Content
# Check Point CloudGuard WAF MCP Server
A [Model Context Protocol (MCP)](https://modelcontextprotocol.io) server that wraps the Check Point CloudGuard WAF Management GraphQL API. This gives AI assistants like Claude the ability to manage your CloudGuard WAF configuration through natural language.
## What It Does
This MCP server exposes **68 tools** that let an AI assistant fully manage your CloudGuard WAF deployment:
| Category | Tools | What You Can Do |
|----------|-------|-----------------|
| **Assets** | 9 | Create, update, delete Web Application and Web API assets |
| **Profiles** | 14 | Manage Docker, Kubernetes, Embedded, and AppSec Gateway deployment profiles |
| **Practices** | 10 | Configure Web Application and Web API security practices (IPS, WebAttacks, WebBot, etc.) |
| **Behaviors** | 10 | Manage exceptions, trusted sources, and web user response behaviors |
| **Zones** | 5 | Create and manage security zones |
| **Triggers** | 6 | Configure log triggers with syslog, CEF, cloud, and agent logging |
| **Policy** | 9 | Publish changes, enforce policy, view threat prevention policy |
| **Agents** | 3 | List agents, revoke access, trigger upgrades |
## Prerequisites
- **Python 3.10+**
- **Check Point Infinity Portal account** with CloudGuard WAF enabled
- **API credentials** (Client ID and Secret Key) from the Infinity Portal
## Installation
### Using uv (recommended)
```bash
# Clone the repo
git clone https://github.com/presidentsu/checkpoint-waf-mcp.git
cd checkpoint-waf-mcp
# Create venv and install
uv venv
uv pip install -e .
```
### Using pip
```bash
git clone https://github.com/presidentsu/checkpoint-waf-mcp.git
cd checkpoint-waf-mcp
python -m venv .venv
source .venv/bin/activate # On Windows: .venv\Scripts\activate
pip install -e .
```
## Configuration
### 1. Get API Credentials
1. Log in to the [Check Point Infinity Portal](https://portal.checkpoint.com)
2. Go to **Settings > API Keys**
3. Create a new API key with CloudGuard WAF permissions
4. Note your **Client ID** and **Secret Key**
### 2. Set Environment Variables
```bash
export CHECKPOINT_CLIENT_ID="your-client-id"
export CHECKPOINT_SECRET_KEY="your-secret-key"
export CHECKPOINT_REGION="us" # Options: us, eu, india, australia
```
Or copy `.env.example` to `.env` and fill in your values.
### 3. Connect to Your MCP Client
#### Claude Desktop
Add to your `claude_desktop_config.json`:
```json
{
"mcpServers": {
"checkpoint-waf": {
"command": "uv",
"args": [
"--directory", "/path/to/checkpoint-waf-mcp",
"run", "checkpoint-waf-mcp"
],
"env": {
"CHECKPOINT_CLIENT_ID": "your-client-id",
"CHECKPOINT_SECRET_KEY": "your-secret-key",
"CHECKPOINT_REGION": "us"
}
}
}
}
```
#### Claude Code (CLI)
Add to your `.claude/settings.json`:
```json
{
"mcpServers": {
"checkpoint-waf": {
"command": "uv",
"args": [
"--directory", "/path/to/checkpoint-waf-mcp",
"run", "checkpoint-waf-mcp"
],
"env": {
"CHECKPOINT_CLIENT_ID": "your-client-id",
"CHECKPOINT_SECRET_KEY": "your-secret-key",
"CHECKPOINT_REGION": "us"
}
}
}
}
```
## Supported Regions
| Region | Endpoint |
|--------|----------|
| `us` (default) | `cloudinfra-gw-us.portal.checkpoint.com` |
| `eu` | `cloudinfra-gw.portal.checkpoint.com` |
| `india` | `cloudinfra-gw.in.portal.checkpoint.com` |
| `australia` | `cloudinfra-gw.au.portal.checkpoint.com` |
## Usage Examples
Once connected, you can ask your AI assistant things like:
- *"List all my WAF assets"*
- *"Create a new Web Application asset called 'prod-app' with upstream URL http://10.0.0.1"*
- *"Show me the security practices attached to asset X"*
- *"Switch the IPS practice to Prevent mode"*
- *"Create a log trigger that sends to my syslog server at 192.168.1.100"*
- *"Publish and enforce the current policy"*
- *"What agents are connected to the production profile?"*
## Architecture
```
src/checkpoint_waf_mcp/
├── __main__.py # Entry point
├── config.py # Region endpoints & env var loading
├── auth.py # Token auth with auto-refresh
├── graphql_client.py # Async GraphQL client with retry
├── server.py # FastMCP server & tool registration
├── queries/ # GraphQL query/mutation definitions
│ ├── assets.py
│ ├── profiles.py
│ ├── practices.py
│ ├── behaviors.py
│ ├── zones.py
│ ├── triggers.py
│ ├── policy.py
│ └── utility.py
└── tools/ # MCP tool implementations
├── assets.py
├── profiles.py
├── practices.py
├── behaviors.py
├── zones.py
├── triggers.py
├── policy.py
└── agents.py
```
## License
Apache 2.0 - see [LICENSE](LICENSE) for details.
MCP Config
Below is the configuration for this MCP Server. You can copy it directly to Cursor or other MCP clients.
mcp.json
Connection Info
You Might Also Like
cc-switch
All-in-One Assistant for Claude Code, Codex & Gemini CLI across platforms.
awesome-claude-skills
A curated list of awesome Claude Skills, resources, and tools for...
claude-flow
Claude-Flow v2.7.0 is an enterprise AI orchestration platform.
Appwrite
Build like a team of hundreds
semantic-kernel
Build and deploy intelligent AI agents with Semantic Kernel's orchestration...
Anthropic-Cybersecurity-Skills
734+ structured cybersecurity skills for AI agents · MITRE ATT&CK mapped ·...