Reco's MCP server connects Claude directly to your tenant, so you can query live security data (threat alerts, posture issues, identities, OAuth grants, discovered agents) in plain language. Connect via OAuth, which mirrors your existing Reco permissions, or a scoped API key for automated workflows; either way, access never exceeds what that credential is already authorized to see. Claude can also take action, like adding comments or updating a role, and comes with four guided workflows: resolving an identity across systems, investigating recent activity, running a compliance gap analysis, and surfacing your highest-severity open issues.
Tools
- list_events
- list_threat_alerts
- list_posture_issues
- list_posture_checks
- list_posture_entities
- list_posture_issues_comments
- list_identities
- list_accounts
- list_groups
- list_apps
- list_app_instances
- list_apps_comments
- list_saas_to_saas
- list_ai_agents
- list_integrations
- list_devices
- list_files
- list_ip_addresses
- list_audit_logs
- list_threat_detection_policies
- list_exclusions
- list_external_business_units
- get_threat_alert
- list_posture_score_history
Only use connectors from developers you trust. Anthropic does not control which tools developers make available and cannot verify that they will work as intended or that they won’t change.