Documentation
Build with vetkit
Everything you can do in the vetkit app is available programmatically. Start with an API key, then pick the interface that fits your workflow.
- MCP serverGive Claude Code or any MCP client tools to connect repos, run audits and read findings.
- REST APIAuthenticate with an API key, start audits from CI, poll for results and download SARIF.
Quickstart
- Request early access. Once you are in, sign in with GitHub and install the vetkit GitHub App on the repositories you want to audit.
- In the app, open Settings → API keys and create a key with the scopes you need. The secret is shown once — store it in your password manager or secret store.
- Follow the MCP guide to use vetkit from your coding agent, or the API guide to call it from scripts and CI.
Concepts
- Organization — owns repositories, audits and API keys. Everyone gets a personal organization; team organizations add members with roles.
- Repository — a GitHub repository connected through the vetkit GitHub App.
- Audit — one run of all analyzers against a specific commit. Status moves from
QUEUEDtoRUNNINGtoSUCCEEDED,FAILEDorCANCELLED. - Finding — a single issue with category, severity, rule, file and line. Findings are fingerprinted, so re-audits mark them as new or existing.
- Report — the graded summary of an audit, available as JSON, Markdown or SARIF 2.1.0.