Kodem is now part of OpenAI’s Daybreak Program
Read the full press release
Kodem MCP Server

Ground your AI assistant in what actually runs

The Kodem MCP server connects AI assistants such as Claude, Cursor and GitHub Copilot to your Kodem data. Ask about issues with runtime context, inventory, deployments and posture in plain language, and act on findings. Every request runs with your own Kodem account, so the assistant sees and does only what you can.

List my high severity issues that are reachable at runtime.
kodem Searching issues

Two high severity issues are reachable at runtime in your environment:

  • jackson-databind in checkout-serviceReachable at runtime
  • lodash in pricing-apiReachable at runtime

I'd start with jackson-databind in checkout-service.

Link the jackson-databind issue to PAY-1423 in Jira.
kodem Linking Jira ticket

Done. The jackson-databind issue is now linked to PAY-1423.

Your assistant reads the code. Kodem knows what runs.

AI assistants reason over what they can see: source files, manifests, a scanner's export. None of it says what is reachable at runtime. The Kodem MCP server brings the runtime context Kodem already holds into the assistant your team uses every day, so it starts from what matters in production.

Ask about issues, with runtime context

Ask about your issues in plain language and get the runtime context Kodem has for each one, so the assistant knows what is reachable in production.

Know what you run

Ask about your inventory of projects, container images and packages, without leaving your editor or chat.

Track posture, deployments and scans

Pull posture statistics, deployments and scan history into the conversation when you need them.

Review incidents, integrations and scopes

See incidents, connected integrations and the scopes you have access to, in one place.

Act on findings

Dismiss or reopen issues and add labels from the same conversation where you found them.

Close the loop in Jira

Link or unlink a Jira ticket on an issue, and dismiss an incident once it is handled.

Powered by Runtime Intelligence

AI is only as good as the context it receives.

Kodem's Runtime Intelligence observes your running applications down to the function level, so it knows what is loaded, reachable and exposed. The MCP server gives your AI assistant that context, through your own Kodem account.

Ask

Issues with runtime context, inventory, posture statistics, deployments, scan history, incidents, integrations and scopes.

Act

Dismiss or reopen issues, link or unlink a Jira ticket, add labels, and dismiss an incident.

Runtime context comes from the Kodem runtime sensor. Without it, your assistant still works with your code findings, inventory and posture.

OAuth sign-inYour own permissionsRevocable at any timeRuntime context
See how Kodem works →

Connect the Kodem MCP server to your assistant

One server URL works with every supported client. You need a Kodem account and an MCP client that supports remote servers with OAuth sign-in.

claude mcp add --transport http kodem https://api.kodemsecurity.com/mcp

In Claude's connector settings, add a custom connector with the server URL https://api.kodemsecurity.com/mcp

{
  "mcpServers": {
    "kodem": {
      "url": "https://api.kodemsecurity.com/mcp"
    }
  }
}

Add this to your Cursor MCP configuration.

copilot mcp add --transport http kodem https://api.kodemsecurity.com/mcp
  1. Sign inThe first time your assistant uses Kodem, a browser window opens to sign in and approve access. After you approve, the assistant acts as you.
  2. Verify it worksAsk your assistant something that uses your Kodem data, for example: "List my high severity issues that are reachable at runtime." If you see your issues, you are connected.
  3. Stay in controlThe assistant uses your own Kodem permissions and data scopes. You can revoke its access at any time from your Kodem account.
Kodem logo

Sign in with OAuth, as yourself

The assistant sees and does only what your Kodem permissions allow

Data returns only to the MCP client you authorize

Revoke access at any time from your Kodem account

Frequently asked questions

Kodem MCP Server: What to Know

What is the Kodem MCP server?

The Kodem MCP server connects AI assistants to your Kodem data over the Model Context Protocol. Your assistant can ask about issues with runtime context, inventory, posture, deployments, scan history, incidents, integrations and scopes, and act on findings, all with your own Kodem permissions.

Which AI assistants work with the Kodem MCP server?

Any MCP client that supports remote servers with OAuth sign-in, such as Claude, Claude Code, Cursor and GitHub Copilot CLI. You connect them all with the same server URL: https://api.kodemsecurity.com/mcp.

What can my assistant do with Kodem?

It can ask about issues with runtime context, your inventory of projects, images and packages, posture statistics, deployments, scan history, incidents, integrations and scopes. It can also act on findings: dismiss or reopen issues, link or unlink a Jira ticket, add labels, and dismiss an incident.

How does sign-in work?

The first time your assistant uses the Kodem server, a browser window opens so you can sign in to Kodem and approve access. You sign in with OAuth, so there is no API key to manage. After you approve, the assistant acts as you.

Can the assistant see or do more than I can?

No. The assistant acts with your own Kodem permissions and data scopes, so it cannot see or do more than you can. You can revoke its access at any time from your Kodem account.

How does the Kodem MCP server handle my data?

The server reads your organization's Kodem data within your permissions and returns it only to the MCP client you authorize. It does not widen your access or expose data beyond your scopes. Once data reaches your assistant, its handling follows that assistant's own data policy.

Is this the same as Kodem discovering MCP servers in my applications?

No. AI runtime discovery, part of Kodem's Runtime AI Security, inventories the agents and MCP servers running inside your applications. The Kodem MCP server is how your own AI assistant connects to Kodem.

Ready to ground your assistant in what actually runs?
Protect your environment with Kodem®.

Request a demo
Request a demo