MCP server for Rubrik Security Cloud — query-only, full API discovery, user-defined workflows
- ✓Open-source license (MIT)
- ✓Actively maintained (<30d)
- ✓Clear description
- ✓Documented (README)
claude mcp add rubrik-mcp -- uvx rubrik-mcp{
"mcpServers": {
"rubrik-mcp": {
"command": "uvx",
"args": ["rubrik-mcp"],
"env": {
"RSC_URL": "<rsc_url>",
"RSC_CLIENT_SECRET": "<rsc_client_secret>"
}
}
}
}RSC_URLRSC_CLIENT_SECRETResumen de MCP Servers
# Rubrik MCP
An MCP server that connects AI assistants to the [Rubrik Security Cloud](https://www.rubrik.com/) GraphQL API. It's built for Rubrik admins and teams automating against Rubrik, and runs locally (on your own workstation or on an agent's server) alongside the AI assistant that calls it.
<!-- Ownership marker for the MCP Registry. It verifies that this PyPI package
belongs to the server named in server.json by looking for this string in
the published package description. Must match server.json's `name` exactly,
and must not be followed by punctuation. -->
<!-- mcp-name: io.github.rubrikinc/rubrik-mcp -->
---
## What you can do
### Discovery
The MCP ships with a pre-built index of the entire RSC GraphQL API. The discovery tools let the AI agent explore that index — searching operations, inspecting full argument signatures, tracing input and return types — to find exactly the right operation and field shape for any request. This produces precise, well-formed GraphQL on the first try.
Discovery tools require no RSC credentials and work entirely offline. This makes them useful on their own: if you're evaluating the API, prototyping an integration, or building automation before you have production credentials, you can start immediately.
```
> "What operations are available for SLA management?"
> "Show me the full argument shape for the assignSla mutation."
> "Generate Python code to assign an SLA domain to a list of workload IDs."
```
Because the agent understands both queries and mutations from the schema index, it can generate runnable Python code for any write operation — without ever connecting to RSC.
### Execution
With an RSC service account, the agent can run live GraphQL queries against your environment:
- List workloads with protection status, compliance state, and backup history
- Retrieve recent events and failures
- Trigger on-demand snapshots and poll until they complete
- Register hosts and assign SLA domains
Raw GraphQL execution is read-only. If you ask for a write operation not covered by a built-in tool, the server returns the attempted mutation and the agent generates a runnable code sample. A small number of write operations are available as dedicated built-in tools: on-demand snapshots (`rsc_take_on_demand_snapshot`), host onboarding (`rsc_onboard_host`), and SLA assignment (`rsc_assign_sla`). **These are disabled by default** — set `"writes_enabled": true` in the [gating policy](https://github.com/rubrikinc/rubrik-mcp/blob/main/docs/advanced.md#gating-policy) to expose them. For everything else, the generated code approach gives you a runnable script with full control.
> [!WARNING]
> **Write tools act on your Rubrik environment, and the LLM driving the MCP decides when to call them.** Any model can misread instructions or be influenced by untrusted data it reads (prompt injection) and invoke a write tool you did not intend — for example an SLA change via `rsc_assign_sla` that leaves data unprotected. As more write tools are added, this surface grows. They are disabled by default for that reason; enabling them is an explicit choice. The durable boundary is a **least-privilege, read-only service account**, which cannot perform any write operation regardless of which model you use or how the agent behaves. See [Service account role recommendations](#service-account-role-recommendations), and enable **Quorum Authorization** for destructive operations.
### Built-in tools
**Discovery** — no credentials required
| Tool | What it does |
|------|-------------|
| `rsc_search_schema` | Find the right query or mutation by keyword, field meaning, or type vocabulary in one call |
| `rsc_describe_operation_full` | Argument signature with all input/enum types expanded inline |
| `rsc_describe_type` | Fields and values for a GraphQL type |
**Execution** — service account required
| Tool | What it does |
|------|-------------|
| `rsc_execute_operation` | Run any raw GraphQL query (mutations generate code instead) |
| `rsc_get_workloads` | Workloads with protection status, compliance, and backup history |
| `rsc_get_events` | Recent events and activity, always time-scoped |
| `rsc_get_clusters` | Rubrik clusters registered in RSC, with status, version, capacity, and runway |
| `rsc_get_sla_domains` | SLA Domains with base frequency, retention lock, archival, and replication settings |
| `rsc_search_help` | Search KB articles, product docs, and known issues by keyword |
| `rsc_take_on_demand_snapshot` | Trigger a backup for a workload and return the job ID |
| `rsc_wait_for_job` | Poll a job until completion |
| `rsc_onboard_host` | Register a physical or virtual host |
| `rsc_assign_sla` | Assign, unassign, or set do-not-protect on workloads |
**Workflow management** — service account required
| Tool | What it does |
|------|-------------|
| `rsc_save_workflow` | Save a conversation flow as a named reusable tool |
| `rsc_list_workflows` | List all saved workflows |
| `rsc_delete_workflow` | Remove a saved workflow |
### Tool creation
After the agent has done the discovery work to answer a question, you can save that entire flow as a named MCP tool:
> "Save this as a workflow so I can reuse it."
On the next restart, that tool appears alongside the built-in tools — a single call instead of multi-step schema discovery. Repeated operations use fewer tokens and respond faster. Workflow files are plain JSON you can edit, version-control, and share with your team.
---
## Installation
### Prerequisites
- [uv](https://docs.astral.sh/uv/getting-started/installation/) (recommended), or Python 3.10 or later with pip
- A Rubrik Security Cloud account with a service account (for execution tools only)
### Install via agent prompt
If you're using Claude Code, paste this into the chat and the agent will handle the rest:
> "Add the Rubrik MCP server (PyPI package `rubrik-mcp`, run it with `uvx rubrik-mcp`) to my Claude Code MCP configuration. My RSC service account JSON is at `~/.rsc/service_account.json`."
For Claude Desktop:
> "Add the Rubrik MCP server (PyPI package `rubrik-mcp`, run it with `uvx rubrik-mcp`) to my Claude Desktop config. My RSC service account JSON is at `~/.rsc/service_account.json`."
### Install manually
**Using uvx (recommended):** there is nothing to install separately. `uvx rubrik-mcp` downloads the package from PyPI into a cached, isolated environment and runs it. Use it directly as the command in your client configuration below. To pin a specific release, use `rubrik-mcp@<version>`, for example `uvx rubrik-mcp@0.8.20260928`.
**Using pip:**
```bash
pip install rubrik-mcp
```
Note the full path to the installed command. You will use it in place of `uvx rubrik-mcp` in the client configuration:
```bash
which rubrik-mcp
# example: /Users/you/.venv/bin/rubrik-mcp
```
### Hardened install (optional)
For environments that require **install-time hash verification** (each package checked against a known-good cryptographic hash before it is installed), a hashed `requirements.txt` is published in this repository for each release. Install the verified dependency set first, then the package itself:
```bash
pip install --require-hashes -r requirements.txt
pip install --no-deps rubrik-mcp
```
`requirements.txt` is generated from the locked, hash-pinned dependency set (`uv export`); `--require-hashes` makes pip refuse any package whose hash does not match, and `--no-deps` on the second step keeps the verified set untouched. Then configure your client with the full path to `rubrik-mcp`, as in the pip instructions above. This path is optional; the standard install is sufficient for most users.
### Configure your MCP client
**Claude Code:**
```bash
claude mcp add rubrik -e RSC_SERVICE_ACCOUNT_FILE=/path/to/service_account.json -- uvx rubrik-mcp
```
Options such as `-e` go before `--`; everything after `--` is the command that launches the server. For discovery-only usage, omit the `-e` option.
Verify it's registered:
```bash
claude mcp list
```
**Claude Desktop:** edit `~/Library/Application Support/Claude/claude_desktop_config.json` (macOS) or `%APPDATA%\Claude\claude_desktop_config.json` (Windows):
```json
{
"mcpServers": {
"rubrik": {
"command": "uvx",
"args": ["rubrik-mcp"],
"env": {
"RSC_SERVICE_ACCOUNT_FILE": "/path/to/service_account.json"
}
}
}
}
```
Desktop apps don't always inherit your shell's `PATH`. If Claude Desktop reports that it can't find `uvx`, replace `"uvx"` with its full path from `which uvx` (for example `/Users/you/.local/bin/uvx`).
**Other MCP clients (generic stdio):**
```json
{
"name": "rubrik",
"transport": "stdio",
"command": "uvx",
"args": ["rubrik-mcp"],
"env": {
"RSC_SERVICE_ACCOUNT_FILE": "/path/to/service_account.json"
}
}
```
If you installed with pip, set `"command"` to the full path of `rubrik-mcp` and drop `"args"`.
---
## Service account setup
Create a service account in RSC at **Settings > Users and Roles > Service Accounts**. Download the JSON credential file when prompted — RSC will not show the secret again.
The credential file looks like this:
```json
{
"client_id": "client|...",
"client_secret": "...",
"access_token_uri": "https://<your-rsc-domain>/api/client_token"
}
```
Provide it to the MCP server using one of three methods (checked in this order):
**Option A — Service account JSON file (recommended)**
```bash
export RSC_SERVICE_ACCOUNT_FILE=/path/to/service_account.json
```
**Option B — Individual environment variables**
```bash
export RSC_URL=https://<your-rsc-domain>
export RSC_CLIENT_ID=client|...
export RSC_CLIENT_SECRET=...
```
**Option C — Config file at `~/.rsc/config.json`**
```json
{
"client_id": "client|...",
"client_secret": "...",
"access_token_uri": "https://<your-rsc-domain>/api/client_token"
}
```
---
## Service account role recommendations
The role you assign to the service account determines Lo que la gente pregunta sobre rubrik-mcp
¿Qué es rubrikinc/rubrik-mcp?
+
rubrikinc/rubrik-mcp es mcp servers para el ecosistema de Claude AI. MCP server for Rubrik Security Cloud — query-only, full API discovery, user-defined workflows Tiene 1 estrellas en GitHub y su última actualización registrada es del 2026-10-02.
¿Cómo se instala rubrik-mcp?
+
Puedes instalar rubrik-mcp clonando el repositorio (https://github.com/rubrikinc/rubrik-mcp) o siguiendo las instrucciones del README en GitHub. ClaudeWave también te ofrece bloques de instalación rápida en esta misma página.
¿Es seguro usar rubrikinc/rubrik-mcp?
+
Nuestro agente de seguridad ha analizado rubrikinc/rubrik-mcp y le ha asignado un Trust Score de 87/100 (tier: Trusted). Revisa el desglose completo de comprobaciones superadas y flags en esta página.
¿Quién mantiene rubrikinc/rubrik-mcp?
+
rubrikinc/rubrik-mcp es mantenido por rubrikinc. La última actividad registrada en GitHub es del 2026-10-02, con 1 issues abiertos.
¿Hay alternativas a rubrik-mcp?
+
Sí. En ClaudeWave puedes explorar mcp servers similares en /categories/mcp, ordenados por popularidad o actividad reciente.
Despliega rubrik-mcp en tu cloud
Lleva este repo a producción en minutos. Cada plataforma genera su propio entorno con variables de entorno editables.
¿Mantienes este repo? Añade un badge a tu README
Pega el badge en tu README de GitHub para mostrar que está auditado por ClaudeWave. Cada badge enlaza de vuelta a esta página y muestra el Trust Score actual.
[](https://claudewave.com/repo/rubrikinc-rubrik-mcp)<a href="https://claudewave.com/repo/rubrikinc-rubrik-mcp"><img src="https://claudewave.com/api/badge/rubrikinc-rubrik-mcp" alt="Featured on ClaudeWave: rubrikinc/rubrik-mcp" width="320" height="64" /></a>Más MCP Servers
Fair-code workflow automation platform with native AI capabilities. Combine visual building with custom code, self-host or cloud, 400+ integrations.
User-friendly AI Interface (Supports Ollama, OpenAI API, ...)
An open-source AI agent that brings the power of Gemini directly into your terminal.
Real-time global intelligence dashboard. AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational awareness interface
🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl! Don't be shy, join here: https://discord.gg/EMgGbDceNQ and follow here for daily tips and tricks: https://x.com/Scrapling_dev
The fastest path to AI-powered full stack observability, even for lean teams.