MCP server for Ironscales — phishing incident management, email classification, and remediation
- ✓Open-source license (Apache-2.0)
- ✓Actively maintained (<30d)
- ✓Clear description
- ✓Topics declared
- ✓Documented (README)
claude mcp add ironscales-mcp -- npx -y @wyre-ai/ironscales-mcp{
"mcpServers": {
"ironscales-mcp": {
"command": "npx",
"args": ["-y", "@wyre-ai/ironscales-mcp"],
"env": {
"IRONSCALES_API_KEY": "<ironscales_api_key>"
}
}
}
}IRONSCALES_API_KEYMCP Servers overview
# Ironscales MCP Server
[](https://opensource.org/licenses/Apache-2.0)
[](https://nodejs.org/)
A Model Context Protocol (MCP) server for Ironscales email security. Enables AI assistants to investigate phishing incidents, manage email classification, execute remediations, and view security statistics.
This is a [Model Context Protocol (MCP)](https://modelcontextprotocol.io/) server that connects Claude (or any MCP-compatible AI) to your Ironscales environment.
> **Part of the [MSP Claude Plugins](https://github.com/WYRE-AI) ecosystem** — a growing suite of AI integrations for the MSP stack. Built by MSPs, for MSPs.
## Interactive Incident Card (MCP Apps)
`ironscales_incidents_get` renders as an interactive card in MCP Apps hosts
(Claude Desktop/web) showing the phishing incident's subject, status, severity,
sender, affected recipients, and threat indicators; plain-JSON behavior is
unchanged in other hosts. The card is read-only — remediation stays with the
model-driven remediation tools. It is neutral by default and brandable via
`window.__BRAND__` injection or `MCP_BRAND_*` env vars (`MCP_BRAND_NAME`,
`MCP_BRAND_LOGO_URL`, `MCP_BRAND_PRIMARY_COLOR`, `MCP_BRAND_ACCENT_COLOR`,
`MCP_BRAND_BG`, `MCP_BRAND_TEXT`) — no rebuild needed.
## Installation
```bash
npm install @wyre-ai/ironscales-mcp
```
## Configuration
Set the following environment variables:
| Variable | Required | Description |
|----------|----------|-------------|
| `IRONSCALES_API_KEY` | Yes | Your Ironscales API key |
| `IRONSCALES_COMPANY_ID` | Yes | Your Ironscales company ID |
| `MCP_TRANSPORT` | No | Transport mode: stdio (default) or http |
## Usage
### Running with Claude Desktop
Add to your Claude Desktop `claude_desktop_config.json`:
```json
{
"mcpServers": {
"ironscales-mcp": {
"command": "npx",
"args": ["@wyre-ai/ironscales-mcp"],
"env": {
"IRONSCALES_API_KEY": "your-ironscales-api-key"
"IRONSCALES_COMPANY_ID": "your-ironscales-company-id"
}
}
}
}
```
### Running with Claude Code (CLI)
```bash
claude mcp add ironscales-mcp \
-e IRONSCALES_API_KEY=your-value \
-e IRONSCALES_COMPANY_ID=your-value \
-- npx -y @wyre-ai/ironscales-mcp
```
### Docker
```bash
docker build -t ironscales-mcp .
docker run \
-e IRONSCALES_API_KEY=your-value \
-e IRONSCALES_COMPANY_ID=your-value \
-p 8080:8080 ironscales-mcp
```
## Available Domains
### Allowlist
Manage email allowlists and blocklists
### Email
Email investigation and classification
### Incidents
Phishing incident management and triage
### Remediation
Execute email remediations and quarantine
### Stats
Security statistics and reporting
## Development
```bash
# Clone the repository
git clone https://github.com/WYRE-AI/ironscales-mcp.git
cd ironscales-mcp
# Install dependencies
npm install
# Build
npm run build
# Run tests
npm test
```
## Contributing
Contributions are welcome! Please see [CONTRIBUTING.md](CONTRIBUTING.md) if present, or open an issue to discuss changes.
## License
Licensed under the Apache License, Version 2.0. See [LICENSE](LICENSE) for details.
What people ask about ironscales-mcp
What is WYRE-AI/ironscales-mcp?
+
WYRE-AI/ironscales-mcp is mcp servers for the Claude AI ecosystem. MCP server for Ironscales — phishing incident management, email classification, and remediation It has 0 GitHub stars and its last recorded update is dated 2026-08-25.
How do I install ironscales-mcp?
+
You can install ironscales-mcp by cloning the repository (https://github.com/WYRE-AI/ironscales-mcp) or following the README instructions on GitHub. ClaudeWave also provides quick install blocks on this page.
Is WYRE-AI/ironscales-mcp safe to use?
+
Our security agent has analyzed WYRE-AI/ironscales-mcp and assigned a Trust Score of 95/100 (tier: Verified). See the full breakdown of passed checks and flags on this page.
Who maintains WYRE-AI/ironscales-mcp?
+
WYRE-AI/ironscales-mcp is maintained by WYRE-AI. The last recorded GitHub activity is dated 2026-08-25, with 2 open issues.
Are there alternatives to ironscales-mcp?
+
Yes. On ClaudeWave you can browse similar mcp servers at /categories/mcp, sorted by popularity or recent activity.
Deploy ironscales-mcp to your cloud
Ship this repo to production in minutes. Each platform spins up its own environment with editable env vars.
Maintain this repo? Add a badge to your README
Drop the badge into your GitHub README to show it's tracked on ClaudeWave. Each badge links back to this page and reflects the live Trust Score.
[](https://claudewave.com/repo/wyre-ai-ironscales-mcp)<a href="https://claudewave.com/repo/wyre-ai-ironscales-mcp"><img src="https://claudewave.com/api/badge/wyre-ai-ironscales-mcp" alt="Featured on ClaudeWave: WYRE-AI/ironscales-mcp" width="320" height="64" /></a>More MCP Servers
Fair-code workflow automation platform with native AI capabilities. Combine visual building with custom code, self-host or cloud, 400+ integrations.
User-friendly AI Interface (Supports Ollama, OpenAI API, ...)
An open-source AI agent that brings the power of Gemini directly into your terminal.
Real-time global intelligence dashboard. AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational awareness interface
The fastest path to AI-powered full stack observability, even for lean teams.
🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl!