NinjaOne MCP Server
io.github.wyre-technology/ninjaone-mcp
MCP server for NinjaOne RMM — manage devices, organizations, alerts, and tickets
What is the NinjaOne MCP server?
The NinjaOne MCP server provides Model Context Protocol access to NinjaOne remote monitoring and management (RMM) platform. It enables AI agents to list and manage devices, organizations, alerts, and tickets through a hierarchical tool-loading architecture that reduces cognitive load and improves performance.
This server connects Claude and other AI agents to NinjaOne RMM, allowing you to query device status, manage endpoints, view alerts, and handle service tickets programmatically. It uses a decision-tree navigation model where you first select a domain (devices, organizations, alerts, or tickets), then access domain-specific tools—keeping the interface organized and responsive.
How to install NinjaOne
Copy-paste configuration for popular MCP clients.
NINJAONE_CLIENT_IDrequiredNinjaOne OAuth 2.0 Client ID
NINJAONE_CLIENT_SECRETrequiredsecretNinjaOne OAuth 2.0 Client Secret
NINJAONE_REGIONNinjaOne region: 'us' (default), 'eu', or 'oc'
MCP_TRANSPORTTransport mode for the server. Set to 'stdio' for local CLI use; the image defaults to 'http' for gateway hosting.
AUTH_MODECredential source: 'env' reads vars locally, 'gateway' expects header injection from the WYRE MCP Gateway.
LOG_LEVELLog verbosity: debug, info, warn, error
Tools & capabilities
Tools this server exposes to the agent.
ninjaone_navigate— Select a domain to work with (devices, organizations, alerts, tickets)ninjaone_status— Show current state and credential statusninjaone_back— Return to main menu when in a domainninjaone_devices_list— List devices, filterable by organization, device class, and online status with paginationninjaone_devices_get— Get device detailsninjaone_devices_reboot— Schedule a device rebootninjaone_devices_services— List Windows services on a deviceninjaone_devices_alerts— Get device-specific alertsninjaone_devices_activities— View device activity logninjaone_devices_get_custom_fields— Get device custom fieldsninjaone_devices_update_custom_fields— Update device custom fieldsninjaone_organizations_list— List organizationsninjaone_organizations_get— Get organization detailsninjaone_organizations_create— Create a new organizationninjaone_organizations_locations— List organization locationsninjaone_organizations_devices— List devices for an organization with paginationninjaone_organizations_get_custom_fields— Get organization custom fieldsninjaone_organizations_update_custom_fields— Update organization custom fieldsninjaone_alerts_list— List alerts with filtersninjaone_alerts_get— Get a single alert by UID with interactive card rendering in MCP Apps hosts
Use cases
- List all devices across your fleet and filter by organization, device class, or online status
- Reboot endpoints remotely and monitor device activity logs
- View and reset alerts across devices or organizations
- Create, update, and comment on service tickets from your NinjaOne board
- Retrieve and update custom fields on devices and organizations
NinjaOne MCP server FAQ
It's an MCP server that connects Claude and other AI agents to NinjaOne RMM, enabling programmatic access to devices, organizations, alerts, and tickets through a hierarchical navigation interface.
The server itself is open-source (Apache-2.0 licensed), but you need a NinjaOne account and API credentials (Client ID and Secret) to use it. NinjaOne pricing depends on your subscription plan.
Add the server to your `claude_desktop_config.json` with the `npx @wyre-ai/ninjaone-mcp` command and set environment variables for `NINJAONE_CLIENT_ID`, `NINJAONE_CLIENT_SECRET`, and optionally `NINJAONE_REGION`.
You need NinjaOne OAuth 2.0 credentials: create an API application in your NinjaOne dashboard (Administration > Apps > API) with Client Credentials grant type, then set the Client ID and Secret as environment variables.
Yes, the server supports one-click deployment to DigitalOcean App Platform or Cloudflare Workers. Both require a GitHub Personal Access Token with `read:packages` scope for the build process.
The server supports six regions: `us` (default), `eu`, `oc`, `ca`, `us2`, and `fed`. Set the `NINJAONE_REGION` environment variable to specify your region.
README (reference)
Source of truth, from the repository.
NinjaOne MCP Server
A Model Context Protocol (MCP) server for interacting with NinjaOne, featuring a decision tree architecture for efficient tool loading.
One-Click Deployment
[!IMPORTANT] Before you click: this server depends on
@wyre-ai/node-ninjaone, which is hosted on the GitHub Packages npm registry. GitHub Packages has no anonymous access — even though the package is public, everynpm installneeds a token. The cloud builder runsnpm installfor you, so you must give it one, or the build fails withnpm error 401 Unauthorized ... npm.pkg.github.com.
- Create a GitHub Personal Access Token with the
read:packagesscope (classic token). Any GitHub account works — you do not need to be a member of thewyre-aiorg to read its public packages.- Add it as a build variable when prompted by the deploy flow:
- Cloudflare Workers → set a build variable named
NODE_AUTH_TOKENto your PAT (Workers → Settings → Build → Variables and Secrets).- DigitalOcean App Platform → set an encrypted env var named
GITHUB_TOKENwith scope Build Time to your PAT (the.do/app.yamlalready declares it).
[!NOTE] Both targets run the full MCP server. DigitalOcean builds the Docker image and serves it over HTTP; Cloudflare Workers serves the same server via the SDK's Web Standard Streamable HTTP transport (
src/worker.ts). After deploying, set your NinjaOne credentials as secrets —NINJAONE_CLIENT_ID,NINJAONE_CLIENT_SECRET, and optionallyNINJAONE_REGION— or setAUTH_MODE=gatewayto take credentials per-request fromX-Ninja-*headers. The MCP endpoint is/mcp;/healthis an unauthenticated liveness probe.
Architecture
This MCP server uses a hierarchical tool loading approach instead of exposing all tools upfront:
- Navigation Phase: Initially exposes only a navigation tool (
ninjaone_navigate) - Domain Selection: User selects a domain (devices, organizations, alerts, tickets)
- Domain Tools: Server exposes domain-specific tools after selection
- Lazy Loading: Domain handlers and the NinjaOne client are loaded on-demand
This architecture provides:
- Reduced cognitive load (fewer tools to choose from)
- Faster initial load times
- Better organization of related operations
- Clear navigation state
Installation
This package is published to the GitHub Packages npm registry, which requires a token even for public packages. Authenticate once, then install:
# Authenticate npm to GitHub Packages (token needs the read:packages scope)
export NODE_AUTH_TOKEN=$(gh auth token) # or a PAT with read:packages
npm install @wyre-ai/ninjaone-mcp
The repo's .npmrc already points the @wyre-ai scope at GitHub Packages and
reads the token from NODE_AUTH_TOKEN, so no further config is needed. The same applies
to npx @wyre-ai/ninjaone-mcp below. Prefer a zero-setup option? Use the prebuilt
container image (ghcr.io/wyre-ai/ninjaone-mcp) or the .mcpb bundle attached to
each release.
Configuration
Set the following environment variables:
| Variable | Required | Description |
|---|---|---|
NINJAONE_CLIENT_ID | Yes | OAuth 2.0 Client ID |
NINJAONE_CLIENT_SECRET | Yes | OAuth 2.0 Client Secret |
NINJAONE_REGION | No | Region: us (default), eu, oc, ca, us2, or fed |
NINJAONE_SCOPES | No | OAuth scopes to request. Defaults to monitoring,management. Set this if your API app is granted a narrower set — see OAuth scopes |
NinjaOne API Regions
| Region | Base URL |
|---|---|
us | https://app.ninjarmm.com |
eu | https://eu.ninjarmm.com |
oc | https://oc.ninjarmm.com |
ca | https://ca.ninjarmm.com |
us2 | https://us2.ninjarmm.com |
fed | https://fed.ninjarmm.com |
Usage
Running Standalone
# Set credentials
export NINJAONE_CLIENT_ID="your-client-id"
export NINJAONE_CLIENT_SECRET="your-client-secret"
export NINJAONE_REGION="us"
# Run the server
npx @wyre-ai/ninjaone-mcp
Claude Desktop Configuration
Add to your Claude Desktop claude_desktop_config.json:
{
"mcpServers": {
"ninjaone": {
"command": "npx",
"args": ["@wyre-ai/ninjaone-mcp"],
"env": {
"NINJAONE_CLIENT_ID": "your-client-id",
"NINJAONE_CLIENT_SECRET": "your-client-secret",
"NINJAONE_REGION": "us"
}
}
}
}
Docker
docker build -t ninjaone-mcp .
docker run -e NINJAONE_CLIENT_ID=xxx -e NINJAONE_CLIENT_SECRET=xxx -e NINJAONE_REGION=us ninjaone-mcp
Available Domains
Devices
Manage endpoints, reboot devices, view services and alerts.
Tools:
ninjaone_devices_list- List devices, filterable by organization, device class, and online status. Paginated: a full page returnshasMore: trueand acursorto pass back for the next page.ninjaone_devices_get- Get device detailsninjaone_devices_reboot- Schedule a device rebootninjaone_devices_services- List Windows services on a deviceninjaone_devices_alerts- Get device-specific alertsninjaone_devices_activities- View device activity logninjaone_devices_get_custom_fields- Get device custom fieldsninjaone_devices_update_custom_fields- Update device custom fields
Organizations
Manage customer organizations and their resources.
Tools:
ninjaone_organizations_list- List organizationsninjaone_organizations_get- Get organization detailsninjaone_organizations_create- Create a new organizationninjaone_organizations_locations- List organization locationsninjaone_organizations_devices- List devices for an organization.device_classis sent upstream asdf=class=<NodeClass>and applied to each page. The response is{ devices, count, hasMore, cursor }, not a bare array.ninjaone_organizations_get_custom_fields- Get organization custom fieldsninjaone_organizations_update_custom_fields- Update organization custom fields
Alerts
View and manage alerts across all devices.
Tools:
ninjaone_alerts_list- List alerts with filtersninjaone_alerts_get- Get a single alert by UID (renders as an interactive card in MCP Apps hosts)ninjaone_alerts_reset- Reset/dismiss a single alertninjaone_alerts_reset_all- Reset all alerts for a device or organizationninjaone_alerts_summary- Get alert count summary
Features:
- Interactive Alert Card (MCP Apps, SEP-1865):
ninjaone_alerts_getrenders as an interactive card in MCP Apps hosts (Claude Desktop/web) with an in-card "Reset alert" round-trip vianinjaone_alerts_reset; neutral by default, brandable viawindow.__BRAND__injection orMCP_BRAND_*env vars; plain-JSON behavior is unchanged in other hosts
Tickets
Manage service tickets.
Tools:
ninjaone_tickets_list- List tickets from a board (requiresboard_id;status/organization_id/device_idfilters are applied client-side, see notes below)ninjaone_tickets_get- Get ticket detailsninjaone_tickets_create- Create a new ticketninjaone_tickets_update- Update an existing ticketninjaone_tickets_add_comment- Add a comment to a ticketninjaone_tickets_comments- Get ticket commentsninjaone_tickets_boards_list- List ticket boards (to discoverboard_idvalues)
Note: NinjaOne queries tickets per board, and board IDs vary by tenant — board 1 is not always the "All Tickets" board, so
ninjaone_tickets_listrequires an explicitboard_idrather than silently guessing one. Discover IDs withninjaone_tickets_boards_list; on tenants where that endpoint returns 404, read the numeric ID from the board link's URL in the NinjaOne web UI (e.g. the "All tickets" sidebar link).Note: NinjaOne's board-run API cannot filter tickets by status, organization, or device server-side (attempting to throws a generic
Bad request).ninjaone_tickets_listtherefore applies those filters client-side within one board page. The response separatescount(matches in this page) fromscanned(tickets examined) and includeshasMore/cursor— page through untilhasMoreisfalseto get every match, and never treat a single page'scountas a board-wide total. Status is matched against each ticket's status display name, so custom board statuses may not map to theOPEN/IN_PROGRESS/WAITING/CLOSEDvalues.Similarly,
ninjaone_devices_listfilters byorganization_idthrough NinjaOne's dedicated per-organization endpoint (the generaldf=orgdevice filter is unreliable and can silently return the full fleet). That endpoint documents no device-class query parameter.ninjaone_devices_list(when an organization is set) andninjaone_organizations_devicesstill senddevice_classupstream asdf=class=<NodeClass>(a namednodeClassparameter is ignored) and apply class and online filters to each page.countis matches in the page; keep paging whilehasMoreis true.device_classuses NinjaOne node classes (LINUX_WORKSTATION,VMWARE_VM_HOST,NMS_SWITCH, …) —LINUX,VMWARE_VM, andNMSare not valid.
Navigation Tools
Always available:
ninjaone_navigate- Select a domain to work withninjaone_status- Show current state and credential statusninjaone_back- Return to main menu (when in a domain)
Example Workflow
User: Check my devices
Claude: [calls ninjaone_navigate with domain="devices"]
-> Navigated to devices domain. Available tools: ...
User: List all Windows servers
Claude: [calls ninjaone_devices_list with device_class="WINDOWS_SERVER"]
-> [device list results]
User: Now show me alerts
Claude: [calls ninjaone_back]
-> Navigated back to main menu.
[calls ninjaone_navigate with domain="alerts"]
-> Navigated to alerts domain.
Authentication
NinjaOne uses OAuth 2.0 for authentication. You need to:
- Log in to your NinjaOne dashboard
- Go to Administration > Apps > API
- Create a new API application (application platform: API Services, grant type Client Credentials)
- Grant it the scopes you need — see below
- Note the Client ID and Client Secret
- Configure the environment variables
The client library handles token refresh automatically.
OAuth scopes
By default the server requests monitoring management. Which scopes you actually
need depends on what you use:
| Scope | Needed for |
|---|---|
monitoring | All read operations — listing devices, organizations, alerts, and tickets |
management | Write operations — rebooting devices, resetting alerts, creating/updating tickets and organizations |
control | Not used by this server |
If your API app is granted fewer scopes than the default, set NINJAONE_SCOPES
to match. NinjaOne rejects a token request that asks for a scope the app was
never granted — it returns 400 invalid_scope rather than narrowing the grant —
so the failure happens at the token exchange and every tool call fails, including
reads. For a monitoring-only app:
export NINJAONE_SCOPES="monitoring"
Values may be comma- or space-separated and are case-insensitive. In gateway
deployments the same value can be supplied per request via the X-Ninja-Scopes
header.
License
Apache-2.0
Related MCP servers

Nutanix Prism Central
Multitenant Streamable HTTP bridge over Nutanix's official v4 API MCP server (Prism Central).

Proofpoint
MCP server for Proofpoint TAP — threat intelligence, forensics, quarantine, and email security.

QuickBooks Online
MCP server for QuickBooks Online — accounts, customers, invoices, bills, and reports.

RocketCyber
MCP server for RocketCyber Managed SOC — incidents, alerts, agents, and customer telemetry.

Rootly
MCP server for Rootly — incidents, alerts, escalations, and post-incident reports.

SaaS Alerts
MCP server for Kaseya SaaS Alerts — SaaS security monitoring for M365 & Google Workspace.