Using your client
Once configured, you can ask the AI assistant to retrieve information from SCM.
Available tools
Tools are what the AI agent calls the functions that are available for the user. An AI agent using the MCP server to connect to SCM has access to some or all of these functions, depending on specific user permissions.
-
List certificates (filtered by certificate number, status, organization, SAN, etc.)
-
Get details for a specific certificate (by ID number)
-
Download certificates in PEM, PKCS7, or Base64 format
-
Download PKCS12 or JKS keystore
-
Get Domain Control Validation status
-
See the Step-by-step enrollment orchestrator
-
Enroll a new certificate with a CSR
-
Enroll a new certificate with server-side key generation via Private Key Agent (no CSR needed)
-
Enroll a new certificate with server-side key generation in Azure Key Vault (no CSR needed)
-
Renew an existing certificate
-
Replace an existing certificate with a new CSR
-
Approve a pending certificate request
-
Decline a pending certificate request
-
Revoke a certificate
-
List organizations available for enrollment
-
List certificate types/profiles
-
Get profile details (key types, terms, validation)
-
List custom fields
-
List Azure accounts configured in SCM
-
List Azure resource groups for a given Azure account
-
List Azure Key Vaults for a given account, subscription, and resource group