Skip to content
mcp/skillhub

Abnormal Security MCP Server

by servosityio.github.Servosity/abnormal-mcpv0.1.3

Every Action1 endpoint, plus fleet-wide patch and vulnerability views across all your organizations.

55stdioofficial registry

context tax

queued

security

queued

cold start

queued

freshness

Active6d ago

Install Abnormal Security MCP server

No published package or hosted endpoint yet — see the repository README for build-from-source instructions.

Configuration

VariableRequiredSecretDescription
ABNORMAL_API_TOKENyesyesSet the ABNORMAL_API_TOKEN credential for the Abnormal Security MCP server.
ABNORMAL_BASE_URL——Base URL for the Abnormal Security API. Leave the prefilled default unless your account uses a different regional or self-hosted host.
ACRONIS_BASE_URL——Full API base URL. Leave blank: the CLI builds it from ACRONIS_DATACENTER. Set it only to point at a different host.
ACRONIS_BEARER_AUTHyesyesSets ACRONIS_BEARER_AUTH for the Acronis Cyber Protect Cloud MCP server.
ACRONIS_CLIENT_IDyesyesOAuth2 client ID of the Acronis API client (Acronis console: Settings > API clients). Used with ACRONIS_CLIENT_SECRET to mint a bearer token.
ACRONIS_CLIENT_SECRETyesyesOAuth2 client secret paired with ACRONIS_CLIENT_ID. Acronis shows it once, when the API client is created.
ACRONIS_DATACENTER——Acronis datacenter host prefix (for example eu2-cloud or us-cloud).
ACTION1_BASE_URL——Base URL for the Action1 API. Leave the prefilled default unless your account uses a different regional or self-hosted host.
ACTION1_CLIENT_IDyesyesSet the ACTION1_CLIENT_ID credential for the Action1 MCP server.
ACTION1_CLIENT_SECRETyesyesSet the ACTION1_CLIENT_SECRET credential for the Action1 MCP server.
ACTION1_OAUTH2—yesPre-minted Action1 bearer token, used instead of ACTION1_CLIENT_ID + ACTION1_CLIENT_SECRET. Leave blank when you set the client ID and secret; the CLI mints and refreshes the token itself.
ACTION1_ORG_ID——Organization ID the fleet commands scope to by default (the --org flag overrides it). Leave blank to span every organization your credentials can see.
ACTION1_NO_CONFIG_WRITE——Set to 1 to keep credentials off disk. The token cache becomes a no-op, so the connector mints a fresh token each run instead of writing one to config.toml. Leave blank for the default cached behaviour.
AFI_API_KEYyesyesSet the AFI_API_KEY credential for the Afi MCP server.
AFI_BASE_URL——Base URL for the Afi API. Leave the prefilled default unless your account uses a different regional or self-hosted host.
APPDIRECT_BASE_URL——Base URL for the AppDirect API. Leave the prefilled default unless your account uses a different regional or self-hosted host.
APPDIRECT_CLIENT_IDyesyesSet the APPDIRECT_CLIENT_ID credential for the AppDirect MCP server.
APPDIRECT_CLIENT_SECRETyesyesSet the APPDIRECT_CLIENT_SECRET credential for the AppDirect MCP server.
APPDIRECT_OAUTH_SCOPEyesyesOptional. Overrides the OAuth2 scope sent to AppDirect (default: ROLE_PARTNER ROLE_PARTNER_READ).
APPDIRECT_TOKEN_URL——Token endpoint the client-credentials exchange posts to. Leave the prefilled default unless your tenant uses a different token endpoint.
APPDIRECT_NO_CONFIG_WRITE——Set to 1 to keep credentials off disk. The token cache becomes a no-op, so the connector mints a fresh token each run instead of writing one to config.toml. Leave blank for the default cached behaviour.
ATERA_ACCOUNT_APIyesyesSet the ATERA_ACCOUNT_API credential for the Atera MCP server.
ATERA_API_KEYyesyesSet the ATERA_API_KEY credential for the Atera MCP server.
ATERA_BASE_URL——Base URL for the Atera API. Leave the prefilled default unless your account uses a different regional or self-hosted host.
AUTOTASK_API_INTEGRATION_CODEyesyesSets AUTOTASK_API_INTEGRATION_CODE for the Autotask PSA MCP server.
AUTOTASK_BASE_URL——Base URL for the Autotask PSA API. Leave the prefilled default unless your account uses a different regional or self-hosted host.
AUTOTASK_PSA_SECRETyesyesSet the AUTOTASK_PSA_SECRET credential for the Autotask MCP server.
AUTOTASK_PSA_USER_NAMEyesyesSet the AUTOTASK_PSA_USER_NAME credential for the Autotask MCP server.
AUVIK_API_KEYyesyesAuvik API key (Basic auth password). Auvik > Admin > Integrations > Auvik API.
AUVIK_BASE_URLyes—Your Auvik regional API host with no path suffix, e.g. https://auvikapi.us1.my.auvik.com
AUVIK_TENANT——Tenant ID the inventory reads and sync default to (the --tenant flag overrides it). Child tenants are included in the response. Leave blank to use your credential's own tenant.
AUVIK_USERNAMEyes—The Auvik user email whose API key you are using (Basic auth username).
AUVIK_USER_AGENT——Overrides the User-Agent the CLI sends on Auvik requests. Leave blank to use the CLI's own built-in User-Agent.
PRINTING_PRESS_CLIENT_PROFILE——Binds this MCP server to one tenant-gated client profile, so every call answers for that customer. Leave blank to use the profile configured as default_client_profile.
AVANAN_APP_IDyesyesSet the AVANAN_APP_ID credential for the Avanan MCP server.
AVANAN_BASE_URL——Base URL for the Avanan API. Leave the prefilled default unless your account uses a different regional or self-hosted host.
AVANAN_CLIENT_SECRETyesyesSet the AVANAN_CLIENT_SECRET credential for the Avanan MCP server.
AVANAN_TOKENyesyesBearer token for the Avanan Smart API. Minted from your Avanan client ID and secret by `auth login`, or pasted here directly.
AVANAN_USER_AGENT——Overrides the User-Agent the CLI sends on Avanan requests. Leave blank to use the CLI's own built-in User-Agent.
BLUMIRA_API_TOKEN—yesPre-minted Blumira JWT. An alternative to BLUMIRA_CLIENT_ID + BLUMIRA_CLIENT_SECRET: set this OR the Client ID/Secret pair.
BLUMIRA_BASE_URL——Base URL for the Blumira API. Leave the prefilled default unless your account uses a different regional or self-hosted host.
BLUMIRA_CLIENT_ID—yesBlumira API Client ID (Settings > Organization > Generate API Credentials). With BLUMIRA_CLIENT_SECRET, the server mints and auto-refreshes a JWT.
BLUMIRA_CLIENT_SECRET—yesBlumira API Client Secret, paired with BLUMIRA_CLIENT_ID to mint a JWT (OAuth2 client_credentials, audience public-api).
CIPP_API_KEYyesyesSet the CIPP_API_KEY credential for the CIPP MCP server.
CIPP_BASE_URLyes—Base URL of your self-hosted CIPP instance's API, e.g. https://cipp.example.com/api. The shipped default points at an example host, so until you set this the CLI is not talking to your tenant at all.
CIPP_NO_CONFIG_WRITE——Set to 1 to keep credentials off disk. The token cache becomes a no-op, so the connector mints a fresh token each run instead of writing one to config.toml. Leave blank for the default cached behaviour.
CONNECTWISE_CONTROL_BASE_URLyes—Your ScreenConnect instance base URL, e.g. https://company.screenconnect.com (per-instance).
CONNECTWISE_CONTROL_USERNAMEyes—Your ConnectWise Control instance user name (HTTP Basic auth).
CONNECTWISE_CONTROL_PASSWORDyesyesYour ConnectWise Control instance password (HTTP Basic auth).
CONNECTWISE_MANAGE_BASE_URL——Base URL for the ConnectWise PSA API. Leave the prefilled default unless your account uses a different regional or self-hosted host.
CW_API_VERSION——Pins the ConnectWise Manage API version sent on each request, e.g. 2025.1. Leave blank to use the version your instance defaults to.
CW_CLIENT_IDyesyesSet the CW_CLIENT_ID credential for the ConnectWise Manage MCP server.
CW_COMPANY_IDyes—ConnectWise Manage company ID/codebase used in the composite Basic auth username.
CW_PRIVATE_KEYyesyesAPI Member private key used as the composite Basic auth password.
CW_PUBLIC_KEYyesyesAPI Member public key used with the company ID in the composite Basic auth username.
CW_SITEyes—ConnectWise Manage region host such as api-na.myconnectwise.net, api-eu.myconnectwise.net, api-au.myconnectwise.net, or your on-prem host.
CORK_API_KEYyesyesSet the CORK_API_KEY credential for the Cork MCP server.
CORK_BASE_URL——Base URL for the Cork API. Leave the prefilled default unless your account uses a different regional or self-hosted host.
CORK_USER_AGENT——Overrides the User-Agent the CLI sends on Cork requests. Leave blank to use the CLI's own built-in User-Agent.
COVE_BASE_URL——Base URL for the Cove Data Protection API. Leave the prefilled default unless your account uses a different regional or self-hosted host.
COVE_PARTNERyes—The full customer/partner string exactly as it appears in the Cove console dropdown, including the parenthesised email, e.g. 'Acme Corp (admin@acme.com)'.
COVE_PASSWORDyesyesAPI token issued with the Cove API user. Cove shows it once, at creation.
COVE_USERNAMEyes—Login name of the Cove API user (Cove console: Settings > API users). This is the API user's login, not your console email.
CROWDSTRIKE_BASE_URL——Base URL for the CrowdStrike Falcon API. Leave the prefilled default unless your account uses a different regional or self-hosted host.
CROWDSTRIKE_OAUTH_SCOPEyesyesSet the CROWDSTRIKE_OAUTH_SCOPE credential for the CrowdStrike MCP server.
CROWDSTRIKE_TOKEN_URL——Token endpoint the client-credentials exchange posts to. Leave the prefilled default unless your tenant uses a different token endpoint.
FALCON_CLIENT_IDyesyesSet the FALCON_CLIENT_ID credential for the CrowdStrike MCP server.
FALCON_CLIENT_SECRETyesyesSet the FALCON_CLIENT_SECRET credential for the CrowdStrike MCP server.
CROWDSTRIKE_NO_CONFIG_WRITE——Set to 1 to keep credentials off disk. The token cache becomes a no-op, so the connector mints a fresh token each run instead of writing one to config.toml. Leave blank for the default cached behaviour.
DATAGATE_API_KEYyesyesBearer token from your DataGate account.
DATAGATE_CLIENT_IDyesyesClientId GUID from your DataGate account. Required in addition to the Bearer token on every request.
DATAGATE_BASE_URL——Full API base URL. Leave blank to use DataGate's production endpoint (api.dgportal.net).
DATAGATE_USER_AGENT——Overrides the User-Agent the CLI sends on DataGate requests.
DATAGATE_MCP_HTTP_TOKEN—yesRequired only when running the MCP server with --transport http. Not needed for the default local stdio transport.
DATTO_BCDR_BASE_URL——Base URL for the Datto BCDR API. Leave the prefilled default unless your account uses a different regional or self-hosted host.
DATTO_BCDR_PUBLIC_KEYyesyesSet the DATTO_BCDR_PUBLIC_KEY credential for the Datto BCDR MCP server.
DATTO_BCDR_SECRET_KEYyesyesSet the DATTO_BCDR_SECRET_KEY credential for the Datto BCDR MCP server.
DATTO_BCDR_MCP_HTTP_TOKEN—yesRequired only when running the MCP server with --transport http. Not needed for the default local stdio transport.
DATTO_BCDR_USER_AGENT——Overrides the User-Agent the CLI sends on Datto BCDR requests. Leave blank to use the CLI's own built-in User-Agent.
DATTO_RMM_API_KEYyesyesSet the DATTO_RMM_API_KEY credential for the Datto RMM MCP server.
DATTO_RMM_API_SECRET_KEYyesyesSet the DATTO_RMM_API_SECRET_KEY credential for the Datto RMM MCP server.
DATTO_RMM_BASE_URL——Full API base URL, e.g. https://merlot-api.centrastage.net/api. Overrides the platform shortcut above. Leave blank when you set the platform.
DATTO_RMM_PLATFORM——Regional platform shortcut that selects the API host: pinotage, merlot, concord, vidal, zinfandel, or syrah. It is the 'merlot' in merlot.centrastage.net. Leave blank if you set the base URL directly.
DATTO_RMM_TOKENyesyesSet the DATTO_RMM_TOKEN credential for the Datto RMM MCP server.
DATTO_RMM_NO_CONFIG_WRITE——Set to 1 to keep credentials off disk. The token cache becomes a no-op, so the connector mints a fresh token each run instead of writing one to config.toml. Leave blank for the default cached behaviour.
HALOPSA_BASE_URL——Full API base URL. Leave blank: the CLI builds it from HALOPSA_TENANT and HALOPSA_DOMAIN. Set it only to point at a different host.
HALOPSA_CLIENT_IDyesyesOAuth2 client_credentials ID from Configuration → Integrations → Halo PSA API.
HALOPSA_CLIENT_SECRETyesyesOAuth2 client_credentials secret.
HALOPSA_DOMAIN——Domain template variable. Defaults to halopsa.com.
HALOPSA_OAUTH_SCOPEyesyesSets HALOPSA_OAUTH_SCOPE for the HaloPSA MCP server. Required by the generated client for credential refresh or hand-written auth flow.
HALOPSA_SCOPE——Optional. OAuth2 scope (defaults to "all"); set to a narrower scope when your API application requires it
HALOPSA_TENANTyes—Your HaloPSA tenant identifier.
HALOPSA_TOKEN—yesOptional. Pre-issued Bearer access token. Overrides the client_credentials flow when set.
HALOPSA_TOKEN_URL——Token endpoint the client-credentials exchange posts to. Leave blank: the CLI derives it from the base URL.
HALOPSA_NO_CONFIG_WRITE——Set to 1 to keep credentials off disk. The token cache becomes a no-op, so the connector mints a fresh token each run instead of writing one to config.toml. Leave blank for the default cached behaviour.
HUBSPOT_ACCESS_TOKENyesyesSet the HUBSPOT_ACCESS_TOKEN credential for the HubSpot MCP server.
HUBSPOT_BASE_URL——Base URL for the HubSpot API. Leave the prefilled default unless your account uses a different regional or self-hosted host.
HUBSPOT_OWNER_EMAIL——Email address that `--owner me` resolves to when git config user.email is not set. Leave blank to name the owner on each call.
HUBSPOT_MCP_HTTP_TOKEN—yesBearer token required by `hubspot-mcp --transport http`; unused by the default stdio transport.
HUBSPOT_USER_AGENT——Overrides the User-Agent the CLI sends on HubSpot requests.
HUDU_API_KEYyesyesSet the HUDU_API_KEY credential for the Hudu MCP server.
HUDU_BASE_URLyes—Your Hudu instance's API base URL, including the /api/v1 path, e.g. https://your-subdomain.huducloud.com/api/v1 (self-hosted, *.huducloud.com, or a custom domain).
HUNTRESS_API_KEYyesyesSet the HUNTRESS_API_KEY credential for the Huntress MCP server.
HUNTRESS_API_SECRETyesyesSet the HUNTRESS_API_SECRET credential for the Huntress MCP server.
HUNTRESS_BASE_URL——Base URL for the Huntress API. Leave the prefilled default unless your account uses a different regional or self-hosted host.
HUNTRESS_USER_AGENT——Overrides the User-Agent the CLI sends on Huntress requests.
HUNTRESS_MCP_HTTP_TOKEN—yesRequired only when running the MCP server with --transport http. Not needed for the default local stdio transport.
IMMYBOT_BASE_URL——Full API base URL. Leave blank: the CLI builds it from IMMYBOT_SUBDOMAIN. Set it only to point at a different host.
IMMYBOT_CLIENT_IDyesyesSet the IMMYBOT_CLIENT_ID credential for the ImmyBot MCP server.
IMMYBOT_CLIENT_SECRETyesyesSet the IMMYBOT_CLIENT_SECRET credential for the ImmyBot MCP server.
IMMYBOT_SUBDOMAINyes—Set the IMMYBOT_SUBDOMAIN credential for the ImmyBot MCP server.
IMMYBOT_TENANT_IDyes—Set the IMMYBOT_TENANT_ID credential for the ImmyBot MCP server.
IMMYBOT_TOKEN_URL——Token endpoint the client-credentials exchange posts to. Leave the prefilled default unless your tenant uses a different token endpoint.
IMMYBOT_USER_AGENT——Overrides the User-Agent the CLI sends on ImmyBot requests. Leave blank to use the CLI's own built-in User-Agent.
IMMYBOT_NO_CONFIG_WRITE——Set to 1 to keep credentials off disk. The token cache becomes a no-op, so the connector mints a fresh token each run instead of writing one to config.toml. Leave blank for the default cached behaviour.
ITGLUE_API_KEYyesyesSet the ITGLUE_API_KEY credential for the IT Glue MCP server.
ITGLUE_BASE_URL——Base URL for the IT Glue / MyGlue API. Leave the prefilled default unless your account uses a different regional or self-hosted host.
KASEYA_BMS_BASE_URL——Base URL for the Kaseya BMS API. Leave the prefilled default unless your account uses a different regional or self-hosted host.
KASEYA_BMS_BEARER_AUTH—yesAlias for KASEYA_BMS_TOKEN - a pre-minted Kaseya BMS JWT sent as a Bearer token. Set one of the two, or use 'auth login'.
KASEYA_BMS_PASSWORDyesyesPassword for KASEYA_BMS_USERNAME. Exchanged for a JWT; never sent on data calls.
KASEYA_BMS_TENANTyes—Your company name exactly as it appears under My Settings in BMS. The authenticate call rejects the login without it.
KASEYA_BMS_TOKEN—yesPre-minted Kaseya BMS JWT, sent as a Bearer token. Set this OR KASEYA_BMS_BEARER_AUTH; alternatively run 'kaseya-bms-cli auth login' to mint one from username/password/tenant.
KASEYA_BMS_USERNAMEyes—Kaseya BMS login used by `auth login` to exchange for a short-lived JWT.
KNOWBE4_API_KEYyesyesSet the KNOWBE4_API_KEY credential for the KnowBe4 MCP server.
KNOWBE4_BASE_URL——Full API base URL. Leave blank: the CLI builds it from KNOWBE4_REGION. Set it only to point at a different host.
KNOWBE4_REGIONyesyesSet the KNOWBE4_REGION credential for the KnowBe4 MCP server.
KNOWBE4_USER_EVENT_API_KEY—yesSeparate bearer key for the KnowBe4 User Events API, which has its own host and key. Needed only for the `events` commands; leave blank otherwise.
LEVELIO_BASE_URL——Base URL for the Level API. Leave the prefilled default unless your account uses a different regional or self-hosted host.
LEVEL_API_TOKENyesyesSet the LEVEL_API_TOKEN credential for the Level MCP server.
LIONGARD_ACCESS_KEY_ID—yesLiongard Access Key ID, the half that pairs with LIONGARD_ACCESS_KEY_SECRET; the server composes the two into the base64 X-ROAR-API-KEY. One of two ways to authenticate - set EITHER this pair OR the pre-encoded LIONGARD_API_KEY, never both. LIONGARD_API_KEY wins when it is set, so leave it blank to use this pair.
LIONGARD_ACCESS_KEY_SECRET—yesLiongard Access Key Secret, the other half of LIONGARD_ACCESS_KEY_ID. One of two ways to authenticate - set EITHER this pair OR the pre-encoded LIONGARD_API_KEY, never both. LIONGARD_API_KEY wins when it is set, so leave it blank to use this pair.
LIONGARD_API_KEY—yesPre-encoded X-ROAR-API-KEY: base64 of 'accessKeyId:accessKeySecret'. One of two ways to authenticate - set EITHER this key OR the LIONGARD_ACCESS_KEY_ID + LIONGARD_ACCESS_KEY_SECRET pair, never both. This key wins when it is set, and the pair is ignored.
LIONGARD_BASE_URL——Full API base URL. Leave blank: the CLI builds it from LIONGARD_INSTANCE. Set it only to point at a different host.
LIONGARD_INSTANCEyes—Your Liongard subdomain (the 'acme' in acme.app.liongard.com); builds the API URL.
MAXIO_API_KEY—yesSingle-secret Maxio credential, sent as the HTTP Basic username with the constant 'x' as the password. Use this or the MAXIO_USERNAME + MAXIO_PASSWORD pair.
MAXIO_BASE_URL——Full API base URL. Leave blank: the CLI builds it from MAXIO_SITE. Set it only to point at a different host.
MAXIO_PASSWORDyesyesSet the MAXIO_PASSWORD credential for the Maxio MCP server.
MAXIO_SITEyesyesSet the MAXIO_SITE credential for the Maxio MCP server.
MAXIO_USERNAMEyesyesSet the MAXIO_USERNAME credential for the Maxio MCP server.
MSPBOTS_API_KEYyesyesSet the MSPBOTS_API_KEY credential for the MSPbots MCP server.
MSPBOTS_BASE_URL——Base URL for the MSPbots API. Leave the prefilled default unless your account uses a different regional or self-hosted host.
NCENTRAL_JWTyesyesSet the NCENTRAL_JWT credential for the N-able N-central MCP server.
N_CENTRAL_BASE_URL——Base URL for the N-central API. Leave the prefilled default unless your account uses a different regional or self-hosted host.
N_CENTRAL_NO_CONFIG_WRITE——Set to 1 to keep credentials off disk. The token cache becomes a no-op, so the connector mints a fresh token each run instead of writing one to config.toml. Leave blank for the default cached behaviour.
NERDIO_BASE_URLyesyesSet the NERDIO_BASE_URL credential for the Nerdio Manager MCP server.
NERDIO_TOKEN_URLyesyesSet the NERDIO_TOKEN_URL credential for the Nerdio Manager MCP server.
NERDIO_CLIENT_IDyesyesSet the NERDIO_CLIENT_ID credential for the Nerdio Manager MCP server.
NERDIO_CLIENT_SECRETyesyesSet the NERDIO_CLIENT_SECRET credential for the Nerdio Manager MCP server.
NERDIO_OAUTH_SCOPEyesyesSet the NERDIO_OAUTH_SCOPE credential for the Nerdio Manager MCP server.
NERDIO_NO_CONFIG_WRITE——Set to 1 to keep credentials off disk. The token cache becomes a no-op, so the connector mints a fresh token each run instead of writing one to config.toml. Leave blank for the default cached behaviour.
NINJAONE_BASE_URL——Base URL for the NinjaOne API. Leave the prefilled default unless your account uses a different regional or self-hosted host.
NINJAONE_CLIENT_IDyesyesSet the NINJAONE_CLIENT_ID credential for the NinjaOne MCP server.
NINJAONE_CLIENT_SECRETyesyesSet the NINJAONE_CLIENT_SECRET credential for the NinjaOne MCP server.
NINJAONE_OAUTH_SCOPEyesyesSet the NINJAONE_OAUTH_SCOPE credential for the NinjaOne MCP server.
NINJAONE_TOKEN_URL——Token endpoint the client-credentials exchange posts to. Leave the prefilled default unless your tenant uses a different token endpoint.
NINJAONE_NO_CONFIG_WRITE——Set to 1 to keep credentials off disk. The token cache becomes a no-op, so the connector mints a fresh token each run instead of writing one to config.toml. Leave blank for the default cached behaviour.
PAGERDUTY_API_KEYyesyesSet the PAGERDUTY_API_KEY credential for the PagerDuty MCP server.
PAGERDUTY_BASE_URL——Base URL for the PagerDuty API. Leave the prefilled default unless your account uses a different regional or self-hosted host.
PANDADOC_API_KEYyesyesSet the PANDADOC_API_KEY credential for the PandaDoc MCP server.
PANDADOC_BASE_URL——Base URL for the PandaDoc API. Leave the prefilled default unless your account uses a different regional or self-hosted host.
PAX8_AUDIENCE——OAuth2 audience claim requested when minting the Pax8 token. The default is the partner API audience; change it only if Pax8 told you to.
PAX8_BASE_URL——Base URL for the Pax8 API. Leave the prefilled default unless your account uses a different regional or self-hosted host.
PAX8_CLIENT_IDyesyesPax8 Partner API OAuth2 Client ID (Pax8 portal > Integrations).
PAX8_CLIENT_SECRETyesyesPax8 Partner API OAuth2 Client Secret (Pax8 portal > Integrations).
PAX8_OAUTH_SCOPEyesyesOptional OAuth2 scope; omitted from the token request when unset.
PAX8_TOKEN_URL——Token endpoint the client-credentials exchange posts to. Leave the prefilled default unless your tenant uses a different token endpoint.
PAX8_NO_CONFIG_WRITE——Set to 1 to keep credentials off disk. The token cache becomes a no-op, so the connector mints a fresh token each run instead of writing one to config.toml. Leave blank for the default cached behaviour.
PIPEDRIVE_API_KEYyesyesSet the PIPEDRIVE_API_KEY credential for the Pipedrive MCP server.
PIPEDRIVE_BASE_URL——Base URL for the Pipedrive API. Leave the prefilled default unless your account uses a different regional or self-hosted host.
PROOFPOINT_API_SECRETyesyesSet the PROOFPOINT_API_SECRET credential for the Proofpoint MCP server.
PROOFPOINT_BASE_URL——Base URL for the Proofpoint TAP API. Leave the prefilled default unless your account uses a different regional or self-hosted host.
PROOFPOINT_SERVICE_PRINCIPALyesyesSet the PROOFPOINT_SERVICE_PRINCIPAL credential for the Proofpoint MCP server.
QUICKBOOKS_ACCESS_TOKENyesyesOAuth 2.0 bearer access token (scope com.intuit.quickbooks.accounting). Mint it from the Intuit OAuth 2.0 Playground or `quickbooks-cli auth refresh`.
QUICKBOOKS_BASE_URL——Full company-scoped API base, e.g. https://quickbooks.api.intuit.com/v3/company/<realm-id>. Leave blank when you set the realm ID and environment above; the CLI builds this from them.
QUICKBOOKS_CLIENT_ID—yesClient ID of your Intuit app (developer.intuit.com > your app > Keys). Set it with the client secret and refresh token so the CLI can mint a fresh access token; leave blank if you paste an access token instead.
QUICKBOOKS_CLIENT_SECRET—yesClient secret paired with QUICKBOOKS_CLIENT_ID.
QUICKBOOKS_ENVIRONMENT——Which Intuit host the realm lives on: production or sandbox. Combined with the realm ID to build the base URL.
QUICKBOOKS_REALM_IDyes—The QuickBooks company ('realm') ID every call is scoped to. Find it in the Intuit developer dashboard or the sandbox company URL. Without it the CLI cannot build a working base URL.
QUICKBOOKS_REFRESH_TOKEN—yesOAuth 2.0 refresh token. Refresh tokens live ~100 days and rotate on every refresh, so the CLI writes the new one back to its config.
QUICKBOOKS_TOKEN_URL——Token endpoint the client-credentials exchange posts to. Leave the prefilled default unless your tenant uses a different token endpoint.
RESOURCEGURU_BASE_URL——Base URL for the Resource Guru API. Leave the prefilled default unless your account uses a different regional or self-hosted host.
RESOURCEGURU_EMAILyesyesSet the RESOURCEGURU_EMAIL credential for the Resource Guru MCP server.
RESOURCEGURU_PASSWORDyesyesSet the RESOURCEGURU_PASSWORD credential for the Resource Guru MCP server.
REWST_BASE_URL——Rewst API base URL for your region (default https://api.rewst.io; set for EU/AU).
REWST_API_TOKENyesyesRewst API token from an API client you create in the console (sent as a bearer token).
RIVERSIDE_FM_BASE_URL——Base URL for the Riverside API. Optional; defaults to https://riverside.com.
RIVERSIDE_FM_NO_CONFIG_WRITE——Set to 1 to keep credentials off disk. The rotated session cookie is kept in memory for the run and never written back to config.toml; an existing config file is read but not updated. Leave blank for the default cached behaviour.
ROCKETCYBER_API_TOKENyesyesSet the ROCKETCYBER_API_TOKEN credential for the RocketCyber MCP server.
ROCKETCYBER_BASE_URL——Base URL for the RocketCyber API. Leave the prefilled default unless your account uses a different regional or self-hosted host.
ROOTLY_API_KEYyesyesSet the ROOTLY_API_KEY credential for the Rootly MCP server.
ROOTLY_API_TOKENyesyesSet the ROOTLY_API_TOKEN credential for the Rootly MCP server.
ROOTLY_BASE_URL——Base URL for the Rootly API. Leave the prefilled default unless your account uses a different regional or self-hosted host.
RUNZERO_API_KEYyesyesSet the RUNZERO_API_KEY credential for the runZero MCP server.
RUNZERO_BASE_URL——Base URL for the runZero API. Leave the prefilled default unless your account uses a different regional or self-hosted host.
SALESBUILDR_API_KEYyesyesSet the SALESBUILDR_API_KEY credential for the Salesbuildr MCP server.
SALESBUILDR_BASE_URL——Full API base URL. Leave blank: the CLI builds it from SALESBUILDR_TENANT. Set it only to point at a different host.
SALESBUILDR_TENANTyes—Your Salesbuildr tenant subdomain (the {tenant} in https://{tenant}.salesbuildr.com).
SENTINELONE_API_TOKENyesyesSet the SENTINELONE_API_TOKEN credential for the SentinelOne MCP server.
SENTINELONE_BASE_URLyes—Base URL of your SentinelOne management console API, including the version path, e.g. https://usea1-partners.sentinelone.net/web/api/v2.1. The shipped default points at an example host.
SENTINELONE_USER_AGENT——Overrides the User-Agent the CLI sends on SentinelOne requests.
SENTINELONE_MCP_HTTP_TOKEN—yesBearer token callers must present when the server runs with --transport http; not used by the stdio transport.
SERVOSITY_MSP_BASE_URL——Base URL for the Servosity API. Leave the prefilled default unless your account uses a different regional or self-hosted host.
SERVOSITY_MSP_RESELLER_ID——Numeric reseller ID from the partner portal, used to scope reseller reports. Leave blank to let the CLI probe for it from your account.
SERVOSITY_MSP_TOKENyesyesServosity partner API token from the partner portal. Scoped to your reseller account only.
SERVOSITY_MSP_USER_AGENT——Overrides the User-Agent the CLI sends on Servosity requests. Leave blank to use the CLI's own built-in User-Agent.
SHERWEB_BASE_URL——Base URL for the Sherweb API. Leave the prefilled default unless your account uses a different regional or self-hosted host.
SHERWEB_CLIENT_IDyesyesSet the SHERWEB_CLIENT_ID credential for the Sherweb MCP server.
SHERWEB_CLIENT_SECRETyesyesSet the SHERWEB_CLIENT_SECRET credential for the Sherweb MCP server.
SHERWEB_OAUTH_SCOPEyesyesSet the SHERWEB_OAUTH_SCOPE credential for the Sherweb MCP server.
SHERWEB_SUBSCRIPTION_KEYyesyesSet the SHERWEB_SUBSCRIPTION_KEY credential for the Sherweb MCP server.
SHERWEB_TOKEN_URL——Token endpoint the client-credentials exchange posts to. Leave the prefilled default unless your tenant uses a different token endpoint.
SHERWEB_NO_CONFIG_WRITE——Set to 1 to keep credentials off disk. The token cache becomes a no-op, so the connector mints a fresh token each run instead of writing one to config.toml. Leave blank for the default cached behaviour.
SKYKICK_BASE_URL——Base URL for the SkyKick API. Leave the prefilled default unless your account uses a different regional or self-hosted host.
SKYKICK_CLIENT_IDyesyesSet the SKYKICK_CLIENT_ID credential for the SkyKick MCP server.
SKYKICK_CLIENT_SECRETyesyesSet the SKYKICK_CLIENT_SECRET credential for the SkyKick MCP server.
SKYKICK_OAUTH_SCOPEyesyesOptional OAuth scope override for the SkyKick MCP server. Defaults to 'Partner' when unset.
SKYKICK_TOKEN_URL——Token endpoint the client-credentials exchange posts to. Leave the prefilled default unless your tenant uses a different token endpoint.
SKYKICK_NO_CONFIG_WRITE——Set to 1 to keep credentials off disk. The token cache becomes a no-op, so the connector mints a fresh token each run instead of writing one to config.json. Leave blank for the default cached behaviour.
SYNCRO_API_KEYyesyesSet the SYNCRO_API_KEY credential for the Syncro MCP server.
SYNCRO_BASE_URL——Full API base URL. Leave blank: the CLI builds it from SYNCRO_SUBDOMAIN. Set it only to point at a different host.
SYNCRO_SUBDOMAINyesyesSet the SYNCRO_SUBDOMAIN credential for the Syncro MCP server.
TACTICAL_RMM_BASE_URLyes—Base URL of your Tactical RMM API host, e.g. https://api.rmm.example.com. It is the api.* hostname from your Tactical RMM install, not the web UI hostname. The shipped default points at an example host.
TRMM_API_KEYyesyesSet the TRMM_API_KEY credential for the Tactical RMM MCP server.
UNIFI_API_KEYyesyesSet the UNIFI_API_KEY credential for the UniFi MCP server.
UNIFI_BASE_PATH——Path segment appended to the gateway host, when your controller does not serve the Network API at the standard location. Leave blank for a stock UniFi OS gateway.
UNIFI_BASE_URL——Full API base URL, e.g. https://10.0.0.1/proxy/network. Leave blank when you set the gateway host above; the CLI builds this from it.
UNIFI_GATEWAY_HOSTyesyesSet the UNIFI_GATEWAY_HOST credential for the UniFi MCP server.
VEEAM_BASE_URLyes—Your VSPC appliance REST API base URL, e.g. https://vspc.example.com:1280/api/v3 (per-instance).
VEEAM_TOKENyesyesBearer token for the VSPC REST API (POST /token with your portal credentials).
WORDPRESS_BASE_URL——Base URL for the Wordpress API. Leave the prefilled default unless your account uses a different regional or self-hosted host.
WORDPRESS_BASIC_AUTHyesyesSet the WORDPRESS_BASIC_AUTH credential for the WordPress MCP server.
WORDPRESS_MCP_HTTP_TOKEN—yesRequired only when running the MCP server with --transport http. Not needed for the default local stdio transport.
WORDPRESS_USER_AGENT——Overrides the User-Agent sent on WordPress requests. Leave blank to use the built-in User-Agent.
XERO_ACCESS_TOKENyesyesSet the XERO_ACCESS_TOKEN credential for the Xero MCP server.
XERO_AUTHORIZATION_URL——Authorization endpoint the login flow opens. Change it only if Xero moves the endpoint.
XERO_BASE_URL——Base URL for the Xero API. Leave the prefilled default unless your account uses a different regional or self-hosted host.
XERO_CLIENT_ID—yesClient ID of your Xero app (developer.xero.com > My Apps). Set it with the client secret to run the OAuth2 flow; leave blank if you paste an access token instead.
XERO_CLIENT_SECRET—yesClient secret paired with XERO_CLIENT_ID.
XERO_OAUTH2—yesOptional. Sets XERO_OAUTH2 for the Xero MCP server.
XERO_TENANT_IDyes—The Xero organisation ('tenant') GUID sent as the Xero-Tenant-Id header. Every call requires it; `connections list` returns the tenants your token can reach.
XERO_TOKEN_URL——Token endpoint the client-credentials exchange posts to. Leave the prefilled default unless your tenant uses a different token endpoint.
XERO_NO_CONFIG_WRITE——Set to 1 to keep credentials off disk. The token cache becomes a no-op, so the connector mints a fresh token each run instead of writing one to config.toml. Leave blank for the default cached behaviour.
ZAMMAD_API_TOKENyesyesSet the ZAMMAD_API_TOKEN credential for the Zammad MCP server.
ZAMMAD_BASE_URL——Explicit full API base, e.g. https://support.example.com/api/v1. Overrides the instance URL above. Leave blank unless your instance serves the API somewhere non-standard.
ZAMMAD_URLyes—Root URL of your Zammad instance, e.g. https://support.example.com. The CLI appends /api/v1 itself. Without it the CLI points at a placeholder host that is not your instance.
ZAMMAD_MCP_HTTP_TOKEN—yesRequired only when running the MCP server with --transport http. Not needed for the default local stdio transport.
ZAMMAD_USER_AGENT——Overrides the User-Agent the CLI sends on Zammad requests. Leave blank to use the CLI's own built-in User-Agent.
AWS_ACCESS_KEY_IDyesyesAccess key ID for an IAM principal with Cost Explorer read access. Resolved by the AWS SDK's default credential chain.
AWS_BILLING_BASE_URL——Base URL for the AWS Billing Intelligence API. Leave the prefilled default unless your account uses a different regional or self-hosted host.
AWS_BILLING_SLACK_CHANNEL——Slack channel or DM ID that `report --slack` posts to by default (the --slack-channel flag overrides it). Leave blank to pass the destination on every run.
AWS_REGION——Region for the EC2, CloudWatch and S3 calls. Cost Explorer is always served from us-east-1 regardless of this value.
AWS_SECRET_ACCESS_KEYyesyesSecret access key paired with AWS_ACCESS_KEY_ID.
AWS_SESSION_TOKEN—yesSession token, required only when the keys above are temporary STS or SSO credentials. Leave blank for long-lived IAM user keys.
AXCIENT_API_KEYyesyesSet the AXCIENT_API_KEY credential for the Axcient MCP server.
AXCIENT_BASE_URL——Base URL for the Axcient x360Recover API. Leave the prefilled default unless your account uses a different regional or self-hosted host.
BETTERSTACK_API_TOKENyesyesSet the BETTERSTACK_API_TOKEN credential for the Better Stack MCP server.
BETTERSTACK_BASE_URL——Base URL for the Better Stack API. Leave the prefilled default unless your account uses a different regional or self-hosted host.
CONNECTWISE_AUTOMATE_BASE_URL——Full API base URL. Leave blank: the CLI builds it from CONNECTWISE_AUTOMATE_SERVER. Set it only to point at a different host.
CONNECTWISE_AUTOMATE_CLIENT_IDyesyesRegistered integration clientId GUID, sent as the clientId header (required for v2020.11+).
CONNECTWISE_AUTOMATE_SERVERyes—Your Automate host, e.g. company.hostedrmm.com (endpoint base URL).
CONNECTWISE_AUTOMATE_TOKENyesyesBearer token for the ConnectWise Automate API (short-lived; mint with apitoken mint).
DOMOTZ_API_KEYyesyesSet the DOMOTZ_API_KEY credential for the Domotz MCP server.
DOMOTZ_BASE_URL——Full API base URL. Leave blank: the CLI builds it from DOMOTZ_REGION. Set it only to point at a different host.
DOMOTZ_REGION——Selects the Domotz API cell for your portal (default us-east-1-cell-1).
GRADIENT_BASE_URL——Base URL for the Gradient MSP API. Leave the prefilled default unless your account uses a different regional or self-hosted host.
GRADIENT_PARTNER_API_KEYyesyesPartner API key issued alongside the vendor key. Both halves are sent in the GRADIENT-TOKEN header.
GRADIENT_TOKENyesyesSet the GRADIENT_TOKEN credential for the Gradient MSP MCP server.
GRADIENT_VENDOR_API_KEYyesyesVendor API key from Synthesize (Integrations > Custom > Generate API Tokens). Shown once.
MICROSOFT_GRAPH_BASE_URL——Base URL for the Microsoft Graph API. Leave the prefilled default unless your account uses a different regional or self-hosted host.
MICROSOFT_GRAPH_TOKENyesyesSet the MICROSOFT_GRAPH_TOKEN credential for the Microsoft Graph MCP server.
SUPEROPS_API_TOKENyesyesSet the SUPEROPS_API_TOKEN credential for the SuperOps MCP server.
SUPEROPS_BASE_URL——Base URL for the SuperOps API. Leave the prefilled default unless your account uses a different regional or self-hosted host.
SUPEROPS_REGION——Data-centre region your tenant lives in: us or eu. The wrong region answers with an authentication error.
SUPEROPS_SUBDOMAINyes—Your tenant subdomain (SuperOps: Settings > MSP Information). Sent as the CustomerSubdomain header on every call; requests without it are rejected.
THREATLOCKER_API_KEYyesyesPortal API key (ThreatLocker portal: Settings > API Keys), sent as the Authorization header on every call.
THREATLOCKER_BASE_URL——Base URL for the ThreatLocker API. Leave the prefilled default unless your account uses a different regional or self-hosted host.
THREATLOCKER_ORG_ID——Tenant GUID sent as ManagedOrganizationId (the --org flag overrides it). Most Portal API data calls answer 401/403 without it, so set it unless you pass --org on every call.
THREATLOCKER_USER_AGENT——Overrides the User-Agent the CLI sends on ThreatLocker requests. Leave blank to use the CLI's own built-in User-Agent.

Freshness

Active — last maintenance signal 6d ago. The newest of the signals below sets the band.

  1. Last commit (default branch)

    2026-10-03 · 6d ago · GitHub

  2. Latest release

    2026-10-03 · 6d ago · GitHub · action1-v0.1.6

  3. Package published

    no data · npm/PyPI

  4. Registry entry updated

    2026-09-10 · 29d ago · official registry · v0.1.3

FAQ

›Does Abnormal Security require an API key?

Yes. It expects ABNORMAL_API_TOKEN, ACRONIS_BEARER_AUTH, ACRONIS_CLIENT_ID, ACRONIS_CLIENT_SECRET, ACTION1_CLIENT_ID, ACTION1_CLIENT_SECRET, AFI_API_KEY, APPDIRECT_CLIENT_ID, APPDIRECT_CLIENT_SECRET, APPDIRECT_OAUTH_SCOPE, ATERA_ACCOUNT_API, ATERA_API_KEY, AUTOTASK_API_INTEGRATION_CODE, AUTOTASK_PSA_SECRET, AUTOTASK_PSA_USER_NAME, AUVIK_API_KEY, AUVIK_BASE_URL, AUVIK_USERNAME, AVANAN_APP_ID, AVANAN_CLIENT_SECRET, AVANAN_TOKEN, CIPP_API_KEY, CIPP_BASE_URL, CONNECTWISE_CONTROL_BASE_URL, CONNECTWISE_CONTROL_USERNAME, CONNECTWISE_CONTROL_PASSWORD, CW_CLIENT_ID, CW_COMPANY_ID, CW_PRIVATE_KEY, CW_PUBLIC_KEY, CW_SITE, CORK_API_KEY, COVE_PARTNER, COVE_PASSWORD, COVE_USERNAME, CROWDSTRIKE_OAUTH_SCOPE, FALCON_CLIENT_ID, FALCON_CLIENT_SECRET, DATAGATE_API_KEY, DATAGATE_CLIENT_ID, DATTO_BCDR_PUBLIC_KEY, DATTO_BCDR_SECRET_KEY, DATTO_RMM_API_KEY, DATTO_RMM_API_SECRET_KEY, DATTO_RMM_TOKEN, HALOPSA_CLIENT_ID, HALOPSA_CLIENT_SECRET, HALOPSA_OAUTH_SCOPE, HALOPSA_TENANT, HUBSPOT_ACCESS_TOKEN, HUDU_API_KEY, HUDU_BASE_URL, HUNTRESS_API_KEY, HUNTRESS_API_SECRET, IMMYBOT_CLIENT_ID, IMMYBOT_CLIENT_SECRET, IMMYBOT_SUBDOMAIN, IMMYBOT_TENANT_ID, ITGLUE_API_KEY, KASEYA_BMS_PASSWORD, KASEYA_BMS_TENANT, KASEYA_BMS_USERNAME, KNOWBE4_API_KEY, KNOWBE4_REGION, LEVEL_API_TOKEN, LIONGARD_INSTANCE, MAXIO_PASSWORD, MAXIO_SITE, MAXIO_USERNAME, MSPBOTS_API_KEY, NCENTRAL_JWT, NERDIO_BASE_URL, NERDIO_TOKEN_URL, NERDIO_CLIENT_ID, NERDIO_CLIENT_SECRET, NERDIO_OAUTH_SCOPE, NINJAONE_CLIENT_ID, NINJAONE_CLIENT_SECRET, NINJAONE_OAUTH_SCOPE, PAGERDUTY_API_KEY, PANDADOC_API_KEY, PAX8_CLIENT_ID, PAX8_CLIENT_SECRET, PAX8_OAUTH_SCOPE, PIPEDRIVE_API_KEY, PROOFPOINT_API_SECRET, PROOFPOINT_SERVICE_PRINCIPAL, QUICKBOOKS_ACCESS_TOKEN, QUICKBOOKS_REALM_ID, RESOURCEGURU_EMAIL, RESOURCEGURU_PASSWORD, REWST_API_TOKEN, ROCKETCYBER_API_TOKEN, ROOTLY_API_KEY, ROOTLY_API_TOKEN, RUNZERO_API_KEY, SALESBUILDR_API_KEY, SALESBUILDR_TENANT, SENTINELONE_API_TOKEN, SENTINELONE_BASE_URL, SERVOSITY_MSP_TOKEN, SHERWEB_CLIENT_ID, SHERWEB_CLIENT_SECRET, SHERWEB_OAUTH_SCOPE, SHERWEB_SUBSCRIPTION_KEY, SKYKICK_CLIENT_ID, SKYKICK_CLIENT_SECRET, SKYKICK_OAUTH_SCOPE, SYNCRO_API_KEY, SYNCRO_SUBDOMAIN, TACTICAL_RMM_BASE_URL, TRMM_API_KEY, UNIFI_API_KEY, UNIFI_GATEWAY_HOST, VEEAM_BASE_URL, VEEAM_TOKEN, WORDPRESS_BASIC_AUTH, XERO_ACCESS_TOKEN, XERO_TENANT_ID, ZAMMAD_API_TOKEN, ZAMMAD_URL, AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AXCIENT_API_KEY, BETTERSTACK_API_TOKEN, CONNECTWISE_AUTOMATE_CLIENT_ID, CONNECTWISE_AUTOMATE_SERVER, CONNECTWISE_AUTOMATE_TOKEN, DOMOTZ_API_KEY, GRADIENT_PARTNER_API_KEY, GRADIENT_TOKEN, GRADIENT_VENDOR_API_KEY, MICROSOFT_GRAPH_TOKEN, SUPEROPS_API_TOKEN, SUPEROPS_SUBDOMAIN, THREATLOCKER_API_KEY, ACTION1_OAUTH2, BLUMIRA_API_TOKEN, BLUMIRA_CLIENT_ID, BLUMIRA_CLIENT_SECRET, DATAGATE_MCP_HTTP_TOKEN, DATTO_BCDR_MCP_HTTP_TOKEN, HALOPSA_TOKEN, HUBSPOT_MCP_HTTP_TOKEN, HUNTRESS_MCP_HTTP_TOKEN, KASEYA_BMS_BEARER_AUTH, KASEYA_BMS_TOKEN, KNOWBE4_USER_EVENT_API_KEY, LIONGARD_ACCESS_KEY_ID, LIONGARD_ACCESS_KEY_SECRET, LIONGARD_API_KEY, MAXIO_API_KEY, QUICKBOOKS_CLIENT_ID, QUICKBOOKS_CLIENT_SECRET, QUICKBOOKS_REFRESH_TOKEN, SENTINELONE_MCP_HTTP_TOKEN, WORDPRESS_MCP_HTTP_TOKEN, XERO_CLIENT_ID, XERO_CLIENT_SECRET, XERO_OAUTH2, ZAMMAD_MCP_HTTP_TOKEN, AWS_SESSION_TOKEN, of which 137 are secrets.

›Can I use Abnormal Security as a remote (hosted) MCP server?

No hosted endpoint is published; it runs locally over stdio.

›Is Abnormal Security in the official MCP registry?

Yes, as io.github.Servosity/abnormal-mcp.

Alternatives to Abnormal Security

Other security MCP servers.

View all