Tenable One Hexa AI MCP and cloud API
Tenable · saas · enterprise
Tenable One is automatable today through the Tenable-hosted Hexa AI MCP server and the cloud.tenable.com APIs that Tenable says include Tenable One. The MCP endpoint is https://cloud.tenable.com/mcp/. Tenable says it exposes 90 tools from the Exposure Data Fabric and that Tenable hosts the server without hosting the model. Use requires a Tenable One Foundation or Advanced license, the Hexa AI MCP toggle, and Vulnerability Management API keys in the X-ApiKeys header. Example workflows search assets, create tickets, tag assets, build dashboards, and launch scans, and write steps are presented for confirmation. The feature is not supported in Tenable FedRAMP Moderate environments. The API basics page says the cloud.tenable.com guidance covers Tenable One, Vulnerability Management, Web App Scanning, and Exposure Management, and does not cover Security Center, Cloud Exposure, Attack Surface Management, or OT Exposure. Requests use X-ApiKeys with an access key and a secret key. This pass did not inventory every API resource, and it did not open an SDK, CLI, or webhook contract. Connector catalogs were not opened. Computer-use viability is unassessed. MCP scores 7 and is the best path because the tool workflows are documented specifically. The API scores 6 because the shared cloud API is real and partial across the Tenable One domains.
Best path today: mcp · Overall automatability: 7/10
Modalities
| Modality | Status | Detail |
|---|---|---|
| API | yes | restx-apikeys coverage: partial · docs |
| SDK | unknown | official: unknown |
| MCP | yes | verdict: official |
| Integrations | unknown | |
| CLI | unknown | |
| Extensibility | unknown | webhooks: unknown |
| Data access | export: unknown · import: unknown | |
| RPA / UI automation | unknown | web-dom No repeatable UI probe was run. Tenable documents a hosted Hexa AI MCP server and cloud.tenable.com APIs for Tenable One. Several Tenable One domains use separate API documentation.
|
| Computer use | unknown | measured verdicts only — "unknown" means not yet probed by us |
Scores
| api | mcp | integrations | cli | rpa | computer use | overall |
|---|---|---|---|---|---|---|
| 6 | 7 | — | — | — | — | 7 |
Evidence
| Fact | Tier | Source | Date |
|---|---|---|---|
homepage | declared | source | 2026-10-06 |
vendor | declared | source | 2026-10-06 |
deployment | declared | source | 2026-10-06 |
platforms[0] | declared | source | 2026-10-06 |
license | declared | source | 2026-10-06 |
modalities.api.exists | declared | source | 2026-10-06 |
modalities.api.kinds[0] | declared | source | 2026-10-06 |
modalities.api.auth[0] | declared | source | 2026-10-06 |
modalities.api.coverage | declared | source | 2026-10-06 |
modalities.api.docs | declared | source | 2026-10-06 |
modalities.mcp.first_party | declared | source | 2026-10-06 |
modalities.mcp.verdict | declared | source | 2026-10-06 |
modalities.rpa.ui_stack[0] | declared | source | 2026-10-06 |
modalities.rpa.drivability | declared | source | 2026-10-06 |
modalities.computer_use.viability | declared | source | 2026-10-06 |
modalities.agent_docs.llms_txt | declared | source | 2026-10-06 |
verdict.best_path | declared | source | 2026-10-06 |
verdict.scores.api | declared | source | 2026-10-06 |
verdict.scores.mcp | declared | source | 2026-10-06 |
freshness.watch[0].url | declared | source | 2026-10-06 |
freshness.watch[1].url | declared | source | 2026-10-06 |
freshness.watch[2].url | declared | source | 2026-10-06 |
Related tools
Other products in this database that share a category with Tenable One.
Last verified 2026-10-06 · volatility medium · JSON record