Netskope NPA MCP

Infrastructure · tested 2026-08-14 · by the Hlido desk, not the vendor

In short: Seventy tools for Netskope Private Access with three documented deployment paths and a decision table telling you which to pick — enterprise-grade documentation from what appears to be an independent maintainer.

Quick answer

Netskope NPA MCP scores 80/100 (STEADY) on Hlido’s independent, hands-on test (reviewed 2026-08-14). STEADY and near the top because nearly every check passes with evidence: version-pinned docs, a published tool surface, three documented deployment paths with a decision table, verbatim install commands for two package c Pricing: Paid.

This is a well-built documentation surface. The server exposes 70 tools covering publishers, private apps, local brokers, policies, SCIM identity data, upgrade profiles, steering, alerts, search and validation. Rather than listing features, the landing page opens with a decision table: hosted HTTP if you want the quickest client setup and can pass tenant URL and API token as MCP request headers, local stdio if your client launches servers as local commands, self-hosted HTTP if you want a private endpoint behind your own network controls. Each row links where to start. That is a genuinely user-centred way to open technical documentation and it is uncommon. Install commands for both npm and Docker (ghcr.io) are given verbatim, the documentation is sectioned into starter, install, tools, workflows, examples, operations and reference — including a published tool surface and a dedicated tool-and-security page — and the whole thing is version-stamped as applying to v6.3.0. A version-pinned documentation set with a workflows section describing real operating patterns is the mark of something maintained in earnest. The caveats are about provenance rather than quality: this manages enterprise zero-trust network access infrastructure, and while the docs mention passing an API token as MCP request headers, that mechanism deserves more scrutiny than the surface gives it — a tenant token transiting request headers to a hosted endpoint is a meaningful trust decision. The hosted option's operator is not identified beyond the maintainer's own GitHub identity, and there is no third-party or vendor endorsement indicating Netskope itself has reviewed this.

Why STEADY

STEADY and near the top because nearly every check passes with evidence: version-pinned docs, a published tool surface, three documented deployment paths with a decision table, verbatim install commands for two package channels, and dedicated operations and security sections. Held out of the top band on provenance rather than craft — this is an independent project managing enterprise zero-trust infrastructure, the hosted endpoint's operator is not identified, and the header-borne tenant-token pattern is documented but not security-argued.

What we saw

4 screenshots captured by the Hlido engine during the reviewed run (run-9100eae4f581f3e8-johnneerdael-github-io). Our own captures — not vendor marketing material.

Netskope NPA MCP — run screenshot 1 (home.png)
home.png
Netskope NPA MCP — run screenshot 2 (page_.png)
page_.png
Netskope NPA MCP — run screenshot 3 (pagestarter_.png)
pagestarter_.png
Netskope NPA MCP — run screenshot 4 (pageinstall_.png)
pageinstall_.png

What it does well

What it fails at

Red flags

Best for

  • Netskope NPA administrators who want AI-assisted management of publishers, private apps and policies
  • Teams that will self-host the HTTP endpoint behind their own network controls — the documented path that avoids the third-party trust question
  • Engineers who evaluate on documentation quality; this is among the strongest surfaces in its class

Not recommended for

  • Organisations requiring vendor-endorsed or vendor-supported tooling for zero-trust infrastructure
  • Teams that cannot accept an unidentified third party in the path of a tenant API token — use the self-hosted path instead
  • Non-Netskope environments; this is entirely platform-specific

Pricing & access

Derived from Hlido-held evidence only (engine checklist + editorial text); quotes are verbatim from the scorecard; not vendor-supplied; re-derived daily. Verify current prices on the vendor's pricing page. Last verified 2026-08-13.

Compared to

Agent relevance

API MCP Behavioral-testable

Agentic-Commerce Readiness 56/100 · INTEGRABLE

Independent readiness for agent delegation & transaction. How it’s scored · check live

MCP server with 70 published tools across both stdio and Streamable HTTP transports, plus a hosted endpoint requiring only header credentials. The published tool surface and worked prompt examples mean an agent can reason about capability before connecting — among the better-documented agent surfaces reviewed.

Agent-friendly score: 9/10

Evidence

scorecard.json · transparency passport · registry · methodology

More: compare agents · best of · developer tools · incident registry

Verdict by Hlido Editor, our automated editorial system · Method: public-surface-tier-2+editorial-narrative-v2 · Methodology version 2026.08 ·

How this page was produced. The scores, claim verdicts and evidence come from automated hands-on testing of the product’s public surface. The written analysis is drafted by an AI system, and pages publish without a person reviewing each one. Hlido publishes this record and answers for it — tell us if anything here is wrong and we will correct it.

Embed this trust badge

Hlido trust score

Live, always-current independent score — free to embed on your site or README. No vendor pays for placement.

Markdown

[![Hlido trust score](https://hlido.eu/badge/johnneerdael-netskope-mcp.svg)](https://hlido.eu/check/?agent=johnneerdael-netskope-mcp)

HTML

<a href="https://hlido.eu/check/?agent=johnneerdael-netskope-mcp"><img src="https://hlido.eu/badge/johnneerdael-netskope-mcp.svg" alt="Hlido trust score"></a>