knowbe4-mcp
# KnowBe4 MCP Server
[](https://opensource.org/licenses/Apache-2.0)
[](https://nodejs.org/)
A Model Context Protocol (MCP) server for KnowBe4 security awareness training. Enables AI assistants to manage phishing simulations, training campaigns, user risk scoring, and security awareness reporting.
This is a [Model Context Protocol (MCP)](https://modelcontextprotocol.io/) server that connects Claude (or any MCP-compatible AI) to your KnowBe4 environment.
> **Part of the [MSP Claude Plugins](https://github.com/WYRE-AI) ecosystem** — a growing suite of AI integrations for the MSP stack. Built by MSPs, for MSPs.
## Installation
```bash
npm install @wyre-ai/knowbe4-mcp
```
## Configuration
Set the following environment variables:
| Variable | Required | Description |
|----------|----------|-------------|
| `KNOWBE4_API_KEY` | Yes | Your KnowBe4 API key |
| `KNOWBE4_REGION` | No | API region: us, eu, ca, uk, de (default: us) |
| `KNOWBE4_BASE_URL` | No | Custom base URL (overrides region) |
| `MCP_TRANSPORT` | No | Transport mode: stdio (default) or http |
## Usage
### Running with Claude Desktop
Add to your Claude Desktop `claude_desktop_config.json`:
```json
{
"mcpServers": {
"knowbe4-mcp": {
"command": "npx",
"args": ["@wyre-ai/knowbe4-mcp"],
"env": {
"KNOWBE4_API_KEY": "your-knowbe4-api-key"
}
}
}
}
```
### Running with Claude Code (CLI)
```bash
claude mcp add knowbe4-mcp \
-e KNOWBE4_API_KEY=your-value \
-- npx -y @wyre-ai/knowbe4-mcp
```
### Docker
```bash
docker build -t knowbe4-mcp .
docker run \
-e KNOWBE4_API_KEY=your-value \
-p 8080:8080 knowbe4-mcp
```
## Available Domains
### Account
Account information and settings
### Groups
User group management
### Phishing
Phishing simulation campaigns
### Reporting
Security awareness reports
### Training
Training campaign management
### Users
User management and risk scoring
## Interactive User Card (MCP Apps)
`knowbe4_users_get` renders as an interactive card in MCP Apps hosts
(Claude Desktop/web) showing the user's risk score, phish-prone percentage,
risk-score trend, and profile details; plain-JSON behavior is unchanged in
other hosts, and the card is read-only (no write round-trip). The card is
neutral by default and brandable via `window.__BRAND__` injection or
`MCP_BRAND_*` env vars (`MCP_BRAND_NAME`, `MCP_BRAND_LOGO_URL`,
`MCP_BRAND_PRIMARY_COLOR`, `MCP_BRAND_ACCENT_COLOR`, `MCP_BRAND_BG`,
`MCP_BRAND_TEXT`) — no rebuild needed.
## Development
```bash
# Clone the repository
git clone https://github.com/WYRE-AI/knowbe4-mcp.git
cd knowbe4-mcp
# Install dependencies
npm install
# Build
npm run build
# Run tests
npm test
```
## Contributing
Contributions are welcome! Please see [CONTRIBUTING.md](CONTRIBUTING.md) if present, or open an issue to discuss changes.
## License
Licensed under the Apache License, Version 2.0. See [LICENSE](LICENSE) for details.
TDQS
Scored across 30 tools
Each tool targets a distinct resource (campaigns, security tests, recipients, training, groups, users, reporting) with clear specificity. Tools like phishing_security_tests_list vs phishing_campaign_tests are differentiated by scope (all tests vs per-campaign), and the naming plus descriptions make boundaries clear.
All tools follow a consistent knowbe4_<domain>_<resource>_<action> pattern. The hierarchy is predictable: domain prefixes (phishing, training, users, groups, reporting) followed by singular/plural resource nouns and consistent verbs (list, get, members). The only minor deviation is the utility tools (navigate, back, status) which break the pattern but are intentional.
30 tools is on the heavy side, but KnowBe4 is a broad platform covering phishing, training, users, groups, reporting, and account data. Each tool covers a genuinely distinct resource that an agent would query. It leans toward the upper edge of reasonable scope, though several reporting summary tools aggregate data that could be computed from existing list tools, suggesting some redundancy.
The surface covers the primary KnowBe4 domains well: phishing campaigns/tests/recipients, training, users, groups, store purchases, and policies. However, the toolset is entirely read-only — there are no create, update, or delete tools for any resource, which means agents cannot trigger phishing simulations, enroll users, or modify campaigns. This limits it to a querying/analysis server.