{"name":"io.github.AIops-tools/identity-aiops","slug":"aiops-tools-identity-aiops","title":"Identity AIops","description":"Governed Keycloak + authentik identity ops: users, events, clients, MFA, RCA. 29 tools.","url":"https://mcp.market/server/aiops-tools-identity-aiops","rating":null,"grade":"A","score":91,"certified":false,"status":"active","category":"other","tags":[],"presence":{"score":29,"stars":0,"forks":0,"downloads_week":755,"last_push_at":"2026-09-16T23:27:14.000Z","license":"MIT"},"uptime":null,"claimed":false,"transport":"pypi","callable_via_gateway":false,"default_price_micros":0,"repository":"https://github.com/AIops-tools/Identity-AIops","website":null,"version":"0.8.5","remotes":[],"packages":[{"registryType":"pypi","identifier":"identity-aiops","version":"0.8.5","transport":{"type":"stdio"}}],"tools":[{"name":"admin_events","description":"[READ] Recent admin/config-change events (who changed what, from where).","write_action":false,"price_micros":0,"input_schema":null},{"name":"client_detail","description":"[READ] One client's normalized detail by internal id.","write_action":false,"price_micros":0,"input_schema":null},{"name":"client_misconfig_audit","description":"[READ] Ranked OAuth/OIDC client risk: wildcard/http redirect URIs, public clients with secrets, implicit flow, missing PKCE, password grant — per-client riskScore with evidence and actions.","write_action":false,"price_micros":0,"input_schema":null},{"name":"client_session_stats","description":"[READ] Active-session counts per client, busiest first (Keycloak).","write_action":false,"price_micros":0,"input_schema":null},{"name":"client_sessions","description":"[READ] Active user sessions on one client (Keycloak).","write_action":false,"price_micros":0,"input_schema":null},{"name":"disable_user","description":"[WRITE][risk=medium] Disable a user (blocks sign-in); reversible.","write_action":false,"price_micros":0,"input_schema":null},{"name":"enable_user","description":"[WRITE][risk=high] Re-enable a user (restores sign-in); reversible.","write_action":false,"price_micros":0,"input_schema":null},{"name":"group_members","description":"[READ] Members of one group, normalized user rows.","write_action":false,"price_micros":0,"input_schema":null},{"name":"identity_overview","description":"[READ] One-shot summary: platform/realm, user/client/IdP counts, and the size of the recent failed-login feed. Lead with this.","write_action":false,"price_micros":0,"input_schema":null},{"name":"list_clients","description":"[READ] OAuth/OIDC clients in the realm, normalized (redirect URIs, public/confidential, grant flags, PKCE method).","write_action":false,"price_micros":0,"input_schema":null},{"name":"list_groups","description":"[READ] Groups in the realm.","write_action":false,"price_micros":0,"input_schema":null},{"name":"list_identity_providers","description":"[READ] Federated identity providers / sources configured on the IdP.","write_action":false,"price_micros":0,"input_schema":null},{"name":"list_users","description":"[READ] Users in the realm, normalized across Keycloak/authentik.","write_action":false,"price_micros":0,"input_schema":null},{"name":"login_events","description":"[READ] Recent authentication events, normalized (time/type/user/ip/client/error).","write_action":false,"price_micros":0,"input_schema":null},{"name":"login_failure_rca","description":"[READ] RCA over the failed-auth feed: separates brute-force (spray or targeted) from a misconfigured client from an expired-credential storm and a lockout storm — each finding carries its numbers, cause, and action.","write_action":false,"price_micros":0,"input_schema":null},{"name":"main","description":"Run the MCP server over stdio.","write_action":true,"price_micros":0,"input_schema":null},{"name":"mfa_coverage_analysis","description":"[READ] Second-factor coverage: overall %, the users without MFA, and the factor types counted. Pulls one credential list per user (bounded).","write_action":false,"price_micros":0,"input_schema":null},{"name":"realm_info","description":"[READ] Realm / instance settings relevant to identity hygiene (brute-force protection, password policy, OTP policy, registration).","write_action":false,"price_micros":0,"input_schema":null},{"name":"require_password_reset","description":"[WRITE][risk=medium] Require a password reset at next sign-in (Keycloak required actions); reversible — the undo clears the flag only if this call set it. Pass clear=True to remove a pending requirement instead.","write_action":false,"price_micros":0,"input_schema":null},{"name":"revoke_user_sessions","description":"[WRITE][risk=medium] Revoke ALL of a user's sessions. IRREVERSIBLE — no undo; the prior session count is recorded (audit shows the blast radius).","write_action":false,"price_micros":0,"input_schema":null},{"name":"rotate_client_secret","description":"[WRITE][risk=high] Rotate a client's secret. IRREVERSIBLE — the old secret is invalidated; only masked fingerprints are recorded/returned, never the value.","write_action":false,"price_micros":0,"input_schema":null},{"name":"stale_access_audit","description":"[READ] Dormant-access audit: enabled users idle > N days, accounts that never signed in, service accounts with interactive logins, and sessions orphaned by disabled/unknown users.","write_action":false,"price_micros":0,"input_schema":null},{"name":"undo_apply","description":"[WRITE][risk=medium] Apply a recorded undo by dispatching its inverse tool.","write_action":false,"price_micros":0,"input_schema":null},{"name":"undo_list","description":"[READ] List recorded, not-yet-applied undo tokens (most recent first).","write_action":false,"price_micros":0,"input_schema":null},{"name":"update_client_redirect_uris","description":"[WRITE][risk=high] REPLACE a client's redirect-URI list; reversible — the prior list is captured and the undo replays it.","write_action":true,"price_micros":0,"input_schema":null},{"name":"user_count","description":"[READ] Total user count in the realm (the cheap health probe).","write_action":false,"price_micros":0,"input_schema":null},{"name":"user_credentials","description":"[READ] A user's configured credentials/authenticators — the MFA surface.","write_action":false,"price_micros":0,"input_schema":null},{"name":"user_detail","description":"[READ] One user's full detail (enabled state, required actions, attributes).","write_action":false,"price_micros":0,"input_schema":null},{"name":"user_lockout_status","description":"[READ] Brute-force lockout status for one user (Keycloak attack-detection).","write_action":false,"price_micros":0,"input_schema":null},{"name":"user_sessions","description":"[READ] A user's active sessions (id, IP, start/last access, clients).","write_action":false,"price_micros":0,"input_schema":null}],"scan":{"score":91,"grade":"A","scanned_at":"2026-09-19T19:42:40.141Z","report":{"scannerVersion":"0.1.5","scannedAt":"2026-09-19T19:42:40.087Z","components":{"code":{"score":25,"max":25,"notes":["55 source files scanned"]},"reliability":{"score":-1,"max":20,"notes":["no gateway calls yet and no remote to probe"]},"poisoning":{"score":-1,"max":15,"notes":["tools not inspected (local package is not executed); not counted"]},"auth":{"score":12,"max":15,"notes":["local package, no credentials required"]},"maintenance":{"score":15,"max":15,"notes":["last push 3 days ago"]},"identity":{"score":7,"max":10,"notes":["registry namespace matches repository owner"]}},"findings":[],"inputs":{"packages":[{"registryType":"pypi","identifier":"identity-aiops","version":"0.8.5","found":true,"license":"MIT","dependencyCount":6,"publishedAt":"2026-09-16T23:25:09.983025Z"}],"repo":{"found":true,"owner":"AIops-tools","repo":"Identity-AIops","archived":false,"pushedAt":"2026-09-16T23:27:14Z","stars":0,"forks":0,"openIssues":0,"ownerType":"Organization","ownerAvatarUrl":"https://avatars.githubusercontent.com/u/295714335?v=4","ownerCreatedAt":"2026-06-22T02:46:57Z","license":"MIT"},"icon":{"url":null,"source":"none"},"presence":{"stars":0,"forks":0,"downloadsWeek":755,"license":"MIT","lastPushAt":"2026-09-16T23:27:14.000Z","score":29}}}},"grade_history":[],"reviews":[]}