AppViewX MCP Server
Overview
The AppViewX MCP Server enables MCP-compatible AI assistants to query certificate information from the AppViewX Platform using approved read-only tools.
This Tech Preview release supports natural language access to certificate visibility use cases such as certificate inventory search, expiry checks, cryptographic algorithm review, and certificate compliance insights.
- Local Mode (stdio):
The server runs on your machine as a process spawned by your AI client
- Remote Mode (HTTP):
The server runs as a hosted endpoint on the AppViewX Platform and your AI client connects to it directly over the network.
Note:- Remote Mode is available for SaaS deployments only.
- Both modes expose the same tools and support the same
natural language queries. The tools available to a given
user depend on three factors:
- Product licenses active on their tenant.
- OAuth scopes granted at login.
- MCP permissions assigned to their AppViewX role.
How It Works
The server supports two deployment modes. The mode you use depends on your AppViewX deployment type and how your organisation manages AI client access.
What's Available Today
| Tool | Type | Scope | Input / Lookup by | Returns |
|---|---|---|---|---|
| CLM | ||||
fetch-certificate-listSearch and filter the certificate inventory with server-side filters and pagination. |
Read | cert:fetch |
category, expiryStatus, expiryBetween, certStatus, certificateAuthority, discoverysource, subject fields, max, start. | Paginated certificate list with commonName, serialNumber, resourceId, status, avxStatus, issuer details, key info, validity dates. |
fetch-certificateRetrieve full details for a single certificate. |
Read | cert:fetch |
Lookup by: certificateUuid, resourceId. | Paginated certificate list with commonName, serialNumber, resourceId, status, avxStatus, issuer details, key info, validity dates, and discovery sources. |
certificate-renewSubmit an asynchronous renewal request for a certificate. |
Write | cert:renew |
resourceId, or commonName + serialNumber. Optional: csrContent. | 202 Accepted status, requestId (work order ID), resourceId. |
certificate-revokeRevoke a certificate using an RFC 5280 reason code. |
Write | cert:revoke |
resourceId, or commonName + serialNumber. certificateAuthority, revocationReason (required). Optional: comments. | 202 Accepted status and requestId for the revocation work order. |
certificate-regenerateGenerate a new key pair and certificate while preserving the existing configuration. |
Write | cert:regenerate |
resourceId, or commonName + serialNumber. Optional: csrContent. | 202 Accepted status, requestId (work order ID), resourceId, and newResourceId of the newly generated certificate. |
| Workflow | ||||
get-cert-workorder-statusCheck the step-by-step workflow status of a pending request. |
Read | workflow:status |
requestId returned by any lifecycle action tool. | Each workflow step with its name and current status: Success, In Progress, or Failed. |
| ADC | ||||
fetch-device-list-based-on-filterRetrieve device inventory details for ADC devices configured in AppViewX. |
Read | adc:device:fetch |
Filter by: name, ip, fqdn, dataCenter, vendor, status,
version, or free-text keyword search. The AI maps natural language to the correct filters automatically. Supports pagination with max and start parameters. |
Retrieves ADC devices using filter criteria. Supports filtering by vendor, IP address, FQDN, device status, HA configuration, data center, and firmware version. |
fetch-objects-based-on-filter Retrieve ADC
object details including virtual servers, pools, monitors, and
topology metadata. |
Read | adc:objects:fetch |
Filter by: name, ip, fqdn, parentName, code, partition,
status, deviceName, vendor, isOrphan, or free-text keyword
search. Supports pagination with max and start parameters. Supported ADC object types: Wide IP, GTM pool, GTM pool member, virtual server, LTM pool, LTM pool member, profiles, iRules, policies, monitors, DataScript, IPGroup, DNS loadbalancer, HTTP/TCP load balancer |
Retrieves ADC objects using filter criteria. Supports virtual servers, pools, pool members, wide IPs, profiles, iRules, and monitors. |
