Tenzir MCP Server
[](https://fastmcp.me/MCP/Details/1423/tenzir)
[](https://fastmcp.me/MCP/Details/1423/tenzir)
[](https://fastmcp.me/MCP/Details/1423/tenzir)
[](https://fastmcp.me/MCP/Details/1423/tenzir)
[](https://fastmcp.me/MCP/Details/1423/tenzir)
[](https://fastmcp.me/MCP/Details/1423/tenzir)
# βοΈ Tenzir MCP Server
[](https://pypi.org/project/tenzir-mcp)
[](https://opensource.org/licenses/Apache-2.0)
A [Model Context Protocol](https://modelcontextprotocol.io) (MCP) server that
enables AI assistants to interact with [Tenzir](https://tenzir.com)βa data
pipeline engine for security operations.
This MCP server provides tools for executing pipelines written in the [Tenzir
Query Language (TQL))](https://docs.tenzir.com/explanations/language), working
with Open Cybersecurity Schema Framework (OCSF), managing packages, generating parsers, and exploring documentation.
## β¨ Features
- **Pipeline Execution**: Run TQL pipelines and tests
- **Documentation Access**: Search and browse embedded Tenzir documentation with
cross-reference support
- **OCSF Integration**: Query and work with OCSF definitions, event classes,
objects, and profiles.
- **Package Management**: Create and manage Tenzir packages with operators,
pipelines, enrichment contexts, and tests
- **Code Generation**: Auto-generate TQL parsers and OCSF mapping packages
## π¦ Installation
Use Docker as the fastest way to get started:
```bash
docker run -i tenzir/mcp
```
Or use [`uvx`](https://docs.astral.sh/uv/) when you have a local Tenzir
installation:
```bash
uvx tenzir-mcp
```
## π Documentation
Consult our [setup guide](https://docs.tenzir.com/guides/mcp-usage/install-mcp-server)
for installation and MCP client configuration.
We also provide a [reference](https://docs.tenzir.com/reference/mcp-server) that
explains usage and available tools.
## π€ Contributing
Want to contribute? We're all-in on agentic coding with [Claude
Code](https://claude.ai/code)! The repo comes pre-configured with our [custom
plugins](https://github.com/tenzir/claude-plugins)βjust clone and start hacking.
## π License
This project is licensed under the [Apache License 2.0](LICENSE).
TDQS
Scored across 15 tools
Every tool has a distinct purpose: parsing, mapping, documentation lookup, pipeline execution, testing, OCSF schema access, and package management. The five ocsf_get_* tools are clearly differentiated by what they retrieve (classes, class, object, versions, latest version), and the docs_* and package_* tools have non-overlapping roles.
All tool names follow a consistent verb_noun pattern in snake_case: make_parser, make_ocsf_mapping, docs_read, docs_search, run_pipeline, run_test, ocsf_get_class, package_create, etc. Domain prefixes (docs_, ocsf_, package_) are used uniformly, making the naming predictable and easy to navigate.
15 tools is well within the ideal 3-15 range and matches the server's broad scope of documentation, OCSF schema exploration, package scaffolding, pipeline execution, and testing. Each tool earns its place without redundancy or bloat.
The tool set covers the full development lifecycle: create a package, add operators, tests, and changelogs, parse and map data, run pipelines, run tests, and consult documentation. Minor gaps exist for package management operations like listing or deleting existing components, and there is no tool to edit an existing operator directly, but these are not dead ends for the main workflow.