# MCP Server

The Anantis MCP HTTP server exposes your threats, interactions, decoys, canaries, and reports to any client that speaks the [Model Context Protocol](https://modelcontextprotocol.io).

---

## Connection details

| | |
| --- | --- |
| **Endpoint** | `https://api.anantis.io/mcp` |
| **Transport** | Streamable HTTP |
| **Authentication** | `Authorization: Bearer <api-key>` |
| **OAuth** | Not supported |

## Prerequisites

An Anantis API key, [create it here](/docs/api/authentication/). The MCP server uses the same key as the REST API.

**Use a dedicated read-only key:** Create a **separate key for MCP** rather than reusing an existing integration key, and grant it read scopes only (`threats:read`, `interactions:read`, `decoys:read`, `canaries:read`, `reports:read`). The MCP server exposes read tools only.

## Configuration

Replace `YOUR_KEY` with your API key throughout.
Add the server from the terminal:

```bash
claude mcp add --transport http anantis https://api.anantis.io/mcp \
  --header "Authorization: Bearer YOUR_KEY"
```

By default the server is added for the current project only. Use `--scope user` to make it available across all your projects:

```bash
claude mcp add --scope user --transport http anantis https://api.anantis.io/mcp \
  --header "Authorization: Bearer YOUR_KEY"
```

Verify with `claude mcp list`: the server should report `✔ Connected`.

**Install link**: [Add Anantis MCP to Cursor](cursor://anysphere.cursor-deeplink/mcp/install?name=anantis&config=eyJ1cmwiOiJodHRwczovL2FwaS5hbmFudGlzLmlvL21jcCIsImhlYWRlcnMiOnsiQXV0aG9yaXphdGlvbiI6IkJlYXJlciBZT1VSX0tFWSJ9fQ==)

**OR**

**Configuration file**: 

Create `.cursor/mcp.json` in your project, or `~/.cursor/mcp.json` to enable it globally:

```json
{
  "mcpServers": {
    "anantis": {
      "url": "https://api.anantis.io/mcp",
      "headers": {
        "Authorization": "Bearer YOUR_KEY"
      }
    }
  }
}
```

**Install link**: [VS Code](vscode:mcp/install?%7B%22name%22%3A%22anantis%22%2C%22type%22%3A%22http%22%2C%22url%22%3A%22https%3A%2F%2Fapi.anantis.io%2Fmcp%22%2C%22headers%22%3A%7B%22Authorization%22%3A%22Bearer%20YOUR_KEY%22%7D%7D) · [VS Code Insiders](vscode-insiders:mcp/install?%7B%22name%22%3A%22anantis%22%2C%22type%22%3A%22http%22%2C%22url%22%3A%22https%3A%2F%2Fapi.anantis.io%2Fmcp%22%2C%22headers%22%3A%7B%22Authorization%22%3A%22Bearer%20YOUR_KEY%22%7D%7D)

**OR**

**Configuration file**:

Create `.vscode/mcp.json`. VS Code prompts for the key on first use and stores it securely, so nothing secret is written to the file:

```json
{
  "inputs": [
    {
      "type": "promptString",
      "id": "anantis-api-key",
      "description": "Anantis API key",
      "password": true
    }
  ],
  "servers": {
    "anantis": {
      "type": "http",
      "url": "https://api.anantis.io/mcp",
      "headers": {
        "Authorization": "Bearer ${input:anantis-api-key}"
      }
    }
  }
}
```

Edit `~/.codeium/windsurf/mcp_config.json`:

```json
{
  "mcpServers": {
    "anantis": {
      "serverUrl": "https://api.anantis.io/mcp",
      "headers": {
        "Authorization": "Bearer YOUR_KEY"
      }
    }
  }
}
```

Most MCP clients accept the same three values:

| Setting | Value |
| --- | --- |
| Transport | Streamable HTTP (`streamable-http`, sometimes written `http`) |
| URL | `https://api.anantis.io/mcp` |
| Header | `Authorization: Bearer <api-key>` |

## Available tools

The MCP server is **read-only**: no tool writes to the platform. Each tool requires the scope listed below, so a tool whose scope the key lacks simply fails when called.

| Tool | Purpose | Scope |
| --- | --- | --- |
| `whoami` | Inspect the connected key: entity, scopes, accessible organizations. | none |
| `list_threats` | List threats, aggregated by source IP. | `threats:read` |
| `get_threat` | Retrieve a single threat. | `threats:read` |
| `list_interactions` | List events captured by decoys, most recent first. | `interactions:read` |
| `get_interaction` | Retrieve a single interaction. | `interactions:read` |
| `list_decoys` | List deployed decoys. | `decoys:read` |
| `get_decoy` | Retrieve one decoy's metadata. | `decoys:read` |
| `list_canaries` | List deployed canaries. | `canaries:read` |
| `get_canary` | Retrieve one canary's metadata. | `canaries:read` |
| `get_report` | Generate the executive report for a period. | `reports:read` |
| `list_users` | List console users. | `users:read` |
| `get_user` | Retrieve a single console user. | `users:read` |

## Verify the connection

Ask your client a question that exercises the server. A good first prompt is:

> Using the Anantis MCP server, call whoami and tell me which organizations this key can reach.

A successful response echoes your `entity_uuid` and the scopes you granted.