Local Mode
| Mode | How it works | Typical client |
|---|---|---|
| stdio | The AI client spawns the MCP server as a child process and communicates over standard input/output. No additional network port is required. | Claude Desktop, VS Code with GitHub Copilot or Claude Code |
- You ask a certificate-related question in an MCP-compatible AI assistant.
- The AI assistant converts the request into an MCP tool call and sends it to the AppViewX MCP Server over stdio.
- The MCP Server translates the tool call into an authenticated HTTPS request to the AppViewX Platform.
- The AppViewX Platform returns the requested certificate data.
- The MCP Server sends the response back to the AI assistant in a human-readable format.
What's Available Today
| Tool | Type | Scope | Input / Lookup by | Returns |
|---|---|---|---|---|
| CLM | ||||
fetch-certificate-listSearch and filter the certificate inventory with server-side filters and pagination. |
Read | cert:fetch |
category, expiryStatus, expiryBetween, certStatus, certificateAuthority, discoverysource, subject fields, max, start. | Paginated certificate list with commonName, serialNumber, resourceId, status, avxStatus, issuer details, key info, validity dates. |
fetch-certificateRetrieve full details for a single certificate. |
Read | cert:fetch |
Lookup by: certificateUuid, resourceId. | Paginated certificate list with commonName, serialNumber, resourceId, status, avxStatus, issuer details, key info, validity dates, and discovery sources. |
certificate-renewSubmit an asynchronous renewal request for a certificate. |
Write | cert:renew |
resourceId, or commonName + serialNumber. Optional: csrContent. | 202 Accepted status, requestId (work order ID), resourceId. |
certificate-revokeRevoke a certificate using an RFC 5280 reason code. |
Write | cert:revoke |
resourceId, or commonName + serialNumber. certificateAuthority, revocationReason (required). Optional: comments. | 202 Accepted status and requestId for the revocation work order. |
certificate-regenerateGenerate a new key pair and certificate while preserving the existing configuration. |
Write | cert:regenerate |
resourceId, or commonName + serialNumber. Optional: csrContent. | 202 Accepted status, requestId (work order ID), resourceId, and newResourceId of the newly generated certificate. |
| Workflow | ||||
get-cert-workorder-statusCheck the step-by-step workflow status of a pending request. |
Read | workflow:status |
requestId returned by any lifecycle action tool. | Each workflow step with its name and current status: Success, In Progress, or Failed. |
| ADC | ||||
fetch-device-list-based-on-filterRetrieve device inventory details for ADC devices configured in AppViewX. |
Read | adc:device:fetch |
Filter by: name, ip, fqdn, dataCenter, vendor, status,
version, or free-text keyword search. The AI maps natural language to the correct filters automatically. Supports pagination with max and start parameters. |
Retrieves ADC devices using filter criteria. Supports filtering by vendor, IP address, FQDN, device status, HA configuration, data center, and firmware version. |
fetch-objects-based-on-filter Retrieve ADC
object details including virtual servers, pools, monitors, and
topology metadata. |
Read | adc:objects:fetch |
Filter by: name, ip, fqdn, parentName, code, partition,
status, deviceName, vendor, isOrphan, or free-text keyword
search. Supports pagination with max and start parameters. Supported ADC object types: Wide IP, GTM pool, GTM pool member, virtual server, LTM pool, LTM pool member, profiles, iRules, policies, monitors, DataScript, IPGroup, DNS loadbalancer, HTTP/TCP load balancer |
Retrieves ADC objects using filter criteria. Supports virtual servers, pools, pool members, wide IPs, profiles, iRules, and monitors. |
Getting Started
- Create a service account in AppViewX.
- Download and extract the MCP Server.
- Configure your AI client.
- Verify the connection.
Prerequisites
| Requirement | Version | Notes |
|---|---|---|
| AppViewX CLM | 2026.2.0+ | Reachable over HTTPS from your local machine. |
| Java Runtime Environment | Java 21 | Must be on your system PATH. Verify with java
-version. |
| AI Client | Latest | Claude Desktop or VS Code with GitHub Copilot configuration is required. |
| AppViewX Service Account | — | Provides the Client ID and Client Secret used to authenticate with AppViewX CLM. See Step 1: Create a Service Account in AppViewX. |
https://mcp.appvx.com/mcp before you begin
setup.Setting Up Local Mode
Step 1: Create a Service Account in AppViewX
- Log in to your AppViewX instance.
- Navigate to .
- Click Create New Service Account.
-
Enter a descriptive name for the account.
Example: mcp-copilot-integration
-
Under Role, assign the
MCP_Certificate_RO.This is the built-in read-only role for MCP integrations and grants the minimum permissions required. - Map the service account to the appropriate usergroup that has the CLM permissions your team requires.
- Copy and securely store the generated Client ID and Client Secret.
Step 2: Download and Extract the MCP Server
- Login to AppViewX and click the (?) icon in the top-right corner.
- Select Agents and Downloads.
-
Locate the AppViewX MCP Server widget and click
Download.
The file mcp-dist-26.300.0.0.zip is saved to your Downloads folder.
-
Extract the ZIP to a permanent location.
Tip: Choose a stable path, for example C:\mcp on Windows or /opt/avx-mcp on Linux or macOS. The full path to avx-mcp.jar will be referenced in the configuration step and must not change after setup.
After extraction, the folder contains:
avx-mcp-26.300.0.0/ ├── lib/ │ └── avx-mcp.jar ← the server executable ├── mcp.json ← sample client configuration └── README.md -
Note the full absolute path to
avx-mcp.jar.Example (Windows):C:\mcp\avx-mcp-26.300.0.0\lib\avx-mcp.jarYou will need this path in the next step.
Step 3a: Configure Claude Desktop
- Open Claude Desktop.
-
Navigate to .
The file claude_desktop_config.json opens in your default text editor.
-
Add the
avx-mcp-serverblock inside themcpServersobject:{ "mcpServers": { "avx-mcp-server": { "type": "stdio", "command": "java", "args": [ "-jar", "C:\\mcp\\avx-mcp-26.2.0.0\\lib\\avx-mcp.jar" ], "env": { "AVX_BASE_URL": "https://your-appviewx.example.com:31443", "CLIENT_ID": "your-client-id", "CLIENT_SECRET": "your-client-secret" } } } }Replace the placeholder values:- JAR path: The absolute path to
avx-mcp.jar on your machine. Use
double backslashes
\\on Windows. - AVX_BASE_URL: Your AppViewX instance URL including port.
- CLIENT_ID: From your AppViewX Service Account.
- CLIENT_SECRET: From your AppViewX Service Account.
- JAR path: The absolute path to
avx-mcp.jar on your machine. Use
double backslashes
-
Save the file and fully restart Claude
Desktop.
Claude Desktop spawns the MCP Server process automatically on startup. AppViewX is now natively available inside Claude.
Step 3b: Configure VS Code (GitHub Copilot)
- Open VS Code.
- Press Ctrl+Shift+P to open the Command Palette.
-
Type and select MCP: Open User MCP
Configuration.
Tip: To limit this server to a single project, select MCP: Open Workspace Folder MCP Configuration instead. This creates .vscode/mcp.json in your current workspace folder only.
-
Open the sample configuration file included in your extracted
distribution:
avx-mcp-<version>/mcp.json. Add theavx-mcp-serverentry from it into theserversobject in your MCP config, or use the sample below:{ "servers": { "avx-mcp-server": { "type": "stdio", "command": "java", "args": [ "-jar", "C:\\mcp\\avx-mcp-26.2.0.0\\lib\\avx-mcp.jar" ], "env": { "AVX_BASE_URL": "https://your-appviewx.example.com:31443", "CLIENT_ID": "your-client-id", "CLIENT_SECRET": "your-client-secret" } } } }Replace JAR path, AVX_BASE_URL, CLIENT_ID, and CLIENT_SECRET with your actual values.
-
Save the file (Ctrl+S).
VS Code detects the configuration and automatically starts the MCP Server process.Remember: Always use absolute paths do not rely on working directory resolution. Ensure Java is available in PATH before starting VS Code. Avoid wrapping the JAR in shell scripts unless strictly necessary.
Step 4: Verify the Connection
- Check that AppViewX tools appear in the available tools panel.
- Send the test prompt: Show me available tools in AppViewX
MCP.
Claude lists the available AppViewX tools if the connection is successful.
- Press Ctrl+Shift+P and select MCP: Show Installed Servers.
- The server
avx-mcp-serverappears with a status of Running or Started, and the list of discovered tools is visible beneath it.
The AppViewX MCP Server is now ready. You can query your certificate inventory, check certificate expiry, inspect algorithms, and more through natural language conversation.
Using the AppViewX MCP Server
The following sections describe each available tool, its inputs, and example prompts.
Query Certificate Inventory
fetch-certificate-listSearches and filters the AppViewX certificate inventory. The AI assistant maps your natural language request to the correct filter parameters automatically.
-
Type a natural language query in your AI assistant describing the
certificates you want to find.
Example prompts:
- Get all the server certificates.
- Get the certificates that are expiring in 09/26/2026.
- Get the certificates that are discovered from ptpld260, which is expired already.
- Renew the certificates which are expiring next month, issued from AppViewX CA, from OU IoT.
- Show certificates expiring in 90 days across all categories.
-
Review the results returned by the AI assistant.
The assistant returns a paginated list of certificates matching your criteria. Each record includes:
commonName,serialNumber,resourceId,status,avxStatus, issuer details, key information, and validity dates. - To retrieve the next page, ask the AI assistant to continue or specify the next starting record.
resourceId from any
returned record as input to the fetch-certificate,
certificate-renew, certificate-revoke, or
certificate-regenerate tools.Get Certificate Details
fetch-certificateRetrieves the full details of a single certificate, including key algorithm and size, SANs, issuer details, compliance status, thumbprint, and discovery sources.
-
Provide the certificate identifier in your prompt.
Example prompts:
- Get the certificate detail of the certificate with UUID: 45e43ee2186e1c4944f9ff02a73a193112f55247.
-
Review the full certificate record returned by the AI assistant.
The assistant returns the complete certificate profile, including: common name, serial number, resource ID, validity dates, issuer common name, Certificate Authority, issuer settings name, organization, key algorithm, key size, signature algorithm, key usage, extended key usage, thumbprint, SAN entries, compliance status, and discovery sources.Note: A single query can invoke multiple tools in combination. For example, a request like "renew all server certificates expiring in the next 30 days" would use the fetch-list tool (to identify matching certificates) followed by the renew tool (to renew each one), and so on for similar multi-step queries.
Renew a Certificate
certificate-renewSubmits a renewal request through AppViewX's configured workflow. Renewal runs asynchronously. A work order ID is returned immediately so you can track progress.
get-cert-workorder-status to track the renewal
progress.-
Identify the certificate to renew and provide its identifier in your
prompt.
Example prompts:
- Renew the certificate which has the serial number 6D:AB:04:35:26:DC:82:1D:33:26:DD:28:3C:7D:31:79.
- Renew the certificate codesign-cert-test-01.app.com.
- Renew the certificates which are expiring next month, issued from AppViewX CA, from OU IoT.
Provide one of the following identifiers:- resourceId the AppViewX resource ID.
- commonName + serialNumber the certificate common name combined with its serial number.
Optional parameters:- csrContent a custom CSR to use during renewal. Supported for DigiCert and HydrantID CAs. For CAs that do not support CSR upload during renewal, this field is ignored and the existing CSR is used automatically.
-
If the AI assistant finds more than one certificate with the same
common name, select the correct certificate from the list it
presents.
Important: When multiple certificates share the same common name, the AI assistant displays each one with its serial number, validity dates, and asks you to confirm your selection before proceeding. This prevents accidental renewal of the wrong certificate.
- Confirm the renewal when prompted by the AI assistant.
- HTTP status: 202 Accepted
- Work order ID (
requestId) use this withget-cert-workorder-statusto track the renewal workflow. - The resource ID of the acted-on certificate
(
resourceId).
Revoke a Certificate
certificate-revokeRevokes a certificate asynchronously through the AppViewX workflow using an RFC 5280 reason code. The AI assistant surfaces the reason codes and asks for explicit confirmation before submitting the request.
fetch-certificate before confirming the revocation.
Revocation via MCP uses the workflow path only. Policy-engine-based
revocation is not supported in this release.-
Note: The revocation reason can be provided as either a code or a plain-text reason the AI will handle framing the payload accordingly.Type a revocation request in your AI assistant, or enter /certificate-revoke to start a guided revocation flow.
Example prompts:
- Revoke the certificate with resource id 6a8e65e5f467261a8b110556, revoke reason as key compromise.
- Revoke old.example.com reason: cessation of operation.
-
Provide the certificate identifier, Certificate Authority, and
revocation reason when requested by the AI assistant.
Required inputs:
- Certificate identifier provide one of:
- resourceId the AppViewX MongoDB resource ID. Preferred — avoids ambiguity when multiple certificates share a common name.
- commonName + serialNumber the certificate common name combined with its serial number.
- certificateAuthority the CA that issued the certificate. Required for correct routing of the revocation request.
- revocationReason the RFC 5280 reason code (0–10) or
plain-text phrase. Defaults to
0(Unspecified) if not provided.
Revocation reason codes (RFC 5280):Code Reason 00 Unspecified 01 Key Compromise 02 CA Compromise 03 Affiliation Changed 04 Superseded 05 Cessation Of Operation 06 Certificate Hold 09 Privilege Withdrawn 10 AA Compromise Optional inputs:- comments an audit note attached to the revocation request.
- Certificate identifier provide one of:
-
Confirm the revocation when the AI assistant presents the certificate
details and prompts for confirmation.
The AI assistant displays the certificate identifier, CA, and reason code, and warns that the action is irreversible before proceeding.
- HTTP status: 202 Accepted
- Work order ID (
requestId) use this withget-cert-workorder-statusto track the revocation workflow.
Regenerate a Certificate
certificate-regenerateRegenerates a certificate with a brand-new key pair while preserving the original certificate's configuration subject, SANs, CA settings, and template. Use regeneration when you need a new private key, as distinct from a routine renewal.
get-cert-workorder-status to
track each workflow step.-
Provide the certificate identifier in your prompt.
Example prompts:
- Regenerate certificate app.cert01.test.com.
Provide one of the following identifiers:- resourceId the AppViewX resource ID. Preferred identifier.
- commonName + serialNumber the certificate common name combined with its serial number.
-
Review the regeneration confirmation returned by the AI
assistant.
The AI assistant confirms the regeneration has been triggered and displays:
- Certificate common name
- HTTP status: 202 Accepted
- Request ID (
requestId) - New resource ID (
newResourceId) the ID of the newly generated certificate in AppViewX
Check Workflow Request Status
get-cert-workorder-statusChecks the current step-by-step workflow status of any pending request. The response includes each workflow step with its current status: Success, In Progress, or Failed. Use the request ID returned by the Renew, Revoke, or Regenerate tools.
-
Ask the AI assistant to check the status of a pending request by
providing the request ID.
Example prompts:
- Check the status of request 60.
-
Review the step-by-step workflow status returned by the AI
assistant.
Note: A single query can invoke multiple tools in combination. For example, a request like "renew all server certificates expiring in the next 30 days" would use the fetch-list tool (to identify matching certificates) followed by the renew tool (to renew each one), and so on for similar multi-step queries.
More Things You Can Ask
- Show me all certificates issued by DigiCert.
- Find RSA 2048 certificates expiring this quarter.
- Show me all DigiCert managed server certificates expiring in 30 days.
- Renew all expiring server certificates issued by GlobalSign expiring in next 30 days.
- Show me all the expired certificates from microsoft enterprise CA, which are in monitored status.
- Revoke all certificates with common name "old.appviewx.com" and organizational unit "Old OU".
- Find all certificates in organization unit "Expired OU" expiring in the next 7 days and renew them.
Troubleshooting
Cause: The path to avx-mcp.jar in the configuration is incorrect.
Resolution:
- Double-check the absolute path in your configuration file.
- On Windows, verify the file exists:
Test-Path "C:\mcp\avx-mcp-26.2.0.0\lib\avx-mcp.jar"The command must return True. - Use double backslashes
\\or forward slashes/in the path string inside the JSON.
Cause: Java is not installed or is not on the system PATH.
Resolution:
- Install Java 21.
- Restart your terminal or AI client after installation.
- Verify:
java -version
Cause: A startup error commonly an incorrect AppViewX URL or invalid credentials.
Resolution: Run the JAR manually to see the error in the console:
java -jar "C:\mcp\avx-mcp-26.2.0.0\lib\avx-mcp.jar"- Connection refused verify
AVX_BASE_URLis correct and reachable from your machine. - Unauthorized / 401 verify
CLIENT_IDandCLIENT_SECRETare correct and the service account is active.
| Check | Resolution |
|---|---|
| Server status is not Running | Verify the JAR path is correct and restart the AI client. |
| JSON syntax error in configuration file | Validate the JSON with a linter or paste it into a JSON validator before saving. |
| Service account has no CLM permissions | In AppViewX, verify the service account is mapped to a group with the required permissions. |
Cause: The MCP client is not communicating with the server, often due to a configuration error or a stale client state.
- Verify the MCP client configuration file has no JSON syntax errors paste it into a JSON validator if unsure.
- Fully restart the AI client (Claude Desktop or VS Code) to force a fresh server spawn.
- Run the JAR manually to confirm it starts without
errors:
java -jar "C:\mcp\avx-mcp-26.2.0.0\lib\avx-mcp.jar"
Cause: The Client ID or Client Secret is incorrect or has expired.
Resolution:
- Log in to AppViewX and navigate to .
- Regenerate or confirm the credentials for your service account.
- Update
CLIENT_IDandCLIENT_SECRETin your configuration file and restart the MCP Server.
