Connect AI systems to your Commvault environment using the Commvault MCP Server. The server provides secure access to read and manage backup jobs, storage pools, users, plans, and other supported Commvault resources. It follows the Model Context Protocol (MCP) to enable automated visibility, faster decisions, and smoother protection workflows.
The Commvault MCP Server supports the following personas:
-
Backup admins: Monitor job health, check SLAs, query job history, and investigate failed jobs.
-
AI integrators and developers: Connect AI tools securely to Commvault using MCP endpoints and configure integrations such as DocuSign.
-
IT automation teams: Integrate Commvault workflows into other platforms such as ServiceNow.
Use cases
The following examples show common ways to use the Commvault MCP Server; actual use cases might vary by environment and integration.
-
Back up a DocuSign workload: The AI assistant can configure a plan, trigger backups and restores, and set a weekly schedule.
-
Check SLA health: The AI assistant can retrieve SLA data and highlight missed targets.
-
Investigate failed jobs: The AI client runs job analysis and identifies failure causes through Commvault MCP.
-
Create incident tickets: Use ServiceNow and Commvault MCP servers together to create incident tickets through conversational workflows.
Choose a deployment method
You can deploy the Commvault MCP Server using one of the following methods:
-
Use Method 1 (Commvault hosted) when:
-
You need Commvault-native operations for jobs, clients, CommCell information, storage and policies, schedules, users, user groups, and plans.
-
You want streamlined setup through Command Center.
-
You don't require third-party platform integrations.
-
Use Method 2 (Git repository) when you want to extend the server with custom integrations such as DocuSign backup or ServiceNow ticketing integration.
Both methods can run simultaneously in the same environment if you need both Commvault-native and third-party capabilities.
Method 1: Deploy the hosted MCP server
Prerequisites
A Web Server client running Commvault release 11.46.20 or later and having network access to Command Center.
Deploy the MCP service on a Web Server client in your Command Center environment.
-
From the navigation pane, go to Manage > Infrastructure > Servers.
-
Select the Web Server client where you want to host the service.
If your environment has multiple Web Server clients, identify the Command Center endpoint that points to the Web Server client you select. You'll use this endpoint when connecting your AI client.
-
From the Maintenance menu, select Add software.
-
Select the MCP Service package, and then click Install.
-
Wait for the installation job to complete successfully.
Note
You can start using the MCP server as soon as the installation job completes successfully. The MCP Service package might not appear immediately in the Roles list.
After the package installation completes, review the supported tools and configure your AI client to connect to the hosted service.
Supported tools
The Commvault-hosted MCP server provides the following tools for managing and monitoring your Commvault environment.
| Tool | Description |
|---|---|
get_job_detail |
Retrieves complete details for a specified job. |
suspend_job |
Suspends a job, optionally with a reason for the suspension. |
resume_job |
Resumes a previously suspended job. |
resubmit_job |
Resubmits a job to run again. |
kill_job |
Terminates a job immediately. |
get_jobs_list |
Retrieves jobs filtered by type, status, client ID, and lookup window, with pagination support. |
get_failed_jobs |
Retrieves jobs with a failed status within a specified time window. |
get_job_task_details |
Retrieves detailed task information for a specified job. |
get_retention_info_of_a_job |
Retrieves retention information and policies for a specified job. |
create_send_logs_job_for_a_job |
Creates a send-logs job for a specified job and sends the logs by email. |
| Tool | Description |
|---|---|
get_client_group_list |
Retrieves client groups, including the ID, name, and description of each group. |
get_client_list |
Retrieves clients registered in the Commvault environment, including client ID, client name, host name, and operating system type. |
get_client_group_properties |
Retrieves detailed properties for a specified client group. |
get_clientid_from_clientname |
Retrieves the client ID for a specified client name. |
get_subclient_list |
Retrieves subclients for a specified client, identified by client name or ID. |
get_subclient_properties |
Retrieves detailed properties for a specified subclient. |
run_backup_for_subclient |
Runs a backup for a specified subclient. Supported backup types are Full, Incremental, and Synthetic Full. |
| Tool | Description |
|---|---|
get_sla_status |
Retrieves SLA status, including protected, unprotected, and excluded counts and percentages. |
get_security_posture |
Retrieves the security posture of the CommCell, including security checks and their statuses. |
get_security_score |
Retrieves the security posture and calculates the percentage of evaluated security checks that pass. |
get_storage_space_utilization |
Retrieves storage capacity, used space, and savings from compression and deduplication across disk and cloud libraries. |
get_commcell_details |
Retrieves CommCell information, including the name, version, and license information. |
get_entity_counts |
Retrieves counts of entities in the CommCell, including servers, virtual machines, laptops, and users. |
| Tool | Description |
|---|---|
get_storage_policy_list |
Retrieves storage policies configured in the environment. |
get_storage_policy_properties |
Retrieves detailed properties for a specified storage policy. |
get_storage_policy_copy_details |
Retrieves detailed information for a specified storage policy copy. |
get_storage_policy_copy_size |
Retrieves size metrics for a specified storage policy copy. |
get_library_list |
Retrieves storage libraries in the environment. |
get_library_properties |
Retrieves detailed properties for a specified library. |
get_storage_pool_list |
Retrieves storage pools, including capacity and usage information. |
get_mediaagent_list |
Retrieves MediaAgents available in the environment. |
| Tool | Description |
|---|---|
get_schedules_list |
Retrieves backup schedules, including task details and next run times. |
get_schedule_properties |
Retrieves complete properties for a specified schedule. |
enable_schedule |
Enables a schedule so that it can run at its scheduled times. |
disable_schedule |
Disables a schedule to prevent it from running at scheduled times. |
| Tool | Description |
|---|---|
get_users_list |
Retrieves users in the CommCell, including user ID, user name, email address, and enabled status. |
get_user_properties |
Retrieves detailed properties for a specified user. |
set_user_enabled |
Enables or disables a user account. |
get_associated_entities_for_user_or_group |
Retrieves entities, roles, and permissions associated with a specified user or user group. |
view_entity_permissions |
Retrieves the permissions that the current user has for a specified entity type. |
get_roles_list |
Retrieves available roles in the CommCell. |
get_my_user_info |
Retrieves information about the currently authenticated user. |
| Tool | Description |
|---|---|
get_user_groups_list |
Retrieves user groups, including the ID, name, and description of each group. |
get_user_group_properties |
Retrieves detailed properties for a specified user group. |
| Tool | Description |
|---|---|
get_plan_list |
Retrieves plans, with optional filtering for plans that are compatible with S3 vaults. |
get_plan_properties |
Retrieves detailed properties for a specified plan. |
Configure AI clients
The MCP server can connect with various AI clients. Each client requires its own configuration file or settings entry that defines how it communicates with the MCP server. For detailed integration steps, see your AI client's documentation.
The following steps explain how to connect using Visual Studio Code:
-
In Visual Studio Code, open the Command Palette (
Ctrl+Shift+P). -
Select MCP: Add MCP Server, and then choose HTTP (HTTP or Server-Sent Events).
-
Enter the MCP service URL in the following format:
https://$[Command Center FQDN]/commandcenter/mcpUse the Command Center endpoint that points to the Web Server client where you installed the MCP Service package.
-
Name the server and click Start.
-
When prompted for authentication, the browser opens automatically. Sign in to the Command Center and return to Visual Studio Code.
-
Verify the connection is active.
In Visual Studio Code, check that the MCP server displays as connected and lists the available tools.
Note
The hosted service uses your Command Center credentials. No additional authentication configuration is required.
Method 2: Deploy the MCP server from the Git repository
Prerequisites
-
Network access to Command Center from the machine where you will run the MCP server.
-
Python 3.11 or later.
-
uv package manager.
Set up the MCP server locally using Python and the Commvault MCP Server repository.
-
Verify that Python 3.11 or later and the uv package manager are installed on your machine.
-
To clone the repository, run:
git clone https://github.com/Commvault/commvault-mcp-server.git cd commvault-mcp-server -
Run the setup script:
uv run setup.pyThe setup wizard guides you through selecting a transport mode (such as STDIO, Streamable HTTP, or SSE), providing connection details, and selecting an authentication method.
-
Start the server:
uv run -m src.server -
Verify the server started successfully.
Supported authentication methods
The Commvault MCP Server supports the following authentication methods.
OAuth is the preferred authentication method and provides identity management through supported identity providers. Use OAuth when Commvault is configured with modern identity providers.
Important
Ensure OAuth is configured in the CommServe before using this option.
You need the following information:
-
Discovery endpoint URL: The OAuth discovery/metadata endpoint.
-
Client ID: The OAuth application's client identifier.
-
Client secret: The OAuth application's client secret.
-
Base URL: The base URL of the MCP server.
-
Redirect URI: Set to
OAUTH_BASE_URL/auth/callbackin your OAuth provider's app/client configuration.
Use this authentication method when OAuth is not available.
You need the following:
-
A valid
access_tokenandrefresh_tokento authenticate with the Commvault API. For information about creating the access and refresh tokens, see Creating an Access Token. -
A secret key for MCP client access. This secret acts as a security layer for remote tool access and must be included by the MCP client in the Authorization header of all tool requests.
Configure AI clients
The MCP server can connect with various AI clients. Each client requires its own configuration file or settings entry that defines how it communicates with the MCP server. For detailed integration steps, see your AI client's documentation.
Note
npx is required for the following remote client configuration that uses mcp-remote. Install Node.js, which includes npx, before configuring the client.
The following examples show Claude configurations for both remote and local setups.
Remote MCP server
Client on Windows
{
"mcpServers": {
"Commvault": {
"command": "cmd",
"args": [
"/c",
"npx",
"mcp-remote",
"$[HOST:PORT]/mcp",
"--header",
"Authorization: $[secret stored in server keyring]"
]
}
}
}
Streamable HTTP / SSE
{
"mcpServers": {
"Commvault": {
"command": "npx",
"args": [
"mcp-remote",
"$[HOST:PORT]/mcp",
"--header",
"Authorization: $[secret stored in server keyring]"
]
}
}
}
Local MCP server (STDIO)
Unix
{
"mcpServers": {
"Commvault": {
"command": "$[/path/to/.venv]/bin/python",
"args": ["$[/path/to]/src/server.py"]
}
}
}
Windows
{
"mcpServers": {
"Commvault": {
"command": "$[C:\\YOUR\\PATH\\TO\\commvault-mcp-server\\.venv]\\Scripts\\python.exe",
"args": ["$[C:\\YOUR\\PATH\\TO]\\commvault-mcp-server\\src\\server.py"]
}
}
}
Integrations
Extend the MCP Server with optional integrations to connect Commvault with third-party platforms.
DocuSign
Back up completed DocuSign envelopes to a Commvault S3 vault. Automate listing and restore operations directly through the AI assistant.
-
Set the following environment variable:
ENABLE_DOCUSIGN_TOOLS=true -
Configure an S3 vault in Commvault. For information about configuring an S3 vault, see Getting Started for MSP Administrators and Getting Started for Tenants.
-
In the
config/directory, perform the following: -
Create a
docusign_config.jsonfile using the following template.Template for docusign_config file
{ "docusign": { "integrationKey": "$[YOUR_INTEGRATION_KEY_HERE]", "userId": "$[YOUR_USER_ID_HERE]", "authServer": "account-d.docusign.com", "scopes": "signature impersonation", "basePath": "https://demo.docusign.net/restapi" }, "fromDate": "$[YYYY-MM-DDTHH:MM:SSZ]" } -
Add your DocuSign private key file
docusign_key.pem.
ServiceNow
The MCP server supporting ServiceNow actions must be added to your AI client to enable the integration.
Example workflow: Create incident tickets when backup jobs fail.
-
AI client analyzes failed jobs in Commvault through MCP.
-
Identifies all failed jobs.
-
Creates ServiceNow tickets for each failure.
-
Confirms creation within your ServiceNow dashboard.