D
Damira AI

MCP Server

The Damira MCP server bundled with the plugin — seven tools for Claude Desktop, Cursor, and any stdio MCP client.

The Damira plugin ships its own MCP server: a single standard-library Python script at mcp/server.py in the damira-plugins repo. It gives any MCP client seven tools — troubleshooting, upgrade assessment, vendor doc, CVE, and release note lookups, and a config audit that runs on your machine.

Using Cursor or Claude Code? Install the plugin — it adds skills and document templates on top of these tools. Use this page for Claude Desktop and other MCP clients, and as the tool reference.

Quick Start

The fastest MCP path — Claude Desktop on macOS:

git clone https://github.com/ciscoittech/damira-plugins ~/.damira/damira-plugins
python3 ~/.damira/damira-plugins/damira-cursor/scripts/damira.py install-mcp --target claude-desktop

Restart Claude Desktop.

No API key required to try it. Without a key the server uses a shared demo key — 50 queries/day, no signup. Every answer served on the demo key starts with a note saying so.

Try it:

Is CVE-2023-20198 being exploited, and how bad is it?

When you're ready for your plan's full daily limit, add your own key.

Installation

macOS — writes the config for you and keeps your existing servers:

git clone https://github.com/ciscoittech/damira-plugins ~/.damira/damira-plugins
python3 ~/.damira/damira-plugins/damira-cursor/scripts/damira.py install-mcp --target claude-desktop

Windows / Linux — add to %APPDATA%\Claude\claude_desktop_config.json or ~/.config/Claude/claude_desktop_config.json, with the absolute path to your clone:

{
  "mcpServers": {
    "damira": {
      "command": "python3",
      "args": ["/Users/you/.damira/damira-plugins/damira-cursor/mcp/server.py"],
      "env": {
        "DAMIRA_API_KEY": "oncall_sk_your_key_here"
      }
    }
  }
}

Restart Claude Desktop to load the server. Leave DAMIRA_API_KEY out to use the demo key.

Prerequisites: git and Python 3.9+. No pip, no uv — the server is a single standard-library script.

API Key Setup

  1. Sign up at damiraai.com (free, no credit card)
  2. Go to Dashboard > API Keys
  3. Copy the Default Key, or click Create Key — it starts with oncall_sk_

For Claude Desktop and other MCP clients, put DAMIRA_API_KEY in the server's env block and restart the client. You can also export it in your shell profile or write it to ~/.damira/config (api_key = oncall_sk_…). See API key for the lookup order and how to check which key you're on.

Never commit API keys to source control. Use environment variables or your client's secret management.

Available Tools

The bundled server exposes seven tools. One runs on your machine; six call the Damira API.

Runs locally

ToolDescription
analyze_configRegex security audit of a device configuration — weak credentials, type 7 passwords, SNMP communities, HTTP management, missing NTP/logging/banner. Runs on your machine: the config text is never sent to Damira.

Calls Damira

These return CCIE-level domain data your AI model doesn't have from training.

ToolDescription
damira_search_vendor_docsSearch official Cisco, Juniper, Arista, Palo Alto, and Fortinet documentation for version-specific procedures and exact CLI syntax.
damira_search_cveSearch CVEs and security advisories from NVD, CVE.org, and vendor advisories — whether a version is vulnerable, and security posture before an upgrade.
damira_search_release_notesRelease notes, upgrade guides, and known issues for a specific platform version.
damira_troubleshootStructured GIDRP diagnosis (Gather, Isolate, Diagnose, Recommend, Prevent): ranks likely causes and gives the exact CLI to confirm and fix. Each call is independent, so your AI sends the full problem and all output collected so far.
damira_upgrade_planUpgrade assessment for a named version-to-version upgrade: path, prerequisites, risks, maintenance window, rollback.
damira_agentFull agent pipeline for complex multi-domain queries that don't fit the tools above. Slower (30-60s).

Document templates

MOP, change control, runbook, and incident report templates ship with the plugin as skill reference files — the MOP and change control with the upgrade-plan skill, the runbook and incident report with the troubleshoot skill. They're in your clone under skills/*/references/. Your AI fills them in with the data these tools return. See Documents.

Example Prompts

Your AI assistant calls the right Damira tools automatically.

Troubleshooting:

My BGP neighbor 10.1.1.2 is stuck in Active state on a Cisco ISR4451 running IOS-XE 17.6.
Here's the output: [paste show ip bgp summary]

Vendor Documentation:

What does the Cisco documentation say about OSPF BFD timers on IOS-XE 17.x?

CVE Lookup:

Is CVE-2023-20198 affecting our IOS-XE 17.6 devices? What versions are patched?

Upgrade Planning:

Plan an upgrade for our CUCM from 12.5 SU7 to 15.0.
We have 2 publishers and 4 subscribers with 3000 phones.

Config Audit:

Audit this config for security issues:
[paste your device config]

Example Workflows

Multi-step prompts where your AI chains several Damira calls and then writes the deliverable.

Upgrade MOP:

Plan the IOS-XE 17.6 to 17.9 upgrade for our 4 branch routers
and write the full MOP.

Your AI will:

  1. Call damira_upgrade_plan — upgrade path, prerequisites, risks
  2. Call damira_search_cve — security advisories for 17.9
  3. Call damira_search_release_notes — known bugs and caveats in 17.9
  4. Write the MOP from the plugin's MOP template, filling every section with that data

Troubleshoot + incident report:

Troubleshoot this BGP issue, then write the incident report:
[paste show command output]

Config audit + findings table:

Audit the configs in this folder and create a findings
summary with severity ratings.

Upgrade planning + change control:

Plan the CUCM upgrade from 12.5 SU7 to 15.0 for our 4-node cluster.
Write both the MOP and the change control.

How It Works

Damira provides the domain data. Your AI assistant writes the documents, configs, and scripts.

Damira providesYour AI assistant does
Vendor doc search results with sourcesWrites the config using vendor syntax
CVE data with severity and remediationAdvises on patching urgency
GIDRP troubleshooting diagnosisPresents findings with recommended commands
Upgrade path, prerequisites, and risksWrites the MOP and change control
Document templates (plugin skills)Fills in every section with technical details

Your AI writes the MOP. Damira makes sure it's true.

Advisor Mode

Damira runs in advisor mode. It recommends the exact commands to run and interprets the output you paste back — you run the commands. The MCP server has no tools that connect to devices, so Damira never touches your network.

  • Output you paste is PII-redacted before any model sees it.
  • analyze_config runs on your machine; the config never leaves it.

Security

  • Advisor mode — Damira recommends commands and never connects to your devices
  • Config audit runs locally — analyze_config never sends your config to Damira servers
  • No credentials stored — API keys authenticate your account, never your device credentials
  • Zero-data-retention model hosting — model calls go only to providers with a zero-data-retention policy, so the model host doesn't keep your prompts. Damira keeps only what you ask it to: knowledge base uploads and deep research results, scoped to your account
  • PII redaction — public IPs, passwords, and SNMP communities in what you send are redacted before processing. See Security

Troubleshooting

"python3: command not found" / server won't start Install Python 3.9+ (macOS: brew install python). Check the path in your config points at damira-cursor/mcp/server.py inside your clone.

Answers start with the demo-key note after adding your key The key isn't reaching the server. Check DAMIRA_API_KEY is in the server's env block and restart the client. See If your key isn't taking.

"invalid API key" The key was revoked or mistyped. Copy it again from the dashboard — it should start with oncall_sk_.

Tools not appearing Restart your client (Claude Desktop, Windsurf). In Cursor: Settings → Plugins (or /plugins) and confirm damira is installed and enabled; for the MCP fallback, close and reopen the agent. Claude Code picks up changes on next session.

Tool call timed out Troubleshooting, upgrade plans, and damira_agent can take 30-60 seconds. Searches return faster.

"Cannot connect to Damira API" Check your internet connection. The API endpoint is https://damiraai.com. If you're behind a corporate proxy, configure your proxy settings.

Pricing

analyze_config runs on your machine and doesn't count against your plan. The other six tools count against your plan's daily query limit. See Pricing for plans and limits.

MCP vs the Plugin

Both use the same server and your same API key.

Use the plugin if you work in Cursor or Claude Code. You get the MCP tools plus skills, the document templates, and a device gate that blocks the agent from SSHing to network gear. Install it.

Use MCP on its own for Claude Desktop, Windsurf, or another MCP client. Good for looking up CVEs, planning upgrades, and troubleshooting with your AI as the writer.

What's Next

On this page