Skip to main content
Your agent chooses and calls these tools based on your requests. Use this page to write precise requests, set up auto-approval rules, or debug a tool call. It covers the CodeAnt AI MCP server as of CLI 0.5.10. Parameters marked required must be passed. Everything else is optional.

Conventions

Connection parameters

The Hotlist, anti-pattern, cloud, pentest, and API tools act on one authenticated organization and Git-provider connection. They accept these parameters: Call codeant_scans_orgs to list the connections. If a tool reports multiple matching organizations, pass both org and service. They must match an authenticated connection. providerBaseUrl replaces the connection’s provider URL in the request. Your token is only ever sent to the configured CodeAnt API host.

Repository parameters

The pull request tools call your Git provider directly and accept: When omitted, both are detected from the origin remote of the git repository in the server’s working directory. Detection works for github.com, gitlab.com, bitbucket.org, and self-hosted hosts whose name contains the provider name. On Azure DevOps, always pass name. Provider tokens are covered in Pull request tools.
The pull request tools spell Azure DevOps azure. The connection parameter service spells it azuredevops.

Responses and errors

  • Every tool returns one text content item that holds compact JSON. The exception is the write tool codeant_scans_start, which returns a plain-text message.
  • Failures set isError: true and return {"error": "<message>"}. codeant_review_local failures return the full review result, including its error. Some messages name the equivalent CLI flag, for example --tenant-id for tenantId or --max-wait for maxWaitSeconds.
  • Invalid arguments, such as a value outside an enum, are rejected by the MCP SDK with a plain-text Input validation error and isError: true. Unknown parameters are ignored.
  • A result over 80,000 characters is refused with {"error": "Result too large: …", "hint": "…"}. Narrow the request, or raise CODEANT_MCP_MAX_RESULT_CHARS. See Results and paging.
  • Responses from tools that take connection parameters include a tenant object that identifies the connection used.

Repositories and scans

codeant_scans_orgs

List the organization connections the current login can access. Takes no parameters. Returns connections (each with organizationName, baseUrl, and service) and the signed-in email. CLI equivalent: codeant scans orgs.

codeant_scans_repos

List repositories connected to CodeAnt in one organization, most recently pushed first. Returns org, total, offset, limit, next_offset (null on the last page), and repos. Each slim record has full_name, name, private, visibility, default_branch, language, description, archived, and pushed_at. Pass full_name as repo to the other scan tools. CLI equivalent: codeant scans repos (always returns full records).

codeant_scans_history

List recent scans of one repository. CLI equivalent: codeant scans history.

codeant_scans_get

Get the summary of one scan: severity and category counts, without findings. With neither scan nor branch, the tool uses the repository’s most recent scan on any branch. CLI equivalent: codeant scans get.

codeant_scans_results

Fetch findings from one scan of one repository. To cover several repositories, call it once per repository. Parallel calls are safe. With neither scan nor branch, the tool uses the repository’s most recent scan on any branch. Returns repo, scan, categories, summary (totals by severity and category, before paging), pagination (limit, offset, returned, total, has_more), filters, errors (one entry per scan type that failed), and findings. Each finding has id, category, severity, file_path, line_number, line_range, check_id, check_name, message, rule_id, cwe, cve, package, and metadata. CLI equivalent: codeant scans results or codeant findings repo.

codeant_scans_dismissed

List findings dismissed in the app for one repository. Use it during triage to avoid resurfacing handled findings. CLI equivalent: codeant scans dismissed.

codeant_scans_overrides

List per-finding overrides users set in the app. codeant_scans_results already applies them; use this tool to explain why a finding is hidden or re-rated. CLI equivalent: codeant scans overrides.

Organization Hotlist

codeant_hotlist_list

Query the organization-wide Hotlist, with the same stable IDs, ranking, and filters as the CodeAnt app. Accepts the connection parameters. Returns items, total_filtered, has_more, next_cursor, summary, and facets. With all, it also returns returned_count. Pass an item’s id to codeant_hotlist_get. CLI equivalent: codeant hotlist list or codeant findings list.

codeant_hotlist_get

Fetch one complete Hotlist finding. Accepts the connection parameters. CLI equivalent: codeant hotlist get or codeant findings get.

Anti-patterns

codeant_findings_antipatterns

Fetch anti-pattern findings across selected repositories, or across every repository in the organization. Accepts the connection parameters. Returns antipatterns, total, limit, and offset. Request the next page with offset + limit while it’s below total. CLI equivalent: codeant findings antipatterns.

Cloud security

Cloud findings belong to an organization and cloud account, not to a repository.

codeant_cloud_scan_history

List AWS, Azure, or GCP scans. Accepts the connection parameters. With provider: "all", returns providers keyed by provider. Each entry has scans, total, offset, limit, next_offset, and an error if that provider was unavailable. With a single provider, those fields are returned directly. Pass a scan’s scan_id (and account_id, tenant_id, or project_id) to codeant_cloud_findings_list. CLI equivalent: codeant findings cloud history.

codeant_cloud_findings_list

List findings for one cloud scan. Accepts the connection parameters. VM and container scans accept only scanId and the paging parameters; the CSPM filters don’t apply to them. Returns findings and total. CSPM responses also include offset, limit, next_offset, dismissed_findings, and dismissed_total. dismissed_findings is returned in full on every page. Each CSPM finding includes uid, check_id, check_title, service, severity, status, resource, region, and dismissal fields. CLI equivalent: codeant findings cloud list (returns every CSPM finding).

codeant_cloud_finding_get

Fetch complete detail for one cloud finding. Accepts the connection parameters. CLI equivalent: codeant findings cloud get.

Pentesting

codeant_pentest_history

List pentest engagements, newest first, with status and finding counts. Accepts the connection parameters. Returns total, offset, limit, next_offset, and history. Each engagement has id, requested_at, testing_type, domains, status, findings (counts by severity), and report_url. Pass id as reportId to the issue and report tools. CLI equivalent: codeant findings pentest history.

codeant_pentest_issues

Fetch the issues for one engagement. The backend applies the same plan-based redaction as the app. Accepts the connection parameters. CLI equivalent: codeant findings pentest issues.

codeant_pentest_report

Fetch the full customer report for one engagement. The backend applies the same plan-based redaction as the app. Accepts the connection parameters. CLI equivalent: codeant findings pentest report.

API passthrough

codeant_api_get

Call any authenticated GET endpoint on the configured CodeAnt API host, for read APIs that no dedicated tool covers. Accepts the connection parameters. Returns ok, status, tenant, and data. A non-2xx response comes back as a normal result with ok: false, except 403, which fails with an Access denied error. CLI equivalent: codeant api request GET.

Pull requests and comments

These tools accept the repository parameters and need a token for your Git provider.

codeant_pr_list

List pull requests or merge requests. Filters and paging depend on the provider: Returns an array of pull requests, without a total. CLI equivalent: codeant pr list.

codeant_pr_get

Fetch one pull request’s provider metadata and reviewer approval states (reviewSummary). CLI equivalent: codeant pr get.

codeant_pr_comments

List comments on one pull request. On GitLab, Bitbucket, and Azure DevOps, each comment has a resolved field. GitHub comments don’t report resolved state. CLI equivalent: codeant pr comments. Search review comments in one repository by text. The tool reads comments on the 10 most recently updated pull requests (open ones only on Bitbucket and Azure DevOps; inline review comments only on GitHub) and returns case-insensitive substring matches from every author. Each result has prNumber, prTitle, id, author, body, path, line, createdAt, and isCodeantComment. Filter on isCodeantComment for CodeAnt’s comments. CLI equivalent: codeant comments search.

Local review

codeant_review_local

Run a CodeAnt AI review of local changes in the git repository in the server’s working directory. It needs a client that starts the server inside your project, such as Claude Code. It never modifies files. The review sends the diff and the full current contents of each changed file to CodeAnt, and the reviewer can read, list, and search other repository files for context. Returns issues, meta (including the reviewed files), and error. When error is set, for example Could not find a .git directory., the result has isError: true. noFiles: true means there were no changes in scope. CLI equivalent: codeant review --headless. The CLI defaults to --all, while this tool defaults to uncommitted.

Authentication

codeant_login

Start browser sign-in to CodeAnt AI. Concurrent calls share one sign-in. The pending sign-in lives in the server process, so if the client restarts the server before the user finishes, call codeant_login again. CLI equivalent: codeant login.

codeant_logout

Revoke the token on the server, remove it from ~/.codeant/config.json, unset CODEANT_API_TOKEN in the server process, and cancel a pending sign-in. Takes no parameters. Because the CLI shares the config file, the CLI is signed out too. Returns wasLoggedIn, serverRevoked, status (logged_out or not_logged_in), and a warning if server revocation couldn’t be confirmed. CLI equivalent: codeant logout.

Write tools

Registered only when CODEANT_READ_ONLY=0. See Enable write tools.