# CrowdStrike Falcon MCP Server (MCP server)

> CrowdStrike Falcon MCP Server is an MCP server that connects AI agents with CrowdStrike Falcon for security analysis and automation. It has 265 GitHub stars, is released under the MIT license and runs locally with uvx falcon-mcp. It works with Claude Desktop, Claude Code, Cursor and VS Code and needs an API key.

falcon-mcp is a Model Context Protocol (MCP) server that connects AI agents with the CrowdStrike Falcon platform, powering intelligent security analysis in your agentic workflows. It delivers programmatic access to essential security capabilities—including detections, threat intelligence, and host management—establishing the foundation for advanced security operations and automation.

## Key facts

| Fact | Value |
|---|---|
| Repository | https://github.com/CrowdStrike/falcon-mcp |
| GitHub stars | 265 |
| License | MIT |
| Language | Python |
| Transport | stdio |
| Packages | pypi: falcon-mcp |
| Remote URL | none |
| Needs API key | yes |
| Official | yes |
| Works with | Claude Desktop, Claude Code, Cursor, VS Code |
| Category | Other |
| Latest release | v0.19.0 (Sep 1, 2026) |
| Last commit | Oct 6, 2026 |
| MCP registry name | io.github.CrowdStrike/falcon-mcp |

## Install

### Claude Desktop (claude_desktop_config.json)

```json
{
  "mcpServers": {
    "crowdstrike-falcon-mcp-server": {
      "command": "uvx",
      "args": [
        "falcon-mcp"
      ],
      "env": {
        "FALCON_CLIENT_ID": "your-value",
        "FALCON_CLIENT_SECRET": "your-value",
        "FALCON_MCP_API_KEY": "your-value"
      }
    }
  }
}
```

Settings > Developer > Edit Config. macOS: ~/Library/Application Support/Claude/, Windows: %APPDATA%\Claude\. Restart Claude Desktop afterwards.

### Claude Code

```sh
claude mcp add --env FALCON_CLIENT_ID=your-value --env FALCON_CLIENT_SECRET=your-value --env FALCON_MCP_API_KEY=your-value --transport stdio crowdstrike-falcon-mcp-server -- uvx falcon-mcp
```

### Cursor (.cursor/mcp.json)

```json
{
  "mcpServers": {
    "crowdstrike-falcon-mcp-server": {
      "type": "stdio",
      "command": "uvx",
      "args": [
        "falcon-mcp"
      ],
      "env": {
        "FALCON_CLIENT_ID": "your-value",
        "FALCON_CLIENT_SECRET": "your-value",
        "FALCON_MCP_API_KEY": "your-value"
      }
    }
  }
}
```

Project file; use ~/.cursor/mcp.json to enable it in every project.

### VS Code (.vscode/mcp.json)

```json
{
  "inputs": [
    {
      "type": "promptString",
      "id": "falcon_client_id",
      "description": "FALCON_CLIENT_ID",
      "password": true
    },
    {
      "type": "promptString",
      "id": "falcon_client_secret",
      "description": "FALCON_CLIENT_SECRET",
      "password": true
    },
    {
      "type": "promptString",
      "id": "falcon_mcp_api_key",
      "description": "FALCON_MCP_API_KEY",
      "password": true
    }
  ],
  "servers": {
    "crowdstrike-falcon-mcp-server": {
      "type": "stdio",
      "command": "uvx",
      "args": [
        "falcon-mcp"
      ],
      "env": {
        "FALCON_CLIENT_ID": "${input:falcon_client_id}",
        "FALCON_CLIENT_SECRET": "${input:falcon_client_secret}",
        "FALCON_MCP_API_KEY": "${input:falcon_mcp_api_key}"
      }
    }
  }
}
```

Config formats checked against the official docs on 2026-10-07.

## Environment variables

- `FALCON_CLIENT_ID` (secret) (required): CrowdStrike API client ID
- `FALCON_CLIENT_SECRET` (secret) (required): CrowdStrike API client secret
- `FALCON_BASE_URL`: CrowdStrike API region URL
- `FALCON_MEMBER_CID`: Child CID for Flight Control (MSSP) support
- `FALCON_MCP_MODULES`: Comma-separated list of modules to enable
- `FALCON_MCP_TRANSPORT`: Transport protocol to use
- `FALCON_MCP_DEBUG`: Enable debug logging
- `FALCON_MCP_HOST`: Host to bind to for HTTP transports
- `FALCON_MCP_PORT`: Port to listen on for HTTP transports
- `FALCON_MCP_USER_AGENT_COMMENT`: Additional information to include in the User-Agent comment section
- `FALCON_MCP_STATELESS_HTTP`: Enable stateless HTTP mode for scalable deployments
- `FALCON_MCP_API_KEY` (secret): API key for HTTP transport authentication (x-api-key header)

## Similar MCP servers

- [Reactive Resume](https://appsgit.com/mcp-servers/reactive-resume): A one-of-a-kind resume builder that keeps your privacy in mind. (43,921 stars, MIT)
- [N8n MCP](https://appsgit.com/mcp-servers/n8n-mcp): A MCP for Claude Desktop / Claude Code / Windsurf / Cursor to build n8n workflows for you. (23,047 stars, MIT)
- [XHS Downloader](https://appsgit.com/mcp-servers/xhs-downloader): 小红书（XiaoHongShu、RedNote）链接提取/作品采集工具. (12,922 stars, GPL-3.0)
- [MCP Use](https://appsgit.com/mcp-servers/mcp-use): The fullstack MCP framework to develop MCP Apps for ChatGPT / Claude & MCP Servers for AI Agents. (10,726 stars, MIT)
- [Ha MCP](https://appsgit.com/mcp-servers/ha-mcp): Comprehensive Model Context Protocol server for managing Home Assistant through AI assistants. (4,964 stars, MIT)
- [MCP Server Chart](https://appsgit.com/mcp-servers/mcp-server-chart): A Model Context Protocol server for generating charts using AntV. (4,391 stars, MIT, needs API key)

---

Canonical page: https://appsgit.com/mcp-servers/crowdstrike-falcon-mcp-server
Source: appsgit (https://appsgit.com), the app store for github. Data from the GitHub API, refreshed nightly.
Machine access: JSON API https://appsgit.com/api/v1/apps (OpenAPI: https://appsgit.com/openapi.json), MCP server https://mcp.appsgit.com/mcp, full index https://appsgit.com/llms-full.txt.
