Back to Browse

Datto Rmm MCP Server

Developer ToolsUse Caution4.8MCP RegistryLocal
Free

Server data from the Official MCP Registry

MCP server for Datto RMM — devices, alerts, sites, jobs, and audit data.

About

MCP server for Datto RMM — devices, alerts, sites, jobs, and audit data.

Security Report

4.8
Use Caution4.8High Risk

This MCP server demonstrates good security practices with proper authentication via environment variables, no hardcoded secrets, and appropriate use of external dependencies. The codebase shows clean patterns with TypeScript type safety. One minor concern is the reliance on GitHub Packages requiring a token for npm install, but this is well-documented and handled properly in deployment paths. The server's permissions align with its purpose of managing Datto RMM devices remotely. Supply chain analysis found 5 known vulnerabilities in dependencies (0 critical, 2 high severity).

3 files analyzed · 8 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

env_vars

Check that this permission is expected for this type of plugin.

HTTP Network Access

Connects to external APIs or services over the internet.

What You'll Need

Set these up before or after installing:

Datto RMM API keyRequired

Environment variable: DATTO_API_KEY

Datto RMM API secret keyRequired

Environment variable: DATTO_API_SECRET

Datto RMM API platform/zone: pinotage, merlot, concord, vidal, zinfandel, or syrahOptional

Environment variable: DATTO_PLATFORM

Transport mode for the server. Set to 'stdio' for local CLI use; the image defaults to 'http' for gateway hosting.Optional

Environment variable: MCP_TRANSPORT

Credential source: 'env' reads vars locally, 'gateway' expects header injection from the WYRE MCP Gateway.Optional

Environment variable: AUTH_MODE

Log verbosity: debug, info, warn, errorOptional

Environment variable: LOG_LEVEL

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-wyre-ai-datto-rmm-mcp": {
      "env": {
        "AUTH_MODE": "your-auth-mode-here",
        "LOG_LEVEL": "your-log-level-here",
        "DATTO_API_KEY": "your-datto-api-key-here",
        "MCP_TRANSPORT": "your-mcp-transport-here",
        "DATTO_PLATFORM": "your-datto-platform-here",
        "DATTO_API_SECRET": "your-datto-api-secret-here"
      },
      "args": [
        "-y",
        "@wyre-ai/datto-rmm-mcp"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

Datto RMM MCP Server

MCP server for Datto RMM, enabling Claude to interact with your Datto RMM account.

One-Click Deployment

[!IMPORTANT] Before you click: this server depends on @wyre-technology/node-datto-rmm, which is hosted on the GitHub Packages npm registry. GitHub Packages has no anonymous access — even though the package is public, every npm install needs a token. The cloud builder runs npm install for you, so you must give it one, or the build fails with npm error 401 Unauthorized ... npm.pkg.github.com.

  1. Create a GitHub Personal Access Token with the read:packages scope (classic token). Any GitHub account works — you do not need to be a member of the wyre-technology org to read its public packages.
  2. Add it as a build variable when prompted by the deploy flow:
    • Cloudflare Workers → set a build variable named NODE_AUTH_TOKEN to your PAT (Workers → Settings → Build → Variables and Secrets).
    • DigitalOcean App Platform → set an encrypted env var named GITHUB_TOKEN with scope Build Time to your PAT (the .do/deploy.template.yaml already declares it).

Deploy to DO

Deploy to Cloudflare Workers

[!NOTE] The DigitalOcean target builds the full Docker image and runs the complete MCP server over HTTP — this is the recommended path for operators. This repo has no Cloudflare Workers entrypoint (src/worker.ts), so the Workers button is not a supported target yet; prefer DigitalOcean or the prebuilt container image (ghcr.io/wyre-ai/datto-rmm-mcp).

Features

  • Device Management: List, search, and get details for devices
  • Alert Management: View and resolve alerts
  • Interactive Alert Card (MCP Apps): datto_get_alert renders as an interactive card in MCP Apps hosts (Claude Desktop/web) with an in-card "Resolve alert" round-trip; neutral by default, brandable via window.__BRAND__ injection or MCP_BRAND_* env vars; plain-JSON behavior is unchanged in other hosts
  • Site Management: List and view site details
  • Quick Jobs: Run quick jobs on devices
  • Audit Data: Retrieve full device audit or software inventory

Installation

Via MCP Gateway (Recommended)

This server is designed to work with the MCP Gateway which handles authentication and credential management.

Local Development

This server's @wyre-technology/* dependencies live on the GitHub Packages npm registry, which requires a token even for public packages. Authenticate once, then install:

# Authenticate npm to GitHub Packages (token needs the read:packages scope)
export NODE_AUTH_TOKEN=$(gh auth token)   # or a PAT with read:packages

npm install
npm run build
npm start

The repo's .npmrc already points the @wyre-technology scope at GitHub Packages and reads the token from NODE_AUTH_TOKEN, so no further config is needed.

Configuration

The server accepts credentials via environment variables:

VariableDescription
DATTO_API_KEYYour Datto RMM API key
DATTO_API_SECRETYour Datto RMM API secret
DATTO_PLATFORMAPI platform: pinotage, merlot, concord, vidal, zinfandel, or syrah (default: concord)

When used with the MCP Gateway, credentials are injected via X_API_KEY and X_API_SECRET environment variables.

Platform Selection

Datto RMM uses regional API endpoints. Select the platform that matches your account:

PlatformRegion/Description
pinotageSouth Africa
merlotEurope
concordUS East (default)
vidalCanada
zinfandelUS West
syrahAustralia

Available Tools

ToolDescription
datto_list_devicesList devices with optional site filter
datto_find_deviceFind a device by hostname (exact or partial match) and resolve its UID
datto_get_deviceGet device details by UID
datto_list_alertsList open alerts with optional site filter
datto_get_alertGet alert details by UID (renders as an interactive card in MCP Apps hosts)
datto_resolve_alertResolve an alert
datto_list_sitesList all sites
datto_get_siteGet site details
datto_run_quickjobRun a quick job on a device
datto_get_device_auditGet device audit data (full or software only)

Docker

Use the prebuilt image (no build, no token)

docker pull ghcr.io/wyre-ai/datto-rmm-mcp:latest

docker run -p 8080:8080 \
  -e DATTO_API_KEY=xxx \
  -e DATTO_API_SECRET=xxx \
  -e DATTO_PLATFORM=concord \
  ghcr.io/wyre-ai/datto-rmm-mcp:latest

The image is public and pulls anonymously, so this path needs no GitHub token at all.

Build from source

The build installs @wyre-technology/node-datto-rmm from GitHub Packages, which requires a token even though the package is public (see One-Click Deployment). The Dockerfile takes it as the GITHUB_TOKEN build arg — omit it and the build fails at npm ci with npm error 401 Unauthorized ... npm.pkg.github.com:

docker build --build-arg GITHUB_TOKEN=$(gh auth token) -t datto-rmm-mcp .

docker run -p 8080:8080 \
  -e DATTO_API_KEY=xxx \
  -e DATTO_API_SECRET=xxx \
  -e DATTO_PLATFORM=concord \
  datto-rmm-mcp

The token is written to a temporary .npmrc that is deleted in the same layer, so it is never baked into the image.

[!NOTE] The image defaults to MCP_TRANSPORT=http on port 8080, so -p 8080:8080 is required to reach it. Health check: curl http://localhost:8080/health.

License

Apache-2.0

Reviews

No reviews yet

Be the first to review this server!