phishfort-mcp
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| PHISHFORT_API_KEY | No | API key for authentication. | |
| PHISHFORT_SECRET_DIR | No | Directory for webhook secrets. | ~/.config/phishfort-mcp/secrets |
| PHISHFORT_MAX_RETRIES | No | Maximum number of retries for 429 and 5xx. | 3 |
| PHISHFORT_API_BASE_URL | No | Base URL for PhishFort API. | https://capi.phishfort.com/v1 |
| PHISHFORT_API_KEY_FILE | No | Path to a file containing the API key. | |
| PHISHFORT_TIMEOUT_SECONDS | No | HTTP request timeout in seconds. | 30 |
| PHISHFORT_ATTACHMENT_ROOTS | No | Comma-separated roots allowed for attachment uploads. | . |
| PHISHFORT_ALLOW_CUSTOM_BASE_URL | No | Test-only escape hatch for non-production API hosts. | false |
| PHISHFORT_ALLOW_UNSAFE_WEBHOOK_URL | No | Test-only escape hatch for localhost/private webhook targets. | false |
Capabilities
Features and capabilities supported by this server
| Capability | Details |
|---|---|
| tools | {
"listChanged": false
} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| phishfort_plan_changeB | Plan a PhishFort write. Does not mutate. Use returned approval fields on write tools. |
| phishfort_list_capabilitiesA | List supported PhishFort MCP operations and mutation approval requirements. |
| phishfort_get_limitsA | Return documented API limits and MCP-enforced limit choices. |
| phishfort_whoamiA | Return authenticated PhishFort client identity. |
| phishfort_list_usersC | List users with role, client, search, limit, and offset filters. |
| phishfort_list_clientsA | List visible clients with id, search, active, limit, and offset filters. |
| phishfort_list_documentsC | List document metadata. doc_type accepts comma-separated documented types. |
| phishfort_get_documentA | Get document metadata and its time-limited signed URL without fetching it. |
| phishfort_get_document_signed_urlA | Get a time-limited document URL without fetching it. |
| phishfort_list_incidentsC | List incidents. Set include_total to request paging.total. |
| phishfort_get_incidentB | Get one PhishFort incident by id. |
| phishfort_find_incident_by_subjectB | Find one incident by URL, domain, or subject value. Subject is URL-encoded. |
| phishfort_report_incidentC | Report incident for takedown or monitoring after approval. |
| phishfort_request_incident_actionB | Request takedown, monitoring, or safe review for an existing incident. |
| phishfort_add_attachmentsC | Add attachment files to an existing incident after approval. |
| phishfort_add_commentB | Add a comment to an existing incident after approval. |
| phishfort_list_webhooksA | List configured webhook subscriptions. |
| phishfort_create_webhookC | Create webhook subscription. One-time secret is saved locally, not returned. |
| phishfort_update_webhookC | Update webhook subscription after approval. |
| phishfort_delete_webhookC | Delete webhook subscription after approval. |
| phishfort_test_webhookC | Send test webhook delivery after approval. |
| phishfort_rotate_webhook_secretC | Rotate webhook secret. One-time secret is saved locally, not returned. |
| phishfort_verify_webhook_signatureB | Verify a fresh X-PhishFort-Signature using a contained local secret file. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
| reference_summary | |
| reference_limits | |
| reference_source_manifest | |
| reference_security_review |
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/mychaelconnolly/phishfort-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server