ironscales-mcp
This server connects AI assistants to the Ironscales email security platform, enabling phishing incident management, email investigation, remediation, and security reporting.
Core Navigation & Status
Check API connection status — verify connectivity and see available domains
Navigate between domains — switch between functional areas
Available Domains
Incidents — Investigate and triage phishing incidents; view incident details (subject, status, severity, sender, affected recipients, threat indicators) via interactive cards in supported hosts
Email — Investigate emails and manage email classification
Remediation — Execute email remediations and quarantine actions
Stats — View company-level security statistics and reports
Allowlist — Manage sender allowlists and blocklists
Additional Highlights
Interactive, brandable incident cards (customizable via
MCP_BRAND_*environment variables)Supports Claude Desktop, Claude Code (CLI), and Docker deployment
Transport modes:
stdio(default) orhttp
Ironscales MCP Server
A Model Context Protocol (MCP) server for Ironscales email security. Enables AI assistants to investigate phishing incidents, manage email classification, execute remediations, and view security statistics.
This is a Model Context Protocol (MCP) server that connects Claude (or any MCP-compatible AI) to your Ironscales environment.
Part of the MSP Claude Plugins ecosystem — a growing suite of AI integrations for the MSP stack. Built by MSPs, for MSPs.
Interactive Incident Card (MCP Apps)
ironscales_incidents_get renders as an interactive card in MCP Apps hosts
(Claude Desktop/web) showing the phishing incident's subject, status, severity,
sender, affected recipients, and threat indicators; plain-JSON behavior is
unchanged in other hosts. The card is read-only — remediation stays with the
model-driven remediation tools. It is neutral by default and brandable via
window.__BRAND__ injection or MCP_BRAND_* env vars (MCP_BRAND_NAME,
MCP_BRAND_LOGO_URL, MCP_BRAND_PRIMARY_COLOR, MCP_BRAND_ACCENT_COLOR,
MCP_BRAND_BG, MCP_BRAND_TEXT) — no rebuild needed.
Related MCP server: avanan-mcp
Installation
npm install @wyre-technology/ironscales-mcpConfiguration
Set the following environment variables:
Variable | Required | Description |
| Yes | Your Ironscales API key |
| Yes | Your Ironscales company ID |
| No | Transport mode: stdio (default) or http |
Usage
Running with Claude Desktop
Add to your Claude Desktop claude_desktop_config.json:
{
"mcpServers": {
"ironscales-mcp": {
"command": "npx",
"args": ["@wyre-technology/ironscales-mcp"],
"env": {
"IRONSCALES_API_KEY": "your-ironscales-api-key"
"IRONSCALES_COMPANY_ID": "your-ironscales-company-id"
}
}
}
}Running with Claude Code (CLI)
claude mcp add ironscales-mcp \
-e IRONSCALES_API_KEY=your-value \
-e IRONSCALES_COMPANY_ID=your-value \
-- npx -y @wyre-technology/ironscales-mcpDocker
docker build -t ironscales-mcp .
docker run \
-e IRONSCALES_API_KEY=your-value \
-e IRONSCALES_COMPANY_ID=your-value \
-p 8080:8080 ironscales-mcpAvailable Domains
Allowlist
Manage email allowlists and blocklists
Email investigation and classification
Incidents
Phishing incident management and triage
Remediation
Execute email remediations and quarantine
Stats
Security statistics and reporting
Development
# Clone the repository
git clone https://github.com/wyre-technology/ironscales-mcp.git
cd ironscales-mcp
# Install dependencies
npm install
# Build
npm run build
# Run tests
npm testContributing
Contributions are welcome! Please see CONTRIBUTING.md if present, or open an issue to discuss changes.
License
Licensed under the Apache License, Version 2.0. See LICENSE for details.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- Alicense-qualityDmaintenanceAn advanced email security analysis MCP server for real-time phishing detection, comprehensive header analysis, and threat intelligence integration. It enables users to extract indicators of compromise and validate email authentication protocols like DKIM, SPF, and DMARC.Last updatedMIT
- AlicenseAqualityAmaintenanceMCP server for Checkpoint Harmony Email & Collaboration (Avanan). Enables AI assistants to manage email security, anti-phishing, anti-malware, and threat detection via the Avanan API.Last updated131Apache 2.0
- AlicenseBqualityAmaintenanceMCP server for KnowBe4 — security awareness training, phishing simulation, and user risk management API integrationLast updated30Apache 2.0
- Flicense-qualityAmaintenanceMCP server for ThreatLocker — zero-trust application allowlisting, approval requests, audit logsLast updated1
Related MCP Connectors
MCP Server for agents to onboard, pay, and provision services autonomously with InFlow
MCP server for LeadDelta — manage LinkedIn connections and CRM data via AI assistants.
Managed LinkedIn MCP server for AI agents: search, connect, message and enrich on accounts you own.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/wyre-technology/ironscales-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server