mcp server · pro plan

Let your agent check its own work.

VibeProtect runs a hosted MCP server, so Cursor, Claude Code, Windsurf and other MCP clients can scan your app, read the findings and their fix prompts, make the changes and scan again. You watch it go green instead of copying prompts back and forth.

server details

What you are connecting to

Endpointhttps://75c36bbx12.execute-api.us-east-1.amazonaws.com/prod/mcp
TransportStreamable HTTP
Sign-inOAuth in the browser where your client supports it, or an API key from the app sent as Authorization: Bearer
ReachOnly apps your account has verified, and repos you connected through the GitHub App
PlanPro (pricing)

connect a client

Set it up in a minute

Cursor

Add this to ~/.cursor/mcp.json (or .cursor/mcp.json in your project). Cursor opens a browser window to sign in the first time.

{
  "mcpServers": {
    "vibeprotect": {
      "url": "https://75c36bbx12.execute-api.us-east-1.amazonaws.com/prod/mcp"
    }
  }
}

Prefer an API key (for CI, or a client without OAuth)? Create one in the app and send it as a header:

{
  "mcpServers": {
    "vibeprotect": {
      "url": "https://75c36bbx12.execute-api.us-east-1.amazonaws.com/prod/mcp",
      "headers": { "Authorization": "Bearer YOUR_API_KEY" }
    }
  }
}

Claude Code

claude mcp add --transport http vibeprotect https://75c36bbx12.execute-api.us-east-1.amazonaws.com/prod/mcp

Then run /mcp in a session to sign in. With an API key instead:

claude mcp add --transport http vibeprotect https://75c36bbx12.execute-api.us-east-1.amazonaws.com/prod/mcp \
  --header "Authorization: Bearer YOUR_API_KEY"

Windsurf

Add the server to ~/.codeium/windsurf/mcp_config.json:

{
  "mcpServers": {
    "vibeprotect": {
      "serverUrl": "https://75c36bbx12.execute-api.us-east-1.amazonaws.com/prod/mcp",
      "headers": { "Authorization": "Bearer YOUR_API_KEY" }
    }
  }
}

Other MCP clients

Anything that can add a remote MCP server by URL over Streamable HTTP can connect. Use the endpoint above, with OAuth or the API key header.

try it

Then just ask

Your agent sees the same findings you do, including the fix prompt for each one, so it knows what to change and how to check it worked.

Ask your agent click to select

Scan my app with VibeProtect. Fix every critical and high finding using its fix prompt, one at a time, then run the scan again and tell me what is left.

tools

What the server offers

Your client always gets the live list from tools/list. This is the human-readable version.

ToolWhat it does
list_appsYour apps, their addresses, whether each one is verified, linked repo and latest grades
add_appRegister a deployed app by its address; returns the verification file or meta tag to add
verify_appCheck the verification file or meta tag after you deploy it
scan_appStart a live app scan or a repo scan of one of your apps; returns a scan id
get_findingsThe findings from a scan, most serious first, each with its plain explanation, file and line (repo scans) and fix prompt
list_scansRecent scans and their grades, for all apps or one
list_changesWhat moved between scans: new issues, fixed issues, grade changes
set_triageMute or accept a finding you meant to have, with a review date
get_accountYour plan and how much of it you have used this month

questions

MCP questions

Can the agent scan any website it likes?

No. The MCP server goes through the same gate as the app: it can only scan apps your account has verified, at their exact address. Asking it to scan someone else's site fails the same way it would in the dashboard.

Which plan do I need?

Pro. The MCP server and API keys are part of the Pro plan, and scans started by your agent count the same as scans you start yourself. See pricing.

Will my agent see my secret keys?

No, because we do not keep them. Findings carry the redacted form (like sk-proj-Ab…9xQ) and the file and line, which is all the agent needs to remove the key from the code. Rotating the key is still on you.

How do I cut off access?

Delete the API key in the app, or disconnect the client if you signed in with OAuth. It stops working on its next request.