Conventions
Connection parameters
The Hotlist, anti-pattern, cloud, pentest, and API tools act on one authenticated organization and Git-provider connection. They accept these parameters:
Call
codeant_scans_orgs to list the connections. If a tool reports multiple matching organizations, pass both org and service. They must match an authenticated connection. providerBaseUrl replaces the connection’s provider URL in the request. Your token is only ever sent to the configured CodeAnt API host.
Repository parameters
The pull request tools call your Git provider directly and accept:
When omitted, both are detected from the
origin remote of the git repository in the server’s working directory. Detection works for github.com, gitlab.com, bitbucket.org, and self-hosted hosts whose name contains the provider name. On Azure DevOps, always pass name. Provider tokens are covered in Pull request tools.
Responses and errors
- Every tool returns one text content item that holds compact JSON. The exception is the write tool
codeant_scans_start, which returns a plain-text message. - Failures set
isError: trueand return{"error": "<message>"}.codeant_review_localfailures return the full review result, including itserror. Some messages name the equivalent CLI flag, for example--tenant-idfortenantIdor--max-waitformaxWaitSeconds. - Invalid arguments, such as a value outside an enum, are rejected by the MCP SDK with a plain-text
Input validation errorandisError: true. Unknown parameters are ignored. - A result over 80,000 characters is refused with
{"error": "Result too large: …", "hint": "…"}. Narrow the request, or raiseCODEANT_MCP_MAX_RESULT_CHARS. See Results and paging. - Responses from tools that take connection parameters include a
tenantobject that identifies the connection used.
Repositories and scans
codeant_scans_orgs
List the organization connections the current login can access. Takes no parameters. Returnsconnections (each with organizationName, baseUrl, and service) and the signed-in email.
CLI equivalent: codeant scans orgs.
codeant_scans_repos
List repositories connected to CodeAnt in one organization, most recently pushed first.
Returns
org, total, offset, limit, next_offset (null on the last page), and repos. Each slim record has full_name, name, private, visibility, default_branch, language, description, archived, and pushed_at. Pass full_name as repo to the other scan tools.
CLI equivalent: codeant scans repos (always returns full records).
codeant_scans_history
List recent scans of one repository.
CLI equivalent:
codeant scans history.
codeant_scans_get
Get the summary of one scan: severity and category counts, without findings.
With neither
scan nor branch, the tool uses the repository’s most recent scan on any branch.
CLI equivalent: codeant scans get.
codeant_scans_results
Fetch findings from one scan of one repository. To cover several repositories, call it once per repository. Parallel calls are safe.
With neither
scan nor branch, the tool uses the repository’s most recent scan on any branch.
Returns repo, scan, categories, summary (totals by severity and category, before paging), pagination (limit, offset, returned, total, has_more), filters, errors (one entry per scan type that failed), and findings. Each finding has id, category, severity, file_path, line_number, line_range, check_id, check_name, message, rule_id, cwe, cve, package, and metadata.
CLI equivalent: codeant scans results or codeant findings repo.
codeant_scans_dismissed
List findings dismissed in the app for one repository. Use it during triage to avoid resurfacing handled findings.
CLI equivalent:
codeant scans dismissed.
codeant_scans_overrides
List per-finding overrides users set in the app.codeant_scans_results already applies them; use this tool to explain why a finding is hidden or re-rated.
CLI equivalent:
codeant scans overrides.
Organization Hotlist
codeant_hotlist_list
Query the organization-wide Hotlist, with the same stable IDs, ranking, and filters as the CodeAnt app. Accepts the connection parameters.
Returns
items, total_filtered, has_more, next_cursor, summary, and facets. With all, it also returns returned_count. Pass an item’s id to codeant_hotlist_get.
CLI equivalent: codeant hotlist list or codeant findings list.
codeant_hotlist_get
Fetch one complete Hotlist finding. Accepts the connection parameters.
CLI equivalent:
codeant hotlist get or codeant findings get.
Anti-patterns
codeant_findings_antipatterns
Fetch anti-pattern findings across selected repositories, or across every repository in the organization. Accepts the connection parameters.
Returns
antipatterns, total, limit, and offset. Request the next page with offset + limit while it’s below total.
CLI equivalent: codeant findings antipatterns.
Cloud security
Cloud findings belong to an organization and cloud account, not to a repository.codeant_cloud_scan_history
List AWS, Azure, or GCP scans. Accepts the connection parameters.
With
provider: "all", returns providers keyed by provider. Each entry has scans, total, offset, limit, next_offset, and an error if that provider was unavailable. With a single provider, those fields are returned directly. Pass a scan’s scan_id (and account_id, tenant_id, or project_id) to codeant_cloud_findings_list.
CLI equivalent: codeant findings cloud history.
codeant_cloud_findings_list
List findings for one cloud scan. Accepts the connection parameters.
VM and container scans accept only
scanId and the paging parameters; the CSPM filters don’t apply to them.
Returns findings and total. CSPM responses also include offset, limit, next_offset, dismissed_findings, and dismissed_total. dismissed_findings is returned in full on every page. Each CSPM finding includes uid, check_id, check_title, service, severity, status, resource, region, and dismissal fields.
CLI equivalent: codeant findings cloud list (returns every CSPM finding).
codeant_cloud_finding_get
Fetch complete detail for one cloud finding. Accepts the connection parameters.
CLI equivalent:
codeant findings cloud get.
Pentesting
codeant_pentest_history
List pentest engagements, newest first, with status and finding counts. Accepts the connection parameters.
Returns
total, offset, limit, next_offset, and history. Each engagement has id, requested_at, testing_type, domains, status, findings (counts by severity), and report_url. Pass id as reportId to the issue and report tools.
CLI equivalent: codeant findings pentest history.
codeant_pentest_issues
Fetch the issues for one engagement. The backend applies the same plan-based redaction as the app. Accepts the connection parameters.
CLI equivalent:
codeant findings pentest issues.
codeant_pentest_report
Fetch the full customer report for one engagement. The backend applies the same plan-based redaction as the app. Accepts the connection parameters.
CLI equivalent:
codeant findings pentest report.
API passthrough
codeant_api_get
Call any authenticated GET endpoint on the configured CodeAnt API host, for read APIs that no dedicated tool covers. Accepts the connection parameters.
Returns
ok, status, tenant, and data. A non-2xx response comes back as a normal result with ok: false, except 403, which fails with an Access denied error.
CLI equivalent: codeant api request GET.
Pull requests and comments
These tools accept the repository parameters and need a token for your Git provider.codeant_pr_list
List pull requests or merge requests.
Filters and paging depend on the provider:
Returns an array of pull requests, without a total.
CLI equivalent:
codeant pr list.
codeant_pr_get
Fetch one pull request’s provider metadata and reviewer approval states (reviewSummary).
CLI equivalent:
codeant pr get.
codeant_pr_comments
List comments on one pull request.
On GitLab, Bitbucket, and Azure DevOps, each comment has a
resolved field. GitHub comments don’t report resolved state.
CLI equivalent: codeant pr comments.
codeant_comments_search
Search review comments in one repository by text. The tool reads comments on the 10 most recently updated pull requests (open ones only on Bitbucket and Azure DevOps; inline review comments only on GitHub) and returns case-insensitive substring matches from every author.
Each result has
prNumber, prTitle, id, author, body, path, line, createdAt, and isCodeantComment. Filter on isCodeantComment for CodeAnt’s comments.
CLI equivalent: codeant comments search.
Local review
codeant_review_local
Run a CodeAnt AI review of local changes in the git repository in the server’s working directory. It needs a client that starts the server inside your project, such as Claude Code. It never modifies files.
The review sends the diff and the full current contents of each changed file to CodeAnt, and the reviewer can read, list, and search other repository files for context.
Returns
issues, meta (including the reviewed files), and error. When error is set, for example Could not find a .git directory., the result has isError: true. noFiles: true means there were no changes in scope.
CLI equivalent: codeant review --headless. The CLI defaults to --all, while this tool defaults to uncommitted.
Authentication
codeant_login
Start browser sign-in to CodeAnt AI.
Concurrent calls share one sign-in. The pending sign-in lives in the server process, so if the client restarts the server before the user finishes, call
codeant_login again.
CLI equivalent: codeant login.
codeant_logout
Revoke the token on the server, remove it from~/.codeant/config.json, unset CODEANT_API_TOKEN in the server process, and cancel a pending sign-in. Takes no parameters. Because the CLI shares the config file, the CLI is signed out too.
Returns wasLoggedIn, serverRevoked, status (logged_out or not_logged_in), and a warning if server revocation couldn’t be confirmed.
CLI equivalent: codeant logout.
Write tools
Registered only whenCODEANT_READ_ONLY=0. See Enable write tools.