
Company News
Free Business Plan Upgrades for Open Source Maintainers
Open source maintainers are under more pressure than ever. We're raising our open source program from the Team plan to the Business plan, free.
qualys-mcp-full
Advanced tools
Model Context Protocol server for full Qualys portal management (VMDR, PC, WAS, Cloud Agent, Container Security, TotalCloud, Patch, CSAM, EASM, and more) across multiple Qualys consoles.
A Model Context Protocol server for full Qualys portal management — expose VMDR, Policy Compliance, WAS, Cloud Agent, Container Security, TotalCloud, Patch Management, CSAM/GAV, EASM and administration to any MCP‑capable client (Claude, and other MCP hosts).
One process per Qualys console (run as many as you have subscriptions). Built on FastMCP, with a single client that speaks all three Qualys API families, a strict read / write / destructive safety model, and credentials that never touch chat or plaintext.
list_hosts, list_host_detections, launch_scan,
search_was_findings, list_knowledgebase, get_cs_image_vulnerabilities,
and hundreds more, each mapped 1:1 to a documented Qualys API operation.self._fo /
self._qps / self._gateway.--check runs
fully offline with no credentials.| Regime | Base path | Auth | Payload |
|---|---|---|---|
| Classic "FO" | /api/2.0/fo/, /msp/ | Basic + X-Requested-With header | form → XML |
| QPS REST | /qps/rest/ | Basic | XML <ServiceRequest> / JSON |
| Gateway | gateway.<pod>.apps.qualys.com | Bearer JWT (from /auth) | JSON |
qualys_mcp/
server.py FastMCP server; lazy auth; --check offline validation
registry.py auto-discovers modules/*.py
client.py one client, three API regimes (FO / QPS / Gateway-JWT)
config.py per-console config + platform (POD) -> URL map
common/ auth (HTTP mw), errors, logging, rate_limit, utils, xml
modules/ base.py + one file per feature module (the bulk of the surface)
Adding a capability is just dropping a file in qualys_mcp/modules/ — see
docs/MODULE_BUILD_GUIDE.md.
python -m venv .venv
# Windows: .\.venv\Scripts\pip install -e .
# macOS/Linux: ./.venv/bin/pip install -e .
python -m qualys_mcp --check
Lists every discovered module with its tool count and exits — a good first smoke test.
You need a Qualys API user and your platform/POD code (e.g. US1, US2,
EU1; find it under your console URL or Help → About).
Any OS — environment variables:
export QUALYS_USERNAME='api-user'
export QUALYS_PASSWORD='api-pass'
export QUALYS_PLATFORM='US2' # or set QUALYS_API_URL / QUALYS_GATEWAY_URL
python -m qualys_mcp --transport streamable-http --host 127.0.0.1 --port 8781 --console-label consulting
Windows — DPAPI‑encrypted blobs (recommended for a persistent deployment):
# Encrypt once per console; the blob is user-scoped and stored under .secrets/
.\encrypt-qualys-creds.ps1 -Console consulting -Platform US2
.\encrypt-qualys-creds.ps1 -Console cloud -Platform US2
# Launch one instance per console (:8781, :8782)
.\start-qualys-mcp.ps1
# ...opt into destructive tools for a console only when you mean it:
.\start-qualys-mcp.ps1 -EnableDestructive cloud
# Optional: keep both alive across reboots via a Scheduled Task watchdog
.\register-qualys-mcp-task.ps1
See .env.example for every QUALYS_* setting.
A ready‑to‑use .mcp.json is included for Claude Code:
{
"mcpServers": {
"qualys-consulting": { "type": "http", "url": "http://localhost:8781/mcp" },
"qualys-cloud": { "type": "http", "url": "http://localhost:8782/mcp" }
}
}
scripts/register_mcp_clients.py shows how to register the same local‑HTTP
servers into several MCP clients at once.
QUALYS_ENABLE_DESTRUCTIVE=true.confirm=<id>
argument before it will act — so a destructive call can never happen by
accident from a single prompt.Read docs/SAFETY_AUDIT.md for the full tiering.
qualys_mcp/modules/.QUALYS_ENABLE_DESTRUCTIVE=true (the extra ~40 are the guarded destructive
tools that otherwise stay hidden).The full per‑module table (registry name, API family, tool counts, one‑line description) is in docs/MODULE_INDEX.md, and a complete endpoint → tool → action breakdown is in docs/ENDPOINTS_TOOLS_ACTIONS.md.
| Variable | Purpose |
|---|---|
QUALYS_USERNAME / QUALYS_PASSWORD | API user credentials |
QUALYS_PLATFORM | POD code (US1…KSA1) — auto‑fills API + Gateway URLs |
QUALYS_API_URL / QUALYS_GATEWAY_URL | Explicit overrides for unlisted PODs |
QUALYS_CONSOLE_LABEL | Names the console in logs and the server name |
QUALYS_ENABLE_DESTRUCTIVE | true to register the destructive tier |
QUALYS_MCP_MODULES | Comma‑separated allowlist to scope a console to its licensed modules |
QUALYS_MCP_API_KEY | Optional shared secret for the HTTP transport |
pip install -e ".[dev]"
python -m qualys_mcp --check # offline validation
pytest # unit tests (no network)
ruff check . # lint
Contributions welcome — see CONTRIBUTING.md.
This is an independent, community project. It is not affiliated with, endorsed by, or supported by Qualys, Inc. "Qualys" and product names are trademarks of their respective owners. Use against your own subscriptions in accordance with your Qualys license and API terms. The software is provided "as is" (see LICENSE); you are responsible for what you run against your environment — especially the destructive tier.
MIT © 2026 Rijul Sharma
FAQs
Model Context Protocol server for full Qualys portal management (VMDR, PC, WAS, Cloud Agent, Container Security, TotalCloud, Patch, CSAM, EASM, and more) across multiple Qualys consoles.
We found that qualys-mcp-full demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Company News
Open source maintainers are under more pressure than ever. We're raising our open source program from the Team plan to the Business plan, free.

Security News
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.

Security News
During a UK cyber test, a Mythos 5 agent used sockpuppets, social engineering, and prompt injection to try to get a maintainer to merge malware.