MCP Server
tripwire-mcp is a Model Context Protocol
server that lets MCP-capable clients such as Claude Desktop and Claude Code work with your tripwires.
Ask Claude to "put a postgres decoy in the prod namespace", "which tripwires have been touched
this week?" or "renew everything expiring in the next month", and it does it through the same
API the web app uses.
It speaks JSON-RPC 2.0 over stdio, so it works identically against the SaaS API
(https://api.gettripwires.com) and a self-hosted control server. The binary depends only on
the Go standard library — no third-party dependencies.
What it can see
The server has no privileges of its own. Every call carries your credential and your active organization, and the API applies exactly the permissions it applies in the browser:
- Only organizations you are a member of. Tripwires belonging to anyone else's organization are neither listed nor addressable — asking for one by ID reports it as not found.
- Only namespaces you have been granted. A namespace you cannot see behaves as though it does not exist.
- Your role decides what you may change:
vieweris read-only;memberand above can create, update and delete. - Nothing installation-wide. Platform users, settings, billing and system health are not reachable from here.
Install
Download tripwire-mcp from the
releases page
(published alongside the CLI for Linux, macOS and Windows), or build from source:
go build -o tripwire-mcp ./cmd/mcp
Authenticate
The server takes a bearer credential: a scoped API key (tw_…) or a session JWT. Mint a key
under Settings → API Keys, or with tripwire keys create. It needs:
| Scope | Needed for |
|---|---|
org:read | list_orgs, list_org_members, whoami — how the server discovers which organizations you belong to |
tripwire:read | Listing tripwires, reading one, fetching its artifact, detections, analytics |
tripwire:create | create_tripwire |
tripwire:update | update_tripwire, renew_tripwire, reset_tripwire |
tripwire:delete | delete_tripwire |
Grant only what you want the assistant to be able to do — leaving
tripwire:delete off is a cheap way to make sure it cannot remove anything.
Configuration comes from flags or environment variables (flags win):
| Flag | Environment | Meaning |
|---|---|---|
--endpoint | TRIPWIRE_ENDPOINT | API base URL |
--api-key | TRIPWIRE_API_KEY | API key or JWT. Use the environment variable — see below. |
--org | TRIPWIRE_ORG | Default organization ID (org_…). Individual tools can override it. |
--read-only | TRIPWIRE_MCP_READ_ONLY=true | Offer only tools that cannot change anything. See Read-only mode. |
Pass the key through TRIPWIRE_API_KEY, not --api-key. Command-line arguments are
readable by every local user in the process list (ps, /proc/<pid>/cmdline) for as
long as the server runs; its environment is not. The flag exists for one-off testing.
--org takes the organization's ID, not its name. Find it with
tripwire orgs list, or leave it out and ask the assistant to list your organizations first.
Configure your client
Claude Desktop / generic MCP host config:
{
"mcpServers": {
"tripwire": {
"command": "tripwire-mcp",
"env": {
"TRIPWIRE_ENDPOINT": "https://api.gettripwires.com",
"TRIPWIRE_API_KEY": "tw_your_api_key",
"TRIPWIRE_ORG": "org_your_organization_id"
}
}
}
}
Claude Code — --env writes the same env block, so the key never appears on a command line:
claude mcp add \
--env TRIPWIRE_ENDPOINT=https://api.gettripwires.com \
--env TRIPWIRE_API_KEY=tw_your_api_key \
--env TRIPWIRE_ORG=org_your_organization_id \
tripwire -- tripwire-mcp
A stdio MCP server does not inherit your shell
Exporting TRIPWIRE_API_KEY in .bashrc is not enough on its own — the value has
to be in the env block. Claude Code expands ${VAR} inside its
config, which lets you keep the key out of the file:
"env": { "TRIPWIRE_API_KEY": "${TRIPWIRE_API_KEY}" }
Self-hosted installations point the endpoint at your control server, e.g.
https://tripwire.internal.example.com. Settings → MCP Server
in the app generates both snippets with this installation's endpoint and your organization filled in.
Read-only mode
Start the server with --read-only (or TRIPWIRE_MCP_READ_ONLY=true in its
env block) and it offers only the tools that cannot change anything: create_tripwire,
update_tripwire, renew_tripwire, reset_tripwire and delete_tripwire
disappear from the tool list, and a client that calls one anyway is refused before any request leaves your machine.
Use it for an assistant that should investigate detections but never touch the estate.
It is a client-side guard. The hard boundary is still the key: a key minted with only tripwire:read
and org:read cannot write no matter how the server is started. Use both.
Tools
Every tool takes an optional org_id, so one session can work across
several of your organizations without restarting the server.
| Tool | Action |
|---|---|
list_orgs | The organizations you belong to, and your role in each |
list_org_members | Members of one of your organizations, with roles and namespace grants |
whoami | The identity behind the configured credential |
create_tripwire | Create a decoy: name, technology, optional namespace, tags and lease |
list_tripwires | List your tripwires, with search, technology/status/tag filters, sort and paging |
get_tripwire | One tripwire: configuration, status, recent detections, and its trigger when that is a value (see below) |
get_tripwire_artifact | The trigger file of a file-based tripwire: a fresh download URL, and the content itself for text files up to 256 KiB |
update_tripwire | Change name, destination, namespace, tags or expiry |
renew_tripwire | Extend the lease by a duration (e.g. 720h) |
reset_tripwire | Re-baseline the trip count; optionally purge the detection records |
delete_tripwire | Delete a tripwire and its detections |
list_detections | Detections recorded against one tripwire: source IP, time, captured context |
list_org_detections | The org-wide detections feed — every trip across the organization, filterable by time window, tripwire, protocol and source IP (“what fired in the last hour?”) |
analytics | Summary of activity across your estate. Self-hosted installations only — on SaaS it says so rather than failing obscurely |
create_tripwire’s technology argument is an enum of exactly the
technologies the dashboard offers (38 today, from postgresql and ssh to
docx, qr_code and aws_session); the transport type is derived from it.
See the technology reference
for the full list and what each returns. Not-yet-supported values such as gcp and
azure are rejected before any API call.
Getting a tripwire's trigger
A tripwire is only useful once its trigger is planted somewhere. Where that trigger comes from depends on the type:
| Type | Where the trigger is |
|---|---|
| Protocol honeypots (PostgreSQL, MySQL, Redis, …) | get_tripwire → connection (host, port, credentials, connection string) |
| Cloud credentials | get_tripwire → aws_credentials |
| Web, redirect, DNS and SAML tokens | get_tripwire → tracking_url, hostname or acs_url / entity_id |
| Files (documents, scripts, kubeconfig, WireGuard, SQL dumps, QR codes, …) | get_tripwire reports has_artifact: true; get_tripwire_artifact returns the file. Text files come back inline, ready for the assistant to write where the decoy should live; binary files (xlsx, docx, zip, png, exe) come back as a download URL that expires after about five minutes. |
create_tripwire returns the same trigger in its response, so a fresh decoy can be planted straight away.
Protocol support
The server speaks MCP revisions 2025-06-18, 2025-03-26 and 2024-11-05, and
answers initialize with the client's own revision when it is one of those. On 2025-03-26 and
later every tool carries annotations:
reads are marked readOnlyHint, and delete_tripwire and reset_tripwire are marked
destructiveHint, so a client can auto-approve lookups and still stop to ask before evidence is removed.
On 2025-06-18 results also carry structuredContent alongside the text.
Security
- The key is you. Store it in your client's secret store, never in shared config, and scope it to the minimum the assistant needs. Pass it in the environment, not as
--api-key, which any local user can read from the process list. - Artifact downloads use the short-lived presigned URL alone; your API key is never sent to the object store.
- Destructive tools —
delete_tripwire, andreset_tripwirewithpurge— permanently remove evidence. Both carry the MCPdestructiveHintannotation, so clients that honour it ask first. Review the model's proposed calls before approving them, withholdtripwire:deleteentirely, or run the server read-only. - Nothing here is installation-wide: administering the platform is a separate surface, deliberately not exposed through MCP.
- Revoke a key at any time under Settings → API Keys; the server has no other way in.
See also: the developer CLI.