Netskope

by johnneerdael

3 stars
2.1k downloads
Not rated
GitHub Website

About

Integrates with Netskope API to manage private access infrastructure, enabling automated publisher lifecycle, app configuration, policy creation, and traffic diagnostics.

Details

Author
johnneerdael
Repository
johnneerdael/privateaccess-mcp
GitHub stars
3
Downloads
2,088
Categories
Productivity, Developer Tools, Design, Workplace, AI, Infrastructure, Frontend, API, Other
Tags
#integration

- AI-native design with parameter validation and rich error context
- Workflow orchestration with built-in retry and error recovery
- Schema-driven input validation using Zod
- Rate limiting and API quota management
- SCIM integration for identity resolution
- Streamable HTTP transport with liveness endpoint

Setting up with Highlight

This MCP is not yet compatible with Highlight’s one-click setup. However, you can still use it with Highlight by following these steps:

  1. Download and install Highlight from highlightai.com/download
  2. Navigate to the plugins tab and select "Add Custom Plugin"
  3. Configure the plugin with the settings below
    Plugin Name Netskope
    Command (node, npx, python, etc.) node
    Arguments
    • Argument 1 /path/to/privateaccess-mcp/build/index.js
    Environment
    • NETSKOPE_TOKEN your-api-token
    • NETSKOPE_BASE_URL https://your-tenant.goskope.com

    Please refer to the README for specific instructions on how to obtain API keys or other required environment variables.

  4. Enable "Start Automatically" if you want the plugin to start when Highlight launches

From the repository

1. Environment Setup

   export NETSKOPE_BASE_URL="https://your-tenant.goskope.com"
export NETSKOPE_TOKEN="your-api-token"

2. Install and Run

   npm install
npm run build
npm start

3. Connect via MCP Client

   {
"mcpServers": {
"netskope-npa": {
"command": "node",
"args": ["/path/to/privateaccess-mcp/build/index.js"],
"env": {
"NETSKOPE_BASE_URL": "https://your-tenant.goskope.com",
"NETSKOPE_TOKEN": "your-api-token"
}
}
}
}

| Category | Description | Link |
|----------|-------------|------|
| 🏗️ Architecture | Server design and patterns | Server Architecture |
| 🛠️ Tools Reference | Complete tool documentation | Publisher Tools, Private App Tools, Policy Tools |
| 🔄 Workflows | Common automation patterns | Common Workflows |
| 💼 Real Examples | Complete use cases | Real-World Examples |

AI Response: Automated compliance assessment
- ✅ Audits all publishers for version compliance
- ✅ Identifies applications without access policies
- ✅ Validates SCIM group references in policies
- ✅ Generates compliance score and remediation plan
- ✅ Creates detailed findings report with priorities

For clients that take a JSON map (Cursor, Windsurf, custom hosts):

{
  "mcpServers": {
    "netskope": {
      "url": "https://YOUR-MCP-HOST.example.com/mcp",
      "headers": {
        "X-Netskope-Tenant": "https://YOUR-TENANT.goskope.com",
        "Authorization": "Bearer YOUR_NETSKOPE_API_TOKEN"
      }
    }
  }
}

- Documentation Issues: Open an issue on GitHub
- Feature Requests: Create a feature request issue
- Bug Reports: Use the bug report template
- Security Issues: See SECURITY.md

---

This MCP server transforms complex Netskope NPA management into simple, AI-driven conversations.

Claude Desktop / Cursor

Paste into your MCP client config file to install this server.

{
    "mcpServers": {
        "netskope": {
            "env": {
                "NETSKOPE_TOKEN": "your-api-token",
                "NETSKOPE_BASE_URL": "https://your-tenant.goskope.com"
            },
            "args": [
                "/path/to/privateaccess-mcp/build/index.js"
            ],
            "command": "node"
        }
    }
}

Linux

{
    "env": {
        "NETSKOPE_TOKEN": "your-api-token",
        "NETSKOPE_BASE_URL": "https://your-tenant.goskope.com"
    },
    "args": [
        "/path/to/privateaccess-mcp/build/index.js"
    ],
    "command": "node"
}

Macos

{
    "env": {
        "NETSKOPE_TOKEN": "your-api-token",
        "NETSKOPE_BASE_URL": "https://your-tenant.goskope.com"
    },
    "args": [
        "/path/to/privateaccess-mcp/build/index.js"
    ],
    "command": "node"
}

Windows

{
    "env": {
        "NETSKOPE_TOKEN": "your-api-token",
        "NETSKOPE_BASE_URL": "https://your-tenant.goskope.com"
    },
    "args": [
        "/path/to/privateaccess-mcp/build/index.js"
    ],
    "command": "node"
}

Netskope NPA MCP Server

A comprehensive Model Context Protocol (MCP) server for managing Netskope Private Access (NPA) infrastructure through AI-powered automation.

📚 Complete Documentation

This project includes extensive documentation organized for easy navigation:

👉 Start with the Complete Documentation - Overview and navigation guide

Quick Access Links

| Category | Description | Link |
|----------|-------------|------|
| 🏗️ Architecture | Server design and patterns | Server Architecture |
| 🛠️ Tools Reference | Complete tool documentation | Publisher Tools, Private App Tools, Policy Tools |
| 🔄 Workflows | Common automation patterns | Common Workflows |
| 💼 Real Examples | Complete use cases | Real-World Examples |

Tool Overview

The MCP server provides 84 specialized tools across 10 categories:

| Category | Tools | Primary Use Cases |
|----------|-------|------------------|
| Publishers | 9 tools | Infrastructure deployment and management |
| Private Apps | 15 tools | Application lifecycle and configuration |
| Local Brokers | 7 tools | Network connectivity and routing |
| Policy Management | 6 tools | Access control and security rules |
| SCIM Integration | 5 tools | Identity and user management |
| Upgrade Profiles | 7 tools | Automated maintenance scheduling |
| Steering | 3 tools | Traffic routing and associations |
| Alerts | 2 tools | Event monitoring and notifications |
| Search | 2 tools | Resource discovery and querying |
| Validation | 2 tools | Configuration compliance |

Real-World Usage Examples

🏢 "Set up complete NPA infrastructure for our new London office"

AI Response: Executes comprehensive deployment workflow - ✅ Creates publisher with auto-upgrade profile - ✅ Configures local broker for internal routing - ✅ Sets up core business applications (CRM, ERP, File Server) - ✅ Creates access policies with SCIM group validation - ✅ Enables monitoring and discovery for office network - ✅ Generates registration token for field deployment

🚨 "URGENT: Security incident - lock down HR/Finance apps immediately"

AI Response: Emergency security response workflow - ✅ Identifies all HR/Finance applications automatically - ✅ Creates emergency policy group with highest priority - ✅ Blocks access for all users except incident response team - ✅ Enhances monitoring for security events - ✅ Tags applications for incident tracking

📊 "Perform comprehensive compliance audit of our NPA environment"

AI Response: Automated compliance assessment - ✅ Audits all publishers for version compliance - ✅ Identifies applications without access policies - ✅ Validates SCIM group references in policies - ✅ Generates compliance score and remediation plan - ✅ Creates detailed findings report with priorities

Quick Start

1. Environment Setup

   export NETSKOPE_BASE_URL="https://your-tenant.goskope.com"
export NETSKOPE_TOKEN="your-api-token"

2. Install and Run

   npm install
npm run build
npm start

3. Connect via MCP Client

   {
"mcpServers": {
"netskope-npa": {
"command": "node",
"args": ["/path/to/privateaccess-mcp/build/index.js"],
"env": {
"NETSKOPE_BASE_URL": "https://your-tenant.goskope.com",
"NETSKOPE_TOKEN": "your-api-token"
}
}
}
}

Key Features

🤖 AI-Native Design

- Tools designed for LLM interaction with clear descriptions - Automatic parameter validation and transformation - Rich error context for troubleshooting

🔄 Workflow Orchestration

- Tools automatically coordinate with each other - Built-in retry logic and error recovery - Transactional operations where possible

🛡️ Production Ready

- Comprehensive input validation using Zod schemas - Rate limiting and API quota management - Detailed logging and monitoring

🔗 Integration Patterns

- SCIM integration for identity resolution - Search tools for resource discovery - Validation tools for compliance checking

Installation Options

NPM Package

npm install @johnneerdael/ns-private-access-mcp

Local Development

git clone https://github.com/johnneerdael/privateaccess-mcp.git
cd privateaccess-mcp
npm install
npm run build

Generic JSON client config

For clients that take a JSON map (Cursor, Windsurf, custom hosts):

{
  "mcpServers": {
    "netskope": {
      "url": "https://YOUR-MCP-HOST.example.com/mcp",
      "headers": {
        "X-Netskope-Tenant": "https://YOUR-TENANT.goskope.com",
        "Authorization": "Bearer YOUR_NETSKOPE_API_TOKEN"
      }
    }
  }
}

Self-hosting

Prefer to run your own instance? Two compose files are shipped:

| File | Purpose | Command |
|------|---------|---------|
| docker-compose.yml | Run the prebuilt multi-arch image from GHCR. | docker compose up -d |
| docker-compose.build.yml | Build from local sources (for development). | docker compose -f docker-compose.build.yml up --build |

One-liners without compose:

```bash

No reviews yet — be the first

Sign in to leave a review

Use Google, GitHub, or an email account so ratings stay tied to real people.

Email sign in

No reviews posted yet.