Docs · MCP
vetkit MCP server
Give your coding agent a code auditor. The vetkit MCP server lets Claude Code — and any other Model Context Protocol client — connect repositories, run audits and read findings and reports.
claude mcp add vetkit -e VETKIT_API_KEY=vk_live_... -- npx -y @vetkit/mcpThen ask your agent something like “Audit acme/payments-api and tell me what to fix first.” Run /mcp inside Claude Code to confirm that vetkit is connected.
Requirements
- Node.js 20.3 or newer, with
npxon yourPATH. - A vetkit account with the GitHub App installed on the repositories you want to audit.
- A vetkit API key (next step).
Create an API key
- Open Settings → API keys in the vetkit app. Only organization owners and admins can manage keys.
- Name the key after where it will live, for example “Claude Code — laptop”.
- Pick scopes. For full MCP functionality choose
repos:read,repos:write,audits:read,audits:write,findings:readandreports:read. For a read-only agent, leave outrepos:writeandaudits:write. - Optionally set an expiry and a per-minute rate limit (default 60, up to 600).
- Copy the secret. It looks like
vk_live_…and is shown once; vetkit stores only a hash.
Rotation and revocation
401 API_KEY_REVOKED.Install
Claude Code
claude mcp add vetkit -e VETKIT_API_KEY=vk_live_... -- npx -y @vetkit/mcpAdd --scope user to make vetkit available in every project instead of only the current one.
Claude Desktop
Open Settings → Developer → Edit Config and add vetkit to claude_desktop_config.json, then restart Claude Desktop:
{ "mcpServers": { "vetkit": { "command": "npx", "args": ["-y", "@vetkit/mcp"], "env": { "VETKIT_API_KEY": "vk_live_..." } } }}Cursor
Add the same block to ~/.cursor/mcp.json (global) or .cursor/mcp.json in a project. Do not commit a project config that contains your key.
{ "mcpServers": { "vetkit": { "command": "npx", "args": ["-y", "@vetkit/mcp"], "env": { "VETKIT_API_KEY": "vk_live_..." } } }}Other MCP clients
Any client that can launch a stdio server works: run npx -y @vetkit/mcp with VETKIT_API_KEY in its environment. You can also install the package globally and run the vetkit-mcp binary directly.
npm install -g @vetkit/mcpVETKIT_API_KEY=vk_live_... vetkit-mcpConfiguration
The server is configured entirely through environment variables.
| Variable | Required | Description |
|---|---|---|
VETKIT_API_KEY | Yes | Your API key, vk_live_… or vk_test_…. |
VETKIT_API_URL | No | API base URL. Default https://api.vetkit.dev. Must be HTTPS; plain HTTP is accepted only for localhost. |
VETKIT_ORG_ID | No | Organization id. Each API key belongs to exactly one organization, which is used by default, so you rarely need this. |
VETKIT_APP_URL | No | Web app URL used for links to audits. Default https://app.vetkit.dev. |
Tools
Every tool returns readable text, and all tools except vetkit_get_report also return typed structured content. Tools carry MCP annotations, so clients can auto-approve the read-only ones. None of the tools delete anything.
vetkit_list_repos
read-onlyLists repositories connected to your organization, with the latest audit’s grade and score.
Scopes: repos:read
| Argument | Type | Description |
|---|---|---|
limit | number | Page size, 1–100. Default 25. |
cursor | string | The nextCursor value from the previous page. |
{ "limit": 10 }vetkit_connect_repo
writesConnects a GitHub repository. If the vetkit GitHub App is not installed for the owner yet, returns outcome "installation_required" with an install URL to open in the browser.
Scopes: repos:write
| Argument | Type | Description |
|---|---|---|
urlrequired | string | GitHub URL (https://github.com/owner/name) or "owner/name". |
{ "url": "https://github.com/acme/payments-api" }vetkit_run_audit
writesStarts an audit and, by default, waits for it to finish while sending progress notifications. Connects the repository first if needed. Returns the grade, score and finding counts.
Scopes: repos:read, audits:write, audits:read (+ repos:write to auto-connect)
| Argument | Type | Description |
|---|---|---|
reporequired | string | Repository id, "owner/name", or a GitHub URL — including /tree/<branch>. |
ref | string | Branch, tag or commit SHA. Defaults to the ref in the URL, then the default branch. |
wait | boolean | Wait for a terminal status. Default true. |
timeoutSeconds | number | Maximum wait, 10–1800. Default 600. The audit keeps running after a timeout. |
{ "repo": "acme/payments-api", "ref": "main" }vetkit_get_audit
read-onlyReturns status, grade, score, finding counts and per-analyzer progress for one audit.
Scopes: audits:read
| Argument | Type | Description |
|---|---|---|
auditIdrequired | uuid | The audit id returned by vetkit_run_audit. |
{ "auditId": "0192f3a4-5b6c-7d8e-9f01-23456789abcd" }vetkit_list_findings
read-onlyLists findings for an audit, most severe first. Returns a compact table as text and full details — message, redacted snippet, remediation, references — as structured content.
Scopes: findings:read
| Argument | Type | Description |
|---|---|---|
auditIdrequired | uuid | The audit to read. |
severity | string[] | CRITICAL, HIGH, MEDIUM, LOW or INFO. |
category | string[] | SECURITY, SECRETS, DEPENDENCIES, QUALITY, HYGIENE or AI_SIGNAL. |
status | string | NEW (introduced since the previous audit) or EXISTING. |
limit | number | Page size, 1–100. Default 25. |
cursor | string | The nextCursor value from the previous page. |
{ "auditId": "0192f3a4-…", "severity": ["CRITICAL", "HIGH"] }vetkit_get_report
read-onlyReturns the report of a finished audit: readable Markdown, a JSON summary with category scores and the diff against the previous audit, or SARIF 2.1.0.
Scopes: reports:read
| Argument | Type | Description |
|---|---|---|
auditIdrequired | uuid | The audit to read. |
format | string | markdown (default), json or sarif. |
maxChars | number | Truncate output beyond this many characters, 2,000–500,000. Default 40,000. |
{ "auditId": "0192f3a4-…", "format": "markdown" }Long-running audits
Most audits finish in a few minutes. vetkit_run_audit polls every few seconds and sends progress notifications while it waits. Some clients cancel tool calls after a fixed time — Claude Code, for example, respects MCP_TOOL_TIMEOUT. If yours does, pass "wait": false and poll with vetkit_get_audit. When timeoutSeconds runs out, the audit keeps running and the tool returns "outcome": "still_running".
Errors
API errors come back as tool results with isError: true and include the HTTP status, vetkit error code, message, request id and a hint.
401 API_KEY_INVALID,API_KEY_REVOKED,API_KEY_EXPIRED— create or rotate a key, updateVETKIT_API_KEYand restart the server.403 INSUFFICIENT_SCOPE— the key lacks a scope the tool needs.409 AUDIT_CONCURRENCY_LIMITand429 RATE_LIMITED— wait and retry; the hint includes the delay when the API sendsRetry-After.INSTALLATION_REQUIREDis returned as a normal result with the GitHub App install URL, not as an error.
Security notes
- Treat the API key like a password. It grants access to your organization’s audits and findings, including private repositories. Keep it in your MCP client’s
envconfig, never in files you commit. Grant only the scopes you need, set an expiry, and revoke it from the app if it leaks. - The key is sent only to
VETKIT_API_URL, as anAuthorization: Bearerheader over HTTPS. The server never logs it or includes it in error messages. - The server speaks MCP over stdio only. It opens no network ports and logs only to stderr.
- Finding snippets are redacted before vetkit stores them; secret values are never returned.
- Report and finding text comes from the audited repository (file paths, messages). Treat it as untrusted input, like any other tool output — a malicious repository could try to embed instructions aimed at your agent.
Prefer raw HTTP? Everything the MCP server does is available through the REST API.