Back to Browse

Kaseya Vsa MCP Server

Developer ToolsModerate6.2MCP RegistryLocal
Free

Server data from the Official MCP Registry

MCP server for Kaseya VSA RMM — agents, patches, procedures, alarms, tickets.

About

MCP server for Kaseya VSA RMM — agents, patches, procedures, alarms, tickets.

Security Report

6.2
Moderate6.2Moderate Risk

The Kaseya VSA MCP server is a well-structured RMM integration tool with proper authentication and appropriate permission scoping for its purpose. Authentication is required and correctly handled through environment variables or gateway headers. The embedded UI bundle and dependency management are sound. Minor code quality issues around error handling and input validation do not substantially impact security. Supply chain analysis found 1 known vulnerability in dependencies (0 critical, 1 high severity).

3 files analyzed · 5 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

env_vars

Check that this permission is expected for this type of plugin.

HTTP Network Access

Connects to external APIs or services over the internet.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

File System Write

Writes or modifies files on your machine. Check that this is expected for the tool.

What You'll Need

Set these up before or after installing:

Full base URL including /api/v1.0 (e.g. https://vsa.example.com/api/v1.0)Optional

Environment variable: KASEYA_VSA_TENANT_URL

Local-auth username (omit if using Kaseya One token)Optional

Environment variable: KASEYA_VSA_USERNAME

Local-auth password (omit if using Kaseya One token)Required

Environment variable: KASEYA_VSA_PASSWORD

Kaseya One SSO token (alternative to username + password)Required

Environment variable: KASEYA_VSA_K1_TOKEN

Transport mode for the server. Set to 'stdio' for local CLI use; the image defaults to 'http' for gateway hosting.Optional

Environment variable: MCP_TRANSPORT

Credential source: 'env' reads vars locally, 'gateway' expects header injection from the WYRE MCP Gateway.Optional

Environment variable: AUTH_MODE

Log verbosity: debug, info, warn, errorOptional

Environment variable: LOG_LEVEL

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-wyre-technology-kaseya-vsa-mcp": {
      "env": {
        "AUTH_MODE": "your-auth-mode-here",
        "LOG_LEVEL": "your-log-level-here",
        "MCP_TRANSPORT": "your-mcp-transport-here",
        "KASEYA_VSA_K1_TOKEN": "your-kaseya-vsa-k1-token-here",
        "KASEYA_VSA_PASSWORD": "your-kaseya-vsa-password-here",
        "KASEYA_VSA_USERNAME": "your-kaseya-vsa-username-here",
        "KASEYA_VSA_TENANT_URL": "your-kaseya-vsa-tenant-url-here"
      },
      "args": [
        "-y",
        "@wyre-technology/kaseya-vsa-mcp"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

Kaseya VSA MCP Server

Release License: Apache 2.0

Model Context Protocol (MCP) server for the Kaseya VSA RMM API. Exposes managed endpoints, software / hardware inventory, patch state, agent procedures, alarms, Service Desk tickets, organizations, and machine groups to AI assistants.

Tools

ToolDescription
kaseya_vsa_list_agentsList managed endpoints (agents). Optional $filter.
kaseya_vsa_get_agentGet an agent's details by ID (renders as an interactive card in MCP Apps hosts).
kaseya_vsa_get_software_inventoryInstalled software for an agent.
kaseya_vsa_get_hardware_inventoryHardware audit for an agent.
kaseya_vsa_get_patch_statusPending and installed patches for an agent.
kaseya_vsa_deploy_patches_nowForce a patch deploy on an agent (destructive — confirmation required).
kaseya_vsa_list_proceduresAgent procedures available to run.
kaseya_vsa_run_procedureExecute a procedure on an agent (destructive — confirmation required).
kaseya_vsa_list_alarmsOpen alarms (optional state filter; date-window elicitation if missing).
kaseya_vsa_list_ticketsService Desk tickets (returns a friendly message if SD module isn't enabled).
kaseya_vsa_list_organizationsTenant organizations.
kaseya_vsa_list_machine_groupsMachine group hierarchy.

When the user omits required filters or runs a destructive action, the server uses MCP elicitation to prompt for choices or confirm.

Interactive device card (MCP Apps)

kaseya_vsa_get_agent renders as a read-only interactive device card in MCP Apps hosts (Claude Desktop/web), showing the endpoint's name, online status, organization, machine group, OS, IP address, and last check-in. The card is neutral by default, brandable via window.__BRAND__ injection or MCP_BRAND_* env vars (MCP_BRAND_NAME, MCP_BRAND_LOGO_URL, MCP_BRAND_PRIMARY_COLOR, MCP_BRAND_ACCENT_COLOR, MCP_BRAND_BG, MCP_BRAND_TEXT) applied at serve time. Plain-JSON behavior is unchanged in other hosts. After editing ui/, regenerate the embedded bundle with npm run build:ui.

Configuration

Environment-variable mode (default)

VariableRequiredDescription
KASEYA_VSA_TENANT_URLyesFull base URL incl. /api/v1.0
KASEYA_VSA_USERNAMEone ofLocal-auth username
KASEYA_VSA_PASSWORDone ofLocal-auth password (secret)
KASEYA_VSA_K1_TOKENone ofKaseya One SSO token (alternative to username + password)
MCP_TRANSPORTnostdio (default) or http
MCP_HTTP_PORTnoHTTP listen port (default 8080)
AUTH_MODEnoenv (default) or gateway

Either the username + password pair OR the KASEYA_VSA_K1_TOKEN is required.

Gateway mode

When deployed behind the WYRE MCP Gateway, set AUTH_MODE=gateway and the server will read credentials from per-request HTTP headers:

  • X-Kaseya-VSA-Tenant-Url (required)
  • X-Kaseya-VSA-Username (with password)
  • X-Kaseya-VSA-Password (with username)
  • X-Kaseya-VSA-K1-Token (alternative to username + password)

Each request creates a fresh server instance with isolated credentials — no cross-tenant process.env pollution.

Local development

npm install
npm run build
KASEYA_VSA_TENANT_URL=https://vsa.example.com/api/v1.0 \
  KASEYA_VSA_USERNAME=... \
  KASEYA_VSA_PASSWORD=... \
  npm start

Run as HTTP for testing:

MCP_TRANSPORT=http npm start
curl http://localhost:8080/health

Docker

docker build -t kaseya-vsa-mcp .
docker run --rm -p 8080:8080 \
  -e KASEYA_VSA_TENANT_URL=https://vsa.example.com/api/v1.0 \
  -e KASEYA_VSA_USERNAME=... \
  -e KASEYA_VSA_PASSWORD=... \
  kaseya-vsa-mcp

License

Apache-2.0

Reviews

No reviews yet

Be the first to review this server!