AI Context for internet infrastructure,over one MCP endpoint
Connect any MCP client once to a single endpoint, then ask about internet infrastructure in plain language. Your agent picks a read-only tool, runs it against WhisperGraph, and gets structured JSON back. Connect in the box below; the tools you get are listed in the features underneath.
Point your client at the endpoint, then ask in plain language. The agent picks the right read-only tool and answers.
claude mcp add --transport http whisper-graph https://mcp.whisper.security \ --header "Authorization: Bearer YOUR_API_KEY"
One connection, the whole graph
MCP for AI agents
A Model Context Protocol server your agent connects to once, then asks infrastructure questions in plain language — with a provably read-only query surface.
Read the overview18 tools, read-only query surface
Six core graph tools — run Cypher, discover the schema on demand, score indicators, pull docs, and run whole investigations from a shared gallery — plus host-identity and dedicated write tools. Every graph query returns structured JSON and never modifies the graph.
See the tool referenceConnect in one line
Point any MCP client at mcp.whisper.security with an OAuth 2.1 sign-in or a Bearer API key, and start querying. Sessions last ~6 months and survive deploys.
Set up the connectionRead-only query surface
Any write or admin Cypher is rejected before it reaches the database, so an agent reads the graph but never changes it through query. The sanctioned write path lives in separate, honestly-annotated tools — agent identity and subscriptions — authorized by your own key.
How safety worksA workflow & recipe gallery
A shared library of investigation playbooks, the same one behind the use cases and the console. Agents find them with list_workflows and run them with run_workflow.
Browse the galleryThe whole internet, queryable
WhisperGraph maps about 7.4B nodes and 39B edges of DNS, BGP, WHOIS, certificates and threat intel from 43 feeds across 25 categories. That is 39 node labels and 45 edge types.
Threat-intel use cases
Three things that make it agent-native
Token-efficient by design
“39 labels / 45 edges — discovered on demand, never dumped into your context.”
The schema and docs load only when the agent needs them, through explain_schema and read_docs. The always-listed resources are half what they used to be, and a single run_workflow call does the work of several query round-trips.
One-call investigations
“Investigations in one call, not five.”
run_workflow runs a whole multi-step pivot in one call. Resolve DNS to an IP, the IP to its ASN, then check threat intel, all from one named playbook instead of a chain of hand-written queries.
Evidence for every claim
“Every answer ships the query and the rows behind it.”
Each query and run_workflow result comes back with the exact Cypher it ran, the row counts, and the timing. So when the agent makes a claim, you can see the query that backs it.
Everything your agent can call
The agent chooses among these on its own. Every one is read-only and returns structured rows. The connector also carries host-identity and dedicated write tools — see the full 18-tool reference.
queryRun a Cypher query against the graph and get back columns, rows, statistics, and an evidence block. Supports table/graph/compact formats and count-first pagination. This is the primary tool.
explain_indicatorGet a threat verdict for an IP, hostname, CIDR or ASN, with a score, a severity level, and the reasoning and sources behind it.
explain_schemaThe schema, on demand. No argument returns the label catalogue; pass a label to get its properties, edges, and a runnable sample traversal — never dumped into context up front.
read_docsPull the Whisper docs on demand — list, search, or fetch one page as Markdown — so the Cypher reference and cookbook stay out of the always-on context.
list_workflowsSearch the shared workflow & recipe gallery. Each item comes back with its summary and full parameter space, so the agent can run any variant.
run_workflowRun one or more gallery playbooks by slug in a single call — a multi-step investigation collapsed into one tool call, returning chained per-step results, derived signals, and an evidence trail.
Full input schemas and example calls in the MCP tool reference.
Give your agent eyes on the internet
A free key connects any MCP client to the live graph in one step. Ask in plain language and get sourced, structured answers back.