CLI Commands
Basic Usage
Section titled “Basic Usage”Run the server with default settings (stdio transport):
claroty-ctd-mcpRun with SSE transport:
claroty-ctd-mcp --transport sseRun with streamable-http transport:
claroty-ctd-mcp --transport streamable-httpRun with streamable-http on a custom port:
claroty-ctd-mcp --transport streamable-http --host 0.0.0.0 --port 8080Run with stateless HTTP mode (for scalable deployments like AWS AgentCore):
claroty-ctd-mcp --transport streamable-http --stateless-httpRun with API key authentication:
claroty-ctd-mcp --transport streamable-http --api-key your-secret-keyModule Selection
Section titled “Module Selection”Enable specific modules by name (comma-separated):
claroty-ctd-mcp --modules inventory,detections,vulnerabilitiesEnable only one module:
claroty-ctd-mcp --modules detectionsIf no --modules flag is provided, all available modules are enabled.
All Options
Section titled “All Options”claroty-ctd-mcp --help| Flag | Env Variable | Default | Description |
|---|---|---|---|
--transport | CLAROTY_CTD_MCP_TRANSPORT | stdio | Transport methods:
|
--host | CLAROTY_CTD_MCP_HOST | 127.0.0.1 | Host for HTTP transports. Accepts IPv4 and IPv6 addresses. |
--port | CLAROTY_CTD_MCP_PORT | 8000 | Port for HTTP transports |
--modules | CLAROTY_CTD_MCP_MODULES | all | Comma-separated list of modules to enable:
|
--debug | CLAROTY_CTD_MCP_DEBUG | false | Enable debug logging. Debug diagnostics go to stderr; sensitive HTTP-library debug logging remains suppressed. |
--stateless-http | CLAROTY_CTD_MCP_STATELESS_HTTP | false | Stateless mode for scalable deployments |
Using as a Library
Section titled “Using as a Library”Python embedding is now supported through ClarotyCTDMCPServer.
Pass CTD credentials using the username and password constructor arguments:
from claroty_ctd_mcp.server import ClarotyCTDMCPServer
server = ClarotyCTDMCPServer( base_url="https://your-ctd-URL.com", username=os.environ["CTD_USERNAME"], password=os.environ["CTD_PASSWORD"], debug=True, enabled_modules=["detections", "insights"])
# Run with stdio transport (default)server.run()
# Or with a specific transport# server.run("streamable-http")For enterprise deployments using secret management systems (HashiCorp Vault, AWS Secrets Manager, etc.), you can pass credentials directly:
server = FalconMCPServer( client_id="your-client-id", client_secret="your-client-secret", base_url="https://your-ctd-URL.com", enabled_modules=["detections", "hosts"])server.run()CLI arguments take precedence over environment variables. Invalid transports, IP addresses, ports, module names, and boolean values stop startup with a clear error.