Skip to content
vetkit

Docs · MCP

vetkit MCP server

Give your coding agent a code auditor. The vetkit MCP server lets Claude Code — and any other Model Context Protocol client — connect repositories, run audits and read findings and reports.

Install in Claude Code
claude mcp add vetkit -e VETKIT_API_KEY=vk_live_... -- npx -y @vetkit/mcp

Then ask your agent something like “Audit acme/payments-api and tell me what to fix first.” Run /mcp inside Claude Code to confirm that vetkit is connected.

Requirements

  • Node.js 20.3 or newer, with npx on your PATH.
  • A vetkit account with the GitHub App installed on the repositories you want to audit.
  • A vetkit API key (next step).

Create an API key

  1. Open Settings → API keys in the vetkit app. Only organization owners and admins can manage keys.
  2. Name the key after where it will live, for example “Claude Code — laptop”.
  3. Pick scopes. For full MCP functionality choose repos:read, repos:write, audits:read, audits:write, findings:read and reports:read. For a read-only agent, leave out repos:write and audits:write.
  4. Optionally set an expiry and a per-minute rate limit (default 60, up to 600).
  5. Copy the secret. It looks like vk_live_… and is shown once; vetkit stores only a hash.

Rotation and revocation

Rotating a key issues a new secret and keeps the old one valid for 24 hours so you can roll it out. Revoking takes effect immediately — the next request returns 401 API_KEY_REVOKED.

Install

Claude Code

Terminal
claude mcp add vetkit -e VETKIT_API_KEY=vk_live_... -- npx -y @vetkit/mcp

Add --scope user to make vetkit available in every project instead of only the current one.

Claude Desktop

Open Settings → Developer → Edit Config and add vetkit to claude_desktop_config.json, then restart Claude Desktop:

claude_desktop_config.json
{  "mcpServers": {    "vetkit": {      "command": "npx",      "args": ["-y", "@vetkit/mcp"],      "env": { "VETKIT_API_KEY": "vk_live_..." }    }  }}

Cursor

Add the same block to ~/.cursor/mcp.json (global) or .cursor/mcp.json in a project. Do not commit a project config that contains your key.

~/.cursor/mcp.json
{  "mcpServers": {    "vetkit": {      "command": "npx",      "args": ["-y", "@vetkit/mcp"],      "env": { "VETKIT_API_KEY": "vk_live_..." }    }  }}

Other MCP clients

Any client that can launch a stdio server works: run npx -y @vetkit/mcp with VETKIT_API_KEY in its environment. You can also install the package globally and run the vetkit-mcp binary directly.

Global install
npm install -g @vetkit/mcpVETKIT_API_KEY=vk_live_... vetkit-mcp

Configuration

The server is configured entirely through environment variables.

VariableRequiredDescription
VETKIT_API_KEYYesYour API key, vk_live_… or vk_test_….
VETKIT_API_URLNoAPI base URL. Default https://api.vetkit.dev. Must be HTTPS; plain HTTP is accepted only for localhost.
VETKIT_ORG_IDNoOrganization id. Each API key belongs to exactly one organization, which is used by default, so you rarely need this.
VETKIT_APP_URLNoWeb app URL used for links to audits. Default https://app.vetkit.dev.

Tools

Every tool returns readable text, and all tools except vetkit_get_report also return typed structured content. Tools carry MCP annotations, so clients can auto-approve the read-only ones. None of the tools delete anything.

vetkit_list_repos

read-only

Lists repositories connected to your organization, with the latest audit’s grade and score.

Scopes: repos:read

ArgumentTypeDescription
limitnumberPage size, 1–100. Default 25.
cursorstringThe nextCursor value from the previous page.
Example arguments
{ "limit": 10 }

vetkit_connect_repo

writes

Connects a GitHub repository. If the vetkit GitHub App is not installed for the owner yet, returns outcome "installation_required" with an install URL to open in the browser.

Scopes: repos:write

ArgumentTypeDescription
urlrequiredstringGitHub URL (https://github.com/owner/name) or "owner/name".
Example arguments
{ "url": "https://github.com/acme/payments-api" }

vetkit_run_audit

writes

Starts an audit and, by default, waits for it to finish while sending progress notifications. Connects the repository first if needed. Returns the grade, score and finding counts.

Scopes: repos:read, audits:write, audits:read (+ repos:write to auto-connect)

ArgumentTypeDescription
reporequiredstringRepository id, "owner/name", or a GitHub URL — including /tree/<branch>.
refstringBranch, tag or commit SHA. Defaults to the ref in the URL, then the default branch.
waitbooleanWait for a terminal status. Default true.
timeoutSecondsnumberMaximum wait, 10–1800. Default 600. The audit keeps running after a timeout.
Example arguments
{ "repo": "acme/payments-api", "ref": "main" }

vetkit_get_audit

read-only

Returns status, grade, score, finding counts and per-analyzer progress for one audit.

Scopes: audits:read

ArgumentTypeDescription
auditIdrequireduuidThe audit id returned by vetkit_run_audit.
Example arguments
{ "auditId": "0192f3a4-5b6c-7d8e-9f01-23456789abcd" }

vetkit_list_findings

read-only

Lists findings for an audit, most severe first. Returns a compact table as text and full details — message, redacted snippet, remediation, references — as structured content.

Scopes: findings:read

ArgumentTypeDescription
auditIdrequireduuidThe audit to read.
severitystring[]CRITICAL, HIGH, MEDIUM, LOW or INFO.
categorystring[]SECURITY, SECRETS, DEPENDENCIES, QUALITY, HYGIENE or AI_SIGNAL.
statusstringNEW (introduced since the previous audit) or EXISTING.
limitnumberPage size, 1–100. Default 25.
cursorstringThe nextCursor value from the previous page.
Example arguments
{ "auditId": "0192f3a4-…", "severity": ["CRITICAL", "HIGH"] }

vetkit_get_report

read-only

Returns the report of a finished audit: readable Markdown, a JSON summary with category scores and the diff against the previous audit, or SARIF 2.1.0.

Scopes: reports:read

ArgumentTypeDescription
auditIdrequireduuidThe audit to read.
formatstringmarkdown (default), json or sarif.
maxCharsnumberTruncate output beyond this many characters, 2,000–500,000. Default 40,000.
Example arguments
{ "auditId": "0192f3a4-…", "format": "markdown" }

Long-running audits

Most audits finish in a few minutes. vetkit_run_audit polls every few seconds and sends progress notifications while it waits. Some clients cancel tool calls after a fixed time — Claude Code, for example, respects MCP_TOOL_TIMEOUT. If yours does, pass "wait": false and poll with vetkit_get_audit. When timeoutSeconds runs out, the audit keeps running and the tool returns "outcome": "still_running".

Errors

API errors come back as tool results with isError: true and include the HTTP status, vetkit error code, message, request id and a hint.

  • 401 API_KEY_INVALID, API_KEY_REVOKED, API_KEY_EXPIRED — create or rotate a key, update VETKIT_API_KEY and restart the server.
  • 403 INSUFFICIENT_SCOPE — the key lacks a scope the tool needs.
  • 409 AUDIT_CONCURRENCY_LIMIT and 429 RATE_LIMITED — wait and retry; the hint includes the delay when the API sends Retry-After.
  • INSTALLATION_REQUIRED is returned as a normal result with the GitHub App install URL, not as an error.

Security notes

  • Treat the API key like a password. It grants access to your organization’s audits and findings, including private repositories. Keep it in your MCP client’s env config, never in files you commit. Grant only the scopes you need, set an expiry, and revoke it from the app if it leaks.
  • The key is sent only to VETKIT_API_URL, as an Authorization: Bearer header over HTTPS. The server never logs it or includes it in error messages.
  • The server speaks MCP over stdio only. It opens no network ports and logs only to stderr.
  • Finding snippets are redacted before vetkit stores them; secret values are never returned.
  • Report and finding text comes from the audited repository (file paths, messages). Treat it as untrusted input, like any other tool output — a malicious repository could try to embed instructions aimed at your agent.

Prefer raw HTTP? Everything the MCP server does is available through the REST API.