Skip to content
mcp/skillhub

ThreatLocker MCP Server

by wyre-aiio.github.WYRE-AI/threatlocker-mcpv1.3.10

MCP server for ThreatLocker — zero-trust endpoint protection, allowlisting, and policies.

1Dockerstdioofficial registry

context tax

queued

security

queued

cold start

queued

freshness

Active5d ago

Install ThreatLocker MCP server

Install in Claude Code

claude mcp add threatlocker-wyre-ai -e THREATLOCKER_API_KEY='<threatlocker-api-key>' -e THREATLOCKER_ORGANIZATION_ID='<threatlocker-organization-id>' -- docker run -i --rm -e THREATLOCKER_API_KEY -e THREATLOCKER_ORGANIZATION_ID ghcr.io/wyre-ai/threatlocker-mcp:v1.3.10

Configuration

VariableRequiredSecretDescription
THREATLOCKER_API_KEYyesyesThreatLocker API key
THREATLOCKER_ORGANIZATION_IDyes—ThreatLocker organization ID
MCP_TRANSPORT——Transport mode for the server. Set to 'stdio' for local CLI use; the image defaults to 'http' for gateway hosting.
AUTH_MODE——Credential source: 'env' reads vars locally, 'gateway' expects header injection from the WYRE MCP Gateway.
LOG_LEVEL——Log verbosity: debug, info, warn, error

Freshness

Active — last maintenance signal 5d ago. The newest of the signals below sets the band.

  1. Last commit (default branch)

    2026-10-05 · 5d ago · GitHub

  2. Latest release

    2026-09-24 · 16d ago · GitHub · v1.3.10

  3. Package published

    no data · npm/PyPI

  4. Registry entry updated

    2026-09-24 · 16d ago · official registry · v1.3.10

FAQ

›How do I install the ThreatLocker MCP server in Claude Code?

Run: claude mcp add threatlocker-wyre-ai -e THREATLOCKER_API_KEY='<threatlocker-api-key>' -e THREATLOCKER_ORGANIZATION_ID='<threatlocker-organization-id>' -- docker run -i --rm -e THREATLOCKER_API_KEY -e THREATLOCKER_ORGANIZATION_ID ghcr.io/wyre-ai/threatlocker-mcp:v1.3.10. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.

›Does ThreatLocker require an API key?

Yes. It expects THREATLOCKER_API_KEY, THREATLOCKER_ORGANIZATION_ID, of which 1 is a secret.

›Can I use ThreatLocker as a remote (hosted) MCP server?

No hosted endpoint is published; it runs locally over stdio.

›Is ThreatLocker in the official MCP registry?

Yes, as io.github.WYRE-AI/threatlocker-mcp.