MCP server for DefectDojo: 24 tools with RBAC, HMAC audit chain, and SIEM forwarding
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
π‘ Paste the JSON block into your client's configuration file under mcpServers, then restart the application.
MCP server for DefectDojo vulnerability management. Exposes 24 tools for managing products, engagements, tests, findings, scan imports, and finding lifecycle through the Model Context Protocol.
Getting Started Guide β step-by-step setup, from install through connecting your first MCP client.
Requires Python 3.12+, uv, and a running DefectDojo instance.
All configuration is via environment variables. Copy env.example to .env for local development.
| Variable | Description |
|---|---|
DEFECTDOJO_URL | Base URL of the DefectDojo instance (must use https:// unless overridden) |
DEFECTDOJO_API_KEY | API key for DefectDojo (generate at DefectDojo > API v2 > Your API Key) |
For least-privilege access, use separate read/write keys instead of DEFECTDOJO_API_KEY:
| Variable | Description |
|---|---|
DEFECTDOJO_READ_API_KEY | Read-only API key (used for GET requests) |
DEFECTDOJO_WRITE_API_KEY | Write API key (used for POST/PATCH requests) |
Token-role bindings using MCP_ROLE_* env vars (preferred):
| Variable | Description |
|---|---|
MCP_ROLE_<NAME> | Format: <token>:<role>. Binds a bearer token to a role. Name becomes the caller ID. |
Four roles are available, each inheriting from the one below:
| Role | Permissions |
|---|---|
admin | All permissions including product_mgmt |
writer | engagement_mgmt, finding_mgmt, scan_mgmt, metadata_read, system |
scanner | scan_mgmt, metadata_read, system |
reader | metadata_read, system |
Example: MCP_ROLE_CI=tok_abc123:scanner grants the token scanner-level access.
Legacy variables (mapped to RBAC roles for backward compatibility):
| Variable | Maps to |
|---|---|
MCP_AUTH_TOKEN | admin role |
MCP_READ_TOKEN | reader role |
| Variable | Default | Description |
|---|---|---|
FASTMCP_TRANSPORT | stdio | Transport mode: stdio, sse, streamable-http, http |
FASTMCP_HOST | 0.0.0.0 | Bind address for network transports |
FASTMCP_PORT | 8000 | Port for network transports |
| Variable | Default | Description |
|---|---|---|
ALLOW_INSECURE_HTTP | false | Allow http:// URLs (TLS required by default) |
MUTATION_RATE_LIMIT | 60 | Max mutations per rate window per authenticated caller (per-token bucket) |
OPEN_ACCESS_MUTATION_RATE_LIMIT | 10 | Max mutations per rate window across all unauthenticated traffic (one shared bucket β applies only when REQUIRE_AUTH=false) |
MUTATION_RATE_WINDOW | 60 | Rate window in seconds (applies to both buckets) |
UNTRUSTED_CONTENT_WRAPPING | on | F-002 read-side wrapping kill-switch. When on (default), title, description, tags, notes, and note entry fields are returned inside {"value": <content>, "_warning": "untrusted-content: ..."}. Set to off only for legacy downstream consumers that cannot parse the wrapped shape. |
DEFECTDOJO_DEFAULT_FOUND_BY_ID | 1 | Finding type ID used in create_finding payloads. The default 1 corresponds to "API Test" on stock DefectDojo installs; set to the ID for your "Manual" or "Pen Test" type if the default is missing or incorrect. Validated at startup β must be a positive integer. |
| Variable | Default | Description |
|---|---|---|
LOG_LEVEL | INFO | DEBUG, INFO, WARNING, ERROR, CRITICAL |
AUDIT_HMAC_KEY | (ephemeral) | HMAC key for audit log integrity chain. Required for cross-restart log verification. Generate with: python3 -c "import secrets; print(secrets.token_hex(32))" |
AUDIT_LOG_FILE | (stderr only) | Path for dedicated audit log file (JSON-lines, logrotate-compatible) |
| Variable | Default | Description |
|---|---|---|
AUDIT_LOG_SYSLOG | (disabled) | Syslog destination. Format: [transport://]host[:port]. Transports: tcp, udp, tcp+tls (default). |
AUDIT_LOG_SYSLOG_CA | (system CAs) | Custom CA certificate for syslog TLS verification |
AUDIT_LOG_HTTPS_URL | (disabled) | HTTPS endpoint for log forwarding (JSON array POST) |
AUDIT_LOG_HTTPS_TOKEN | (none) | Bearer token for HTTPS endpoint authentication |
AUDIT_LOG_HTTPS_BATCH_SIZE | 10 | Number of log records per HTTPS batch |
AUDIT_LOG_HTTPS_FLUSH_SECS | 5 | Seconds before flushing a partial batch |
AUDIT_LOG_HTTPS_CA | (system CAs) | Custom CA certificate path for HTTPS TLS verification β required when forwarding to a SIEM signed by an internal PKI (e.g. Caddy + Vault PKI). |
The HTTPS forwarder retries each batch once on transient failure with a short backoff and opens a 30-second circuit breaker after 3 consecutive failures, matching the syslog forwarder's behavior. Batch and circuit-open failures are emitted as structured audit_forward_failure events with forwarder: "https" for SIEM correlation.
These traps bite first-time deployments most often. Each one is a fail-CLOSED guard by design β the server refuses to start rather than running in a silently-degraded state.
AUDIT_HMAC_KEYSymptom: Container exits immediately with:
Cause: On sse, streamable-http, or http transports, the server requires a persistent HMAC key for the audit-log integrity chain. Without it, the chain can't survive a process restart β a regulatory-grade audit log shouldn't run in that mode by accident.
Fix (recommended): Generate and set a real key:
Store it in a secret manager (Vault, AWS Secrets Manager, etc.) so it persists across deploys.
Fix (escape hatch): If you've consciously accepted the ephemeral-key posture (e.g., short-lived dev container), set REQUIRE_AUDIT_HMAC_KEY=false. The server starts and logs a CRITICAL warning at boot.
Note for stdio users: This guard only fires on network transports. Local stdio (Claude Desktop / Claude Code) is unaffected.
Symptom: Server refuses to start on sse/streamable-http/http with a missing-auth error.
Cause: Network transports require at least one MCP_ROLE_<NAME>=<token>:<role> binding (or the legacy MCP_AUTH_TOKEN). Open access on the network is opt-in only.
Fix: Set at least one role token:
Or, for development only, opt out with REQUIRE_AUTH=false (warning: any caller on the network can use the server).
If you combine REQUIRE_AUTH=false with the default FASTMCP_HOST=0.0.0.0, you have an open mutation API on the LAN. The server emits a distinct CRITICAL audit event when both conditions hold so a SIEM rule can alert on the compound case. For workstation development, set FASTMCP_HOST=127.0.0.1 to bind only to localhost.
Symptom: Server refuses to start with:
Cause: TLS is enforced by default. Local dev DefectDojo instances often run on http://localhost:8080 without TLS.
Fix: For local development against a non-TLS DefectDojo, set ALLOW_INSECURE_HTTP=true. Never set this in production β use a reverse proxy (Caddy, nginx, Traefik) to terminate TLS in front of DefectDojo instead.
create_product returns 403 with a valid API keySymptom: Read tools work; create_product returns Permission denied (HTTP 403) from DefectDojo.
Cause: This isn't an MCP server bug β the DefectDojo API key inherits its user's role. Product creation requires admin-level access in DefectDojo itself. Most scanner-style service accounts can create engagements, tests, and findings but not products.
Fix: Either (a) use an admin API key for the MCP server, or (b) pre-create products in DefectDojo and let the MCP server manage everything below the product level. The dual-key mode (DEFECTDOJO_READ_API_KEY + DEFECTDOJO_WRITE_API_KEY) helps here: scope the write key narrowly and accept that create_product will fail-fast.
Symptom: First ~60 imports succeed, then subsequent calls return ToolError: rate limit exceeded β retry after Ns with a Retry-After hint.
Cause: The default mutation rate limit is 60 mutations per 60-second sliding window per authenticated token. Bulk operations exceed it quickly.
Fix: For legitimate bulk-import workflows, either (a) raise MUTATION_RATE_LIMIT to a value matched to your batch size, (b) raise MUTATION_RATE_WINDOW to a longer window, or (c) use the scanner role with import_scan/reimport_scan β scan imports bundle many findings into a single mutation. Don't disable the rate limiter outright; it's the only defense against runaway agent loops.
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/defectdojo)<a href="https://allmcps.com/mcp/defectdojo"><img src="https://allmcps.com/api/badge/defectdojo?style=directory" alt="DefectDojo on AllMCPs" /></a>