Claude Code Integration¶
This page explains how to connect misp-workbench to Claude Code so you can query threat intelligence directly from the terminal.
1. Get your MCP token¶
Generate a scoped MCP token from the /mcp/config endpoint:
The response contains a ready-to-use configuration:
{
"mcpServers": {
"misp-workbench": {
"type": "http",
"url": "https://your-instance/mcp",
"headers": {
"Authorization": "Bearer <mcp-scoped-token>"
}
}
}
}
Copy the Bearer token value — you'll use it in the next step.
2. Add the MCP server¶
Run claude mcp add from any terminal:
claude mcp add --transport http \
--header "Authorization: Bearer <mcp-scoped-token>" \
misp-workbench https://your-instance/mcp
Scope options¶
By default the server is added at project scope (stored in .mcp.json in the current directory, suitable for team repos). To add it at user scope instead (available in all projects, stored in ~/.claude.json):
claude mcp add --transport http --scope user \
--header "Authorization: Bearer <mcp-scoped-token>" \
misp-workbench https://your-instance/mcp
Use an environment variable for the token
Avoid hardcoding the token in your shell history. Set it as an env var first:
3. Verify the connection¶
List registered MCP servers and confirm misp-workbench appears:

Then start a session and check the server is reachable:
In the Claude Code session, type /mcp to see connected servers and their tool counts.
Local dev (no auth)¶
When running the dev stack locally with MCP_AUTH_ENABLED=false (the default), no token is needed:
Example session¶
Once connected, you can ask questions in natural language:
> search for ransomware events from the last 30 days
> look up the indicator 185.220.101.45 and check for correlations
> generate a threat report for APT28
> enrich 8.8.8.8 with geolocation
Claude will automatically select the appropriate tools (search_events, search_attributes, get_correlations, enrich_indicator, etc.) and combine results into a response.
See MCP Server Overview for the full list of available tools, resources, and prompts.