Gene Library Courses Download Pricing Contact Sign in
drata logo
security Official Website

Drata MCP Server – Compliance and Risk Access

Drata MCP is a remotely hosted Model Context Protocol server for connecting AI assistants to Drata trust-management data. It lets authorized users query and report on live compliance, policy, control, monitoring-test, workspace, and risk information while enforcing configured OAuth scopes and Drata role permissions.

#grc#compliance#risk

Overview

Drata MCP is Drata's hosted Model Context Protocol server for AI-native trust management. It connects MCP-compatible clients such as ChatGPT, Claude, Cursor, and Microsoft Copilot to Drata workspace data, giving AI agents a controlled way to answer compliance and risk questions from live Drata context instead of static model knowledge.

What the MCP server enables

The server exposes Drata data according to the OAuth configuration selected by an administrator. Documented scopes include reading risks, controls, control details, policies, workspaces, risk registers, assigned policies, and monitoring tests. In practice, agents can help users identify controls missing evidence, review failing monitoring tests, summarize risks that need attention, find policy requirements such as security awareness training or vulnerability SLAs, and prepare scoped reports from current compliance data.

Access is bounded by two layers: the OAuth scopes configured for the MCP connection and the permissions granted by the user's Drata role. A user cannot access MCP data beyond the intersection of those two permission sets.

When to use it

Use Drata MCP when a GRC, security, engineering, or compliance team wants an AI assistant to answer operational questions about Drata without manually navigating dashboards. Useful workflows include creating risk summaries, checking policy obligations, reviewing controls by framework, triaging failed monitoring tests, and asking natural-language questions during audit preparation or vendor-risk reviews.

Connection and authentication

Drata provides hosted remote MCP endpoints for US, EU, and APAC regions. Administrators configure MCP OAuth from Drata settings, create an OAuth configuration, select scopes, and then connect an MCP-compatible client to the regional endpoint. Drata documents OAuth authentication, SSO support, user-level permissions, and audit logging for MCP usage.

Key considerations

Drata describes the MCP server as a beta or early-access feature, so organizations should confirm availability with Drata before production use. Administrators should grant only the scopes required for the intended workflow, review client-specific behavior before approving write-capable actions, and monitor usage over time. Users should mention Drata explicitly in prompts and include framework names, time ranges, risk categories, or teams when they need precise results.

Supported Transports

streamable_http

URL: https://mcp.drata.com/mcp/

streamable_http

URL: https://mcp-euc1.drata.com/mcp/

streamable_http

URL: https://mcp-apse2.drata.com/mcp/

Frequently Asked Questions

When should an AI agent use the Drata MCP server?
Use Drata MCP when an agent needs live Drata trust-management context, such as summarizing risks, reviewing failed monitoring tests, checking controls, answering policy questions, or preparing compliance reports from current workspace data.
What does Drata MCP add to an AI agent's capabilities?
It gives the agent authenticated access to Drata data governed by MCP OAuth scopes and Drata role permissions, allowing it to reason over current controls, policies, risks, risk registers, workspaces, assigned policies, and monitoring tests.
What can the AI agent access through Drata MCP?
Documented scopes cover risks, controls, detailed control requirements, policies, workspaces, risk registers, assigned policies, and monitoring tests. Actual access depends on the scopes configured by an administrator and the user's Drata role.
How is authentication configured for Drata MCP?
A Drata administrator configures MCP OAuth in Drata, creates an OAuth configuration, selects the allowed scopes, and connects the chosen MCP client to the appropriate regional hosted endpoint. Drata notes that credentials are not shared with the AI client and access can be revoked.
Which transport should be used for Drata MCP?
Use Drata's hosted Streamable HTTP MCP endpoint for the organization's region: US, EU, or APAC. Drata's documentation lists these remote endpoints and does not document a local stdio server or SSE endpoint for this hosted MCP service.