How to Use the CrowdSec MCP in Claude
Give Claude Desktop direct access to CrowdSec threat intelligence to investigate IPs and active bans right in your chat window.
Works with every AI agent you already use
…and any MCP-compatible client
Connect CrowdSec MCP to Claude Desktop
Create your Vinkius account to connect CrowdSec to Claude Desktop and route execution through our secure gateway. The platform manages server hosting, runtime updates, and security layers. Configuration requires no manual server provisioning.
Investigate Suspicious IPs via Claude Desktop
The `get_cti_smoke` tool lets Claude Desktop pull the global reputation for any IP address instantly. When your logs show weird traffic spikes, you do not have to leave the chat to figure out if the source is a known bad actor. You just paste the IP into your prompt. The agent hits the CrowdSec CTI database, reads the smoke score, and tells you exactly what kind of attacks that address is famous for.
Read Active LAPI Decisions
Using the `get_decisions` tool, your AI client queries your Local API to see exactly who is blocked right now. This means you can ask Claude to summarize the current firewall state without touching a command line. The server pulls down the active list of bans and captchas applied to your infrastructure. You get a plain English breakdown of which subnets are locked out and why the security engine flagged them.
Monitor Threat Streams with this MCP Server
The `get_decisions_stream` tool turns this MCP Server into a live monitor for new and deleted security rules. Claude can poll the local engine to see what changed in the last five minutes. Instead of digging through raw logs, you ask the agent what IPs just got banned. It fetches the latest delta from the stream and formats the blocklist updates for your incident report.
Set up CrowdSec MCP in Claude Web or Desktop
- 1
Open Claude Settings
Go to claude.ai, click your profile icon, then navigate to Customize → Connectors.
- 2
Add Custom Connector
Click the "+" button and select Add custom connector. Paste your Vinkius endpoint URL:
https://edge.vinkius.com/[YOUR_TOKEN_HERE]/mcpReplace[YOUR_TOKEN_HERE]with your token from cloud.vinkius.com. For OAuth-protected servers, expand Advanced settings to add credentials. - 3
Start a conversation
Open a new chat. The CrowdSec MCP tools are available immediately — no restart needed.
Endpoint URL
https://edge.vinkius.com/[YOUR_TOKEN_HERE]/mcp No configuration file needed — paste the URL directly in the Claude web interface.
Available on Free (1 connector), Pro, Max, Team, and Enterprise plans.
Why Choose Vinkius
Vinkius connects your tools to AI with real-time monitoring and automatic cost savings — all from one dashboard.
Real-time monitoring
Live
visibility into every interaction
Connect your favorite tools to your AI and see exactly what's happening — every request, every response, in real time.
Built-in savings
60%
lower AI costs
Vinkius compresses data between your apps and your AI automatically. Lower bills every month — no configuration required.
Single dashboard
One
place for every integration
Every tool your AI connects to, managed from a single screen. One account, complete control.
Common questions about CrowdSec MCP in Claude Desktop
Use it with your favorite AI tools
Connect this server to Cursor, Claude, VS Code, and more.
Start using the CrowdSec MCP today
We host it, we monitor it, we maintain it. You just paste one token.