Local Mode

The AppViewX MCP Server runs locally on your machine in stdio mode and acts as a bridge between your AI assistant and the AppViewX Platform.
Mode How it works Typical client
stdio The AI client spawns the MCP server as a child process and communicates over standard input/output. No additional network port is required. Claude Desktop, VS Code with GitHub Copilot or Claude Code
The request flow works as follows:
  1. You ask a certificate-related question in an MCP-compatible AI assistant.
  2. The AI assistant converts the request into an MCP tool call and sends it to the AppViewX MCP Server over stdio.
  3. The MCP Server translates the tool call into an authenticated HTTPS request to the AppViewX Platform.
  4. The AppViewX Platform returns the requested certificate data.
  5. The MCP Server sends the response back to the AI assistant in a human-readable format.
The communication between the AI assistant and the local MCP Server does not require to open an additional network port in your machine.

What's Available Today

The AppViewX MCP Server exposes 6 tools. The primary CLM certificate management tools are listed below. All tools respect your existing AppViewX RBAC permissions on your AppViewX service account.
Tool Type Scope Input / Lookup by Returns
CLM
fetch-certificate-list

Search and filter the certificate inventory with server-side filters and pagination.

Read cert:fetch category, expiryStatus, expiryBetween, certStatus, certificateAuthority, discoverysource, subject fields, max, start. Paginated certificate list with commonName, serialNumber, resourceId, status, avxStatus, issuer details, key info, validity dates.
fetch-certificate

Retrieve full details for a single certificate.

Read cert:fetch Lookup by: certificateUuid, resourceId. Paginated certificate list with commonName, serialNumber, resourceId, status, avxStatus, issuer details, key info, validity dates, and discovery sources.
certificate-renew

Submit an asynchronous renewal request for a certificate.

Write cert:renew resourceId, or commonName + serialNumber. Optional: csrContent. 202 Accepted status, requestId (work order ID), resourceId.
certificate-revoke

Revoke a certificate using an RFC 5280 reason code.

Write cert:revoke resourceId, or commonName + serialNumber. certificateAuthority, revocationReason (required). Optional: comments. 202 Accepted status and requestId for the revocation work order.
certificate-regenerate

Generate a new key pair and certificate while preserving the existing configuration.

Write cert:regenerate resourceId, or commonName + serialNumber. Optional: csrContent. 202 Accepted status, requestId (work order ID), resourceId, and newResourceId of the newly generated certificate.
Workflow
get-cert-workorder-status

Check the step-by-step workflow status of a pending request.

Read workflow:status requestId returned by any lifecycle action tool. Each workflow step with its name and current status: Success, In Progress, or Failed.
ADC
fetch-device-list-based-on-filter

Retrieve device inventory details for ADC devices configured in AppViewX.

Read adc:device:fetch Filter by: name, ip, fqdn, dataCenter, vendor, status, version, or free-text keyword search.

The AI maps natural language to the correct filters automatically.

Supports pagination with max and start parameters.

Retrieves ADC devices using filter criteria. Supports filtering by vendor, IP address, FQDN, device status, HA configuration, data center, and firmware version.
fetch-objects-based-on-filter Retrieve ADC object details including virtual servers, pools, monitors, and topology metadata. Read adc:objects:fetch Filter by: name, ip, fqdn, parentName, code, partition, status, deviceName, vendor, isOrphan, or free-text keyword search.

Supports pagination with max and start parameters.

Supported ADC object types: Wide IP, GTM pool, GTM pool member, virtual server, LTM pool, LTM pool member, profiles, iRules, policies, monitors, DataScript, IPGroup, DNS loadbalancer, HTTP/TCP load balancer

Retrieves ADC objects using filter criteria. Supports virtual servers, pools, pool members, wide IPs, profiles, iRules, and monitors.
Note: Workflow status tool will be required to know the status of the clm actions.

Getting Started

Before you begin, ensure that the prerequisites listed for both the modes in this section are in place.
To set up the AppViewX MCP Server in the local mode, complete the following steps:
  1. Create a service account in AppViewX.
  2. Download and extract the MCP Server.
  3. Configure your AI client.
  4. Verify the connection.

Prerequisites

Table 1. Local Mode
Requirement Version Notes
AppViewX CLM 2026.2.0+ Reachable over HTTPS from your local machine.
Java Runtime Environment Java 21 Must be on your system PATH. Verify with java -version.
AI Client Latest Claude Desktop or VS Code with GitHub Copilot configuration is required.
AppViewX Service Account — Provides the Client ID and Client Secret used to authenticate with AppViewX CLM. See Step 1: Create a Service Account in AppViewX.
Important: If your organisation uses an enterprise account for your AI client, you may not be able to add connectors yourself. Contact your IT team or administrator to add the AppViewX MCP Server https://mcp.appvx.com/mcp before you begin setup.

Setting Up Local Mode

In local mode, the MCP Server runs on your machine as a process spawned by your AI client. To set it up, you create a service account in AppViewX, download the MCP Server plugin, and configure your AI client to start and authenticate with it.

Step 1: Create a Service Account in AppViewX

The MCP Server authenticates every request to AppViewX CLM using a service account Client ID and Client Secret. Create a dedicated account, assign the built-in MCP role, and scope it to the certificate resources it needs to access.
  1. Log in to your AppViewX instance.
  2. Navigate to Platform > Service Account.
  3. Click Create New Service Account.
  4. Enter a descriptive name for the account.

    Example: mcp-copilot-integration

  5. Under Role, assign the MCP_Certificate_RO.
    This is the built-in read-only role for MCP integrations and grants the minimum permissions required.
  6. Map the service account to the appropriate usergroup that has the CLM permissions your team requires.
  7. Copy and securely store the generated Client ID and Client Secret.
You now have a Client ID and Client Secret to use when configuring the MCP Server.

Step 2: Download and Extract the MCP Server

Download the AppViewX MCP Server plugin from the AppViewX Agents and Downloads page and extract it to a stable location on your machine.
  1. Login to AppViewX and click the (?) icon in the top-right corner.
  2. Select Agents and Downloads.
  3. Locate the AppViewX MCP Server widget and click Download.
    The file mcp-dist-26.300.0.0.zip is saved to your Downloads folder.
  4. Extract the ZIP to a permanent location.
    Tip: Choose a stable path, for example C:\mcp on Windows or /opt/avx-mcp on Linux or macOS. The full path to avx-mcp.jar will be referenced in the configuration step and must not change after setup.

    After extraction, the folder contains:

    avx-mcp-26.300.0.0/
     ├── lib/
     │    └── avx-mcp.jar    ← the server executable
     ├── mcp.json            ← sample client configuration
     └── README.md
  5. Note the full absolute path to avx-mcp.jar.
    Example (Windows):
    C:\mcp\avx-mcp-26.300.0.0\lib\avx-mcp.jar

    You will need this path in the next step.

Proceed to configure your AI client. Choose the section that matches your tool: Configure Claude Desktop or Configure VS Code.

Step 3a: Configure Claude Desktop

Register the AppViewX MCP Server with Claude Desktop so that Claude can discover and invoke certificate management tools. Have your Client ID, Client Secret, and AppViewX base URL ready.
  1. Open Claude Desktop.
  2. Navigate to Claude > Settings > Developer > Edit Config.
    The file claude_desktop_config.json opens in your default text editor.
  3. Add the avx-mcp-server block inside the mcpServers object:
    {
      "mcpServers": {
        "avx-mcp-server": {
          "type": "stdio",
          "command": "java",
          "args": [
            "-jar",
            "C:\\mcp\\avx-mcp-26.2.0.0\\lib\\avx-mcp.jar"
          ],
          "env": {
            "AVX_BASE_URL": "https://your-appviewx.example.com:31443",
            "CLIENT_ID": "your-client-id",
            "CLIENT_SECRET": "your-client-secret"
          }
        }
      }
    }
    Replace the placeholder values:
    • JAR path: The absolute path to avx-mcp.jar on your machine. Use double backslashes \\ on Windows.
    • AVX_BASE_URL: Your AppViewX instance URL including port.
    • CLIENT_ID: From your AppViewX Service Account.
    • CLIENT_SECRET: From your AppViewX Service Account.
  4. Save the file and fully restart Claude Desktop.
    Claude Desktop spawns the MCP Server process automatically on startup. AppViewX is now natively available inside Claude.
Proceed to verify the connection. See Step 4: Verify the Connection.

Step 3b: Configure VS Code (GitHub Copilot)

Add the AppViewX MCP Server to VS Code so that GitHub Copilot can discover and invoke certificate management tools. Have your Client ID, Client Secret, and AppViewX base URL ready.
  1. Open VS Code.
  2. Press Ctrl+Shift+P to open the Command Palette.
  3. Type and select MCP: Open User MCP Configuration.
    Tip: To limit this server to a single project, select MCP: Open Workspace Folder MCP Configuration instead. This creates .vscode/mcp.json in your current workspace folder only.
  4. Open the sample configuration file included in your extracted distribution: avx-mcp-<version>/mcp.json. Add the avx-mcp-server entry from it into the servers object in your MCP config, or use the sample below:
    {
      "servers": {
        "avx-mcp-server": {
          "type": "stdio",
          "command": "java",
          "args": [
            "-jar",
            "C:\\mcp\\avx-mcp-26.2.0.0\\lib\\avx-mcp.jar"
          ],
          "env": {
            "AVX_BASE_URL": "https://your-appviewx.example.com:31443",
            "CLIENT_ID": "your-client-id",
            "CLIENT_SECRET": "your-client-secret"
          }
        }
      }
    }

    Replace JAR path, AVX_BASE_URL, CLIENT_ID, and CLIENT_SECRET with your actual values.

  5. Save the file (Ctrl+S).
    VS Code detects the configuration and automatically starts the MCP Server process.
    Remember: Always use absolute paths do not rely on working directory resolution. Ensure Java is available in PATH before starting VS Code. Avoid wrapping the JAR in shell scripts unless strictly necessary.
Proceed to verify the connection. See Step 4: Verify the Connection.

Step 4: Verify the Connection

Confirm the AppViewX MCP Server is running and tools are available to your AI assistant.
Claude Desktop:
  • Check that AppViewX tools appear in the available tools panel.
  • Send the test prompt: Show me available tools in AppViewX MCP.

    Claude lists the available AppViewX tools if the connection is successful.

VS Code:
  • Press Ctrl+Shift+P and select MCP: Show Installed Servers.
  • The server avx-mcp-server appears with a status of Running or Started, and the list of discovered tools is visible beneath it.

The AppViewX MCP Server is now ready. You can query your certificate inventory, check certificate expiry, inspect algorithms, and more through natural language conversation.

Using the AppViewX MCP Server

With the server running, interact with your certificate inventory using natural language directly inside your AI assistant. The AI reaches out to AppViewX in real time, pulling live data and surfacing it as structured, actionable results.

The following sections describe each available tool, its inputs, and example prompts.

Query Certificate Inventory

Tool name: fetch-certificate-list

Searches and filters the AppViewX certificate inventory. The AI assistant maps your natural language request to the correct filter parameters automatically.

  1. Type a natural language query in your AI assistant describing the certificates you want to find.

    Example prompts:

    • Get all the server certificates.
    • Get the certificates that are expiring in 09/26/2026.
    • Get the certificates that are discovered from ptpld260, which is expired already.
    • Renew the certificates which are expiring next month, issued from AppViewX CA, from OU IoT.
    • Show certificates expiring in 90 days across all categories.
  2. Review the results returned by the AI assistant.
    The assistant returns a paginated list of certificates matching your criteria. Each record includes: commonName, serialNumber, resourceId, status, avxStatus, issuer details, key information, and validity dates.
  3. To retrieve the next page, ask the AI assistant to continue or specify the next starting record.
Use the resourceId from any returned record as input to the fetch-certificate, certificate-renew, certificate-revoke, or certificate-regenerate tools.

Get Certificate Details

Tool name: fetch-certificate

Retrieves the full details of a single certificate, including key algorithm and size, SANs, issuer details, compliance status, thumbprint, and discovery sources.

  1. Provide the certificate identifier in your prompt.

    Example prompts:

    • Get the certificate detail of the certificate with UUID: 45e43ee2186e1c4944f9ff02a73a193112f55247.
  2. Review the full certificate record returned by the AI assistant.
    The assistant returns the complete certificate profile, including: common name, serial number, resource ID, validity dates, issuer common name, Certificate Authority, issuer settings name, organization, key algorithm, key size, signature algorithm, key usage, extended key usage, thumbprint, SAN entries, compliance status, and discovery sources.
    Note: A single query can invoke multiple tools in combination. For example, a request like "renew all server certificates expiring in the next 30 days" would use the fetch-list tool (to identify matching certificates) followed by the renew tool (to renew each one), and so on for similar multi-step queries.

Renew a Certificate

Tool name: certificate-renew

Submits a renewal request through AppViewX's configured workflow. Renewal runs asynchronously. A work order ID is returned immediately so you can track progress.

Note: Renewal via MCP uses the workflow path only. Policy-engine-based renewal is not supported in this release. Use get-cert-workorder-status to track the renewal progress.
  1. Identify the certificate to renew and provide its identifier in your prompt.

    Example prompts:

    • Renew the certificate which has the serial number 6D:AB:04:35:26:DC:82:1D:33:26:DD:28:3C:7D:31:79.
    • Renew the certificate codesign-cert-test-01.app.com.
    • Renew the certificates which are expiring next month, issued from AppViewX CA, from OU IoT.
    Provide one of the following identifiers:
    • resourceId the AppViewX resource ID.
    • commonName + serialNumber the certificate common name combined with its serial number.
    Optional parameters:
    • csrContent a custom CSR to use during renewal. Supported for DigiCert and HydrantID CAs. For CAs that do not support CSR upload during renewal, this field is ignored and the existing CSR is used automatically.
  2. If the AI assistant finds more than one certificate with the same common name, select the correct certificate from the list it presents.
    Important: When multiple certificates share the same common name, the AI assistant displays each one with its serial number, validity dates, and asks you to confirm your selection before proceeding. This prevents accidental renewal of the wrong certificate.
  3. Confirm the renewal when prompted by the AI assistant.
The AI assistant returns a confirmation with the following details:
  • HTTP status: 202 Accepted
  • Work order ID (requestId) use this with get-cert-workorder-status to track the renewal workflow.
  • The resource ID of the acted-on certificate (resourceId).

Revoke a Certificate

Tool name: certificate-revoke

Revokes a certificate asynchronously through the AppViewX workflow using an RFC 5280 reason code. The AI assistant surfaces the reason codes and asks for explicit confirmation before submitting the request.

CAUTION: Revocation is irreversible. Verify the certificate details using fetch-certificate before confirming the revocation. Revocation via MCP uses the workflow path only. Policy-engine-based revocation is not supported in this release.
  1. Note: The revocation reason can be provided as either a code or a plain-text reason the AI will handle framing the payload accordingly.
    Type a revocation request in your AI assistant, or enter /certificate-revoke to start a guided revocation flow.

    Example prompts:

    • Revoke the certificate with resource id 6a8e65e5f467261a8b110556, revoke reason as key compromise.
    • Revoke old.example.com reason: cessation of operation.
  2. Provide the certificate identifier, Certificate Authority, and revocation reason when requested by the AI assistant.
    Required inputs:
    • Certificate identifier provide one of:
      • resourceId the AppViewX MongoDB resource ID. Preferred — avoids ambiguity when multiple certificates share a common name.
      • commonName + serialNumber the certificate common name combined with its serial number.
    • certificateAuthority the CA that issued the certificate. Required for correct routing of the revocation request.
    • revocationReason the RFC 5280 reason code (0–10) or plain-text phrase. Defaults to 0 (Unspecified) if not provided.
    Revocation reason codes (RFC 5280):
    Code Reason
    00 Unspecified
    01 Key Compromise
    02 CA Compromise
    03 Affiliation Changed
    04 Superseded
    05 Cessation Of Operation
    06 Certificate Hold
    09 Privilege Withdrawn
    10 AA Compromise
    Optional inputs:
    • comments an audit note attached to the revocation request.
  3. Confirm the revocation when the AI assistant presents the certificate details and prompts for confirmation.
    The AI assistant displays the certificate identifier, CA, and reason code, and warns that the action is irreversible before proceeding.
The AI assistant returns a confirmation with:
  • HTTP status: 202 Accepted
  • Work order ID (requestId) use this with get-cert-workorder-status to track the revocation workflow.

Regenerate a Certificate

Tool name: certificate-regenerate

Regenerates a certificate with a brand-new key pair while preserving the original certificate's configuration subject, SANs, CA settings, and template. Use regeneration when you need a new private key, as distinct from a routine renewal.

Note: Regeneration always runs asynchronously through the configured workflow. A request ID and new resource ID are returned immediately. Use get-cert-workorder-status to track each workflow step.
  1. Provide the certificate identifier in your prompt.

    Example prompts:

    • Regenerate certificate app.cert01.test.com.
    Provide one of the following identifiers:
    • resourceId the AppViewX resource ID. Preferred identifier.
    • commonName + serialNumber the certificate common name combined with its serial number.
  2. Review the regeneration confirmation returned by the AI assistant.
    The AI assistant confirms the regeneration has been triggered and displays:
    • Certificate common name
    • HTTP status: 202 Accepted
    • Request ID (requestId)
    • New resource ID (newResourceId) the ID of the newly generated certificate in AppViewX

Check Workflow Request Status

Tool name: get-cert-workorder-status

Checks the current step-by-step workflow status of any pending request. The response includes each workflow step with its current status: Success, In Progress, or Failed. Use the request ID returned by the Renew, Revoke, or Regenerate tools.

  1. Ask the AI assistant to check the status of a pending request by providing the request ID.

    Example prompts:

    • Check the status of request 60.
  2. Review the step-by-step workflow status returned by the AI assistant.
    Note: A single query can invoke multiple tools in combination. For example, a request like "renew all server certificates expiring in the next 30 days" would use the fetch-list tool (to identify matching certificates) followed by the renew tool (to renew each one), and so on for similar multi-step queries.

More Things You Can Ask

The following table lists additional natural language prompts and what they return.
  • Show me all certificates issued by DigiCert.
  • Find RSA 2048 certificates expiring this quarter.
  • Show me all DigiCert managed server certificates expiring in 30 days.
  • Renew all expiring server certificates issued by GlobalSign expiring in next 30 days.
  • Show me all the expired certificates from microsoft enterprise CA, which are in monitored status.
  • Revoke all certificates with common name "old.appviewx.com" and organizational unit "Old OU".
  • Find all certificates in organization unit "Expired OU" expiring in the next 7 days and renew them.

Troubleshooting

Common issues when setting up or running the AppViewX MCP Server, with resolution steps.
Unable to access jarfile

Cause: The path to avx-mcp.jar in the configuration is incorrect.

Resolution:

  1. Double-check the absolute path in your configuration file.
  2. On Windows, verify the file exists:
    Test-Path "C:\mcp\avx-mcp-26.2.0.0\lib\avx-mcp.jar"
    The command must return True.
  3. Use double backslashes \\ or forward slashes / in the path string inside the JSON.
java: command not found

Cause: Java is not installed or is not on the system PATH.

Resolution:

  1. Install Java 21.
  2. Restart your terminal or AI client after installation.
  3. Verify: java -version
Server starts but exits immediately

Cause: A startup error commonly an incorrect AppViewX URL or invalid credentials.

Resolution: Run the JAR manually to see the error in the console:

java -jar "C:\mcp\avx-mcp-26.2.0.0\lib\avx-mcp.jar"
  • Connection refused verify AVX_BASE_URL is correct and reachable from your machine.
  • Unauthorized / 401 verify CLIENT_ID and CLIENT_SECRET are correct and the service account is active.
Tools are not visible in the AI assistant
Check Resolution
Server status is not Running Verify the JAR path is correct and restart the AI client.
JSON syntax error in configuration file Validate the JSON with a linter or paste it into a JSON validator before saving.
Service account has no CLM permissions In AppViewX, verify the service account is mapped to a group with the required permissions.
No response from server

Cause: The MCP client is not communicating with the server, often due to a configuration error or a stale client state.

Resolution:
  1. Verify the MCP client configuration file has no JSON syntax errors paste it into a JSON validator if unsure.
  2. Fully restart the AI client (Claude Desktop or VS Code) to force a fresh server spawn.
  3. Run the JAR manually to confirm it starts without errors:
    java -jar "C:\mcp\avx-mcp-26.2.0.0\lib\avx-mcp.jar"
Authentication fails or returns Unauthorized

Cause: The Client ID or Client Secret is incorrect or has expired.

Resolution:

  1. Log in to AppViewX and navigate to Platform > Service Account.
  2. Regenerate or confirm the credentials for your service account.
  3. Update CLIENT_ID and CLIENT_SECRET in your configuration file and restart the MCP Server.