be useful.
Completeness1/5
The server lacks any tools for actual operations on the listed domains, such as viewing incidents, classifying emails, or managing remediation. It only has navigation and status checks, leaving massive gaps.
Maintenance
ActivityActive
ResponsivenessNo issues