Skip to content
Last updated

Atlas MCP Quick Start

Connect an AI assistant to your live Tanium environment and get a real answer about your fleet — in under five minutes.

CVE-2025-29824 just dropped. Am I exposed?
tanium_patch_tools, tanium_comply_tools
1,284 of 41,905 endpoints are running an affected Windows build.
63 are internet-facing and reachable from outside your perimeter.
Here's the staged remediation plan, sequenced by exposure…
This is not the Developer Docs MCP Server

The Tanium Developer Documentation MCP Server searches this site's content and never touches your environment. The Atlas MCP Server, covered here, operates your live Tanium environment directly.

What You Can Ask It

Friday, 3:45 PM

"CVE-2025-29824 just dropped. Am I exposed, and what do I patch first?"

From "I have no idea" to a sequenced remediation plan in under a minute.

Stop guessing why it's slow

"Endpoint XYZ has been sluggish all week. What's actually going on?"

From a support ticket with no leads to a root-cause read in minutes, not an afternoon of pivoting between consoles.

Act as a SOC 2 auditor

"Walk through our endpoint compliance posture like an external SOC 2 auditor would."

From a week of screenshotting reports before an audit to a live, question-driven walkthrough.

Past Win10 EOL

"How many endpoints are still on an OS past end-of-life, and what's our exposure trend?"

From a static spreadsheet nobody trusts to a report you can actually show your boss.

Before You Start

You'll need:

  • A licensed Atlas MCP Server, plus the Tanium solutions whose tools you want to use.
  • Your Tanium Cloud domain (the <domain> in https://<domain>-api.cloud.tanium.com).
  • An MCP-compatible client — pick your tab below.

Step 1 below requires the Oauth Clients write privilege (carried by the Admin reserved role). No admin access? Ask your Tanium admin for the endpoint URL and a client ID (and secret, if applicable), then skip to step 2 in your tab below.

Mind the -api in the domain

The MCP endpoint is https://<domain>-api.cloud.tanium.com/mcp — note the -api. The most common setup failure is using the console URL, https://<domain>.cloud.tanium.com, instead. Once you've registered an OAuth client, you can derive the endpoint from its authorization URL: swap /oauth/authorize for /mcp.

Set It Up

1. Register the OAuth client

In Tanium Atlas, click the Command Palette icon in the far left nav, search for oauth clients, and select the OAuth Clients template. Fill in the Register OAuth Client panel:

FieldValue
NameAnything — for example, Claude Desktop
Grant typeAuthorization Code
OAuth 2.0 SupportOff — Claude is a public client: it uses OAuth 2.1 and takes no client secret
Redirect URIshttps://claude.ai/api/mcp/auth_callback and https://claude.com/api/mcp/auth_callback — add both. One connector then covers Claude Desktop and Claude on the web.
Allowed rolesMCP Read Only User, Interact Power User, Patch Read Only User, and Performance Read Only User

Registration returns a Client ID, an authorization URL, and a token URL. Keep the client ID.

2. Add the custom connector

In Claude, open Settings > Connectors, click Add custom connector, and fill in:

FieldValue
NameAnything — for example, Tanium Atlas MCP
Remote MCP server URLhttps://<domain>-api.cloud.tanium.com/mcp
Client IDFrom step 1
Client secretLeave empty

Claude runs preflight checks against the URL and detects that the server uses pre-registered OAuth clients. Click Add.

3. Connect and authorize

Back in Settings > Connectors, click Connect in your connector's row. The Tanium consent page opens in your browser: pick the persona whose permissions the client should act with, then authorize. Your tools show up in Claude as soon as consent completes.

Claude Desktop troubleshooting

  • The consent page says No role overlap for any persona — none of the OAuth client's allowed roles match a role on any persona you can select. Add an overlapping role to the client.
  • The connector won't connect — check the connector log at ~/Library/Logs/Claude/mcp-server-tanium-mcp-router.log for the specific error.

Register a separate OAuth client for each integration so you can scope and revoke them independently.

Your First Three Prompts

A ladder of read-only prompts, safe to run against any environment:

  1. "How many endpoints do I have, and how many are online right now?" — a 30-second fleet count that proves the pipe is open.
  2. "Run a proactive ops health check on my environment." — a prioritized read of platform, patch, and performance health.
  3. "Which endpoints run an OS that's end-of-life or within 12 months of it, and which should I upgrade first?" — a ranked upgrade list, the one to show your boss.

Control What It Can Do

Read-only mode and toolset scoping — set whichever your client supports:

  • Headers (preferred): X-Tanium-MCP-Toolsets: patch,asset and/or X-Tanium-MCP-Readonly: true
  • Path suffixes (when your client only exposes a URL field): /x/<toolset>, /readonly, or /x/<toolset>/readonly

Two skills come pre-baked with every Atlas MCP Server:

  • Tanium Expert routes any question to the right tool across modules, so nobody has to memorize a tool taxonomy.
  • Risk Evaluator is a mandatory gate on every state-changing call. It grades risk as safe, elevated, or high, and demands explicit confirmation before anything irreversible.

Together, these are the strongest available answer to "can I trust an agent against my production environment?"

FAQ

No tools show up when I connect. Why?
Effective permissions are the intersection of the roles on your OAuth client and the roles on your user. Check that both carry the roles you expect. If you see 403 RBACInsufficientPrivilege, your session token lacks the Atlas MCP Server Api execute permission that those roles grant.
I can't get an answer to a question about my endpoints. Why?
You're likely missing the Interact Power User role. MCP Read Only User alone lets you connect, but issuing questions to endpoints requires Interact Power User too (unless your role already carries Atlas MCP Server Api execute, such as Admin, which makes MCP Read Only User redundant).
The consent page says 'No role overlap for any persona'. What does that mean?
None of the OAuth client's allowed roles match a role assigned to any persona you can select, so there's nothing to consent to. Edit the OAuth client and add a role that overlaps with one of your personas.
A tool I expect isn't in the catalog. Where is it?
Work through four things: the Tanium solution that provides the tool has to be in your license, your user's roles need the permissions the tool requires (a solution's tools need that solution's permissions; for example, Patch Read Only User grants Patch's read tools), the OAuth client's allowed roles need them too, and after a server restart the catalog takes about a minute to refresh — wait and retry.
My refresh token was rejected. What happened?
Tanium revokes the whole token family when a refresh token is used after revocation, which can happen through token rotation or an explicit revocation. Sign out of your MCP client, sign back in, and repeat the consent flow.
My client only supports stdio. Can I still connect?
No. The Atlas MCP Server only supports Streamable HTTP — stdio is not supported, and there's no proxy for it.
I registered my OAuth client with the wrong redirect URI. Now what?
Redirect URIs are editable after registration. Edit the OAuth client and update it.
I lost my client secret. Can I retrieve it?
No, it's shown only once at registration. Register a new OAuth client instead.
My firewall is blocking the connection. What do I need to allow?
Allow outbound 443 to these five endpoints, where <domain> is your Tanium Cloud domain: • https://<domain>-api.cloud.tanium.com/.well-known/oauth-authorization-server • https://<domain>-api.cloud.tanium.com/.well-known/oauth-protected-resource • https://<domain>-api.cloud.tanium.com/oauth/authorize • https://<domain>-api.cloud.tanium.com/oauth/token • https://<domain>-api.cloud.tanium.com/oauth/revoke
Does using the Atlas MCP Server consume AI credits?
Yes, for the tools that ask a natural-language question against your fleet: atlas-ask-fleet, atlas-ask-endpoint, and atlas-ask-get-answer.