codeant mcp over stdio, so you don’t run it yourself. Run by hand, it waits for input and prints nothing.
The server is read-only by default and exposes 24 tools: 22 read tools plus
codeant_login and codeant_logout. Three write tools are added only when you set CODEANT_READ_ONLY=0. See the MCP tool reference for every tool’s parameters.Prerequisites
- A CodeAnt AI account. The cloud security and pentest tools return data only if your organization uses those CodeAnt AI products.
-
CodeAnt CLI 0.5.10 or later and Node.js 18 or later. Skip this if you use the Claude Desktop extension, which doesn’t need either.
- For the pull request and comment tools, a token for your Git provider. See Pull request tools.
Install
Pick your client. After editing a client’s MCP configuration, restart the client.- Claude Code
- Claude Code plugin
- Claude Desktop
- Cursor
- VS Code
- Windsurf / Devin Desktop
- Zed
- Codex CLI
- Other clients
Add the server at user scope so it’s available in every project:Use
--scope project instead to write the configuration to .mcp.json at the repository root and share it with your team.Run /mcp in Claude Code and confirm that codeant shows as connected. Claude Code starts the server in your project directory, so codeant_review_local and the pull request tools find your repository automatically.Authenticate
The server picks its CodeAnt token in this order:CODEANT_API_TOKENin the MCP server’s environment, including the desktop extension’s CodeAnt API token setting.- The token saved in
~/.codeant/config.jsonbycodeant login,codeant set-codeant-api-key, or thecodeant_logintool. The server reads this file on every request, so signing in or out in a terminal takes effect without restarting the client.
1
Start sign-in
The agent calls
codeant_login. It returns right away with status: "pending" and a loginUrl, and opens the link in your browser when it can. If no browser opens (for example over SSH or in a container), open loginUrl yourself.2
Sign in
Sign in to CodeAnt AI in the browser within 10 minutes. You can close the tab when sign-in completes.
3
Confirm
Tell the agent you’ve finished. It calls
codeant_login again and gets status: "success". The server checks for completion about every 10 seconds, so if it still returns pending, wait a few seconds and ask again.codeant_login returns alreadyLoggedIn: true. When the token is rejected (Invalid API key, or access denied after an upgrade), the agent calls codeant_login with force: true to start a new sign-in. To switch accounts, ask the agent to sign in again with force: true.
codeant_logout revokes the token on the server, removes it from ~/.codeant/config.json, and cancels a pending sign-in. The CLI and the MCP server share that file, so logging out from either one logs out both.
On a self-hosted CodeAnt AI instance, codeant_login needs your dashboard URL. See Self-hosted CodeAnt AI.
Tools
The Hotlist, anti-pattern, cloud, pentest, and API tools act on one organization connection. Ifcodeant_scans_orgs lists more than one, pass org and service to those tools, and org to codeant_scans_repos. For parameters and responses, see the MCP tool reference.
Repositories and scans
Organization findings
Pull requests and local review
API passthrough and authentication
Example agent requests
- “List my repositories, then show critical SAST findings for the API repository.”
- “Show the ten highest-priority Hotlist findings.”
- “Show failing high-severity checks from the latest AWS CSPM scan.”
- “Fetch this Hotlist finding by its stable ID and explain the remediation.”
- “List the open issues in the latest pentest engagement.”
- “Review my staged changes with CodeAnt.” This needs a client that starts the server in your repository, such as Claude Code.
Configuration reference
Add variables to theenv object of the codeant entry you created in Install:
config.toml, add a [mcp_servers.codeant.env] table. On the command line, pass --env KEY=value (or -e) to claude mcp add or codex mcp add. In claude mcp add, put another option such as --transport stdio between -e and the server name.
The Git provider variables are listed under Pull request tools.
Pull request tools
codeant_pr_list, codeant_pr_get, codeant_pr_comments, and codeant_comments_search call your Git provider’s API directly, so they need a token for that provider. The server checks these sources in order:
The
gh and glab fallbacks work only when those CLIs are on the client’s PATH. Tokens saved with codeant set-token work in every client.
Working directory and repository detection
codeant_review_local reviews the git repository in the server’s working directory. The pull request tools detect name and remote from that repository’s origin remote.
- Claude Code starts the server in your project, so both work without extra parameters.
- Claude Desktop, with the extension or a manual configuration, starts it outside your projects. Pass
name(owner/repo) andremote(github,gitlab,bitbucket, orazure) to the pull request tools. Local review isn’t available. - Other clients: ask the agent to run
codeant_review_local. If it returnsCould not find a .git directory, the client starts the server outside your repository. Passnameandremoteto the pull request tools, and runcodeant reviewin a terminal for local review. - Azure DevOps: always pass
nameasproject/repo. Detection from Azure DevOps remote URLs doesn’t produce that form.
Self-hosted CodeAnt AI
Set both URLs in the server’s environment, or save them once with the CLI:
In the Claude Desktop extension, set API base URL and Dashboard URL in the extension settings instead. The extension’s settings take precedence over values saved with the CLI.
The CLI asks your instance for its dashboard URL. If
codeant_login fails with Could not determine the dashboard URL, set it explicitly. For self-hosted Git providers, see Pull request tools.
Enable write tools
SetCODEANT_READ_ONLY=0 only when the MCP client should be allowed to change external state. Add it to the env object of the codeant entry:
Approve tools automatically
Every read tool is marked read-only (readOnlyHint), so clients can approve it without prompting. codeant_login and codeant_logout aren’t, so clients still ask before signing in or out.
In Claude Code, add rules to permissions.allow in ~/.claude/settings.json (all projects) or .claude/settings.json (one project):
mcp__plugin_codeant_codeant__ instead of mcp__codeant__.
Results and paging
MCP clients limit how much tool output they accept. Claude Code, for example, caps it at 25,000 tokens by default. The server keeps results small:-
One page per call. Most list tools return a total and take
limitandoffset, but some differ: the Hotlist usescursorandnext_cursor,codeant_pr_listreturns no total, andcodeant_scans_historytakes nooffset. See each tool in the MCP tool reference for its paging fields. -
Small default page sizes:
-
Slim records. Repository lists, cloud scan history, cloud findings, and pentest history leave out bulky fields such as raw provider metadata, per-service rollups, compliance mappings, and billing details. Pass
full: trueto include them. -
Size limit. The server refuses any result over 80,000 characters (about 20,000 tokens) and returns a hint for narrowing the request. If your client accepts larger results, raise
CODEANT_MCP_MAX_RESULT_CHARSin the server’s environment. In Claude Code, also start Claude Code with a higherMAX_MCP_OUTPUT_TOKENS, for exampleMAX_MCP_OUTPUT_TOKENS=50000 claude. The desktop extension doesn’t have a setting for the limit.
Privacy and telemetry
- Tools send requests to the CodeAnt API with your token. The pull request tools call your Git provider directly.
codeant_review_localsends the diff and the full current contents of each changed file to CodeAnt for review. While reviewing, CodeAnt can also read, list, and search other files in the repository for context. The tool never modifies files.- Local reviews send usage events to PostHog. The events are tied to your CodeAnt API token and can include review error messages. To turn them off, set
CODEANT_TELEMETRY_DISABLED=1in the server’s environment, runcodeant set-telemetry false(not in the desktop extension), or enable Disable telemetry in the desktop extension.
Troubleshooting
To test the server outside your client, open it in the MCP Inspector:
MCP tool reference
Parameters, defaults, and key response fields for every tool.
Findings
Query repository, Hotlist, cloud-security, and pentest findings from the CLI.
SCM and PR tools
Manage pull requests, comments, and review data.
Claude Code integration
Slash-command skills that review and fix code with the CodeAnt CLI.