# Snyk API & Web MCP server

> Onboard scan targets, run DAST scans and triage vulnerability findings in Snyk API & Web from your AI assistant.

- Listing: https://mcp.tc/i/snyk-api-web
- Connect: this is a local (stdio) server; install it on your machine (see Install). The listing link is a page, not an MCP endpoint.
- Type: local (stdio)
- Auth: API key
- Category: [Security & Compliance](https://mcp.tc/c/security)
- Vendor: Snyk
- Repository: <https://github.com/snyk/saw-mcp>
- Package: pypi `snyk-apiweb-mcp`

## About

Connects an AI assistant to Snyk API & Web (formerly Probely). You can onboard API and web scan targets, configure authentication, run dynamic application security testing (DAST) scans, and manage and triage findings in natural language. Tool names still use the legacy probely\_ prefix.

It runs locally over stdio, started with uvx from the PyPI package snyk-apiweb-mcp, and is built on FastMCP. It needs a Snyk API & Web API key in MCP\_SAW\_API\_KEY; a limited-scope key with a custom role is recommended. Python 3.10+ is required. Onboarding web targets with login sequences also needs playwright-cli or Playwright MCP for browser recording.

## What it can do

- Onboard API targets from OpenAPI, Swagger or Postman collections
- Onboard web targets, including authenticated apps with login sequences
- Configure target authentication
- Run DAST scans against configured targets
- Review and triage scan findings

## Example prompts

- "Configure a Snyk API & Web API target from this OpenAPI schema."
- "Add a web target for example.com with these login credentials."
- "Start a DAST scan on my staging API target."
- "Show the open high-severity findings and help me triage them."

## Install

### Claude Code

1. Run this in a terminal, in your project folder:

```bash
claude mcp add --transport stdio snyk-api-web --env "MCP_SAW_API_KEY=<YOUR_MCP_SAW_API_KEY>" -- uvx snyk-apiweb-mcp
```

2. Start Claude Code and type `/mcp`. **snyk-api-web** should show as connected.

Add `--scope user` to make it available in every project. Replace the placeholders with your own values.

### Claude Desktop

1. Open **Settings → Developer → Edit Config**. It opens `claude_desktop_config.json`. Add:

`claude_desktop_config.json`:

```json
{
  "mcpServers": {
    "snyk-api-web": {
      "command": "uvx",
      "args": [
        "snyk-apiweb-mcp"
      ],
      "env": {
        "MCP_SAW_API_KEY": "<YOUR_MCP_SAW_API_KEY>"
      }
    }
  }
}
```

2. Save the file and restart Claude Desktop. Replace the placeholders with your own values.

Needs uv (Python) on your computer. The file lives in `~/Library/Application Support/Claude/` on macOS and `%APPDATA%\Claude\` on Windows.

### Cursor

[Add to Cursor](<https://cursor.com/install-mcp?name=snyk-api-web&config=eyJjb21tYW5kIjoidXZ4IiwiYXJncyI6WyJzbnlrLWFwaXdlYi1tY3AiXSwiZW52Ijp7Ik1DUF9TQVdfQVBJX0tFWSI6IjxZT1VSX01DUF9TQVdfQVBJX0tFWT4ifX0%3D>) (opens Cursor)

Or add it by hand to `~/.cursor/mcp.json` (all projects) or `.cursor/mcp.json` (this project):

`mcp.json`:

```json
{
  "mcpServers": {
    "snyk-api-web": {
      "command": "uvx",
      "args": [
        "snyk-apiweb-mcp"
      ],
      "env": {
        "MCP_SAW_API_KEY": "<YOUR_MCP_SAW_API_KEY>"
      }
    }
  }
}
```

Needs uv (Python) on your computer. Replace the placeholders with your own values.

### VS Code

Add it to `.vscode/mcp.json`. VS Code asks for the secret the first time and stores it securely:

`.vscode/mcp.json`:

```json
{
  "servers": {
    "snyk-api-web": {
      "type": "stdio",
      "command": "uvx",
      "args": [
        "snyk-apiweb-mcp"
      ],
      "env": {
        "MCP_SAW_API_KEY": "${input:mcp-saw-api-key}"
      }
    }
  },
  "inputs": [
    {
      "type": "promptString",
      "id": "mcp-saw-api-key",
      "description": "MCP_SAW_API_KEY",
      "password": true
    }
  ]
}
```

Needs uv (Python) on your computer.

### Devin Desktop

1. Add it to `~/.config/devin/mcp_config.json` (macOS and Linux) or `%APPDATA%\devin\mcp_config.json` (Windows):

`mcp_config.json`:

```json
{
  "mcpServers": {
    "snyk-api-web": {
      "command": "uvx",
      "args": [
        "snyk-apiweb-mcp"
      ],
      "env": {
        "MCP_SAW_API_KEY": "<YOUR_MCP_SAW_API_KEY>"
      }
    }
  }
}
```

2. Refresh the MCP server list in Cascade. Replace the placeholders with your own values.

Devin Desktop is the new name for Windsurf.

### Codex

```bash
codex mcp add snyk-api-web --env "MCP_SAW_API_KEY=<YOUR_MCP_SAW_API_KEY>" -- uvx snyk-apiweb-mcp
```

Or edit `~/.codex/config.toml` directly:

`config.toml`:

```toml
[mcp_servers.snyk-api-web]
command = "uvx"
args = ["snyk-apiweb-mcp"]
env = { MCP_SAW_API_KEY = "<YOUR_MCP_SAW_API_KEY>" }
```

Needs uv (Python) on your computer. Replace the placeholders with your own values.

### Gemini CLI

```bash
gemini mcp add -e "MCP_SAW_API_KEY=<YOUR_MCP_SAW_API_KEY>" snyk-api-web uvx snyk-apiweb-mcp
```

This adds it to the current project. Add `-s user` to use it everywhere.

### Any client

Most clients that start local servers accept this shape:

```json
{
  "mcpServers": {
    "snyk-api-web": {
      "command": "uvx",
      "args": [
        "snyk-apiweb-mcp"
      ],
      "env": {
        "MCP_SAW_API_KEY": "<YOUR_MCP_SAW_API_KEY>"
      }
    }
  }
}
```

Zed puts servers under `context_servers` in its settings, with the same `command`, `args` and `env` fields.

Needs uv (Python) on your computer. Replace the placeholders with your own values.

## Details

- Server version: 1.1.2
- Last checked: 2026-10-04
- Listed: 2026-10-04
- Updated: 2026-10-04

---
Source: https://mcp.tc/i/snyk-api-web (mcp.tc is an independent directory, not affiliated with this server's publisher). Corrections: https://mcp.tc/report
