Bitsight MCP: Tools and Capabilities

The Bitsight Model Context Protocol (MCP) server exposes a comprehensive set of tools that enable AI agents to programmatically access, query, and manage data within the Bitsight platform. The Bitsight MCP provides a structured interface to Bitsight's APIs and knowledge base, allowing agents to discover capabilities, execute queries and mutations, and retrieve contextual information about security concepts and operations.

Overview of Bitsight MCP tools

The Bitsight MCP offers eight core tools that cover API discovery, query execution, schema inspection, and knowledge management. These tools work together to provide both high-level guidance and low-level access to Bitsight's capabilities.

Discovery and navigation tools

List API groups. The list_api_groups tool surfaces all available API groups and versions within the Bitsight platform. Each group represents a functional area — such as Alerts, Companies, Users, Threats, or Breaches — and specifies the API version (v1, v2, vrm_v1) in which that group is available. This tool is the starting point for discovering what's possible through the Bitsight API.

List APIs. The list_apis tool returns a paginated list of all available API operations across all groups and versions. You can filter results by API group, HTTP method, or version to narrow results and avoid pagination through hundreds of endpoints. Each result includes the versioned API path, HTTP method, human-readable title, and a link to the full specification.

Search APIs. The search_apis tool lets you find specific operations by keyword or phrase. If you know the general area you're interested in — such as finding alert-related endpoints or company lookups — this tool helps you locate relevant operations without manually navigating the full list.

Schema and execution tools

Read API schema. The read_api_schema tool retrieves the complete OpenAPI specification for any Bitsight API operation. This includes parameter definitions, request and response schemas, constraints, and all available options. Use this before calling invoke_query_api or invoke_mutate_api to understand the exact input and output format for an operation.

Invoke query API. The invoke_query_api tool executes read-only (GET) operations against the Bitsight API. Pass the versioned API path and any required parameters, and the tool returns the response data. This is how you retrieve companies, alerts, threats, assessments, and other security intelligence from Bitsight.

Invoke mutate API. The invoke_mutate_api tool executes write operations (POST, PUT, PATCH, DELETE) against the Bitsight API. Use this tool when you need to create records, update existing data, manage access controls, or perform other state-changing operations within Bitsight.

Knowledge and feedback tools

Search knowledge base. The search_kb tool searches the Bitsight knowledge base — including documentation, support articles, and reference material — by keyword or phrase. This tool is useful when you need contextual information about Bitsight products, concepts, or operational guidance without leaving your workflow.

Submit API advice. The submit_api_advice tool allows you to send feedback about Bitsight API operations directly to the Bitsight team. If you encounter confusing documentation, missing functionality, or suggestions for improvement, use this tool to communicate feature requests and bug reports.

How AI agents use the Bitsight MCP

An AI agent using the Bitsight MCP typically follows this pattern: discover available APIs through list_api_groups and search_apis, inspect the operation schema with read_api_schema, then execute read operations via invoke_query_api or write operations via invoke_mutate_api. The agent handles authentication, error handling, and response parsing transparently.

For exploratory or ambiguous requests, the agent can use search_kb to retrieve contextual information about Bitsight concepts and operations, and submit_api_advice to report issues or request improvements to the API.

API groups and coverage

The Bitsight API spans multiple functional areas, each organized into a group. For the complete interactive API reference, visit the Bitsight API documentation..

Key groups include:

Asset and company management. Companies, Assets, Portfolio, and Company Relationships groups provide access to your organization's asset inventory, company records, and relationship data.

Security findings and intelligence. Alerts, Threats, Breaches, and Breach Intel groups cover security events, threat intelligence, and breach information tied to your environment.

User and access control. Users and Access Groups allow you to manage team members, permissions, and role-based access within Bitsight.

Assessment. Assessments and Company Assessment groups help you measure and communicate the business impact of security risks.

Specialized workflows. BII, Benchmarking Configuration, AppRegions, Async Job, Activity Logs, and other groups support specific operational and analytical use cases.

Most groups are available in v1, with newer operations and improvements available in v2. The list_api_groups output always indicates which version(s) contain each group and how many operations are available.

Authentication and access

All Bitsight MCP tools use the same authentication mechanism as the broader Bitsight API. You must have appropriate API credentials and sufficient permissions within your Bitsight organization to access any operation. Refer to your organization's API key management and access control documentation for setup details.

Operations respect Bitsight's role-based access control (RBAC). If you lack permission for an operation, the API will return an authorization error. Check your user role and contact your Bitsight administrator if you need additional permissions.

Discovering capabilities

Agents can use search_kb to understand Bitsight concepts and find documentation on specific endpoints. The list_api_groups tool provides a complete map of available API functionality, and search_apis helps locate specific operations by keyword. The submit_api_advice tool allows agents to report issues or request API improvements to the Bitsight team.

Was this article helpful?
1 out of 1 found this helpful

Comments

0 comments

Please sign in to leave a comment.