Back to Browse

Datto Saas Protection MCP Server

Developer ToolsLow Risk10.0MCP RegistryLocal
Free

Server data from the Official MCP Registry

MCP server for Datto SaaS Protection — customers, seats, backup status, bulk seat licensing.

About

MCP server for Datto SaaS Protection — customers, seats, backup status, bulk seat licensing.

Security Report

10.0
Low Risk10.0Low Risk

Valid MCP server (4 strong, 3 medium validity signals). No known CVEs in dependencies. Imported from the Official MCP Registry. Trust signals: trusted author (83/85 approved).

6 files analyzed · No issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

file_system

Check that this permission is expected for this type of plugin.

Shell Command Execution

Runs commands on your machine. Be cautious — only use if you trust this plugin.

What You'll Need

Set these up before or after installing:

Datto REST API public key (Partner Portal > Admin > Integrations > API Keys)Required

Environment variable: DATTO_SAAS_PUBLIC_KEY

Datto REST API secret keyRequired

Environment variable: DATTO_SAAS_SECRET_KEY

Transport mode for the server. Set to 'stdio' for local CLI use; the image defaults to 'http' for gateway hosting.Optional

Environment variable: MCP_TRANSPORT

Credential source: 'env' reads vars locally, 'gateway' expects header injection from the WYRE MCP Gateway.Optional

Environment variable: AUTH_MODE

Log verbosity: debug, info, warn, errorOptional

Environment variable: LOG_LEVEL

Documentation

View on GitHub

From the project's GitHub README.

Datto SaaS Protection MCP Server

CI License: Apache 2.0

A Model Context Protocol server exposing the Datto SaaS Protection (Backupify) API to Claude and other MCP clients.

What it does

Surfaces SaaS backup posture for your Microsoft 365 and Google Workspace customers to AI assistants, using the documented Datto REST API (https://api.datto.com/v1/saas/...): list protected customers/domains, inspect seats and their protection state, review backup status per application, and (with confirmation) license, pause or unlicense seats in bulk.

  • Interactive Seat Card (MCP Apps): datto_saas_get_seat renders as an interactive card in MCP Apps hosts (Claude Desktop/web) — read-only, showing seat type and Datto seat state; neutral by default, brandable via window.__BRAND__ injection or MCP_BRAND_* env vars; plain-JSON behavior is unchanged in other hosts

Tools

ToolDatto endpointAnnotations
datto_saas_list_domainsGET /v1/saas/domainsread-only
datto_saas_list_seatsGET /v1/saas/{saasCustomerId}/seatsread-only
datto_saas_get_seatGET /v1/saas/{saasCustomerId}/seats (filtered to one seat)read-only
datto_saas_list_applicationsGET /v1/saas/{saasCustomerId}/applicationsread-only
datto_saas_get_backup_statsGET /v1/saas/{saasCustomerId}/detailedBackupStatsread-only
datto_saas_bulk_seat_changePUT /v1/saas/{saasCustomerId}/{externalSubscriptionId}/bulkSeatChangewrite, destructive (asks for confirmation)

Start with datto_saas_list_domains: it returns the saasCustomerId and externalSubscriptionId every other tool needs.

Earlier versions exposed list_clients, list_backups, queue_restore, get_restore_status, list_activity and get_license_usage. Those were built on routes Datto does not serve (/v1/saas/clients, /restores, …) and always returned 404, so they are removed.

Credentials

Create an API key in the Datto Partner Portal (Admin > Integrations > API Keys). The API uses HTTP Basic auth with the public/secret key pair. There is a single API host (api.datto.com); there is no regional (EU) API host.

Local (env mode)

export DATTO_SAAS_PUBLIC_KEY="..."
export DATTO_SAAS_SECRET_KEY="..."

Hosted (gateway mode)

The WYRE MCP Gateway injects credentials per request via headers:

  • X-Datto-SaaS-Public-Key (required, secret)
  • X-Datto-SaaS-Secret-Key (required, secret)
  • X-Datto-SaaS-Region (accepted for backward compatibility; ignored)

Run

npm install
npm run build
npm start                       # stdio
MCP_TRANSPORT=http npm start    # HTTP on :8080

License

Apache 2.0 — see LICENSE.

Reviews

No reviews yet

Be the first to review this server!