# GitGuardian MCP server

> Scan code for leaked secrets, manage security incidents and create honeytokens with GitGuardian's detectors.

- Listing: https://mcp.tc/i/gitguardian
- Connect: use the server's own URL `https://mcp.gitguardian.com/mcp` (OAuth sign-in at the server); clients connect to it directly. The listing link is a page, not an MCP endpoint.
- Type: remote (Streamable HTTP)
- Auth: OAuth sign-in
- Category: [Security & Compliance](https://mcp.tc/c/security)
- Vendor: GitGuardian
- Homepage: <https://www.gitguardian.com/>
- Repository: <https://github.com/GitGuardian/ggmcp>
- Package: pypi `ggmcp`

## About

Connects an AI assistant to GitGuardian's secret detection platform. You can scan files for hardcoded credentials using 500+ detectors, list, filter, assign, resolve and tag incidents (including Public Monitoring incidents), generate and list honeytokens, and open pull requests that remediate secrets in monitored repositories.

The hosted server runs at https://mcp.gitguardian.com/mcp for US SaaS and https://mcp.eu1.gitguardian.com/mcp for EU workspaces. Users sign in with OAuth, and the tools exposed depend on the granted scopes. Self-hosted GitGuardian instances can run the open source ggmcp server locally with a personal access token or in Docker.

## What it can do

- Scan files and codebases for leaked credentials
- List and filter security incidents
- Assign, resolve and tag incidents
- Get remediation guidance for an incident
- Generate honeytokens and list existing ones
- Open pull requests that remediate secrets in monitored repositories

## Example prompts

- "Scan this codebase for any leaked secrets or credentials."
- "Check if there are any new security incidents assigned to me."
- "Help me understand this security incident and provide remediation steps."
- "Generate a new honeytoken for monitoring AWS credential access."

## Install

### Claude Code

1. Run this in a terminal, in your project folder:

```bash
claude mcp add --transport http gitguardian https://mcp.gitguardian.com/mcp
```

2. Start Claude Code, type `/mcp`, pick **gitguardian** and choose **Authenticate**. A browser window opens for the GitGuardian sign-in.

Add `--scope user` to make it available in every project, not just this one.

### Claude Desktop

1. Open **Settings → Connectors** and click **Add custom connector**.

2. Name it **GitGuardian** and paste this URL:

```url
https://mcp.gitguardian.com/mcp
```

3. Click **Add**, then **Connect**, and sign in when GitGuardian asks.

Claude Desktop’s JSON config file only starts local servers. Remote servers go through Connectors, and connectors you add on claude.ai show up here too.

### claude.ai

1. Open the connector form on claude.ai. This button fills in the name and URL for you:

[Add to claude.ai](<https://claude.ai/customize/connectors?modal=add-custom-connector&connectorName=GitGuardian&connectorUrl=https%3A%2F%2Fmcp.gitguardian.com%2Fmcp>) (opens connector settings)

2. Check that the URL reads `https://mcp.gitguardian.com/mcp` and click **Add**.

3. Click **Connect** and sign in when GitGuardian asks.

Free plans allow one custom connector. On Team and Enterprise plans an owner adds it under **Organization settings → Connectors**.

### ChatGPT

1. On chatgpt.com, open **Settings → Security and login** and turn on **Developer mode**.

2. Go to `chatgpt.com/plugins` and click **+** to create an app for a remote MCP server.

3. Paste `https://mcp.gitguardian.com/mcp` as the server URL and choose **OAuth**. ChatGPT sends you to GitGuardian to sign in.

Developer mode is available on the web for Plus, Pro, Business, Enterprise and Education accounts.

### Cursor

[Add to Cursor](<https://cursor.com/install-mcp?name=gitguardian&config=eyJ1cmwiOiJodHRwczovL21jcC5naXRndWFyZGlhbi5jb20vbWNwIn0%3D>) (opens Cursor)

Or add it by hand to `~/.cursor/mcp.json` (all projects) or `.cursor/mcp.json` (this project):

`mcp.json`:

```json
{
  "mcpServers": {
    "gitguardian": {
      "url": "https://mcp.gitguardian.com/mcp"
    }
  }
}
```

Cursor shows **Needs login** next to the server. Click it to sign in.

### VS Code

[Install in VS Code](<https://vscode.dev/redirect/mcp/install?name=gitguardian&config=%7B%22type%22%3A%22http%22%2C%22url%22%3A%22https%3A%2F%2Fmcp.gitguardian.com%2Fmcp%22%7D>) (opens VS Code)

Or from a terminal:

```bash
code --add-mcp '{"name":"gitguardian","type":"http","url":"https://mcp.gitguardian.com/mcp"}'
```

Or commit it to the repo in `.vscode/mcp.json`:

`.vscode/mcp.json`:

```json
{
  "servers": {
    "gitguardian": {
      "type": "http",
      "url": "https://mcp.gitguardian.com/mcp"
    }
  }
}
```

VS Code asks you to sign in the first time the server starts.

### Devin Desktop

1. Add it to `~/.config/devin/mcp_config.json` (macOS and Linux) or `%APPDATA%\devin\mcp_config.json` (Windows):

`mcp_config.json`:

```json
{
  "mcpServers": {
    "gitguardian": {
      "serverUrl": "https://mcp.gitguardian.com/mcp"
    }
  }
}
```

2. Refresh the MCP server list in Cascade and sign in when asked.

Devin Desktop is the new name for Windsurf. It reads `serverUrl` (or `url`) for remote servers.

### Codex

```bash
codex mcp add gitguardian --url https://mcp.gitguardian.com/mcp
codex mcp login gitguardian
```

Or edit `~/.codex/config.toml` directly:

`config.toml`:

```toml
[mcp_servers.gitguardian]
url = "https://mcp.gitguardian.com/mcp"
```

### Gemini CLI

```bash
gemini mcp add --transport http gitguardian https://mcp.gitguardian.com/mcp
```

Then, inside Gemini CLI, run `/mcp auth gitguardian` to sign in.

This adds it to the current project. Add `-s user` to use it everywhere.

### Any client

Most clients accept this shape. Some name the URL field differently: `serverUrl` in Devin Desktop, `httpUrl` in Gemini CLI’s settings file.

```json
{
  "mcpServers": {
    "gitguardian": {
      "type": "http",
      "url": "https://mcp.gitguardian.com/mcp"
    }
  }
}
```

Zed puts servers under `context_servers` in its settings. Cline needs `"type": "streamableHttp"`, or it assumes SSE.

Client only starts local servers? Bridge it with `npx -y mcp-remote https://mcp.gitguardian.com/mcp`.

## Details

- Server version: 0.7.0
- Last checked: 2026-10-03 (reachable, asks for credentials)
- Listed: 2026-10-03
- Updated: 2026-10-03

---
Source: https://mcp.tc/i/gitguardian (mcp.tc is an independent directory, not affiliated with this server's publisher). Corrections: https://mcp.tc/report
