๐Ÿ”’

Varonis MCP Server

Updated June 2026โœ“ Official

Varonis MCP Server is the official Model Context Protocol interface to the Varonis Data Security Platform, introduced on the Varonis blog in June 2025. Built by Varonis, it is officially maintained and best for Security.

by Varonis

About

Varonis MCP Server is the official Model Context Protocol interface to the Varonis Data Security Platform, introduced on the Varonis blog in June 2025. Varonis frames it explicitly as more than a chat layer over the product: the server orchestrates real Varonis API calls so an AI client can carry out multi-step data-security work that previously meant stitching together several tools, API calls and a fair amount of platform expertise. Varonis documents ChatGPT, Claude and GitHub Copilot as supported clients, with the Copilot-in-VS-Code path shown in their demo. The published example workflows give a good sense of the surface area: pulling the last N high-severity Varonis alerts sorted by MITRE ATT&CK technique and pushing the details into related ServiceNow tickets; running a remediation that removes stale Entra ID guest accounts with no data access in 180+ days; and building a compliance report listing every database and table across AWS and Azure that holds employee PII. Varonis positions four core uses - turning any AI client into a data-security analyst (investigating anomalies, summarizing posture issues, assessing a user's blast radius), chaining workflows across tools (remediate access, update tickets, notify teams, document the action from one prompt), automating investigation and response (enriching alerts with threat-actor and IoC context, then triggering response playbooks), and removing the need to know which API to call. Access status matters before you plan around it: the server is in private preview and available to Varonis customers through the Varonis Developer Hub at dev.varonis.com, with API coverage still expanding. There is no public source repository - the only GitHub result for "varonis mcp" is an unaffiliated Sentinel-alert tooling repo - and no npm package, so no install command is listed. It sits alongside Varonis' other AI work, including Athena AI and the agentic detection enhancements in their MDDR managed service.

โ€“
Unverifiable
not scored

No repository for this entry resolves against the live GitHub API, so there is nothing to verify. It is deliberately left unscored rather than given a number we cannot stand behind.

What could not be measured

These contributed nothing to the score โ€” not a penalty, not a zero. They are why the confidence reads the way it does.

  • Source verificationunknown

    No repository for this entry resolves against the live GitHub API. Without a confirmed source there is nothing to inspect, so this entry is excluded from trust scoring entirely rather than scored on catalog metadata alone.

Frequently Asked Questions

What is Varonis MCP Server?
Varonis is an MCP server built by Varonis. Varonis MCP Server is the official Model Context Protocol interface to the Varonis Data Security Platform, introduced on the Varonis blog in June 2025. Varonis frames it explicitly as more than a chat layer over the product: the server orchestrates real Varonis API calls so an AI client can carry out multi-step data-security work that previously meant stitching together several tools, API calls and a fair amount of platform expertise. Varonis documents ChatGPT, Claude and GitHub Copilot as supported clients, with the Copilot-in-VS-Code path shown in their demo. The published example workflows give a good sense of the surface area: pulling the last N high-severity Varonis alerts sorted by MITRE ATT&CK technique and pushing the details into related ServiceNow tickets; running a remediation that removes stale Entra ID guest accounts with no data access in 180+ days; and building a compliance report listing every database and table across AWS and Azure that holds employee PII. Varonis positions four core uses - turning any AI client into a data-security analyst (investigating anomalies, summarizing posture issues, assessing a user's blast radius), chaining workflows across tools (remediate access, update tickets, notify teams, document the action from one prompt), automating investigation and response (enriching alerts with threat-actor and IoC context, then triggering response playbooks), and removing the need to know which API to call. Access status matters before you plan around it: the server is in private preview and available to Varonis customers through the Varonis Developer Hub at dev.varonis.com, with API coverage still expanding. There is no public source repository - the only GitHub result for "varonis mcp" is an unaffiliated Sentinel-alert tooling repo - and no npm package, so no install command is listed. It sits alongside Varonis' other AI work, including Athena AI and the agentic detection enhancements in their MDDR managed service.
Who built Varonis MCP Server?
Varonis MCP Server was built by Varonis.
Is Varonis MCP Server free?
Yes, Varonis MCP Server has a free option. This MCP server is free and open-source. Check the GitHub repository for details.
How do I install Varonis MCP Server?
Varonis MCP Server has no verified public repository, so there is no confirmed install command for it.
What does Varonis MCP Server integrate with?
Varonis MCP Server integrates with Claude Desktop, Cursor, VS Code.
No verified public repositoryVisit Website

Repo Health

Local install

Local/stdio install โ€” runs on your machine, so there is no remote endpoint to verify live. Trust signal below is from the source repo.

Install
binary

Repo recency not yet available for this server.

Quick Info

Install Type
source
Author
Varonis
Categories
2
Integrations
3

Related Servers

๐Ÿ—„๏ธ

ClickHouse MCP Server

ClickHouse MCP Server is ClickHouse's official MCP server (ClickHouse/mcp-clickhouse) that connects Claude, Cursor, and other MCP clients to a ClickHouse cluster for fast analytical querying over natural language. Its primary tool, run_query, executes arbitrary SQL against your cluster in read-only mode by default (CLICKHOUSE_ALLOW_WRITE_ACCESS=false) so an AI assistant can explore tables, aggregate billions of rows, and answer analytics questions without risk of mutating data โ€” writes can be enabled explicitly when needed. Companion tools list databases and tables and return schema metadata (including the full create_table_query, with an option to omit per-column detail for lighter responses). A second tool set embeds chDB, ClickHouse's in-process engine, via run_chdb_select_query, letting the assistant query files, URLs, and external databases directly without an ETL step (enabled with the optional mcp-clickhouse[chdb] extra). Destructive statements are gated a second time: even with writes enabled, DROP and TRUNCATE require CLICKHOUSE_ALLOW_DROP=true as well. The server supports both stdio and HTTP/SSE transports; on HTTP/SSE authentication is required rather than optional โ€” startup fails unless a static bearer token (CLICKHOUSE_MCP_AUTH_TOKEN), a FastMCP OAuth/OIDC provider (Azure Entra, Google, GitHub, WorkOS via FASTMCP_SERVER_AUTH), or an explicit local-development opt-out (CLICKHOUSE_MCP_AUTH_DISABLED) is configured. Connection is configured through CLICKHOUSE_HOST, CLICKHOUSE_PORT, CLICKHOUSE_USER, and CLICKHOUSE_PASSWORD, with ClickHouse Cloud, self-hosted, and the public SQL playground all supported.

Local๐Ÿ“˜โœ“
๐Ÿ”ง

Sentry MCP Server

The Sentry MCP Server is Sentry's official Model Context Protocol integration, purpose-built for human-in-the-loop coding agents like Claude Code, Cursor, and Windsurf. Rather than exposing every Sentry API endpoint, it focuses tightly on developer debugging workflows: searching and triaging issues, pulling stack traces and event details, inspecting performance traces, and querying project/team/org metadata in natural language. The primary deployment is a hosted remote MCP server at mcp.sentry.dev, built on Cloudflare's remote-MCP infrastructure, so most users connect with zero local setup โ€” just add the remote URL to their client. For self-hosted Sentry instances or local development, a stdio transport is also available via npx @sentry/mcp-server, authenticated with a Sentry User Auth Token scoped to org:read, project:read, project:write, team:read, team:write, and event:write. AI-powered search tools (search_events, search_issues) translate natural-language queries into Sentry's query syntax, but require a configured LLM provider (OpenAI, Azure OpenAI, Anthropic, or OpenRouter) โ€” all other tools work without one. Claude Code users can also install it as a plugin (claude plugin install sentry-mcp@sentry-mcp) for automatic subagent delegation whenever a conversation touches Sentry errors, issues, or traces. This turns "why did this deploy break in production" into a direct conversational debugging session instead of tab-switching into the Sentry dashboard.

Auth required๐Ÿ“˜โœ“
๐Ÿ“Š

Datadog MCP Server

The Datadog MCP Server is Datadog's official, vendor-hosted Model Context Protocol endpoint โ€” not a package. Each Datadog site has its own URL of the form https://mcp.<your-site>/api/unstable/mcp-server/mcp (US1: mcp.datadoghq.com, EU1: mcp.datadoghq.eu), and OAuth 2.0 is the recommended way in; a Personal or Service Access Token as an Authorization bearer header is the documented fallback for CI, with DD_API_KEY plus DD_APPLICATION_KEY headers as a third option. Datadog ships first-party client integrations rather than expecting hand-written config: a Claude Code plugin (/plugin install datadog@claude-plugins-official, then /ddsetup and /ddtoolsets), a Claude connector from the Connectors Directory, plugins for Cursor, VS Code/Copilot, JetBrains and OpenCode, and a ChatGPT app in Preview for US1. Tools are grouped into toolsets selected with a ?toolsets= query parameter, and only `core` โ€” logs, metrics, traces, dashboards, monitors, incidents, hosts, services, events, notebooks โ€” loads by default; two dozen more cover alerting, DBM, DDSQL, RUM, profiling, security, Kubernetes, error tracking, feature flags, cost management and data observability, with apm, cases, code-exec and remote-actions in Preview and excluded from toolsets=all. Access requires the mcp_read or mcp_write role permission in addition to the normal resource permission, which is why a working connection can still return no data. Limits at time of writing are 50 requests per 10 seconds of tool-call burst and 50,000 tool calls per month, and the server is not GovCloud compatible.

Local๐Ÿ“˜โœ“
๐Ÿ“Š

Grafana MCP Server

The official Grafana MCP server connects Claude and other AI assistants directly to your Grafana instance and its surrounding observability ecosystem, turning natural-language questions into dashboard lookups, incident investigations, and datasource queries. Dashboard tools cover search, retrieval, JSONPath-scoped property extraction, patch-based editing, and per-panel query/datasource introspection, with context-window-aware helpers like get_dashboard_summary so an agent never has to pull a full multi-megabyte dashboard JSON just to answer a simple question. Query tools speak PromQL against Prometheus (including histogram-percentile helpers), LogQL against Loki, and native query languages for InfluxDB, ClickHouse, CloudWatch, Graphite, Athena, Snowflake, Elasticsearch/OpenSearch, and Quickwit datasources โ€” most gated behind opt-in --enabled-tools flags to keep the default tool surface lean. It also wraps Grafana Incident for creating and updating incidents, Sift for automated error-pattern and slow-request investigations, full alerting CRUD (rules, contact points, notification policies) across Grafana-managed and external Alertmanager sources, Grafana OnCall schedule/shift/alert-group management, RBAC-gated admin tools for teams/users/roles, deeplink generation so the LLM never has to guess a dashboard URL, annotations, snapshots, PNG rendering via the Grafana Image Renderer, and provisioning-repo validation for git-sync workflows. Authentication is a Grafana service account token (Editor role, or granular RBAC scopes) passed as GRAFANA_SERVICE_ACCOUNT_TOKEN alongside GRAFANA_URL, and every tool category can be individually disabled to control context-window usage. On install, the recommended route is uvx: `uvx mcp-grafana` pulls the PyPI package mcp-grafana, which is published by Grafana Labs from this same repository โ€” so despite the server being written in Go, the copy-paste command most Claude Desktop and Cursor configs use is a Python-tooling one, not a binary download. The alternatives are `go install github.com/grafana/mcp-grafana/cmd/mcp-grafana@latest` for a real binary, or the grafana/mcp-grafana container โ€” `-t stdio` for local clients, or the default HTTP mode on :8000 (add `-t streamable-http`) with MCP_GRAFANA_SERVER_TOKEN set to authenticate callers when you expose it.

Localโœ“
๐Ÿ“Š

Axiom

Query and analyze your Axiom logs, traces, and all other event data in natural language.

Localโœ“

Sponsored

1Password

14-day Free Trial

Store and inject API keys, payment credentials, tokens, and file access secrets into your MCP server configs. Trusted by 150K+ developers.

Try 1Password free โ†’