> For the complete documentation index, see [llms.txt](https://docs.strongdm.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.strongdm.com/ai/mcp-broker.md).

# MCP Broker for Desktop AI Agents

The MCP Broker lets desktop AI agents, including Claude and ChatGPT, natively connect to resources you are entitled to within StrongDM, with credential-less, fully audited access.

{% hint style="warning" %}
This feature is currently in closed-access technical preview. Functionality and documentation may change. Contact StrongDM for more information.
{% endhint %}

## Overview

The MCP Broker is a [Model Context Protocol](https://modelcontextprotocol.io/) (MCP) server built into the StrongDM client. It lets desktop AI agents such as Claude Desktop, Claude Code, and Codex discover and use the StrongDM resources you are already entitled to, directly from within the agent. Agents can list your resources, connect using just-in-time (JIT), run SQL queries and MongoDB commands, execute SSH commands, and run kubectl commands, all through StrongDM's secure, audited, credential-less access layer.

Your agent acts as the MCP client. The Broker receives the agent's MCP tool calls and converts each one into the resource's native protocol (such as PostgreSQL, SSH, or Kubernetes), and then it can route the traffic through the same StrongDM proxies that handle your normal client traffic. Every action runs under your existing StrongDM entitlements, and no credentials are ever exposed to the agent or stored on your machine.

{% hint style="info" %}
**MCP Broker Versus MCP Gateway**

These are different features. The MCP Broker lets your desktop agent reach StrongDM-protected resources (for example, databases, servers, clusters) over their native protocols. The MCP Gateway is a resource type that proxies traffic *to* upstream MCP servers (such as GitHub's). This page covers the MCP Broker only.
{% endhint %}

## **Supported agents**

| Agent                       | Support level          | Notes                                                         |
| --------------------------- | ---------------------- | ------------------------------------------------------------- |
| ChatGPT Desktop             | ✅ Supported            | Verified and supported                                        |
| Claude Code (CLI)           | ✅ Supported            | Primary development platform; recommended for best experience |
| Claude Desktop              | ✅ Supported            | Primary development platform; recommended for best experience |
| Cursor                      | ⚠️ Partially supported | Should work but has not been tested end to end                |
| Other MCP-compatible agents | ⚠️ Partially supported | May work; not officially validated in this preview            |

## **Supported resource types**

The Broker can **execute commands** against the following resource types. Other StrongDM resource types you are entitled to still appear in listings and support connect/disconnect, but the agent cannot execute against them through the Broker.

| Resource type                                                                          | Agent capability  | Minimum client version |
| -------------------------------------------------------------------------------------- | ----------------- | ---------------------- |
| Kubernetes resource types                                                              | kubectl commands  | 53.22.0                |
| Microsoft SQL Server (including Azure AD and Kerberos variants)                        | SQL queries       | 53.56.0                |
| MongoDB and Amazon DocumentDB                                                          | Database commands | 53.56.0                |
| MySQL resource types (including Aurora MySQL, Azure, MariaDB, and SingleStore/MemSQL)  | SQL queries       | 53.22.0                |
| PostgreSQL resource types (including Aurora, Azure, CockroachDB, Greenplum, and Citus) | SQL queries       | 53.22.0                |
| Redshift and Redshift Serverless                                                       | SQL queries       | 53.22.0                |
| SSH resource types                                                                     | Shell commands    | 53.22.0                |

## What Agents Can Do

The Broker exposes the following MCP tools to your agent.

| Tool                     | Description                                                                                                                                    |
| ------------------------ | ---------------------------------------------------------------------------------------------------------------------------------------------- |
| `connect` / `disconnect` | Establishes or tears down a just-in-time (JIT) connection to a resource                                                                        |
| `execute_k8s_command`    | Runs a kubectl command against an entitled cluster                                                                                             |
| `execute_mongo`          | Runs a MongoDB database command against an entitled MongoDB or DocumentDB resource                                                             |
| `execute_ssh`            | Runs a command on an entitled SSH server (60-second default timeout)                                                                           |
| `execute_sql`            | Runs a SQL query against an entitled database. Results are limited to 200 rows and 30 seconds by default (the agent can adjust both per query) |
| `list_resources`         | Lists every resource you are entitled to, with its type, ID, connection state, and the tools it supports                                       |
| `status`                 | Reports whether the Broker is ready: sign-in state, listener health, and the signed-in account                                                 |

The agent does not need to connect before executing: the execute tools automatically establish a connection to the resource if one is not already active.

All actions are subject to your existing StrongDM entitlements and are fully audited in the StrongDM [activity log](/admin/audit/logs.md), the same as access through the StrongDM client.

## Prerequisites

### **For End Users**

StrongDM Desktop Client version 53.22.0 or later (53.56.0 or later for Microsoft SQL Server and MongoDB) must be installed and running on your machine, and you must be authenticated to your StrongDM organization. Verify your version by running:

```shellscript
sdm --version
```

You should see output similar to:

```shellscript
sdm version 53.26.0 (20de84af2c20bb60149b5512c12b36726977c6d3) (crypto)
```

If you are not at the correct version, ensure that you are authenticated to your organization, and update the client:

```shellscript
sdm update
```

For Kubernetes resources, [kubectl](https://kubernetes.io/docs/reference/kubectl/) must be installed on your desktop.

{% hint style="info" %}
If you are a developer with a custom install path, you need to set this environment variable:

```shellscript
SDM_HOME=~/.sdm-app.strongdm.com
```

{% endhint %}

{% hint style="info" %}
If your organization uses a non-default StrongDM app domain (such as for a non-US control plane region), set `SDM_APP_DOMAIN` inside the MCP server's `env` block in your agent's configuration (as shown in the setup examples below), not only in your shell profile. Desktop agents launch the Broker with a minimal environment that does not load your shell profile, and the Desktop App's region selector isn't used.
{% endhint %}

### **For StrongDM Administrators**

* Users must be entitled to resources within StrongDM before their agent can access them. The Broker respects all existing entitlements, and agents can only see and connect to resources the user is already authorized for.
* No additional configuration is required at the admin level beyond standard resource entitlement workflows. For optional controls such as AI agent policy conditions, audit attribution, and enforcing the Broker as the only MCP path on managed devices, see [MCP Broker Administration](/ai/mcp-broker-administration.md).

## Setup Instructions

{% tabs %}
{% tab title="Claude Desktop" %}
**Claude Desktop Instructions**

1. Install [Claude Desktop](https://claude.ai/download).
2. Open Claude Desktop and navigate to **Settings** > **Developer** > **Edit Config**.
3. Open the configuration file in your preferred editor and add the following:<br>

   ```json
   {
     "mcpServers": {
       "sdm-listener-mcp": {
         "command": "sdm",
         "args": [
           "mcp",
           "--acknowledge-experimental-status"
         ],
         "env": {
           "SDM_APP_DOMAIN": "app.strongdm.com"
         }
       }
     }
   }
   ```
4. Save the file and restart Claude Desktop.
5. Verify the connection by navigating to **Settings** > **Developer** and confirming that **sdm-listener-mcp** shows a status of "running".

<figure><img src="https://3360496582-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHaY8OFbXUreWEF61MhKm%2Fuploads%2FgfhJrzZyYntrQrhNjmCa%2Fclaude-local-mcp-servers.png?alt=media&#x26;token=80ec6b94-276e-4cc4-9f44-c7924725a6af" alt=""><figcaption></figcaption></figure>
{% endtab %}

{% tab title="Claude Code (CLI)" %}
**Claude Code (CLI) Instructions**

1. Install and configure [Claude Code](https://code.claude.com/docs/en/quickstart).
2. Issue the following command on the CLI (single line):

{% code overflow="wrap" %}

```shellscript
claude mcp add-json sdm-listener-mcp '{"command":"sdm","args":["mcp","--acknowledge-experimental-status"],"env":{"SDM_APP_DOMAIN":"app.strongdm.com"}}' --scope user
```

{% endcode %}

3. Run `claude` on the CLI.
4. Verify by prompting it for database or SSH resource access.<br>

   <figure><img src="https://3360496582-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHaY8OFbXUreWEF61MhKm%2Fuploads%2FW5ZFkApTbMY4qxhCITSW%2Fclaude2.png?alt=media&#x26;token=178b535c-019b-4567-9738-84653fcb3192" alt=""><figcaption></figcaption></figure>

{% endtab %}

{% tab title="Codex Desktop" %}
**Codex Desktop Instructions**

1. Install [Codex Desktop](https://openai.com/codex).
2. Navigate to **Settings** > **MCP Servers** > **Add Server** and enter the following:

<table><thead><tr><th width="298.87420654296875">Field</th><th>Value</th></tr></thead><tbody><tr><td>Name</td><td><code>SDM Listener</code></td></tr><tr><td>Type</td><td><code>STDIO</code></td></tr><tr><td>Command to Launch</td><td><code>sdm</code></td></tr><tr><td>Argument 1</td><td><code>mcp</code></td></tr><tr><td>Argument 2</td><td><code>--acknowledge-experimental-status</code></td></tr><tr><td>Environment Variable Key</td><td><code>SDM_APP_DOMAIN</code></td></tr><tr><td>Environment Variable Value</td><td><code>app.strongdm.com</code></td></tr></tbody></table>

3. Click **Save** at the bottom of the settings panel.
4. Restart Codex Desktop.
5. Verify the connection is active under **Settings** > **MCP Servers**.

<figure><img src="https://3360496582-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FHaY8OFbXUreWEF61MhKm%2Fuploads%2F02iQEVEvqzdpInIHdzqt%2Fcodex-desktop.png?alt=media&#x26;token=e3ccc510-6800-4395-905b-fa00c260f55c" alt=""><figcaption></figcaption></figure>
{% endtab %}

{% tab title="Cursor" %}
**Cursor Instructions (App)**

1. Install [Cursor](https://cursor.sh/).
2. Navigate to **Settings** > **Tools & Integrations** > **MCP Servers**.
3. Click **Add New MCP Server** and configure as follows (this config file can also typically be found at `~/.cursor/mcp.json`:

{% code overflow="wrap" %}

```
{
  "mcpServers": {
    "SDM Listener": {
      "command": "sdm mcp --acknowledge-experimental-status",
      "env": {
        "SDM_APP_DOMAIN": "app.strongdm.com"
      }
    }
  }
}
```

{% endcode %}

{% hint style="warning" %}
Cursor-specific setup steps are being finalized. Please verify with the StrongDM product team if you encounter issues
{% endhint %}
{% endtab %}
{% endtabs %}

#### Sign In and Session Behavior

The Broker only works while you have a valid StrongDM session. It cannot sign you in on its own.

* **If you are signed out**, the agent's tool calls return a clear message telling you to open StrongDM Desktop and sign in. Sign in, and then ask the agent to retry. No restart is needed.
* **If your session expires mid-task**, the next tool call fails with re-authentication guidance rather than hanging. The Broker automatically refreshes its authentication state once before reporting the failure, so brief interruptions often recover on their own.
* **If access to a resource is revoked while you are using it**, the agent receives a message that the resource is no longer available. It can run `list_resources` again to see your current entitlements.
* **After your computer wakes from sleep**, the agent's connection to the Broker can become stale. If tool calls fail after waking, fully restart the agent application (for example, Claude Desktop or Codex Desktop) and retry.

You can always ask the agent to check the connection. For example, "check my StrongDM status" runs the `status` tool and reports whether you are signed in and which account is active.

#### Known Technical Preview Limitations

* The Broker cannot initiate authentication. When you are signed out, you must sign in through StrongDM Desktop, and then retry from the agent.
* You cannot request access to new resources from within the agent. Only resources you are already entitled to appear in listings. Use your normal access request workflow to gain access, and then ask the agent to list available resources again.
* The configuration of the MCP server in each agent remains a manual process.
* Cursor setup steps are pending final validation.
* For Kubernetes, [kubectl](https://kubernetes.io/docs/reference/kubectl/) must be installed on the user's desktop.

#### Questions and Feedback

This is a Technical Preview. If you encounter issues or have feedback, please reach out to the StrongDM Product team directly.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.strongdm.com/ai/mcp-broker.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
