Developer · Local MCP server
Proofpoint
MCP server for Proofpoint TAP — threat intelligence, forensics, quarantine, and email security.
What the MCP Registry states
The entry as published to the official MCP Registry (read 2026-10-04), latest version.
- Registry name
io.github.wyre-technology/proofpoint-mcp- Version
- 1.1.4
- Status
- Active
- Category
- developer
- Transport
- stdio (local process)
- Package
- OCI image (Docker)
- Published
- 2026-08-13
- Updated
- 2026-08-13
- Publisher
- wyre-technology (GitHub) · 53 servers with pages here
- Website
- github.com/wyre-technology/proofpoint-mcp
- Repository
- github.com/wyre-technology/proofpoint-mcp
- Source
- Registry API entry
Packages
| Registry | Package | Version | Transport |
|---|---|---|---|
| OCI image (Docker) | ghcr.io/wyre-technology/proofpoint-mcp:v1.1.4 | — | stdio |
How to connect Proofpoint
Proofpoint runs locally from a container image in an OCI registry such as Docker Hub or GitHub Container Registry: ghcr.io/wyre-technology/proofpoint-mcp:v1.1.4. It speaks MCP over stdio, so the client starts it as a program and talks to it through standard input and output. It needs Docker or another OCI container runtime; started with docker run — the usual command is docker run -i --rm -e PROOFPOINT_SERVICE_PRINCIPAL -e PROOFPOINT_SERVICE_SECRET -e PROOFPOINT_BASE_URL -e MCP_TRANSPORT -e AUTH_MODE -e LOG_LEVEL ghcr.io/wyre-technology/proofpoint-mcp:v1.1.4. It reads these environment variables: PROOFPOINT_SERVICE_PRINCIPAL (required), PROOFPOINT_SERVICE_SECRET (required, secret), PROOFPOINT_BASE_URL, MCP_TRANSPORT, AUTH_MODE and LOG_LEVEL; set them in the client's configuration for this server.
In the mcpServers JSON format that many desktop and editor MCP clients read, the entry looks like this (placeholders in angle brackets):
{
"mcpServers": {
"proofpoint-mcp": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"-e",
"PROOFPOINT_SERVICE_PRINCIPAL",
"-e",
"PROOFPOINT_SERVICE_SECRET",
"-e",
"PROOFPOINT_BASE_URL",
"-e",
"MCP_TRANSPORT",
"-e",
"AUTH_MODE",
"-e",
"LOG_LEVEL",
"ghcr.io/wyre-technology/proofpoint-mcp:v1.1.4"
],
"env": {
"PROOFPOINT_SERVICE_PRINCIPAL": "<value>",
"PROOFPOINT_SERVICE_SECRET": "<secret>",
"PROOFPOINT_BASE_URL": "<value>",
"MCP_TRANSPORT": "<value>",
"AUTH_MODE": "<value>",
"LOG_LEVEL": "<value>"
}
}
}
}Derived from the registry entry, not tested here. What the server does, and on what terms, is set by its publisher; check its repository or website before giving it access to your accounts or files. How to add an MCP server to an assistant · Before you connect
More from wyre-technology (GitHub)
| Server | Runs |
|---|---|
| KnowBe4MCP server for KnowBe4 security awareness training — users, groups, training, phishing campaigns. | Local · stdio |
| LiongardMCP server for Liongard — inspectors, environments, metrics, detections, and timeline data. | Local · stdio |
| MailprotectorMCP server for Mailprotector — customers, domains, users, quarantine, allow/block rules for MSPs. | Local · stdio |
| MimecastMCP server for Mimecast email security: message queue, held messages, domains, and threats. | Local · stdio |
| NinjaOneMCP server for NinjaOne RMM — devices, organizations, alerts, and tickets. | Local · stdio |
| Nutanix Prism CentralMultitenant Streamable HTTP bridge over Nutanix's official v4 API MCP server (Prism Central). | Local · stdio |
| QuickBooks OnlineMCP server for QuickBooks Online — accounts, customers, invoices, bills, and reports. | Local · stdio |
| RocketCyberMCP server for RocketCyber Managed SOC — incidents, alerts, agents, and customer telemetry. | Local · stdio |
| RootlyMCP server for Rootly — incidents, alerts, escalations, and post-incident reports. | Local · stdio |
| SaaS AlertsMCP server for Kaseya SaaS Alerts — SaaS security monitoring for M365 & Google Workspace. | Local · stdio |
| SalesforceMCP server for Salesforce CRM — Accounts, Contacts, Opportunities, Leads, Cases. | Local · stdio |
| ScalePadMCP server for ScalePad — Core, Lifecycle Manager, ControlMap, Backup Radar, and Quoter. | Local · stdio |
More developer servers
| Server | Runs |
|---|---|
| Proof HoldingsOne API, all things verified — control, delegation, human approval, anti-impersonation. | Remote & Local · HTTP, stdio |
| ProofFlowAudit infrastructure for AI coding agents with evidence-backed review and policy gates. | Local · stdio |
| ProofhandHuman QA on real phones and browsers for your coding agent. Pass/fail per step, with screenshots. | Remote · HTTP |
| ProofpointMCP server for Proofpoint TAP — threat intelligence, forensics, quarantine, and email security. | Local · stdio |
| Proofpoint EssentialsMCP server for Proofpoint Essentials -- MSP org, domain, user, licensing, and reporting management. | Local · stdio |
| ProofRail MCP Release CertifierMCP deployment checks: required tools, schema drift and verifiable receipts. Free preflight. | Remote · HTTP |
| Protectwith KbAI-security knowledge as MCP: standards-mapped tools (OWASP, NIST, MITRE) for AI agents. | Remote · HTTP |
| Protein MCP ServerMCP Server for 3D protein structural data retrieval & analysis from RCSB PDB, PDBe, and UniProt. | Local · stdio, HTTP |