MCP server for Proofpoint TAP and Essentials APIs — threat intelligence, email tracing, and MSP org management
- ✓Open-source license (Apache-2.0)
- ✓Actively maintained (<30d)
- ✓Clear description
- ✓Topics declared
- ✓Documented (README)
claude mcp add proofpoint-mcp -- npx -y @wyre-ai/proofpoint-mcp{
"mcpServers": {
"proofpoint-mcp": {
"command": "npx",
"args": ["-y", "@wyre-ai/proofpoint-mcp"],
"env": {
"PROOFPOINT_SERVICE_SECRET": "<proofpoint_service_secret>"
}
}
}
}PROOFPOINT_SERVICE_SECRETResumen de MCP Servers
# Proofpoint MCP Server
[](https://opensource.org/licenses/Apache-2.0)
[](https://nodejs.org/)
A Model Context Protocol (MCP) server for Proofpoint TAP and Essentials APIs. Enables AI assistants to investigate threats, trace emails, manage quarantine, access threat intelligence, and perform URL defense operations.
This is a [Model Context Protocol (MCP)](https://modelcontextprotocol.io/) server that connects Claude (or any MCP-compatible AI) to your Proofpoint environment.
> **Part of the [MSP Claude Plugins](https://github.com/WYRE-AI) ecosystem** — a growing suite of AI integrations for the MSP stack. Built by MSPs, for MSPs.
## Installation
```bash
npm install @wyre-ai/proofpoint-mcp
```
## Configuration
Set the following environment variables:
| Variable | Required | Description |
|----------|----------|-------------|
| `PROOFPOINT_SERVICE_PRINCIPAL` | Yes | Your Proofpoint TAP service principal |
| `PROOFPOINT_SERVICE_SECRET` | Yes | Your Proofpoint TAP service secret |
| `PROOFPOINT_BASE_URL` | No | Custom base URL (default: tap-api-v2.proofpoint.com) |
| `MCP_TRANSPORT` | No | Transport mode: stdio (default) or http |
## Usage
### Running with Claude Desktop
Add to your Claude Desktop `claude_desktop_config.json`:
```json
{
"mcpServers": {
"proofpoint-mcp": {
"command": "npx",
"args": ["@wyre-ai/proofpoint-mcp"],
"env": {
"PROOFPOINT_SERVICE_PRINCIPAL": "your-proofpoint-service-principal"
"PROOFPOINT_SERVICE_SECRET": "your-proofpoint-service-secret"
}
}
}
}
```
### Running with Claude Code (CLI)
```bash
claude mcp add proofpoint-mcp \
-e PROOFPOINT_SERVICE_PRINCIPAL=your-value \
-e PROOFPOINT_SERVICE_SECRET=your-value \
-- npx -y @wyre-ai/proofpoint-mcp
```
### Docker
```bash
docker build -t proofpoint-mcp .
docker run \
-e PROOFPOINT_SERVICE_PRINCIPAL=your-value \
-e PROOFPOINT_SERVICE_SECRET=your-value \
-p 8080:8080 proofpoint-mcp
```
## Features
### Interactive Threat Card (MCP Apps)
`proofpoint_threat_get_by_id` renders as an interactive, read-only card in
MCP Apps hosts (Claude Desktop/web) showing the threat name, status,
category, severity, and resolved actor / malware-family / campaign names;
plain-JSON behavior is unchanged in other hosts. The card is neutral by
default and brandable via `window.__BRAND__` injection or `MCP_BRAND_*` env
vars (`MCP_BRAND_NAME`, `MCP_BRAND_LOGO_URL`, `MCP_BRAND_PRIMARY_COLOR`,
`MCP_BRAND_ACCENT_COLOR`, `MCP_BRAND_BG`, `MCP_BRAND_TEXT`) — no rebuild
needed.
## Available Domains
### Dlp
Data loss prevention policies
### Events
Security event stream and SIEM export
### Forensics
Forensic analysis of threats
### People
Very Attacked People (VAP) reporting
### Policy
Email policy management
### Quarantine
Email quarantine management
### Reports
Security reports and summaries
### Smart Search
Advanced email search
### Tap
Targeted Attack Protection events and campaigns
### Threat Intel
Threat intelligence and indicators of compromise
### Url Defense
URL rewriting and click defense
## Development
```bash
# Clone the repository
git clone https://github.com/WYRE-AI/proofpoint-mcp.git
cd proofpoint-mcp
# Install dependencies
npm install
# Build
npm run build
# Run tests
npm test
```
## Contributing
Contributions are welcome! Please see [CONTRIBUTING.md](CONTRIBUTING.md) if present, or open an issue to discuss changes.
## License
Licensed under the Apache License, Version 2.0. See [LICENSE](LICENSE) for details.
Lo que la gente pregunta sobre proofpoint-mcp
¿Qué es WYRE-AI/proofpoint-mcp?
+
WYRE-AI/proofpoint-mcp es mcp servers para el ecosistema de Claude AI. MCP server for Proofpoint TAP and Essentials APIs — threat intelligence, email tracing, and MSP org management Tiene 2 estrellas en GitHub y su última actualización registrada es del 2026-08-25.
¿Cómo se instala proofpoint-mcp?
+
Puedes instalar proofpoint-mcp clonando el repositorio (https://github.com/WYRE-AI/proofpoint-mcp) o siguiendo las instrucciones del README en GitHub. ClaudeWave también te ofrece bloques de instalación rápida en esta misma página.
¿Es seguro usar WYRE-AI/proofpoint-mcp?
+
Nuestro agente de seguridad ha analizado WYRE-AI/proofpoint-mcp y le ha asignado un Trust Score de 95/100 (tier: Verified). Revisa el desglose completo de comprobaciones superadas y flags en esta página.
¿Quién mantiene WYRE-AI/proofpoint-mcp?
+
WYRE-AI/proofpoint-mcp es mantenido por WYRE-AI. La última actividad registrada en GitHub es del 2026-08-25, con 1 issues abiertos.
¿Hay alternativas a proofpoint-mcp?
+
Sí. En ClaudeWave puedes explorar mcp servers similares en /categories/mcp, ordenados por popularidad o actividad reciente.
Despliega proofpoint-mcp en tu cloud
Lleva este repo a producción en minutos. Cada plataforma genera su propio entorno con variables de entorno editables.
¿Mantienes este repo? Añade un badge a tu README
Pega el badge en tu README de GitHub para mostrar que está auditado por ClaudeWave. Cada badge enlaza de vuelta a esta página y muestra el Trust Score actual.
[](https://claudewave.com/repo/wyre-ai-proofpoint-mcp)<a href="https://claudewave.com/repo/wyre-ai-proofpoint-mcp"><img src="https://claudewave.com/api/badge/wyre-ai-proofpoint-mcp" alt="Featured on ClaudeWave: WYRE-AI/proofpoint-mcp" width="320" height="64" /></a>Más MCP Servers
Fair-code workflow automation platform with native AI capabilities. Combine visual building with custom code, self-host or cloud, 400+ integrations.
User-friendly AI Interface (Supports Ollama, OpenAI API, ...)
An open-source AI agent that brings the power of Gemini directly into your terminal.
Real-time global intelligence dashboard. AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational awareness interface
The fastest path to AI-powered full stack observability, even for lean teams.
🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl!