For TheHive MCP Server

MCP Server for TheHive

Local serverstdioGo

What is the For TheHive MCP server?

MCP Server for TheHive. The for thehive mcp server wraps that behind the Model Context Protocol, so an assistant can use it through 4 defined tools rather than through you.

What it actually does

An MCP (Model Context Protocol) server that provides AI models and automation tools with access to TheHive incident response platform.

This server acts as a bridge between MCP clients (like AI assistants) and TheHive, allowing them to:

Its toolset

Everything the assistant can do here goes through one of these:

  • Prerequisites — The Prerequisites tool exposed by this server
  • Dependencies — The Dependencies tool exposed by this server
  • Testing — The project includes a comprehensive suite of integration tests that leverage a mock TheHive server. This mock server simulates the TheHive API
  • Logging — The Logging tool exposed by this server

Adding it to your client

Setup follows the usual MCP pattern — install or clone the server, register it in your client's configuration file, restart the client.

Configuration

You will need 2 environment variables: THEHIVE_URL, THEHIVE_API_TOKEN. The server will not start without them, which is usually why the tools fail to appear on a first run. Keep credentials in your client's env block or a secrets manager rather than in a file you might commit.

  • Access to a TheHive 5 instance - Valid TheHive API token

When to reach for it

Plenty of developer tooling servers cover similar ground. The differences that matter in practice are scope of access and how much setup stands between you and a working tool call. For TheHive's toolset — Prerequisites, Dependencies, Testing and 1 more — is a fair guide to whether it matches your workflow. It is maintained by gbrigandi; worth a glance at recent repository activity before you build anything load-bearing on it.

SyncDev reviews every entry in this directory against the project's own documentation before publishing, and revisits them as servers change.

Caveats

  • It runs with your machine's permissions. That is convenient and also the reason to think about what you point it at before you approve a tool call.
  • Missing credentials fail quietly in some clients — if no tools show up, check the environment block first.
  • MCP clients confirm each tool call by default. Leave that on until you have watched what the for thehive mcp server does with a few real requests.

Available tools

ToolWhat it does
PrerequisitesThe Prerequisites tool exposed by this server.
DependenciesThe Dependencies tool exposed by this server.
TestingThe project includes a comprehensive suite of integration tests that leverage a mock TheHive server. This mock server simulates the TheHive API, allowing for isolated and repeatable testing of the MCP server's functional
LoggingThe Logging tool exposed by this server.

Configuration

  • Access to a TheHive 5 instance - Valid TheHive API token
VariableDescriptionRequired
THEHIVE_URLEndpoint or connection string the server talks to.Yes
THEHIVE_API_TOKENCredential the server authenticates with.Yes

Example prompts to try

  • Use For TheHive to Prerequisites.
  • Use For TheHive to Dependencies.
  • Use For TheHive to Testing.

Frequently asked questions

Log into your TheHive instance, go to User Settings → API Keys, click Create API Key, and copy the generated token.