Snyk API & Web

listing.by

Onboard scan targets, run DAST scans and triage vulnerability findings in Snyk API & Web from your AI assistant.

state.local.long (state.local.title)listing.badge.runs_withstate.key.long

listing.install

listing.local.explain

uvx snyk-apiweb-mcp

listing.local.needs listing.local.note

  • MCP_SAW_API_KEY listing.env.secret Snyk API & Web API key. Create at https://plus.probely.app/api-keys

listing.share.h

listing.share.p_local

mcp.tc/i/snyk-api-web

listing.about

Connects an AI assistant to Snyk API & Web (formerly Probely). You can onboard API and web scan targets, configure authentication, run dynamic application security testing (DAST) scans, and manage and triage findings in natural language. Tool names still use the legacy probely_ prefix.

It runs locally over stdio, started with uvx from the PyPI package snyk-apiweb-mcp, and is built on FastMCP. It needs a Snyk API & Web API key in MCP_SAW_API_KEY; a limited-scope key with a custom role is recommended. Python 3.10+ is required. Onboarding web targets with login sequences also needs playwright-cli or Playwright MCP for browser recording.

listing.can

  • Onboard API targets from OpenAPI, Swagger or Postman collections
  • Onboard web targets, including authenticated apps with login sequences
  • Configure target authentication
  • Run DAST scans against configured targets
  • Review and triage scan findings

listing.tools

listing.notools.key

listing.prompts

  • Configure a Snyk API & Web API target from this OpenAPI schema.

  • Add a web target for example.com with these login credentials.

  • Start a DAST scan on my staging API target.

  • Show the open high-severity findings and help me triage them.

listing.setup.h

listing.setup.local

Claude Code

  1. Run this in a terminal, in your project folder:
claude mcp add --transport stdio snyk-api-web --env "MCP_SAW_API_KEY=<YOUR_MCP_SAW_API_KEY>" -- uvx snyk-apiweb-mcp
  1. Start Claude Code and type /mcp. snyk-api-web should show as connected.

Add --scope user to make it available in every project. Replace the placeholders with your own values.

Claude Desktop

  1. Open Settings → Developer → Edit Config. It opens claude_desktop_config.json. Add:
claude_desktop_config.json
{
  "mcpServers": {
    "snyk-api-web": {
      "command": "uvx",
      "args": [
        "snyk-apiweb-mcp"
      ],
      "env": {
        "MCP_SAW_API_KEY": "<YOUR_MCP_SAW_API_KEY>"
      }
    }
  }
}
  1. Save the file and restart Claude Desktop. Replace the placeholders with your own values.

Needs uv (Python) on your computer. The file lives in ~/Library/Application Support/Claude/ on macOS and %APPDATA%\Claude\ on Windows.

Cursor

Or add it by hand to ~/.cursor/mcp.json (all projects) or .cursor/mcp.json (this project):

mcp.json
{
  "mcpServers": {
    "snyk-api-web": {
      "command": "uvx",
      "args": [
        "snyk-apiweb-mcp"
      ],
      "env": {
        "MCP_SAW_API_KEY": "<YOUR_MCP_SAW_API_KEY>"
      }
    }
  }
}

Needs uv (Python) on your computer. Replace the placeholders with your own values.

VS Code

Add it to .vscode/mcp.json. VS Code asks for the secret the first time and stores it securely:

.vscode/mcp.json
{
  "servers": {
    "snyk-api-web": {
      "type": "stdio",
      "command": "uvx",
      "args": [
        "snyk-apiweb-mcp"
      ],
      "env": {
        "MCP_SAW_API_KEY": "${input:mcp-saw-api-key}"
      }
    }
  },
  "inputs": [
    {
      "type": "promptString",
      "id": "mcp-saw-api-key",
      "description": "MCP_SAW_API_KEY",
      "password": true
    }
  ]
}

Needs uv (Python) on your computer.

Devin Desktop

  1. Add it to ~/.config/devin/mcp_config.json (macOS and Linux) or %APPDATA%\devin\mcp_config.json (Windows):
mcp_config.json
{
  "mcpServers": {
    "snyk-api-web": {
      "command": "uvx",
      "args": [
        "snyk-apiweb-mcp"
      ],
      "env": {
        "MCP_SAW_API_KEY": "<YOUR_MCP_SAW_API_KEY>"
      }
    }
  }
}
  1. Refresh the MCP server list in Cascade. Replace the placeholders with your own values.

Devin Desktop is the new name for Windsurf.

Codex

codex mcp add snyk-api-web --env "MCP_SAW_API_KEY=<YOUR_MCP_SAW_API_KEY>" -- uvx snyk-apiweb-mcp

Or edit ~/.codex/config.toml directly:

config.toml
[mcp_servers.snyk-api-web]
command = "uvx"
args = ["snyk-apiweb-mcp"]
env = { MCP_SAW_API_KEY = "<YOUR_MCP_SAW_API_KEY>" }

Needs uv (Python) on your computer. Replace the placeholders with your own values.

Gemini CLI

gemini mcp add -e "MCP_SAW_API_KEY=<YOUR_MCP_SAW_API_KEY>" snyk-api-web uvx snyk-apiweb-mcp

This adds it to the current project. Add -s user to use it everywhere.

Any client

Most clients that start local servers accept this shape:

{
  "mcpServers": {
    "snyk-api-web": {
      "command": "uvx",
      "args": [
        "snyk-apiweb-mcp"
      ],
      "env": {
        "MCP_SAW_API_KEY": "<YOUR_MCP_SAW_API_KEY>"
      }
    }
  }
}

Zed puts servers under context_servers in its settings, with the same command, args and env fields.

Needs uv (Python) on your computer. Replace the placeholders with your own values.

listing.faq

Can I paste mcp.tc/i/snyk-api-web into my MCP client?

No. Snyk API & Web runs on your own computer, started by your client, so it has no web address to connect to. The quick link is the page to share; the install command is uvx snyk-apiweb-mcp.

Does Snyk API & Web need an API key?

Yes. It reads MCP_SAW_API_KEY from its environment, and MCP_SAW_API_KEY is a secret. Put the value in your client's config on your own machine, never in a shared file.

Is Snyk API & Web a remote or a local server?

Local. Your client starts it as a process on your computer with uvx snyk-apiweb-mcp, which needs uv (Python).

What can Snyk API & Web do?

You can onboard API targets from OpenAPI, Swagger or Postman collections, onboard web targets, including authenticated apps with login sequences and configure target authentication.

Which clients can use it?

Any client that starts local servers: Claude Code, Claude Desktop, Cursor, VS Code, Devin Desktop, Codex, Gemini CLI, Zed and others. claude.ai and ChatGPT only connect to remote servers.

Who wrote this page?

mcp.tc's robot read Snyk API & Web's public metadata (its package and repository pages), and an AI model drafted the text from it. A person reviews anything the checks can't confirm. The text can still be wrong, so if you spot a mistake, use Report this listing on this page.

listing.em.h

listing.em.lead_local listing.em.how

listing.em.badge

em.prev_lightem.prev_dark
Markdown
[![Snyk API & Web on mcp.tc](https://mcp.tc/i/snyk-api-web/badge.svg)](https://mcp.tc/i/snyk-api-web)
HTML
<a href="https://mcp.tc/i/snyk-api-web"><img src="https://mcp.tc/i/snyk-api-web/badge.svg" alt="Snyk API &amp; Web on mcp.tc" height="20"></a>

listing.em.badge_note

listing.em.widget

HTML
<script src="https://mcp.tc/w/snyk-api-web.js" async></script>

listing.em.widget_note

iframe

HTML
<iframe src="https://mcp.tc/embed/snyk-api-web" title="Snyk API &amp; Web on mcp.tc" width="420" height="200" loading="lazy" allow="clipboard-write" style="border:0;border-radius:8px;max-width:100%"></iframe>

listing.em.iframe_note

JSON

listing.em.json_local

https://mcp.tc/i/snyk-api-web.json

listing.em.fields

listing.disclaimer_checked