The Kodem MCP server connects AI assistants such as Claude, Cursor and GitHub Copilot to your Kodem data. Ask about issues with runtime context, inventory, deployments and posture in plain language, and act on findings. Every request runs with your own Kodem account, so the assistant sees and does only what you can.
AI assistants reason over what they can see: source files, manifests, a scanner's export. None of it says what is reachable at runtime. The Kodem MCP server brings the runtime context Kodem already holds into the assistant your team uses every day, so it starts from what matters in production.
Ask about your issues in plain language and get the runtime context Kodem has for each one, so the assistant knows what is reachable in production.
Ask about your inventory of projects, container images and packages, without leaving your editor or chat.
Pull posture statistics, deployments and scan history into the conversation when you need them.
See incidents, connected integrations and the scopes you have access to, in one place.
Dismiss or reopen issues and add labels from the same conversation where you found them.
Link or unlink a Jira ticket on an issue, and dismiss an incident once it is handled.
The Kodem MCP server connects AI assistants to your Kodem data over the Model Context Protocol. Your assistant can ask about issues with runtime context, inventory, posture, deployments, scan history, incidents, integrations and scopes, and act on findings, all with your own Kodem permissions.
Any MCP client that supports remote servers with OAuth sign-in, such as Claude, Claude Code, Cursor and GitHub Copilot CLI. You connect them all with the same server URL: https://api.kodemsecurity.com/mcp.
It can ask about issues with runtime context, your inventory of projects, images and packages, posture statistics, deployments, scan history, incidents, integrations and scopes. It can also act on findings: dismiss or reopen issues, link or unlink a Jira ticket, add labels, and dismiss an incident.
The first time your assistant uses the Kodem server, a browser window opens so you can sign in to Kodem and approve access. You sign in with OAuth, so there is no API key to manage. After you approve, the assistant acts as you.
No. The assistant acts with your own Kodem permissions and data scopes, so it cannot see or do more than you can. You can revoke its access at any time from your Kodem account.
The server reads your organization's Kodem data within your permissions and returns it only to the MCP client you authorize. It does not widen your access or expose data beyond your scopes. Once data reaches your assistant, its handling follows that assistant's own data policy.
No. AI runtime discovery, part of Kodem's Runtime AI Security, inventories the agents and MCP servers running inside your applications. The Kodem MCP server is how your own AI assistant connects to Kodem.