CrowdStrike Falcon icon

CONNECT APP

Build with CrowdStrike Falcon

Cloud-native cybersecurity platform

Security

  • OAuth

MCP

Give your agent CrowdStrike Falcon tools

Every CrowdStrike Falcon action is exposed as an MCP tool on Pipedream's remote server. Point a client at it with your end user's ID and Connect resolves that user's CrowdStrike Falcon account for each tool call — you store no tokens.

// accessToken: mint a short-lived token with the Connect SDK — see the MCP guide
const transport = new StreamableHTTPClientTransport(
  new URL("https://remote.mcp.pipedream.net/v3"),
  {
    requestInit: {
      headers: {
        Authorization: `Bearer ${accessToken}`,
        "x-pd-project-id": "{project_id}",
        "x-pd-environment": "production",
        "x-pd-external-user-id": "{external_user_id}", // any stable ID for this user in your system
        "x-pd-app-slug": "crowdstrike_falcon",
      },
    },
  },
)

const mcp = new Client({ name: "my-agent", version: "1.0.0" })
await mcp.connect(transport)

const { tools } = await mcp.listTools()

// e.g. run Get Alert:
const result = await mcp.callTool({
  name: "crowdstrike_falcon-get-alert",
  arguments: {
    alertIds: ["Alert IDs"],
    includeHidden: true,
  },
})

API PROXY

Call the CrowdStrike Falcon API directly

For an endpoint with no pre-built tool, the Connect proxy forwards your request to the CrowdStrike Falcon API with the connected user's credentials attached. You store no tokens and write no refresh logic.

const resp = await pd.proxy.get({
  externalUserId: "{external_user_id}", // any stable ID for this user in your system
  accountId: "apn_xxxxxxx",
  url: "https://api.example.com/v1/me",
})

// Any allowed CrowdStrike Falcon endpoint works here. Pipedream attaches the
// connected account's credentials to the outgoing request.

SDK

Run CrowdStrike Falcon actions from your backend

Connect a user's CrowdStrike Falcon account once, then run Get Alert on their behalf from your own code — TypeScript, Python, or plain HTTP.

import { PipedreamClient } from "@pipedream/sdk"

const pd = new PipedreamClient({
  projectId: process.env.PIPEDREAM_PROJECT_ID!,
  clientId: process.env.PIPEDREAM_CLIENT_ID!,
  clientSecret: process.env.PIPEDREAM_CLIENT_SECRET!,
  projectEnvironment: "production",
})

const result = await pd.actions.run({
  id: "crowdstrike_falcon-get-alert",
  externalUserId: "{external_user_id}", // any stable ID for this user in your system
  configuredProps: {
    crowdstrike_falcon: { authProvisionId: "apn_xxxxxxx" },
    alertIds: ["Alert IDs"],
    includeHidden: true,
  },
})

TOOLS

CrowdStrike Falcon actions

On-demand operations your product or agent can configure and run on behalf of a connected user.

REFERENCE

App details

Reference metadata for the CrowdStrike Falcon connector in the Pipedream registry.

App slug
crowdstrike_falcon
Authentication
OAuth
Categories
Security
Actions
7
Triggers
2
API proxy
Available