Stdio Mode
Stdio is the default transport. The MCP client launches the server as a subprocess over stdin/stdout. No network port opens, no auth is required — the OS user who launched the process is implicitly trusted.
In stdio mode:
- Roles do not apply (implicitly
admin). - The audit log is not written (a
NullAuditLogis used). - Confirm-token enforcement does not apply — mutating tools like
provision-policyandringfence-batchwork without a token. - PCE credentials come from the
PCE_*env vars (same as shared HTTP mode).
Running directly
# With .env file (recommended)
python -m illumio_mcp
# With explicit env
PCE_HOST=https://pce.example.com PCE_PORT=8443 PCE_ORG_ID=1 \
API_KEY=mykey API_SECRET=mysecret python -m illumio_mcp
The server starts and exits cleanly when stdin closes. Starting stdio server is a DEBUG line, so it only appears in illumio-mcp.log when MCP_LOG_LEVEL=DEBUG; at the default INFO the log stays quiet.
Claude Desktop
macOS: ~/Library/Application Support/Claude/claude_desktop_config.json Windows: %APPDATA%\Claude\claude_desktop_config.json
Using uv (recommended)
{
"mcpServers": {
"illumio-mcp": {
"command": "uv",
"args": [
"--directory",
"/path/to/illumio-mcp-server",
"run",
"illumio-mcp"
],
"env": {
"PCE_HOST": "https://your-pce.example.com",
"PCE_PORT": "8443",
"PCE_ORG_ID": "1",
"API_KEY": "your_api_key",
"API_SECRET": "your_api_secret"
}
}
}
}
Using Docker
{
"mcpServers": {
"illumio-mcp-docker": {
"command": "docker",
"args": [
"run", "-i", "--init", "--rm",
"--env-file", "/Users/YOUR_USERNAME/.illumio-mcp.env",
"ghcr.io/alexgoller/illumio-mcp-server:latest"
]
}
}
}
Where ~/.illumio-mcp.env contains:
PCE_HOST=https://your-pce.example.com
PCE_PORT=8443
PCE_ORG_ID=1
API_KEY=your_api_key
API_SECRET=your_api_secret
Cursor
In Cursor, add the server to your MCP configuration (Settings → MCP):
{
"illumio-mcp": {
"command": "uv",
"args": [
"--directory",
"/path/to/illumio-mcp-server",
"run",
"illumio-mcp"
],
"env": {
"PCE_HOST": "https://your-pce.example.com",
"PCE_PORT": "8443",
"PCE_ORG_ID": "1",
"API_KEY": "your_api_key",
"API_SECRET": "your_api_secret"
}
}
}
TLS verification
Set PCE_TLS_VERIFY=false to disable TLS certificate verification for PCE instances with self-signed certificates. Do not disable TLS verification in production environments with trusted certificates.
"env": {
"PCE_TLS_VERIFY": "false",
...
}