Skip to main content

Complete Guide to Druva MSP MCP Server for MSPs

In this article, learn how to connect AI tools to Druva Cloud via the MSP MCP Server to manage multi-tenant data.

Overview

The Druva Model Context Protocol (MCP) server acts as a secure gateway that connects compatible AI agents to the Druva Cloud using your existing Managed Services Provider (MSP) account permissions.

By integrating this server, you can manage your customers' data protection environments, run workflows, and query environment metrics across tenants using natural language prompts within supported AI tools.


Note: Before proceeding, ensure you have accepted the Cloud Service Customer Agreement during your first login to MSC. Otherwise, the MCP Server will fail to authenticate.


Key Benefits

  • Enhanced Operational Efficiency: MSP admins can now check client backups, audit logs, and legal data directly in one place just by calling Report APIs.

  • Governed Security and RBAC Layer: All interactions are strictly constrained by implicit Role-Based Access Control (RBAC) via a 3-Legged OAuth 2.1 flow. The AI application acts exclusively on behalf of the authenticated MSP user.


Note: If an operator lacks console permissions to view a specific customer workload or tenant, the native API blocks execution.


How Druva MSP MCP Server Works

The Druva MSP MCP server establishes a secure remote HTTP connection:

  1. You add the Druva MSP MCP server URL to the supported AI agent.

  2. The agent prompts you to authenticate via the Managed Services Center (MSC).

  3. Once authenticated, the Druva MSP MCP server exposes supported tools to your agent.

  4. The agent uses these tools to fetch MSP environment data and answer your natural language requests.

Compatibility - Supported AI Agents

The Druva MSP MCP server currently supports the following AI Agents:

  • Claude (Desktop, Code, Cowork, Web)

  • Cursor / VS Code

  • Google Antigravity

  • Microsoft Copilot Studio

Configure Druva MSP MCP server

Step 1: Configure the remote Druva MSP MCP server

To connect an MCP-compatible agent to MSC, add the Druva MSP MCP server using the following server details.


📝 Note: The Druva MSP MCP server is currently not available for customer environments hosted on the Druva Australia control plane or GovCloud.


Example agent configuration

Use the format supported by your MCP-compatible agent. The exact fields and setup steps vary by agent.

AI agents with built-in connector UI

If your AI agent has a built-in connector/integration UI, use that option instead of manual configuration. Add the Druva MSP MCP server URL for your region (see Step 1) as a custom connector.


📝 Note: Refer to your AI agent's own documentation for the exact steps, since these UIs vary by vendor and change independently of this article.


JSON example

JSON

{

"mcpServers": {

"druva": {

}

}

}

TOML example

Ini, TOML

[mcp_servers.druva]

Confirm the required configuration format in the documentation for your MCP-compatible agent.

Step 2: Authentication

When you connect to the MCP server for the first time, your agent prompts you to authenticate by redirecting to the Managed Services Center (MSC). Use the same credentials that you use to sign in to the MSC. Authentication supports both password and TOTP methods.

Step 3: Test the connection

  1. Start your MCP-compatible agent after you add the Druva MSP MCP server.

  2. Ask a simple MSP question, such as: "List available customers for my org"

The connection is working if the agent uses the Druva MSP MCP server and returns a MSP response.

For MCP Server use cases, refer to MCP Server use cases for MSC.


Note:

The following actions are not supported by the MCP Server:

  • Update tenant

  • Suspend tenant

  • Un-suspend tenant

  • MSP SIEM events (as these APIs are not available for admin & available only for SIEM events)

  • Delete Actions


Druva MSP MCP Server Capabilities

Druva MCP server capabilities are available through tools. This MCP server includes the following tools:

Tool

Purpose

list_skills

Lists the Druva skills or capabilities available through the Druva MSP MCP server. The AI agent uses this tool to discover which MSP actions are supported.

recommend_skill

Identifies the most relevant Druva skill for a user request. The agent uses this tool when a natural-language request must be matched to a supported Druva MSP capability.

retrieve_skill

Retrieves the details required to use a selected Druva skill. The agent uses this tool after it selects a skill and needs the instructions or action details required to continue.

run_read

Runs the supported script associated with the selected Druva MSP skill. The agent uses this tool to fetch data from the managed Druva MSP environment.

run_write

Runs the supported script or action associated with the selected Druva MSP skill. The agent uses this tool to perform an action in the managed Druva MSP environment.

Limitations & Access Control

  • Agent-Side Approvals: Some agents ask you to manually approve tool execution before a script runs. This is an agent-specific safety feature, not a Druva-controlled setting.

  • Interpretation Variance: Results can vary slightly depending on how your specific AI agent interprets and phrases background prompts.

  • Unsupported Operations: The following actions are not supported:

    • Any delete operation on an entity

    • Update tenant

    • Suspend tenant

    • Unsuspend tenant

Troubleshooting & FAQs

Why can’t my MCP-compatible agent connect to the Druva MSP MCP server?

Verify the following:

  • The server URL is exactly the one mentioned below:

  • The agent supports remote HTTP-based MCP servers.

  • Check that your corporate firewall, network, browser, or endpoint security controls are not blocking outbound traffic to the URL.

Why does authentication fail or not complete?

  • Sign in again with your Managed Services Center (MSC) credentials.

  • If authentication still fails, check whether:

    • Your MSC session expired.

    • The browser sign-in flow was blocked.

    • The MCP-compatible agent blocked or did not complete the sign-in flow.

    • Your network or endpoint security controls blocked the authentication flow.

Why does a request return no data?

Verify that:

  • Your active MSP role has permission to view the requested customer workload, object, or target region.

  • Ensure that the target workload or time range you are asking about actually contains active data in your console.

Why does a request fail with a permission error?

Verify that your MSP role allows access to the requested data. Existing Druva MSP role-based access control (RBAC), tenant permissions, and access boundaries apply when you use the Druva MSP MCP server.

Why doesn’t the MCP-compatible agent ask for approval?

Do not assume that approval prompts are guaranteed. Approval and confirmation behavior depends on the MCP-compatible agent. Existing Druva MSP RBAC, permissions, and security controls still apply.

Why is my query not using the Druva MSP MCP server?

AI agents can sometimes misroute generic prompts. Try being explicit: "Using the Druva MSP MCP server, list the customers."

How do I terminate my access and remove my data from the MSP MCP Server?

To terminate your access and remove your data from the MSP MCP Server, simply log out of your AI tool session.


Note: For optimal performance and reliable tool execution, we recommend using an advanced, capable LLM model as task accuracy and prompt interpretation can vary significantly depending on the model used.


Did this answer your question?