Diese Seite ist nur auf Englisch verfügbar.
AI agents over MCP
Connect Claude or ChatGPT to Vulnara over MCP so an AI assistant can read your findings, scans and repositories as you, read-only.
Vulnara runs an MCP server, so an AI assistant such as Claude or ChatGPT can read your Vulnara data and answer questions about it. The assistant signs in as you and sees exactly what you can see in the web app. It can read, but it cannot change anything.
What it is for
- Asking questions in plain language: "Which repositories have Critical findings?", "What did last night's scan find?", "Which secrets did more than one scanner report?"
- Letting an agent summarise findings, compare scans or draft a triage plan from real data.
- Giving people who do not use the web app every day a way to get answers.
How it works
The MCP server is at https://vulnara-mcp.rso.dev/mcp. When your AI client first connects, the server asks it to sign in. The client sends you to the normal Vulnara sign-in page, you sign in with your own account, and the client receives its own token. You never paste a token or a password into the AI client.
Each tool the assistant calls is one read operation of the Vulnara API. Vulnara checks your role in the workspace on every call, the same way it does for the web app. If you lose access to something, the assistant loses it too.
The tools are generated from the read operations of the API. The full list is on the MCP reference.
What you can set
- MCP URL:
https://vulnara-mcp.rso.dev/mcp - OAuth client ID:
hl04e6MSMRY60LdpGh5rdMRQjkPxvldAYoqXdzo4 - workspace: an optional argument on every workspace tool. It names the workspace to read.
- cursor: an optional argument on list tools. It fetches the next page of a long list.
Do it
Connect Claude
Add a custom connector
In Claude, open Settings, then Connectors, and choose Add custom connector.
Enter the connection details
Paste the MCP URL
https://vulnara-mcp.rso.dev/mcp. Under the advanced settings, choose to use your own OAuth client and paste the client IDhl04e6MSMRY60LdpGh5rdMRQjkPxvldAYoqXdzo4.Sign in from Claude
Claude opens the Vulnara sign-in page. Sign in with your Vulnara account and approve the request.
Ask a question
For example: "List my Vulnara workspaces, then show the Critical findings in the first one."
Connect ChatGPT
Turn on developer mode
In ChatGPT's settings, enable developer mode.
Create an app
Create an app with the MCP URL
https://vulnara-mcp.rso.dev/mcpand the OAuth client IDhl04e6MSMRY60LdpGh5rdMRQjkPxvldAYoqXdzo4.Sign in from ChatGPT
Sign in with your Vulnara account when ChatGPT asks, and approve the request.
Connection snippets for other MCP clients are on the MCP reference.
Choose a workspace
If you belong to one workspace, every tool uses it and you never need to name it.
If you belong to several, ask the assistant to call list_workspaces first. It returns the workspaces you belong to. The assistant then passes one as the workspace argument of the tools it calls. Without that argument, Vulnara picks one of your workspaces for you, which may not be the one you meant.
Good to know
What is never exposed
Some data stays out of reach of the assistant even when you can see it in the web app:
- git tokens and their values, and token checks;
- service accounts;
- invitations;
- invoices, payment methods, plans and usage;
- the raw secret a scanner matched in a finding;
- email addresses;
- alert rule recipients and webhook headers;
- repository clone URLs;
- any field whose name suggests a token, secret or password.
On top of that, every result is checked for values that look like credentials, such as GitHub and GitLab tokens, Slack tokens, AWS access key ids, JSON web tokens, private keys and authorization headers. They are replaced with [REDACTED:<kind>] before the assistant sees them.
Output size
- Pages of 25: list tools return 25 rows at a time, with how many rows matched in total. When there are more, the result ends with a cursor. The assistant passes it back as
cursorto get the next page. - Cursors expire: a cursor works for 15 minutes, and only for the same tool, arguments and account. After that, the assistant asks for the list again.
- A cap per result: a single result is limited to 50,000 characters. A longer result is cut and ends with a note to ask for fewer items or narrow the filters. Filters and smaller pages give better answers than one large dump.
Treat scanned text as data
Findings, file paths, repository names and commit messages come from the code and hosts that were scanned. Anyone who can write to a scanned repository can put text there. Your assistant should treat that text as data to report, never as instructions to follow.
When something goes wrong
- "The product rejected your credential. Sign in again.": your sign-in expired or was revoked. Reconnect in your AI client.
- "The product refused the request": Vulnara refused the call, usually because your role does not allow it or the id does not exist in that workspace. See Teams and roles.
- "You do not belong to any workspace in this product.": your account is not a member of any workspace yet. Ask a workspace admin to invite you.