Developer · Local MCP server

ThreatLocker

MCP server for ThreatLocker — zero-trust endpoint protection, allowlisting, and policies.

Visit ThreatLocker's website

What the MCP Registry states

The entry as published to the official MCP Registry (read 2026-10-04), latest version.

Registry name
io.github.WYRE-AI/threatlocker-mcp
Version
1.3.10
Status
Active
Category
developer
Transport
stdio (local process)
Package
OCI image (Docker)
Published
2026-09-24
Updated
2026-09-24
Publisher
WYRE-AI (GitHub) · 67 servers with pages here
Website
github.com/WYRE-AI/threatlocker-mcp
Repository
github.com/WYRE-AI/threatlocker-mcp
Source
Registry API entry

Packages

RegistryPackageVersionTransportEnvironment variables
OCI image (Docker)ghcr.io/wyre-ai/threatlocker-mcp:v1.3.10—stdioTHREATLOCKER_API_KEY (required, secret), THREATLOCKER_ORGANIZATION_ID (required), MCP_TRANSPORT, AUTH_MODE, LOG_LEVEL

How to connect ThreatLocker

ThreatLocker runs locally from a container image in an OCI registry such as Docker Hub or GitHub Container Registry: ghcr.io/wyre-ai/threatlocker-mcp:v1.3.10. It speaks MCP over stdio, so the client starts it as a program and talks to it through standard input and output. It needs Docker or another OCI container runtime; started with docker run — the usual command is docker run -i --rm -e THREATLOCKER_API_KEY -e THREATLOCKER_ORGANIZATION_ID -e MCP_TRANSPORT -e AUTH_MODE -e LOG_LEVEL ghcr.io/wyre-ai/threatlocker-mcp:v1.3.10. It reads these environment variables: THREATLOCKER_API_KEY (required, secret), THREATLOCKER_ORGANIZATION_ID (required), MCP_TRANSPORT, AUTH_MODE and LOG_LEVEL; set them in the client's configuration for this server.

In the mcpServers JSON format that many desktop and editor MCP clients read, the entry looks like this (placeholders in angle brackets):

{
  "mcpServers": {
    "threatlocker-mcp": {
      "command": "docker",
      "args": [
        "run",
        "-i",
        "--rm",
        "-e",
        "THREATLOCKER_API_KEY",
        "-e",
        "THREATLOCKER_ORGANIZATION_ID",
        "-e",
        "MCP_TRANSPORT",
        "-e",
        "AUTH_MODE",
        "-e",
        "LOG_LEVEL",
        "ghcr.io/wyre-ai/threatlocker-mcp:v1.3.10"
      ],
      "env": {
        "THREATLOCKER_API_KEY": "<secret>",
        "THREATLOCKER_ORGANIZATION_ID": "<value>",
        "MCP_TRANSPORT": "<value>",
        "AUTH_MODE": "<value>",
        "LOG_LEVEL": "<value>"
      }
    }
  }
}

Derived from the registry entry, not tested here. What the server does, and on what terms, is set by its publisher; check its repository or website before giving it access to your accounts or files. How to add an MCP server to an assistant · Before you connect

More from WYRE-AI (GitHub)

ServerRunsEndpoint or package
ScalePadMCP server for ScalePad — Core, Lifecycle Manager, ControlMap, Backup Radar, and Quoter.Local · stdioOCI image (Docker): ghcr.io/wyre-ai/scalepad-mcp:v1.0.6
SherwebMCP server for Sherweb — billing, subscriptions, customers, and product catalog.Local · stdioOCI image (Docker): ghcr.io/wyre-ai/sherweb-mcp:v2.0.1
SlideMCP server for Slide's backup/BDR (business continuity/disaster recovery) API.Local · stdioOCI image (Docker): ghcr.io/wyre-ai/slide-mcp:v1.0.0
SpamTitanMCP server for SpamTitan email security — quarantine, allow/block lists, and policy management.Local · stdioOCI image (Docker): ghcr.io/wyre-ai/spamtitan-mcp:v1.3.3
Spanning Cloud BackupMCP server for Spanning Cloud Backup — M365/GWS/Salesforce backups, restores, audit.Local · stdioOCI image (Docker): ghcr.io/wyre-ai/spanning-mcp:v1.1.4
SuperOpsMCP server for SuperOps unified PSA+RMM — clients, tickets, assets, and more.Local · stdioOCI image (Docker): ghcr.io/wyre-ai/superops-mcp:v2.0.1
SyncroMCP server for Syncro MSP — customers, tickets, assets, invoices, and more.Local · stdioOCI image (Docker): ghcr.io/wyre-ai/syncro-mcp:v1.4.9
TeramindMCP server for Teramind's insider-threat/employee-monitoring API (read-only, metadata-only surface).Local · stdioOCI image (Docker): ghcr.io/wyre-ai/teramind-mcp:v1.0.0
TimeZestMCP server for TimeZest — appointment scheduling, agents, appointment types, and resources for MSPs.Local · stdioOCI image (Docker): ghcr.io/wyre-ai/timezest-mcp:v3.0.1
UISPMCP server for Ubiquiti UISP's REST API - network/ISP infrastructure monitoring for MSPs.Local · stdioOCI image (Docker): ghcr.io/wyre-ai/uisp-mcp:v1.0.0
Unitrends BackupMCP server for Unitrends Backup — appliances, jobs, recovery points, restores, alerts.Local · stdioOCI image (Docker): ghcr.io/wyre-ai/unitrends-mcp:v1.1.4
XeroMCP server for Xero accounting — contacts, invoices, payments, accounts, and financial reports.Local · stdioOCI image (Docker): ghcr.io/wyre-ai/xero-mcp:v1.5.6

More developer servers

All 6,250 →
ServerRunsEndpoint or package
ThousandEyes MCPThousandEyes MCP Server for network intelligence: outages, anomalies, alerts, events, and tests.Remote · HTTPapi.thousandeyes.com
Thread MindGit-friendly memory for AI coding: a tree of thread summaries with inherited context.Local · stdionpm: thread-mind-mcp
thread-keeperMulti-agent shared brain across Claude, Codex, Antigravity, Gemini, Copilot, and VS Code.Local · stdioPyPI: threadkeeper
Threadctx MCPShared memory MCP server for AI coding agents — local by default, team-shared via threadctx.dev.Local · stdionpm: threadctx-mcp
ThreatLockerMCP server for ThreatLocker — zero-trust endpoint protection, allowlisting, and policies.Local · stdioOCI image (Docker): ghcr.io/wyre-technology/threatlocker-mcp:v1.3.6
three.ws BrainList LLM providers and run chat completions through the three.ws multi-provider router.Local · stdionpm: @three-ws/brain-mcp
ThrustLabSimulate electric UAV powertrains and search a public motor, propeller and battery database.Remote · HTTPthrustlab.com
ThryxProtocol MCP ServerThryxProtocol v3.1 — gasless AI agent launchpad on Base. 21 tools wrap thryx.fun HTTP API.Local · stdionpm: @thryx/mcp-server