IBM Z mainframe MCP server - Key Protect HSM & z/OS
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
π‘ Paste into ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows)
Inspect callable tools, capabilities, and parameters exposed to AI agents by Ibmz.
key_protect_list_keysList encryption keys in Key Protect
key_protect_create_keyCreate root or standard keys
key_protect_get_keyGet key details and metadata
key_protect_wrap_keyWrap (encrypt) a DEK with a root key
key_protect_unwrap_keyUnwrap (decrypt) a wrapped DEK
key_protect_rotate_keyRotate a root key
[!License: MIT](https://opensource.org/licenses/MIT) [!MCP](https://modelcontextprotocol.io) [!npm](https://www.npmjs.com/package/ibmz-mcp-server)
MCP server for IBM Z mainframe integration. Provides HSM-backed key management via IBM Key Protect (FIPS 140-2 Level 3) and REST API access to mainframe programs (CICS, IMS, batch) via z/OS Connect.
| Tool | Description |
|---|---|
key_protect_list_keys | List encryption keys in Key Protect |
key_protect_create_key | Create root or standard keys |
key_protect_get_key | Get key details and metadata |
key_protect_wrap_key | Wrap (encrypt) a DEK with a root key |
key_protect_unwrap_key | Unwrap (decrypt) a wrapped DEK |
key_protect_rotate_key | Rotate a root key |
key_protect_delete_key | Delete a key (irreversible) |
key_protect_get_key_policies | Get rotation and dual-auth policies |
| Tool | Description |
|---|---|
zos_connect_list_services | List available mainframe services |
zos_connect_get_service | Get service details and OpenAPI spec |
zos_connect_call_service | Call a mainframe program via REST (JSON to COBOL) |
zos_connect_list_apis | List outbound API configurations |
zos_connect_health | Check z/OS Connect server health |
| Variable | Description | Required |
|---|---|---|
IBM_CLOUD_API_KEY | IBM Cloud API key | Yes (Key Protect) |
KEY_PROTECT_INSTANCE_ID | Key Protect instance OCID | Yes (Key Protect) |
KEY_PROTECT_URL | Key Protect endpoint | No (defaults to us-south) |
ZOS_CONNECT_URL | z/OS Connect base URL | Yes (z/OS Connect) |
ZOS_CONNECT_USERNAME | Mainframe username | Yes (z/OS Connect) |
ZOS_CONNECT_PASSWORD | Mainframe password | Yes (z/OS Connect) |
Root keys (KEK) are stored in the HSM and never leave the hardware. Data encryption keys (DEK) are wrapped by root keys for safe storage alongside ciphertext.
REST APIs that automatically map JSON payloads to COBOL copybooks, enabling access to CICS transactions, IMS programs, and batch jobs.
@modelcontextprotocol/sdk -- MCP protocol SDK@ibm-cloud/ibm-key-protect -- Key Protect clientibm-cloud-sdk-core -- IBM Cloud authenticationShowcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/ibmz)<a href="https://allmcps.com/mcp/ibmz"><img src="https://allmcps.com/api/badge/ibmz?style=directory" alt="Ibmz on AllMCPs" /></a>