{"templateId":"markdown","sharedDataIds":{"sidebar":"sidebar-sidebars.yaml"},"props":{"metadata":{"markdoc":{"tagList":["chat-replay","admonition","cards","card","tabs","tab","faq"]},"type":"markdown"},"seo":{"title":"Atlas MCP Quick Start"},"dynamicMarkdocComponents":[],"compilationErrors":[],"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"atlas-mcp-quick-start","__idx":0},"children":["Atlas MCP Quick Start"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Connect an AI assistant to your live Tanium environment and get a real answer about your fleet — in under five minutes."]}]},{"$$mdtype":"Tag","name":"ChatReplay","attributes":{"script":{"version":1,"turns":[{"role":"user","text":"CVE-2025-29824 just dropped. Am I exposed?"},{"role":"tool","names":["tanium_patch_tools","tanium_comply_tools"]},{"role":"assistant","lines":["1,284 of 41,905 endpoints are running an affected Windows build.","63 are internet-facing and reachable from outside your perimeter.","Here's the staged remediation plan, sequenced by exposure…"],"holdMs":4000}]},"avatar":"/assets/atlas.0358c9084610fc30fdbf9adbf62e5d471c819eb470a8abdda16b39d2b6aa12d9.4461c649.svg"},"children":[]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"info","name":"This is not the Developer Docs MCP Server"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/guides/core-platform/tanium_mcp_servers","title":"Tanium MCP Servers"},"children":["Tanium Developer Documentation MCP Server"]}," searches this site's content and never touches your environment. The Atlas MCP Server, covered here, operates your live Tanium environment directly."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"what-you-can-ask-it","__idx":1},"children":["What You Can Ask It"]},{"$$mdtype":"Tag","name":"Cards","attributes":{"columns":2,"cardMinWidth":220},"children":[{"$$mdtype":"Tag","name":"Card","attributes":{"title":"Friday, 3:45 PM","icon":"../../images/icons/red/-shield-lock.svg","iconRawContent":"<?xml version=\"1.0\" encoding=\"UTF-8\"?><svg id=\"images-icons-red--shield-lock-svg__Layer_1\" data-name=\"Layer 1\" xmlns=\"http://www.w3.org/2000/svg\" viewBox=\"0 0 24 24\"><defs><style>.images-icons-red--shield-lock-svg__cls-1{fill:none;stroke:#e01a33;stroke-linecap:round;stroke-linejoin:round;stroke-width:1.5px}</style></defs><g id=\"images-icons-red--shield-lock-svg__shield-lock\"><g id=\"images-icons-red--shield-lock-svg__Group_72\" data-name=\"Group 72\"><path id=\"images-icons-red--shield-lock-svg__Path_638\" data-name=\"Path 638\" class=\"images-icons-red--shield-lock-svg__cls-1\" d=\"M13.53,11.13v-1.35c0-.84-.68-1.53-1.53-1.53h0c-.84,0-1.53.68-1.53,1.53h0v1.35\"/><path id=\"images-icons-red--shield-lock-svg__Path_639\" data-name=\"Path 639\" class=\"images-icons-red--shield-lock-svg__cls-1\" d=\"M13.75,11.13h-3.5c-.55,0-1,.45-1,1v2.12c0,.55.45,1,1,1h3.5c.55,0,1-.45,1-1v-2.12c0-.55-.45-1-1-1Z\"/></g><g id=\"images-icons-red--shield-lock-svg__Group_73\" data-name=\"Group 73\"><path id=\"images-icons-red--shield-lock-svg__Path_642\" data-name=\"Path 642\" class=\"images-icons-red--shield-lock-svg__cls-1\" d=\"M20,11.24c-.11,4.52-3.14,8.44-7.48,9.69-.34.1-.7.1-1.04,0-4.34-1.25-7.37-5.17-7.48-9.69v-4.03c0-.81.49-1.54,1.24-1.85l4.86-1.99c1.21-.5,2.57-.5,3.79,0l4.86,1.99c.75.31,1.24,1.04,1.24,1.85v4.03Z\"/></g></g></svg>","imagePosition":"start","iconPosition":"auto","layout":"vertical","align":"start","variant":"outlined","iconVariant":"ghost"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["\"CVE-2025-29824 just dropped. Am I exposed, and what do I patch first?\""]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["From \"I have no idea\" to a sequenced remediation plan in under a minute."]}]},{"$$mdtype":"Tag","name":"Card","attributes":{"title":"Stop guessing why it's slow","icon":"/assets/-stethoscope3x.dfb56b0f9308f534a0bdf7ea753c12506f9a337db08b01a484c56f26ae974df3.c49ff43c.png","imagePosition":"start","iconPosition":"auto","layout":"vertical","align":"start","variant":"outlined","iconVariant":"ghost"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["\"Endpoint XYZ has been sluggish all week. What's actually going on?\""]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["From a support ticket with no leads to a root-cause read in minutes, not an afternoon of pivoting between consoles."]}]},{"$$mdtype":"Tag","name":"Card","attributes":{"title":"Act as a SOC 2 auditor","icon":"../../images/icons/red/-document.svg","iconRawContent":"<?xml version=\"1.0\" encoding=\"UTF-8\"?><svg id=\"images-icons-red--document-svg__Layer_1\" data-name=\"Layer 1\" xmlns=\"http://www.w3.org/2000/svg\" viewBox=\"0 0 24 24\"><defs><style>.images-icons-red--document-svg__cls-1{fill:none;stroke:#e01a33;stroke-linecap:round;stroke-linejoin:round;stroke-width:1.5px}</style></defs><g id=\"images-icons-red--document-svg__file-copy-2\"><path id=\"images-icons-red--document-svg__Path_89\" data-name=\"Path 89\" class=\"images-icons-red--document-svg__cls-1\" d=\"M19.41,6.13l-2.54-2.54c-.38-.37-.88-.59-1.41-.59h-6.46c-1.1,0-2,.9-2,2v10.71c0,1.1.9,2,2,2h9c1.1,0,2-.9,2-2V7.54c0-.53-.21-1.04-.59-1.42Z\"/><path id=\"images-icons-red--document-svg__Path_90\" data-name=\"Path 90\" class=\"images-icons-red--document-svg__cls-1\" d=\"M20,8h-4c-.55,0-1-.45-1-1V3\"/><path id=\"images-icons-red--document-svg__Path_91\" data-name=\"Path 91\" class=\"images-icons-red--document-svg__cls-1\" d=\"M17,17.71v1.29c0,1.1-.9,2-2,2H6c-1.1,0-2-.9-2-2v-11c0-1.1.9-2,2-2h1\"/></g></svg>","imagePosition":"start","iconPosition":"auto","layout":"vertical","align":"start","variant":"outlined","iconVariant":"ghost"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["\"Walk through our endpoint compliance posture like an external SOC 2 auditor would.\""]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["From a week of screenshotting reports before an audit to a live, question-driven walkthrough."]}]},{"$$mdtype":"Tag","name":"Card","attributes":{"title":"Past Win10 EOL","icon":"../../images/icons/red/-data-chart-trajectory.svg","iconRawContent":"<?xml version=\"1.0\" encoding=\"UTF-8\"?><svg id=\"images-icons-red--data-chart-trajectory-svg__Layer_1\" data-name=\"Layer 1\" xmlns=\"http://www.w3.org/2000/svg\" viewBox=\"0 0 24 24\"><defs><style>.images-icons-red--data-chart-trajectory-svg__cls-1{fill:none;stroke:#e01a33;stroke-linecap:round;stroke-linejoin:round;stroke-width:1.5px}</style></defs><g id=\"images-icons-red--data-chart-trajectory-svg__trend-upwards\"><path id=\"images-icons-red--data-chart-trajectory-svg__Path_2\" data-name=\"Path 2\" class=\"images-icons-red--data-chart-trajectory-svg__cls-1\" d=\"M5,15.89l5.07-5.07c.39-.39,1.02-.39,1.41,0l2.14,2.14c.39.39,1.02.39,1.41,0l5.96-5.96\"/><path id=\"images-icons-red--data-chart-trajectory-svg__Path_3\" data-name=\"Path 3\" class=\"images-icons-red--data-chart-trajectory-svg__cls-1\" d=\"M18.33,7h2.67v2.67\"/><path id=\"images-icons-red--data-chart-trajectory-svg__Path_4\" data-name=\"Path 4\" class=\"images-icons-red--data-chart-trajectory-svg__cls-1\" d=\"M21,20.93H1.92V3.22\"/></g></svg>","imagePosition":"start","iconPosition":"auto","layout":"vertical","align":"start","variant":"outlined","iconVariant":"ghost"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["\"How many endpoints are still on an OS past end-of-life, and what's our exposure trend?\""]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["From a static spreadsheet nobody trusts to a report you can actually show your boss."]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"before-you-start","__idx":2},"children":["Before You Start"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["You'll need:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["A licensed ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Atlas MCP Server"]},", plus the Tanium solutions whose tools you want to use."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Your Tanium Cloud domain (the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["<domain>"]}," in ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["https://<domain>-api.cloud.tanium.com"]},")."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["An MCP-compatible client — pick your tab below."]}]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"info"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Step 1 below requires the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Oauth Clients write"]}," privilege (carried by the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Admin"]}," reserved role). ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["No admin access?"]}," Ask your Tanium admin for the endpoint URL and a client ID (and secret, if applicable), then skip to step 2 in your tab below."]}]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"warning","name":"Mind the -api in the domain"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The MCP endpoint is ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["https://<domain>-api.cloud.tanium.com/mcp"]}," — note the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["-api"]},". The most common setup failure is using the console URL, ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["https://<domain>.cloud.tanium.com"]},", instead. Once you've registered an OAuth client, you can derive the endpoint from its authorization URL: swap ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["/oauth/authorize"]}," for ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["/mcp"]},"."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"set-it-up","__idx":3},"children":["Set It Up"]},{"$$mdtype":"Tag","name":"Tabs","attributes":{"id":"atlas-mcp-setup","size":"medium"},"children":[{"$$mdtype":"Tag","name":"TabItemFragment","attributes":{"label":"Claude Desktop","disable":false},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["1. Register the OAuth client"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["In Tanium Atlas, click the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Command Palette"]}," icon in the far left nav, search for ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["oauth clients"]},", and select the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["OAuth Clients"]}," template. Fill in the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Register OAuth Client"]}," panel:"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Field"},"children":["Field"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Value"},"children":["Value"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Name"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Anything — for example, ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Claude Desktop"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Grant type"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Authorization Code"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["OAuth 2.0 Support"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Off"]}," — Claude is a public client: it uses OAuth 2.1 and takes no client secret"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Redirect URIs"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["https://claude.ai/api/mcp/auth_callback"]}," ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["and"]}," ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["https://claude.com/api/mcp/auth_callback"]}," — add both. One connector then covers Claude Desktop and Claude on the web."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Allowed roles"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["MCP Read Only User"]},", ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Interact Power User"]},", ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Patch Read Only User"]},", and ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Performance Read Only User"]}]}]}]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Registration returns a ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Client ID"]},", an ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["authorization URL"]},", and a ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["token URL"]},". Keep the client ID."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["2. Add the custom connector"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["In Claude, open ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Settings > Connectors"]},", click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Add custom connector"]},", and fill in:"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Field"},"children":["Field"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Value"},"children":["Value"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Name"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Anything — for example, ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Tanium Atlas MCP"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Remote MCP server URL"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["https://<domain>-api.cloud.tanium.com/mcp"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Client ID"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["From step 1"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Client secret"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Leave empty"]}]}]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Claude runs preflight checks against the URL and detects that the server uses pre-registered OAuth clients. Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Add"]},"."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["3. Connect and authorize"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Back in ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Settings > Connectors"]},", click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Connect"]}," in your connector's row. The Tanium consent page opens in your browser: pick the persona whose permissions the client should act with, then authorize. Your tools show up in Claude as soon as consent completes."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"claude-desktop-troubleshooting","__idx":4},"children":["Claude Desktop troubleshooting"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["The consent page says ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["No role overlap for any persona"]}]}," — none of the OAuth client's allowed roles match a role on any persona you can select. Add an overlapping role to the client."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["The connector won't connect"]}," — check the connector log at ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["~/Library/Logs/Claude/mcp-server-tanium-mcp-router.log"]}," for the specific error."]}]}]},{"$$mdtype":"Tag","name":"TabItemFragment","attributes":{"label":"Copilot Studio","disable":false},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Copilot Studio gives you its redirect URI only partway through setup, so you register with a placeholder and add the real one later. The steps differ by agent type, so pick yours after step 1."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["1. Register the OAuth client"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["In Tanium Atlas, click the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Command Palette"]}," icon in the far left nav, search for ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["oauth clients"]},", and select the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["OAuth Clients"]}," template. Fill in the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Register OAuth Client"]}," panel:"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Field"},"children":["Field"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Value"},"children":["Value"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Name"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Anything — for example, ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Copilot Studio"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Grant type"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Authorization Code"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["OAuth 2.0 Support"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["On"]}," — Copilot Studio needs a client secret. It's shown once, so save it."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Redirect URI"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["A placeholder for now; ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["http://localhost"]}," satisfies the field. You'll add the real one later."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Allowed roles"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["MCP Read Only User"]},", ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Interact Power User"]},", ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Patch Read Only User"]},", and ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Performance Read Only User"]}]}]}]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Registration returns a ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Client ID"]},", a ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Client Secret"]},", an ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["authorization URL"]},", and a ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["token URL"]},". You need all four."]},{"$$mdtype":"Tag","name":"Tabs","attributes":{"id":"copilot-studio-agent","size":"medium"},"children":[{"$$mdtype":"Tag","name":"TabItemFragment","attributes":{"label":"Standard Agent","disable":false},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["2. Create the agent"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["In Copilot Studio, select the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Agents"]}," icon in the left nav. ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Don't click the New agent button"]}," — that creates a GitHub Copilot agent. Click the down arrow next to it, select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Agent (standard)"]},", and click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Create"]},"."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["3. Add the MCP server"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Tools"]}," in the top nav, click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Add a tool"]},", then click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Add new MCP"]},". Fill in:"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Field"},"children":["Field"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Value"},"children":["Value"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Server name"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["For example, ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Tanium Atlas MCP"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Server description"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Anything you like"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Server URL"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["https://<domain>-api.cloud.tanium.com/mcp"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Authentication"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["OAuth 2.0"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Configuration type"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Manual"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Client ID, Client Secret, Authorization URL, Token URL template"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["From step 1"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Refresh URL"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["The token URL again"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Scopes"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Leave empty"]}]}]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Create"]},". Copilot Studio supports at most 70 MCP tools, and the full catalog fits. To narrow it, see ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://help.tanium.com/bundle/ug_atlas_mcp_server_cloud/page/atlas_mcp_server/configuring.html#ariaid-title6"},"children":["Filter tools"]}," in the Tanium Atlas MCP Server user guide."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["4. Add the redirect URI to the OAuth client"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Copy the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Redirect URL"]}," Copilot Studio now shows. In Tanium Atlas, open the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["OAuth Clients"]}," template again, find your client in the list, scroll to the far right, and select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Edit"]}," from its ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Actions"]}," dropdown. Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Add another"]}," under ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Redirect URIs"]},", paste it, and click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Save"]},"."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["5. Connect"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Back in Copilot Studio, click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Not connected"]},", select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Create new connection"]},", and click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Create"]},". In the Tanium ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Authorize Access"]}," window, click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Authorize"]},". The connection shows a green check once it succeeds. Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Add"]},"."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["6. Test it"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Test"]}," at the top right and ask something simple, like ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["How many endpoints do I have online?"]}]}]},{"$$mdtype":"Tag","name":"TabItemFragment","attributes":{"label":"GitHub Copilot Agent","disable":false},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["2. Create the agent"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["In Copilot Studio, select the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Agents"]}," icon in the left nav and click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["New agent"]},". Name it something like ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Tanium Atlas MCP Client"]},"."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["3. Add the MCP server"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["In the right nav menu, click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Tools"]},", click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Add"]},", and select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Model Context Protocol (MCP)"]},". Fill in:"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Field"},"children":["Field"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Value"},"children":["Value"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Server name"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["For example, ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Tanium Atlas MCP"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Server description"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Anything you like"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Server URL"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["https://<domain>-api.cloud.tanium.com/mcp"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Authentication"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["OAuth 2.0"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Configuration type"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Manual"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Client ID, Client Secret, Authorization URL, Token URL"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["From step 1"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Refresh token URL"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["The token URL again"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Scopes"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Leave empty"]}]}]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Add"]},". Copilot Studio supports at most 70 MCP tools, and the full catalog fits. To narrow it, see ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://help.tanium.com/bundle/ug_atlas_mcp_server_cloud/page/atlas_mcp_server/configuring.html#ariaid-title6"},"children":["Filter tools"]}," in the Tanium Atlas MCP Server user guide."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["4. Start the connection"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Not connected"]},", select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Create new connection"]},", and click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Create"]},". A Tanium authorization window opens showing ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Failed to load authorization details"]}," — that's expected, because the OAuth client doesn't have Copilot Studio's redirect URI yet."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["5. Add the redirect URI to the OAuth client"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Copy the URL from that authorization window's address bar and take the value of its ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["redirect_uri"]}," parameter — everything after ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["redirect_uri="]}," up to the next ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["&"]},". Don't include the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["&state=…"]}," that follows. Decode it with a tool such as ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://www.urldecoder.org/"},"children":["URL Decoder"]},". The result starts with ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["https://global.consent.azure-apim.net/redirect/"]},"."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["In Tanium Atlas, open the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["OAuth Clients"]}," template again, find your client in the list, scroll to the far right, and select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Edit"]}," from its ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Actions"]}," dropdown. Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Add another"]}," under ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Redirect URIs"]},", paste the decoded value, and click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Save"]},"."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["6. Connect"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Back in Copilot Studio, close the authorization window and click the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Cancel"]}," next to ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Signing in…"]}," — not the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Cancel"]}," at the bottom of the connection window. Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Create"]}," again. This time Tanium shows ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Authorize Access"]},"; click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Authorize"]},". The connection shows a green check once it succeeds. Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Add"]},"."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["7. Publish"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Back on the agent screen, enter any instructions you want and click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Publish"]},"."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"github-copilot-agent-troubleshooting","__idx":5},"children":["GitHub Copilot Agent troubleshooting"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Failed to load authorization details"]}," after step 5"]}," — the redirect URI on the OAuth client doesn't exactly match the one Copilot Studio sends. Check that you decoded it and that it stops before ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["&state="]},". Then start a fresh sign-in as in step 6; retrying in the old authorization window doesn't pick up the change."]}]}]}]}]},{"$$mdtype":"Tag","name":"TabItemFragment","attributes":{"label":"ChatGPT Codex","disable":false},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["ChatGPT Codex has no field for an OAuth client ID in its interface, so you'll add it to Codex's config file directly in step 4. Everything else happens in the desktop app."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["1. Open the MCP settings"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["In the ChatGPT desktop app, select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Plugins"]}," in the left nav, click the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["gear icon"]}," at the top right, then open the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["MCPs"]}," tab."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["2. Add the server"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Add server"]},", then fill in:"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Field"},"children":["Field"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Value"},"children":["Value"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Name"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["tanium"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Type"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Streamable HTTP"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["URL"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["https://<domain>-api.cloud.tanium.com/mcp"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Bearer token env var"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Leave empty"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Headers"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Leave empty — this is where ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["X-Tanium-MCP-Toolsets"]}," goes if you scope tools later"]}]}]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Save"]},"."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["3. Register the OAuth client"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["In Tanium Atlas, click the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Command Palette"]}," icon in the far left nav, search for ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["oauth clients"]},", and select the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["OAuth Clients"]}," template. Fill in the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Register OAuth Client"]}," panel:"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Field"},"children":["Field"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Value"},"children":["Value"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Name"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Anything — for example, ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["ChatGPT Codex"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Grant type"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Authorization Code"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["OAuth 2.0 Support"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Off"]}," — Codex is a public client: it uses OAuth 2.1 and takes no client secret"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Redirect URI"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["A placeholder for now; ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["http://localhost"]}," satisfies the field. You'll replace it in step 5."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Allowed roles"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["MCP Read Only User"]},", ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Interact Power User"]},", ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Patch Read Only User"]},", and ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Performance Read Only User"]}]}]}]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Copy the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Client ID"]},"."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["4. Give Codex the client ID"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Quit the app first so it doesn't overwrite the file, then add an ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["oauth"]}," block for your server to ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["~/.codex/config.toml"]}," — ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["%USERPROFILE%\\.codex\\config.toml"]}," on Windows:"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"header":{"controls":{"copy":{}}},"source":"[mcp_servers.tanium.oauth]\nclient_id = \"<your client id>\"\ncallback_port = 8086\n"},"children":[]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The table name has to match the server name you used in step 2. ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["callback_port"]}," pins the loopback port: without it Codex picks a fresh one every time you sign in, and no registered redirect URI can match a moving port. Relaunch the app."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["5. Authenticate, and copy the callback"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Back in ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Plugins > gear icon > MCPs"]},", leave the registration dropdown on ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Automatic"]}," and click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Authenticate"]}," next to your server. A browser opens. Copy the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["redirect_uri"]}," value out of the address bar — it looks like ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["http://127.0.0.1:8086/callback/RQUCRjiIl2Nb"]},", where the trailing segment is derived from your server URL."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["In Tanium Atlas, open the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["OAuth Clients"]}," template again, find your client in the list, scroll to the far right, and select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Edit"]}," from its ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Actions"]}," dropdown. Replace the placeholder redirect URI with that value and click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Save"]},"."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["6. Authenticate again"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Authenticate"]}," once more. The Tanium consent page loads: pick the persona whose permissions Codex should act with, then authorize."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"chatgpt-codex-troubleshooting","__idx":6},"children":["ChatGPT Codex troubleshooting"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Couldn't connect to <server>"]}]}," as soon as you click Authenticate — Codex has no client ID, so it tried to register one dynamically, which Tanium doesn't support. Check step 4: the table name must match the server name exactly, and the app has to be relaunched after the edit. Switching the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Automatic"]}," dropdown to CIMD or DCR won't help — all three are ways of obtaining a client ID dynamically, and Tanium issues yours from the console instead."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Failed to load authorization details"]}]}," — the redirect URI on the OAuth client doesn't match the one Codex sent. Compare the two exactly, port and trailing segment included. If the port changes every time you click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Authenticate"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["callback_port"]}," isn't being picked up: it belongs under ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["[mcp_servers.<name>.oauth]"]},", not the server's top-level block."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["The port is already in use"]}," — ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["8086"]}," isn't special; any free port works. Change it in step 4 and update the redirect URI to match."]}]}]},{"$$mdtype":"Tag","name":"TabItemFragment","attributes":{"label":"Claude Code","disable":false},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["1. Register the OAuth client"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["In Tanium Atlas, click the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Command Palette"]}," icon in the far left nav, search for ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["oauth clients"]},", and select the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["OAuth Clients"]}," template. Fill in the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Register OAuth Client"]}," panel:"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Field"},"children":["Field"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Value"},"children":["Value"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Name"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Anything — for example, ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Claude Code"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Grant type"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Authorization Code"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["OAuth 2.0 Support"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Off"]}," — Claude Code is a public client: it uses OAuth 2.1 and takes no client secret"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Redirect URI"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["http://localhost:8085/callback"]}," — loopback URIs are permitted for native apps"]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Allowed roles"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["MCP Read Only User"]},", ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Interact Power User"]},", ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Patch Read Only User"]},", and ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Performance Read Only User"]}]}]}]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Copy the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Client ID"]},"."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["2. Add the server"]}]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"header":{"controls":{"copy":{}}},"source":"claude mcp add --transport http \\\n    --client-id <your client id> \\\n    --callback-port 8085 \\\n    tanium https://<domain>-api.cloud.tanium.com/mcp\n"},"children":[]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["--callback-port"]}," must match the port in your redirect URI."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["3. Authorize"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Start ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["claude"]}," and run ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["/mcp"]},". Select ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["tanium"]}," (",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["△ needs authentication"]},"), press ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Enter"]},", and choose ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Authenticate"]},". Sign in, then close the browser once it says ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Authentication successful"]},". Run ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["/mcp"]}," again to confirm ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["✔ connected"]},"."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"claude-code-troubleshooting","__idx":7},"children":["Claude Code troubleshooting"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["The browser flow fails or never completes"]}," — the OAuth client's redirect URI has to be exactly ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["http://localhost:8085/callback"]},". To fix the command instead, run ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["claude mcp remove tanium"]}," and add it again."]}]}]},{"$$mdtype":"Tag","name":"TabItemFragment","attributes":{"label":"Google Antigravity","disable":false},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Antigravity has no native OAuth support for manually-configured MCP servers, so it authenticates through a local ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://www.npmjs.com/package/mcp-remote"},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["mcp-remote"]}]}," bridge instead. There's no browser consent step and no redirect URI."]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"info","name":"Node.js required"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["This path needs ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Node.js"]},", which provides the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["npx"]}," command the bridge script runs. If you don't already have it, ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"https://nodejs.org/en/download"},"children":["download and install Node.js"]}," first, then confirm it's available:"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"header":{"controls":{"copy":{}}},"source":"$ node -v\n$ npx -v\n"},"children":[]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["1. Register the OAuth client"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["In Tanium Atlas, click the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Command Palette"]}," icon in the far left nav, search for ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["oauth clients"]},", and select the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["OAuth Clients"]}," template. Fill in the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Register OAuth Client"]}," panel:"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Field"},"children":["Field"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Value"},"children":["Value"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Name"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Anything — for example, ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Antigravity"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Grant type"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Client Credentials"]}," — the bridge authenticates with the client ID and secret alone. The secret is shown once, so save it."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Client type"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Model Context Protocol"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Allowed roles"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["MCP Read Only User"]},", ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Interact Power User"]},", ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Patch Read Only User"]},", and ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Performance Read Only User"]}]}]}]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["A Client Credentials client acts as you, the user who registers it, and stops working if your account is disabled or deleted."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The folder can be anywhere, but avoid ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Documents"]}," — IT policy often redirects it to OneDrive or other cloud storage on managed machines, which would make the paths below wrong."]},{"$$mdtype":"Tag","name":"Tabs","attributes":{"id":"antigravity-os","size":"medium"},"children":[{"$$mdtype":"Tag","name":"TabItemFragment","attributes":{"label":"macOS","disable":false},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["2. Save the bridge script"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Create the folder, then save the script as ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["~/.antigravity-mcp-bridge/tanium-mcp.sh"]},":"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"header":{"controls":{"copy":{}}},"source":"mkdir -p ~/.antigravity-mcp-bridge\n"},"children":[]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"header":{"controls":{"copy":{}}},"source":"#!/usr/bin/env bash\nset -euo pipefail\n\n#export PATH=\"/replace/with/npx/directory:$PATH\"\n\ncommand -v npx >/dev/null 2>&1 || { echo \"npx not found - run 'which npx' then uncomment and fill in the export PATH line near the top of this script\" >&2; exit 1; }\n\n: \"${TANIUM_MCP_SERVER_URL:?required, set it in the env block}\" \"${TANIUM_MCP_CLIENT_ID:?required, set it in the env block}\" \"${TANIUM_MCP_CLIENT_SECRET:?required, set it in the env block}\"\n\nexec npx -y mcp-remote \"$TANIUM_MCP_SERVER_URL\" \\\n  --transport http-only \\\n  --client-credentials \\\n  --static-oauth-client-info '{\"client_id\":\"${TANIUM_MCP_CLIENT_ID}\",\"client_secret\":\"${TANIUM_MCP_CLIENT_SECRET}\"}'\n"},"children":[]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Make it executable:"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"header":{"controls":{"copy":{}}},"source":"chmod +x ~/.antigravity-mcp-bridge/tanium-mcp.sh\n"},"children":[]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["3. Point ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["mcp_config.json"]}," at it"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["In Antigravity, open ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Settings > Customizations"]},", scroll down to ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Installed MCP Servers"]},", and click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Open MCP Config"]}," to open ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["mcp_config.json"]}," directly (typically ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["~/.gemini/config/mcp_config.json"]},"). If the file already has an ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["mcpServers"]}," block, add only the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["tanium-mcp"]}," entry inside it:"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"header":{"controls":{"copy":{}}},"source":"{\n  \"mcpServers\": {\n    \"tanium-mcp\": {\n      \"command\": \"/Users/<your macOS username>/.antigravity-mcp-bridge/tanium-mcp.sh\",\n      \"env\": {\n        \"TANIUM_MCP_SERVER_URL\": \"https://<domain>-api.cloud.tanium.com/mcp\",\n        \"TANIUM_MCP_CLIENT_ID\": \"<your client id>\",\n        \"TANIUM_MCP_CLIENT_SECRET\": \"<your client secret>\"\n      }\n    }\n  }\n}\n"},"children":[]}]},{"$$mdtype":"Tag","name":"TabItemFragment","attributes":{"label":"Windows","disable":false},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["2. Save the bridge script"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Create the folder, then save the script as ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["%LOCALAPPDATA%\\antigravity-mcp-bridge\\tanium-mcp.ps1"]},":"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"header":{"controls":{"copy":{}}},"source":"mkdir \"$env:LOCALAPPDATA\\antigravity-mcp-bridge\"\n"},"children":[]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"header":{"controls":{"copy":{}}},"source":"#Requires -Version 5.1\n$ErrorActionPreference = \"Stop\"\n\n#$env:PATH = \"C:\\replace\\with\\npx\\directory;$env:PATH\"\n\nif (-not (Get-Command npx -ErrorAction SilentlyContinue)) { Write-Error \"npx not found - run 'Get-Command npx' then uncomment and fill in the PATH line near the top of this script\"; exit 1 }\nif (-not $env:TANIUM_MCP_SERVER_URL -or -not $env:TANIUM_MCP_CLIENT_ID -or -not $env:TANIUM_MCP_CLIENT_SECRET) { Write-Error \"TANIUM_MCP_SERVER_URL / TANIUM_MCP_CLIENT_ID / TANIUM_MCP_CLIENT_SECRET required, set them in the env block\"; exit 1 }\n\nnpx -y mcp-remote $env:TANIUM_MCP_SERVER_URL `\n    --transport http-only `\n    --client-credentials `\n    --static-oauth-client-info '{\\\"client_id\\\":\\\"${TANIUM_MCP_CLIENT_ID}\\\",\\\"client_secret\\\":\\\"${TANIUM_MCP_CLIENT_SECRET}\\\"}'\n"},"children":[]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["3. Point ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["mcp_config.json"]}," at it"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["In Antigravity, open ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Settings > Customizations"]},", scroll down to ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Installed MCP Servers"]},", click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Open MCP Config"]},", and open ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["mcp_config.json"]}," in the folder that appears. If the file already has an ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["mcpServers"]}," block, add only the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["tanium-mcp"]}," entry inside it. ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["command"]}," is PowerShell, since a ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":[".ps1"]}," file can't be spawned directly:"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"header":{"controls":{"copy":{}}},"source":"{\n  \"mcpServers\": {\n    \"tanium-mcp\": {\n      \"command\": \"powershell.exe\",\n      \"args\": [\"-NoProfile\", \"-ExecutionPolicy\", \"Bypass\", \"-File\", \"C:\\\\Users\\\\<your Windows username>\\\\AppData\\\\Local\\\\antigravity-mcp-bridge\\\\tanium-mcp.ps1\"],\n      \"env\": {\n        \"TANIUM_MCP_SERVER_URL\": \"https://<domain>-api.cloud.tanium.com/mcp\",\n        \"TANIUM_MCP_CLIENT_ID\": \"<your client id>\",\n        \"TANIUM_MCP_CLIENT_SECRET\": \"<your client secret>\"\n      }\n    }\n  }\n}\n"},"children":[]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["4. Refresh the server"]}," — back in ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Settings > Customizations"]},", click the refresh button next to ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Installed MCP Servers"]}," and confirm ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["tanium-mcp"]}," connects. No restart, no browser consent step."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"antigravity-troubleshooting","__idx":8},"children":["Antigravity troubleshooting"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Illegal characters in path"]}," or ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["invalid character ... looking for beginning of value"]}]}," — a ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["<...>"]}," placeholder is still in ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["mcp_config.json"]},". Check that the script path, server URL, client ID, and secret are all real values."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["serverUrl cannot be specified with command, args, or env"]}]}," — the entry must contain only ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["command"]},"/",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["env"]}," (and optionally ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["args"]},"/",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["cwd"]},")."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["connection closed: ... EOF"]}," right at ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["initialize"]}]}," — the script exited before ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["mcp-remote"]}," ever started. Run it directly in a terminal with the three env vars set to see the real error — usually ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["npx"]}," not on ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["PATH"]},", or one of the three variables missing from the entry's ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["env"]}," block."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["npx not found - run '...' then uncomment and fill in the ... line ..."]}]}," — GUI-launched apps often spawn this script with a more limited ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["PATH"]}," than your terminal has, so ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["npx"]}," may not resolve even though it works when you run it yourself. Run ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["which npx"]}," (macOS) or ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Get-Command npx"]}," (Windows) to find where it lives, then uncomment the commented-out ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["PATH"]}," / ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["$env:PATH"]}," line near the top of the script and replace the placeholder with that directory — not the full path to ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["npx"]}," itself."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["A token request fails outright"]}," — some environments return a plain-text error body instead of a JSON RFC 6749 error object on ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["/oauth/token"]}," failure, which surfaces as a raw parse error from ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["mcp-remote"]}," rather than a clean OAuth error. Check with whoever administers your Atlas MCP Server."]}]}]},{"$$mdtype":"Tag","name":"TabItemFragment","attributes":{"label":"General","disable":false},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Any other MCP client. This is the one case where you make the OAuth call yourself, so these steps name what your client needs rather than where to click."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["1. Register the OAuth client"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["In Tanium Atlas, click the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Command Palette"]}," icon in the far left nav, search for ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["oauth clients"]},", and select the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["OAuth Clients"]}," template. Fill in the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Register OAuth Client"]}," panel:"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Field"},"children":["Field"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Value"},"children":["Value"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Name"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Anything — for example, ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["MCP client"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Grant type"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Authorization Code"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["OAuth 2.0 Support"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Off"]},", unless your client asks you for a client ",{"$$mdtype":"Tag","name":"em","attributes":{},"children":["secret"]},". That's the tell — no secret field means it speaks OAuth 2.1 and a Client ID is all you need."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Redirect URI"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Whatever callback your client uses. Must be HTTPS, except that loopback addresses (",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["http://localhost:<port>/callback"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["http://127.0.0.1:<port>/callback"]},") are permitted for native apps. If your client doesn't reveal it until the connection exists, enter ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["http://localhost"]}," for now and come back in step 2."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Allowed roles"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["MCP Read Only User"]},", ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Interact Power User"]},", ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Patch Read Only User"]},", and ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Performance Read Only User"]}]}]}]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Registration returns a ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Client ID"]},", an ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["authorization URL"]},", and a ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["token URL"]}," — plus a ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Client Secret"]}," if you turned OAuth 2.0 Support on. The secret is shown once, so save it."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["2. Add the Atlas MCP server to your client"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Point your client at the server using the credentials from step 1:"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Field"},"children":["Field"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Value"},"children":["Value"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Endpoint"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["https://<domain>-api.cloud.tanium.com/mcp"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Transport"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Streamable HTTP — ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["stdio is not supported"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Auth"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Authorization code flow"]}]}]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Tanium Cloud is the authorization server, so clients that discover it themselves will find it at ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["/.well-known/oauth-authorization-server"]},"."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["If your client generates its callback URL only now"]}," — connector-style clients, the ChatGPT apps among them, produce theirs once the connection exists — copy it, then go back and replace the placeholder redirect URI on the OAuth client from step 1. Redirect URIs stay editable after registration."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["3. Authorize"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Complete the browser consent flow from your client, and pick the persona whose permissions it should act with."]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"info","name":"No human in the loop?"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The authorization code flow needs someone to click through consent, which doesn't work for an autonomous agent or a CI pipeline. For those, register with ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Grant type"]}," set to ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Client Credentials"]}," and ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Client type"]}," set to ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Model Context Protocol"]},", then use the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["client_credentials"]}]}," grant with the client ID and secret to mint a token per run. The client acts as the user who registered it, and stops working if that user is disabled or deleted."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"troubleshooting","__idx":9},"children":["Troubleshooting"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Failed to load authorization details"]}]}," — the redirect URI on the OAuth client doesn't match the one your client actually uses."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Connection refused or a 404 on the endpoint"]}," — check the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["-api"]}," in the domain. See \"Before You Start\" above."]}]}]}]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"info"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Register a separate OAuth client for each integration so you can scope and revoke them independently."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"your-first-three-prompts","__idx":10},"children":["Your First Three Prompts"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["A ladder of read-only prompts, safe to run against any environment:"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["\"How many endpoints do I have, and how many are online right now?\""]}]}," — a 30-second fleet count that proves the pipe is open."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["\"Run a proactive ops health check on my environment.\""]}]}," — a prioritized read of platform, patch, and performance health."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["\"Which endpoints run an OS that's end-of-life or within 12 months of it, and which should I upgrade first?\""]}]}," — a ranked upgrade list, the one to show your boss."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"control-what-it-can-do","__idx":11},"children":["Control What It Can Do"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Read-only mode and toolset scoping — set whichever your client supports:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Headers"]}," (preferred): ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["X-Tanium-MCP-Toolsets: patch,asset"]}," and/or ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["X-Tanium-MCP-Readonly: true"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Path suffixes"]}," (when your client only exposes a URL field): ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["/x/<toolset>"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["/readonly"]},", or ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["/x/<toolset>/readonly"]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Two skills come pre-baked with every Atlas MCP Server:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Tanium Expert"]}," routes any question to the right tool across modules, so nobody has to memorize a tool taxonomy."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Risk Evaluator"]}," is a mandatory gate on every state-changing call. It grades risk as safe, elevated, or high, and demands explicit confirmation before anything irreversible."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Together, these are the strongest available answer to \"can I trust an agent against my production environment?\""]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"faq","__idx":12},"children":["FAQ"]},{"$$mdtype":"Tag","name":"FAQ","attributes":{"question":"No tools show up when I connect. Why?","answer":"Effective permissions are the intersection of the roles on your OAuth client and the roles on your user. Check that both carry the roles you expect. If you see 403 RBACInsufficientPrivilege, your session token lacks the Atlas MCP Server Api execute permission that those roles grant."},"children":[]},{"$$mdtype":"Tag","name":"FAQ","attributes":{"question":"I can't get an answer to a question about my endpoints. Why?","answer":"You're likely missing the Interact Power User role. MCP Read Only User alone lets you connect, but issuing questions to endpoints requires Interact Power User too (unless your role already carries Atlas MCP Server Api execute, such as Admin, which makes MCP Read Only User redundant)."},"children":[]},{"$$mdtype":"Tag","name":"FAQ","attributes":{"question":"The consent page says 'No role overlap for any persona'. What does that mean?","answer":"None of the OAuth client's allowed roles match a role assigned to any persona you can select, so there's nothing to consent to. Edit the OAuth client and add a role that overlaps with one of your personas."},"children":[]},{"$$mdtype":"Tag","name":"FAQ","attributes":{"question":"A tool I expect isn't in the catalog. Where is it?","answer":"Work through four things: the Tanium solution that provides the tool has to be in your license, your user's roles need the permissions the tool requires (a solution's tools need that solution's permissions; for example, Patch Read Only User grants Patch's read tools), the OAuth client's allowed roles need them too, and after a server restart the catalog takes about a minute to refresh — wait and retry."},"children":[]},{"$$mdtype":"Tag","name":"FAQ","attributes":{"question":"My refresh token was rejected. What happened?","answer":"Tanium revokes the whole token family when a refresh token is used after revocation, which can happen through token rotation or an explicit revocation. Sign out of your MCP client, sign back in, and repeat the consent flow."},"children":[]},{"$$mdtype":"Tag","name":"FAQ","attributes":{"question":"My client only supports stdio. Can I still connect?","answer":"No. The Atlas MCP Server only supports Streamable HTTP — stdio is not supported, and there's no proxy for it."},"children":[]},{"$$mdtype":"Tag","name":"FAQ","attributes":{"question":"I registered my OAuth client with the wrong redirect URI. Now what?","answer":"Redirect URIs are editable after registration. Edit the OAuth client and update it."},"children":[]},{"$$mdtype":"Tag","name":"FAQ","attributes":{"question":"I lost my client secret. Can I retrieve it?","answer":"No, it's shown only once at registration. Register a new OAuth client instead."},"children":[]},{"$$mdtype":"Tag","name":"FAQ","attributes":{"question":"My firewall is blocking the connection. What do I need to allow?","answer":"Allow outbound 443 to these five endpoints, where <domain> is your Tanium Cloud domain:\r\n\r\n• https://<domain>-api.cloud.tanium.com/.well-known/oauth-authorization-server\r\n• https://<domain>-api.cloud.tanium.com/.well-known/oauth-protected-resource\r\n• https://<domain>-api.cloud.tanium.com/oauth/authorize\r\n• https://<domain>-api.cloud.tanium.com/oauth/token\r\n• https://<domain>-api.cloud.tanium.com/oauth/revoke"},"children":[]},{"$$mdtype":"Tag","name":"FAQ","attributes":{"question":"Does using the Atlas MCP Server consume AI credits?","answer":"Yes, for the tools that ask a natural-language question against your fleet: atlas-ask-fleet, atlas-ask-endpoint, and atlas-ask-get-answer."},"children":[]}]},"headings":[{"value":"Atlas MCP Quick Start","id":"atlas-mcp-quick-start","depth":1},{"value":"What You Can Ask It","id":"what-you-can-ask-it","depth":1},{"value":"Before You Start","id":"before-you-start","depth":1},{"value":"Set It Up","id":"set-it-up","depth":1},{"value":"Claude Desktop troubleshooting","id":"claude-desktop-troubleshooting","depth":3},{"value":"GitHub Copilot Agent troubleshooting","id":"github-copilot-agent-troubleshooting","depth":3},{"value":"ChatGPT Codex troubleshooting","id":"chatgpt-codex-troubleshooting","depth":3},{"value":"Claude Code troubleshooting","id":"claude-code-troubleshooting","depth":3},{"value":"Antigravity troubleshooting","id":"antigravity-troubleshooting","depth":3},{"value":"Troubleshooting","id":"troubleshooting","depth":3},{"value":"Your First Three Prompts","id":"your-first-three-prompts","depth":1},{"value":"Control What It Can Do","id":"control-what-it-can-do","depth":1},{"value":"FAQ","id":"faq","depth":1}],"frontmatter":{"reel":{"version":1,"turns":[{"role":"user","text":"CVE-2025-29824 just dropped. Am I exposed?"},{"role":"tool","names":["tanium_patch_tools","tanium_comply_tools"]},{"role":"assistant","lines":["1,284 of 41,905 endpoints are running an affected Windows build.","63 are internet-facing and reachable from outside your perimeter.","Here's the staged remediation plan, sequenced by exposure…"],"holdMs":4000}]},"seo":{"title":"Atlas MCP Quick Start"}},"lastModified":"2026-10-06T12:06:34.000Z","pagePropGetterError":{"message":"","name":""}},"slug":"/guides/core-platform/atlas_mcp_quickstart","userData":{"isAuthenticated":false,"teams":["anonymous"]},"isPublic":true}