# Snyk MCP server

> Scan code, dependencies, containers, IaC and secrets for vulnerabilities with Snyk from your AI assistant.

- Listing: https://mcp.tc/i/snyk
- Connect: this is a local (stdio) server; install it on your machine (see Install). The listing link is a page, not an MCP endpoint.
- Type: local (stdio)
- Auth: OAuth sign-in
- Category: [Security & Compliance](https://mcp.tc/c/security)
- Vendor: Snyk
- Verified: yes, mcp.tc checked that this is the official server (https://mcp.tc/verify). It says who runs the server, not that it is safe.
- Homepage: <https://docs.snyk.io/agent-security>
- Repository: <https://github.com/snyk/studio-mcp>
- Package: npm `snyk`

## About

Snyk Studio is the MCP server built into the Snyk CLI. It lets an MCP-enabled assistant run Snyk scans on your local codebase and read the findings. Scans cover open source dependencies, source code, infrastructure as code, containers, SBOM files and secrets. It can also create an AIBOM and check the health of a package.

It runs locally over stdio with the command npx -y snyk@latest mcp -t stdio. You sign in to Snyk through the browser with snyk auth or the snyk\_auth tool, or you set SNYK\_TOKEN. The dependency scan may run ecosystem tools such as Gradle or Maven on your machine to read the dependency tree.

## What it can do

- Scan open source dependencies for known vulnerabilities
- Run static analysis on source code
- Scan IaC files and container images
- Scan SBOM files and detect secrets
- Create an AIBOM for a project
- Check the health and security of a package
- Sign in, sign out and check auth status

## Example prompts

- "Scan this project's dependencies for vulnerabilities with Snyk."
- "Run a Snyk code scan on the current repository and list high severity issues."
- "Check my Terraform files for misconfigurations using Snyk IaC."
- "Is the package lodash healthy and safe to use?"

## Install

### Claude Code

1. Run this in a terminal, in your project folder:

```bash
claude mcp add --transport stdio snyk -- npx -y snyk@latest mcp -t stdio
```

2. Start Claude Code and type `/mcp`. **snyk** should show as connected.

Add `--scope user` to make it available in every project.

### Claude Desktop

1. Open **Settings → Developer → Edit Config**. It opens `claude_desktop_config.json`. Add:

`claude_desktop_config.json`:

```json
{
  "mcpServers": {
    "snyk": {
      "command": "npx",
      "args": [
        "-y",
        "snyk@latest",
        "mcp",
        "-t",
        "stdio"
      ]
    }
  }
}
```

2. Save the file and restart Claude Desktop.

Needs Node.js on your computer. The file lives in `~/Library/Application Support/Claude/` on macOS and `%APPDATA%\Claude\` on Windows.

### Cursor

[Add to Cursor](<https://cursor.com/install-mcp?name=snyk&config=eyJjb21tYW5kIjoibnB4IiwiYXJncyI6WyIteSIsInNueWtAbGF0ZXN0IiwibWNwIiwiLXQiLCJzdGRpbyJdfQ%3D%3D>) (opens Cursor)

Or add it by hand to `~/.cursor/mcp.json` (all projects) or `.cursor/mcp.json` (this project):

`mcp.json`:

```json
{
  "mcpServers": {
    "snyk": {
      "command": "npx",
      "args": [
        "-y",
        "snyk@latest",
        "mcp",
        "-t",
        "stdio"
      ]
    }
  }
}
```

Needs Node.js on your computer.

### VS Code

[Install in VS Code](<https://vscode.dev/redirect/mcp/install?name=snyk&config=%7B%22type%22%3A%22stdio%22%2C%22command%22%3A%22npx%22%2C%22args%22%3A%5B%22-y%22%2C%22snyk%40latest%22%2C%22mcp%22%2C%22-t%22%2C%22stdio%22%5D%7D>) (opens VS Code)

Or from a terminal:

```bash
code --add-mcp '{"name":"snyk","type":"stdio","command":"npx","args":["-y","snyk@latest","mcp","-t","stdio"]}'
```

Or commit it to the repo in `.vscode/mcp.json`:

`.vscode/mcp.json`:

```json
{
  "servers": {
    "snyk": {
      "type": "stdio",
      "command": "npx",
      "args": [
        "-y",
        "snyk@latest",
        "mcp",
        "-t",
        "stdio"
      ]
    }
  }
}
```

Needs Node.js on your computer.

### Devin Desktop

1. Add it to `~/.config/devin/mcp_config.json` (macOS and Linux) or `%APPDATA%\devin\mcp_config.json` (Windows):

`mcp_config.json`:

```json
{
  "mcpServers": {
    "snyk": {
      "command": "npx",
      "args": [
        "-y",
        "snyk@latest",
        "mcp",
        "-t",
        "stdio"
      ]
    }
  }
}
```

2. Refresh the MCP server list in Cascade.

Devin Desktop is the new name for Windsurf.

### Codex

```bash
codex mcp add snyk -- npx -y snyk@latest mcp -t stdio
```

Or edit `~/.codex/config.toml` directly:

`config.toml`:

```toml
[mcp_servers.snyk]
command = "npx"
args = ["-y", "snyk@latest", "mcp", "-t", "stdio"]
```

Needs Node.js on your computer.

### Gemini CLI

```bash
gemini mcp add snyk npx -- -y snyk@latest mcp -t stdio
```

This adds it to the current project. Add `-s user` to use it everywhere.

### Any client

Most clients that start local servers accept this shape:

```json
{
  "mcpServers": {
    "snyk": {
      "command": "npx",
      "args": [
        "-y",
        "snyk@latest",
        "mcp",
        "-t",
        "stdio"
      ]
    }
  }
}
```

Zed puts servers under `context_servers` in its settings, with the same `command`, `args` and `env` fields.

Needs Node.js on your computer.

## Details

- Server version: 1.1304.2
- Last checked: 2026-10-03
- Listed: 2026-10-03
- Updated: 2026-10-04

---
Source: https://mcp.tc/i/snyk (mcp.tc is an independent directory, not affiliated with this server's publisher). Corrections: https://mcp.tc/report
