Skip to content

CLI Commands

Run the server with default settings (stdio transport):

Terminal window
claroty-ctd-mcp

Run with SSE transport:

Terminal window
claroty-ctd-mcp --transport sse

Run with streamable-http transport:

Terminal window
claroty-ctd-mcp --transport streamable-http

Run with streamable-http on a custom port:

Terminal window
claroty-ctd-mcp --transport streamable-http --host 0.0.0.0 --port 8080

Run with stateless HTTP mode (for scalable deployments like AWS AgentCore):

Terminal window
claroty-ctd-mcp --transport streamable-http --stateless-http

Run with API key authentication:

Terminal window
claroty-ctd-mcp --transport streamable-http --api-key your-secret-key

Enable specific modules by name (comma-separated):

Terminal window
claroty-ctd-mcp --modules inventory,detections,vulnerabilities

Enable only one module:

Terminal window
claroty-ctd-mcp --modules detections

If no --modules flag is provided, all available modules are enabled.

claroty-ctd-mcp --help
FlagEnv VariableDefaultDescription
--transportCLAROTY_CTD_MCP_TRANSPORTstdioTransport methods:

  • stdio

  • sse

  • streamable-http
--hostCLAROTY_CTD_MCP_HOST127.0.0.1Host for HTTP transports. Accepts IPv4 and IPv6 addresses.
--portCLAROTY_CTD_MCP_PORT8000Port for HTTP transports
--modulesCLAROTY_CTD_MCP_MODULESallComma-separated list of modules to enable:

  • inventory

  • detections

  • vulnerabilities

  • insights

  • active_detection

  • administration

  • threat_content

  • appliance_updates
--debugCLAROTY_CTD_MCP_DEBUGfalseEnable debug logging. Debug diagnostics go to stderr; sensitive HTTP-library debug logging remains suppressed.
--stateless-httpCLAROTY_CTD_MCP_STATELESS_HTTPfalseStateless mode for scalable deployments

Python embedding is now supported through ClarotyCTDMCPServer.

Pass CTD credentials using the username and password constructor arguments:

from claroty_ctd_mcp.server import ClarotyCTDMCPServer
server = ClarotyCTDMCPServer(
base_url="https://your-ctd-URL.com",
username=os.environ["CTD_USERNAME"],
password=os.environ["CTD_PASSWORD"],
debug=True,
enabled_modules=["detections", "insights"]
)
# Run with stdio transport (default)
server.run()
# Or with a specific transport
# server.run("streamable-http")

For enterprise deployments using secret management systems (HashiCorp Vault, AWS Secrets Manager, etc.), you can pass credentials directly:

server = FalconMCPServer(
client_id="your-client-id",
client_secret="your-client-secret",
base_url="https://your-ctd-URL.com",
enabled_modules=["detections", "hosts"]
)
server.run()

CLI arguments take precedence over environment variables. Invalid transports, IP addresses, ports, module names, and boolean values stop startup with a clear error.