XFA MCP
XFA MCP
XFA 是一个 BYOD 设备信任平台。这是 XFA 的远程 Model Context Protocol 服务器 — 你可以从 Claude、ChatGPT、Cursor 及其他 AI 助手中查询组织的设备态势、合规性、策略以及软件/CVE 状态。只读。
本仓库是面向 AI 市场的连接器包。MCP 服务器本身由 XFA 托管于 https://mcp.xfa.tech/mcp;本地不会运行任何代码。连接时采用 OAuth 2.0 (PKCE) 进行身份验证 — 使用你的 XFA 账号登录即可。
发布位置
平台 | 状态 | 提交/查找位置 |
官方 MCP Registry | ✅ 已上线 |
|
Glama | ⏳ 正在从注册表同步 | |
Smithery | ⏳ 正在从注册表同步 | |
PulseMCP | ⏳ 正在从注册表同步 | |
mcp.so | ⏳ 正在从注册表同步 | |
Cursor Marketplace | 🕒 已提交 — 待批准 | |
Claude Connectors Directory | 🕒 待确认 | Claude.ai → 设置 → 连接器(团队版/企业版) |
ChatGPT 应用目录 | 🕒 待处理 | |
Gemini / Antigravity CLI | ✅ 可安装 · ⏳ 展示区自动爬取 |
|
awesome-mcp-servers | 🕒 PR 已提交 — #12739 | 安全相关章节 |
图例:✅ 已上线 · ⏳ 同步推送中(无需操作) · 🕒 待处理。当某个平台正式上线时,请更新对应行。
Gemini 说明: Gemini CLI 平台没有提交通道 — 它会每天抓取带有
gemini-cli-extensionGitHub 话题的公开仓库(已设置话题)。Gemini CLI 已并入 Antigravity CLI(2026 年 6 月);Antigravity 通过 MCP Registry 发现 MCP 服务器,而该服务器已在其中处于活动状态,因此无需单独提交 Antigravity。
Related MCP server: Fleet MCP
安装
Cursor
一键安装:
cursor://anysphere.cursor-deeplink/mcp/install?name=xfa&config=eyJ1cmwiOiJodHRwczovL21jcC54ZmEudGVjaC9tY3AifQ==或添加至 ~/.cursor/mcp.json:
{
"mcpServers": {
"xfa": { "url": "https://mcp.xfa.tech/mcp" }
}
}Claude
设置 → 连接器 → 添加自定义连接器 → URL https://mcp.xfa.tech/mcp。
ChatGPT
设置 → 连接器 → 添加 → MCP 服务器 URL https://mcp.xfa.tech/mcp。
Gemini CLI
安装扩展:
gemini extensions install https://github.com/gl-ventures/xfa-mcp随附的 gemini-extension.json 指向远程服务器;Gemini 会从使用 mcp.xfa.tech 的 OAuth 元数据中自动发现登录,并在首次使用时提示你登录。
VS Code / Windsurf / Zed / 其他 MCP 客户端
将客户端指向远程 URL https://mcp.xfa.tech/mcp(支持流式 HTTP / SSE,OAuth 2.0)。
工具
所有工具均为只读。实际服务器是“真实情况”的来源 — 客户端每次连接都会获取当前工具列表,因此本列表可能滞后于已部署的服务器。有关维护中的参考,请参阅 连接 AI 助手 文档。
你的组织(范围限定为已登录用户所属组织)
工具 | 说明 |
| 获取你的 XFA 组织 |
| 获取你当前登录的用户 |
| 列出设备(最近 30 天内活跃) |
| 获取单台设备 |
| 组织级合规摘要 |
| 设备态势的历史趋势 |
| 列出策略 |
软件与漏洞(XFA 跟踪的软件目录)
工具 | 说明 |
| 某个互联网软件的最新已知版本 |
| 列出 XFA 跟踪的软件列表 |
| 特定软件版本的状态信息 |
| 影响某个软件版本的 CVE 漏洞列表 |
身份验证
OAuth 2.0 with PKCE (S256),作用域 mcp:read。连接时,系统会将你重定向到 XFA 进行授权;本包不会存储任何 API 密钥或令牌。客户端会自动从服务器已发布的元数据中发现 OAuth 端点:
https://mcp.xfa.tech/.well-known/oauth-protected-resourcehttps://mcp.xfa.tech/.well-known/oauth-authorization-server
支持
维护者
MCP Registry 工作流 会在每次推送时验证 server.json,并在推送到 main 分支(或通过 Run workflow)时发布到官方 MCP Registry。它基于 xfa.tech 顶域上的 v=MCPv1 TXT 记录进行 DNS 身份验证。
要发布新版本:在 server.json 中升级 version 并合并到 main。
所需仓库密钥:MCP_REGISTRY_KEY_PEM — Ed25519 私钥 PEM(与该 TXT 记录配对)。请在密码管理器中备份对应的私钥。
许可证
MIT — 见 LICENSE。
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
AlicenseAqualityCmaintenanceRead-only MCP server that allows AI assistants to query and monitor KVM Fleet devices, audit logs, and console sessions through the official REST API.5141MIT- AlicenseNot gradedqualityDmaintenanceEnables AI assistants to interact with Fleet Device Management for device management, security monitoring, and compliance enforcement through the Model Context Protocol.5MIT
- AlicenseNot gradedqualityCmaintenanceEnables AI assistants read-only access to Sprinklr data via MCP, allowing querying reports, searching cases, and calling Sprinklr API endpoints.7ISC
- AlicenseAqualityCmaintenanceA read-only MCP server that enables AI assistants to query ServiceNow instances—incidents, changes, users, CMDB—with malformed query linting and injection protection.7MIT
Related MCP Connectors
A paid remote MCP for AI SDK data query MCP, built to return verdicts, receipts, usage logs, and aud
Remote MCP for A2A caller identity, scope policy, verdict receipts, and audit history.
Read-only Remote MCP for externally grounded AI agent trust receipts.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/gl-ventures/xfa-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server