Main Hack · MCP Server
In this hack we are asking you to extend an MCP server with tools to solve a business use case.
The Model Context Protocol (MCP) is an open standard for connecting AI clients to outside systems: rather than hard-coding an integration into a single assistant, you expose your capabilities as tools on an MCP server, and any MCP-capable client can discover and call them.
Each tool is a named function with a typed input schema — the model decides when to call it, your server handles authentication and talks to the real API, and the JSON that comes back is turned into a natural-language answer.
Here that means wrapping SailPoint APIs so someone can ask a question in plain language and get identity data back without ever opening the UI.
How to get started
Work through the steps in order. This guide gets you up and running with the essentials, and you'll expand from there.
1. Clone the template
Choose your preferred language and clone that repository.
- Python
- TypeScript
- GoLang
git clone git@github.com:sailpoint-oss/python-mcp-server-template.git
git clone git@github.com:sailpoint-oss/typescript-mcp-server-template.git
git clone git@github.com:sailpoint-oss/golang-mcp-server-template.git
Here's what comes out of the box to get you started:
- Authentication to SailPoint handled via personal access token and the SDK
- A foundational MCP server with copyable tool templates
2. Pick your AI client
The examples in each repository use Claude as their example client for interacting with the MCP server. You can use any AI client that supports MCP connections.
3. Generate your Personal Access Token
When you registered for Hack Day you should have received a demo tenant. Log in to the tenant with the credentials provided to you.
-
Select the User icon from the upper-right corner of the page.
-
From the dropdown menu, select Preferences.
-
Select Personal Access Tokens from the left menu and select New Token.
-
Set an expiration date for the personal access token. By default, the expiration date is set for 6 months. If this field is left blank, the token is created with no expiration date.
-
Select the Other / No associated vendor integration checkbox.
-
Select sp:scopes:all to authorize the personal access token to all scopes granted by the user’s assigned user level.
Copy and save the Secret value before you close this panel. Otherwise, you will have to delete the token and create a new one since this value cannot be retrieved later.
- Save the Secret value somewhere safe.
See Generating a personal access token for the full walkthrough.
4. Configure the MCP server
Everything you need is below — open the tab for the language you cloned.
- Python
- TypeScript
- GoLang
Install the dependencies
- macOS / Linux
- Windows (PowerShell)
cd python-mcp-server-template
python3 -m venv .venv
source .venv/bin/activate
pip install -e ".[dev]"
cd python-mcp-server-template
python -m venv .venv
.venv\Scripts\Activate.ps1
pip install -e ".[dev]"
Add your credentials
Copy the example file, fill in the three values, and make the file readable only by you:
- macOS / Linux
- Windows (PowerShell)
cp .env.example .env
chmod 600 .env
Copy-Item .env.example .env
Keep the project inside your user folder (for example, C:\Users\<you>\). Files there
are readable only by your account by default.
SAIL_BASE_URL=https://your-tenant.api.identitynow.com
SAIL_CLIENT_ID=...
SAIL_CLIENT_SECRET=...
The server loads .env from its own project folder, so it works from whatever directory your MCP
client starts it in. The file is gitignored. Do not commit it or paste it into a client config.
Verify the credentials before touching an MCP client
python scripts/check_auth.py "<Search String>"
You should see three OK lines and a JSON identity record. If this fails, the problem is your
credentials or tenant URL — fix it here, where the error messages are readable.
Register it with the MCP inspector
Use the MCP inspector to build out your tools, verify their output and get them ready for an agent to use.
Run the command to save the config for the MCP inspector on your computer.
- macOS / Linux
- Windows (PowerShell)
cat > mcp-inspector.json <<EOF
{
"mcpServers": {
"sailpoint": {
"command": "$(pwd)/.venv/bin/python",
"args": ["-m", "sailpoint_mcp"]
}
}
}
EOF
$repoPath = (Get-Location).Path -replace '\\', '\\\\'
@"
{
"mcpServers": {
"sailpoint": {
"command": "$repoPath\\.venv\\Scripts\\python.exe",
"args": ["-m", "sailpoint_mcp"]
}
}
}
"@ | Set-Content mcp-inspector.json
Install and build
cd typescript-mcp-server-template
npm install
npm run build
Add your credentials
Copy the example file, fill in the three values, and make the file readable only by you:
- macOS / Linux
- Windows (PowerShell)
cp .env.example .env
chmod 600 .env
Copy-Item .env.example .env
Keep the project inside your user folder (for example, C:\Users\<you>\). Files there
are readable only by your account by default.
SAIL_BASE_URL=https://your-tenant.api.identitynow.com
SAIL_CLIENT_ID=...
SAIL_CLIENT_SECRET=...
The server loads .env from its own project folder, so it works from whatever directory your MCP
client starts it in. The file is gitignored. Do not commit it or paste it into a client config.
Verify the credentials before touching an MCP client
node smoke.js
This does a handshake, lists the tools, and makes one live search_identities call. If it fails,
the problem is your credentials or tenant URL — fix it here, where the error messages are readable.
Register it with the MCP inspector
Use the MCP inspector to build out your tools, verify their output and get them ready for an agent to use.
Run the command to save the config for the MCP inspector on your computer.
- macOS / Linux
- Windows (PowerShell)
cat > mcp-inspector.json <<EOF
{
"mcpServers": {
"sailpoint": {
"command": "node",
"args": ["$(pwd)/dist/index.js"]
}
}
}
EOF
$repoPath = (Get-Location).Path -replace '\\', '\\\\'
@"
{
"mcpServers": {
"sailpoint": {
"command": "node",
"args": ["$repoPath\\dist\\index.js"]
}
}
}
"@ | Set-Content mcp-inspector.json
Build it
Requires Go 1.25+.
cd golang-mcp-server-template
make build # -> bin/sailpoint-mcp-server
Add your credentials
Copy the example file, fill in the three values, and make the file readable only by you:
- macOS / Linux
- Windows (PowerShell)
cp .env.example .env
chmod 600 .env
Copy-Item .env.example .env
Keep the project inside your user folder (for example, C:\Users\<you>\). Files there
are readable only by your account by default.
SAIL_BASE_URL=https://your-tenant.api.identitynow.com
SAIL_CLIENT_ID=...
SAIL_CLIENT_SECRET=...
The server loads .env from its own project folder, so it works from whatever directory your MCP
client starts it in. The file is gitignored. Do not commit it or paste it into a client config.
The server validates the resolved base URL, client ID, client secret and token URL at startup and exits with a descriptive message if any are missing, rather than failing on the first tool call.
Verify the credentials before touching an MCP client
make smoke
This does a handshake, lists the tools, and makes one live search_identities call. If it fails,
the problem is your credentials or tenant URL — fix it here, where the error messages are readable.
Register it with the MCP inspector
Use the MCP inspector to build out your tools, verify their output and get them ready for an agent to use.
Run the command to save the config for the MCP inspector on your computer.
- macOS / Linux
- Windows (PowerShell)
cat > mcp-inspector.json <<EOF
{
"mcpServers": {
"sailpoint": {
"command": "$(pwd)/bin/sailpoint-mcp-server"
}
}
}
EOF
$repoPath = (Get-Location).Path -replace '\\', '\\\\'
@"
{
"mcpServers": {
"sailpoint": {
"command": "$repoPath\\bin\\sailpoint-mcp-server.exe"
}
}
}
"@ | Set-Content mcp-inspector.json
From here the steps are the same whichever language you chose.
Run the following command in your terminal, passing in your configuration and your preferred server name:
npx @modelcontextprotocol/inspector@latest --config mcp-inspector.json --server sailpoint
This opens an MCP inspector instance in your browser. Use the toggle on the servers card to connect.
5. Make an example call
Once connected, open the Tools tab. You will see the default tool created as a part of this
template, search_identities.
Click search_identities in the tools sidebar to open the tool execution window.
Type Adam Kennedy into the query input and click Execute Tool.
You will see the result from the MCP server that an agent would use when answering your question.
6. Build
Now that you have the full picture, build a tool or a set of tools that solves a real-world problem. What you build should:
- Leverage SailPoint APIs to provide actionable insights or data
- Be small, self-contained, and functional
- Demonstrate a clear and intentional use case
Connect it to an AI agent
The inspector is for building and testing your tools. Once they behave the way you want, point a
real agent at the server. Every platform below launches a local stdio server from the same
command and args pair you already put in mcp-inspector.json, so that file is your template.
- Claude Code — register from the terminal with
claude mcp add sailpoint -- <command> <args>, or commit a.mcp.jsonto share the server with your team. - Claude Desktop — add the
server to
claude_desktop_config.json, then restart the app. - Cursor —
.cursor/mcp.jsonfor a single project, or~/.cursor/mcp.jsonto make the server available everywhere. - VS Code —
.vscode/mcp.jsonfor the workspace, used by Copilot's agent mode. - ChatGPT — Settings → MCP servers → Add server, choosing STDIO. The desktop app, Codex CLI, and IDE extension share this configuration.
ChatGPT on the web only accepts remote servers over HTTPS and rejects localhost, so use the
desktop app or Codex CLI for the local server you just built.
Whichever you pick, use absolute paths — the agent does not run from your project directory. You
do not need an env block: the server reads SAIL_BASE_URL, SAIL_CLIENT_ID, and
SAIL_CLIENT_SECRET from the .env in its project folder. If a platform does set those variables,
its values take precedence over .env.