Skip to main content
The CodeAnt AI CLI includes a Model Context Protocol (MCP) server. It gives AI agents structured tools for repository scans, the organization Hotlist, cloud security, pentesting, pull requests, and local code review. Your MCP client starts the server with codeant mcp over stdio, so you don’t run it yourself. Run by hand, it waits for input and prints nothing.
The server is read-only by default and exposes 24 tools: 22 read tools plus codeant_login and codeant_logout. Three write tools are added only when you set CODEANT_READ_ONLY=0. See the MCP tool reference for every tool’s parameters.

Prerequisites

  • A CodeAnt AI account. The cloud security and pentest tools return data only if your organization uses those CodeAnt AI products.
  • CodeAnt CLI 0.5.10 or later and Node.js 18 or later. Skip this if you use the Claude Desktop extension, which doesn’t need either.
  • For the pull request and comment tools, a token for your Git provider. See Pull request tools.

Install

Pick your client. After editing a client’s MCP configuration, restart the client.
Add the server at user scope so it’s available in every project:
Use --scope project instead to write the configuration to .mcp.json at the repository root and share it with your team.Run /mcp in Claude Code and confirm that codeant shows as connected. Claude Code starts the server in your project directory, so codeant_review_local and the pull request tools find your repository automatically.
Check the connection: ask your agent to “list my CodeAnt organizations”. If you haven’t signed in yet, the agent offers to sign you in. Continue with Authenticate.
GUI clients such as Claude Desktop, Cursor, VS Code, Windsurf, and Zed don’t load your shell profile. That affects two things:
  • Finding the CLI. If the client reports codeant: command not found, use the absolute path from which codeant as command. With nvm, the client can’t find node either: set command to the absolute path from which node, and args to ["<npm root -g>/codeant-cli/src/index.js", "mcp"], using the output of npm root -g. Update both paths when you switch Node versions.
  • Environment variables. Variables exported in your shell, such as GITHUB_TOKEN, don’t reach the server. Add them to the server’s env block. See Configuration reference.

Authenticate

The server picks its CodeAnt token in this order:
  1. CODEANT_API_TOKEN in the MCP server’s environment, including the desktop extension’s CodeAnt API token setting.
  2. The token saved in ~/.codeant/config.json by codeant login, codeant set-codeant-api-key, or the codeant_login tool. The server reads this file on every request, so signing in or out in a terminal takes effect without restarting the client.
If neither is set, ask your agent to sign in to CodeAnt:
1

Start sign-in

The agent calls codeant_login. It returns right away with status: "pending" and a loginUrl, and opens the link in your browser when it can. If no browser opens (for example over SSH or in a container), open loginUrl yourself.
2

Sign in

Sign in to CodeAnt AI in the browser within 10 minutes. You can close the tab when sign-in completes.
3

Confirm

Tell the agent you’ve finished. It calls codeant_login again and gets status: "success". The server checks for completion about every 10 seconds, so if it still returns pending, wait a few seconds and ask again.
If a token is already configured, codeant_login returns alreadyLoggedIn: true. When the token is rejected (Invalid API key, or access denied after an upgrade), the agent calls codeant_login with force: true to start a new sign-in. To switch accounts, ask the agent to sign in again with force: true. codeant_logout revokes the token on the server, removes it from ~/.codeant/config.json, and cancels a pending sign-in. The CLI and the MCP server share that file, so logging out from either one logs out both.
A token in CODEANT_API_TOKEN (or the desktop extension’s CodeAnt API token setting) always takes precedence. codeant_logout revokes it, and a force: true sign-in replaces it only until the client restarts the server. Remove or update that token in your client configuration, or every tool fails with an authentication error after the next restart.
On a self-hosted CodeAnt AI instance, codeant_login needs your dashboard URL. See Self-hosted CodeAnt AI.

Tools

The Hotlist, anti-pattern, cloud, pentest, and API tools act on one organization connection. If codeant_scans_orgs lists more than one, pass org and service to those tools, and org to codeant_scans_repos. For parameters and responses, see the MCP tool reference. Repositories and scans Organization findings Pull requests and local review API passthrough and authentication

Example agent requests

  • “List my repositories, then show critical SAST findings for the API repository.”
  • “Show the ten highest-priority Hotlist findings.”
  • “Show failing high-severity checks from the latest AWS CSPM scan.”
  • “Fetch this Hotlist finding by its stable ID and explain the remediation.”
  • “List the open issues in the latest pentest engagement.”
  • “Review my staged changes with CodeAnt.” This needs a client that starts the server in your repository, such as Claude Code.

Configuration reference

Add variables to the env object of the codeant entry you created in Install:
In Codex’s config.toml, add a [mcp_servers.codeant.env] table. On the command line, pass --env KEY=value (or -e) to claude mcp add or codex mcp add. In claude mcp add, put another option such as --transport stdio between -e and the server name. The Git provider variables are listed under Pull request tools.

Pull request tools

codeant_pr_list, codeant_pr_get, codeant_pr_comments, and codeant_comments_search call your Git provider’s API directly, so they need a token for that provider. The server checks these sources in order: The gh and glab fallbacks work only when those CLIs are on the client’s PATH. Tokens saved with codeant set-token work in every client.
Leave GITHUB_API_URL unset for GitHub.com. On GitHub Actions runners it’s preset to https://api.github.com, which the server can’t use, so unset it before starting the server there.

Working directory and repository detection

codeant_review_local reviews the git repository in the server’s working directory. The pull request tools detect name and remote from that repository’s origin remote.
  • Claude Code starts the server in your project, so both work without extra parameters.
  • Claude Desktop, with the extension or a manual configuration, starts it outside your projects. Pass name (owner/repo) and remote (github, gitlab, bitbucket, or azure) to the pull request tools. Local review isn’t available.
  • Other clients: ask the agent to run codeant_review_local. If it returns Could not find a .git directory, the client starts the server outside your repository. Pass name and remote to the pull request tools, and run codeant review in a terminal for local review.
  • Azure DevOps: always pass name as project/repo. Detection from Azure DevOps remote URLs doesn’t produce that form.

Self-hosted CodeAnt AI

Set both URLs in the server’s environment, or save them once with the CLI: In the Claude Desktop extension, set API base URL and Dashboard URL in the extension settings instead. The extension’s settings take precedence over values saved with the CLI. The CLI asks your instance for its dashboard URL. If codeant_login fails with Could not determine the dashboard URL, set it explicitly. For self-hosted Git providers, see Pull request tools.

Enable write tools

Set CODEANT_READ_ONLY=0 only when the MCP client should be allowed to change external state. Add it to the env object of the codeant entry:
In Claude Code, replace the server:
In the desktop extension, turn off Read-only mode. The Claude Code plugin is always read-only. This adds three tools:
codeant_api_request can change or delete data in your CodeAnt AI organization. Enable write tools only when your agent needs them, keep your client prompting before each write call, and don’t add write tools to auto-approve rules. Don’t run codeant_scans_start in parallel with other tool calls.

Approve tools automatically

Every read tool is marked read-only (readOnlyHint), so clients can approve it without prompting. codeant_login and codeant_logout aren’t, so clients still ask before signing in or out. In Claude Code, add rules to permissions.allow in ~/.claude/settings.json (all projects) or .claude/settings.json (one project):
With the Claude Code plugin, tool names start with mcp__plugin_codeant_codeant__ instead of mcp__codeant__.
The rule mcp__codeant approves every tool from the server, including write tools if you enable them later. List read tools individually instead.

Results and paging

MCP clients limit how much tool output they accept. Claude Code, for example, caps it at 25,000 tokens by default. The server keeps results small:
  • One page per call. Most list tools return a total and take limit and offset, but some differ: the Hotlist uses cursor and next_cursor, codeant_pr_list returns no total, and codeant_scans_history takes no offset. See each tool in the MCP tool reference for its paging fields.
  • Small default page sizes:
  • Slim records. Repository lists, cloud scan history, cloud findings, and pentest history leave out bulky fields such as raw provider metadata, per-service rollups, compliance mappings, and billing details. Pass full: true to include them.
  • Size limit. The server refuses any result over 80,000 characters (about 20,000 tokens) and returns a hint for narrowing the request. If your client accepts larger results, raise CODEANT_MCP_MAX_RESULT_CHARS in the server’s environment. In Claude Code, also start Claude Code with a higher MAX_MCP_OUTPUT_TOKENS, for example MAX_MCP_OUTPUT_TOKENS=50000 claude. The desktop extension doesn’t have a setting for the limit.
The CLI commands still return complete results.

Privacy and telemetry

  • Tools send requests to the CodeAnt API with your token. The pull request tools call your Git provider directly.
  • codeant_review_local sends the diff and the full current contents of each changed file to CodeAnt for review. While reviewing, CodeAnt can also read, list, and search other files in the repository for context. The tool never modifies files.
  • Local reviews send usage events to PostHog. The events are tied to your CodeAnt API token and can include review error messages. To turn them off, set CODEANT_TELEMETRY_DISABLED=1 in the server’s environment, run codeant set-telemetry false (not in the desktop extension), or enable Disable telemetry in the desktop extension.
See the CodeAnt AI privacy policy.

Troubleshooting

To test the server outside your client, open it in the MCP Inspector:
The Inspector opens in your browser. Click Connect, then List Tools. You should see 24 tools, or 27 with write tools enabled.

MCP tool reference

Parameters, defaults, and key response fields for every tool.

Findings

Query repository, Hotlist, cloud-security, and pentest findings from the CLI.

SCM and PR tools

Manage pull requests, comments, and review data.

Claude Code integration

Slash-command skills that review and fix code with the CodeAnt CLI.