Standalone gateway · Streamable HTTP · Private preview

Connect Grok & Any LLM to Your Active Defence via MCP

Use natural language to explore OrionEye SSH telemetry, compare coordinated campaign confidence, enrich an indicator with AbuseIPDB context, and submit a finding to the moderated Intel Feed from an MCP-compatible client.

Grok/xAI directory availability subject to vendor support and approval
Client support is not implied. Claude Code supports remote HTTP MCP configuration. The current public xAI documentation does not verify a custom MCP server flow in the Grok consumer UI; connect Grok only if your client release explicitly supports remote MCP. No official xAI partnership or directory listing is claimed.

How it works

  1. 01 · Sign in

    Authorize with OrionEye

    Enterprise users can sign in with their OrionEye account or Google when configured. OAuth uses PKCE and never creates or replaces the normal web-app session.

  2. 02 · Connect

    Add the MCP server URL

    Enter the HTTPS endpoint in a client that supports MCP OAuth discovery. The gateway checks the Enterprise entitlement again for every request; Pro clients may still use an administrator-provisioned bearer where supported.

  3. 03 · Investigate

    Ask, review, then act

    Query threat intelligence or submit an item to moderation. A campaign-block request creates a proposal only; the operator must review it in OrionEye.

What the connector exposes

Read-only resources

orioneye://threats/live
orioneye://campaigns/active
orioneye://telemetry/server
orioneye://intel/feed

IP usernames, server labels, and other internal fields are removed. Feed reads return published items only.

Threat investigation

investigate_ip(ip) combines the tracked SSH record with the AbuseIPDB dossier. It does not report or block an address.

Moderated contribution

post_intel_feed(indicator, severity) creates a submission with status in_review. A human moderator decides whether to publish it.

Action proposal

block_campaign(campaign_id) creates an HMAC-audited proposal. MCP v1 never calls Fail2Ban or the OmniAgent approval endpoint.

Bounded network tools

Enterprise clients may run ping or traceroute only for public IPv4 addresses already in OrionEye threat telemetry, and search RIPE Atlas within a radius capped at 200 km.

Telemetry scope

Health and uptime are exposed. The existing OmniAgent pairing endpoint does not provide CPU, memory, or full SRE metrics.

Example connection

For clients with MCP OAuth discovery, enter the server URL and complete OrionEye sign-in:

https://orioneye.io/mcp

For clients that require a bearer header, an administrator may provision a token securely. For Claude Code, use the remote HTTP transport:

claude mcp add --transport http orioneye \
  https://orioneye.io/mcp \
  --header "Authorization: Bearer YOUR_MCP_CLIENT_TOKEN"

For Claude.ai, Claude Desktop, or Grok, use the custom connector workflow only where that product, account and release support remote MCP. Provider menus and auth options can change; consult the vendor's current documentation.

Example questions:

Plan access

Free

No MCP client token is issued.

Pro

Up to two clients per workspace. Read resources, threat queries and moderated Intel Feed submissions.

Enterprise

Includes proposal and bounded network tools, plus OAuth sign-in with current Enterprise entitlement checks. One gateway instance serves one workspace; OAuth tokens expire after one hour and are reissued through sign-in.

OAuth requires a client that supports MCP's OAuth discovery flow; Grok's consumer connector compatibility is not confirmed. Google sign-in appears only when configured. The gateway uses a privileged backend credential internally, never exposes it to clients, and checks the account's Enterprise plan on every OAuth-authenticated MCP request.

Security by design