# Semgrep MCP server

> Scan code for security issues and bugs with Semgrep static analysis rules from your AI assistant.

- Listing: https://mcp.tc/i/semgrep
- Connect: use the server's own URL `https://mcp.semgrep.ai/mcp` (OAuth sign-in at the server); clients connect to it directly. The listing link is a page, not an MCP endpoint.
- Type: remote (Streamable HTTP)
- Auth: OAuth sign-in
- Category: [Security & Compliance](https://mcp.tc/c/security)
- Vendor: Semgrep
- Homepage: <https://docs.semgrep.dev/mcp>
- Repository: <https://github.com/semgrep/semgrep>

## About

Connects your assistant to Semgrep, a static analysis tool that searches code, finds bugs and enforces security guardrails and coding standards. Semgrep supports more than 30 languages, and its rules look like the code you already write.

The hosted endpoint uses streamable HTTP and asks users to sign in with their Semgrep account through OAuth. The hosted server is marked experimental. A local option runs with semgrep mcp, and the older uvx semgrep-mcp package is legacy. The tool list is not published, so check the Semgrep docs for current tools.

## What it can do

- Scan source code for security vulnerabilities and bugs
- Apply Semgrep rules to find insecure code patterns
- Check code against coding standards and guardrails
- Work with code in more than 30 languages

## Example prompts

- "Scan this Python file for security issues with Semgrep."
- "Check my code for insecure patterns before I open a pull request."
- "Run Semgrep rules on this function and explain the findings."
- "Which Semgrep findings in this snippet should I fix first?"

## Install

### Claude Code

1. Run this in a terminal, in your project folder:

```bash
claude mcp add --transport http semgrep https://mcp.semgrep.ai/mcp
```

2. Start Claude Code, type `/mcp`, pick **semgrep** and choose **Authenticate**. A browser window opens for the Semgrep sign-in.

Add `--scope user` to make it available in every project, not just this one.

### Claude Desktop

1. Open **Settings → Connectors** and click **Add custom connector**.

2. Name it **Semgrep** and paste this URL:

```url
https://mcp.semgrep.ai/mcp
```

3. Click **Add**, then **Connect**, and sign in when Semgrep asks.

Claude Desktop’s JSON config file only starts local servers. Remote servers go through Connectors, and connectors you add on claude.ai show up here too.

### claude.ai

1. Open the connector form on claude.ai. This button fills in the name and URL for you:

[Add to claude.ai](<https://claude.ai/customize/connectors?modal=add-custom-connector&connectorName=Semgrep&connectorUrl=https%3A%2F%2Fmcp.semgrep.ai%2Fmcp>) (opens connector settings)

2. Check that the URL reads `https://mcp.semgrep.ai/mcp` and click **Add**.

3. Click **Connect** and sign in when Semgrep asks.

Free plans allow one custom connector. On Team and Enterprise plans an owner adds it under **Organization settings → Connectors**.

### ChatGPT

1. On chatgpt.com, open **Settings → Security and login** and turn on **Developer mode**.

2. Go to `chatgpt.com/plugins` and click **+** to create an app for a remote MCP server.

3. Paste `https://mcp.semgrep.ai/mcp` as the server URL and choose **OAuth**. ChatGPT sends you to Semgrep to sign in.

Developer mode is available on the web for Plus, Pro, Business, Enterprise and Education accounts.

### Cursor

[Add to Cursor](<https://cursor.com/install-mcp?name=semgrep&config=eyJ1cmwiOiJodHRwczovL21jcC5zZW1ncmVwLmFpL21jcCJ9>) (opens Cursor)

Or add it by hand to `~/.cursor/mcp.json` (all projects) or `.cursor/mcp.json` (this project):

`mcp.json`:

```json
{
  "mcpServers": {
    "semgrep": {
      "url": "https://mcp.semgrep.ai/mcp"
    }
  }
}
```

Cursor shows **Needs login** next to the server. Click it to sign in.

### VS Code

[Install in VS Code](<https://vscode.dev/redirect/mcp/install?name=semgrep&config=%7B%22type%22%3A%22http%22%2C%22url%22%3A%22https%3A%2F%2Fmcp.semgrep.ai%2Fmcp%22%7D>) (opens VS Code)

Or from a terminal:

```bash
code --add-mcp '{"name":"semgrep","type":"http","url":"https://mcp.semgrep.ai/mcp"}'
```

Or commit it to the repo in `.vscode/mcp.json`:

`.vscode/mcp.json`:

```json
{
  "servers": {
    "semgrep": {
      "type": "http",
      "url": "https://mcp.semgrep.ai/mcp"
    }
  }
}
```

VS Code asks you to sign in the first time the server starts.

### Devin Desktop

1. Add it to `~/.config/devin/mcp_config.json` (macOS and Linux) or `%APPDATA%\devin\mcp_config.json` (Windows):

`mcp_config.json`:

```json
{
  "mcpServers": {
    "semgrep": {
      "serverUrl": "https://mcp.semgrep.ai/mcp"
    }
  }
}
```

2. Refresh the MCP server list in Cascade and sign in when asked.

Devin Desktop is the new name for Windsurf. It reads `serverUrl` (or `url`) for remote servers.

### Codex

```bash
codex mcp add semgrep --url https://mcp.semgrep.ai/mcp
codex mcp login semgrep
```

Or edit `~/.codex/config.toml` directly:

`config.toml`:

```toml
[mcp_servers.semgrep]
url = "https://mcp.semgrep.ai/mcp"
```

### Gemini CLI

```bash
gemini mcp add --transport http semgrep https://mcp.semgrep.ai/mcp
```

Then, inside Gemini CLI, run `/mcp auth semgrep` to sign in.

This adds it to the current project. Add `-s user` to use it everywhere.

### Any client

Most clients accept this shape. Some name the URL field differently: `serverUrl` in Devin Desktop, `httpUrl` in Gemini CLI’s settings file.

```json
{
  "mcpServers": {
    "semgrep": {
      "type": "http",
      "url": "https://mcp.semgrep.ai/mcp"
    }
  }
}
```

Zed puts servers under `context_servers` in its settings. Cline needs `"type": "streamableHttp"`, or it assumes SSE.

Client only starts local servers? Bridge it with `npx -y mcp-remote https://mcp.semgrep.ai/mcp`.

## Details

- Last checked: 2026-10-03 (reachable, asks for credentials)
- Listed: 2026-10-03
- Updated: 2026-10-03

---
Source: https://mcp.tc/i/semgrep (mcp.tc is an independent directory, not affiliated with this server's publisher). Corrections: https://mcp.tc/report
