# Agents & MCP

> Connect any MCP client to WhisperGraph: 7 tools, a provably read-only surface, a workflow gallery, and evidence-backed answers for AI agents.

*Source: https://www.whisper.security/docs/ai*

---
Every verdict from WhisperGraph carries a coverage block beside the score, and coverage says what was actually looked at. "We have never observed this host" and "we hold data here and nothing malicious is in it" reach an agent as different answers instead of a guess. Every `query` and `run_workflow` result also ships an `evidence` block with the exact Cypher that ran, the row count and the timing, so the agent can cite the query behind each claim.

The other problem is staleness: an assistant answering infrastructure questions from its training data works from a snapshot that ages by the day. Whisper's MCP server at `https://mcp.whisper.security` connects any MCP-capable client to the live graph — 7.5B nodes and 39.8B edges — so the agent runs the lookup instead of recalling one.

![An MCP client calls a tool; the server validates it, runs read-only Cypher against WhisperGraph, and returns rows with an evidence trail](/images/docs/whisper-mcp-flow.svg)

## What the server offers

The server speaks MCP over streamable HTTP and advertises **7 tools, 4 resources, and 10 prompts**. Every tool reads; none writes, and write and admin Cypher is rejected before it reaches the database, so nothing an agent asks through this connector can change the graph. Every deployment advertises the same seven tools, so `tools/list` is the contract wherever you connect. The [Reference](/docs/ai/mcp/reference) documents each tool, resource and prompt; [Setup](/docs/ai/mcp/setup) has the scopes and the data-handling summary.

## What the server answers

The server reads Whisper's map of the public internet. It tells you what a domain or IP **is** — never whether anything in your environment contacted it, so pair it with your SIEM or EDR for that half of the question.

> **Read `coverage` before `band`.** Only `known-clean` licenses the word "clean"; `no-data` means
> *unknown*, which is a different thing again; `malicious-evidenced` and `ambiguous` mean there is
> evidence, whatever the band says.
> Full contract: [Coverage — what we looked at](/docs/whisper-graph/procedures/coverage).

## Connect

Authentication is always required — there is no anonymous mode: [sign in](https://console.whisper.security/sign-in?redirect_url=https%3A%2F%2Fwww.whisper.security%2Fdocs%2Fai) and an API key is created for you automatically, then add the server to your client. In Claude Code:

```bash
claude mcp add --transport http whisper-graph https://mcp.whisper.security \
  --header "Authorization: Bearer YOUR_API_KEY"
```

Replace `YOUR_API_KEY` before you run it. Interactive clients such as Claude Desktop can sign in through OAuth 2.1 instead; [Setup](/docs/ai/mcp/setup) has a working config per client.

## Where next

[Your first investigation](/docs/ai/mcp/investigation) works one alert end to end. An agent that speaks plain HTTP can skip MCP entirely and call the [HTTP API](/docs/cypher-api) with an `X-API-Key` header.
