Prerequisites
- A TrueFoundry account with permission to add MCP servers.
- A CrowdStrike Falcon subscription with API access.
- Falcon API client credentials for each user or a shared service account.
Create Falcon API Credentials
In Falcon, go to Support > API Clients and Keys, click Add new API client, and select only the API scopes needed by your enabled modules.
Copy the Client ID and Client Secret immediately.
Register in TrueFoundry
Create a Hosted Stdio-based MCP Server with:
Use
https://api.crowdstrike.com for US-1, https://api.us-2.crowdstrike.com for US-2, https://api.eu-1.crowdstrike.com for EU-1, and https://api.laggar.gcw.crowdstrike.com for US-GOV.
For per-user credentials, set FALCON_CLIENT_ID and FALCON_CLIENT_SECRET as templated env vars and have users add Auth Overrides.