axur-mcp
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@axur-mcpGet details for ticket h7dw97"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Axur MCP Server
A Model Context Protocol (MCP) server for the Axur cybersecurity platform. Provides read-only access to ticket data, enabling AI assistants to search, inspect, and analyze security incidents.
Features
Ticket Search & Retrieval — filter, paginate, and fetch tickets by key
Ticket Details — field values, comments, snapshots, attachments, lifecycle state, takedown options
Ticket Statistics — counts by status, incidents by threat type, takedown/treatment metrics, uptime analysis, global and market-segment benchmarks
Related MCP server: mcp-movidesk
Tools
tickets
Search and retrieve tickets.
Action | Description |
| Search/filter tickets with pagination and sorting |
| Get a single ticket by key |
| Get multiple tickets by comma-separated keys |
| Get ticket change history |
| List all supported ticket types |
ticket_details
Get detailed information for a specific ticket.
Action | Description |
| Ticket field values (status, type, domain, IP, etc.) |
| Comments, descriptions, evidence messages |
| Detection snapshots (domain info, ISP, content, digital location) |
| List attachments for a detection |
| Available state transitions |
| Takedown options and eligibility |
| Full ticket timeline |
ticket_stats
Retrieve ticket statistics and metrics.
Action | Description |
| Ticket count by status (requires |
| Incidents grouped by threat type |
| Takedown success rate, median time to notification |
| Internal treatment success rate and metrics |
| Resolution uptime distribution (buckets: <1d, 2d, 5d, etc.) |
| Treatment uptime distribution |
| Median incidents across all Axur customers (13-month trend) |
| Mean incidents across all Axur customers |
| Median incidents for your market segment |
| Mean incidents for your market segment |
Setup
Prerequisites
Node.js 18+
An Axur API token (get one here)
Install
git clone https://github.com/Just5ky/axur-mcp.git
cd axur-mcp
npm install
npm run buildConfigure
cp .env.example .env
# Edit .env and add your Axur API tokenUsage with Claude Desktop
Add to your Claude Desktop config (~/Library/Application Support/Claude/claude_desktop_config.json):
{
"mcpServers": {
"axur": {
"command": "node",
"args": ["/path/to/axur-mcp/dist/index.js"],
"env": {
"AXUR_API_TOKEN": "your_token_here"
}
}
}
}Usage with other MCP clients
# Run directly
AXUR_API_TOKEN=your_token node dist/index.jsExample Queries
Once connected to an AI assistant:
"Show me all open phishing tickets from this month"
"Get details for ticket h7dw97"
"What are the takedown metrics for the last 30 days?"
"How do our incident numbers compare to the market segment median?"
"List all ticket types supported by the platform"
API Coverage
This server covers the read-only Axur Platform ticket APIs:
tickets-api— ticket search, retrieval, statstickets-core— field values, ticket typestickets-texts— textual data (comments, evidence)tickets-snapshots— detection snapshotstickets-attachments— attachment listingtickets-lifecycle— lifecycle state inspectiontickets-takedown— takedown status inspectiontickets-timeline— timeline history
Rate Limits
The Axur API enforces a rate limit of 60 requests per minute on stats endpoints. The server surfaces 429 errors directly — plan queries accordingly.
License
MIT
Available Tools
3 toolsticket_detailsA
Retrieve detailed ticket information from Axur: field values, texts/comments, detection snapshots, attachments, lifecycle transitions, takedown options, and timeline.
| Name | Required | Description | Default |
|---|---|---|---|
| action | Yes | Action: fields (ticket field values), texts (comments/descriptions/evidence), snapshots (detection snapshots — domain, ISP, content), attachments (list attachments for a detection), lifecycle (available state transitions), takedown (takedown options), timeline (ticket timeline history) | |
| ticketKey | Yes | Ticket key (required for all actions) | |
| detectionIndex | No | Detection index (required for snapshots and attachments, default 0) |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries full burden for behavioral disclosure. It only states 'Retrieve', implying read-only, but lacks details on side effects, permissions, error handling, or rate limits. The list of data types is informative but does not describe behavioral traits.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single sentence that efficiently lists all data categories, front-loading the core purpose. No wasted words; every part adds value.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given no output schema and three parameters (one enum), the description adequately enumerates the possible actions and their return types. However, it lacks structural details of the response (e.g., format), which is acceptable due to the clear mapping between actions and data types.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100%, so baseline is 3. The description adds a high-level summary of what each action returns, but it does not provide details beyond the schema, making it marginally helpful. No parameter semantics are elaborated beyond the schema descriptions.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool retrieves detailed ticket information and lists specific data categories (fields, texts, snapshots, etc.), using a specific verb and resource. It distinguishes from siblings 'tickets' (list) and 'ticket_stats' (statistics) by focusing on a single ticket's details.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description implies use for accessing details of a specific ticket, but it does not explicitly state when to use this tool versus siblings or provide exclusions. No alternatives are mentioned beyond the implied differentiation.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
ticketsC
Search, retrieve, and inspect Axur platform tickets. Actions: list (filter/search tickets), get (single ticket), bulk_get (multiple tickets by keys), history (ticket change history), types (list supported ticket types).
| Name | Required | Description | Default |
|---|---|---|---|
| page | No | Page number (default 1) | |
| order | No | Sort order | |
| action | Yes | Action to perform: list (search/filter tickets), get (single ticket by key), bulk_get (multiple tickets by keys), history (ticket history), types (supported ticket types) | |
| filter | No | Query filter for list action. Example: 'current.type=phishing¤t.status=open¤t.open.date=ge2024-01-01' | |
| sortBy | No | Sort field. Example: 'ticket.creation.date' | |
| include | No | Fields to include for list/get: 'fields,snapshots,texts,attachments'. Default is all. | |
| pageSize | No | Page size (default 50) | |
| timezone | No | UTC offset. Example: '-03:00' or 'Z' | |
| ticketKey | No | Ticket key (required for get, history) | |
| ticketKeys | No | Comma-separated ticket keys (required for bulk_get) |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The description implies read-only operations ('search, retrieve, inspect'), but it does not explicitly state that the tool is non-destructive. There are no annotations to cover this, so the description carries the burden. It fails to disclose authentication needs, rate limits, or any side effects, leaving behavioral traits ambiguous.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is structured as a list of actions but is somewhat verbose. It front-loads the main purpose but could be more concise by focusing on the primary 'list' action and noting sub-actions briefly. Each sentence provides some value, but the length could be reduced without losing clarity.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's complexity (10 parameters, multiple actions) and lack of output schema, the description does not sufficiently explain what the tool returns for each action. It describes input but not output structure or behavior, leaving gaps for the agent to understand the full context of invocation.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The input schema has 100% description coverage, meaning each parameter already has a description. The tool description adds minimal new semantic value beyond repeating the action list. The baseline is 3 due to high schema coverage, and the description does not exceed it.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool is for searching, retrieving, and inspecting tickets, and it enumerates specific actions (list, get, bulk_get, history, types). However, it does not explicitly distinguish this tool from sibling tools 'ticket_details' and 'ticket_stats', which are likely more specialized.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides no guidance on when to use this tool versus alternatives. With sibling tools like 'ticket_details' and 'ticket_stats', the agent has no criteria to decide which tool to invoke. The description only lists actions without context on when each is appropriate.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
ticket_statsA
Retrieve Axur ticket statistics: counts by status, incidents by threat type, takedown/treatment metrics and uptime, global and market-segment incident medians/means. Note: from/to date range must not exceed 90 days.
| Name | Required | Description | Default |
|---|---|---|---|
| to | No | End date (YYYY-MM-DD or YYYY-MM-DDTHH:mm:ss). Required for all actions. | |
| from | No | Start date (YYYY-MM-DD or YYYY-MM-DDTHH:mm:ss). Required for most actions. Max 90-day range. | |
| action | Yes | Stats action: count_by_status, incident_by_type, takedown_metrics, internal_treatment, takedown_uptime, treatment_uptime, global_median, global_mean, segment_median, segment_mean | |
| assets | No | Asset key filter | |
| status | No | Ticket status for count_by_status: open, quarantine, incident, treatment, closed | |
| customer | No | Customer name filter | |
| timezone | No | UTC offset. Example: '-03:00' | |
| ticketTypes | No | Comma-separated ticket types. Example: 'phishing,paid-search' |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the full burden. It describes the types of stats and the date constraint, but does not explicitly state that the tool is read-only or whether it has any side effects. The behavioral traits are mostly inferred as safe retrieval.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is two sentences: the first breaks down what is retrieved, and the second gives a critical constraint. It is front-loaded, efficient, and every sentence earns its place.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given 8 parameters, no output schema, and moderate complexity, the description covers the purpose and a key constraint but lacks details on return format, pagination, or potential errors. Some ambiguity remains for the agent.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100% with all parameters described. The description adds value by emphasizing the 90-day maximum date range and listing the action types, which helps the agent understand the purpose beyond the schema definitions.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states it retrieves Axur ticket statistics and enumerates several categories (counts by status, incidents by threat type, etc.). It distinguishes from siblings 'ticket_details' and 'tickets' by focusing on aggregated metrics rather than individual tickets.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description explicitly mentions the 90-day date range constraint, which is a critical usage guideline. However, it does not provide explicit when-to-use or when-not-to-use guidance relative to sibling tools, though the tool name and content imply it's for statistics.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
3 tool updates
v1.0.0- First observed
ticket_details - First observed
ticket_stats - First observed
tickets
TDQS
Scored across 3 tools
The tools are mostly distinct: 'tickets' handles search, list, and summary retrieval; 'ticket_details' provides deep single-ticket information; 'ticket_stats' covers statistics. However, there is potential overlap between 'tickets' get action and 'ticket_details', as both retrieve ticket info, but descriptions suggest different detail levels.
All tool names follow a consistent 'ticket_' prefix with descriptive suffixes: 'tickets', 'ticket_details', 'ticket_stats'. The naming is predictable and uses snake_case uniformly.
With only 3 tools, the count is at the lower borderline. While the 'tickets' tool bundles multiple actions (list, get, bulk_get, history, types), the overall set feels slightly thin for a platform that likely involves CRUD and lifecycle management.
The tools are purely read-only (retrieve, search, stats). Missing operations to create, update, delete, or take action on tickets (e.g., takedown) is a significant gap for a security platform, limiting agent ability to respond to threats.
Maintenance
Related MCP Connectors
Remote MCP server for managing Muninx tickets, messages, ticket search, and support analytics.
Cybersecurity MCP server for URL scanning, threat intelligence, and domain reputation.
Secure MCP server for exploring incwo CRM data, documents, and email workflows.
MCP server for querying and analyzing data from ad platforms, analytics tools, and spreadsheets
Related MCP Servers
- AlicenseNot gradedqualityAmaintenanceAn MCP server for the RocketCyber Managed SOC platform that provides read-only access to security data including incidents, agents, and events. It enables users to monitor and query security information through 10 specialized tools and resources.Apache 2.0
- FlicenseNot gradedqualityDmaintenanceRead-only MCP server for querying Movidesk tickets through the public Movidesk API.9 npm-
- AlicenseAqualityBmaintenanceA read-only MCP server for Archery that enables secure instance query, ticket management, and restricted SQL execution through AI clients.101MIT
- AlicenseNot gradedqualityCmaintenanceMCP server for investigating cloud incidents and managing approvals. Provides read-only tools to list incidents, investigate incidents, and list approvals, keeping remediation behind human approval.MIT