MCP server
Read findings and start re-tests from Claude, ChatGPT, Cursor, or VS Code.
Interopt runs a remote MCP server. Connect an AI assistant or editor to it and ask about your findings where you fix them: pull a finding's reproduction steps and proposed fix into your editor, mark it in progress, and re-test it once the fix ships.
The MCP server is part of Team and up.
Server URL
https://app.interopt.ai/api/mcpThe same URL is on Settings → MCP. There is no key to copy: the first time the app connects, it opens Interopt in your browser to sign in.
Connect
Add the URL as a remote MCP server in your app. Settings → MCP has the steps for each app, with one-click install for Cursor and VS Code.
- Claude: in Settings → Connectors, click Add custom connector and paste the URL. On Team and Enterprise plans an owner adds it once for the organization.
- ChatGPT: turn on Developer mode under Settings → Apps & Connectors → Advanced settings, then Create a connector with the URL and OAuth.
- Claude Code:
claude mcp add --transport http interopt https://app.interopt.ai/api/mcp - Cursor: in
~/.cursor/mcp.json, add"interopt": { "url": "https://app.interopt.ai/api/mcp" }undermcpServers. - VS Code: in
.vscode/mcp.json, add"interopt": { "type": "http", "url": "https://app.interopt.ai/api/mcp" }underservers.
Sign in to Interopt when the browser opens. Every sign-in method and two-factor setting your workspace requires applies.
Pick the workspace and untick any permission you don't want to give. Check the address shown under the app's name: approving sends you there, and Interopt doesn't verify the name an app gives itself.
A connection acts as you, in one workspace. To use a second workspace, connect again and pick it.
Permissions
| Permission | Lets the app |
|---|---|
asset:read | List assets with their open findings and latest scan, and their dependencies with known advisories. |
finding:read | Read findings, including risk, reproduction steps, remediation, and the agent's proposed fix as a diff. |
finding:write | Mark findings in progress or back to open, and comment on them. |
scan:read | List scans and see what a finished scan reproduced and resolved. |
scan:run | Start scans and re-tests, which spend credits. |
report:read | List generated reports with links to them. |
Permissions your role can't use are greyed out when you approve. A read-only member can connect an app to read, but not to change findings or start scans.
Tools
| Tool | Permission | What it does |
|---|---|---|
list_assets | asset:read | Assets, with open findings by severity and the latest scan. Sort by last scan to find what hasn't been tested. |
list_dependencies | asset:read | Packages with known advisories, worst first: across the workspace, or for one asset with the manifest that declares each one or the chain that pulls it in. With by: advisory, one row per advisory instead, with its CVE and fixed version, searchable by CVE or GHSA id. |
get_dependency | asset:read | One package version's advisories with their CVEs, the version that fixes each, and the assets that install it. |
preview_dependency_fix | asset:read | The manifest edits that move a package to its fixed version, as a diff read from the repository. Nothing is written. |
list_findings | finding:read | Findings, most severe first, filtered by asset, severity, status, or text. Open and in-progress by default. |
get_finding | finding:read | One finding in full, with the proposed fix as a unified diff when there is one. |
set_finding_status | finding:write | Set a finding to in progress or open. |
add_finding_comment | finding:write | Comment on a finding, for example with the change that fixed it. Mentions in it notify no one. |
retest_finding | scan:run | Replay one finding against the target. |
list_scans | scan:read | Scan runs, newest first. |
get_scan | scan:read | One scan's state, and once it has ended, the findings it reproduced and resolved. |
start_scan | scan:run | Scan an asset again with its last full scan's configuration. |
cancel_scan | scan:run | Stop a queued or running scan. A queued one is refunded. |
list_reports | report:read | Generated reports. |
The app only sees the tools for the permissions you gave it.
What an app can't do
- Close a finding. A finding is resolved when a re-test or a later scan no longer reproduces it, as in Retesting. Marking a finding a false positive or accepting its risk stays with people in the dashboard.
- Change what a scan tests.
start_scanandretest_findingreuse the configuration someone set in Interopt: the target, scope, auth profile, whether irreversible actions are allowed, and the authorization confirmation. An asset that has never been scanned has to be started from the dashboard. - Spend credits without a limit. Both tools take a
max_creditscap. When the run costs more, nothing is queued and the reply states the price, so the app has to ask you before trying again. If a scan of the asset is already queued or running, the app gets that scan back and no new one is started.
Scans take hours, and findings are written when a run ends. An app that starts
one gets the scan's id back and checks on it later with get_scan.
Disconnect
Settings → MCP lists the apps connected to the workspace. Members see their own; owners and admins see everyone's and can disconnect any of them. A disconnected app's next request fails, even with an access token that hasn't expired yet.
Access also ends when someone leaves the workspace. Role changes apply on the app's next request.
Security
- Access tokens last 15 minutes and are bound to Interopt's MCP server. Apps renew them with a refresh token, which stops working when you disconnect.
- Each request is checked against your current membership, role, and the workspace's two-factor requirement.
- Finding text comes partly from the scanned application, so tool results mark it as data and tell the model not to follow instructions inside it.
- Apps register themselves and must use PKCE. None can skip the approval screen.
See Security and data for how the rest of Interopt handles your data.
