What is the SentinelOne MCP MCP server?
Every SentinelOne v2.1 management endpoint, plus an offline SQLite store and cross-entity analytics
How to install SentinelOne MCP
Copy-paste configuration for popular MCP clients.
SENTINELONE_API_TOKENrequiredsecretSet the SENTINELONE_API_TOKEN credential for the SentinelOne MCP server.
{
"mcpServers": {
"sentinelone-mcp": {
"command": "https://github.com/Servosity/msp-skills/releases/download/sentinelone-v0.1.0/sentinelone-mcp.mcpb",
"args": [],
"env": {
"SENTINELONE_API_TOKEN": "<YOUR_SENTINELONE_API_TOKEN>"
}
}
}
}{
"mcpServers": {
"sentinelone-mcp": {
"command": "https://github.com/Servosity/msp-skills/releases/download/sentinelone-v0.1.0/sentinelone-mcp.mcpb",
"args": [],
"env": {
"SENTINELONE_API_TOKEN": "<YOUR_SENTINELONE_API_TOKEN>"
}
}
}
}{
"mcpServers": {
"sentinelone-mcp": {
"command": "https://github.com/Servosity/msp-skills/releases/download/sentinelone-v0.1.0/sentinelone-mcp.mcpb",
"args": [],
"env": {
"SENTINELONE_API_TOKEN": "<YOUR_SENTINELONE_API_TOKEN>"
}
}
}
}{
"servers": {
"sentinelone-mcp": {
"type": "stdio",
"command": "https://github.com/Servosity/msp-skills/releases/download/sentinelone-v0.1.0/sentinelone-mcp.mcpb",
"args": [],
"env": {
"SENTINELONE_API_TOKEN": "<YOUR_SENTINELONE_API_TOKEN>"
}
}
}
}claude mcp add sentinelone-mcp --env SENTINELONE_API_TOKEN=<YOUR_SENTINELONE_API_TOKEN> -- https://github.com/Servosity/msp-skills/releases/download/sentinelone-v0.1.0/sentinelone-mcp.mcpbRelated MCP servers
Abnormal Security email threats, cases, and reporting in your terminal and your AI agents.
View repository →The first real CLI for the Acronis Cyber Protect Cloud platform - every tenant, agent, and usage
View repository →Every Action1 endpoint, plus fleet-wide patch and vulnerability views across all your organizations.
View repository →The first CLI for Afi SaaS backup - full public-API coverage plus the fleet-wide coverage
View repository →AppDirect marketplace operations with an offline mirror and cross-company billing reconciliation.
View repository →Every Atera RMM + PSA endpoint, plus a local SQLite mirror that answers fleet-health, SLA, and
View repository →