Connect an AI assistant to Hunto (MCP)

Hunto has a built-in Model Context Protocol (MCP) server. Connect an MCP-capable assistant such as Claude, Cursor or your own agent, and it can look up your assets, detections, incidents and security score, and help with tasks, using only the access you give it.

There is nothing to install: the server is part of the Hunto web application.

What you need

  • A Hunto account with access to the modules you want the assistant to use (for example Monitoring).
  • The address of your Hunto region:
Region MCP address
India https://in.hunto.ai/api/mcp
EU https://eu.hunto.ai/api/mcp

Use the region your organisation signs in to. A sign-in or key from one region does not work in the other.

Use this when your assistant supports remote MCP servers with sign-in, as Claude does.

  1. In the assistant, add a remote MCP server and paste your region's address.
  2. The assistant opens a Hunto page in your browser. Sign in if asked.
  3. The Authorize access page names the application, shows where it will send results, and lists every permission it can be given. Tick the ones you want to grant. You can grant fewer than it asked for.
  4. Select Allow access. The assistant is now connected.

Things to know:

  • You can only hand over what you hold. Permissions your account doesn't have appear as unavailable and can't be ticked.
  • Access lasts one hour and renews itself while the assistant stays connected, for up to 30 days. After that, or when you disconnect it, the assistant has to be authorised again.
  • Applications register themselves with Hunto when they connect; you don't create anything beforehand.

Connect with an API key

Use this for scripts and agents that can't open a browser.

  1. In Hunto, open API Management and create a key.
  2. Under access, choose Limit to selected scopes and tick only what the agent needs, or let the key inherit your access. Choose an expiry: 30 days, 90 days, 1 year or never. Prefer an expiry.
  3. Copy the key now. It starts with hnt_ and is shown once.
  4. Send it as a bearer token with every request:
curl https://in.hunto.ai/api/mcp \
  -H "Authorization: Bearer hnt_…" \
  -H "Content-Type: application/json" \
  -H "Accept: application/json, text/event-stream" \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}'

For an assistant configured with a JSON file:

{
  "mcpServers": {
    "hunto": {
      "url": "https://in.hunto.ai/api/mcp",
      "headers": { "Authorization": "Bearer hnt_…" }
    }
  }
}

A key acts as its owner, inside the owner's organisation. Revoke it in API Management and it stops working immediately.

What the assistant can do

Each tool the assistant sees belongs to one permission, written area:verb. The verb is read, write or admin, and each level includes the one below it.

Area What it covers
assets Your assets
detections Detections
incidents Incidents
score Your organisation's security score, its history, and score reports
inventory Inventory and exposures
discovery Discovery runs, schedules and results
investigations Investigation evidence
tasks Tasks and remediation: list, view, create, update, request a review
reports Reports

The assistant only sees tools it may use. A tool appears when all of these allow it: your account's permissions, the permissions you ticked or the key's scopes, and your current organisation. The rules are checked again each time the assistant calls a tool, so removing a permission takes effect straight away.

Ask the assistant to run myAgentAccess to see exactly what it can do in the current connection.

Actions that change things (write) are only offered if you grant a write permission. If you only want an assistant to look, grant read only.

Safety and limits

  • The assistant acts as you, and never has more access than you do.
  • Each call is checked against the specific record it touches, not just the area.
  • Results are the same data you see in Hunto. Treat them as you would an export: the assistant's provider receives what the assistant reads.
  • Give an assistant a dedicated key, with the smallest scopes and a short expiry, and revoke it when the work is done.
  • Hunto can switch an area off for your organisation on request.
  • If an assistant reports "unauthorised", the sign-in or key has expired or been revoked. Connect again.

Troubleshooting

You see Do this
The assistant shows no tools You haven't granted any permission that your account also holds. Reconnect and tick some, or check the account has the module.
401 Unauthorized Key revoked or expired, or the wrong region. Use the address from the table above.
A tool you expected is missing Ask the assistant to call myAgentAccess. Check the permission, the key's scopes and the current organisation.
Works in one region only Sign-ins and keys are per region. Connect each region separately.

Command-line agents

If your assistant runs in a terminal, the Hunto command-line tool has its own MCP mode that works with the same account. See Hunto CLI.