MCP server for ThreatLocker — zero-trust application allowlisting, approval requests, audit logs
- ✓Actively maintained (<30d)
- ✓Clear description
- ✓Topics declared
- !No standard license detected
git clone https://github.com/wyre-technology/threatlocker-mcp{
"mcpServers": {
"threatlocker-mcp": {
"command": "node",
"args": ["/path/to/threatlocker-mcp/dist/index.js"],
"env": {
"THREATLOCKER_API_KEY": "<threatlocker_api_key>",
"MCP_HTTP_HOST": "<mcp_http_host>"
}
}
}
}THREATLOCKER_API_KEYMCP_HTTP_HOSTMCP Servers overview
# ThreatLocker MCP Server
A Model Context Protocol (MCP) server that provides AI assistants with access to the ThreatLocker Portal API. Manage computers, approval requests, audit logs, and organizations through natural language interactions.
## Features
- **Stateless Architecture**: No session state required, fresh connections per request
- **Decision-Tree Navigation**: Navigate domains with `threatlocker_navigate`
- **Gateway Mode**: Multi-tenant support via HTTP headers
- **Elicitation Support**: Interactive prompts for missing parameters
- **Comprehensive Error Handling**: Detailed error messages and logging
- **Docker Support**: Production-ready containerization
## Tools
### Navigation
- `threatlocker_navigate` - Navigate to a domain to see available tools
- `threatlocker_status` - Check API connection status and available domains
### Computers
- `threatlocker_computers_list` - List computers with filters (search, group, pagination)
- `threatlocker_computers_get` - Get detailed computer information
- `threatlocker_computers_get_checkins` - Get computer checkin history
### Computer Groups
- `threatlocker_computer_groups_list` - List computer groups with filters
- `threatlocker_computer_groups_dropdown` - Get computer groups for dropdown selection
### Approval Requests
- `threatlocker_approvals_list` - List approval requests with status filters
- `threatlocker_approvals_get` - Get detailed approval request information
- `threatlocker_approvals_pending_count` - Get count of pending approvals
- `threatlocker_approvals_get_permit_application` - Get permit application details
### Audit Log
- `threatlocker_audit_search` - Search audit log entries with filters
- `threatlocker_audit_get` - Get detailed audit log entry
- `threatlocker_audit_file_history` - Get audit history for specific file
### Organizations
- `threatlocker_organizations_list_children` - List child organizations
- `threatlocker_organizations_get_auth_key` - Get organization auth key
- `threatlocker_organizations_for_move_computers` - Get organizations for computer moves
## Configuration
### Environment Variables
#### Stdio Mode (Direct API Access)
```bash
THREATLOCKER_API_KEY=your_api_key_here
THREATLOCKER_ORGANIZATION_ID=your_org_id_here
MCP_TRANSPORT=stdio
```
#### Gateway Mode (Multi-tenant)
```bash
AUTH_MODE=gateway
MCP_TRANSPORT=http
MCP_HTTP_PORT=8080
MCP_HTTP_HOST=0.0.0.0
```
#### Gateway Mode Headers
When running in gateway mode, include these headers with each request:
- `X-Threatlocker-Api-Key`: Your ThreatLocker API key
- `X-Threatlocker-Organization-Id`: Your organization ID
### Logging
```bash
LOG_LEVEL=debug|info|warn|error # Default: info
```
## Local Development
1. Clone the repository:
```bash
git clone https://github.com/wyre-technology/threatlocker-mcp.git
cd threatlocker-mcp
```
2. Install dependencies:
```bash
npm install
```
3. Set environment variables:
```bash
cp .env.example .env
# Edit .env with your ThreatLocker credentials
```
4. Build and run:
```bash
npm run build
npm start
# Or for development with hot reload:
npm run dev
```
5. Test the server:
```bash
# Stdio mode
echo '{"jsonrpc": "2.0", "id": 1, "method": "tools/list"}' | npm start
# HTTP mode
curl http://localhost:8080/health
```
## Docker
### Using Docker Compose
```bash
# Pull and run latest image
docker compose up -d
# Or build locally
docker compose -f docker-compose.dev.yml up --build
```
### Using Docker directly
```bash
# Gateway mode (recommended)
docker run -d \
--name threatlocker-mcp \
-p 8080:8080 \
-e AUTH_MODE=gateway \
ghcr.io/wyre-technology/threatlocker-mcp:latest
# Stdio mode
docker run -d \
--name threatlocker-mcp \
-e THREATLOCKER_API_KEY=your_key \
-e THREATLOCKER_ORGANIZATION_ID=your_org_id \
-e MCP_TRANSPORT=stdio \
ghcr.io/wyre-technology/threatlocker-mcp:latest
```
## Architecture
### Directory Structure
```
src/
├── domains/ # Domain-specific handlers
│ ├── computers.ts
│ ├── computer_groups.ts
│ ├── approval_requests.ts
│ ├── audit_log.ts
│ ├── organizations.ts
│ ├── navigation.ts
│ └── index.ts
├── utils/ # Utilities
│ ├── client.ts # ThreatLocker API client
│ ├── logger.ts # Structured logging
│ ├── types.ts # TypeScript types
│ ├── server-ref.ts # Server reference for elicitation
│ └── elicitation.ts # Interactive prompts
├── server.ts # MCP server creation
├── index.ts # Stdio transport entry
└── http.ts # HTTP transport entry
```
### Design Patterns
- **Domain Handlers**: Each API area has its own handler with `getTools()` and `handleCall()`
- **Lazy Loading**: Domain handlers are imported on-demand
- **Fresh Connections**: New server instance per HTTP request for stateless operation
- **Credential Invalidation**: Client is reset when credentials change
- **Elicitation Framework**: Interactive prompts for missing parameters
## License
Apache-2.0 - see [LICENSE](LICENSE) for details.What people ask about threatlocker-mcp
What is wyre-technology/threatlocker-mcp?
+
wyre-technology/threatlocker-mcp is mcp servers for the Claude AI ecosystem. MCP server for ThreatLocker — zero-trust application allowlisting, approval requests, audit logs It has 1 GitHub stars and was last updated today.
How do I install threatlocker-mcp?
+
You can install threatlocker-mcp by cloning the repository (https://github.com/wyre-technology/threatlocker-mcp) or following the README instructions on GitHub. ClaudeWave also provides quick install blocks on this page.
Is wyre-technology/threatlocker-mcp safe to use?
+
Our security agent has analyzed wyre-technology/threatlocker-mcp and assigned a Trust Score of 62/100 (tier: OK). See the full breakdown of passed checks and flags on this page.
Who maintains wyre-technology/threatlocker-mcp?
+
wyre-technology/threatlocker-mcp is maintained by wyre-technology. The last recorded GitHub activity is from today, with 2 open issues.
Are there alternatives to threatlocker-mcp?
+
Yes. On ClaudeWave you can browse similar mcp servers at /categories/mcp, sorted by popularity or recent activity.
Deploy threatlocker-mcp to your cloud
Ship this repo to production in minutes. Each platform spins up its own environment with editable env vars.
Maintain this repo? Add a badge to your README
Drop the badge into your GitHub README to show it's tracked on ClaudeWave. Each badge links back to this page and reflects the live Trust Score.
[](https://claudewave.com/repo/wyre-technology-threatlocker-mcp)<a href="https://claudewave.com/repo/wyre-technology-threatlocker-mcp"><img src="https://claudewave.com/api/badge/wyre-technology-threatlocker-mcp" alt="Featured on ClaudeWave: wyre-technology/threatlocker-mcp" width="320" height="64" /></a>More MCP Servers
Fair-code workflow automation platform with native AI capabilities. Combine visual building with custom code, self-host or cloud, 400+ integrations.
User-friendly AI Interface (Supports Ollama, OpenAI API, ...)
An open-source AI agent that brings the power of Gemini directly into your terminal.
The fastest path to AI-powered full stack observability, even for lean teams.
🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl!
Real-time global intelligence dashboard. AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational awareness interface