Snipe-ITCAUTION
MCP server for Snipe-IT asset management. Enables AI assistants to manage assets, consumables, accessories, licenses, users, and system configuration via 39 comprehensive tools.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A comprehensive Model Context Protocol (MCP) server for managing Snipe-IT inventory systems. This server enables AI assistants to perform full CRUD operations across your entire Snipe-IT instance with 40 tools covering all major API endpoints.
Features
Asset Management
- Full CRUD Operations: Create, read, update, delete, and search assets with enhanced filtering
- Barcode/Serial Lookup: Direct bytag/byserial API endpoints for reliable barcode scanning
- Asset Operations: Checkout, checkin, audit, and restore assets
- Checkout Requests: Submit and cancel checkout requests for requestable assets
- File Attachments: Upload, download, list, and delete asset files
- Label Generation: Generate printable PDF labels
- Maintenance Tracking: Create and manage maintenance records
- License Associations: View licenses assigned to assets
Inventory Tracking
- Consumables: Complete management of consumable items
- Components: Manage components with checkout/checkin to assets
- Accessories: Track accessories with checkout/checkin to users, assets, or locations
Users & Organization
- Users: Full user management including restore and current user endpoint
- User Assets: View all items checked out to a user (assets, accessories, licenses, consumables, EULAs)
- Two-Factor Auth: Reset user 2FA (admin function)
- Companies: Multi-tenant company management
- Departments: Organizational department management
- Groups: Permission group management
System Configuration
- Categories: Manage categories for all item types
- Manufacturers: Track manufacturer information
- Models: Define asset models with depreciation, custom fields, and file attachments
- Status Labels: Configure asset statuses with asset listing
- Locations: Manage physical locations with hierarchy, asset/user queries
- **Supplie
64cdcce0204dOBSERVED · 2026-10-09Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add snipeit-mcp --env SNIPEIT_OAUTH_CLIENT_ID=${SNIPEIT_OAUTH_CLIENT_ID} --env SNIPEIT_OAUTH_CLIENT_SECRET=${SNIPEIT_OAUTH_CLIENT_SECRET} --env SNIPEIT_TOKEN=${SNIPEIT_TOKEN} -- uvx snipeit-mcp{
"mcpServers": {
"snipeit-mcp": {
"command": "uvx",
"args": [
"snipeit-mcp"
],
"env": {
"SNIPEIT_OAUTH_CLIENT_ID": "${SNIPEIT_OAUTH_CLIENT_ID}",
"SNIPEIT_OAUTH_CLIENT_SECRET": "${SNIPEIT_OAUTH_CLIENT_SECRET}",
"SNIPEIT_TOKEN": "${SNIPEIT_TOKEN}"
}
}
}
}Exposed tools (8)
8 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
asset_labels | read | Generate printable labels for assets. |
asset_licenses | read | Get all licenses checked out to an asset. |
audit_tracking | read | Track asset audit status for compliance. |
ldap_operations | read | Manage LDAP synchronization. |
status_summary | read | Get asset counts grouped by status label. |
system_info | read | Get Snipe-IT system information. |
user_assets | read | Get items checked out to a user. |
user_two_factor | read | Manage user two-factor authentication. |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (12 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (5)
probe_url="http://127.0.0.1:${MCP_PORT}/.well-known/oauth-authorization-server"probe_url="http://127.0.0.1:${probe_port}/.well-known/oauth-authorization-server"url = f"http://127.0.0.1:{port}/mcp"url = f"http://127.0.0.1:{port}/mcp"response = await http.get(f"http://127.0.0.1:{port}/healthz")Gates applied: no_behavioural_pass.
64cdcce0204dfull audit observations/trust-audit/mcp-server/jameshgordy__snipe-it-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 64cdcce0204d | CAUTION | B | 89 | first audit |
Questions
What is the Snipe-IT MCP server?
MCP server for Snipe-IT asset management. Enables AI assistants to manage assets, consumables, accessories, licenses, users, and system configuration via 39 comprehensive tools.
What tools does Snipe-IT expose?
8 in total: 8 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Snipe-IT safe to connect to an agent?
With care. The audit graded it B (89/100) and found 5 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Snipe-IT need?
It reads SNIPEIT_OAUTH_CLIENT_ID, SNIPEIT_OAUTH_CLIENT_SECRET and SNIPEIT_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Snipe-IT run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on PyPI as snipeit-mcp.
How current is this page?
The grade is for one exact copy of the source (64cdcce0204d), read on 2026-10-09. The repository is watched and re-audited when it changes.