MCP server for Vulnify: MCP clients such as Claude and Cursor check an agent action and get ALLOW, REVIEW or BLOCK. Hosted at mcp.vulnify.io with OAuth, or run locally over stdio.
- ✓Open-source license (MIT)
- ✓Actively maintained (<30d)
- ✓Clear description
- ✓Topics declared
- ✓Documented (README)
claude mcp add vulnify-mcp -- npx -y @vulnify/mcp{
"mcpServers": {
"vulnify-mcp": {
"command": "npx",
"args": ["-y", "@vulnify/mcp"],
"env": {
"VULNIFY_API_KEY": "<vulnify_api_key>"
}
}
}
}VULNIFY_API_KEYResumen de MCP Servers
<p align="center">
<img src="https://raw.githubusercontent.com/vulnify/vulnify-mcp/main/.github/assets/logo.png" alt="Vulnify" width="88" />
</p>
<h1 align="center">Vulnify MCP</h1>
<p align="center">
Ask Vulnify before an AI agent reads, writes, deletes, exports, or sends data.<br />
finalDecision is the authoritative result: <strong>ALLOW</strong>, <strong>REVIEW</strong>, or <strong>BLOCK</strong>.
</p>
<p align="center">
<a href="https://www.npmjs.com/package/@vulnify/mcp"><img alt="npm version" src="https://img.shields.io/npm/v/@vulnify/mcp?color=3D6DFF" /></a>
<a href="https://www.npmjs.com/package/@vulnify/mcp"><img alt="npm downloads" src="https://img.shields.io/npm/dm/@vulnify/mcp?color=3D6DFF" /></a>
<a href="https://github.com/vulnify/vulnify-mcp/blob/main/LICENSE"><img alt="license" src="https://img.shields.io/github/license/vulnify/vulnify-mcp?color=3D6DFF" /></a>
<a href="https://github.com/vulnify/vulnify-mcp/actions/workflows/ci.yml"><img alt="CI" src="https://img.shields.io/github/actions/workflow/status/vulnify/vulnify-mcp/ci.yml?branch=main&label=CI" /></a>
</p>
<p align="center">
<a href="https://docs.vulnify.io/mcp/">Docs</a>
·
<a href="https://github.com/vulnify/vulnify-mcp">MCP</a>
·
<a href="https://github.com/vulnify/vulnify-mcp/blob/main/CHANGELOG.md">Changelog</a>
·
<a href="https://github.com/vulnify/vulnify-sdk">Node SDK</a>
</p>
<p align="center">
<img src="https://raw.githubusercontent.com/vulnify/vulnify-mcp/main/.github/assets/banner.png" alt="Every agent action gets a decision. ALLOW, REVIEW, or BLOCK." width="800" />
</p>
`@vulnify/mcp` is the MCP server for [Vulnify](https://docs.vulnify.io), a runtime authorization layer for AI agents. The agent asks first. This process proxies `https://api.vulnify.io`. It does not store events or API keys.
Sign in with Vulnify (OAuth 2.1) at [`https://mcp.vulnify.io/mcp`](https://mcp.vulnify.io/mcp). That hosted server speaks stateless Streamable HTTP. The local path is `npx -y @vulnify/mcp` with `VULNIFY_API_KEY`.
`check_action` is a dry run. It skips the PII scan and records nothing. `decide_action` records a real decision. A `REVIEW` waits for a person. This server cannot approve or deny one.
Application code that should decide inside your own process uses the [Node SDK](https://github.com/vulnify/vulnify-sdk) (`@vulnify/sdk`). This package does not depend on the SDK. The SDK turns some transport failures into a fail-closed decision. This server returns those failures as MCP tool errors, so a model does not read them as `ALLOW`.
## Quickstart
The source of truth is [docs.vulnify.io/mcp](https://docs.vulnify.io/mcp/). The same steps are in [docs/clients.md](docs/clients.md).
### Sign in with Vulnify
Connect to `https://mcp.vulnify.io/mcp`. Leave API-key and OAuth client fields empty. The client receives HTTP 401 and:
```
WWW-Authenticate: Bearer realm="https://mcp.vulnify.io/mcp", resource_metadata="https://mcp.vulnify.io/.well-known/oauth-protected-resource/mcp", scope="decisions:read decisions:write policies:read policies:test"
```
The body is `{"error":"unauthorized","message":"Sign in with Vulnify, or send an API key as Authorization: Bearer or X-Vulnify-Key:."}`. Protected-resource metadata lists the authorization server `https://api.vulnify.io`.
You choose an organization and allow the scopes the client requests:
| Scope | Tools |
| --- | --- |
| `decisions:read` | `get_decision` |
| `decisions:write` | `decide_action` |
| `policies:read` | `list_policies` |
| `policies:test` | `check_action`, `test_policies` |
After you allow access, the hosted server offers those five tools. `plan_policy_changes` and `check_mcp_tool_call` are not in that list. They need an API key. A missing scope comes back as a tool error that names the scope. That error is not an `ALLOW`. Revoke the connection under Settings > Connected apps: [app.vulnify.io/settings/connected-apps](https://app.vulnify.io/settings/connected-apps).
#### Claude
In Claude, open Settings > Connectors > Add custom connector. Set the URL to `https://mcp.vulnify.io/mcp`. Do not paste an API key. Add Vulnify in Claude opens that dialog with the name and URL filled in. Claude then starts Sign in with Vulnify.
#### Cursor
[Install in Cursor](cursor://anysphere.cursor-deeplink/mcp/install?name=vulnify&config=eyJ1cmwiOiJodHRwczovL21jcC52dWxuaWZ5LmlvL21jcCJ9) adds the hosted server and starts sign-in.
The same server in `.cursor/mcp.json`, or in `~/.cursor/mcp.json`, is the URL with no header:
```json
{
"mcpServers": {
"vulnify": {
"url": "https://mcp.vulnify.io/mcp"
}
}
}
```
#### Grok
Open [grok.com/connectors](https://grok.com/connectors), then New Connector > Custom. Name it `Vulnify`. Set the URL to `https://mcp.vulnify.io/mcp`. Leave the OAuth fields empty. Grok starts Sign in with Vulnify.
#### Claude Code
```bash
claude mcp add --transport http vulnify https://mcp.vulnify.io/mcp
```
Claude Code then signs in. Do not pass an API key on this command.
### API key or local npx
Use an API key when you need `plan_policy_changes` or `check_mcp_tool_call`, when the client cannot open a browser, or when the key has an IP allowlist. The local process needs Node.js 20 or newer and reads `VULNIFY_API_KEY`. It does not open the OAuth consent page.
```bash
npx -y @vulnify/mcp
```
```bash
VULNIFY_API_KEY=vln_live_... npx -y @vulnify/mcp
```
The key is `vln_live_...` or `vln_test_...`. A `TEST` key stores sandbox events. Those stay out of the main dashboards.
On the hosted server, both headers still work. Send the key on every request:
```
Authorization: Bearer <key>
X-Vulnify-Key: <key>
```
An API-key session lists all seven tools.
Cursor, hosted:
```json
{
"mcpServers": {
"vulnify": {
"url": "https://mcp.vulnify.io/mcp",
"headers": {
"Authorization": "Bearer vln_live_..."
}
}
}
}
```
Cursor, local:
```json
{
"mcpServers": {
"vulnify": {
"command": "npx",
"args": ["-y", "@vulnify/mcp"],
"env": {
"VULNIFY_API_KEY": "vln_live_..."
}
}
}
}
```
`X-Vulnify-Key` works in place of `Authorization` on the hosted server.
Claude Code with an API key:
```bash
claude mcp add --transport http vulnify https://mcp.vulnify.io/mcp --header "Authorization: Bearer vln_test_your_key"
```
Prefer an environment variable over a key written into the shell history. For sign-in, use the Claude Code command with no header.
Claude Desktop can run the local process. On macOS the file is `~/Library/Application Support/Claude/claude_desktop_config.json`. On Windows it is `%APPDATA%\Claude\claude_desktop_config.json`. Restart the app after saving.
```json
{
"mcpServers": {
"vulnify": {
"command": "npx",
"args": ["-y", "@vulnify/mcp"],
"env": {
"VULNIFY_API_KEY": "vln_live_..."
}
}
}
}
```
VS Code, `.vscode/mcp.json`, hosted:
```json
{
"servers": {
"vulnify": {
"type": "http",
"url": "https://mcp.vulnify.io/mcp",
"headers": {
"Authorization": "Bearer ${input:vulnify-api-key}"
}
}
}
}
```
VS Code, local:
```json
{
"servers": {
"vulnify": {
"type": "stdio",
"command": "npx",
"args": ["-y", "@vulnify/mcp"],
"env": {
"VULNIFY_API_KEY": "${input:vulnify-api-key}"
}
}
}
}
```
## How it works
<p align="center">
<img src="https://raw.githubusercontent.com/vulnify/vulnify-mcp/main/.github/assets/how-it-works.svg" alt="An agent action goes to Vulnify. finalDecision is ALLOW (the action may run), REVIEW (a person decides), or BLOCK (the action does not run)." width="720" />
</p>
The `finalDecision` field is the authoritative result. A tool error is not an `ALLOW`.
## Tools
Every tool has a title and `readOnlyHint`, `destructiveHint`, `idempotentHint`, and `openWorldHint`. Hints tell the client how to present the tool. They do not change what the tool does.
| Tool | API | Records? | readOnlyHint | Notes |
| --- | --- | --- | --- | --- |
| `check_action` | `POST /v1/policies/test` (one case) | No | true | Skips the PII scan and records nothing. No event id. |
| `decide_action` | `POST /v1/events` | Yes | false | Writes a security event and an audit entry. `finalDecision` is the authoritative result. |
| `get_decision` | `GET /v1/events/{id}` | No | true | Reads a decision. Optional wait polls a `REVIEW` until `ALLOW` or `BLOCK` (30 seconds max). |
| `list_policies` | `GET /v1/policies` | No | true | Policies as code, sorted by name. |
| `test_policies` | `POST /v1/policies/test` | No | true | Up to 200 cases. Skips the PII scan. Proposed `policies` are not saved. |
| `plan_policy_changes` | `POST /v1/policies/apply` | No | true | `dryRun` is forced to true. Needs an org-wide LIVE key. |
| `check_mcp_tool_call` | `POST /v1/gateway/mcp` | Yes | false | Maps a tool name to an action and records the decision. Does not run the tool. |
`destructiveHint` is false on every tool. `openWorldHint` is false on every tool, because each call stays inside the caller's own Vulnify organization. `idempotentHint` is true for the read-only tools and false for `decide_action` and `check_mcp_tool_call`. An `idempotencyKey` makes a retry of a recorded decision return the same event.
Policy list, test, and plan calls are limited to 60 requests per minute per key. Batch dry runs with `test_policies`. `POST /v1/events` has its own limit. The OpenAPI text says only that the limit was exceeded.
## Safety
This server cannot change a review and cannot save a policy.
- There is no approve tool and no deny tool. A human resolves a `REVIEW` in Vulnify.
- There is no apply tool. `plan_policy_changes` calls `POST /v1/policies/apply` with `dryRun: true` on every request. The tool input has no `dryRun` field. The server sets `dryRun` last, so a caller cannot turn the dry run off. The tool returns the diff.
- `POLo que la gente pregunta sobre vulnify-mcp
¿Qué es vulnify/vulnify-mcp?
+
vulnify/vulnify-mcp es mcp servers para el ecosistema de Claude AI. MCP server for Vulnify: MCP clients such as Claude and Cursor check an agent action and get ALLOW, REVIEW or BLOCK. Hosted at mcp.vulnify.io with OAuth, or run locally over stdio. Tiene 1 estrellas en GitHub y su última actualización registrada es del 2026-10-10.
¿Cómo se instala vulnify-mcp?
+
Puedes instalar vulnify-mcp clonando el repositorio (https://github.com/vulnify/vulnify-mcp) o siguiendo las instrucciones del README en GitHub. ClaudeWave también te ofrece bloques de instalación rápida en esta misma página.
¿Es seguro usar vulnify/vulnify-mcp?
+
Nuestro agente de seguridad ha analizado vulnify/vulnify-mcp y le ha asignado un Trust Score de 95/100 (tier: Verified). Revisa el desglose completo de comprobaciones superadas y flags en esta página.
¿Quién mantiene vulnify/vulnify-mcp?
+
vulnify/vulnify-mcp es mantenido por vulnify. La última actividad registrada en GitHub es del 2026-10-10, con 0 issues abiertos.
¿Hay alternativas a vulnify-mcp?
+
Sí. En ClaudeWave puedes explorar mcp servers similares en /categories/mcp, ordenados por popularidad o actividad reciente.
Despliega vulnify-mcp en tu cloud
Lleva este repo a producción en minutos. Cada plataforma genera su propio entorno con variables de entorno editables.
¿Mantienes este repo? Añade un badge a tu README
Pega el badge en tu README de GitHub para mostrar que está auditado por ClaudeWave. Cada badge enlaza de vuelta a esta página y muestra el Trust Score actual.
[](https://claudewave.com/repo/vulnify-vulnify-mcp)<a href="https://claudewave.com/repo/vulnify-vulnify-mcp"><img src="https://claudewave.com/api/badge/vulnify-vulnify-mcp" alt="Featured on ClaudeWave: vulnify/vulnify-mcp" width="320" height="64" /></a>Más MCP Servers
Fair-code workflow automation platform with native AI capabilities. Combine visual building with custom code, self-host or cloud, 400+ integrations.
User-friendly AI Interface (Supports Ollama, OpenAI API, ...)
An open-source AI agent that brings the power of Gemini directly into your terminal.
Real-time global intelligence dashboard. AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational awareness interface
🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl! Don't be shy, join here: https://discord.gg/EMgGbDceNQ and follow here for daily tips and tricks: https://x.com/Scrapling_dev
The fastest path to AI-powered full stack observability, even for lean teams.