rocketcyber-mcp
Provides read-only access to the RocketCyber Managed SOC platform, exposing tools to test connectivity, retrieve account information, list monitored agents/endpoints, security incidents, security events, event summaries/statistics, firewall devices, managed apps, Windows Defender status, and Office 365 status, plus resources for account, incidents, and agents.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@rocketcyber-mcpShow me the latest security incidents"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
rocketcyber-mcp
MCP (Model Context Protocol) server for the RocketCyber Managed SOC platform. Provides read-only access to RocketCyber security data through 10 tools and 3 resources.
Features
10 read-only tools covering all RocketCyber API resources, each annotated
readOnlyHint: trueso MCP clients (e.g. Microsoft 365 Copilot) can skip per-call confirmation prompts3 MCP resources for quick data access
Dual transport: stdio (default) and HTTP Streamable
Lazy SDK initialization on first tool call
Winston logger with all output routed to stderr
Connection test tool for validating credentials
Related MCP server: action1-mcp
One-Click Deployment
Before you click: this server depends on @wyre-ai/node-rocketcyber,
which is hosted on the GitHub Packages npm registry. GitHub Packages has no
anonymous access — even though the package is public, every npm install needs a
token. The cloud builder runs npm install for you, so you must give it one, or
the build fails with npm error 401 Unauthorized ... npm.pkg.github.com.
Create a GitHub Personal Access Token with the
read:packagesscope (classic token). Any GitHub account works — you do not need to be a member of theWYRE-AIorg to read its public packages.Add it as a build variable when prompted by the deploy flow:
Cloudflare Workers → set a build variable named
NODE_AUTH_TOKENto your PAT (Workers → Settings → Build → Variables and Secrets).DigitalOcean App Platform → set an encrypted env var named
GITHUB_TOKENwith scope Build Time to your PAT (the Dockerfile reads it for the install).
Installation
This project depends on @wyre-ai/node-rocketcyber, published to the
GitHub Packages npm registry, which requires a token even for public packages.
Authenticate once, then install:
# Authenticate npm to GitHub Packages (token needs the read:packages scope)
export NODE_AUTH_TOKEN=$(gh auth token) # or a PAT with read:packages
npm install
npm run buildThe repo's .npmrc already points the @wyre-ai scope at GitHub Packages and
reads the token from NODE_AUTH_TOKEN, so no further config is needed.
Configuration
Environment Variable | Required | Default | Description |
| Yes | - | RocketCyber API key |
| No |
| API region: |
| No |
| Transport type: |
| No |
| HTTP port (when using http transport) |
| No |
| HTTP host (when using http transport) |
| No |
| Log level: |
| No |
| Log format: |
Usage
Claude Desktop (stdio)
Add to your Claude Desktop configuration (claude_desktop_config.json):
{
"mcpServers": {
"rocketcyber": {
"command": "node",
"args": ["/path/to/rocketcyber-mcp/dist/entry.js"],
"env": {
"ROCKETCYBER_API_KEY": "your-api-key"
}
}
}
}HTTP Transport
ROCKETCYBER_API_KEY=your-api-key MCP_TRANSPORT=http npm startTools
Every tool below only reads data (no tool issues a write to the RocketCyber API), so each is annotated annotations: { readOnlyHint: true } in the tools/list response. MCP clients that honor readOnlyHint — Microsoft 365 Copilot / Copilot Studio among them — use this to skip the per-call confirmation prompt they'd otherwise show before every tool call.
Tool | Description |
|
| Test the connection to RocketCyber API | true |
| Get account information | true |
| List monitored agents/endpoints | true |
| List security incidents | true |
| List security events | true |
| Get event summary/statistics | true |
| List firewall devices | true |
| List managed apps | true |
| Get Windows Defender status | true |
| Get Office 365 status | true |
Resources
URI | Description |
| Account information |
| Security incidents |
| Monitored agents/endpoints |
Development
# Install dependencies
npm install
# Run in development mode
npm run dev
# Build
npm run build
# Start production server
npm startLicense
This server cannot be deployed
Maintenance
Related MCP Connectors
Hosted MCP servers for MSP tools: ConnectWise, NinjaOne, Microsoft 365, SentinelOne, Pax8 and more.
MCP server for querying and analyzing data from ad platforms, analytics tools, and spreadsheets
Read-only MCP access to a documented IT fleet: state, changes, posture. 15 tools.
The CustomGPT.ai MCP server is a fully managed, RAG-powered endpoint that connects large language models with private knowledge bases and external data sources. It provides tools for retrieval-augmented generation queries (send_message), data ingestion (upload_file), and source listing, enabling AI agents to query private documents like PDFs with high accuracy and real-time citations.
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceAn MCP server that provides secure, read-only access to the TrakSYS manufacturing analytics platform through entity-based tools and guided investigation prompts. It enables users to interact with manufacturing databases and perform data analysis via natural language.MIT
- AlicenseAqualityAmaintenanceAn MCP server for Action1, a cloud-native RMM platform, enabling remote monitoring, patch management, and endpoint management through Action1's API.63Apache 2.0
- AlicenseNot gradedqualityAmaintenanceAn MCP server for Blackpoint Cyber MDR platform, enabling management of security monitoring, threat detection, and incident response through Blackpoint's API.Apache 2.0
- FlicenseNot gradedqualityBmaintenanceMCP server that exposes Acronis Cyber Protect Cloud APIs as 14 read-only tools for managing alerts, tasks, agents, resources, policies, and tenants.-