Connects Claude to the Shodan API for programmatic access to internet-connected device data. You get the full range of Shodan operations: host lookups, database searches with cursor support, alert management, network scanning, exploit archive queries, and saved query browsing. Requires a Shodan API key. Reach for this when you need Claude to investigate exposed services, assess internet-facing infrastructure, or pull vulnerability intelligence during security assessments. The comprehensive tool set means you can go from broad searches to specific host enumeration without switching contexts.
MCP server exposing Shodan API functionality via the Model Context Protocol.
pip install mcp-shodan
export SHODAN_API_KEY=your_api_key
mcp-shodan
Or add to your MCP configuration:
{
"mcpServers": {
"shodan": {
"command": "mcp-shodan",
"env": {
"SHODAN_API_KEY": "your_api_key"
}
}
}
}
shodan_host - Get all available information on an IP addressshodan_search - Search the Shodan databaseshodan_search_cursor - Search and return an iteratorshodan_count - Get total number of search resultsshodan_search_tokens - Get information about a search queryshodan_alerts - List all active alertsshodan_create_alert - Create a new alertshodan_delete_alert - Delete an alertshodan_scan - Scan a networkshodan_scan_internet - Scan the internet on a portshodan_scan_status - Get scan statusshodan_queries - List shared search queriesshodan_queries_search - Search saved queriesshodan_queries_tags - Get popular query tagsshodan_exploits_search - Search the Shodan Exploits archiveshodan_exploits_count - Get total exploit countshodan_info - Get API key informationshodan_ports - Get list of ports Shodan crawlsshodan_protocols - Get supported protocolsshodan_services - Get list of services# Get information about a host
shodan_host("1.1.1.1")
# Search for specific services
shodan_search("apache", limit=10)
# Count results for a query
shodan_count("nginx")
# Check your API plan
shodan_info()
mcp-name: io.github.daedalus/mcp-shodan