Developer · Local MCP server
Proofpoint
MCP server for Proofpoint TAP — threat intelligence, forensics, quarantine, and email security.
What the MCP Registry states
The entry as published to the official MCP Registry (read 2026-10-04), latest version.
- Registry name
io.github.WYRE-AI/proofpoint-mcp- Version
- 1.1.5
- Status
- Active
- Category
- developer
- Transport
- stdio (local process)
- Package
- OCI image (Docker)
- Published
- 2026-08-26
- Updated
- 2026-08-26
- Publisher
- WYRE-AI (GitHub) · 67 servers with pages here
- Listed under
- Email MCP servers
- Website
- github.com/WYRE-AI/proofpoint-mcp
- Repository
- github.com/WYRE-AI/proofpoint-mcp
- Source
- Registry API entry
Packages
| Registry | Package | Version | Transport |
|---|---|---|---|
| OCI image (Docker) | ghcr.io/wyre-ai/proofpoint-mcp:v1.1.5 | — | stdio |
How to connect Proofpoint
Proofpoint runs locally from a container image in an OCI registry such as Docker Hub or GitHub Container Registry: ghcr.io/wyre-ai/proofpoint-mcp:v1.1.5. It speaks MCP over stdio, so the client starts it as a program and talks to it through standard input and output. It needs Docker or another OCI container runtime; started with docker run — the usual command is docker run -i --rm -e PROOFPOINT_SERVICE_PRINCIPAL -e PROOFPOINT_SERVICE_SECRET -e PROOFPOINT_BASE_URL -e MCP_TRANSPORT -e AUTH_MODE -e LOG_LEVEL ghcr.io/wyre-ai/proofpoint-mcp:v1.1.5. It reads these environment variables: PROOFPOINT_SERVICE_PRINCIPAL (required), PROOFPOINT_SERVICE_SECRET (required, secret), PROOFPOINT_BASE_URL, MCP_TRANSPORT, AUTH_MODE and LOG_LEVEL; set them in the client's configuration for this server.
In the mcpServers JSON format that many desktop and editor MCP clients read, the entry looks like this (placeholders in angle brackets):
{
"mcpServers": {
"proofpoint-mcp": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"-e",
"PROOFPOINT_SERVICE_PRINCIPAL",
"-e",
"PROOFPOINT_SERVICE_SECRET",
"-e",
"PROOFPOINT_BASE_URL",
"-e",
"MCP_TRANSPORT",
"-e",
"AUTH_MODE",
"-e",
"LOG_LEVEL",
"ghcr.io/wyre-ai/proofpoint-mcp:v1.1.5"
],
"env": {
"PROOFPOINT_SERVICE_PRINCIPAL": "<value>",
"PROOFPOINT_SERVICE_SECRET": "<secret>",
"PROOFPOINT_BASE_URL": "<value>",
"MCP_TRANSPORT": "<value>",
"AUTH_MODE": "<value>",
"LOG_LEVEL": "<value>"
}
}
}
}Derived from the registry entry, not tested here. What the server does, and on what terms, is set by its publisher; check its repository or website before giving it access to your accounts or files. How to add an MCP server to an assistant · Before you connect
More from WYRE-AI (GitHub)
| Server | Runs |
|---|---|
| LiongardMCP server for Liongard — inspectors, environments, metrics, detections, and timeline data. | Local · stdio |
| MailprotectorMCP server for Mailprotector — customers, domains, users, quarantine, allow/block rules for MSPs. | Local · stdio |
| MimecastMCP server for Mimecast email security: message queue, held messages, domains, and threats. | Local · stdio |
| MSP360MCP server for MSP360's Managed Backup Service API — companies, computers, and backup plans. | Local · stdio |
| NinjaOneMCP server for NinjaOne RMM — devices, organizations, alerts, and tickets. | Local · stdio |
| Nutanix Prism CentralMultitenant Streamable HTTP bridge over Nutanix's official v4 API MCP server (Prism Central). | Local · stdio |
| Proofpoint EssentialsMCP server for Proofpoint Essentials -- MSP org, domain, user, licensing, and reporting management. | Local · stdio |
| PRTGMCP server for Paessler PRTG's REST API v2 - network/infrastructure monitoring for MSPs. | Local · stdio |
| QuickBooks OnlineMCP server for QuickBooks Online — accounts, customers, invoices, bills, and reports. | Local · stdio |
| RocketCyberMCP server for RocketCyber Managed SOC — incidents, alerts, agents, and customer telemetry. | Local · stdio |
| RootlyMCP server for Rootly — incidents, alerts, escalations, and post-incident reports. | Local · stdio |
| SaaS AlertsMCP server for Kaseya SaaS Alerts — SaaS security monitoring for M365 & Google Workspace. | Local · stdio |
More developer servers
| Server | Runs |
|---|---|
| Proof CLI (unofficial)Notarize, e-sign, and verify identity with the Proof API. Unofficial; not affiliated with Proof. | Local · stdio |
| Proof HoldingsOne API, all things verified — control, delegation, human approval, anti-impersonation. | Remote & Local · HTTP, stdio |
| ProofFlowAudit infrastructure for AI coding agents with evidence-backed review and policy gates. | Local · stdio |
| ProofhandHuman QA on real phones and browsers for your coding agent. Pass/fail per step, with screenshots. | Remote · HTTP |
| ProofpointMCP server for Proofpoint TAP — threat intelligence, forensics, quarantine, and email security. | Local · stdio |
| ProofRail MCP Release CertifierMCP deployment checks: required tools, schema drift and verifiable receipts. Free preflight. | Remote · HTTP |
| Protectwith KbAI-security knowledge as MCP: standards-mapped tools (OWASP, NIST, MITRE) for AI agents. | Remote · HTTP |