crowdstrike.com
CrowdStrike provides the Falcon cybersecurity platform for endpoint, identity, cloud, threat intelligence, and SIEM use cases. It offers cloud-hosted security capabilities and developer tooling for automating detection, investigation, and response workflows.
CrowdStrike exposes the Falcon HTTP API, an Identity Protection GraphQL API, and the self-hosted falcon-mcp package as both a CLI and MCP server; Falcon integrations authenticate with CrowdStrike API client credentials, while HTTP access to a self-hosted MCP server can also be protected by a local x-api-key.
- CrowdStrike Falcon APIdiscovered
- Identity Protection GraphQL APIdiscovered
- falcon-mcp CLIdiscovered
In the Falcon console, go to Support > API clients and keys, create an API client, and copy the client_id and client_secret. Grant the scopes required by the API collections or MCP modules you plan to use. Use your CrowdStrike cloud's API base URL, for example https://api.crowdstrike.com; the SDK docs note you can also target the appropriate cloud/region base URL.
conventions · 1/7 published
- integrations.json——
- llms.txt✓https://crowdstrike.com/llms.txt
- API catalog✗
/.well-known/api-catalog - OpenAPI document✗
/api/schema/, /openapi.json, /swagger.json, /api/openapi.json, or /v1/openapi.json - MCP server card✗
/.well-known/mcp/server-card.json - OAuth protected resource✗
/.well-known/oauth-protected-resource - Agent card✗
/.well-known/agent-card.json - Agent skills✗
/.well-known/agent-skills/index.json
Publish these signals → /publishing