
CrowdStrike Falcon MCP Server
by crowdstrikeio.github.CrowdStrike/falcon-mcpv0.19.0
Connects AI agents with CrowdStrike Falcon for security analysis and automation.
context tax
queued
security
queued
cold start
queued
freshness
Active1d ago
Install CrowdStrike Falcon MCP server
Install in Claude Code
claude mcp add falcon -e FALCON_CLIENT_ID='<falcon-client-id>' -e FALCON_CLIENT_SECRET='<falcon-client-secret>' -e FALCON_MCP_API_KEY='<falcon-mcp-api-key>' -- uvx falcon-mcpInstall in Cursor
{
"mcpServers": {
"falcon": {
"command": "uvx",
"args": [
"falcon-mcp"
],
"env": {
"FALCON_CLIENT_ID": "<falcon-client-id>",
"FALCON_CLIENT_SECRET": "<falcon-client-secret>",
"FALCON_MCP_API_KEY": "<falcon-mcp-api-key>"
}
}
}
}Add to ~/.cursor/mcp.json (global) or .cursor/mcp.json (project).
Install in Claude Desktop
{
"mcpServers": {
"falcon": {
"command": "uvx",
"args": [
"falcon-mcp"
],
"env": {
"FALCON_CLIENT_ID": "<falcon-client-id>",
"FALCON_CLIENT_SECRET": "<falcon-client-secret>",
"FALCON_MCP_API_KEY": "<falcon-mcp-api-key>"
}
}
}
}Settings → Developer → Edit Config (claude_desktop_config.json), then restart.
Install in VS Code
{
"servers": {
"falcon": {
"type": "stdio",
"command": "uvx",
"args": [
"falcon-mcp"
],
"env": {
"FALCON_CLIENT_ID": "<falcon-client-id>",
"FALCON_CLIENT_SECRET": "<falcon-client-secret>",
"FALCON_MCP_API_KEY": "<falcon-mcp-api-key>"
}
}
}
}Add to .vscode/mcp.json in your workspace.
Install in Windsurf
{
"mcpServers": {
"falcon": {
"command": "uvx",
"args": [
"falcon-mcp"
],
"env": {
"FALCON_CLIENT_ID": "<falcon-client-id>",
"FALCON_CLIENT_SECRET": "<falcon-client-secret>",
"FALCON_MCP_API_KEY": "<falcon-mcp-api-key>"
}
}
}
}Add to ~/.codeium/windsurf/mcp_config.json.
Configuration
| Variable | Required | Secret | Description |
|---|---|---|---|
| FALCON_CLIENT_ID | yes | yes | CrowdStrike API client ID |
| FALCON_CLIENT_SECRET | yes | yes | CrowdStrike API client secret |
| FALCON_BASE_URL | — | — | CrowdStrike API region URL |
| FALCON_MEMBER_CID | — | — | Child CID for Flight Control (MSSP) support |
| FALCON_MCP_MODULES | — | — | Comma-separated list of modules to enable |
| FALCON_MCP_TRANSPORT | — | — | Transport protocol to use |
| FALCON_MCP_DEBUG | — | — | Enable debug logging |
| FALCON_MCP_HOST | — | — | Host to bind to for HTTP transports |
| FALCON_MCP_PORT | — | — | Port to listen on for HTTP transports |
| FALCON_MCP_USER_AGENT_COMMENT | — | — | Additional information to include in the User-Agent comment section |
| FALCON_MCP_STATELESS_HTTP | — | — | Enable stateless HTTP mode for scalable deployments |
| FALCON_MCP_API_KEY | — | yes | API key for HTTP transport authentication (x-api-key header) |
Freshness
Active — last maintenance signal 1d ago. The newest of the signals below sets the band.
Last commit (default branch)
2026-10-08 · 1d ago · GitHub
Latest release
2026-09-01 · 38d ago · GitHub · v0.19.0
Package published
no data · npm/PyPI
Registry entry updated
2026-09-01 · 38d ago · official registry · v0.19.0
FAQ
›How do I install the CrowdStrike Falcon MCP server in Claude Code?
Run: claude mcp add falcon -e FALCON_CLIENT_ID='<falcon-client-id>' -e FALCON_CLIENT_SECRET='<falcon-client-secret>' -e FALCON_MCP_API_KEY='<falcon-mcp-api-key>' -- uvx falcon-mcp. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.
›Does CrowdStrike Falcon require an API key?
Yes. It expects FALCON_CLIENT_ID, FALCON_CLIENT_SECRET, FALCON_MCP_API_KEY, of which 3 are secrets.
›Can I use CrowdStrike Falcon as a remote (hosted) MCP server?
No hosted endpoint is published; it runs locally over stdio.
›Is CrowdStrike Falcon in the official MCP registry?
Yes, as io.github.CrowdStrike/falcon-mcp.
Alternatives to CrowdStrike Falcon
Other security MCP servers.