Connects Claude to Proofpoint TAP and Essentials APIs for email security operations. You get tools to query threat events, trace message paths, manage quarantine, pull threat intelligence feeds, and interact with URL Defense. It exposes domains like forensics, Smart Search for advanced email queries, VAP reporting for targeted users, DLP policies, and SIEM event exports. Reach for this when you need to investigate phishing campaigns, automate threat response workflows, or give an AI assistant direct access to your Proofpoint security telemetry. Built by Wyre Technology as part of their MSP tooling ecosystem.
A Model Context Protocol (MCP) server for Proofpoint TAP and Essentials APIs. Enables AI assistants to investigate threats, trace emails, manage quarantine, access threat intelligence, and perform URL defense operations.
This is a Model Context Protocol (MCP) server that connects Claude (or any MCP-compatible AI) to your Proofpoint environment.
Part of the MSP Claude Plugins ecosystem — a growing suite of AI integrations for the MSP stack. Built by MSPs, for MSPs.
npm install @wyre-technology/proofpoint-mcp
Set the following environment variables:
| Variable | Required | Description |
|---|---|---|
PROOFPOINT_SERVICE_PRINCIPAL | Yes | Your Proofpoint TAP service principal |
PROOFPOINT_SERVICE_SECRET | Yes | Your Proofpoint TAP service secret |
PROOFPOINT_BASE_URL | No | Custom base URL (default: tap-api-v2.proofpoint.com) |
MCP_TRANSPORT | No | Transport mode: stdio (default) or http |
Add to your Claude Desktop claude_desktop_config.json:
{
"mcpServers": {
"proofpoint-mcp": {
"command": "npx",
"args": ["@wyre-technology/proofpoint-mcp"],
"env": {
"PROOFPOINT_SERVICE_PRINCIPAL": "your-proofpoint-service-principal"
"PROOFPOINT_SERVICE_SECRET": "your-proofpoint-service-secret"
}
}
}
}
claude mcp add proofpoint-mcp \
-e PROOFPOINT_SERVICE_PRINCIPAL=your-value \
-e PROOFPOINT_SERVICE_SECRET=your-value \
-- npx -y @wyre-technology/proofpoint-mcp
docker build -t proofpoint-mcp .
docker run \
-e PROOFPOINT_SERVICE_PRINCIPAL=your-value \
-e PROOFPOINT_SERVICE_SECRET=your-value \
-p 8080:8080 proofpoint-mcp
Data loss prevention policies
Security event stream and SIEM export
Forensic analysis of threats
Very Attacked People (VAP) reporting
Email policy management
Email quarantine management
Security reports and summaries
Advanced email search
Targeted Attack Protection events and campaigns
Threat intelligence and indicators of compromise
URL rewriting and click defense
# Clone the repository
git clone https://github.com/wyre-technology/proofpoint-mcp.git
cd proofpoint-mcp
# Install dependencies
npm install
# Build
npm run build
# Run tests
npm test
Contributions are welcome! Please see CONTRIBUTING.md if present, or open an issue to discuss changes.
Licensed under the Apache License, Version 2.0. See LICENSE for details.
PROOFPOINT_SERVICE_PRINCIPAL*Proofpoint TAP service principal (API user identifier)
PROOFPOINT_SERVICE_SECRET*secretProofpoint TAP service secret
PROOFPOINT_BASE_URLProofpoint TAP API base URL (defaults to https://tap-api-v2.proofpoint.com)
MCP_TRANSPORTdefault: stdioTransport mode for the server. Set to 'stdio' for local CLI use; the image defaults to 'http' for gateway hosting.
AUTH_MODEdefault: envCredential source: 'env' reads vars locally, 'gateway' expects header injection from the WYRE MCP Gateway.
LOG_LEVELdefault: infoLog verbosity: debug, info, warn, error
io.github.mindstone/mcp-server-microsoft-teams
com.mintmcp/outlook-email
helbertparanhos/resend-email-mcp
marlinjai/email-mcp
io.github.mindstone/mcp-server-email-imap
io.github.osamahassouna/email-playbook-mcp