85trust / 100

Castle MCP by usefulapi

by castle.usefulapi.io in Security & trust

MCP serverPassing, checked 3 h ago

Investigate security events and manage the allow/deny lists an analyst acts on.

https://castle.usefulapi.io/mcp

Last 30 days

All checks passedSome failedAll failedNot checked
Uptime
100%
Response time
306 ms typical, 306 ms slowest 5%
Last check
3 h ago
Next check
in 4 h

How to call it

Add it to any MCP client that supports remote servers.

{
  "mcpServers": {
    "castle-mcp-by-usefulapi": {
      "type": "http",
      "url": "https://castle.usefulapi.io/mcp"
    }
  }
}

14 tools

  • castle_get_events_schema

    List the event fields you can filter and group on, with their types. Read this first — the other query tools need real field names. Castle: GET /v1/events/schema.

  • castle_search_events

    Query the security event stream — logins, registrations, transactions and their risk verdicts. Read-only despite being a POST: Castle takes the query in the body. Castle: POST /v1/events/query.

  • castle_group_events

    Aggregate matching events by one or more fields — the fast way to see which IPs, devices or countries dominate a spike. Read-only despite being a POST. Castle: POST /v1/events/group.

  • castle_search_lists

    Find the allow/deny lists defined in the environment. Read-only despite being a POST. Castle: POST /v1/lists/query.

  • castle_get_list

    Fetch a single list with its primary and secondary field definitions. Castle: GET /v1/lists/{id}.

  • castle_search_list_items

    Search the entries of one list — the blocked IPs, emails or device ids it holds. Read-only despite being a POST. Castle: POST /v1/lists/{list_id}/items/query.

  • castle_count_list_items

    Count the entries in one list, with the same optional filters as the search. Read-only despite being a POST. Castle: POST /v1/lists/{list_id}/items/count.

  • castle_get_list_item

    Fetch a single list entry — its value, who added it, the comment and its archive time. Castle: GET /v1/lists/{list_id}/items/{id}.

  • castle_create_list

    Create a new allow or deny list. primary_field is the event field its entries match on, e.g. ip or user.email. Castle: POST /v1/lists.

  • castle_update_list

    Rename a list or change its colour or description. Castle: PUT /v1/lists/{id}.

  • castle_create_list_item

    Add an entry to a list — for example block an IP or an email. This changes live policy behaviour. Castle: POST /v1/lists/{list_id}/items.

  • castle_update_list_item

    Change the comment on a list entry. Castle: PUT /v1/lists/{list_id}/items/{id}.

  • castle_archive_list_item

    Archive a list entry so it stops matching. Reversible with castle_unarchive_list_item. Castle: DELETE /v1/lists/{list_id}/items/{id}/archive.

  • castle_unarchive_list_item

    Restore a previously archived list entry so it matches again. Castle: PUT /v1/lists/{list_id}/items/{id}/unarchive.

Security scan

  • No findings. We scan names, descriptions and tool definitions for hidden instructions and other prompt-injection patterns.

Recent checks

WhenResultHTTPTime
3 h agoPassed200306 ms