MCP Server
The Damira MCP server bundled with the plugin — seven tools for Claude Desktop, Cursor, and any stdio MCP client.
The Damira plugin ships its own MCP server: a single standard-library Python script at mcp/server.py in the damira-plugins repo. It gives any MCP client seven tools — troubleshooting, upgrade assessment, vendor doc, CVE, and release note lookups, and a config audit that runs on your machine.
Using Cursor or Claude Code? Install the plugin — it adds skills and document templates on top of these tools. Use this page for Claude Desktop and other MCP clients, and as the tool reference.
Quick Start
The fastest MCP path — Claude Desktop on macOS:
Restart Claude Desktop.
No API key required to try it. Without a key the server uses a shared demo key — 50 queries/day, no signup. Every answer served on the demo key starts with a note saying so.
Try it:
When you're ready for your plan's full daily limit, add your own key.
Installation
macOS — writes the config for you and keeps your existing servers:
Windows / Linux — add to %APPDATA%\Claude\claude_desktop_config.json or ~/.config/Claude/claude_desktop_config.json, with the absolute path to your clone:
Restart Claude Desktop to load the server. Leave DAMIRA_API_KEY out to use the demo key.
Prerequisites: git and Python 3.9+. No pip, no uv — the server is a single standard-library script.
API Key Setup
- Sign up at damiraai.com (free, no credit card)
- Go to Dashboard > API Keys
- Copy the Default Key, or click Create Key — it starts with
oncall_sk_
For Claude Desktop and other MCP clients, put DAMIRA_API_KEY in the server's env block and restart the client. You can also export it in your shell profile or write it to ~/.damira/config (api_key = oncall_sk_…). See API key for the lookup order and how to check which key you're on.
Never commit API keys to source control. Use environment variables or your client's secret management.
Available Tools
The bundled server exposes seven tools. One runs on your machine; six call the Damira API.
Runs locally
| Tool | Description |
|---|---|
analyze_config | Regex security audit of a device configuration — weak credentials, type 7 passwords, SNMP communities, HTTP management, missing NTP/logging/banner. Runs on your machine: the config text is never sent to Damira. |
Calls Damira
These return CCIE-level domain data your AI model doesn't have from training.
| Tool | Description |
|---|---|
damira_search_vendor_docs | Search official Cisco, Juniper, Arista, Palo Alto, and Fortinet documentation for version-specific procedures and exact CLI syntax. |
damira_search_cve | Search CVEs and security advisories from NVD, CVE.org, and vendor advisories — whether a version is vulnerable, and security posture before an upgrade. |
damira_search_release_notes | Release notes, upgrade guides, and known issues for a specific platform version. |
damira_troubleshoot | Structured GIDRP diagnosis (Gather, Isolate, Diagnose, Recommend, Prevent): ranks likely causes and gives the exact CLI to confirm and fix. Each call is independent, so your AI sends the full problem and all output collected so far. |
damira_upgrade_plan | Upgrade assessment for a named version-to-version upgrade: path, prerequisites, risks, maintenance window, rollback. |
damira_agent | Full agent pipeline for complex multi-domain queries that don't fit the tools above. Slower (30-60s). |
Document templates
MOP, change control, runbook, and incident report templates ship with the plugin as skill reference files — the MOP and change control with the upgrade-plan skill, the runbook and incident report with the troubleshoot skill. They're in your clone under skills/*/references/. Your AI fills them in with the data these tools return. See Documents.
Example Prompts
Your AI assistant calls the right Damira tools automatically.
Troubleshooting:
Vendor Documentation:
CVE Lookup:
Upgrade Planning:
Config Audit:
Example Workflows
Multi-step prompts where your AI chains several Damira calls and then writes the deliverable.
Upgrade MOP:
Your AI will:
- Call
damira_upgrade_plan— upgrade path, prerequisites, risks - Call
damira_search_cve— security advisories for 17.9 - Call
damira_search_release_notes— known bugs and caveats in 17.9 - Write the MOP from the plugin's MOP template, filling every section with that data
Troubleshoot + incident report:
Config audit + findings table:
Upgrade planning + change control:
How It Works
Damira provides the domain data. Your AI assistant writes the documents, configs, and scripts.
| Damira provides | Your AI assistant does |
|---|---|
| Vendor doc search results with sources | Writes the config using vendor syntax |
| CVE data with severity and remediation | Advises on patching urgency |
| GIDRP troubleshooting diagnosis | Presents findings with recommended commands |
| Upgrade path, prerequisites, and risks | Writes the MOP and change control |
| Document templates (plugin skills) | Fills in every section with technical details |
Your AI writes the MOP. Damira makes sure it's true.
Advisor Mode
Damira runs in advisor mode. It recommends the exact commands to run and interprets the output you paste back — you run the commands. The MCP server has no tools that connect to devices, so Damira never touches your network.
- Output you paste is PII-redacted before any model sees it.
analyze_configruns on your machine; the config never leaves it.
Security
- Advisor mode — Damira recommends commands and never connects to your devices
- Config audit runs locally —
analyze_confignever sends your config to Damira servers - No credentials stored — API keys authenticate your account, never your device credentials
- Zero-data-retention model hosting — model calls go only to providers with a zero-data-retention policy, so the model host doesn't keep your prompts. Damira keeps only what you ask it to: knowledge base uploads and deep research results, scoped to your account
- PII redaction — public IPs, passwords, and SNMP communities in what you send are redacted before processing. See Security
Troubleshooting
"python3: command not found" / server won't start
Install Python 3.9+ (macOS: brew install python). Check the path in your config points at damira-cursor/mcp/server.py inside your clone.
Answers start with the demo-key note after adding your key
The key isn't reaching the server. Check DAMIRA_API_KEY is in the server's env block and restart the client. See If your key isn't taking.
"invalid API key"
The key was revoked or mistyped. Copy it again from the dashboard — it should start with oncall_sk_.
Tools not appearing
Restart your client (Claude Desktop, Windsurf). In Cursor: Settings → Plugins (or /plugins) and confirm damira is installed and enabled; for the MCP fallback, close and reopen the agent. Claude Code picks up changes on next session.
Tool call timed out
Troubleshooting, upgrade plans, and damira_agent can take 30-60 seconds. Searches return faster.
"Cannot connect to Damira API"
Check your internet connection. The API endpoint is https://damiraai.com. If you're behind a corporate proxy, configure your proxy settings.
Pricing
analyze_config runs on your machine and doesn't count against your plan. The other six tools count against your plan's daily query limit. See Pricing for plans and limits.
MCP vs the Plugin
Both use the same server and your same API key.
Use the plugin if you work in Cursor or Claude Code. You get the MCP tools plus skills, the document templates, and a device gate that blocks the agent from SSHing to network gear. Install it.
Use MCP on its own for Claude Desktop, Windsurf, or another MCP client. Good for looking up CVEs, planning upgrades, and troubleshooting with your AI as the writer.
What's Next
- Install — Cursor, Claude Code, and every other client
- Troubleshooting Guide — how the diagnosis works
- Upgrade Planning — structured upgrade assessments and MOPs
- API Reference — programmatic access for automation