Read-only resources
orioneye://threats/liveorioneye://campaigns/activeorioneye://telemetry/serverorioneye://intel/feed
IP usernames, server labels, and other internal fields are removed. Feed reads return published items only.
Use natural language to explore OrionEye SSH telemetry, compare coordinated campaign confidence, enrich an indicator with AbuseIPDB context, and submit a finding to the moderated Intel Feed from an MCP-compatible client.
Grok/xAI directory availability subject to vendor support and approvalEnterprise users can sign in with their OrionEye account or Google when configured. OAuth uses PKCE and never creates or replaces the normal web-app session.
Enter the HTTPS endpoint in a client that supports MCP OAuth discovery. The gateway checks the Enterprise entitlement again for every request; Pro clients may still use an administrator-provisioned bearer where supported.
Query threat intelligence or submit an item to moderation. A campaign-block request creates a proposal only; the operator must review it in OrionEye.
orioneye://threats/liveorioneye://campaigns/activeorioneye://telemetry/serverorioneye://intel/feed
IP usernames, server labels, and other internal fields are removed. Feed reads return published items only.
investigate_ip(ip) combines the tracked SSH record with the AbuseIPDB dossier. It does not report or block an address.
post_intel_feed(indicator, severity) creates a submission with status in_review. A human moderator decides whether to publish it.
block_campaign(campaign_id) creates an HMAC-audited proposal. MCP v1 never calls Fail2Ban or the OmniAgent approval endpoint.
Enterprise clients may run ping or traceroute only for public IPv4 addresses already in OrionEye threat telemetry, and search RIPE Atlas within a radius capped at 200 km.
Health and uptime are exposed. The existing OmniAgent pairing endpoint does not provide CPU, memory, or full SRE metrics.
For clients with MCP OAuth discovery, enter the server URL and complete OrionEye sign-in:
https://orioneye.io/mcp
For clients that require a bearer header, an administrator may provision a token securely. For Claude Code, use the remote HTTP transport:
claude mcp add --transport http orioneye \ https://orioneye.io/mcp \ --header "Authorization: Bearer YOUR_MCP_CLIENT_TOKEN"
For Claude.ai, Claude Desktop, or Grok, use the custom connector workflow only where that product, account and release support remote MCP. Provider menus and auth options can change; consult the vendor's current documentation.
Example questions:
No MCP client token is issued.
Up to two clients per workspace. Read resources, threat queries and moderated Intel Feed submissions.
Includes proposal and bounded network tools, plus OAuth sign-in with current Enterprise entitlement checks. One gateway instance serves one workspace; OAuth tokens expire after one hour and are reissued through sign-in.
OAuth requires a client that supports MCP's OAuth discovery flow; Grok's consumer connector compatibility is not confirmed. Google sign-in appears only when configured. The gateway uses a privileged backend credential internally, never exposes it to clients, and checks the account's Enterprise plan on every OAuth-authenticated MCP request.