MCP Integration
Connect Claude and other AI assistants to mlab.sh through the Model Context Protocol server.
mlab.sh exposes a Model Context Protocol (MCP) server that lets Claude and other AI assistants query threat intelligence, run scans, and manage your account directly from a conversation.
Official support: Claude only. This MCP integration has been tested and is officially supported on Claude (claude.ai web and Claude Desktop). Other MCP-compatible clients may work but are neither tested nor guaranteed - use them at your own discretion and expect no dedicated support for third-party clients.
Endpoint and transports
The MCP server is available at a single URL and supports two transports:
- Streamable HTTP -
POST https://mlab.sh/mcp - SSE -
GET https://mlab.sh/mcp
Authentication: All requests require a Bearer token in the Authorization header. Tokens start with mcp_ and can be created in Account → Settings → MCP Tokens or via OAuth from any compatible AI client (e.g. Claude.ai).
Claude.ai web connector (recommended)
Claude.ai supports remote MCP connectors via OAuth 2.0. No token to copy - authorization is handled automatically.
Open Claude.ai → Settings → Integrations → Add connector (or the connector icon in the chat input bar).
Enter the MCP server URL:
https://mlab.sh/mcpClaude.ai will redirect you to mlab.sh to authorize the connection. Click Authorize - done.
Claude Desktop (local)
Claude Desktop uses a stdio bridge (mcp-remote) to connect to remote HTTP servers. Requires Node.js.
Create an MCP token in Account → Settings → MCP Tokens.
Open your Claude Desktop config file:
# macOS
~/Library/Application Support/Claude/claude_desktop_config.json
# Windows
%APPDATA%\Claude\claude_desktop_config.jsonAdd the following entry (replace mcp_xxx with your token):
{
"mcpServers": {
"mlab": {
"command": "npx",
"args": [
"-y",
"mcp-remote",
"https://mlab.sh/mcp",
"--header",
"Authorization: Bearer mcp_xxx"
]
}
}
}Restart Claude Desktop. The mlab tools will appear in the tool picker.
Available tools
| Tool | Description | Parameters |
|---|---|---|
detect_ioc | Auto-detect IOC type and enrich IPs with geolocation & reputation | value |
scan_ip | Look up an IPv4 or IPv6 address, or a CIDR range. Geolocation, ISP, ASN, network type, TOR status, reverse DNS with forward confirmation, and the RDAP allocation with its abuse contact | ip |
start_domain_scan | Launch a domain scan (returns cached results instantly if available) | domain |
get_domain_scan_results | Poll scan results - DNS, subdomains, SSL, security.txt, robots.txt | domain |
get_scan_history | Recent scan history, optionally filtered by type | type? limit? |
get_bookmarks | List saved bookmarks (IPs, domains, hashes) | limit? |
add_bookmark | Save an IOC to bookmarks | value |
remove_bookmark | Remove an IOC from bookmarks | value |
scan_crypto | Look up a blockchain address - labels, sanctions, risk score. 18 chains, all reachable. Pass chain for an EVM address: it cannot be derived, and a wrong guess loses every label | address chain? |
cve_search | Search CVEs by keyword, product, vendor or CVE ID. Returns CVSS score, severity, EPSS probability, KEV status and affected products | query severity? date_start? date_end? limit? page? |
cve_detail | Full record for a single CVE - CVSS vector breakdown, CWE weaknesses, references, EPSS exploitation probability and CISA KEV dates | cve_id |
search_actors | Search threat actors by name - optional filters on suspected origin, motivation and targeted sector | query origin? motivation? sector? limit? |
get_actor | Full profile for a threat actor - aliases, suspected origin, motivations, targeted countries & sectors, exploited CVEs, tools, techniques and references | slug |
actors_by_cve | Reverse lookup - list every threat actor known to exploit a given CVE, with attribution sources | cve_id |
get_scan_limits | Remaining daily quotas for IP, domain, file and crypto scans | - |
get_account_info | Current user, organization and subscription plan | - |
Token management
MCP tokens are personal and scoped to your user account. You can create up to 5 active tokens. Tokens can be revoked at any time from Account → Settings.
Tokens issued via OAuth (e.g. from Claude.ai) are also listed there, labeled OAuth: <client name>.