Diese Seite ist nur auf Englisch verfügbar.
Quick start for AI users
Connect Claude or ChatGPT to Vulnara, sign in with your Vulnara account, choose a workspace and ask questions about your security findings.
Vulnara has an MCP server, so an AI assistant such as Claude or ChatGPT can read your workspace and answer questions about it: which repositories have critical findings, what the last scans found, how your security score is moving. This guide connects your assistant and gets you a first answer.
You need a Vulnara account that belongs to at least one workspace, and an AI client plan that allows custom connectors.
Copy the connection details
You need two values:
- MCP URL:
https://vulnara-mcp.rso.dev/mcp - Client ID:
hl04e6MSMRY60LdpGh5rdMRQjkPxvldAYoqXdzo4
Neither is a password. The client ID is the same for every customer. Access is protected by your own Vulnara sign-in, and you never paste a token.
- MCP URL:
Add Vulnara to your AI client
Claude (claude.ai and Claude Desktop): open Settings, then Connectors, and choose Add custom connector. Paste the MCP URL. Open the advanced settings, choose to use your own OAuth client, and paste the client ID. On Claude Team and Enterprise, an Owner adds the connector once and each member then signs in individually.
ChatGPT: turn on developer mode, then create an app with the same MCP URL and client ID.
Claude Code and other MCP clients: see MCP.
Sign in with your Vulnara account
Your client opens the Vulnara sign-in page. Sign in with the same account you use for the web app, and approve the request. The assistant now acts as you, with your role in each workspace, and never with more.
Choose a workspace
If you belong to one workspace, there is nothing to choose. If you belong to several, ask the assistant which workspaces you have, then tell it which one to use. It lists them with list_workspaces and passes the one you pick to every other tool.
Ask a question
Try one of these:
- "Which of my repositories has the lowest security score?"
- "Summarise the dashboard for the last 30 days."
- "List the critical and high findings in the repository called payments-api."
- "What did the most recent scan of my main repository find?"
- "Show me the triage decisions taken on this repository, newest first."
The assistant should say which workspace it read from. If the answer looks wrong, check that first.
What the assistant can and cannot do
- Read-only: every tool reads. The assistant cannot start scans, change settings, triage findings or delete anything, even if you are an ADMIN.
- Your permissions only: the assistant sees what you can see in the web app, checked on every call. If your role changes, the next call uses the new role.
- Never exposed: git tokens, service accounts, billing and invoices, and the raw values of secrets that scanners found. Credential-shaped values are removed from results.
- Untrusted text is marked: file paths, repository names and similar text come from your repositories, and anyone who can commit to them controls it. The server marks that text as data, so a well-behaved assistant does not follow instructions hidden in it.
- Large results are paged: long lists come back a page at a time. Ask the assistant to read further pages if it stops early.
The full list of tools is in the MCP reference.