Skip to main content

← All Hack Day tracks

Main Hack · MCP Server

In this hack we are asking you to extend an MCP server with tools to solve a business use case.

The Model Context Protocol (MCP) is an open standard for connecting AI clients to outside systems: rather than hard-coding an integration into a single assistant, you expose your capabilities as tools on an MCP server, and any MCP-capable client can discover and call them.

Each tool is a named function with a typed input schema — the model decides when to call it, your server handles authentication and talks to the real API, and the JSON that comes back is turned into a natural-language answer.

Here that means wrapping SailPoint APIs so someone can ask a question in plain language and get identity data back without ever opening the UI.

How to get started​

Work through the steps in order. This guide gets you up and running with the essentials, and you'll expand from there.

1. Clone the template​

Choose your preferred language and clone that repository.

git clone git@github.com:sailpoint-oss/python-mcp-server-template.git

Here's what comes out of the box to get you started:

  • Authentication to SailPoint handled via personal access token and the SDK
  • A foundational MCP server with copyable tool templates

2. Pick your AI client​

The examples in each repository use Claude as their example client for interacting with the MCP server. You can use any AI client that supports MCP connections.

3. Generate your Personal Access Token​

When you registered for Hack Day you should have received a demo tenant. Log in to the tenant with the credentials provided to you.

  1. Select the User icon from the upper-right corner of the page.

  2. From the dropdown menu, select Preferences.

  3. Select Personal Access Tokens from the left menu and select New Token.

  4. Set an expiration date for the personal access token. By default, the expiration date is set for 6 months. If this field is left blank, the token is created with no expiration date.

  5. Select the Other / No associated vendor integration checkbox.

  6. Select sp:scopes:all to authorize the personal access token to all scopes granted by the user’s assigned user level.

warning

Copy and save the Secret value before you close this panel. Otherwise, you will have to delete the token and create a new one since this value cannot be retrieved later.

  1. Save the Secret value somewhere safe.

See Generating a personal access token for the full walkthrough.

4. Configure the MCP server​

Everything you need is below — open the tab for the language you cloned.

Install the dependencies

cd python-mcp-server-template

python3 -m venv .venv
source .venv/bin/activate
pip install -e ".[dev]"

Add your credentials

Copy the example file, fill in the three values, and make the file readable only by you:

cp .env.example .env
chmod 600 .env
SAIL_BASE_URL=https://your-tenant.api.identitynow.com
SAIL_CLIENT_ID=...
SAIL_CLIENT_SECRET=...

The server loads .env from its own project folder, so it works from whatever directory your MCP client starts it in. The file is gitignored. Do not commit it or paste it into a client config.

Verify the credentials before touching an MCP client

python scripts/check_auth.py "<Search String>"

You should see three OK lines and a JSON identity record. If this fails, the problem is your credentials or tenant URL — fix it here, where the error messages are readable.

Register it with the MCP inspector

Use the MCP inspector to build out your tools, verify their output and get them ready for an agent to use.

Run the command to save the config for the MCP inspector on your computer.

cat > mcp-inspector.json <<EOF
{
"mcpServers": {
"sailpoint": {
"command": "$(pwd)/.venv/bin/python",
"args": ["-m", "sailpoint_mcp"]
}
}
}
EOF

From here the steps are the same whichever language you chose.

Run the following command in your terminal, passing in your configuration and your preferred server name:

npx @modelcontextprotocol/inspector@latest --config mcp-inspector.json --server sailpoint

This opens an MCP inspector instance in your browser. Use the toggle on the servers card to connect.

5. Make an example call​

Once connected, open the Tools tab. You will see the default tool created as a part of this template, search_identities.

Click search_identities in the tools sidebar to open the tool execution window.

Type Adam Kennedy into the query input and click Execute Tool.

You will see the result from the MCP server that an agent would use when answering your question.

6. Build​

Now that you have the full picture, build a tool or a set of tools that solves a real-world problem. What you build should:

  • Leverage SailPoint APIs to provide actionable insights or data
  • Be small, self-contained, and functional
  • Demonstrate a clear and intentional use case

Connect it to an AI agent​

The inspector is for building and testing your tools. Once they behave the way you want, point a real agent at the server. Every platform below launches a local stdio server from the same command and args pair you already put in mcp-inspector.json, so that file is your template.

  • Claude Code — register from the terminal with claude mcp add sailpoint -- <command> <args>, or commit a .mcp.json to share the server with your team.
  • Claude Desktop — add the server to claude_desktop_config.json, then restart the app.
  • Cursor — .cursor/mcp.json for a single project, or ~/.cursor/mcp.json to make the server available everywhere.
  • VS Code — .vscode/mcp.json for the workspace, used by Copilot's agent mode.
  • ChatGPT — Settings → MCP servers → Add server, choosing STDIO. The desktop app, Codex CLI, and IDE extension share this configuration.
note

ChatGPT on the web only accepts remote servers over HTTPS and rejects localhost, so use the desktop app or Codex CLI for the local server you just built.

Whichever you pick, use absolute paths — the agent does not run from your project directory. You do not need an env block: the server reads SAIL_BASE_URL, SAIL_CLIENT_ID, and SAIL_CLIENT_SECRET from the .env in its project folder. If a platform does set those variables, its values take precedence over .env.