September 2026 product updates: Get powerful detection and response for the cloud workspace, customized for your SecOps.
At Material, we’re building a solution that gives you security detection and response across the cloud workspace, but we know some teams don’t want to work directly within a UI. We’re investing in our API and MCP so you can operationalize the data held in Material, allowing you to get our intelligence into your SOAR, your incident response workflow, and your custom automations.
Material offers a production-grade, fully documented API that gives technical teams clean programmatic access to Material's detection engine, without needing to touch the UI. And if you're building with AI agents and want even less friction, Material gives you a secure, open Model Context Protocol (MCP) server to connect AI agents directly with workspace-wide security detection and remediation capabilities.
For teams that hate click-ops and want their security infrastructure to be programmatic, integrable, and composable, we’ve got your back. This month, we’re highlighting updates to the API and MCP that will make Material even more flexible.
Two Problems. Two Solutions. One Architecture.
Material's approach here reflects a philosophy: let your team decide how to use detection intelligence, not where.
The API: Deterministic Programmatic Access
With the Issues API, your team can list open issues, match them against signals in your existing workflows, and fetch full issue details (including related messages, accounts, and files) to enrich an incident or trigger a response action.
That's the basics. Here's what matters for technical teams:
- Stable, production-grade. In May, we announced the release of our production-grade, fully documented API. This strong foundation lets teams build with confidence.
- Full resource coverage across the cloud workspace. Material’s API includes these resources now: Issues, Messages, Accounts, Groups, Roles, OAuth Apps, and Trusted Entities. That's not just email threat data; it's the full context you need to remediate at scale. And the list continues to grow rapidly as we add more functionality to the API.
- Built for integration. Any time your team needs to analyze, export, or operationalize Material data in an external system, the API makes that easy to set up. The most common use case is SOAR integration. But it works equally well for exporting to data lakes, triggering webhooks in your orchestration layer, or feeding Material signals into broader incident correlation.
The MCP Server: Natural Language + Powerful Orchestration
Material's MCP server also launched in May, and lets AI agents query, triage, and update email security issues programmatically. Simply connect it using OAuth and start working with Material’s data in your agents. It’s the perfect match for companies who are looking to take an AI-first approach to their security operations.
Ask an agent in natural language:
"Show me all open critical-severity issues from today."
The agent calls the underlying tool, returns a summary, and you can follow up:
"That first one looks like a false positive. Mark it as ignored."
No tab-switching. No UI. A workflow that would take a dozen clicks happens in two sentences of conversation.
We’ve broadened the tools available in the MCP server, letting it work across issues, messages, accounts, and OAuth apps.
This sounds like a convenience layer, but it's much more powerful when you start combining Material with other context the agent already has. If you're investigating an incident and your agent is connected to both Material and your SIEM, you can ask it to correlate what Material detected with what your SIEM logged, and triage directly from the same conversation.
Here’s an example of using the MCP server to update your trusted entities (Material’s version of an allowlist):
Transparency in Detection: The Other Half of the Story
These API improvements landed alongside another shift in Material's architecture. Material recently overhauled the detection explanation experience in the Issue Details page, giving analysts a clearer, more specific picture of what drove a flag.
Why mention this in the context of API improvements? Because transparency works in both directions. Analysts need to see why a detection fired so they can defend the decision. Engineers need to trust that decision well enough to automate on it. Material's goal here is accountability, not just an attractive UI. Security programs work better when analysts can defend the decisions their tools make. These updates give them the specific, technical evidence to do that.
When you're building programmatic workflows on top of Material's detection engine through API or MCP, you're building on evidence you can understand and audit. That changes the calculus for your deployment
Enabling Teams to Build the Security Stack of Tomorrow
Material’s dedication to clear, clean UI still exists, but it's also a platform built for integration. You decide whether that's through a REST API in your automation layer, or through an agent in your SOAR, or through both. For high-velocity organizations running a deeply integrated security stack, this furthers Material's commitment to serving as connective tissue in a system where every tool needs to communicate and every signal needs to flow.
That's what separates security infrastructure that feels bolted-on from security infrastructure that feels like a security accelerator.
Ready to integrate Material into your workflow? Check out the API v1 documentation or learn about the MCP server.

