Skip to main content
Data Infrastructure Insights

Set up the DII MCP Server

Contributors netapp-alavoie

Use this guide to connect an MCP-compatible AI client to DII.

Note The DII MCP is a Preview feature and is therefore subject to change.

Before you begin

You need:

  • Access to a DII tenant.

  • A DII user or service identity authorized to read the resources you intend to query.

  • The remote MCP endpoint supplied for your DII environment.

  • An MCP client that supports remote HTTP servers and your organization's authentication method.

The examples use <DII_HOST_URL> as a placeholder. Do not paste access tokens into source-controlled files. For example, the URL used by Cursor is:

https://<DII_HOST_URL>/api/v1/mcp

See the specific code snippets for your connection.

Configure the MCP client

  1. Navigate to Admin > API Access and select the "MCP Configuration" tab.

  2. Select the client you wish to configure.

  3. Provide a meaningful name and an expiration, and select Generate Token.

  4. Copy the code snippet You will only be able to copy this during this step. The token is hidden in the snippet but will paste correctly into your client app.

  5. In the client settings, enter the correct DII Host URL in the "url" field.

  6. Save the configuration.

Important Do not place bearer tokens in shell history, prompts, screenshots, project files, or source control.

Verify access

After the client reports that the server is connected, you can start sending requests like the following:

List the DII object types available to me.
List the DII log types available to me.
List my acquisition units without displaying IP addresses or UUIDs.

Successful discovery confirms connectivity, but it does not guarantee access to every underlying resource. Tenant features, collectors, and permissions determine what data is returned.

Credential safety

  • Prefer interactive OAuth or another short-lived credential flow where available.

  • Use a dedicated service identity for unattended clients.

  • Do not put tokens in prompts, screenshots, examples, issue descriptions, or source control.

  • Do not ask the agent to display complete webhook addresses.

For additional guidance, see Security and privacy.