Vanta

MCP-Server von Vanta

Query Vanta controls, failing tests, vendors and compliance data, and remediate failing tests from your AI assistant.

OAuth-Anmeldung (Beim ersten Verbinden meldest du dich beim Anbieter an)Streamable HTTP

Mit Vanta verbinden

Vanta braucht eine Anmeldung. Verbinde dich mit seiner eigenen URL:

https://mcp.vanta.com/mcp

Dein Client öffnet beim ersten Mal die Anmeldung von Vanta. Das Token bleibt zwischen deinem Client und Vanta.

Diesen Server teilen

Öffnet diese Seite, mit der URL und den Einrichtungsschritten.

mcp.tc/i/vanta

Über den Server

Vanta's MCP server lets AI assistants call the Vanta API on your behalf. You can query controls, find and remediate failing tests, and work with vendors and other compliance data. The server is in beta.

It runs as a hosted streamable HTTP endpoint with a separate URL per region: https://mcp.vanta.com/mcp (US), https://mcp.eu.vanta.com/mcp (EU) and https://mcp.aus.vanta.com/mcp (Australia). Users sign in with OAuth and must hold the Vanta Admin role. It works with Claude Code, Cursor, Perplexity, Codex and other clients that support remote MCP.

Was du damit machen kannst

  • Query Vanta controls
  • Find failing tests
  • Remediate failing tests
  • Look up vendors
  • Act on compliance data through the Vanta API

Tools

Vanta zeigt seine Tools erst nach der Anmeldung, deshalb können wir sie hier nicht auflisten. Dein Client zeigt sie, sobald du verbunden bist.

Beispiel-Prompts

  • List my failing Vanta tests and group them by owner.

  • Which Vanta controls need attention this week?

  • Help me fix the failing test for unencrypted storage.

  • Show the vendors in Vanta and their current status.

Einrichtung

Jeder Client verbindet sich mit mcp.vanta.com, und beim ersten Mal fragt Vanta nach deiner Anmeldung. Wähl deinen; die Seite merkt sich deine Wahl.

Claude Code

  1. Run this in a terminal, in your project folder:
claude mcp add --transport http vanta https://mcp.vanta.com/mcp
  1. Start Claude Code, type /mcp, pick vanta and choose Authenticate. A browser window opens for the Vanta sign-in.

Add --scope user to make it available in every project, not just this one.

Claude Desktop

  1. Open Settings → Connectors and click Add custom connector.
  2. Name it Vanta and paste this URL:
https://mcp.vanta.com/mcp
  1. Click Add, then Connect, and sign in when Vanta asks.

Claude Desktop’s JSON config file only starts local servers. Remote servers go through Connectors, and connectors you add on claude.ai show up here too.

claude.ai

  1. Open the connector form on claude.ai. This button fills in the name and URL for you:
  1. Check that the URL reads https://mcp.vanta.com/mcp and click Add.
  2. Click Connect and sign in when Vanta asks.

Free plans allow one custom connector. On Team and Enterprise plans an owner adds it under Organization settings → Connectors.

ChatGPT

  1. On chatgpt.com, open Settings → Security and login and turn on Developer mode.
  2. Go to chatgpt.com/plugins and click + to create an app for a remote MCP server.
  3. Paste https://mcp.vanta.com/mcp as the server URL and choose OAuth. ChatGPT sends you to Vanta to sign in.

Developer mode is available on the web for Plus, Pro, Business, Enterprise and Education accounts.

Cursor

Or add it by hand to ~/.cursor/mcp.json (all projects) or .cursor/mcp.json (this project):

mcp.json
{
  "mcpServers": {
    "vanta": {
      "url": "https://mcp.vanta.com/mcp"
    }
  }
}

Cursor shows Needs login next to the server. Click it to sign in.

VS Code

Or from a terminal:

code --add-mcp '{"name":"vanta","type":"http","url":"https://mcp.vanta.com/mcp"}'

Or commit it to the repo in .vscode/mcp.json:

.vscode/mcp.json
{
  "servers": {
    "vanta": {
      "type": "http",
      "url": "https://mcp.vanta.com/mcp"
    }
  }
}

VS Code asks you to sign in the first time the server starts.

Devin Desktop

  1. Add it to ~/.config/devin/mcp_config.json (macOS and Linux) or %APPDATA%\devin\mcp_config.json (Windows):
mcp_config.json
{
  "mcpServers": {
    "vanta": {
      "serverUrl": "https://mcp.vanta.com/mcp"
    }
  }
}
  1. Refresh the MCP server list in Cascade and sign in when asked.

Devin Desktop is the new name for Windsurf. It reads serverUrl (or url) for remote servers.

Codex

codex mcp add vanta --url https://mcp.vanta.com/mcp
codex mcp login vanta

Or edit ~/.codex/config.toml directly:

config.toml
[mcp_servers.vanta]
url = "https://mcp.vanta.com/mcp"

Gemini CLI

gemini mcp add --transport http vanta https://mcp.vanta.com/mcp

Then, inside Gemini CLI, run /mcp auth vanta to sign in.

This adds it to the current project. Add -s user to use it everywhere.

Any client

Most clients accept this shape. Some name the URL field differently: serverUrl in Devin Desktop, httpUrl in Gemini CLI’s settings file.

{
  "mcpServers": {
    "vanta": {
      "type": "http",
      "url": "https://mcp.vanta.com/mcp"
    }
  }
}

Zed puts servers under context_servers in its settings. Cline needs "type": "streamableHttp", or it assumes SSE.

Client only starts local servers? Bridge it with npx -y mcp-remote https://mcp.vanta.com/mcp.

Häufige Fragen

Can I paste mcp.tc/i/vanta into my MCP client?

No. mcp.tc links are pages, not server addresses. Connect with https://mcp.vanta.com/mcp, so your client talks to Vanta directly. The sign-in token only works there anyway. The quick link is for sharing: it opens this page, with setup steps for every client.

Does Vanta need an API key or a sign-in?

Yes, you need a Vanta account. The first time your client connects, it opens Vanta’s sign-in page. The token goes straight to the server’s own URL, never through mcp.tc.

Is Vanta a remote or a local server?

Remote. Vanta hosts it at https://mcp.vanta.com/mcp, and it speaks Streamable HTTP. There’s nothing to install.

What can Vanta do?

You can Query Vanta controls, Find failing tests und Remediate failing tests.

Which clients can use it?

Any client that supports remote MCP servers: Claude Code, Claude Desktop, claude.ai, ChatGPT in developer mode, Cursor, VS Code, Devin Desktop, Codex, Gemini CLI, Zed and others. The setup steps cover each one.

Who wrote this page?

mcp.tc’s robot read Vanta’s own metadata (its MCP handshake, tool list and public pages), and an AI model drafted the text from it. A person reviews anything the checks can’t confirm. The text can still be wrong, so if you spot a mistake, use Report this listing on this page.

Einbinden

Zeig Vanta in einem README oder auf deiner Website. Jede Einbindung verlinkt auf diese Seite, nutzt die eigene URL des Servers und setzt keine Cookies. So funktionieren Einbindungen

README-Badge

Badge-Vorschau, hellBadge-Vorschau, dunkel
Markdown
[![Vanta on mcp.tc](https://mcp.tc/i/vanta/badge.svg)](https://mcp.tc/i/vanta)
HTML
<a href="https://mcp.tc/i/vanta"><img src="https://mcp.tc/i/vanta/badge.svg" alt="Vanta on mcp.tc" height="20"></a>

Es folgt dem hellen oder dunklen Modus der Lesenden. Hänge ?theme=light oder ?theme=dark an, um ihn festzulegen, oder ?style=compact, um das Zeichen ohne Schriftzug zu zeigen.

Website-Karte

HTML
<script src="https://mcp.tc/w/vanta.js" async></script>

Die Karte erscheint dort, wo das Tag steht. Füge dem Tag data-theme="dark" oder data-size="compact" hinzu, um sie zu ändern. Die Datei enthält alles, was sie braucht, stellt also keine weiteren Anfragen und setzt keine Cookies.

iframe

HTML
<iframe src="https://mcp.tc/embed/vanta" title="Vanta on mcp.tc" width="420" height="200" loading="lazy" allow="clipboard-write" style="border:0;border-radius:8px;max-width:100%"></iframe>

Nutze es auf Seiten, die keine Skripte erlauben. Hänge ?theme=light oder ?theme=dark an die Adresse an, um die Farben festzulegen.

JSON

Der Eintrag als Daten für deine eigenen Seiten und Tools: Name, Kurzbeschreibung, die eigene URL des Servers, Tools und die „Add to“-Links. Jede Website kann ihn lesen (CORS ist offen).

https://mcp.tc/i/vanta.json

Was jedes Feld bedeutet

mcp.tc ist nicht mit Vanta verbunden. Diese Seite entstand aus den öffentlichen Metadaten von Vanta, zuletzt geprüft am 3. Okt. 2026, und ein KI-Modell hat die Beschreibung geschrieben, sie kann also Fehler enthalten. Namen und Marken gehören ihren Inhabern. Stimmt etwas nicht? Eintrag melden.