Threatcluster MCP Server
by jam0kio.github.Jam0k/threatclusterv0.2.3
MCP server for the ThreatCluster threat-intelligence API: incident clusters, entity profiles, CVEs and ransomware leak-site victims as tools for Claude, Cursor, VS Code and any MCP client
context tax
queued
security
queued
cold start
queued
freshness
Active8d ago
Install Threatcluster MCP server
Install in Claude Code
claude mcp add threatcluster -e THREATCLUSTER_API_KEY='<threatcluster-api-key>' -- npx -y threatcluster-mcpInstall in Cursor
{
"mcpServers": {
"threatcluster": {
"command": "npx",
"args": [
"-y",
"threatcluster-mcp"
],
"env": {
"THREATCLUSTER_API_KEY": "<threatcluster-api-key>"
}
}
}
}Add to ~/.cursor/mcp.json (global) or .cursor/mcp.json (project).
Install in Claude Desktop
{
"mcpServers": {
"threatcluster": {
"command": "npx",
"args": [
"-y",
"threatcluster-mcp"
],
"env": {
"THREATCLUSTER_API_KEY": "<threatcluster-api-key>"
}
}
}
}Settings → Developer → Edit Config (claude_desktop_config.json), then restart.
Install in VS Code
{
"servers": {
"threatcluster": {
"type": "stdio",
"command": "npx",
"args": [
"-y",
"threatcluster-mcp"
],
"env": {
"THREATCLUSTER_API_KEY": "<threatcluster-api-key>"
}
}
}
}Add to .vscode/mcp.json in your workspace.
Install in Windsurf
{
"mcpServers": {
"threatcluster": {
"command": "npx",
"args": [
"-y",
"threatcluster-mcp"
],
"env": {
"THREATCLUSTER_API_KEY": "<threatcluster-api-key>"
}
}
}
}Add to ~/.codeium/windsurf/mcp_config.json.
Configuration
| Variable | Required | Secret | Description |
|---|---|---|---|
| THREATCLUSTER_API_KEY | yes | yes | ThreatCluster API key (tc_live_... / tc_agent_...). Free keys: https://threatcluster.io/api |
| THREATCLUSTER_API_BASE | — | — | API base URL |
Remote endpoints
- streamable-http
https://threatcluster.io/mcp
Freshness
Active — last maintenance signal 8d ago. The newest of the signals below sets the band.
Last commit (default branch)
2026-10-01 · 8d ago · GitHub
Latest release
no data · GitHub
Package published
no data · npm/PyPI
Registry entry updated
2026-09-26 · 13d ago · official registry · v0.2.3
FAQ
›How do I install the Threatcluster MCP server in Claude Code?
Run: claude mcp add threatcluster -e THREATCLUSTER_API_KEY='<threatcluster-api-key>' -- npx -y threatcluster-mcp. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.
›Does Threatcluster require an API key?
Yes. It expects THREATCLUSTER_API_KEY, of which 1 is a secret.
›Can I use Threatcluster as a remote (hosted) MCP server?
Yes — it offers both a hosted endpoint and a local stdio package.
›Is Threatcluster in the official MCP registry?
Yes, as io.github.Jam0k/threatcluster.
Alternatives to Threatcluster
Other ai & llm tools MCP servers.