Connect Claude to Splunk MCP Server
The following example uses Claude code and the command line interface (CLI) to make the connection.
For more information on scope restriction in Claude Code, see the Claude Code MCP documentation at https://code.claude.com/docs/en/mcp.
-
Register the Splunk MCP Server.
-
Run the following command on your workstation. Replace the placeholders with the values from your administrator:
CODEclaude mcp add --transport http \ --callback-port <callback-port> \ --client-id <client-id> \ --client-secret \ splunk-mcp <mcp-endpoint> -
When prompted, paste the Client secret:
-
The
<callback-port>must exactly match the port in the Redirect URI your administrator configured in Splunk. -
The
<client-id>is the Client ID from the Splunk OAuth client. -
The
<mcp-endpoint>is the HTTP endpoint of the Splunk MCP Server.For Splunk Observability tools using the MCP Gateway and Unified Identity, include the splunk_tenant header. You can also include the X-SPLUNK-O11Y-TOOL-SETS header to make additional Splunk Observability toolsets available to Claude Code.
For example:CODEclaude mcp add \ --transport http \ --callback-port <callback-port> \ --client-id <client-id> \ --client-secret \ splunk-mcp <mcp-gateway-endpoint> \ --header "splunk_tenant: <splunk-tenant>" \ --header "X-SPLUNK-O11Y-TOOL-SETS: apm,metrics,dashboards,detectors"Note: Specify the server name and MCP Gateway endpoint before the--headeroptions. In Claude Code, the--headeroption can consume following arguments if the headers appear earlier in the command.
-
-
-
Restrict OAuth scopes. Open Claude Code's configuration file (~/.claude.json) and locate the splunk-mcp entry. Claude Code does not currently provide a command-line option for configuring OAuth scopes.
Add a scopes field inside the OAuth block, set to openid offline_access:
JSON"splunk-mcp": { "type": "http", "url": "<mcp-endpoint>", "oauth": { "clientId": "<client-id>", "callbackPort": <callback-port>, "scopes": "openid offline_access" } } -
Authenticate:
-
Start Claude Code:
claude -
From inside Claude Code run:
/mcp -
Your browser opens to the Splunk sign-in page.
-
Sign in with your Splunk credentials and approve access for the Claude Code application.
-
The browser redirects to http://localhost:<callback-port>/callback and Claude Code completes authentication.
-
-
Verify tools:
-
Run
/mcpagain to confirmsplunk-mcpis connected. -
Review the list of tools exposed by the Splunk MCP Server.
-
Invoke any tool to validate end-to-end connectivity. For example, a read-only search tool.
-
Troubleshoot the Claude connection
See the following table of messages you might see when connecting Claude Code and how to resolve them:
| Messages | Resolution |
|---|---|
Query argument scope is required |
Confirm that openid offline_access is configured in the oauth.scopes field in ~/.claude.json. |
redirect_uri does not match |
Confirm that the OAuth client has the exact callback URL registered. Also confirm that the URL wasn't manually double-encoded. |
Client authentication failed |
Confirm that the client secret was supplied and stored. |
Authorization header is not Bearer |
Don't open the MCP Gateway URL directly in a browser. Start the OAuth flow from Claude Code. |