Skip to content

Configuration

Configure your Claroty CTD credentials and server settings using environment variables.

VariableDescription
CTD_USERNAMEClaroty CTD username
CTD_PASSWORDClaroty CTD password
VariableDefaultDescription
CTD_ENABLED_MODULESallDefines which tools the server exposes.

Accepts a Comma-separated list of supported modules:

  • inventory

  • detections

  • vulnerabilities

  • insights

  • active_detection

  • administration

  • threat_content

  • appliance_updates

CTD_AUDIT_TO_STDERRfalseWrites sanitized audit records to stderr. Possible values are:

true, which enables, or

false, which disables

The recommended approach for development is a .env file.

Terminal window
cp .env.example .env
Terminal window
curl -o .env https://raw.githubusercontent.com/CrowdStrike/falcon-mcp/main/.env.example
# Required Configuration
FALCON_CLIENT_ID=your-client-id
FALCON_CLIENT_SECRET=your-client-secret
FALCON_BASE_URL=https://api.crowdstrike.com
# Optional Configuration
#FALCON_MEMBER_CID=your-child-cid
#FALCON_MCP_MODULES=detections,hosts,intel
#FALCON_MCP_TRANSPORT=stdio
#FALCON_MCP_DEBUG=false
#FALCON_MCP_HOST=127.0.0.1
#FALCON_MCP_PORT=8000
#FALCON_MCP_STATELESS_HTTP=false
#FALCON_MCP_API_KEY=your-api-key
#FALCON_PROXY_URL=http://proxy.corp.example.com:8080

By default, all available modules are enabled. To restrict which modules load:

Terminal window
# Command line (highest priority)
falcon-mcp --modules detections,hosts,intel
Terminal window
# Environment variable (fallback)
export FALCON_MCP_MODULES=detections,hosts,intel
falcon-mcp

Priority order: CLI flag > FALCON_MCP_MODULES env var > all modules (default)

When running HTTP transports (sse or streamable-http), protect the endpoint with an API key:

Terminal window
falcon-mcp --transport streamable-http --api-key your-secret-key

This is a self-generated key (any secure string you create) that ensures only authorized clients with the matching key can access the MCP server. It is separate from your CrowdStrike API credentials.