MCP Server
The Anantis MCP HTTP server exposes your threats, interactions, decoys, canaries, and reports to any client that speaks the Model Context Protocol.
Connection details
Section titled “Connection details”| Endpoint | https://api.anantis.io/mcp |
| Transport | Streamable HTTP |
| Authentication | Authorization: Bearer <api-key> |
| OAuth | Not supported |
Prerequisites
Section titled “Prerequisites”An Anantis API key, create it here. The MCP server uses the same key as the REST API.
Configuration
Section titled “Configuration”Replace YOUR_KEY with your API key throughout.
Add the server from the terminal:
claude mcp add --transport http anantis https://api.anantis.io/mcp \ --header "Authorization: Bearer YOUR_KEY"By default the server is added for the current project only. Use --scope user to make it available across all your projects:
claude mcp add --scope user --transport http anantis https://api.anantis.io/mcp \ --header "Authorization: Bearer YOUR_KEY"Verify with claude mcp list: the server should report ✔ Connected.
Install link: Add Anantis MCP to Cursor
OR
Configuration file:
Create .cursor/mcp.json in your project, or ~/.cursor/mcp.json to enable it globally:
{ "mcpServers": { "anantis": { "url": "https://api.anantis.io/mcp", "headers": { "Authorization": "Bearer YOUR_KEY" } } }}Install link: VS Code · VS Code Insiders
OR
Configuration file:
Create .vscode/mcp.json. VS Code prompts for the key on first use and stores it securely, so nothing secret is written to the file:
{ "inputs": [ { "type": "promptString", "id": "anantis-api-key", "description": "Anantis API key", "password": true } ], "servers": { "anantis": { "type": "http", "url": "https://api.anantis.io/mcp", "headers": { "Authorization": "Bearer ${input:anantis-api-key}" } } }}Edit ~/.codeium/windsurf/mcp_config.json:
{ "mcpServers": { "anantis": { "serverUrl": "https://api.anantis.io/mcp", "headers": { "Authorization": "Bearer YOUR_KEY" } } }}Most MCP clients accept the same three values:
| Setting | Value |
|---|---|
| Transport | Streamable HTTP (streamable-http, sometimes written http) |
| URL | https://api.anantis.io/mcp |
| Header | Authorization: Bearer <api-key> |
Available tools
Section titled “Available tools”The MCP server is read-only: no tool writes to the platform. Each tool requires the scope listed below, so a tool whose scope the key lacks simply fails when called.
| Tool | Purpose | Scope |
|---|---|---|
whoami | Inspect the connected key: entity, scopes, accessible organizations. | none |
list_threats | List threats, aggregated by source IP. | threats:read |
get_threat | Retrieve a single threat. | threats:read |
list_interactions | List events captured by decoys, most recent first. | interactions:read |
get_interaction | Retrieve a single interaction. | interactions:read |
list_decoys | List deployed decoys. | decoys:read |
get_decoy | Retrieve one decoy’s metadata. | decoys:read |
list_canaries | List deployed canaries. | canaries:read |
get_canary | Retrieve one canary’s metadata. | canaries:read |
get_report | Generate the executive report for a period. | reports:read |
list_users | List console users. | users:read |
get_user | Retrieve a single console user. | users:read |
Verify the connection
Section titled “Verify the connection”Ask your client a question that exercises the server. A good first prompt is:
Using the Anantis MCP server, call whoami and tell me which organizations this key can reach.
A successful response echoes your entity_uuid and the scopes you granted.

