vcf-ops-mcp
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@vcf-ops-mcpshow me critical alerts from the last 24 hours"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
vcf-ops-mcp
An MCP server that wraps the VCF Operations (vROps) suite-api REST API, exposing
resources, metrics, and alerts as MCP tools so an LLM client can query monitored
infrastructure directly.
Setup
python3 -m venv .venv
source .venv/bin/activate
pip install -e ".[dev]"
cp .env.example .env # then fill in your VCF Operations detailsRequired configuration (via .env or real environment variables):
Variable | Description |
| Base URL of the VCF Operations instance, e.g. |
| User to authenticate as |
| Password for that user |
| Auth source name (default |
| Set |
| Per-request timeout in seconds (default |
The server acquires a token from /suite-api/api/auth/token/acquire on first use,
caches it, and transparently re-acquires it when it's near expiry or rejected with
401.
Server transport/auth configuration (also via .env or real environment variables):
Variable | Description |
|
|
| Bind host for streamable-http (default |
| Bind port for streamable-http (default |
| Required for streamable-http. Clients must send |
| Comma-separated Host-header allowlist for DNS-rebinding protection (see below) |
Running
By default this runs as a standalone remote server over streamable-http,
bound to 127.0.0.1:8000, requiring a bearer token on every request:
export VCFOPS_MCP_BEARER_TOKEN="$(openssl rand -hex 32)"
vcf-ops-mcp
# or
python -m vcf_ops_mcpGET /healthz is unauthenticated (for load balancer/orchestrator liveness checks);
everything else requires the bearer token. 127.0.0.1 only listens locally — to
actually reach it from another host, bind VCFOPS_MCP_HOST=0.0.0.0 (or run it
behind a reverse proxy) and make sure the bearer token is the only thing standing
between the network and credentials capable of querying your whole monitored
environment, so treat it like any other secret and prefer TLS termination (e.g. a
reverse proxy) in front of it rather than plaintext HTTP over an untrusted network.
When VCFOPS_MCP_HOST isn't 127.0.0.1/localhost, FastMCP's own DNS-rebinding
protection (a check against the incoming request's Host header) has nothing to
allowlist by default, since it only auto-configures that allowlist for a loopback
host. Left unset, no Host-header check is enforced and the bearer token is your
only gate — fine on a network you trust, but set VCFOPS_MCP_ALLOWED_HOSTS to the
hostname(s)/IP:port clients actually connect through (comma-separated) for defense
in depth on a shared or untrusted network.
Point an MCP client at it as a streamable-http server, e.g. in Claude Code:
claude mcp add --transport http vcf-operations http://<host>:8000/mcp \
--header "Authorization: Bearer <your-token>"Running over stdio instead
For local use where an MCP client spawns the server itself as a subprocess (no
network exposure needed), set VCFOPS_MCP_TRANSPORT=stdio — the bearer token is
not required in this mode. Example Claude Desktop config:
{
"mcpServers": {
"vcf-operations": {
"command": "/absolute/path/to/.venv/bin/vcf-ops-mcp",
"env": {
"VCFOPS_MCP_TRANSPORT": "stdio",
"VCFOPS_BASE_URL": "https://ops.example.com",
"VCFOPS_USERNAME": "admin",
"VCFOPS_PASSWORD": "changeme"
}
}
}
}Tools
Resources
list_resources— search monitored objects by name/adapter kind/resource kind/healthget_resource— full detail for one resourceget_resource_properties— collected configuration propertiesget_resource_relationships— parent/child objects
Metrics
list_metric_keys— available statKeys for an adapter/resource kind pairget_latest_stats— most recent metric value(s) for a resourcequery_stats— historical time series across resources, with rollup/interval
Alerts
list_alerts— active/all alerts, optionally scoped to a resource or criticalityget_alert— full detail for one alertlist_alert_definitions— the rule definitions behind alerts
Testing
pip install -e ".[dev]"
pytestTests mock the VCF Operations HTTP API with respx — no live instance required.
Notes
Pinned to
mcp<2.0.0: the MCP Python SDK's 2.x line renamedFastMCPtoMCPServerand moved it tomcp.server.mcpserver. This project targets the well-established 1.xmcp.server.fastmcp.FastMCPAPI.
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Connectors
MCP server exposing the Backtest360 engine API as tools for AI agents.
MCP server for Pentest-Tools.com: run scans, manage findings and reports via your preffered LLM.
MCP server providing access to the Scorecard API to evaluate and optimize LLM systems.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/mdegrasse/vcf-ops-mcp-server'
If you have feedback or need assistance with the MCP directory API, please join our Discord server