Juno MCP Server
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Juno MCP ServerAre there any privilege escalation attempts?"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
MCP server for Uptycs Juno — the AI-powered security assistant.
Connect Juno to any MCP-compatible client to investigate threats, analyze findings, and manage security investigations.
What you can do
Investigate threats — "Are there any privilege escalation attempts in the last 24 hours?"
Follow up — "What user accounts were involved in the lateral movement?"
Scope investigations — Target specific connectors, time ranges, and personas
Manage investigations — List, create, and delete investigations
Reuse playbooks — Save an investigation brief once, then launch it on demand with per-run values
Browse connectors — See which external integrations (GitHub, Splunk, AWS, etc.) are configured
Share — Publish investigation runs for others to see
Related MCP server: Purple AI MCP Server
How it works
flowchart LR
Client["MCP Client"]
Server["juno-mcp-server"]
subgraph UptycsJuno["Uptycs Juno"]
Juno["AI Assistant"]
Connectors["Connectors<br/>(GitHub, Splunk, …)"]
Juno -. "calls during investigation" .-> Connectors
end
Client -- "tool calls" --> Server
Server -- "responses" --> Client
Server -- "HTTPS + JWT auth" --> Juno
Juno -- "findings, recommendations, summaries" --> Server
style Client fill:#4a90d9,stroke:#2c5f8a,color:#fff
style Server fill:#2ecc71,stroke:#1a9c54,color:#fff
style Juno fill:#e74c3c,stroke:#c0392b,color:#fff
style Connectors fill:#e74c3c,stroke:#c0392b,color:#fffThe MCP client discovers available Juno tools via the MCP protocol
When a tool is called, the server authenticates with your Uptycs API key (JWT) and calls the Juno API
Juno processes the request and returns findings, summaries, and recommendations back through the server
Prerequisites
Python 3.11+
uv package manager
An Uptycs account with Juno enabled
An Uptycs API key (how to create one)
Installation
git clone https://github.com/uptycslabs/juno-mcp-server.git
cd juno-mcp-serverAPI key
Download your API key JSON file from the Uptycs console (Configuration > API Keys):
{
"key": "YOUR_API_KEY",
"secret": "YOUR_API_SECRET",
"customerId": "YOUR_CUSTOMER_ID",
"domain": "your-domain",
"domainSuffix": ".uptycs.net"
}Configure your MCP client
Add the following to your MCP client configuration. Example for Claude Desktop (~/Library/Application Support/Claude/claude_desktop_config.json on macOS):
{
"mcpServers": {
"juno": {
"command": "uv",
"args": ["--directory", "/path/to/juno-mcp-server", "run", "juno-mcp"],
"env": {
"UPTYCS_API_KEY_FILE": "/path/to/apikey.json"
}
}
}
}Restart your MCP client. You should see Juno tools available.
Tools
Investigations
Tool | Description |
| Start a new security investigation |
| List recent investigations |
| Get investigation details |
| Delete an investigation |
Runs & Follow-ups
Tool | Description |
| Get investigation run results |
| Ask a follow-up question on a completed run |
Sharing
Tool | Description |
| Share a run with other users |
| Unshare a run |
| List shared runs |
Playbooks
Tool | Description |
| List reusable investigation templates |
| Get a playbook's brief and input parameters |
| Save a new investigation template |
| Partially update a playbook |
| Delete a playbook |
| Start a new investigation from a playbook |
Connectors
Tool | Description |
| List configured external integrations (GitHub, Splunk, AWS, etc.) |
| Get details of a specific connector |
Environment variables
Variable | Required | Default | Description |
| Yes | — | Path to your Uptycs API key JSON file |
| No |
| Set to |
Blocking mode
By default, create_investigation and create_follow_up return immediately with a pending run, and the client must poll get_run until the run completes.
With blocking mode enabled, these calls wait internally until the investigation completes and return the full results directly — no polling required.
{
"mcpServers": {
"juno": {
"command": "uv",
"args": ["--directory", "/path/to/juno-mcp-server", "run", "juno-mcp"],
"env": {
"UPTYCS_API_KEY_FILE": "/path/to/apikey.json",
"JUNO_MCP_BLOCKING": "true"
}
}
}
}Note: Investigations can take several minutes to complete. In blocking mode, the tool call will wait until done.
License
Copyright Uptycs, Inc. All rights reserved.
This server cannot be deployed
Maintenance
Related MCP Connectors
Jepto MCP server that provides access to client knowledgebase & analytics for connected data sources
Unified MCP Server is a remote MCP connector for AI agents and vertical AI products that provides access to 22,000+ authorized SaaS tools across 400+ integrations and 24 categories directly inside LLMs (Claude, GPT, Gemini, Cohere). Tools operate only on explicitly authorized customer connections, enabling agents to safely read and write against live third-party systems.
An MCP server that provides an API to LLMs to manage their JumpCloud resources.
Let AI agents query data and act across all your business apps via MCP.
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceAn MCP server that connects AI agents to the CrowdStrike Falcon platform for intelligent security analysis and automation across various security modules. It provides programmatic access to detections, incidents, host management, and threat intelligence to enhance security operations within agentic workflows.MIT

Purple AI MCP Serverofficial
AlicenseBqualityBmaintenanceEnables MCP clients to interact with SentinelOne's cybersecurity platform for security analysis, threat investigation, and asset management through natural language queries. Provides read-only access to alerts, vulnerabilities, misconfigurations, and inventory data.3398MIT
AccuKnox MCP Serverofficial
FlicenseNot gradedqualityCmaintenanceEnables interaction with the AccuKnox cloud security platform through MCP, allowing users to query cloud assets, vulnerabilities, and perform security analysis via natural language or API.1-- AlicenseNot gradedqualityAmaintenanceA modular, multi-transport Model Context Protocol server that connects AI assistants to the CrowdStrike Falcon platform. Query NG-SIEM logs, triage alerts, inspect endpoints, manage detection rules, and audit cloud security posture — all through natural language.13MIT