Skip to content
appsgit

CrowdStrike Falcon MCP Server

CrowdStrike Falcon MCP Server is an MCP server that connects AI agents with CrowdStrike Falcon for security analysis and automation. It has 265 GitHub stars, is released under the MIT license and runs locally with uvx falcon-mcp. It works with Claude Desktop, Claude Code, Cursor and VS Code and needs an API key.

github.com/CrowdStrike/falcon-mcp (opens in a new tab)

  • Official
  • Needs API key
  • Other
  • MIT
  • Actively maintained

Install CrowdStrike Falcon MCP Server

Generated from the server's MCP registry entry. Replace your-value with your own values.

Claude Desktop

claude_desktop_config.json
{
  "mcpServers": {
    "crowdstrike-falcon-mcp-server": {
      "command": "uvx",
      "args": [
        "falcon-mcp"
      ],
      "env": {
        "FALCON_CLIENT_ID": "your-value",
        "FALCON_CLIENT_SECRET": "your-value",
        "FALCON_MCP_API_KEY": "your-value"
      }
    }
  }
}

Settings > Developer > Edit Config. macOS: ~/Library/Application Support/Claude/, Windows: %APPDATA%\Claude\. Restart Claude Desktop afterwards.

Claude Code

claude mcp add --env FALCON_CLIENT_ID=your-value --env FALCON_CLIENT_SECRET=your-value --env FALCON_MCP_API_KEY=your-value --transport stdio crowdstrike-falcon-mcp-server -- uvx falcon-mcp

Cursor

.cursor/mcp.json
{
  "mcpServers": {
    "crowdstrike-falcon-mcp-server": {
      "type": "stdio",
      "command": "uvx",
      "args": [
        "falcon-mcp"
      ],
      "env": {
        "FALCON_CLIENT_ID": "your-value",
        "FALCON_CLIENT_SECRET": "your-value",
        "FALCON_MCP_API_KEY": "your-value"
      }
    }
  }
}

Project file; use ~/.cursor/mcp.json to enable it in every project.

VS Code

.vscode/mcp.json
{
  "inputs": [
    {
      "type": "promptString",
      "id": "falcon_client_id",
      "description": "FALCON_CLIENT_ID",
      "password": true
    },
    {
      "type": "promptString",
      "id": "falcon_client_secret",
      "description": "FALCON_CLIENT_SECRET",
      "password": true
    },
    {
      "type": "promptString",
      "id": "falcon_mcp_api_key",
      "description": "FALCON_MCP_API_KEY",
      "password": true
    }
  ],
  "servers": {
    "crowdstrike-falcon-mcp-server": {
      "type": "stdio",
      "command": "uvx",
      "args": [
        "falcon-mcp"
      ],
      "env": {
        "FALCON_CLIENT_ID": "${input:falcon_client_id}",
        "FALCON_CLIENT_SECRET": "${input:falcon_client_secret}",
        "FALCON_MCP_API_KEY": "${input:falcon_mcp_api_key}"
      }
    }
  }
}

Config formats checked against the official docs on Oct 7, 2026: modelcontextprotocol.io (opens in a new tab), code.claude.com (opens in a new tab), cursor.com (opens in a new tab), code.visualstudio.com (opens in a new tab).

Environment variables

Variables the server reads at startup.

NameRequiredDescription
FALCON_CLIENT_IDsecretYesCrowdStrike API client ID
FALCON_CLIENT_SECRETsecretYesCrowdStrike API client secret
FALCON_BASE_URLNoCrowdStrike API region URL
FALCON_MEMBER_CIDNoChild CID for Flight Control (MSSP) support
FALCON_MCP_MODULESNoComma-separated list of modules to enable
FALCON_MCP_TRANSPORTNoTransport protocol to use
FALCON_MCP_DEBUGNoEnable debug logging
FALCON_MCP_HOSTNoHost to bind to for HTTP transports
FALCON_MCP_PORTNoPort to listen on for HTTP transports
FALCON_MCP_USER_AGENT_COMMENTNoAdditional information to include in the User-Agent comment section
FALCON_MCP_STATELESS_HTTPNoEnable stateless HTTP mode for scalable deployments
FALCON_MCP_API_KEYsecretNoAPI key for HTTP transport authentication (x-api-key header)

About CrowdStrike Falcon MCP Server

falcon-mcp is a Model Context Protocol (MCP) server that connects AI agents with the CrowdStrike Falcon platform, powering intelligent security analysis in your agentic workflows. It delivers programmatic access to essential security capabilities—including detections, threat intelligence, and host management—establishing the foundation for advanced security operations and automation.

  • ai
  • crowdstrike
  • falcon
  • mcp
  • mcp-server

FAQ

CrowdStrike Falcon MCP Server FAQ

Still curious? Email info@appsgit.com.

What is CrowdStrike Falcon MCP Server?

CrowdStrike Falcon MCP Server is an MCP server that connects AI agents with CrowdStrike Falcon for security analysis and automation. It has 265 GitHub stars, is released under the MIT license and runs locally with uvx falcon-mcp. It works with Claude Desktop, Claude Code, Cursor and VS Code and needs an API key. The source code is at github.com/CrowdStrike/falcon-mcp.

How do I install the CrowdStrike Falcon MCP Server MCP server?

Add the command uvx falcon-mcp to your MCP client: put it in claude_desktop_config.json for Claude Desktop, run claude mcp add for Claude Code, or add it to .cursor/mcp.json (Cursor) or .vscode/mcp.json (VS Code). The snippets on this page are ready to paste.

Is CrowdStrike Falcon MCP Server free?

The server is open source under the MIT license, so running it is free. It needs credentials (FALCON_CLIENT_ID, FALCON_CLIENT_SECRET and FALCON_MCP_API_KEY) for the service it connects to, which may require a paid account.

Is CrowdStrike Falcon MCP Server actively maintained?

The most recent commit was on Oct 6, 2026. The latest release is v0.19.0, published Sep 1, 2026. appsgit only lists MCP servers with a commit in the last six months and re-checks every server daily.