Skip to main content
AllMCPs
BrowseBestCategoriesStackCompareToolsGuidesBlog
Log in Submit MCP

Stay in the loop

Get new MCP servers and top picks in your inbox.

AllMCPs

The open directory for discovering and installing Model Context Protocol servers.

AllMCPs on GitHub (opens in a new tab)
Launched onTiny Startupstinystartups.com
Explore
  • Browse servers
  • Best MCP servers
  • Categories
  • MCP clients
  • Agent prompts
  • Stack Builder
  • Compare servers
  • Random discovery New
  • Submit a server
  • Pricing & Boost Boost
Learn
  • Guides hub
  • What is MCP?
  • Install guide
  • Build an MCP server
  • Deploy an MCP server
  • Security guide
  • Troubleshooting
  • MCP for SEO & AEO
  • Protocol versioning
  • Blog & updates
Tools
  • All developer tools
  • Config generator
  • Config validator
  • Config auditor
  • MCP playground
  • Token calculator
  • OpenAPI β†’ MCP
  • Badge generator
For agents
  • REST API docs
  • Trust & traffic Live
  • Remote MCP server SSE β†— (opens in a new tab)
  • llms.txt β†— (opens in a new tab)
  • Catalog JSON β†— (opens in a new tab)
Company
  • About
  • Advertise Sponsor
  • Contact
  • GitHub β†— (opens in a new tab)
  • Terms
  • Privacy
AllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZoneAllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZone
Β© 2026 Jackalope Digital LLC. All rights reserved.
  1. Home
  2. πŸ’» Developer Tools
  3. Sophos Central MCP
S
Health: ActiveRecent health check succeeded.Last checked 9/8/2026, 11:46:24 AM

Sophos Central MCP

User RatingsBe the first to rate and review this MCP server! Enrichment pendingWe haven’t run our AI enrichment pass on this listing yet, so the overview, use cases, and FAQ below may be sparse or missing. We work through the catalog over time β€” check back soon.
View Repository

MCP server for Sophos Central β€” endpoint security, XDR/MDR, and MSSP multi-tenant ops

Quick Install

Automated & IDE Setup

Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β€” or use 1-click editor setup below.

Add to CursorAdd to VS Code
Not yet automatically verified

We haven't yet run this listing's install command through our automated sandbox check. This isn't a red flag β€” we're steadily working through the catalog.

Manual Client & Custom JSON ConfigExpand JSON β–Ύ

Client Config & Setup

Choose your client or environment
Target File:~/Library/Application Support/Claude/claude_desktop_config.json
claude_desktop_config.json
{
  "mcpServers": {
    "sophos-central-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@modelcontextprotocol/inspector"
      ]
    }
  }
}

πŸ’‘ Paste the JSON block into your client's configuration file under mcpServers, then restart the application.

Install Directory Badge Claim listing AlternativesπŸ’» More in Developer Tools

Documentation Overview

Sophos Central MCP Server

Node.js License MCP Protocol Tools GitHub Stars

Build & Test npm MCP Registry

For MSP/MSSP teams: Manage endpoint security, email threats, and firewall policy across all your Sophos tenants through natural language. Ask Claude to investigate an alert, isolate a host, run Live Discover queries, and correlate with XDR data β€” without leaving your AI workflow.

Overview

A Model Context Protocol (MCP) server for the Sophos Central API, enabling AI-powered security operations through Claude and other MCP-compatible clients. Designed for MSP/MSSP environments with Partner Super Admin credentials, it provides multi-tenant management across all customer tenants from a single server instance β€” covering endpoint protection, threat detection, Live Discover forensics, XDR hunting, email security, firewall management, and more.

Features

  • 334 tools across 33 API domains β€” comprehensive Sophos Central API coverage
  • Multi-tenant MSSP support β€” enumerate and target any customer tenant via Partner Super Admin credentials
  • Endpoint isolation and investigation β€” isolate endpoints, check tamper protection, trigger scans
  • Alert triage β€” list, filter, acknowledge, and action Sophos alerts across tenants
  • Live Discover SQL queries β€” run real-time forensic SQL queries directly on managed endpoints
  • XDR Data Lake hunting β€” historical threat hunting with SQL against the Sophos XDR data lake
  • Threat detections β€” query, group, and count behavioral detections
  • Case management β€” create and manage investigation cases end-to-end
  • Email security β€” quarantine management, mailbox listing, post-delivery message clawback
  • Firewall management β€” CRUD operations, group management, firmware upgrades
  • DNS protection β€” location policies, custom domain allow/block lists
  • SOC playbooks β€” built-in sophos_playbook_* tools for guided IR and threat hunting workflows
  • Three transport modes β€” stdio (Claude Desktop), SSE, and Streamable HTTP (Claude Code)
  • Automatic OAuth2 token management β€” token refresh with no manual intervention
  • Regional routing β€” requests automatically routed to the correct data region (US, EU, CA, AU, JP, BR)

Prerequisites

  • Node.js v18 or later (native fetch support required)
  • npm v8 or later
  • Sophos Central Partner Super Admin API credentials β€” see Configuration for how to create these

Installation

bash
git clone https://github.com/rijul170/sophos-central-mcp.git
cd sophos-central-mcp
npm install
npm run build

Configuration

1. Create a .env file

bash
cp .env.example .env

Edit .env with your credentials:

env
# Required
SOPHOS_CLIENT_ID=your-client-id-here
SOPHOS_CLIENT_SECRET=your-client-secret-here

# Optional β€” transport mode: stdio | sse | streamable-http (default: stdio)
MCP_TRANSPORT=stdio

# Optional β€” host for HTTP transports (default: 127.0.0.1)
MCP_HOST=127.0.0.1

# Optional β€” port for HTTP transports (default: 3001)
MCP_PORT=3001

2. Create API Credentials in Sophos Central

  1. Log in to Sophos Central Partner Dashboard
  2. Navigate to Settings & Policies β†’ API Credentials Management
  3. Click Add Credential
  4. Set the role to Service Principal Super Admin
  5. Copy the Client ID and Client Secret β€” the secret is displayed only once
VariableRequiredDescription
SOPHOS_CLIENT_IDYesPartner Super Admin Client ID from Sophos Central
SOPHOS_CLIENT_SECRETYesCorresponding client secret
MCP_TRANSPORTNoTransport mode: stdio, sse, or streamable-http (default: stdio)
MCP_HOSTNoBind host for HTTP transports (default: 127.0.0.1)
MCP_PORTNoPort for HTTP transports (default: 3001)
SOPHOS_MCP_READONLYNoSet to true to register only read tools β€” write and destructive tools are never exposed to the AI client
SOPHOS_MCP_ALLOW_DESTRUCTIVENoDestructive tools (deletes, endpoint isolation, Live Discover execution, clawback, ...) are suppressed by default. Set to true to arm all of them, or a comma-separated list of tool names to arm selectively

Claude Code Integration (HTTP Mode)

HTTP mode is recommended for Claude Code β€” it supports concurrent sessions and does not require restarting the server between conversations.

Start the server:

bash
MCP_TRANSPORT=streamable-http MCP_PORT=3001 node build/index.js

Or set MCP_TRANSPORT=streamable-http in your .env and run:

bash
node build/index.js

Add to your Claude Code MCP configuration (.claude/settings.json or global settings):

config.json
{
  "mcpServers": {
    "sophos-mcp": {
      "type": "http",
      "url": "http://localhost:3001/mcp"
    }
  }
}

A /health endpoint is available at http://localhost:3001/health for liveness checks.

Claude Desktop Integration (stdio Mode)

stdio mode is the standard transport for Claude Desktop. The server process is managed by Claude Desktop directly.

Add to your Claude Desktop MCP configuration (claude_desktop_config.json):

config.json
{
  "mcpServers": {
    "sophos-mcp": {
      "command": "node",
      "args": ["/path/to/sophos-central-mcp/build/index.js"],
      "env": {
        "SOPHOS_CLIENT_ID": "your-client-id",
        "SOPHOS_CLIENT_SECRET": "your-client-secret"
      }
    }
  }
}

Replace /path/to/sophos-central-mcp with the absolute path to your cloned repository.

SSE Mode

SSE (Server-Sent Events) mode is available for legacy MCP clients that do not support Streamable HTTP.

bash
MCP_TRANSPORT=sse MCP_PORT=3001 node build/index.js

The SSE endpoint is available at http://localhost:3001/sse.

Tool Domains

DomainToolsDescription
Alerts5List, get, acknowledge, and action Sophos alerts
Endpoint26Isolation, tamper protection, scans, migrations, bulk operations
Detections7Query-based behavioral detection search, grouping, and counts
Live Discover11Real-time forensic SQL queries on managed endpoints
XDR10Historical SQL hunting against the Sophos XDR Data Lake
Cases9Investigation case create, read, update, close, and evidence management
Partner23Tenant enumeration, admins, roles, billing, permission sets
Organization2Tenant listing for organization-type accounts
Policy7Full CRUD for all Sophos policy types
Group8Endpoint group CRUD and member management
SIEM2Events and alerts export for SIEM integration
Firewall20Firewall CRUD, group management, firmware upgrades
DNS Protection15Locations, policies, custom domain allow/block lists
Email31Quarantine management, mailboxes, post-delivery message clawback
Directory15User and user group full CRUD
Settings16Tamper protection, exclusions, web control, endpoint tags
Allowed/Blocked12SHA256 hash, certificate, and path allow/block lists
Exploit Mitigation8Application-level exploit protection exclusions
IPS Exclusion10Network IPS and isolation exclusion management
Tenant Admin14Tenant admin CRUD, role assignments, custom roles
Account Health4Health check reports, snooze, and historical health scores
Account Management4Account-level settings and license management
Audit Events2Audit log retrieval for compliance and governance
Business Automation3Automation rules and business logic configuration
Licensing2License entitlement and usage queries
Mobile38Mobile device management β€” enrollment, policies, device actions
Cloud Security6Cloud workload protection posture and findings
Software9Installer downloads, software inventory, packages
Switch3Network switch management
WiFi3Wireless network management
User Activity2User activity reporting and session data
Playbooks5SOC incident response and threat hunting workflow guides
Auth2OAuth2 authentication and WhoAmI identity discovery

MSSP Multi-Tenant Support

The server is built around Sophos Partner Super Admin credentials, which have visibility across all managed customer tenants.

How it works:

  1. On startup, the server authenticates to Sophos Central using your Partner credentials and discovers your organization type (partner or organization).
  2. Use sophos_list_tenants (or sophos_list_org_tenants for organization accounts) to enumerate all managed tenants and their IDs.
  3. Pass the tenantId parameter to any tenant-scoped tool to target a specific customer environment.
  4. All API calls are automatically routed to the correct regional endpoint (US, EU, CA, AU, JP, BR) based on the tenant's data residency.

Example workflow:

Code
1. sophos_list_tenants          β†’ get all tenant IDs and names
2. sophos_list_alerts           β†’ pass tenantId for a specific customer
3. sophos_isolate_endpoint      β†’ isolate an endpoint in that tenant
4. sophos_live_discover_run_query β†’ run forensic SQL on the isolated host

Read the full README β†’View source on GitHub β†’

Related MCP Servers

View all in Developer Tools View all alternatives
  • T
    Tldraw

    Draw and visually collaborate with your agents on tldraw's canvas.

    πŸ’» Developer Tools0 views
    Compare vs Tldraw β†’
  • PraisonAI logoPraisonAI

    AI Agents Framework with Self Reflection and MCP support

    πŸ’» Developer Tools1 views
    Compare vs PraisonAI β†’
  • T
    Telnyx

    Official TypeScript library for the Telnyx API

    πŸ’» Developer Tools0 views
    Compare vs Telnyx β†’
  • Ignite UI MCP Server logoIgnite UI MCP Server

    Unified MCP server for Ignite UI β€” documentation, API, and CLI scaffolding

    πŸ’» Developer Tools1 views
    Compare vs Ignite UI MCP Server β†’

Reviews

No reviews yet β€” be the first to share how this listing worked for you.

Frequently Asked Questions about Sophos Central MCP

Add the following block to your claude_desktop_config.json under mcpServers: "mcpServers": { "sophos-central-mcp": { "command": "npx", "args": ["-y", "sophos-central-mcp"] } }

AllMCPs Directory Badge

Full Badge Customizer

Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.

Badge Style:
Live Dynamic SVG PreviewSophos Central MCP AllMCPs Directory Badge
Markdown (GitHub README)
[![AllMCPs](https://allmcps.com/api/badge/sophos-central-mcp?style=directory)](https://allmcps.com/mcp/sophos-central-mcp)
HTML Embed
<a href="https://allmcps.com/mcp/sophos-central-mcp"><img src="https://allmcps.com/api/badge/sophos-central-mcp?style=directory" alt="Sophos Central MCP on AllMCPs" /></a>

Technical Specs & Signals

CategoryπŸ’»Developer Tools
More technical detailsExpand β–Ύ
TransportSTDIO
RuntimeNode.js
Last updatedJul 26, 2026
Views0
Unique ViewsTotal visits recorded for this listing page on AllMCPs.
Installs0
Installs & Copy ActionsTotal times users copied install commands or configuration snippets for this server.
GitHub stars0
GitHub Star CountTotal stargazers on GitHub representing community popularity (0 stars).
Last commit1mo ago
Last Repository CommitThe most recent commit or push recorded for this server's GitHub repository.Last commit on Jul 26, 2026
37Quality signal: Fair Β· 37/100How this signal is calculated β–Ύ
Server availabilityNot measured

Not scored for repo-hosted servers β€” we can't reach the running server, only its GitHub page. Hosted MCP endpoints are health-checked live.

Verified ownership10/20
Documentation & tools16/30
Adoption & activity2/15
Community engagement0/10

A guidance signal from public completeness & health data β€” not a user rating. New listings start lower and rise as they add docs, get verified, and grow adoption. Signals we can't observe for a listing are skipped, not counted against it.

β˜… Spotlight Slot

Feature Your MCP Server

Get maximum visibility for your server across our directory, search results, and detail pages.

Spotlight Your Server

Own this project?

This directory is pre-filled from public sources. Claim via GitHub README, site badge, or DNS TXT to unlock edit access and the Official badge and attach your website β€” proof is checked automatically, then reviewed by our team.

Free dofollow backlink: add your website and place the AllMCPs badge on it β€” no claim needed. We detect it automatically and keep it verified as long as the badge stays live.

Claim & get free dofollow

Share & Embed

Add our SVG badge (dark/light directory styles) or embeddable widget to your site.

Explore more

More in πŸ’» Developer Tools β†’Best MCP servers for Developers β†’Alternatives to Sophos Central MCP β†’Install in Claude DesktopInstall in CursorInstall in VS Code