com.bluecat/integritymcp
Runs onlineNo credentials listedUpdated 2026-09-24
com.bluecat/integritymcp · Registry status: active
At a glance
BlueCat Integrity MCP Server (formerly bammcp)
Vendor's own description, untranslated and unverified
- Execution location
- Runs online
- Required secrets declared
- No credentials listed
- Declared version and change
26.1.0· Source-reported change date 2026-09-24- Configuration
- can be built from the disclosed start template
Inspect connection paths and prerequisites
Related categories
- MCP servers without declared required secrets35,800
- Remotely executed MCP servers24,811
- MCP servers without a repository URL11,760
- MCP servers over streamable-http only23,554
- MCP servers as a container only702
- Remote MCP servers without a repository URL10,856
6 of 7 categories. All categories in the segment catalogue
What this entry shares with others
Same namespace: com.bluecat
Page last changed:
Sources and collection
- Runs
- Runs online
- Credentials
- No credentials listed
- Registry record changed
- 2026-09-24
- Setup
- Template available
- Registry name
com.bluecat/integritymcp- Package coordinate
oci:quay.io/bluecat/integritymcp@sha256:1b38c5fc9321ced181e414b82873a705a46b80c28209227e39fea4578e7a3a0d- Declared version
26.1.0- Source-reported listing date
- 2026-09-24
- Source-reported change date
- 2026-09-24
- First seen by tracevero
- 2026-09-25
Evidence for this page · Source: MCP-Register · collected on 2026-09-25
Every value below comes from it. Where one differs, its origin is stated on its row. What the confidence levels mean
Measured values
| Required secrets declared | No credentials listed no Original data – Required secret variables (raw): confirmed absent Original data – Required secret headers (raw): confirmed absent Source: MCP-Register · collected on 2026-09-25 · derived |
|---|---|
| Execution location | Runs online remote Original data – Transports (raw): streamable-http Source: MCP-Register · collected on 2026-09-25 · derived |
| Path argument present | no Original data – Path arguments (raw): confirmed absent Original data – Path environment variables (raw): confirmed absent Source: MCP-Register · collected on 2026-09-25 · derived |
| Repository URL listed | No repository declared no Original data – Repository (raw): confirmed absent Source: MCP-Register · collected on 2026-09-25 · derived |
| Declared version | 26.1.0 Source: MCP-Register · collected on 2026-09-25 · self-declared |
What is measured is what a manifest declares, not what a piece of software does. This registry fetches no repository URL, no endpoint and no package index; nothing here is verified. Which value comes from which source, and by which rule it was formed, is set out in the Methodology.
Source data25
All 25 values in this block: self-declared.
| Description (raw) | BlueCat Integrity MCP Server (formerly bammcp) |
|---|---|
| Environment variables (raw) | BAM_BASE_URL, BAM_USERNAME, BAM_PASSWORD, BAM_SSO_USERNAME, BAM_SSO_PASSWORD, MCP_AUTH_MODE, MCP_API_KEY, MCP_REQUEST_STATE_KEY, MCP_REQUEST_STATE_KEY_PREVIOUS, MCP_ED25519_PUBLIC_KEY, MCP_SIGNED_KEY_AUDIENCE, MCP_OAUTH_ISSUER, MCP_OAUTH_JWKS_URI, MCP_OAUTH_AUDIENCE, ACCEPT_EULA |
| Required secret variables (raw) | confirmed absent |
| Transports (raw) | streamable-http |
| Path arguments (raw) | confirmed absent |
| Repository (raw) | confirmed absent |
| Package registries (raw) | oci |
| Required secret headers (raw) | confirmed absent |
| Path environment variables (raw) | confirmed absent |
| Remote URLs (raw) | confirmed absent |
| Remote hosts (raw) | confirmed absent |
| Registry status message (raw) | confirmed absent |
| First listed in the registry (raw) | 2026-09-24 |
| Last changed in the registry (raw) | 2026-09-24 |
| Schema version of the raw record (raw) | https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json |
| Delivery form (raw) | package |
| Repository platform (raw) | confirmed absent |
| Repository subfolder (raw) | confirmed absent |
| Package identifiers (raw) | quay.io/bluecat/integritymcp@sha256:1b38c5fc9321ced181e414b82873a705a46b80c28209227e39fea4578e7a3a0d |
| Package versions (raw) | confirmed absent |
| Runtime hints (raw) | docker |
| Environment variable formats (raw) | confirmed absent |
| Environment variable descriptions (raw) | ACCEPT_EULA=Set to Y (or Yes/YES, any casing) to accept the BlueCat End User License Agreement. The container refuses to start without it. · BAM_BASE_URL=BAM base URL (e.g., https://bam.bluecat.com). · BAM_PASSWORD=BAM service-account password. Required alongside BAM_USERNAME, unless the SSO pair is used instead. · BAM_SSO_PASSWORD=BAM SSO password. Required alongside BAM_SSO_USERNAME when using the SSO pair. · BAM_SSO_USERNAME=BAM SSO username. Alternative to BAM_USERNAME + BAM_PASSWORD; the server needs exactly one of the two pairs. · BAM_USERNAME=BAM service-account username. Required unless the SSO pair (BAM_SSO_USERNAME + BAM_SSO_PASSWORD) is used instead — the server needs exactly one of the two pairs. · MCP_API_KEY=Static bearer token clients present as `Authorization: Bearer <key>`. Required only when MCP_AUTH_MODE=static-key. · MCP_AUTH_MODE=Client authentication mode for the /mcp endpoint. One of: none | static-key | signed-key | resource-server. Required at runtime — the server refuses to start without it (no default). · MCP_ED25519_PUBLIC_KEY=Ed25519 public key (base64url) that MCP_AUTH_MODE=signed-key verifies license tokens against. DEFAULTS TO A SHARED DEMO KEY, which authenticates a token holder rather than a customer — every BlueCat-issued token for this server verifies against it. For anything beyond a trial, generate a per-deployment key pair (license-keygen --gen-key) and set this to its public half. · MCP_OAUTH_AUDIENCE=Expected JWT aud claim for MCP_AUTH_MODE=resource-server. A token carrying a different audience, or no aud claim at all, is rejected. Unset skips audience validation entirely. · MCP_OAUTH_ISSUER=Token issuer URL, matched against the iss claim of incoming JWTs. Required when MCP_AUTH_MODE=resource-server — the server refuses to start in that mode without it. · MCP_OAUTH_JWKS_URI=JWKS endpoint whose public keys verify the signature on every incoming Bearer JWT. Required when MCP_AUTH_MODE=resource-server — the server refuses to start in that mode without it. · MCP_REQUEST_STATE_KEY=HMAC key (at least 32 bytes) sealing the approval-gated write tools' requestState on MCP 2026-07-28 connections (#1031). Optional: unset uses a random per-process key, which is fine for a single replica; set the same value on every replica of a multi-replica deployment. · MCP_REQUEST_STATE_KEY_PREVIOUS=Second requestState HMAC key, accepted for opening a sealed plan but never for sealing one: two-key rotation of MCP_REQUEST_STATE_KEY (#1032). Optional, and only valid together with MCP_REQUEST_STATE_KEY. When rolling the key across replicas set this to the old key, and remove it two minutes after the last replica restarted. · MCP_SIGNED_KEY_AUDIENCE=When set, a license token must carry exactly this audience or it is rejected — a declarative scope check on top of the key, so a token minted for another deployment fails even if it verifies. Unset means the aud claim is not checked. Only meaningful with MCP_AUTH_MODE=signed-key. |
| Icon formats (raw) | confirmed absent |
| Connection paths (source structure) | {"packages":[{"registryType":"oci","identifier":"quay.io/bluecat/integritymcp@sha256:1b38c5fc9321ced181e414b82873a705a46b80c28209227e39fea4578e7a3a0d","runtimeHint":"docker","transport":"streamable-http","environment":[{"name":"BAM_BASE_URL","description":"BAM base URL (e.g., https://bam.bluecat.com).","required":true,"secret":false},{"name":"BAM_USERNAME","description":"BAM service-account username. Required unless the SSO pair (BAM_SSO_USERNAME + BAM_SSO_PASSWORD) is used instead — the server needs exactly one of the two pairs.","required":false,"secret":false},{"name":"BAM_PASSWORD","description":"BAM service-account password. Required alongside BAM_USERNAME, unless the SSO pair is used instead.","required":false,"secret":true},{"name":"BAM_SSO_USERNAME","description":"BAM SSO username. Alternative to BAM_USERNAME + BAM_PASSWORD; the server needs exactly one of the two pairs.","required":false,"secret":false},{"name":"BAM_SSO_PASSWORD","description":"BAM SSO password. Required alongside BAM_SSO_USERNAME when using the SSO pair.","required":false,"secret":true},{"name":"MCP_AUTH_MODE","description":"Client authentication mode for the /mcp endpoint. One of: none | static-key | signed-key | resource-server. Required at runtime — the server refuses to start without it (no default).","required":true,"secret":false},{"name":"MCP_API_KEY","description":"Static bearer token clients present as `Authorization: Bearer <key>`. Required only when MCP_AUTH_MODE=static-key.","required":false,"secret":true},{"name":"MCP_REQUEST_STATE_KEY","description":"HMAC key (at least 32 bytes) sealing the approval-gated write tools' requestState on MCP 2026-07-28 connections (#1031). Optional: unset uses a random per-process key, which is fine for a single replica; set the same value on every replica of a multi-replica deployment.","required":false,"secret":true},{"name":"MCP_REQUEST_STATE_KEY_PREVIOUS","description":"Second requestState HMAC key, accepted for opening a sealed plan but never for sealing one: two-key rotation of MCP_REQUEST_STATE_KEY (#1032). Optional, and only valid together with MCP_REQUEST_STATE_KEY. When rolling the key across replicas set this to the old key, and remove it two minutes after the last replica restarted.","required":false,"secret":true},{"name":"MCP_ED25519_PUBLIC_KEY","description":"Ed25519 public key (base64url) that MCP_AUTH_MODE=signed-key verifies license tokens against. DEFAULTS TO A SHARED DEMO KEY, which authenticates a token holder rather than a customer — every BlueCat-issued token for this server verifies against it. For anything beyond a trial, generate a per-deployment key pair (license-keygen --gen-key) and set this to its public half.","required":false,"secret":false},{"name":"MCP_SIGNED_KEY_AUDIENCE","description":"When set, a license token must carry exactly this audience or it is rejected — a declarative scope check on top of the key, so a token minted for another deployment fails even if it verifies. Unset means the aud claim is not checked. Only meaningful with MCP_AUTH_MODE=signed-key.","required":false,"secret":false},{"name":"MCP_OAUTH_ISSUER","description":"Token issuer URL, matched against the iss claim of incoming JWTs. Required when MCP_AUTH_MODE=resource-server — the server refuses to start in that mode without it.","required":false,"secret":false},{"name":"MCP_OAUTH_JWKS_URI","description":"JWKS endpoint whose public keys verify the signature on every incoming Bearer JWT. Required when MCP_AUTH_MODE=resource-server — the server refuses to start in that mode without it.","required":false,"secret":false},{"name":"MCP_OAUTH_AUDIENCE","description":"Expected JWT aud claim for MCP_AUTH_MODE=resource-server. A token carrying a different audience, or no aud claim at all, is rejected. Unset skips audience validation entirely.","required":false,"secret":false},{"name":"ACCEPT_EULA","description":"Set to Y (or Yes/YES, any casing) to accept the BlueCat End User License Agreement. The container refuses to start without it.","required":true,"secret":false}],"additional_arguments_declared":true}],"remotes":[]} |
Embed this badge
Paste this line into a README of your own. The badge states how many values the registry holds for the entry and when it last looked, and it links back to this page.
[](https://tracevero.com/mcp/com-bluecat-integritymcp)
The image is drawn again on every request, so it always reports the current state while the pasted line stays as it is. It carries no rating and no traffic light – only the two measured figures.
Changes
| 2026-09-25 | Declared version: – → 26.1.0 |
|---|---|
| 2026-09-25 | Repository URL listed: – → no |
| 2026-09-25 | Path argument present: – → no |
These are the 3 most recent changes to this entry. Full history
tracevero · https://tracevero.com/mcp/com-bluecat-integritymcp