Back to Browse

Spanning MCP Server

Developer ToolsModerate6.8MCP RegistryLocal
Free

Server data from the Official MCP Registry

MCP server for Spanning Cloud Backup — M365/GWS/Salesforce backups, restores, audit.

About

MCP server for Spanning Cloud Backup — M365/GWS/Salesforce backups, restores, audit.

Security Report

6.8
Moderate6.8Moderate Risk

This MCP server for Spanning Cloud Backup demonstrates good security practices with proper authentication, reasonable permissions scoped to its purpose, and clean code structure. The server properly handles credentials via environment variables and HTTP headers in gateway mode, implements input validation for destructive operations (restore requires confirmation), and uses standard MCP SDK patterns. Minor code quality observations exist but do not constitute security vulnerabilities. Supply chain analysis found 1 known vulnerability in dependencies (0 critical, 1 high severity).

3 files analyzed · 4 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

What You'll Need

Set these up before or after installing:

Platform: 'm365', 'gws', or 'salesforce'Optional

Environment variable: SPANNING_PLATFORM

Spanning admin account emailOptional

Environment variable: SPANNING_ADMIN_EMAIL

Spanning API tokenRequired

Environment variable: SPANNING_API_TOKEN

Transport mode for the server. Set to 'stdio' for local CLI use; the image defaults to 'http' for gateway hosting.Optional

Environment variable: MCP_TRANSPORT

Credential source: 'env' reads vars locally, 'gateway' expects header injection from the WYRE MCP Gateway.Optional

Environment variable: AUTH_MODE

Log verbosity: debug, info, warn, errorOptional

Environment variable: LOG_LEVEL

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-wyre-technology-spanning-mcp": {
      "env": {
        "AUTH_MODE": "your-auth-mode-here",
        "LOG_LEVEL": "your-log-level-here",
        "MCP_TRANSPORT": "your-mcp-transport-here",
        "SPANNING_PLATFORM": "your-spanning-platform-here",
        "SPANNING_API_TOKEN": "your-spanning-api-token-here",
        "SPANNING_ADMIN_EMAIL": "your-spanning-admin-email-here"
      },
      "args": [
        "-y",
        "@wyre-technology/spanning-mcp"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

Spanning Cloud Backup MCP Server

CI License: Apache 2.0

A Model Context Protocol server exposing the Spanning Cloud Backup API to Claude and other MCP clients.

What it does

Surface SaaS backup posture for your M365, Google Workspace, or Salesforce tenants directly to AI assistants — list backed-up users, inspect covered services, browse backup history, queue restores, and audit admin activity and license usage.

  • Interactive backup status card (MCP Apps, SEP-1865): spanning_get_user renders as a read-only interactive card in MCP Apps hosts (Claude Desktop/web) showing the user's backup status, license state, last backup, and per-service coverage; neutral by default, brandable via window.__BRAND__ injection or MCP_BRAND_* env vars (MCP_BRAND_NAME, MCP_BRAND_LOGO_URL, MCP_BRAND_PRIMARY_COLOR, MCP_BRAND_ACCENT_COLOR, MCP_BRAND_BG, MCP_BRAND_TEXT). Plain-JSON behavior is unchanged in other hosts. Rebuild the embedded card with npm run build:ui after editing ui/.

Tools

ToolPurpose
spanning_list_usersList backed-up users in the org
spanning_get_userFetch a single user's detail
spanning_list_servicesList services covered for a user
spanning_list_backupsList backup runs for a user + service
spanning_queue_restoreQueue a restore (DESTRUCTIVE — requires confirmation)
spanning_get_restore_statusCheck restore progress
spanning_list_audit_logAdmin audit log (date-range elicitation)
spanning_get_license_usageSeats used vs purchased
spanning_statusServer status / health

Credentials

Local (env mode)

export SPANNING_PLATFORM="m365"        # or "gws" or "salesforce"
export SPANNING_ADMIN_EMAIL="..."
export SPANNING_API_TOKEN="..."

Hosted (gateway mode)

The WYRE MCP Gateway injects credentials per request via headers:

  • X-Spanning-Platform (required, one of m365 | gws | salesforce)
  • X-Spanning-Admin-Email (required)
  • X-Spanning-API-Token (required, secret)

Run

npm install
npm run build
npm start                       # stdio
MCP_TRANSPORT=http npm start    # HTTP on :8080

License

Apache 2.0 — see LICENSE.

Reviews

No reviews yet

Be the first to review this server!