MCP Server for TheHive
MCP Server for TheHive. The for thehive mcp server wraps that behind the Model Context Protocol, so an assistant can use it through 4 defined tools rather than through you.
An MCP (Model Context Protocol) server that provides AI models and automation tools with access to TheHive incident response platform.
This server acts as a bridge between MCP clients (like AI assistants) and TheHive, allowing them to:
Everything the assistant can do here goes through one of these:
Prerequisites — The Prerequisites tool exposed by this serverDependencies — The Dependencies tool exposed by this serverTesting — The project includes a comprehensive suite of integration tests that leverage a mock TheHive server. This mock server simulates the TheHive APILogging — The Logging tool exposed by this serverSetup follows the usual MCP pattern — install or clone the server, register it in your client's configuration file, restart the client.
You will need 2 environment variables: THEHIVE_URL, THEHIVE_API_TOKEN. The server will not start without them, which is usually why the tools fail to appear on a first run. Keep credentials in your client's env block or a secrets manager rather than in a file you might commit.
Plenty of developer tooling servers cover similar ground. The differences that matter in practice are scope of access and how much setup stands between you and a working tool call. For TheHive's toolset — Prerequisites, Dependencies, Testing and 1 more — is a fair guide to whether it matches your workflow. It is maintained by gbrigandi; worth a glance at recent repository activity before you build anything load-bearing on it.
SyncDev reviews every entry in this directory against the project's own documentation before publishing, and revisits them as servers change.
| Tool | What it does |
|---|---|
| Prerequisites | The Prerequisites tool exposed by this server. |
| Dependencies | The Dependencies tool exposed by this server. |
| Testing | The project includes a comprehensive suite of integration tests that leverage a mock TheHive server. This mock server simulates the TheHive API, allowing for isolated and repeatable testing of the MCP server's functional |
| Logging | The Logging tool exposed by this server. |
| Variable | Description | Required |
|---|---|---|
| THEHIVE_URL | Endpoint or connection string the server talks to. | Yes |
| THEHIVE_API_TOKEN | Credential the server authenticates with. | Yes |
Kill hallucinated APIs — version-accurate, up-to-date library documentation injected straight into context.
Microsoft's official browser automation server — drive a real browser through the accessibility tree, no screenshots needed.
GitHub's official server — repos, issues, pull requests, Actions and code security, straight from your assistant.
Issue tracking at the speed of conversation — Linear's official hosted server with OAuth and zero install.
Local repository surgery — status, diffs, commits, branches and history for any repo on disk.
Timezone sanity for AI — current time anywhere and correct conversions, without the model doing date math.