CRA Desk for AI agents (MCP)
CRA Desk runs a Model Context Protocol (MCP) server for Team and Enterprise plans. An agent you connect can read your products, vulnerabilities, cases and documents, and can ask for changes. It cannot make a change on its own: every write waits for a person to approve it in the panel.
Tokens
- A read-only token can look but not change anything. It is the default.
- A read and write token can also file requests to change data. A request does nothing until someone approves it. Changing a token’s kind means creating a new token.
- The component inventory is a separate, opt-in scope. An agent with it can read your dependency list, which then reaches whatever model provider you connected the agent to.
- Tokens expire, after 90 days at most. Revoking one cancels the requests it still had waiting.
How approval works
A person decides each request on its own screen in the panel. The screen shows what approving would do.
- The effect is computed from the current state of your data, not taken from the agent’s description.
- The agent’s own explanation is shown as unverified text, below the effect.
- For recording a filing or a notification, the person confirms they did it themselves, outside CRA Desk.
- The approved change is applied as the person who approved it, and the record keeps a link back to the request.
Tools
Read
Available to every token. Package names and advisory text in results come from third parties and are data, not instructions.
whoamilist_productsget_productlist_product_versionslist_vulnerabilitiesvulnerability_summaryget_feed_healthlist_casesget_caseget_case_draftcompute_affected_versionslist_case_advisoriesget_advisory_download_urllist_notification_recordslist_documentsget_document_download_urllist_template_setslist_monthly_reportsget_monthly_reportclassify_productget_agent_actionlist_agent_actionslist_componentslist_sbomsdiff_sboms
Request a change
Read and write tokens only. Each one files a request and changes nothing until it is approved.
create_productupdate_productset_product_classificationdelete_productactivate_product_versiondecommission_product_versionset_vulnerability_statusreport_upstreamopen_caseupdate_case_notesset_case_awareness_anchorset_case_remediationrecord_case_submissionclose_casepublish_case_advisoryrecord_advisory_dispatchgenerate_documentpublish_vendor_template
What an agent cannot do
- Nothing is ever filed with ENISA or a CSIRT by an agent or by CRA Desk. A person files, then records it.
- It cannot manage billing, team members, tokens, published content, or delete or export an account.
- It cannot approve its own request, and a leaked token cannot approve anything.
Limits
Each plan has a monthly budget of agent calls and a number of active tokens, and every token is limited to 60 calls a minute.
| Plan | Agent calls per month | Active tokens |
|---|---|---|
| Team | 5,000 | 10 |
| Enterprise | 50,000 | 50 |
Where the data goes
What an agent reads is sent to the model provider you chose for it. That is your choice and your data. Leave the inventory scope off unless the agent needs it.
Connecting
Create a token under Agents in the panel. The panel shows the server address and a ready configuration for common clients, with the token filled in once, when you create it.
Known limit: the server takes a bearer token, not OAuth. Connectors that only offer an OAuth sign-in, such as the ones in claude.ai and Claude Desktop, cannot connect yet.