WYRE-AI/msp-claude-plugins/msp-claude-plugins/huntress/huntress/skills/api-patterns/SKILL.md
Huntress API Patterns
Huntress MCP fundamentals: HTTP Basic Auth via API key/secret headers, the full MCP tool catalog, token-based pagination, the 60 req/min rate limit, and the common HTTP error codes with their causes.
- Source repository stars
- 42
- Declared platforms
- 0
- Static risk flags
- 0
- Last source update
- 2026-08-28
- Source checked
- 2026-08-28
Decision brief
What it does: where it fits
Huntress MCP fundamentals: HTTP Basic Auth via API key/secret headers, the full MCP tool catalog, token-based pagination, the 60 req/min rate limit, and the common HTTP error codes with their causes.
Not for
- Tasks that require unconfirmed production actions or broad system permissions.
- Environments where the pinned source and install steps cannot be inspected.
Compatibility matrix
Platform support, with evidence labels
| Platform | Status | Evidence | What to check |
|---|---|---|---|
| Codex | Not declared | No explicit evidence | Portability before use |
| Claude Code | Not declared | No explicit evidence | Portability before use |
| Cursor | Not declared | No explicit evidence | Portability before use |
| Gemini CLI | Not declared | No explicit evidence | Portability before use |
Installation
Inspect first. Install second.
The source command is displayed only when detected. A safe inspection prompt is always available so your agent can explain every action before execution.
npx skills add https://github.com/WYRE-AI/msp-claude-plugins --skill "msp-claude-plugins/huntress/huntress/skills/api-patterns"Inspect the Agent Skill "Huntress API Patterns" from https://github.com/WYRE-AI/msp-claude-plugins/blob/5005f73ba2f52cd299f58aa6bb79f4e70ae87103/msp-claude-plugins/huntress/huntress/skills/api-patterns/SKILL.md at commit 5005f73ba2f52cd299f58aa6bb79f4e70ae87103. List every install step, command, network request, credential, file read/write, external action, and rollback step. Explain whether it fits my task. Do not install or execute anything until I approve.
Workflow
What the source asks the agent to do
- 01
Connection & Authentication
Huntress authenticates using an API key and secret passed as HTTP headers:
Huntress authenticates using an API key and secret passed as HTTP headers:Generate credentials at: Huntress Dashboard Settings API Credentials - 02
HTTP Basic Auth
Huntress authenticates using an API key and secret passed as HTTP headers:
Huntress authenticates using an API key and secret passed as HTTP headers:Generate credentials at: Huntress Dashboard Settings API Credentials - 03
Available MCP Tools
Navigation here is stateless discovery, not a cursor. There is no current resource and no history, so there is no "back" tool — every tool below is callable directly at any time, and huntressnavigate is never a prerequisite for calling one.
Navigation here is stateless discovery, not a cursor. There is no current resource and no history, so there is no "back" tool — every tool below is callable directly at any time, and huntressnavigate is never a prerequi…Through Conduit, huntressnavigate is refused for every caller by the discovery-tool suppression gate, so a workflow that begins by calling it will fail at step one. Read the catalog below instead. - 04
Navigation
Navigation here is stateless discovery, not a cursor. There is no current resource and no history, so there is no "back" tool — every tool below is callable directly at any time, and huntressnavigate is never a prerequisite for calling one.
Navigation here is stateless discovery, not a cursor. There is no current resource and no history, so there is no "back" tool — every tool below is callable directly at any time, and huntressnavigate is never a prerequi…Through Conduit, huntressnavigate is refused for every caller by the discovery-tool suppression gate, so a workflow that begins by calling it will fail at step one. Read the catalog below instead. - 05
Account
Review the “Account” section in the pinned source before continuing.
Review and apply the “Account” source section.
Permission review
Static risk signals and limitations
No configured static risk pattern was detected
This is not proof of safety. Runtime behavior, indirect dependencies, and hidden external systems are outside the static scan.
Evidence record
Why each signal appears
| Signal | Value | Evidence type | Meaning |
|---|---|---|---|
| Quality score | 91/100 | Computed | Documentation, specificity, maintenance, and trust rules |
| Repository stars | 42 | Source | Repository attention, not individual Skill quality |
| Compatibility | 0 platforms | Source | Declared in the catalog source record |
| Usage guide | automated source guide | Editorial | Generated or reviewed according to the visible evidence level |
Pinned source
Provenance and original SKILL.md
- Repository
- WYRE-AI/msp-claude-plugins
- Skill path
- msp-claude-plugins/huntress/huntress/skills/api-patterns/SKILL.md
- Commit
- 5005f73ba2f52cd299f58aa6bb79f4e70ae87103
- License
- Apache-2.0
- Collected
- 2026-08-28
- Default branch
- main
View the original SKILL.md
Huntress MCP Tools & API Patterns
Overview
The Huntress MCP server provides AI tool integration with the Huntress managed threat detection and response platform. It exposes tools covering account management, endpoint agents, organizations, incidents, escalations, billing, signals, and user management. The API uses HTTP Basic Auth with an API key and secret.
Connection & Authentication
HTTP Basic Auth
Huntress authenticates using an API key and secret passed as HTTP headers:
| Header | Description |
|---|---|
X-Huntress-API-Key | Your Huntress API key |
X-Huntress-API-Secret | Your Huntress API secret |
Generate credentials at: Huntress Dashboard > Settings > API Credentials
Environment Variables:
export HUNTRESS_API_KEY="your-api-key"
export HUNTRESS_API_SECRET="your-api-secret"
Available MCP Tools
Navigation
| Tool | Description |
|---|---|
huntress_navigate | Discovery aid — lists the tool names and descriptions in one domain (accounts, agents, organizations, incidents, billing, signals, users) |
huntress_status | Check Huntress API connection status and which domains are available |
Navigation here is stateless discovery, not a cursor. There is no
current resource and no history, so there is no "back" tool — every tool
below is callable directly at any time, and huntress_navigate is never
a prerequisite for calling one.
Through Conduit, huntress_navigate is refused for every caller by the
discovery-tool suppression gate, so a workflow that begins by calling it
will fail at step one. Read the catalog below instead.
Account
| Tool | Description |
|---|---|
huntress_accounts_get | Get account details |
huntress_accounts_actor | Get current authenticated actor info |
Agents
| Tool | Description |
|---|---|
huntress_agents_list | List endpoint agents with filters |
huntress_agents_get | Get details for a specific agent |
Organizations
| Tool | Description |
|---|---|
huntress_organizations_list | List all organizations |
huntress_organizations_get | Get organization details |
huntress_organizations_create | Create a new organization |
huntress_organizations_update | Update an organization |
huntress_organizations_delete | Delete an organization |
Incidents
| Tool | Description |
|---|---|
huntress_incidents_list | List incidents with filters |
huntress_incidents_get | Get incident details |
huntress_incidents_resolve | Resolve an incident |
huntress_incidents_remediations | List remediations for an incident |
huntress_incidents_remediation_get | Get specific remediation details |
huntress_incidents_bulk_approve | Bulk approve remediations |
huntress_incidents_bulk_reject | Bulk reject remediations |
Escalations
| Tool | Description |
|---|---|
huntress_escalations_list | List escalations |
huntress_escalations_get | Get escalation details |
huntress_escalations_resolve | Resolve an escalation |
Reports
| Tool | Description |
|---|---|
huntress_billing_reports_list | List billing reports |
huntress_billing_reports_get | Get a specific billing report |
huntress_summary_reports_list | List summary reports |
huntress_summary_reports_get | Get a specific summary report |
Signals
| Tool | Description |
|---|---|
huntress_signals_list | List security signals |
huntress_signals_get | Get signal details |
Users
| Tool | Description |
|---|---|
huntress_users_list | List users |
huntress_users_get | Get user details |
huntress_users_create | Create a user |
huntress_users_update | Update a user |
huntress_users_delete | Delete a user |
Pagination
The Huntress API uses token-based pagination:
- Pass
page_tokento retrieve the next page of results - The response includes
next_page_tokenif more results are available - Continue fetching pages until
next_page_tokenis absent or null
Example workflow:
- Call
huntress_agents_listwith nopage_token - If response includes
next_page_token, call again with that token - Repeat until no
next_page_tokenis returned
Rate Limiting
Huntress enforces 60 requests per minute.
- HTTP 429 responses indicate rate limit exceeded
- Wait before retrying — use exponential backoff
- Batch operations where possible
- Use filters to reduce result set sizes
Error Handling
Common Error Codes
| Code | Meaning | Resolution |
|---|---|---|
| 401 | Unauthorized | Check API key and secret |
| 403 | Forbidden | Insufficient permissions |
| 404 | Not Found | Resource doesn't exist or wrong ID |
| 429 | Rate Limited | Wait and retry after delay |
| 500 | Server Error | Retry; contact support if persistent |
Error Response Format
{
"error": {
"code": 401,
"message": "Invalid API credentials"
}
}
Best Practices
- Use organization filters to scope queries to specific clients
- Cache account/org info to reduce API calls
- Do not build workflows on navigation state — there is none. Call the tool you need directly; use
huntress_statusonly to confirm credentials and reachability before a batch run
Related Skills
- agents - Endpoint agent management
- organizations - Organization CRUD operations
- incidents - Incident lifecycle management
- escalations - Escalation handling
- billing - Billing and summary reports
- signals - Security signals monitoring
Frequently asked questions
What to verify before installation and use
What does the Huntress API Patterns source document cover?
Huntress MCP fundamentals: HTTP Basic Auth via API key/secret headers, the full MCP tool catalog, token-based pagination, the 60 req/min rate limit, and the common HTTP error codes with their causes.
How do I install Huntress API Patterns?
The source record exposes this install command: npx skills add https://github.com/WYRE-AI/msp-claude-plugins --skill "msp-claude-plugins/huntress/huntress/skills/api-patterns". Inspect the command and pinned source before running it.
Alternatives
Compare before choosing
coreyhaines31/marketingskills
ab-testing
When the user wants to plan, design, or implement an A/B test or experiment, or build a growth experimentation program. Also use when the user mentions "A/B test," "split test," "experiment," "test this change," "variant copy," "multivariate test," "hypothesis," "should I test this," "which version is better," "test two versions," "statistical significance," "how long should I run this test," "growth experiments," "experiment velocity," "experiment backlog," "ICE score," "experimentation program
garrytan/gbrain
bulk-ingestion
End-to-end discipline for turning any large data source (audio libraries, email takeouts, document corpora, chat exports, API dumps) into brain pages at scale. The lifecycle spine: SCHEMA → ACCESS → TRIAL → EVALUATE → IMPROVE → CODIFY → TEST → SKILLIFY → BULK → MONITOR. State is tracked in a durable JSON manifest (see MANIFEST-PATTERN.md) so any crash, session boundary, or subagent fan-out resumes from ground truth instead of memory.
alirezarezvani/claude-skills
app-store-optimization
App Store Optimization (ASO) toolkit for researching keywords, analyzing competitor rankings, generating metadata suggestions, and improving app visibility on Apple App Store and Google Play Store. Use when the user asks about ASO, app store rankings, app metadata, app titles and descriptions, app store listings, app visibility, or mobile app marketing on iOS or Android. Supports keyword research and scoring, competitor keyword analysis, metadata optimization, A/B test planning, launch checklist
dotnet/skills
migrate-vstest-to-mtp
Migrates .NET test projects from VSTest to Microsoft.Testing.Platform (MTP). Use when user asks to "migrate to MTP", "switch from VSTest", "enable Microsoft.Testing.Platform", "use MTP runner", set OutputType=Exe only for test projects in Directory.Build.props, or mentions EnableMSTestRunner, EnableNUnitRunner, or UseMicrosoftTestingPlatformRunner. USE FOR: MTP behavioral differences vs VSTest (exit code 8, zero tests discovered, --ignore-exit-code, TESTINGPLATFORM_EXITCODE_IGNORE); centralizing