
Research
/Security News
Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack
Popular npm packages keyv and cacheable compromised.
MCP server for SolarWinds Service Desk (SWSD / Samanage). Dual transport: stdio for local agents, Streamable HTTP for Copilot Studio and hosted deployments. Not affiliated with SolarWinds.
MCP server for SolarWinds Service Desk (SWSD / Samanage). Works with any Model Context Protocol client to handle tickets, service requests, knowledge-base work, change/release workflows, assets/CMDB context, procurement records, risks, time entries, and attachments using each user's own SWSD API token. See the client compatibility matrix for the tested list.
📖 Full docs: mcp-swsd.pages.dev
The server holds zero credentials at rest. Tokens are forwarded per-request, never persisted, never logged, and only sent to the configured SWSD API host.
You need:
Install with either supported local option:
npx -y swsd-mcp.swsd-mcp, confirm that the publisher is mikimatsub, then select Allow.
swsd, then choose Global for your VS Code profile or Workspace for the current project.The non-VS-Code clients listed below use this common JSON shape. Add it under mcpServers in your client's config file:
{
"mcpServers": {
"swsd": {
"command": "npx",
"args": ["-y", "swsd-mcp"],
"env": {
"SWSD_TOKEN": "your-jwt-here",
"SWSD_BASE_URL": "https://api.samanage.com"
}
}
}
}
Replace your-jwt-here with your token. EU tenants use https://apieu.samanage.com instead. To customize behavior, add any configuration variable (most common: SWSD_PROFILE to choose the tool set) into the same env block.
| Client | Config file path |
|---|---|
| Claude Desktop (macOS) | ~/Library/Application Support/Claude/claude_desktop_config.json |
| Claude Desktop (Windows) | %APPDATA%\Claude\claude_desktop_config.json |
| Claude Desktop (Linux) | ~/.config/Claude/claude_desktop_config.json |
| Claude Code | ~/.claude.json (or use the shortcut below) |
| Cursor | ~/.cursor/mcp.json |
| Continue, Cline, other clients | check your client's docs — same JSON shape |
Create the file if it doesn't exist. Then restart your client.
Claude Code shortcut — skip editing the file by hand. This single line pastes verbatim into any shell (bash, zsh, PowerShell, cmd):
claude mcp add swsd --env SWSD_TOKEN="your-jwt-here" --env SWSD_BASE_URL="https://api.samanage.com" -- npx -y swsd-mcp
Microsoft Copilot Studio — different path. Copilot Studio can't spawn local processes, so it needs an HTTP-transport server. See copilot-studio/README.md and the Azure Container Apps recipe.
In your MCP client, ask:
"Use swsd to check if you can connect."
The agent should call swsd_health_check and report success. If it does, you're set up. Try a few more:
updated_within: "7d" (also "24h", "1w", "30d").swsd_list_my_incidents calls swsd_get_me internally, so you don't have to spell out an email.| Category | Tools |
|---|---|
| Utility | swsd_get_server_info, swsd_health_check, swsd_get_me |
| Incidents | swsd_list_incidents, swsd_list_my_incidents, swsd_get_incident, swsd_create_incident, swsd_update_incident, swsd_assign_incident, swsd_update_incident_state, swsd_link_solution_to_incident |
| Comments | swsd_list_incident_comments, swsd_add_incident_comment, swsd_update_comment |
| Tasks | swsd_list_incident_tasks, swsd_create_incident_task, swsd_update_task_state |
| Problems | swsd_list_problems, swsd_get_problem, swsd_create_problem |
| Change & Release | swsd_list_changes, swsd_get_change, swsd_create_change, swsd_update_change, swsd_list_releases, swsd_get_release, swsd_create_release, swsd_update_release |
| Assets & CMDB | swsd_list_hardware_assets, swsd_get_hardware_asset, swsd_list_mobile_devices, swsd_get_mobile_device, swsd_list_printers, swsd_get_printer, swsd_list_software_assets, swsd_get_software_asset, swsd_list_other_assets, swsd_get_other_asset, swsd_list_configuration_items, swsd_get_configuration_item |
| Procurement & Risk | swsd_list_contracts, swsd_get_contract, swsd_list_purchase_orders, swsd_get_purchase_order, swsd_list_vendors, swsd_get_vendor, swsd_list_risks |
| Time tracking | swsd_list_time_tracks, swsd_log_time, swsd_update_time_track |
| Attachments | swsd_upload_attachment |
| Solutions / KB | swsd_search_solutions, swsd_get_solution, swsd_create_solution, swsd_update_solution |
| Service Catalog | swsd_list_catalog_items, swsd_get_catalog_item, swsd_create_service_request |
| Lookups | swsd_list_categories, swsd_list_sites, swsd_list_departments, swsd_list_users, swsd_list_groups, swsd_list_roles |
| Custom fields | swsd_describe_custom_fields |
| Audits | swsd_get_record_audits |
Each tool's input schema, description, and output shape is auto-discovered by your MCP client at runtime. See the Tools reference for full per-tool documentation.
Seven read tools ship interactive UI bundles using the MCP Apps capability. On capable hosts (Claude Desktop, Claude Web, VS Code Copilot Chat, ChatGPT, Goose, Postman), the tool returns a rendered widget alongside the structured response. On text-only hosts (Claude Code, LM Studio), the same tools return their normal structured payload.

Example — swsd_list_incidents rendering the incident-list widget. Synthetic data; no real tenant info. See the full gallery for screenshots of all seven widgets.
| Tool | Widget | What it renders |
|---|---|---|
swsd_get_incident | incident-detail | Single-record card (description, due date, SLA, resolution, custom fields) |
swsd_get_solution | solution-detail | Knowledge-base article with sanitized HTML body |
swsd_list_incidents, swsd_list_my_incidents | incident-list | Filterable, sortable table |
swsd_list_incident_comments | comment-thread | Vertical conversation with author chips, public/private badges |
swsd_get_record_audits | audit-timeline | Timeline grouped by day with action chips and field diffs |
swsd_get_catalog_item | catalog-item-form | Form that submits via swsd_create_service_request |
swsd_describe_custom_fields | custom-fields | Searchable explorer with scope/module filters |
See the Widgets reference for screenshots and per-widget detail.
Most users only need SWSD_TOKEN and SWSD_BASE_URL:
| Variable | Default | Notes |
|---|---|---|
SWSD_TOKEN | — | Required. Your SWSD admin token (JWT). |
SWSD_BASE_URL | https://api.samanage.com | EU tenant: https://apieu.samanage.com |
SWSD_PROFILE | agent | triage, agent, knowledge, operations, or full — see Profiles |
SWSD_WRITE_MODE | live | live, dry-run, or disabled — preview or block write tools without changing profiles |
For the full env-var reference (HTTP transport, retries, rate limits, allowlists), see Configuration.
Profiles control which tools are registered at startup. Cannot be changed mid-session.
| Profile | Intent | Tool count |
|---|---|---|
triage | Read-heavy first-line support + commenting | 14 |
agent | Full ticket-handler workflow (default) | 37 |
knowledge | KB-author workflow + incident reads | 15 |
operations | Agent workflow plus change/release, ITAM, CMDB, procurement, and risk context | 64 |
full | Every tool | 66 |
Use SWSD_ENABLE_EXTRAS=swsd_foo,swsd_bar to add specific tools on top of a profile.
Quick Start above runs swsd-mcp on your own machine — your MCP client spawns it on demand via npx. Most users stop there.
Set up an HTTP-mode server only if you need:
The Docker image runs anywhere — Azure, AWS, GCP, Render, Fly.io, your own VM. See Deployment for the full guide and the Azure Container Apps recipe (recommended for Copilot Studio; scale-to-zero pricing).
SECURITY.md — vulnerability reporting via GitHub Security Advisoriesdocs/SECURITY-POSTURE.md — security controls, supply-chain hardening, verification methodsCONTRIBUTING.md — bug reports, PR review criteria, local development setupCHANGELOG.md — version historycopilot-studio/ — Microsoft Copilot Studio Swagger connector specs and import guidedocs/deployment/ — cloud deployment recipesMIT — see LICENSE. Provided "as is" without warranty.
SolarWinds, Samanage, and Service Desk are trademarks of SolarWinds Worldwide, LLC. This project is not affiliated with, endorsed by, or sponsored by SolarWinds. It wraps the publicly documented SWSD REST API.
FAQs
MCP server for SolarWinds Service Desk (SWSD / Samanage). Dual transport: stdio for local agents, Streamable HTTP for Copilot Studio and hosted deployments. Not affiliated with SolarWinds.
The npm package swsd-mcp receives a total of 65 weekly downloads. As such, swsd-mcp popularity was classified as not popular.
We found that swsd-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Popular npm packages keyv and cacheable compromised.

Security News
A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to PyPI.

Security News
/Company News
Socket has joined the new Composer and Packagist sponsorship program as a launch sponsor, supporting the team that keeps PHP's package ecosystem secure.