bigfix-root-mcp
Provides read-only tools for interacting with the HCL BigFix root server REST API, including session relevance queries, client fast queries, server info retrieval, site listing, computer group and operator lookups, dashboard variable reads, and a generic read-only API escape hatch.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@bigfix-root-mcphow many computers are reporting in my enterprise"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
bigfix-root-mcp
A minimal, read-only MCP server around the besapi library, exposing the HCL BigFix root server REST API to MCP clients. Built on FastMCP 4 (stateless).
Focus: session relevance queries (data the server already has) and client fast query (live questions answered by BigFix agents), plus a few read-only helpers.
Tools
Tool | Purpose |
| Evaluate session relevance on the root server; returns the JSON envelope ( |
| Submit a client fast query, return its |
| Fetch current (cumulative) results for a query ID; safe to call repeatedly. |
| Submit + poll in one call with progress notifications; stops on expected count reached, results stable, or timeout. |
| Root server version info ( |
| Sites visible to the configured operator. |
| Look up a group by name — requires an explicit |
| Look up a console operator by name. |
| Read a dashboard datastore variable. |
| Configured user/root server, main-operator status; connectivity smoke test. |
| Read-only escape hatch: GET any |
Client fast query semantics
Client queries are answered by live agents: results accumulate at
/api/clientqueryresults/{id} over seconds to minutes as clients report in,
and there is no completion flag. The client_query tool polls with three
termination heuristics (reported in stop_reason):
expected_count_reached— as many distinct computers reported as targeted;results_stable— no new computers forstable_pollsconsecutive polls;timeout— partial results at timeout are a normal outcome (offline agents never report), not an error.
For long waits, use client_query_submit then client_query_results
repeatedly instead of a single blocking call.
Related MCP server: MSSQL-MCP
Configuration
Environment variables win over config files:
Setting | Env var / | Default |
Root server URL |
| — |
REST operator |
| — |
Password |
| — |
TLS verification |
|
|
Config files are searched in besapi's order: /etc/besapi.conf,
~/besapi.conf, ~/.besapi.conf, ./besapi.conf — same
[besapi] section format as besapi/bescli, so an existing config just works.
Prefer keeping credentials in ~/besapi.conf over MCP client config files.
Example MCP client config (see .mcp.json):
{
"mcpServers": {
"bigfix-root": {
"command": "uvx",
"args": ["bigfix-root-mcp"]
}
}
}Install / run
pip install bigfix-root-mcp # or: uvx bigfix-root-mcpFrom a checkout:
pip install -e ".[dev]"
bigfix-root-mcp # or: python -m bigfix_root_mcpSmoke test against a live root server with MCP Inspector:
npx @modelcontextprotocol/inspector bigfix-root-mcpthen call whoami, session_relevance_query with number of bes computers,
and client_query targeting a known computer ID.
Operator scope
Every result is limited to what the configured REST operator can see. Only a
master operator has full visibility; a regular operator can never be
certain its view is complete, and cannot distinguish "does not exist" from
"outside my scope". So number of bes computers returning 35 means 35
computers visible to this operator — a lower bound, not the BigFix total.
whoami reports is_main_operator for exactly this reason: check it before
treating any result as the full state of BigFix. The tool descriptions carry
this caveat so LLM clients don't overstate scoped results.
Safety and design notes
Read-only surface: only the tools above are registered; no mutating besapi calls exist in this package. One nuance: submitting a client query does create a query object server-side, but agents only evaluate relevance against it — no managed-endpoint state changes. Any future write support would be opt-in via an explicit environment flag.
Explicit site paths: this server never uses besapi's mutable "current site path" connection state (
set_current_site_path/get_current_site_path— a bescli convenience); tools that need a site take a requiredsite_pathparameter.Stdout hygiene: stdout belongs to the MCP stdio transport; all logging goes to stderr, and config loading avoids besapi helpers that print.
TLS: verification is off by default to match besapi; set
BES_SSL_VERIFY=true(or a CA bundle path) for anything beyond a lab.Generic BigFix logic here is written to be upstreamed into besapi — see docs/besapi-proposals.md.
Documentation
Doc | Contents |
Client fast query protocol reference: endpoints, payloads, live-captured result schema, termination heuristics and their tradeoffs. | |
besapi behaviors this wrapper depends on or works around (error surfacing, connection lifecycle, return shapes, site-path state). | |
Why the server is shaped this way, plus FastMCP 4 beta specifics. | |
Proposed upstream besapi changes that would let this project shrink. |
Development
python3 -m venv .venv && .venv/bin/pip install -e ".[dev]"
.venv/bin/python -m pytestTests run entirely offline against a scripted fake BESConnection, including
in-memory end-to-end MCP calls via fastmcp.Client.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseAqualityCmaintenanceA read-only MCP server for InvGate Asset Management, enabling natural language queries for assets, people, computers, servers, software, and API health.Last updated12301MIT
- Alicense-qualityAmaintenanceSecurity-first, read-only MCP server for Microsoft SQL Server, enabling safe natural-language querying of databases.Last updated21MIT
- FlicenseAqualityCmaintenanceA read-only MCP server that enables AI assistants to query ServiceNow instances—incidents, changes, users, CMDB—with malformed query linting and injection protection.Last updated7
- Alicense-qualityAmaintenanceA read-only MCP server that enables natural language querying of DSpace 7+ repositories via the REST API, allowing users to search, retrieve items, and analyze repository data.Last updated2MIT
Related MCP Connectors
Official Microsoft MCP Server to query Microsoft Entra data using natural language
Read-only MCP server for ClassQuill, a tutoring-business-management platform.
GibsonAI MCP server: manage your databases with natural language
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/jgstew/bigfix-root-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server