CipherTrust Manager MCP Server
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@CipherTrust Manager MCP Serverlist all encryption keys in the production environment"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
CipherTrust Manager MCP Server
This project implements an independently-developed CipherTrust MCP (Model Context Protocol) server that allows AI Assistants like Claude or Cursor to interact with CipherTrust Manager resources using the ksctl CLI.
Table of Contents
Related MCP server: K8s MCP Server
Important Notice
This is an independent, open-source project. Please note:
โ ๏ธ Not officially supported by Thales
โ Uses public APIs and documented interfaces
๐ง Independently maintained
๐ Use at your own risk - test thoroughly in your environment
๐ผ No warranty - see license for full terms
For official CipherTrust Manager support, please contact Thales directly.
Features
The MCP server exposes a set of tools and endpoints for clients (such as Claude Desktop and Cursor) to interact with CipherTrust resources. Supported operations include:
Key management
CTE client management
User management
Connection management
And more
Benefits:
Unified interface for AI assistants to interact with CipherTrust Manager
Support for key management, connection management, CTE client management, and more
JSON-RPC communication over stdin/stdout
Configurable via environment variables
Prerequisites
Git
Python 3.11 or higher
uv for dependency management
Access to a CipherTrust Manager instance
Valid CipherTrust Manager credentials
Installing Git (Windows)
If you don't have Git installed on Windows, follow these steps:
Download and install Git for Windows: https://git-scm.com/download/win
Or install via winget:
winget install --id Git.Git -e --source wingetVerify installation - Open PowerShell and execute:
git --versionYou should see the installed Git version.
Installing Python and uv
Method 1: Manual Installation
1. Download Python
# Open PowerShell as Administrator (optional)
cd $env:USERPROFILE\Downloads
Invoke-WebRequest -Uri "https://www.python.org/ftp/python/3.12.4/python-3.12.4-amd64.exe" -OutFile "python-installer.exe"2. Run the Installer
.\python-installer.exe /quiet InstallAllUsers=1 PrependPath=1 Include_test=03. Verify Installation
Open a new terminal and run:
python --version
pip --version4. Install uv
pip install uv
uv --version5. Clone the Repository
git clone https://github.com/sanyambassi/ciphertrust-manager-mcp-server.git
cd ciphertrust-manager-mcp-server6. Create a Virtual Environment and Install Dependencies
uv venv
.venv\Scripts\activate
uv pip install -e .Method 2: Using winget (Windows)
1. Install Python with winget
winget install --id Python.Python.3.12 --source winget --accept-package-agreements --accept-source-agreements2. Close and Reopen PowerShell
This ensures Python is available in your PATH.
3. Verify Installation
python --version
pip --version4. Install uv
pip install uv
uv --version5. Clone the Repository
git clone https://github.com/sanyambassi/ciphertrust-manager-mcp-server.git
cd ciphertrust-manager-mcp-server6. Create a Virtual Environment and Install Dependencies
uv venv
.venv\Scripts\activate
uv pip install -e .Configuration
(Optional) Copy and Edit the Example Environment File
Example .env:
cp .env.example .env
# Edit .env with your CipherTrust Manager detailsYou can also set these as environment variables directly instead of using a .env file.
Example .env content:
CIPHERTRUST_URL=https://your-ciphertrust-manager.example.com
CIPHERTRUST_USER=admin
CIPHERTRUST_PASSWORD=your-password-here
CIPHERTRUST_NOSSLVERIFY=trueUsage
โ ๏ธ Important: Before starting, either the environment variable or .env should contain a valid CipherTrust Manager URL.
You have two main ways to run the CipherTrust MCP Server:
Method 1: Direct Execution
uv run ciphertrust-mcp-serverThis runs the main() function in ciphertrust_mcp_server/__main__.py.
Method 2: Module Execution
uv run python -m ciphertrust_mcp_server.__main__Testing
This project includes comprehensive testing capabilities using the Model Context Protocol Inspector and Python unit tests.
Quick Testing
# Manual JSON-RPC testing (direct stdin/stdout)
uv run ciphertrust-mcp-server
# Then send JSON-RPC commands (see TESTING.md for details)
# Interactive UI (Inspector 2.5+). Open the printed URL; it includes MCP_INSPECTOR_API_TOKEN.
npx @modelcontextprotocol/inspector uv run --no-sync ciphertrust-mcp-server
# Quick CLI testing
# Get tools
npx @modelcontextprotocol/inspector --cli --config tests/mcp_inspector_config.json --server ciphertrust-local --method tools/list --format json
# Get system information
npx @modelcontextprotocol/inspector --cli --config tests/mcp_inspector_config.json --server ciphertrust-local --method tools/call --tool-name system_information --tool-arg action=get --format json
# Get 2 keys
npx @modelcontextprotocol/inspector --cli --config tests/mcp_inspector_config.json --server ciphertrust-local --method tools/call --tool-name key_management --tool-arg action=list --tool-arg limit=2 --format jsonAvailable Testing Methods
๐ง Manual JSON-RPC Testing: Direct stdin/stdout communication for debugging and development
๐ฅ๏ธ Interactive UI Testing: Visual web interface for manual testing and debugging
โก CLI Automated Testing: Command-line automation for CI/CD integration
๐งช Python Unit Tests: Comprehensive unit testing for server components
๐ Integration Tests: End-to-end testing with real CipherTrust Manager instances
NPM Scripts
npm run test:inspector:ui # Open Inspector UI (uses project .env)
npm run test:inspector:cli # List tools via Inspector CLI
npm run test:python # Run Python unit tests
npm run test:full # Run complete test suiteComprehensive Testing Guide
๐ For detailed testing instructions, see TESTING.md
๐ง For example AI assistant prompts, see EXAMPLE_PROMPTS.md
The testing guide covers:
Complete setup and configuration
Advanced testing scenarios
The example prompts include:
Key management operations
User and group management
System and service management
Cluster management
License management
CTE operations
Crypto operations
And more practical scenarios
Integration with AI Assistants
Using with Cursor
1. Configure Cursor
Go to Settings > MCP Tools > Add Custom MCP
Add the following contents in the config file (e.g.,
mcp.json):
{
"mcpServers": {
"ciphertrust": {
"command": "Path to your project folder/ciphertrust-manager-mcp-server/.venv/bin/ciphertrust-mcp-server",
"args": [],
"env": {
"CIPHERTRUST_URL": "https://your-ciphertrust.example.com",
"CIPHERTRUST_USER": "admin",
"CIPHERTRUST_PASSWORD": "your-password-here"
}
}
}
}On Windows, use the .venv\Scripts\ciphertrust-mcp-server.exe path and double backslashes:
{
"mcpServers": {
"ciphertrust": {
"command": "C:\\path\\to\\ciphertrust-manager-mcp-server\\.venv\\Scripts\\ciphertrust-mcp-server",
"args": [],
"env": {
"CIPHERTRUST_URL": "https://your-ciphertrust.example.com",
"CIPHERTRUST_USER": "admin",
"CIPHERTRUST_PASSWORD": "your-password-here"
}
}
}
}2. Apply Configuration
Disable and Re-enable the CipherTrust MCP server in Cursor to apply the changes.
Using with Claude Desktop
1. Locate or create the Claude Desktop config file:
macOS:
~/Library/Application Support/Claude/claude_desktop_config.jsonWindows:
%APPDATA%\Roaming\Claude\claude_desktop_config.json
2. Add or update the MCP server configuration:
macOS/Linux Example:
{
"mcpServers": {
"ciphertrust": {
"command": "/absolute/path/to/ciphertrust-manager-mcp-server/.venv/bin/ciphertrust-mcp-server",
"env": {
"CIPHERTRUST_URL": "https://your-ciphertrust.example.com",
"CIPHERTRUST_USER": "admin",
"CIPHERTRUST_PASSWORD": "your-password-here"
}
}
}
}Windows Example:
{
"mcpServers": {
"ciphertrust": {
"command": "C:\\absolute\\path\\to\\ciphertrust-manager-mcp-server\\.venv\\Scripts\\ciphertrust-mcp-server",
"env": {
"CIPHERTRUST_URL": "https://your-ciphertrust.example.com",
"CIPHERTRUST_USER": "admin",
"CIPHERTRUST_PASSWORD": "your-password-here"
}
}
}
}Adjust the path to match your actual project location and environment.
3. Restart Claude Desktop
Restart Claude Desktop to apply the changes.
Environment Variables
Set these in your shell or in a .env file in the project root:
Variable Name | Description | Required/Default |
| CipherTrust Manager URL (http/https) | Required |
| CipherTrust Manager username | Required |
| CipherTrust Manager password | Required |
| Disable SSL verification (true/false) |
|
| Timeout for CipherTrust requests (seconds) |
|
| Default CipherTrust domain |
|
| Authentication domain |
|
| Path to ksctl binary |
|
| Path to ksctl config file |
|
| Logging level (DEBUG, INFO) |
|
Example .env file:
CIPHERTRUST_URL=https://your-ciphertrust.example.com
CIPHERTRUST_USER=admin
CIPHERTRUST_PASSWORD=yourpassword
CIPHERTRUST_NOSSLVERIFY=false
CIPHERTRUST_TIMEOUT=30
CIPHERTRUST_DOMAIN=root
CIPHERTRUST_AUTH_DOMAIN=root
KSCTL_PATH=
KSCTL_CONFIG_PATH=
LOG_LEVEL=INFOTroubleshooting
Successful startup logs:
The server is designed to be run as a subprocess by MCP clients (like Claude Desktop or Cursor) and communicates via JSON-RPC over stdin/stdout.
You'll see log output like in the AI assistant's MCP log:
2025-06-16 02:22:30,462 - ciphertrust_mcp_server.server - INFO - Starting ciphertrust-manager v0.2.0
2025-06-16 02:22:30,838 - ciphertrust_mcp_server.server - INFO - Successfully connected to CipherTrust Manager
2025-06-16 02:22:30,838 - ciphertrust_mcp_server.server - INFO - MCP server ready and waiting for JSON-RPC messages on stdin...Dependencies
The pyproject.toml file includes these dependencies:
mcp>=2.1.1,<3pydantic>=2.12.0pydantic-settings>=2.0.0httpx>=0.27.0python-dotenv>=1.0.0
If you encounter issues, ensure all dependencies are installed and up-to-date.
Project Structure
ciphertrust-manager-mcp-server/
โโโ src
โ โโโ ciphertrust_mcp_server/ # Main server code
โโโ tests/ # Testing configuration and unit tests
โ โโโ mcp_inspector_config.json
โ โโโ test_scenarios.json
โ โโโ test_server.py
โ โโโ test_integration_simple.py
โโโ scripts/ # Testing and utility scripts
โ โโโ test_with_inspector.bat
โ โโโ test_with_inspector.sh
โ โโโ run_tests.py
โโโ docs/ # Additional documentation
โ โโโ TESTING.md
โ โโโ EXAMPLE_PROMPTS.md
โ โโโ TOOLS.md
โโโ README.md # This file
โโโ pyproject.toml # Python dependencies
โโโ package.json # Node.js dependencies for testingContributing
Contributions are welcome! Please feel free to submit a Pull Request. While this started as a personal project, contributions help make it better for everyone.
Legal
Trademark Notice
CipherTrustยฎ and related trademarks are the property of Thales Group and its subsidiaries. This project is not affiliated with, endorsed by, or sponsored by Thales Group.
No Warranty
This software is provided "as is" without warranty of any kind. Use at your own risk.
Support
This is an independent project. For official CipherTrust Manager support, please contact Thales directly. For issues with this unofficial MCP server, please use the GitHub issue tracker.
License
This project is licensed under the MIT License. See the LICENSE file for details.
This server cannot be deployed
Maintenance
Related MCP Connectors
Deploy, monitor, and manage your OpenClaw AI assistants via natural language.
Connects AI assistants to CloudQuell multi-cloud and AI cost, savings, anomaly, and budget data.
- mcpOAuthcom.keboola
Connect your AI assistants to Keboola and expose your data, transformations, SQL queries, ...
Unified API to query AWS, GCP, Azure and generate Terraform/CLI execution kits for AI agents.
Related MCP Servers
- FlicenseBqualityDmaintenanceEnables managing Kubernetes clusters through natural language by providing tools to list resources, view logs, port-forward services, scale deployments, and execute kubectl operations via AI assistants.81-
- AlicenseNot gradedqualityDmaintenanceEnables LLMs like Claude to securely execute Kubernetes CLI tools (kubectl, helm, istioctl, argocd) across multiple clusters through dynamic kubeconfig support, allowing natural language Kubernetes management and operations.5MIT
- AlicenseNot gradedqualityBmaintenanceEnables AI assistants to interact with VAST Data clusters for monitoring, listing, and management operations. It provides both read-only and read-write modes for cluster and tenant administration tasks.Apache 2.0
- AlicenseNot gradedqualityFmaintenanceEnables AI-powered management of multi-cluster Kubernetes environments through natural language, supporting kubectl operations, function execution, and agent interactions with multiple AI providers.7Apache 2.0