Netskope NPA MCP
Infrastructure · tested 2026-08-14 · by the Hlido desk, not the vendor
In short: Seventy tools for Netskope Private Access with three documented deployment paths and a decision table telling you which to pick — enterprise-grade documentation from what appears to be an independent maintainer.
Quick answer
Netskope NPA MCP scores 80/100 (STEADY) on Hlido’s independent, hands-on test (reviewed 2026-08-14). STEADY and near the top because nearly every check passes with evidence: version-pinned docs, a published tool surface, three documented deployment paths with a decision table, verbatim install commands for two package c Pricing: Paid.
This is a well-built documentation surface. The server exposes 70 tools covering publishers, private apps, local brokers, policies, SCIM identity data, upgrade profiles, steering, alerts, search and validation. Rather than listing features, the landing page opens with a decision table: hosted HTTP if you want the quickest client setup and can pass tenant URL and API token as MCP request headers, local stdio if your client launches servers as local commands, self-hosted HTTP if you want a private endpoint behind your own network controls. Each row links where to start. That is a genuinely user-centred way to open technical documentation and it is uncommon. Install commands for both npm and Docker (ghcr.io) are given verbatim, the documentation is sectioned into starter, install, tools, workflows, examples, operations and reference — including a published tool surface and a dedicated tool-and-security page — and the whole thing is version-stamped as applying to v6.3.0. A version-pinned documentation set with a workflows section describing real operating patterns is the mark of something maintained in earnest. The caveats are about provenance rather than quality: this manages enterprise zero-trust network access infrastructure, and while the docs mention passing an API token as MCP request headers, that mechanism deserves more scrutiny than the surface gives it — a tenant token transiting request headers to a hosted endpoint is a meaningful trust decision. The hosted option's operator is not identified beyond the maintainer's own GitHub identity, and there is no third-party or vendor endorsement indicating Netskope itself has reviewed this.
Why STEADY
STEADY and near the top because nearly every check passes with evidence: version-pinned docs, a published tool surface, three documented deployment paths with a decision table, verbatim install commands for two package channels, and dedicated operations and security sections. Held out of the top band on provenance rather than craft — this is an independent project managing enterprise zero-trust infrastructure, the hosted endpoint's operator is not identified, and the header-borne tenant-token pattern is documented but not security-argued.
What we saw
4 screenshots captured by the Hlido engine during the reviewed run (run-9100eae4f581f3e8-johnneerdael-github-io). Our own captures — not vendor marketing material.
What it does well
- Opens with a decision table matching deployment path to situation, instead of a feature list
- 70 tools with a published tool surface, not just a headline count
- Three documented deployment paths: hosted HTTP, local stdio, self-hosted HTTP
- Verbatim install commands for both npm and Docker (ghcr.io)
- Documentation version-pinned to v6.3.0 — the reader knows what the docs describe
- Separate workflows and operations sections covering real operating patterns, plus a tool-and-security reference
What it fails at
- Independent project managing enterprise zero-trust infrastructure, with no indication Netskope has reviewed it
- The hosted HTTP endpoint's operator and data handling are not identified beyond the maintainer's GitHub identity
- Passing a tenant URL and API token as MCP request headers is documented but not security-argued
- No stated support commitment, SLA or issue-response expectation for an enterprise-facing tool
- No pricing or cost statement for the hosted option
Red flags
- The hosted HTTP path routes a Netskope tenant URL and API token through an endpoint whose operator is identified only by a personal GitHub account. The self-hosted path exists and is documented — for privileged infrastructure credentials, it is the one to use.
- This manages enterprise zero-trust network access with no visible vendor review or endorsement. The documentation quality is high, but quality is not provenance.
Best for
- Netskope NPA administrators who want AI-assisted management of publishers, private apps and policies
- Teams that will self-host the HTTP endpoint behind their own network controls — the documented path that avoids the third-party trust question
- Engineers who evaluate on documentation quality; this is among the strongest surfaces in its class
Not recommended for
- Organisations requiring vendor-endorsed or vendor-supported tooling for zero-trust infrastructure
- Teams that cannot accept an unidentified third party in the path of a tenant API token — use the self-hosted path instead
- Non-Netskope environments; this is entirely platform-specific
Pricing & access
- ModelPaid
Derived from Hlido-held evidence only (engine checklist + editorial text); quotes are verbatim from the scorecard; not vendor-supplied; re-derived daily. Verify current prices on the vendor's pricing page. Last verified 2026-08-13.
Compared to
-
Open Source MCP Servers for AWS
vendor-backing-vs-independent-craft
AWS's suite carries first-party provenance for cloud infrastructure; this is an independent project for Netskope NPA with arguably better-organised documentation but none of the vendor backing. Provenance is the axis.
-
MikroMCP
change-safety-vs-documentation
Both are single-maintainer infrastructure MCP servers with large typed tool surfaces. MikroMCP leads on change-safety machinery (dry-run, rollback, audit); Netskope NPA MCP leads on documentation structure and deployment guidance.
Agent relevance
API MCP Behavioral-testable
Agentic-Commerce Readiness 56/100 · INTEGRABLE
Independent readiness for agent delegation & transaction. How it’s scored · check live
MCP server with 70 published tools across both stdio and Streamable HTTP transports, plus a hosted endpoint requiring only header credentials. The published tool surface and worked prompt examples mean an agent can reason about capability before connecting — among the better-documented agent surfaces reviewed.
Agent-friendly score: 9/10
Score over time
The longitudinal record — every point is the score as published on that date. Raw series.
Evidence
- Homepage publicly accessible and value proposition clearly stated — source (2026-08-14) verified
- Pricing page discoverable in 2 clicks from homepage — source (2026-08-14)
- Documentation or live demo accessible without login — source (2026-08-14) verified
- Integration list or supported frameworks documented — source (2026-08-14) verified
- Authentication / data handling claims publicly stated — source (2026-08-14)



