mcp server · pro plan
Let your agent check its own work.
VibeProtect runs a hosted MCP server, so Cursor, Claude Code, Windsurf and other MCP clients can scan your app, read the findings and their fix prompts, make the changes and scan again. You watch it go green instead of copying prompts back and forth.
server details
What you are connecting to
| Endpoint | https://75c36bbx12.execute-api.us-east-1.amazonaws.com/prod/mcp |
|---|---|
| Transport | Streamable HTTP |
| Sign-in | OAuth in the browser where your client supports it, or an API key from the app sent as Authorization: Bearer |
| Reach | Only apps your account has verified, and repos you connected through the GitHub App |
| Plan | Pro (pricing) |
connect a client
Set it up in a minute
Cursor
Add this to ~/.cursor/mcp.json (or .cursor/mcp.json in your project). Cursor opens a browser window to sign in the first time.
{
"mcpServers": {
"vibeprotect": {
"url": "https://75c36bbx12.execute-api.us-east-1.amazonaws.com/prod/mcp"
}
}
}
Prefer an API key (for CI, or a client without OAuth)? Create one in the app and send it as a header:
{
"mcpServers": {
"vibeprotect": {
"url": "https://75c36bbx12.execute-api.us-east-1.amazonaws.com/prod/mcp",
"headers": { "Authorization": "Bearer YOUR_API_KEY" }
}
}
}
Claude Code
claude mcp add --transport http vibeprotect https://75c36bbx12.execute-api.us-east-1.amazonaws.com/prod/mcp
Then run /mcp in a session to sign in. With an API key instead:
claude mcp add --transport http vibeprotect https://75c36bbx12.execute-api.us-east-1.amazonaws.com/prod/mcp \
--header "Authorization: Bearer YOUR_API_KEY"
Windsurf
Add the server to ~/.codeium/windsurf/mcp_config.json:
{
"mcpServers": {
"vibeprotect": {
"serverUrl": "https://75c36bbx12.execute-api.us-east-1.amazonaws.com/prod/mcp",
"headers": { "Authorization": "Bearer YOUR_API_KEY" }
}
}
}
Other MCP clients
Anything that can add a remote MCP server by URL over Streamable HTTP can connect. Use the endpoint above, with OAuth or the API key header.
try it
Then just ask
Your agent sees the same findings you do, including the fix prompt for each one, so it knows what to change and how to check it worked.
Scan my app with VibeProtect. Fix every critical and high finding using its fix prompt, one at a time, then run the scan again and tell me what is left.
tools
What the server offers
Your client always gets the live list from tools/list. This is the human-readable version.
| Tool | What it does |
|---|---|
list_apps | Your apps, their addresses, whether each one is verified, linked repo and latest grades |
add_app | Register a deployed app by its address; returns the verification file or meta tag to add |
verify_app | Check the verification file or meta tag after you deploy it |
scan_app | Start a live app scan or a repo scan of one of your apps; returns a scan id |
get_findings | The findings from a scan, most serious first, each with its plain explanation, file and line (repo scans) and fix prompt |
list_scans | Recent scans and their grades, for all apps or one |
list_changes | What moved between scans: new issues, fixed issues, grade changes |
set_triage | Mute or accept a finding you meant to have, with a review date |
get_account | Your plan and how much of it you have used this month |
questions
MCP questions
Can the agent scan any website it likes?
No. The MCP server goes through the same gate as the app: it can only scan apps your account has verified, at their exact address. Asking it to scan someone else's site fails the same way it would in the dashboard.
Which plan do I need?
Pro. The MCP server and API keys are part of the Pro plan, and scans started by your agent count the same as scans you start yourself. See pricing.
Will my agent see my secret keys?
No, because we do not keep them. Findings carry the redacted form (like
sk-proj-Ab…9xQ) and the file and line, which is all the agent needs to remove
the key from the code. Rotating the key is still on you.
How do I cut off access?
Delete the API key in the app, or disconnect the client if you signed in with OAuth. It stops working on its next request.