MCP Store
Jamf Pro MCP Server
Jamf Pro MCP server
Connect the Jamf Pro MCP server
Connect the Jamf Pro MCP server to Atomicwork to enable agentic device management and workflows.
Integrate the Jamf Pro Model Context Protocol (MCP) server with Atomicwork to give your AI Coworkers, workflow builder, and coding agents direct access to execute device management tasks and retrieve real-time fleet data. This integration enables agentic actions like checking device compliance, updating inventory, and sending MDM commands automatically.
Standard integration vs. MCP server
This integration is specifically for the MCP server, which enables agentic actions and workflows. If you need to sync employee device attributes or run standard IT asset discovery, connect the standard integration instead. For more details on the standard setup, see our guide on Jamf: Permissions and setup.
Before you begin
Before connecting the Jamf Pro MCP server, make sure you have the following:
- Jamf Pro URL: Your Jamf Pro instance URL (e.g., https://yourcompany.jamfcloud.com).
- Jamf Pro Admin access: Permissions to create API Roles and Clients in Jamf Pro.
- Recommended privileges: We recommend granting View MDM command information in Jamf Pro API, Read Mobile Devices, and Read Computers to your API role. You can add more privileges later to control which tools your AI Coworkers can access.
Step 1: Create an API Role and Client in Jamf Pro
To allow Atomicwork to securely communicate with your Jamf Pro instance, you must set up an API Role and an API Client.
-
Log in to your Jamf Pro instance and navigate to Settings > System > API Roles and Clients.
-
Select the API Roles tab and click New.
-
Enter a descriptive display name, such as "Atomicwork Integration".
-
In the Privileges field, search for and add the privileges required for the integration. We recommend adding View MDM command information in Jamf Pro API, Read Mobile Devices, and Read Computers.
-
Click Save to create the role.
-
Select the API Clients tab and click New.
-
Enter a display name (e.g., "Atomicwork") and select the API Role you created in the previous steps.
-
Set the Access Token Lifetime in seconds (e.g., 1800 for 30 minutes) and toggle the client to Enabled.
-
Click Save. Jamf Pro will automatically generate a Client ID on the client's detail page. Copy this value and store it securely.
-
On the same page, click Generate Client Secret and confirm by clicking Create Secret. Copy the secret immediately and save it in a secure location, as it will not be displayed again.
Step 2: Connect the Jamf Pro MCP server
Once you have generated your credentials in Jamf Pro, you can complete the connection in Atomicwork.
-
In Atomicwork, navigate to Settings > MCP Store > Jamf.
-
Click the Jamf tile and select Connect.
-
Enter your Client URL (your Jamf Pro base URL), Client ID, and Client Secret into the setup modal.
-
Click Connect to finalize the setup. A list of all available Jamf Pro tools will display on your screen.
Manage access to Jamf Pro tools
After completing the setup, you can control which tools your AI Coworkers can access.
- AI Coworker access: Navigate to AI Workforce > AI Coworker > Tools, select your AI Coworker, and grant granular or complete access to the Jamf Pro tools based on your workspace requirements.
Available Jamf Pro MCP tools
The Jamf Pro MCP server provides a wide range of tools grouped by category. These tools allow your AI Coworkers to retrieve information and execute tasks across your fleet:
- Fleet Overview: Tools like getFleetOverview, getSecurityPosture, and checkDeviceCompliance provide high-level summaries of your inventory, compliance status, and security posture.
- Devices (Computers): Tools like searchDevices, getDeviceDetails, updateInventory, and sendComputerMDMCommand allow agents to search computers, force inventory updates, and send MDM commands (such as lock, wipe, or restart).
- Mobile Devices: Tools like searchMobileDevices, getMobileDeviceDetails, and sendMDMCommand manage mobile devices, check battery status, and clear passcodes.
- Policies and Scripts: Tools like listPolicies, getPolicyDetails, listScripts, and deployScript allow your AI Coworkers to browse, analyze, and execute scripts or policies on managed devices (destructive actions require confirmation).
- LAPS (Local Admin Passwords): Tools like getLocalAdminPassword and getLocalAdminPasswordAudit securely retrieve and audit local admin passwords (requires confirmation).
- Reports: Tools like getInventorySummary and getDeviceComplianceSummary generate reports on OS distribution, model distribution, and check-in regularity.
Where to go next
- Setting up an AI Coworker — Learn how to assign tools and configure guardrails for your AI agents.
- Jamf: Permissions and setup — Set up standard asset synchronization and discovery for your IT workspace.
- Connect the JumpCloud MCP server — Explore alternative device-management MCP integrations.
