MCP Server

tripwire-mcp is a Model Context Protocol server that lets MCP-capable clients such as Claude Desktop and Claude Code work with your tripwires. Ask Claude to "put a postgres decoy in the prod namespace", "which tripwires have been touched this week?" or "renew everything expiring in the next month", and it does it through the same API the web app uses.

It speaks JSON-RPC 2.0 over stdio, so it works identically against the SaaS API (https://api.gettripwires.com) and a self-hosted control server. The binary depends only on the Go standard library — no third-party dependencies.

What it can see

The server has no privileges of its own. Every call carries your credential and your active organization, and the API applies exactly the permissions it applies in the browser:

  • Only organizations you are a member of. Tripwires belonging to anyone else's organization are neither listed nor addressable — asking for one by ID reports it as not found.
  • Only namespaces you have been granted. A namespace you cannot see behaves as though it does not exist.
  • Your role decides what you may change: viewer is read-only; member and above can create, update and delete.
  • Nothing installation-wide. Platform users, settings, billing and system health are not reachable from here.

Install

Download tripwire-mcp from the releases page (published alongside the CLI for Linux, macOS and Windows), or build from source:

go build -o tripwire-mcp ./cmd/mcp

Authenticate

The server takes a bearer credential: a scoped API key (tw_…) or a session JWT. Mint a key under Settings → API Keys, or with tripwire keys create. It needs:

ScopeNeeded for
org:readlist_orgs, list_org_members, whoami — how the server discovers which organizations you belong to
tripwire:readListing tripwires, reading one, fetching its artifact, detections, analytics
tripwire:createcreate_tripwire
tripwire:updateupdate_tripwire, renew_tripwire, reset_tripwire
tripwire:deletedelete_tripwire

Grant only what you want the assistant to be able to do — leaving tripwire:delete off is a cheap way to make sure it cannot remove anything.

Configuration comes from flags or environment variables (flags win):

FlagEnvironmentMeaning
--endpointTRIPWIRE_ENDPOINTAPI base URL
--api-keyTRIPWIRE_API_KEYAPI key or JWT. Use the environment variable — see below.
--orgTRIPWIRE_ORGDefault organization ID (org_…). Individual tools can override it.
--read-onlyTRIPWIRE_MCP_READ_ONLY=trueOffer only tools that cannot change anything. See Read-only mode.

Pass the key through TRIPWIRE_API_KEY, not --api-key. Command-line arguments are readable by every local user in the process list (ps, /proc/<pid>/cmdline) for as long as the server runs; its environment is not. The flag exists for one-off testing.

--org takes the organization's ID, not its name. Find it with tripwire orgs list, or leave it out and ask the assistant to list your organizations first.

Configure your client

Claude Desktop / generic MCP host config:

{
  "mcpServers": {
    "tripwire": {
      "command": "tripwire-mcp",
      "env": {
        "TRIPWIRE_ENDPOINT": "https://api.gettripwires.com",
        "TRIPWIRE_API_KEY": "tw_your_api_key",
        "TRIPWIRE_ORG": "org_your_organization_id"
      }
    }
  }
}

Claude Code — --env writes the same env block, so the key never appears on a command line:

claude mcp add \
  --env TRIPWIRE_ENDPOINT=https://api.gettripwires.com \
  --env TRIPWIRE_API_KEY=tw_your_api_key \
  --env TRIPWIRE_ORG=org_your_organization_id \
  tripwire -- tripwire-mcp

A stdio MCP server does not inherit your shell

Exporting TRIPWIRE_API_KEY in .bashrc is not enough on its own — the value has to be in the env block. Claude Code expands ${VAR} inside its config, which lets you keep the key out of the file: "env": { "TRIPWIRE_API_KEY": "${TRIPWIRE_API_KEY}" }

Self-hosted installations point the endpoint at your control server, e.g. https://tripwire.internal.example.com. Settings → MCP Server in the app generates both snippets with this installation's endpoint and your organization filled in.

Read-only mode

Start the server with --read-only (or TRIPWIRE_MCP_READ_ONLY=true in its env block) and it offers only the tools that cannot change anything: create_tripwire, update_tripwire, renew_tripwire, reset_tripwire and delete_tripwire disappear from the tool list, and a client that calls one anyway is refused before any request leaves your machine. Use it for an assistant that should investigate detections but never touch the estate.

It is a client-side guard. The hard boundary is still the key: a key minted with only tripwire:read and org:read cannot write no matter how the server is started. Use both.

Tools

Every tool takes an optional org_id, so one session can work across several of your organizations without restarting the server.

ToolAction
list_orgsThe organizations you belong to, and your role in each
list_org_membersMembers of one of your organizations, with roles and namespace grants
whoamiThe identity behind the configured credential
create_tripwireCreate a decoy: name, technology, optional namespace, tags and lease
list_tripwiresList your tripwires, with search, technology/status/tag filters, sort and paging
get_tripwireOne tripwire: configuration, status, recent detections, and its trigger when that is a value (see below)
get_tripwire_artifactThe trigger file of a file-based tripwire: a fresh download URL, and the content itself for text files up to 256 KiB
update_tripwireChange name, destination, namespace, tags or expiry
renew_tripwireExtend the lease by a duration (e.g. 720h)
reset_tripwireRe-baseline the trip count; optionally purge the detection records
delete_tripwireDelete a tripwire and its detections
list_detectionsDetections recorded against one tripwire: source IP, time, captured context
list_org_detectionsThe org-wide detections feed — every trip across the organization, filterable by time window, tripwire, protocol and source IP (“what fired in the last hour?”)
analyticsSummary of activity across your estate. Self-hosted installations only — on SaaS it says so rather than failing obscurely

create_tripwire’s technology argument is an enum of exactly the technologies the dashboard offers (38 today, from postgresql and ssh to docx, qr_code and aws_session); the transport type is derived from it. See the technology reference for the full list and what each returns. Not-yet-supported values such as gcp and azure are rejected before any API call.

Getting a tripwire's trigger

A tripwire is only useful once its trigger is planted somewhere. Where that trigger comes from depends on the type:

TypeWhere the trigger is
Protocol honeypots (PostgreSQL, MySQL, Redis, …)get_tripwire → connection (host, port, credentials, connection string)
Cloud credentialsget_tripwire → aws_credentials
Web, redirect, DNS and SAML tokensget_tripwire → tracking_url, hostname or acs_url / entity_id
Files (documents, scripts, kubeconfig, WireGuard, SQL dumps, QR codes, …)get_tripwire reports has_artifact: true; get_tripwire_artifact returns the file. Text files come back inline, ready for the assistant to write where the decoy should live; binary files (xlsx, docx, zip, png, exe) come back as a download URL that expires after about five minutes.

create_tripwire returns the same trigger in its response, so a fresh decoy can be planted straight away.

Protocol support

The server speaks MCP revisions 2025-06-18, 2025-03-26 and 2024-11-05, and answers initialize with the client's own revision when it is one of those. On 2025-03-26 and later every tool carries annotations: reads are marked readOnlyHint, and delete_tripwire and reset_tripwire are marked destructiveHint, so a client can auto-approve lookups and still stop to ask before evidence is removed. On 2025-06-18 results also carry structuredContent alongside the text.

Security

  • The key is you. Store it in your client's secret store, never in shared config, and scope it to the minimum the assistant needs. Pass it in the environment, not as --api-key, which any local user can read from the process list.
  • Artifact downloads use the short-lived presigned URL alone; your API key is never sent to the object store.
  • Destructive tools — delete_tripwire, and reset_tripwire with purge — permanently remove evidence. Both carry the MCP destructiveHint annotation, so clients that honour it ask first. Review the model's proposed calls before approving them, withhold tripwire:delete entirely, or run the server read-only.
  • Nothing here is installation-wide: administering the platform is a separate surface, deliberately not exposed through MCP.
  • Revoke a key at any time under Settings → API Keys; the server has no other way in.

See also: the developer CLI.