Connect an AI assistant to your live Tanium environment and get a real answer about your fleet — in under five minutes.
The Tanium Developer Documentation MCP Server searches this site's content and never touches your environment. The Atlas MCP Server, covered here, operates your live Tanium environment directly.
Friday, 3:45 PM
"CVE-2025-29824 just dropped. Am I exposed, and what do I patch first?"
From "I have no idea" to a sequenced remediation plan in under a minute.

Stop guessing why it's slow
"Endpoint XYZ has been sluggish all week. What's actually going on?"
From a support ticket with no leads to a root-cause read in minutes, not an afternoon of pivoting between consoles.
Act as a SOC 2 auditor
"Walk through our endpoint compliance posture like an external SOC 2 auditor would."
From a week of screenshotting reports before an audit to a live, question-driven walkthrough.
Past Win10 EOL
"How many endpoints are still on an OS past end-of-life, and what's our exposure trend?"
From a static spreadsheet nobody trusts to a report you can actually show your boss.
You'll need:
- A licensed Atlas MCP Server, plus the Tanium solutions whose tools you want to use.
- Your Tanium Cloud domain (the
<domain>inhttps://<domain>-api.cloud.tanium.com). - An MCP-compatible client — pick your tab below.
Step 1 below requires the Oauth Clients write privilege (carried by the Admin reserved role). No admin access? Ask your Tanium admin for the endpoint URL and a client ID (and secret, if applicable), then skip to step 2 in your tab below.
The MCP endpoint is https://<domain>-api.cloud.tanium.com/mcp — note the -api. The most common setup failure is using the console URL, https://<domain>.cloud.tanium.com, instead. Once you've registered an OAuth client, you can derive the endpoint from its authorization URL: swap /oauth/authorize for /mcp.
1. Register the OAuth client
In Tanium Atlas, click the Command Palette icon in the far left nav, search for oauth clients, and select the OAuth Clients template. Fill in the Register OAuth Client panel:
| Field | Value |
|---|---|
| Name | Anything — for example, Claude Desktop |
| Grant type | Authorization Code |
| OAuth 2.0 Support | Off — Claude is a public client: it uses OAuth 2.1 and takes no client secret |
| Redirect URIs | https://claude.ai/api/mcp/auth_callback and https://claude.com/api/mcp/auth_callback — add both. One connector then covers Claude Desktop and Claude on the web. |
| Allowed roles | MCP Read Only User, Interact Power User, Patch Read Only User, and Performance Read Only User |
Registration returns a Client ID, an authorization URL, and a token URL. Keep the client ID.
2. Add the custom connector
In Claude, open Settings > Connectors, click Add custom connector, and fill in:
| Field | Value |
|---|---|
| Name | Anything — for example, Tanium Atlas MCP |
| Remote MCP server URL | https://<domain>-api.cloud.tanium.com/mcp |
| Client ID | From step 1 |
| Client secret | Leave empty |
Claude runs preflight checks against the URL and detects that the server uses pre-registered OAuth clients. Click Add.
3. Connect and authorize
Back in Settings > Connectors, click Connect in your connector's row. The Tanium consent page opens in your browser: pick the persona whose permissions the client should act with, then authorize. Your tools show up in Claude as soon as consent completes.
- The consent page says
No role overlap for any persona— none of the OAuth client's allowed roles match a role on any persona you can select. Add an overlapping role to the client. - The connector won't connect — check the connector log at
~/Library/Logs/Claude/mcp-server-tanium-mcp-router.logfor the specific error.
Register a separate OAuth client for each integration so you can scope and revoke them independently.
A ladder of read-only prompts, safe to run against any environment:
"How many endpoints do I have, and how many are online right now?"— a 30-second fleet count that proves the pipe is open."Run a proactive ops health check on my environment."— a prioritized read of platform, patch, and performance health."Which endpoints run an OS that's end-of-life or within 12 months of it, and which should I upgrade first?"— a ranked upgrade list, the one to show your boss.
Read-only mode and toolset scoping — set whichever your client supports:
- Headers (preferred):
X-Tanium-MCP-Toolsets: patch,assetand/orX-Tanium-MCP-Readonly: true - Path suffixes (when your client only exposes a URL field):
/x/<toolset>,/readonly, or/x/<toolset>/readonly
Two skills come pre-baked with every Atlas MCP Server:
- Tanium Expert routes any question to the right tool across modules, so nobody has to memorize a tool taxonomy.
- Risk Evaluator is a mandatory gate on every state-changing call. It grades risk as safe, elevated, or high, and demands explicit confirmation before anything irreversible.
Together, these are the strongest available answer to "can I trust an agent against my production environment?"