Go back

API and MCP Server Updates: Material Detection and Response without Click-Ops

September 2026 product updates: Get powerful detection and response for the cloud workspace, customized for your SecOps.

Product
September 28, 2026
6m read
6m read
6m listen
6m watch
6m watch
API and MCP Server Updates: Material Detection and Response without Click-OpsAPI and MCP Server Updates: Material Detection and Response without Click-Ops
speakers
speakers
speakers
authors
Kate Hutchinson
participants
No items found.
share

September 2026 product updates: Get powerful detection and response for the cloud workspace, customized for your SecOps.

At Material, we’re building a solution that gives you security detection and response across the cloud workspace, but we know some teams don’t want to work directly within a UI. We’re investing in our API and MCP so you can operationalize the data held in Material, allowing you to get our intelligence into your SOAR, your incident response workflow, and your custom automations. 

Material offers a production-grade, fully documented API that gives technical teams clean programmatic access to Material's detection engine, without needing to touch the UI. And if you're building with AI agents and want even less friction, Material gives you a secure, open Model Context Protocol (MCP) server to connect AI agents directly with workspace-wide security detection and remediation capabilities.

For teams that hate click-ops and want their security infrastructure to be programmatic, integrable, and composable, we’ve got your back. This month, we’re highlighting updates to the API and MCP that will make Material even more flexible.

Two Problems. Two Solutions. One Architecture.

Material's approach here reflects a philosophy: let your team decide how to use detection intelligence, not where.

The API: Deterministic Programmatic Access

With the Issues API, your team can list open issues, match them against signals in your existing workflows, and fetch full issue details (including related messages, accounts, and files) to enrich an incident or trigger a response action.

That's the basics. Here's what matters for technical teams:

  • Stable, production-grade. In May, we announced the release of our production-grade, fully documented API. This strong foundation lets teams build with confidence.
  • Full resource coverage across the cloud workspace. Material’s API includes these resources now: Issues, Messages, Accounts, Groups, Roles, OAuth Apps, and Trusted Entities. That's not just email threat data; it's the full context you need to remediate at scale. And the list continues to grow rapidly as we add more functionality to the API.‍
  • Built for integration. Any time your team needs to analyze, export, or operationalize Material data in an external system, the API makes that easy to set up. The most common use case is SOAR integration. But it works equally well for exporting to data lakes, triggering webhooks in your orchestration layer, or feeding Material signals into broader incident correlation.

The MCP Server: Natural Language + Powerful Orchestration

Material's MCP server also launched in May, and lets AI agents query, triage, and update email security issues programmatically. Simply connect it using OAuth and start working with Material’s data in your agents. It’s the perfect match for companies who are looking to take an AI-first approach to their security operations.

Ask an agent in natural language:

"Show me all open critical-severity issues from today."

The agent calls the underlying tool, returns a summary, and you can follow up:

"That first one looks like a false positive. Mark it as ignored."

No tab-switching. No UI. A workflow that would take a dozen clicks happens in two sentences of conversation.

We’ve broadened the tools available in the MCP server, letting it work across issues, messages, accounts, and OAuth apps.

This sounds like a convenience layer, but it's much more powerful when you start combining Material with other context the agent already has. If you're investigating an incident and your agent is connected to both Material and your SIEM, you can ask it to correlate what Material detected with what your SIEM logged, and triage directly from the same conversation.

Here’s an example of using the MCP server to update your trusted entities (Material’s version of an allowlist):

Transparency in Detection: The Other Half of the Story

These API improvements landed alongside another shift in Material's architecture. Material recently overhauled the detection explanation experience in the Issue Details page, giving analysts a clearer, more specific picture of what drove a flag.

Why mention this in the context of API improvements? Because transparency works in both directions. Analysts need to see why a detection fired so they can defend the decision. Engineers need to trust that decision well enough to automate on it. Material's goal here is accountability, not just an attractive UI. Security programs work better when analysts can defend the decisions their tools make. These updates give them the specific, technical evidence to do that.

When you're building programmatic workflows on top of Material's detection engine through API or MCP, you're building on evidence you can understand and audit. That changes the calculus for your deployment

Enabling Teams to Build the Security Stack of Tomorrow

Material’s dedication to clear, clean UI still exists, but it's also a platform built for integration. You decide whether that's through a REST API in your automation layer, or through an agent in your SOAR, or through both. For high-velocity organizations running a deeply integrated security stack, this furthers Material's commitment to serving as connective tissue in a system where every tool needs to communicate and every signal needs to flow.

That's what separates security infrastructure that feels bolted-on from security infrastructure that feels like a security accelerator.

Ready to integrate Material into your workflow? Check out the API v1 documentation or learn about the MCP server. 

‍

Frequently Asked Questions

Find answers to common questions and get the details you need.

No items found.

Related posts

Our blog is your destination for expert insights, practical tips, and the latest news in technology. Stay informed with our regular updates and in-depth articles. Join the conversation and enhance your understanding of the tech landscape.

blog post

API and MCP Server Updates: Material Detection and Response without Click-Ops

September 2026 product updates: Get powerful detection and response for the cloud workspace, customized for your SecOps.

Kate Hutchinson
6
m read
Read post
Podcast

API and MCP Server Updates: Material Detection and Response without Click-Ops

September 2026 product updates: Get powerful detection and response for the cloud workspace, customized for your SecOps.

6
m listen
Listen to episode
Video

API and MCP Server Updates: Material Detection and Response without Click-Ops

September 2026 product updates: Get powerful detection and response for the cloud workspace, customized for your SecOps.

6
m watch
Watch video
Downloads

API and MCP Server Updates: Material Detection and Response without Click-Ops

September 2026 product updates: Get powerful detection and response for the cloud workspace, customized for your SecOps.

6
m listen
Watch video
Webinar

API and MCP Server Updates: Material Detection and Response without Click-Ops

September 2026 product updates: Get powerful detection and response for the cloud workspace, customized for your SecOps.

6
m listen
Listen episode
blog post

When a Demo Becomes a Real Attack: OAuth Abuse Against Google Workspace

No password, no MFA bypass: this OAuth attack takes one click, and Russian state hackers are already running it in the wild.

Rajan Kapoor
7
m read
Read post
Podcast

When a Demo Becomes a Real Attack: OAuth Abuse Against Google Workspace

No password, no MFA bypass: this OAuth attack takes one click, and Russian state hackers are already running it in the wild.

7
m listen
Listen to episode
Video

When a Demo Becomes a Real Attack: OAuth Abuse Against Google Workspace

No password, no MFA bypass: this OAuth attack takes one click, and Russian state hackers are already running it in the wild.

7
m watch
Watch video
Downloads

When a Demo Becomes a Real Attack: OAuth Abuse Against Google Workspace

No password, no MFA bypass: this OAuth attack takes one click, and Russian state hackers are already running it in the wild.

7
m listen
Watch video
Webinar

When a Demo Becomes a Real Attack: OAuth Abuse Against Google Workspace

No password, no MFA bypass: this OAuth attack takes one click, and Russian state hackers are already running it in the wild.

7
m listen
Listen episode
blog post

Sharper, Easier Google Drive Detection and Response

Material is releasing a series of upgrades to our existing Google Drive capabilities to make it easier to detect and fix risky sharing so you can rest assured that information is flowing only where it’s both needed and allowed.

Marie Ketner
5
m read
Read post
Podcast

Sharper, Easier Google Drive Detection and Response

Material is releasing a series of upgrades to our existing Google Drive capabilities to make it easier to detect and fix risky sharing so you can rest assured that information is flowing only where it’s both needed and allowed.

5
m listen
Listen to episode
Video

Sharper, Easier Google Drive Detection and Response

Material is releasing a series of upgrades to our existing Google Drive capabilities to make it easier to detect and fix risky sharing so you can rest assured that information is flowing only where it’s both needed and allowed.

5
m watch
Watch video
Downloads

Sharper, Easier Google Drive Detection and Response

Material is releasing a series of upgrades to our existing Google Drive capabilities to make it easier to detect and fix risky sharing so you can rest assured that information is flowing only where it’s both needed and allowed.

5
m listen
Watch video
Webinar

Sharper, Easier Google Drive Detection and Response

Material is releasing a series of upgrades to our existing Google Drive capabilities to make it easier to detect and fix risky sharing so you can rest assured that information is flowing only where it’s both needed and allowed.

5
m listen
Listen episode
blog post

Why You Need to Rethink Google Workspace Security in the Age of AI

The workspace attack chain has evolved. If your security strategy ends at the inbox, it has a critical gap where both modern attackers and AI agents operate.

Rajan Kapoor
3
m read
Read post
Podcast

Why You Need to Rethink Google Workspace Security in the Age of AI

The workspace attack chain has evolved. If your security strategy ends at the inbox, it has a critical gap where both modern attackers and AI agents operate.

3
m listen
Listen to episode
Video

Why You Need to Rethink Google Workspace Security in the Age of AI

The workspace attack chain has evolved. If your security strategy ends at the inbox, it has a critical gap where both modern attackers and AI agents operate.

3
m watch
Watch video
Downloads

Why You Need to Rethink Google Workspace Security in the Age of AI

The workspace attack chain has evolved. If your security strategy ends at the inbox, it has a critical gap where both modern attackers and AI agents operate.

3
m listen
Watch video
Webinar

Why You Need to Rethink Google Workspace Security in the Age of AI

The workspace attack chain has evolved. If your security strategy ends at the inbox, it has a critical gap where both modern attackers and AI agents operate.

3
m listen
Listen episode
Privacy Preference Center

By clicking “Accept”, you agree to the storing of cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing efforts. View our Privacy Policy for more information.

New