{"componentChunkName":"component---src-templates-simple-markdown-js","path":"/developer-portal/v2/mcp-server/","matchPath":"","result":{"data":{"markdownRemark":{"html":"<h1 style=\"position:relative;\"><a href=\"#mcp-server\" aria-label=\"mcp server permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><div class=\"hidden-anchor\" id=\"mcp-server\"></div>MCP Server</h1>\n<h2 style=\"position:relative;\"><a href=\"#overview\" aria-label=\"overview permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><div class=\"hidden-anchor\" id=\"overview\"></div>Overview</h2>\n<p>The Drata MCP (Model Context Protocol) Server allows AI assistants like Claude, ChatGPT, Cursor, and Microsoft Copilot to securely access your Drata data. This guide walks you through setting up OAuth authentication for MCP clients.</p>\n<h2 style=\"position:relative;\"><a href=\"#prerequisites\" aria-label=\"prerequisites permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><div class=\"hidden-anchor\" id=\"prerequisites\"></div>Prerequisites</h2>\n<ul>\n<li>\nAdministrator access in Drata\n</li>\n<li>\nAn MCP-compatible client (Claude, ChatGPT, Cursor, or Microsoft Copilot)\n</li>\n</ul>\n<h2 style=\"position:relative;\"><a href=\"#configuration-steps\" aria-label=\"configuration steps permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><div class=\"hidden-anchor\" id=\"configuration-steps\"></div>Configuration Steps</h2>\n<h3 style=\"position:relative;\"><a href=\"#1-configure-the-drata-mcp-server\" aria-label=\"1 configure the drata mcp server permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><div class=\"hidden-anchor\" id=\"1-configure-the-drata-mcp-server\"></div>1. Configure the Drata MCP Server</h3>\n<ol>\n<li>\nClick \n<strong>Settings</strong>\n in your Drata account\n</li>\n<li>\nClick \n<strong>MCP Configuration</strong>\n</li>\n</ol>\n<blockquote>\n<p><strong>Note:</strong> You must be an administrator in Drata to access this page.</p>\n</blockquote>\n<h3 style=\"position:relative;\"><a href=\"#2-configure-your-mcp-client\" aria-label=\"2 configure your mcp client permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><div class=\"hidden-anchor\" id=\"2-configure-your-mcp-client\"></div>2. Configure Your MCP Client</h3>\n<p>Follow the setup instructions for your specific MCP client. Drata provides remote hosted MCP servers at the following endpoints:</p>\n<ul>\n<li>\n<strong>US:</strong>\n \n<code class=\"language-text\">https://mcp.drata.com/mcp/</code>\n</li>\n<li>\n<strong>EU:</strong>\n \n<code class=\"language-text\">https://mcp-euc1.drata.com/mcp/</code>\n</li>\n<li>\n<strong>APAC:</strong>\n \n<code class=\"language-text\">https://mcp-apse2.drata.com/mcp/</code>\n</li>\n</ul>\n<h4 style=\"position:relative;\"><a href=\"#client-specific-setup-instructions\" aria-label=\"client specific setup instructions permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><div class=\"hidden-anchor\" id=\"client-specific-setup-instructions\"></div>Client-Specific Setup Instructions</h4>\n<ul>\n<li>\n<strong>Claude:</strong>\n \n<a href=\"https://support.claude.com/en/articles/11175166-getting-started-with-custom-connectors-using-remote-mcp\">Getting started with custom connectors using remote MCP</a>\n</li>\n<li>\n<strong>ChatGPT:</strong>\n \n<a href=\"https://developers.openai.com/apps-sdk/deploy/connect-chatgpt/\">Connect ChatGPT to MCP</a>\n</li>\n<li>\n<strong>Cursor:</strong>\n \n<a href=\"https://cursor.com/docs/context/mcp\">MCP Documentation</a>\n</li>\n<li>\n<strong>Microsoft Copilot:</strong>\n \n<a href=\"https://learn.microsoft.com/en-us/microsoft-copilot-studio/mcp-add-existing-server-to-agent\">Add existing server to agent</a>\n</li>\n</ul>\n<h2 style=\"position:relative;\"><a href=\"#mcp-tools\" aria-label=\"mcp tools permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><div class=\"hidden-anchor\" id=\"mcp-tools\"></div>MCP Tools</h2>\n<p>The Drata MCP Server exposes the following tools. Each tool maps to a Drata Public API v2 operation and requires the OAuth scope shown below. Access is always limited to the intersection of the scopes you grant and the permissions your Drata role already provides.</p>\n<!-- BEGIN GENERATED: mcp-tools (do not edit by hand -- run `yarn gen:mcp-tools`) -->\n<table>\n<thead>\n<tr>\n<th>Tool</th>\n<th>Description</th>\n<th>OAuth Scope</th>\n<th>Allowed Roles</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Get Company</td>\n<td>Get the account's company information.</td>\n<td><code class=\"language-text\">read:company</code></td>\n<td>Admin</td>\n</tr>\n<tr>\n<td>Search Controls</td>\n<td>Search or list controls for a workspace.</td>\n<td><code class=\"language-text\">read:controls</code></td>\n<td>Admin, Control Manager, DevOps Engineer, Information Security Lead, Restricted Control Manager, Restricted Risk Manager, Risk Manager, Risk Register Owner, Workspace Administrator</td>\n</tr>\n<tr>\n<td>Create Control</td>\n<td>Create a new control in a workspace.</td>\n<td><code class=\"language-text\">create:control</code></td>\n<td>Admin, Control Manager, DevOps Engineer, Information Security Lead, Restricted Control Manager, Workspace Administrator</td>\n</tr>\n<tr>\n<td>Update Control</td>\n<td>Update an existing control in a workspace.</td>\n<td><code class=\"language-text\">update:control</code></td>\n<td>Admin, Control Manager, DevOps Engineer, Information Security Lead, Restricted Control Manager, Workspace Administrator</td>\n</tr>\n<tr>\n<td>List Devices</td>\n<td>List a person's devices with each device's per-monitor compliance checks.</td>\n<td><code class=\"language-text\">read:device</code></td>\n<td>Admin, Information Security Lead, Personnel Compliance Manager, Workspace Administrator</td>\n</tr>\n<tr>\n<td>Get Evidence Bucket</td>\n<td>Get one evidence bucket, including its renewal date, renewal cadence, and status.</td>\n<td><code class=\"language-text\">read:evidence</code></td>\n<td>Admin, Control Manager, DevOps Engineer, Information Security Lead, Restricted Control Manager, Workspace Administrator</td>\n</tr>\n<tr>\n<td>List Evidence Artifacts</td>\n<td>List the individual files inside one evidence bucket.</td>\n<td><code class=\"language-text\">read:evidence</code></td>\n<td>Admin, Control Manager, DevOps Engineer, Information Security Lead, Restricted Control Manager, Workspace Administrator</td>\n</tr>\n<tr>\n<td>List Evidence Buckets</td>\n<td>List or search Evidence Library items via Public API v2, with optional client-side filtering.</td>\n<td><code class=\"language-text\">read:evidence</code></td>\n<td>Admin, Control Manager, DevOps Engineer, Information Security Lead, Restricted Control Manager, Workspace Administrator</td>\n</tr>\n<tr>\n<td>Create Evidence Bucket</td>\n<td>Register (POST) a new evidence bucket with exactly one artifact via Public API v2.</td>\n<td><code class=\"language-text\">create:evidence</code></td>\n<td>Admin, Control Manager, Information Security Lead, Restricted Control Manager, Workspace Administrator</td>\n</tr>\n<tr>\n<td>Delete Evidence Artifact</td>\n<td>Permanently delete one file from an evidence bucket.</td>\n<td><code class=\"language-text\">delete:evidence</code></td>\n<td>Admin, Control Manager, Information Security Lead, Restricted Control Manager, Workspace Administrator</td>\n</tr>\n<tr>\n<td>Delete Evidence Bucket</td>\n<td>Delete an existing evidence library item.</td>\n<td><code class=\"language-text\">delete:evidence</code></td>\n<td>Admin, Control Manager, Information Security Lead, Restricted Control Manager, Workspace Administrator</td>\n</tr>\n<tr>\n<td>Update Evidence Artifacts</td>\n<td>Add, replace, archive, or restore the files inside one evidence bucket.</td>\n<td><code class=\"language-text\">update:evidence</code></td>\n<td>Admin, Control Manager, Information Security Lead, Restricted Control Manager, Workspace Administrator</td>\n</tr>\n<tr>\n<td>Update Evidence Bucket</td>\n<td>Update an existing Evidence Library item.</td>\n<td><code class=\"language-text\">update:evidence</code></td>\n<td>Admin, Control Manager, Information Security Lead, Restricted Control Manager, Workspace Administrator</td>\n</tr>\n<tr>\n<td>List Requirements</td>\n<td>List framework requirements, with optional client-side code/name filter.</td>\n<td><code class=\"language-text\">read:framework</code></td>\n<td>Admin, Control Manager, DevOps Engineer, Information Security Lead, Restricted Control Manager, Workspace Administrator</td>\n</tr>\n<tr>\n<td>List Personnel Groups</td>\n<td>List the personnel groups (teams / departments) in the account.</td>\n<td><code class=\"language-text\">read:personnel</code></td>\n<td>Admin, Information Security Lead, Personnel Compliance Manager, Workspace Administrator</td>\n</tr>\n<tr>\n<td>Search Monitoring Tests</td>\n<td>Search or list monitoring tests for a workspace.</td>\n<td><code class=\"language-text\">read:monitor-test</code></td>\n<td>Admin, Control Manager, DevOps Engineer, Information Security Lead, Restricted Control Manager, Workspace Administrator</td>\n</tr>\n<tr>\n<td>List Personnel</td>\n<td>List/search personnel (identity, employment, overall compliance) via OpenSearch.</td>\n<td><code class=\"language-text\">read:personnel</code></td>\n<td>Admin, Information Security Lead, Personnel Compliance Manager, Workspace Administrator</td>\n</tr>\n<tr>\n<td>Search Device Compliance</td>\n<td>Find personnel by a specific DEVICE compliance reason (agent, encryption, antivirus, etc.).</td>\n<td><code class=\"language-text\">read:personnel</code></td>\n<td>Admin, Information Security Lead, Personnel Compliance Manager, Workspace Administrator</td>\n</tr>\n<tr>\n<td>Search Personnel Compliance</td>\n<td>Find personnel by a specific PERSON compliance reason (policies, BG check, MFA, training, offboarding).</td>\n<td><code class=\"language-text\">read:personnel</code></td>\n<td>Admin, Information Security Lead, Personnel Compliance Manager, Workspace Administrator</td>\n</tr>\n<tr>\n<td>Update Personnel</td>\n<td>Update a person's employment record, identified by personnel_id, email, or resolved name.</td>\n<td><code class=\"language-text\">update:personnel</code></td>\n<td>Admin, Information Security Lead, Personnel Compliance Manager, Workspace Administrator</td>\n</tr>\n<tr>\n<td>List Policies</td>\n<td>List account policies, or a user's assigned policies when assigned<em>to</em>user is set.</td>\n<td><code class=\"language-text\">read:assigned-policies</code><br><code class=\"language-text\">read:policy</code></td>\n<td>Admin, Control Manager, DevOps Engineer, Employee, Information Security Lead, Internal Auditor, Knowledge Base, Personnel Compliance Manager, Policy Manager, Restricted Control Manager, Restricted Risk Manager, Reviewer, Risk Manager, Trust Center Manager, Trust Center Reviewer, Trust User, Workspace Administrator</td>\n</tr>\n<tr>\n<td>Search My Assigned Policies</td>\n<td>Search policies assigned to the authenticated user.</td>\n<td><code class=\"language-text\">read:assigned-policies</code></td>\n<td>Admin, Control Manager, DevOps Engineer, Employee, Information Security Lead, Internal Auditor, Knowledge Base, Personnel Compliance Manager, Policy Manager, Restricted Control Manager, Restricted Risk Manager, Reviewer, Risk Manager, Trust Center Manager, Trust Center Reviewer, Trust User, Workspace Administrator</td>\n</tr>\n<tr>\n<td>List Risk Registers</td>\n<td>List all risk registers for the account.</td>\n<td><code class=\"language-text\">read:risk-registers</code></td>\n<td>Admin, Information Security Lead, Restricted Risk Manager, Risk Manager</td>\n</tr>\n<tr>\n<td>Search Risks</td>\n<td>Search or list risks from the risk register.</td>\n<td><code class=\"language-text\">read:risk</code></td>\n<td>Admin, Information Security Lead, Restricted Risk Manager, Risk Manager, Risk Register Owner, Workspace Administrator</td>\n</tr>\n<tr>\n<td>Create Risk</td>\n<td>Create a new risk in a risk register.</td>\n<td><code class=\"language-text\">create:risk</code></td>\n<td>Admin, Information Security Lead, Restricted Risk Manager, Risk Manager, Risk Register Owner, Workspace Administrator</td>\n</tr>\n<tr>\n<td>Delete Risk</td>\n<td>Delete an existing risk from a risk register.</td>\n<td><code class=\"language-text\">delete:risk</code></td>\n<td>Admin, Information Security Lead, Restricted Risk Manager, Risk Manager, Risk Register Owner, Workspace Administrator</td>\n</tr>\n<tr>\n<td>Update Risk</td>\n<td>Update an existing risk.</td>\n<td><code class=\"language-text\">update:risk</code></td>\n<td>Admin, Information Security Lead, Restricted Risk Manager, Risk Manager, Risk Register Owner, Workspace Administrator</td>\n</tr>\n<tr>\n<td>Look Up User Identity</td>\n<td>Look up a Drata account (incl. roles / SSO identities) via Public API v2.</td>\n<td><code class=\"language-text\">read:user</code><br><code class=\"language-text\">read:users</code></td>\n<td>Admin, Control Manager, DevOps Engineer, Employee, Information Security Lead, Internal Auditor, Knowledge Base, Personnel Compliance Manager, Policy Manager, Restricted Control Manager, Restricted Risk Manager, Reviewer, Risk Manager, Risk Register Owner, Trust Center Manager, Trust Center Reviewer, Trust User, Workspace Administrator</td>\n</tr>\n<tr>\n<td>Get Vendor</td>\n<td>Get a single vendor by ID.</td>\n<td><code class=\"language-text\">read:vendor</code></td>\n<td>Admin, Information Security Lead, Restricted Risk Manager, Risk Manager, Workspace Administrator</td>\n</tr>\n<tr>\n<td>List Vendor Documents</td>\n<td>List documents for a vendor, with optional filtering.</td>\n<td><code class=\"language-text\">read:vendor-document</code></td>\n<td>Admin, Information Security Lead, Restricted Risk Manager, Risk Manager, Workspace Administrator</td>\n</tr>\n<tr>\n<td>List Vendor Security Reviews</td>\n<td>List security reviews for a vendor, with optional filtering.</td>\n<td><code class=\"language-text\">read:vendor-security-review</code></td>\n<td>Admin, Information Security Lead, Restricted Risk Manager, Risk Manager, Workspace Administrator</td>\n</tr>\n<tr>\n<td>List Vendors</td>\n<td>List third-party vendors for the account, with optional filtering.</td>\n<td><code class=\"language-text\">read:vendor</code></td>\n<td>Admin, Information Security Lead, Restricted Risk Manager, Risk Manager, Workspace Administrator</td>\n</tr>\n<tr>\n<td>Create Vendor</td>\n<td>Create a new vendor in the account.</td>\n<td><code class=\"language-text\">create:vendor</code></td>\n<td>Admin, Information Security Lead, Restricted Risk Manager, Risk Manager, Workspace Administrator</td>\n</tr>\n<tr>\n<td>Delete Vendor</td>\n<td>Permanently delete a vendor from the account.</td>\n<td><code class=\"language-text\">delete:vendor</code></td>\n<td>Admin, Information Security Lead, Restricted Risk Manager, Risk Manager, Workspace Administrator</td>\n</tr>\n<tr>\n<td>Update Vendor</td>\n<td>Update an existing vendor.</td>\n<td><code class=\"language-text\">update:vendor</code></td>\n<td>Admin, Information Security Lead, Restricted Risk Manager, Risk Manager, Workspace Administrator</td>\n</tr>\n<tr>\n<td>List Workspaces</td>\n<td>List all workspaces.</td>\n<td><code class=\"language-text\">read:workspace</code></td>\n<td>Admin, Control Manager, DevOps Engineer, Information Security Lead, Personnel Compliance Manager, Policy Manager, Restricted Control Manager, Restricted Risk Manager, Risk Manager, Risk Register Owner</td>\n</tr>\n</tbody>\n</table>\n<p><strong>Notes on roles:</strong></p>\n<ul>\n<li>\nFor read (\n<code class=\"language-text\">read:*</code>\n) scopes, the read-only variant of any listed role (e.g. Read-Only Admin, Read-Only Control Manager) has the same view access; read-only roles cannot use \n<code class=\"language-text\">create</code>\n, \n<code class=\"language-text\">update</code>\n, or \n<code class=\"language-text\">delete</code>\n scopes.\n</li>\n<li>\nThe Service User (integration) role also has equivalent access to every scope above.\n</li>\n<li>\nA user always receives only the intersection of the granted scope and their role's permissions in Drata.\n</li>\n</ul>\n<!-- END GENERATED: mcp-tools -->\n<h2 style=\"position:relative;\"><a href=\"#important-security-considerations\" aria-label=\"important security considerations permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><div class=\"hidden-anchor\" id=\"important-security-considerations\"></div>Important Security Considerations</h2>\n<blockquote>\n<p><strong>Access Control:</strong> End users can only access the intersection of what the OAuth scopes offer and what their roles provide them access to. They cannot access anything beyond what their roles inside the application give them access to while using the MCP.</p>\n</blockquote>\n<p>This means that even if an OAuth scope is granted, users are still limited by their role-based permissions within Drata.</p>\n<h2 style=\"position:relative;\"><a href=\"#next-steps\" aria-label=\"next steps permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><div class=\"hidden-anchor\" id=\"next-steps\"></div>Next Steps</h2>\n<p>After completing the OAuth configuration:</p>\n<ol>\n<li>\nTest the connection with your MCP client\n</li>\n<li>\nVerify that the appropriate data is accessible (see \n<a href=\"#best-practices-for-using-the-drata-mcp-server\">Best Practices</a>\n)\n</li>\n<li>\nMonitor usage and adjust scopes as needed\n</li>\n</ol>\n<h2 style=\"position:relative;\"><a href=\"#best-practices-for-using-the-drata-mcp-server\" aria-label=\"best practices for using the drata mcp server permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><div class=\"hidden-anchor\" id=\"best-practices-for-using-the-drata-mcp-server\"></div>Best Practices for Using the Drata MCP Server</h2>\n<h3 style=\"position:relative;\"><a href=\"#chatgpt-specific-tips\" aria-label=\"chatgpt specific tips permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><div class=\"hidden-anchor\" id=\"chatgpt-specific-tips\"></div>ChatGPT-Specific Tips</h3>\n<ul>\n<li>\nTag \n<strong>@Drata MCP</strong>\n in your message to explicitly invoke the connector\n</li>\n<li>\nUse \n<strong>Developer Mode</strong>\n for full tool access (read and write)\n</li>\n<li>\nWhen ChatGPT prompts for confirmation on write actions, review before approving\n</li>\n</ul>\n<h3 style=\"position:relative;\"><a href=\"#claude-specific-tips\" aria-label=\"claude specific tips permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><div class=\"hidden-anchor\" id=\"claude-specific-tips\"></div>Claude-Specific Tips</h3>\n<ul>\n<li>\nToggle the Drata connector on at the start of each conversation using the \"+\" menu\n</li>\n<li>\nYou can combine Drata with other connectors (e.g., Slack, Notion) in the same conversation for cross-tool workflows\n</li>\n</ul>\n<h3 style=\"position:relative;\"><a href=\"#cursor-specific-tips\" aria-label=\"cursor specific tips permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><div class=\"hidden-anchor\" id=\"cursor-specific-tips\"></div>Cursor-Specific Tips</h3>\n<ul>\n<li>\nSwitch Cursor to \n<strong>Agent mode</strong>\n (Ctrl/Cmd + .) for the best MCP tool integration\n</li>\n<li>\nReference Drata tools by name when prompting for precision\n</li>\n</ul>\n<h3 style=\"position:relative;\"><a href=\"#security-reminders\" aria-label=\"security reminders permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><div class=\"hidden-anchor\" id=\"security-reminders\"></div>Security Reminders</h3>\n<ul>\n<li>\nDrata's MCP server uses OAuth authentication — your credentials are never shared with the AI client\n</li>\n<li>\nThe AI client can only access data you have permissions for in Drata\n</li>\n<li>\nYou can revoke access at any time from your Drata account or from the AI client's connector settings\n</li>\n</ul>\n<h3 style=\"position:relative;\"><a href=\"#prompt-library\" aria-label=\"prompt library permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><div class=\"hidden-anchor\" id=\"prompt-library\"></div>Prompt Library</h3>\n<p>See the <a href=\"https://help.drata.com/en/articles/13379899-drata-mcp-setup-usage-guide\">Drata MCP Setup &#x26; Usage Guide</a> for a full prompt library and additional usage tips.</p>\n<h2 style=\"position:relative;\"><a href=\"#privacy\" aria-label=\"privacy permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><div class=\"hidden-anchor\" id=\"privacy\"></div>Privacy</h2>\n<p>The Drata MCP server operates on your own Drata data, in your own session, through your own OAuth grant — the connection stores no credentials of its own, and what any request can reach is bounded by the scopes you grant and your Drata role. Your data is handled under Drata's <a href=\"https://drata.com/privacy\">Privacy Notice</a>. For how Drata secures its platform, see the <a href=\"https://trust.drata.com\">Drata Trust Center</a>.</p>\n<h2 style=\"position:relative;\"><a href=\"#support\" aria-label=\"support permalink\" class=\"anchor before\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a><div class=\"hidden-anchor\" id=\"support\"></div>Support</h2>\n<ul>\n<li>\n<strong>Documentation and help:</strong>\n \n<a href=\"https://help.drata.com\">help.drata.com</a>\n</li>\n<li>\n<strong>Security questions or reports:</strong>\n \n<a href=\"mailto:security@drata.com\">security@drata.com</a>\n</li>\n</ul>","headings":[{"value":"MCP Server","depth":1},{"value":"Overview","depth":2},{"value":"Prerequisites","depth":2},{"value":"Configuration Steps","depth":2},{"value":"1. Configure the Drata MCP Server","depth":3},{"value":"2. Configure Your MCP Client","depth":3},{"value":"Client-Specific Setup Instructions","depth":4},{"value":"MCP Tools","depth":2},{"value":"Important Security Considerations","depth":2},{"value":"Next Steps","depth":2},{"value":"Best Practices for Using the Drata MCP Server","depth":2},{"value":"ChatGPT-Specific Tips","depth":3},{"value":"Claude-Specific Tips","depth":3},{"value":"Cursor-Specific Tips","depth":3},{"value":"Security Reminders","depth":3},{"value":"Prompt Library","depth":3},{"value":"Privacy","depth":2},{"value":"Support","depth":2}]},"contentItem":{"data":{"lastModified":"2026-09-03T23:32:02.000Z","enableToc":null,"disableLastModified":null,"tocMaxDepth":null,"requestLogin":false}},"siteConfig":{"enableToc":false,"disableLastModified":false,"tocMaxDepth":4}},"pageContext":{"matchPath":"","id":"426fba61-52a9-5047-bbc6-07abbd2e3526__redocly content/developer-portal/v2/mcp-server/","seo":{"title":"MCP Server","description":null,"image":"","keywords":null,"jsonLd":null,"lang":null,"siteUrl":null},"pageId":"developer-portal/v2/mcp-server.md","pageBaseUrl":"/developer-portal/v2/mcp-server","type":"markdown","toc":{"enable":true,"maxDepth":4,"headings":[{"depth":1,"value":"MCP Server","id":"mcp-server"},{"depth":2,"value":"Overview","id":"overview"},{"depth":2,"value":"Prerequisites","id":"prerequisites"},{"depth":2,"value":"Configuration Steps","id":"configuration-steps"},{"depth":3,"value":"1. Configure the Drata MCP Server","id":"1-configure-the-drata-mcp-server"},{"depth":3,"value":"2. Configure Your MCP Client","id":"2-configure-your-mcp-client"},{"depth":4,"value":"Client-Specific Setup Instructions","id":"client-specific-setup-instructions"},{"depth":2,"value":"MCP Tools","id":"mcp-tools"},{"depth":2,"value":"Important Security Considerations","id":"important-security-considerations"},{"depth":2,"value":"Next Steps","id":"next-steps"},{"depth":2,"value":"Best Practices for Using the Drata MCP Server","id":"best-practices-for-using-the-drata-mcp-server"},{"depth":3,"value":"ChatGPT-Specific Tips","id":"chatgpt-specific-tips"},{"depth":3,"value":"Claude-Specific Tips","id":"claude-specific-tips"},{"depth":3,"value":"Cursor-Specific Tips","id":"cursor-specific-tips"},{"depth":3,"value":"Security Reminders","id":"security-reminders"},{"depth":3,"value":"Prompt Library","id":"prompt-library"},{"depth":2,"value":"Privacy","id":"privacy"},{"depth":2,"value":"Support","id":"support"}]},"data":{"title":""},"catalogInfo":null,"link":"/developer-portal/v2/mcp-server/","sidebarName":"training","isLanding":false,"showPrevButton":null,"showNextButton":null,"apiVersions":null,"apiVersionId":null,"isDefaultApiVersion":null}},"staticQueryHashes":["1123603147","1302185487","1344209882","1398840060","1520077861","1975142765","2667623876","2950305614","3240152602","3743992808","561138138"]}