From mimecast
Use this skill when working with Mimecast MCP tools — available tools, OAuth 2.0 client credentials authentication, regional API endpoints, pagination, rate limiting, and error handling.
How this skill is triggered — by the user, by Claude, or both
Slash command
/mimecast:api-patternsWhen to use
When working with available tools, OAuth 2.0 client credentials authentication, regional API endpoints, pagination, rate limiting, and error handling in Mimecast MCP tools. Use when: mimecast, mimecast api, mimecast authentication, mimecast tools, mimecast mcp, mimecast request, mimecast error, mimecast region, or mimecast pagination.
The summary Claude sees in its skill listing — used to decide when to auto-load this skill
The Mimecast MCP server provides AI tool integration with the Mimecast Email Security platform. It covers message tracking, threat intelligence (TTP), email delivery queue management, and audit event access. Authentication is via OAuth 2.0 client credentials — the MCP Gateway handles token acquisition automatically using the injected client ID and secret.
The Mimecast MCP server provides AI tool integration with the Mimecast Email Security platform. It covers message tracking, threat intelligence (TTP), email delivery queue management, and audit event access. Authentication is via OAuth 2.0 client credentials — the MCP Gateway handles token acquisition automatically using the injected client ID and secret.
Mimecast uses OAuth 2.0 client credentials flow. The MCP Gateway injects credentials via headers:
| Header | Description |
|---|---|
X-Mimecast-Client-ID | OAuth 2.0 Client ID |
X-Mimecast-Client-Secret | OAuth 2.0 Client Secret |
X-Mimecast-Region | Regional API endpoint key (us, eu, de, ca, za, au) |
The server exchanges the client ID and secret for a bearer token at startup and refreshes it as needed. Individual tool calls do not require manual token management.
Environment Variables (self-hosted):
export MIMECAST_CLIENT_ID="your-client-id"
export MIMECAST_CLIENT_SECRET="your-client-secret"
export MIMECAST_REGION="us"
IMPORTANT: Never hardcode credentials. Always use environment variables or the MCP Gateway.
Mimecast tenants are hosted in specific regions. Using the wrong region returns empty results or authentication failures.
| Region Key | Base URL |
|---|---|
us | https://api.services.mimecast.com |
eu | https://eu-api.mimecast.com |
de | https://de-api.mimecast.com |
ca | https://ca-api.mimecast.com |
za | https://za-api.mimecast.com |
au | https://au-api.mimecast.com |
To identify the correct region, log into the Mimecast Administration Console and check the URL — the subdomain indicates the region (us, eu, de, etc.).
| Tool | Description |
|---|---|
mimecast_find_message | Search messages by sender, recipient, subject, date range |
mimecast_get_message_info | Get detailed metadata for a specific message |
mimecast_hold_message | Place a message on hold (prevent delivery) |
mimecast_release_message | Release a held message for delivery |
| Tool | Description |
|---|---|
mimecast_get_threat_incidents | List threat remediation incidents |
mimecast_get_ttp_logs | Get TTP logs — URL clicks, attachment checks, impersonation |
mimecast_get_audit_events | Retrieve audit log entries |
| Tool | Description |
|---|---|
mimecast_get_queue | Get email delivery queue status |
Most Mimecast list endpoints use cursor-based pagination:
meta.pagination object with pageSize, totalCount, and optionally nextnext cursor value as the pageToken parameter on the next callmeta.pagination.next is absent or nullExample pagination response:
{
"meta": {
"status": 200,
"pagination": {
"pageSize": 25,
"totalCount": 142,
"next": "eyJwYWdlIjoyLCJwYWdlU2l6ZSI6MjV9"
}
},
"data": []
}
Pagination workflow:
pageTokenmeta.pagination.next in the responsepageToken set to that valuenext is absentMimecast enforces per-endpoint rate limits. Specific limits vary by subscription tier.
| Code | Meaning | Resolution |
|---|---|---|
| 400 | Bad Request | Check required parameters and date format (ISO 8601) |
| 401 | Unauthorized | Verify Client ID and Secret; check token expiry |
| 403 | Forbidden | Insufficient OAuth scopes for the operation |
| 404 | Not Found | Message ID or resource doesn't exist |
| 429 | Rate Limited | Wait and retry with backoff |
| 500 | Server Error | Retry; contact Mimecast support if persistent |
{
"meta": {
"status": 401,
"message": "Invalid credentials"
},
"fail": [
{
"errors": [
{
"code": "err_auth_invalid",
"message": "The provided client credentials are invalid",
"retryable": false
}
]
}
]
}
If requests succeed but return empty data arrays when results are expected, the region is likely incorrect. Verify the tenant's region and update the MIMECAST_REGION configuration.
meta.status field in every response — Mimecast sometimes returns HTTP 200 with error status in the bodyrequestId from response headers for support escalationsnpx claudepluginhub wyre-technology/msp-claude-plugins --plugin mimecastUse this skill when investigating Mimecast threat activity — TTP logs for URL clicks, malicious attachment analysis, impersonation attempts, threat remediation incidents, and audit events.
Manages Proofpoint email quarantine: list, search, release, and delete messages. Covers reasons, sender/recipient filtering, bulk operations, folders, and preview. For MSP help desk teams.
Use this skill when managing the SpamTitan quarantine queue — listing held messages, releasing legitimate emails, deleting spam, reviewing email flow statistics, and performing bulk quarantine operations.