Datto Bcdr Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Datto Bcdr Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Model Context Protocol (MCP) server for the Datto BCDR (Backup Portal) API. Exposes SIRIS / Alto appliances, protected agents, recovery points, screenshot verifications, off-site sync status, alerts, and activity logs to AI assistants.
| Tool | Description |
|---|---|
datto_bcdr_list_devices | List all SIRIS/Alto appliances in the partner portal |
datto_bcdr_get_device | Get appliance details by serialNumber |
datto_bcdr_list_assets | List protected agents on an appliance |
datto_bcdr_get_asset | Get a specific protected agent |
datto_bcdr_list_backups | List recovery points for an agent |
datto_bcdr_list_screenshots | List screenshot verifications for an agent |
datto_bcdr_get_screenshot | Fetch a screenshot PNG (returned as base64 image content) |
datto_bcdr_get_offsite_status | Off-site sync status for an appliance |
datto_bcdr_list_alerts | Portal alerts (date-range filtered) |
datto_bcdr_list_activity | Activity log (date-range filtered) |
When the user omits required filters (date range, serial number, etc.) the server uses MCP elicitation to prompt for them.
| Variable | Required | Description |
|---|---|---|
DATTO_BCDR_PUBLIC_KEY | yes | Datto BCDR partner portal public key |
DATTO_BCDR_PRIVATE_KEY | yes | Datto BCDR partner portal private key (secret) |
DATTO_BCDR_REGION | no | us (default) or eu |
MCP_TRANSPORT | no | stdio (default) or http |
MCP_HTTP_PORT | no | HTTP listen port (default 8080) |
AUTH_MODE | no | env (default) or gateway |
When deployed behind the WYRE MCP Gateway, set AUTH_MODE=gateway and the server will read credentials from per-request HTTP headers:
X-Datto-BCDR-Public-KeyX-Datto-BCDR-Private-KeyX-Datto-BCDR-Region (optional)Each request creates a fresh server instance with isolated credentials — no cross-tenant process.env pollution.
npm install
npm run build
DATTO_BCDR_PUBLIC_KEY=... DATTO_BCDR_PRIVATE_KEY=... npm startRun as HTTP for testing:
MCP_TRANSPORT=http npm start
curl http://localhost:8080/healthdocker build -t datto-bcdr-mcp .
docker run --rm -p 8080:8080 \
-e DATTO_BCDR_PUBLIC_KEY=... \
-e DATTO_BCDR_PRIVATE_KEY=... \
datto-bcdr-mcpApache-2.0
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.