Back to Browse

Ironscales MCP Server

Developer ToolsLow Risk9.8MCP RegistryLocal
Free

Server data from the Official MCP Registry

MCP server for Ironscales phishing incident management — incidents, mailboxes, and reporting.

About

MCP server for Ironscales phishing incident management — incidents, mailboxes, and reporting.

Security Report

9.8
Low Risk9.8Low Risk

Valid MCP server (2 strong, 1 medium validity signals). 1 known CVE in dependencies Imported from the Official MCP Registry.

4 files analyzed · 1 issue found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

env_vars

Check that this permission is expected for this type of plugin.

HTTP Network Access

Connects to external APIs or services over the internet.

What You'll Need

Set these up before or after installing:

Ironscales API keyRequired

Environment variable: IRONSCALES_API_KEY

Ironscales company (tenant) identifierOptional

Environment variable: IRONSCALES_COMPANY_ID

Transport mode for the server. Set to 'stdio' for local CLI use; the image defaults to 'http' for gateway hosting.Optional

Environment variable: MCP_TRANSPORT

Credential source: 'env' reads vars locally, 'gateway' expects header injection from the WYRE MCP Gateway.Optional

Environment variable: AUTH_MODE

Log verbosity: debug, info, warn, errorOptional

Environment variable: LOG_LEVEL

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-wyre-technology-ironscales-mcp": {
      "env": {
        "AUTH_MODE": "your-auth-mode-here",
        "LOG_LEVEL": "your-log-level-here",
        "MCP_TRANSPORT": "your-mcp-transport-here",
        "IRONSCALES_API_KEY": "your-ironscales-api-key-here",
        "IRONSCALES_COMPANY_ID": "your-ironscales-company-id-here"
      },
      "args": [
        "-y",
        "@wyre-technology/ironscales-mcp"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

Ironscales MCP Server

License Node.js

A Model Context Protocol (MCP) server for Ironscales email security. Enables AI assistants to investigate phishing incidents, manage email classification, execute remediations, and view security statistics.

This is a Model Context Protocol (MCP) server that connects Claude (or any MCP-compatible AI) to your Ironscales environment.

Part of the MSP Claude Plugins ecosystem — a growing suite of AI integrations for the MSP stack. Built by MSPs, for MSPs.

Interactive Incident Card (MCP Apps)

ironscales_incidents_get renders as an interactive card in MCP Apps hosts (Claude Desktop/web) showing the phishing incident's subject, status, severity, sender, affected recipients, and threat indicators; plain-JSON behavior is unchanged in other hosts. The card is read-only — remediation stays with the model-driven remediation tools. It is neutral by default and brandable via window.__BRAND__ injection or MCP_BRAND_* env vars (MCP_BRAND_NAME, MCP_BRAND_LOGO_URL, MCP_BRAND_PRIMARY_COLOR, MCP_BRAND_ACCENT_COLOR, MCP_BRAND_BG, MCP_BRAND_TEXT) — no rebuild needed.

Installation

npm install @wyre-technology/ironscales-mcp

Configuration

Set the following environment variables:

VariableRequiredDescription
IRONSCALES_API_KEYYesYour Ironscales API key
IRONSCALES_COMPANY_IDYesYour Ironscales company ID
MCP_TRANSPORTNoTransport mode: stdio (default) or http

Usage

Running with Claude Desktop

Add to your Claude Desktop claude_desktop_config.json:

{
  "mcpServers": {
    "ironscales-mcp": {
      "command": "npx",
      "args": ["@wyre-technology/ironscales-mcp"],
      "env": {
        "IRONSCALES_API_KEY": "your-ironscales-api-key"
        "IRONSCALES_COMPANY_ID": "your-ironscales-company-id"
      }
    }
  }
}

Running with Claude Code (CLI)

claude mcp add ironscales-mcp \
  -e IRONSCALES_API_KEY=your-value \
  -e IRONSCALES_COMPANY_ID=your-value \
  -- npx -y @wyre-technology/ironscales-mcp

Docker

docker build -t ironscales-mcp .
docker run \
  -e IRONSCALES_API_KEY=your-value \
  -e IRONSCALES_COMPANY_ID=your-value \
  -p 8080:8080 ironscales-mcp

Available Domains

Allowlist

Manage email allowlists and blocklists

Email

Email investigation and classification

Incidents

Phishing incident management and triage

Remediation

Execute email remediations and quarantine

Stats

Security statistics and reporting

Development

# Clone the repository
git clone https://github.com/wyre-technology/ironscales-mcp.git
cd ironscales-mcp

# Install dependencies
npm install

# Build
npm run build

# Run tests
npm test

Contributing

Contributions are welcome! Please see CONTRIBUTING.md if present, or open an issue to discuss changes.

License

Licensed under the Apache License, Version 2.0. See LICENSE for details.

Reviews

No reviews yet

Be the first to review this server!

Ironscales MCP Server - MCP server for Ironscales phishing incident management — | MCP Marketplace