Skip to main content

Documentation Index

Fetch the complete documentation index at: https://docs.tracecat.com/llms.txt

Use this file to discover all available pages before exploring further.

Tracecat works best with agentic coding tools (Claude Code, Cursor, Codex, OpenCode). Agents connected to Tracecat MCP gain the ability to build and orchestrate core Tracecat resources:
  • Agents
  • Workflows
  • Tables (local and remote)
  • Integrations (HTTP, gRPC, SQL)
  • Scripts (Python, docker run)
  • Cases (local and remote)
Tracecat MCP turns any coding agent into a security automation architect and engineer.

Self-hosted

MCP authentication uses a built-in OIDC provider. Your agent will be redirected to sign in through the browser on first connection. Replace <your-tracecat-url> with your PUBLIC_APP_URL (e.g. http://localhost or https://tracecat.example.com).
claude mcp add -t http tracecat <your-tracecat-url>/mcp
claude
/mcp

Cloud

Subscription required
claude mcp add -t http tracecat https://platform.tracecat.com/mcp
claude
/mcp

Starter prompts

Recreate automation from blog post

Audit and improve existing workflows

Build alert triage automation

Automate phishing email response

MCP tools

Workspaces
Namespace
Workflows
Namespace
Cases
Namespace
Tables
Namespace
Variables
Namespace
Secrets
Namespace
Integrations
Namespace
Agents
Namespace