Snyk
About
Enhance security posture by embedding Snyk vulnerability scanning directly into agentic workflows.
Explore
- Trigger security scans for open‑source, code, and configuration issues.
- Retrieve Snyk findings directly in your MCP‑enabled environment.
- Supports stdio and SSE transport protocols.
- Provides authentication (snyk_auth) and version (snyk_version) tools.
- Early Access feature – usage and parameters may evolve.
- No extra dependencies beyond the Snyk CLI.
Setting up with Highlight
This MCP is not yet compatible with Highlight’s one-click setup. However, you can still use it with Highlight by following these steps:
- Download and install Highlight from highlightai.com/download
- Navigate to the plugins tab and select "Add Custom Plugin"
-
Configure the plugin with the settings below
Plugin Name
SnykCommand (node, npx, python, etc.)Please refer to the README for specific instructions on how to obtain API keys or other required environment variables.
- Enable "Start Automatically" if you want the plugin to start when Highlight launches
From the repository
To add an MCP server, check the documentation for the AI system where you plan to integrate Snyk and review the specific MCP instructions. Examples of systems where you can integrate Snyk include Windsurf's MCP, Qodo's MCP support, and VS Code MCP support.
You may need to create or modify an mcpconfig.json file. This assumes that the Snyk CLI is in your system path and can be invoked with the command snyk. If the CLI is not in your system path, you can provide the full path to the CLI.
The following examples show how to add the Snyk MCP server in the mcpconfig.json file for each transport type.
{
"mcpServers": {
"Snyk Security Scanner": {
"command": "snyk",
"args": [
"mcp",
"-t",
"stdio",
"--experimental"
]
}
}
}
If your MCP Client expects a URL, then you will need to start the MCP server in your terminal first by running snyk mcp -t sse --experimental 
This will output the base URL for your local SSE server. The sse endpoint lives on http://baseUrl/sse.
{
"mcpServers": {
"Snyk Security Scanner": {
"url": "http://baseUrl/sse",
}
}
}
snyk_sca_test
(Open Source scans)
snyk_code_test
(Code scans)
snyk_auth
(authentication)
snyk_logout
(logout)
snyk_auth_status
(authentication status check)
snyk_version
(version information)
 The Snyk MCP server supports integrating the following Snyk security tools into an AI system:
- snyk_sca_test (Open Source scans)
- snyk_code_test (Code scans)
- snyk_auth (authentication)
- snyk_logout (logout)
- snyk_auth_status (authentication status check)
- snyk_version (version information)
Claude Desktop / Cursor
Paste into your MCP client config file to install this server.
{
"mcpServers": {
"snyk": {
"Snyk Security Scanner": {
"command": "snyk",
"args": [
"mcp",
"-t",
"stdio",
"--experimental"
]
}
}
}
}
McpServers
{
"Snyk Security Scanner": {
"command": "snyk",
"args": [
"mcp",
"-t",
"stdio",
"--experimental"
]
}
}
To bridge the gap between security scanning and emerging AI-assisted workflows, Snyk is introducing an MCP server as part of the Snyk CLI. This will allow MCP-enabled tools and contexts to integrate Snyk security scanning capabilities directly.
In environments or applications that use MCP, you can use the snyk mcp CLI command to:
- Invoke Snyk scans:\
Trigger security scans for code, dependencies, or configurations in your codebase in your current MCP context.
- Retrieve results:\
Obtain Snyk security findings directly in your MCP-enabled tool or environment.
To use the Snyk MCP server, download and install the Snyk CLI v1.1296.2 or later following the steps on the installation page. No other dependencies are needed. Snyk recommends always using the latest version of the CLI.
The snyk mcp command is available in Early Access, under the --experimental flag for the following reasons:
- MCP is a new and evolving standard.
- The snyk mcp command is an early implementation of integrating Snyk security scanning into the MCP ecosystem.
- Snyk wants to gather feedback on the benefits of MCP as an integration pattern for Snyk security.
Because the snyk mcp command is an experimental feature, the specific usage, parameters, and output related to this command may evolve as both MCP and this Snyk integration mature. Changes are possible before a general release.
Sign in to leave a review
Use Google, GitHub, or an email account so ratings stay tied to real people.
No reviews posted yet.



