Cisco vManage MCP Server
by weegienamja
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| AI_CA_BUNDLE | No | AI-provider CA path, or 'bundled' for packaged Cisco roots | |
| AUDIT_STDERR | No | Also write structured audit events to stderr | false |
| VMANAGE_HOST | No | vManage hostname or IP | sandbox-sdwan-2.cisco.com |
| VMANAGE_PORT | No | vManage HTTPS port | 443 |
| AUDIT_LOG_PATH | No | Path for audit log file (JSONL format) | |
| BROWSER_AI_MODEL | No | Optional browser explainer model override | |
| VMANAGE_PASSWORD | Yes | vManage password | |
| VMANAGE_USERNAME | Yes | vManage username | |
| VMANAGE_WEB_HOST | No | Browser workspace bind address (loopback only) | 127.0.0.1 |
| VMANAGE_WEB_PORT | No | Browser workspace port | 8765 |
| VMANAGE_CA_BUNDLE | No | Private CA bundle used with verification enabled | |
| SPLUNK_HANDOFF_URL | No | Optional credential-free HTTPS specialist view | |
| VMANAGE_VERIFY_SSL | No | Verify TLS certificates (true or false) | true |
| BROWSER_AI_PROVIDER | No | Browser explainer: claude, openai, or gemini | |
| CONNECTOR_CA_BUNDLE | No | Private CA bundle for HTTPS evidence connectors | |
| SPLUNK_EVIDENCE_URL | No | HTTPS JSON evidence feed | |
| VMANAGE_CONFIG_FILE | No | Protected dotenv file written by the installer | ~/.vmanage-mcp/vmanage.env |
| VMANAGE_MAX_RETRIES | No | Transient retries, from 0 through 10 | 3 |
| THOUSANDEYES_MCP_URL | No | ThousandEyes Streamable HTTP MCP endpoint (HTTPS only) | |
| VMANAGE_OTEL_ENABLED | No | Export snapshot metrics through OTLP | false |
| SPLUNK_EVIDENCE_TOKEN | No | Server-side evidence-feed token (required when enabled) | |
| VMANAGE_MCP_TELEMETRY | No | Enable minimal Splunk telemetry | false |
| VMANAGE_WEB_AUTH_MODE | No | Browser identity mode: local or oidc | local |
| VMANAGE_WEB_STATE_DIR | No | Owner-only encrypted browser investigation state | ~/.vmanage-mcp/browser |
| VMANAGE_WEB_TENANT_ID | No | Exact customer tenant claim accepted by this instance (required for OIDC) | |
| THOUSANDEYES_MCP_TOKEN | No | ThousandEyes MCP bearer token (required when enabled) | |
| VMANAGE_WEB_PUBLIC_URL | No | Credential-free HTTPS origin required in OIDC mode | |
| APPDYNAMICS_HANDOFF_URL | No | Optional credential-free HTTPS specialist view | |
| VMANAGE_OTEL_TIMEOUT_MS | No | OTLP force-flush timeout, clamped to 100-30000 ms | 5000 |
| VMANAGE_WEB_OIDC_ISSUER | No | Exact HTTPS token issuer (required for OIDC) | |
| APPDYNAMICS_EVIDENCE_URL | No | HTTPS JSON evidence feed | |
| THOUSANDEYES_HANDOFF_URL | No | Optional credential-free HTTPS specialist view | |
| VMANAGE_MCP_IDE_TELEMETRY | No | Enable Cisco IDE SDK telemetry | false |
| VMANAGE_WEB_ALLOWED_HOSTS | No | Comma-separated public host allowlist (required for OIDC) | |
| VMANAGE_WEB_OIDC_AUDIENCE | No | Required token audience (required for OIDC) | |
| VMANAGE_WEB_OIDC_JWKS_URL | No | HTTPS signing-key endpoint (required for OIDC) | |
| APPDYNAMICS_EVIDENCE_TOKEN | No | Server-side evidence-feed token (required when enabled) | |
| VMANAGE_WEB_OIDC_CA_BUNDLE | No | Private CA bundle for the OIDC JWKS endpoint | |
| OTEL_EXPORTER_OTLP_ENDPOINT | No | Standard OTLP HTTP collector endpoint | |
| THOUSANDEYES_MCP_TIMEOUT_MS | No | Per-collection timeout, clamped to 1000-120000 ms | 30000 |
| VMANAGE_SOURCE_STALE_SECONDS | No | Snapshot source delay threshold, clamped to 1-86400 seconds | 300 |
| VMANAGE_WEB_OIDC_OWNER_ROLES | No | Comma-separated IdP roles mapped to owner | vmanage-owner |
| VMANAGE_WEB_OIDC_VIEWER_ROLES | No | Comma-separated IdP roles mapped to viewer | vmanage-viewer |
| VMANAGE_WEB_TRUSTED_PROXY_IPS | No | Immediate proxy IPs/CIDRs trusted for forwarded HTTPS | 127.0.0.1,::1 |
| VMANAGE_WEB_OIDC_OPERATOR_ROLES | No | Comma-separated IdP roles mapped to operator | vmanage-operator |
| VMANAGE_WEB_OIDC_TOKEN_USE_CLAIM | No | Optional claim distinguishing access tokens | |
| VMANAGE_WEB_OIDC_JWKS_RETRY_SECONDS | No | Backoff after a failed signing-key refresh, clamped to 1-300 seconds | 30 |
| VMANAGE_WEB_OIDC_REQUIRED_TOKEN_USE | No | Required value for the token-use claim |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Server capabilities have not been inspected yet.
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
No tools | |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
This server cannot be deployed
Maintenance
ActivityMaintained
ResponsivenessNo issues