Semgrep

MCP server by Semgrep

Scan code for security issues and bugs with Semgrep static analysis rules from your AI assistant.

OAuth sign-in (You sign in with the vendor the first time you connect)Streamable HTTP

Connect to Semgrep

Semgrep needs sign-in. Connect with its own URL:

https://mcp.semgrep.ai/mcp

Your client opens Semgrep’s sign-in the first time you use it. The token stays between your client and Semgrep.

Share this server

Opens this page, with the URL and setup steps.

mcp.tc/i/semgrep

About

Connects your assistant to Semgrep, a static analysis tool that searches code, finds bugs and enforces security guardrails and coding standards. Semgrep supports more than 30 languages, and its rules look like the code you already write.

The hosted endpoint uses streamable HTTP and asks users to sign in with their Semgrep account through OAuth. The hosted server is marked experimental. A local option runs with semgrep mcp, and the older uvx semgrep-mcp package is legacy. The tool list is not published, so check the Semgrep docs for current tools.

What you can do

  • Scan source code for security vulnerabilities and bugs
  • Apply Semgrep rules to find insecure code patterns
  • Check code against coding standards and guardrails
  • Work with code in more than 30 languages

Tools

Semgrep lists its tools only after you sign in, so we can’t show them here. Your client lists them once you’re connected.

Example prompts

  • Scan this Python file for security issues with Semgrep.

  • Check my code for insecure patterns before I open a pull request.

  • Run Semgrep rules on this function and explain the findings.

  • Which Semgrep findings in this snippet should I fix first?

Set up

Every client connects to mcp.semgrep.ai, and Semgrep asks you to sign in the first time. Pick yours; the page remembers your choice.

Claude Code

  1. Run this in a terminal, in your project folder:
claude mcp add --transport http semgrep https://mcp.semgrep.ai/mcp
  1. Start Claude Code, type /mcp, pick semgrep and choose Authenticate. A browser window opens for the Semgrep sign-in.

Add --scope user to make it available in every project, not just this one.

Claude Desktop

  1. Open Settings → Connectors and click Add custom connector.
  2. Name it Semgrep and paste this URL:
https://mcp.semgrep.ai/mcp
  1. Click Add, then Connect, and sign in when Semgrep asks.

Claude Desktop’s JSON config file only starts local servers. Remote servers go through Connectors, and connectors you add on claude.ai show up here too.

claude.ai

  1. Open the connector form on claude.ai. This button fills in the name and URL for you:
  1. Check that the URL reads https://mcp.semgrep.ai/mcp and click Add.
  2. Click Connect and sign in when Semgrep asks.

Free plans allow one custom connector. On Team and Enterprise plans an owner adds it under Organization settings → Connectors.

ChatGPT

  1. On chatgpt.com, open Settings → Security and login and turn on Developer mode.
  2. Go to chatgpt.com/plugins and click + to create an app for a remote MCP server.
  3. Paste https://mcp.semgrep.ai/mcp as the server URL and choose OAuth. ChatGPT sends you to Semgrep to sign in.

Developer mode is available on the web for Plus, Pro, Business, Enterprise and Education accounts.

Cursor

Or add it by hand to ~/.cursor/mcp.json (all projects) or .cursor/mcp.json (this project):

mcp.json
{
  "mcpServers": {
    "semgrep": {
      "url": "https://mcp.semgrep.ai/mcp"
    }
  }
}

Cursor shows Needs login next to the server. Click it to sign in.

VS Code

Or from a terminal:

code --add-mcp '{"name":"semgrep","type":"http","url":"https://mcp.semgrep.ai/mcp"}'

Or commit it to the repo in .vscode/mcp.json:

.vscode/mcp.json
{
  "servers": {
    "semgrep": {
      "type": "http",
      "url": "https://mcp.semgrep.ai/mcp"
    }
  }
}

VS Code asks you to sign in the first time the server starts.

Devin Desktop

  1. Add it to ~/.config/devin/mcp_config.json (macOS and Linux) or %APPDATA%\devin\mcp_config.json (Windows):
mcp_config.json
{
  "mcpServers": {
    "semgrep": {
      "serverUrl": "https://mcp.semgrep.ai/mcp"
    }
  }
}
  1. Refresh the MCP server list in Cascade and sign in when asked.

Devin Desktop is the new name for Windsurf. It reads serverUrl (or url) for remote servers.

Codex

codex mcp add semgrep --url https://mcp.semgrep.ai/mcp
codex mcp login semgrep

Or edit ~/.codex/config.toml directly:

config.toml
[mcp_servers.semgrep]
url = "https://mcp.semgrep.ai/mcp"

Gemini CLI

gemini mcp add --transport http semgrep https://mcp.semgrep.ai/mcp

Then, inside Gemini CLI, run /mcp auth semgrep to sign in.

This adds it to the current project. Add -s user to use it everywhere.

Any client

Most clients accept this shape. Some name the URL field differently: serverUrl in Devin Desktop, httpUrl in Gemini CLI’s settings file.

{
  "mcpServers": {
    "semgrep": {
      "type": "http",
      "url": "https://mcp.semgrep.ai/mcp"
    }
  }
}

Zed puts servers under context_servers in its settings. Cline needs "type": "streamableHttp", or it assumes SSE.

Client only starts local servers? Bridge it with npx -y mcp-remote https://mcp.semgrep.ai/mcp.

FAQ

Can I paste mcp.tc/i/semgrep into my MCP client?

No. mcp.tc links are pages, not server addresses. Connect with https://mcp.semgrep.ai/mcp, so your client talks to Semgrep directly. The sign-in token only works there anyway. The quick link is for sharing: it opens this page, with setup steps for every client.

Does Semgrep need an API key or a sign-in?

Yes, you need a Semgrep account. The first time your client connects, it opens Semgrep’s sign-in page. The token goes straight to the server’s own URL, never through mcp.tc.

Is Semgrep a remote or a local server?

Remote. Semgrep hosts it at https://mcp.semgrep.ai/mcp, and it speaks Streamable HTTP. There’s nothing to install.

What can Semgrep do?

You can scan source code for security vulnerabilities and bugs, apply Semgrep rules to find insecure code patterns and check code against coding standards and guardrails.

Which clients can use it?

Any client that supports remote MCP servers: Claude Code, Claude Desktop, claude.ai, ChatGPT in developer mode, Cursor, VS Code, Devin Desktop, Codex, Gemini CLI, Zed and others. The setup steps cover each one.

Who wrote this page?

mcp.tc’s robot read Semgrep’s own metadata (its MCP handshake, tool list and public pages), and an AI model drafted the text from it. A person reviews anything the checks can’t confirm. The text can still be wrong, so if you spot a mistake, use Report this listing on this page.

Embed

Show Semgrep in a README or on your site. Each embed links to this page, uses the server’s own URL, and sets no cookies. How embeds work

README badge

Badge preview, lightBadge preview, dark
Markdown
[![Semgrep on mcp.tc](https://mcp.tc/i/semgrep/badge.svg)](https://mcp.tc/i/semgrep)
HTML
<a href="https://mcp.tc/i/semgrep"><img src="https://mcp.tc/i/semgrep/badge.svg" alt="Semgrep on mcp.tc" height="20"></a>

It follows the reader’s light or dark mode. Add ?theme=light or ?theme=dark to fix it, or ?style=compact to show the mark without the word.

Website card

HTML
<script src="https://mcp.tc/w/semgrep.js" async></script>

The card appears where the tag is. Add data-theme="dark" or data-size="compact" to the tag to change it. The file holds everything it needs, so it makes no other requests and sets no cookies.

iframe

HTML
<iframe src="https://mcp.tc/embed/semgrep" title="Semgrep on mcp.tc" width="420" height="200" loading="lazy" allow="clipboard-write" style="border:0;border-radius:8px;max-width:100%"></iframe>

Use it on pages that don’t allow scripts. Add ?theme=light or ?theme=dark to the address to fix the colors.

JSON

The listing as data for your own pages and tools: name, tagline, the server’s own URL, tools and the “Add to” links. Any site can read it (CORS is open).

https://mcp.tc/i/semgrep.json

What each field means

mcp.tc isn’t affiliated with Semgrep. This page was built from Semgrep’s public metadata, last checked on 3 Oct 2026, and an AI model wrote the description, so it can be wrong. Names and marks belong to their owners. Something off? Report this listing.