# StackHawk MCP server

> Set up StackHawk, run security scans and triage findings from your IDE or chat.

- Listing: https://mcp.tc/i/stackhawk
- Connect: this is a local (stdio) server; install it on your machine (see Install). The listing link is a page, not an MCP endpoint.
- Type: local (stdio)
- Auth: API key
- Category: [Security & Compliance](https://mcp.tc/c/security)
- Vendor: StackHawk
- Repository: <https://github.com/stackhawk/stackhawk-mcp>
- Package: pypi `stackhawk-mcp`

## About

Connects an AI assistant to the StackHawk security scanning platform. It can detect your project, create a StackHawk application, generate a stackhawk.yml, run scans with the StackHawk CLI, and return findings at or above your failure threshold for remediation. It also validates YAML configs against the official schema.

Runs locally over stdio as the PyPI package stackhawk-mcp (for example with uvx), and requires Python 3.10 or higher. A StackHawk API key is required and is passed in the STACKHAWK\_API\_KEY environment variable. An optional FastAPI HTTP server is also included.

## What it can do

- Detect a project and create a StackHawk application
- Generate a ready-to-scan stackhawk.yml
- Run StackHawk scans from the IDE or chat
- Triage findings at or above the failure threshold
- Validate YAML configs against the official schema
- Validate field paths to avoid invented config keys

## Example prompts

- "Set up StackHawk for this project and create a stackhawk.yml."
- "Validate this StackHawk YAML config for errors."
- "Run a StackHawk scan on my app and summarize the findings."
- "Show the findings above my failure threshold and suggest fixes."

## Install

### Claude Code

1. Run this in a terminal, in your project folder:

```bash
claude mcp add --transport stdio stackhawk --env "STACKHAWK_API_KEY=<YOUR_STACKHAWK_API_KEY>" -- uvx stackhawk-mcp
```

2. Start Claude Code and type `/mcp`. **stackhawk** should show as connected.

Add `--scope user` to make it available in every project. Replace the placeholders with your own values.

### Claude Desktop

1. Open **Settings → Developer → Edit Config**. It opens `claude_desktop_config.json`. Add:

`claude_desktop_config.json`:

```json
{
  "mcpServers": {
    "stackhawk": {
      "command": "uvx",
      "args": [
        "stackhawk-mcp"
      ],
      "env": {
        "STACKHAWK_API_KEY": "<YOUR_STACKHAWK_API_KEY>"
      }
    }
  }
}
```

2. Save the file and restart Claude Desktop. Replace the placeholders with your own values.

Needs uv (Python) on your computer. The file lives in `~/Library/Application Support/Claude/` on macOS and `%APPDATA%\Claude\` on Windows.

### Cursor

[Add to Cursor](<https://cursor.com/install-mcp?name=stackhawk&config=eyJjb21tYW5kIjoidXZ4IiwiYXJncyI6WyJzdGFja2hhd2stbWNwIl0sImVudiI6eyJTVEFDS0hBV0tfQVBJX0tFWSI6IjxZT1VSX1NUQUNLSEFXS19BUElfS0VZPiJ9fQ%3D%3D>) (opens Cursor)

Or add it by hand to `~/.cursor/mcp.json` (all projects) or `.cursor/mcp.json` (this project):

`mcp.json`:

```json
{
  "mcpServers": {
    "stackhawk": {
      "command": "uvx",
      "args": [
        "stackhawk-mcp"
      ],
      "env": {
        "STACKHAWK_API_KEY": "<YOUR_STACKHAWK_API_KEY>"
      }
    }
  }
}
```

Needs uv (Python) on your computer. Replace the placeholders with your own values.

### VS Code

Add it to `.vscode/mcp.json`. VS Code asks for the secret the first time and stores it securely:

`.vscode/mcp.json`:

```json
{
  "servers": {
    "stackhawk": {
      "type": "stdio",
      "command": "uvx",
      "args": [
        "stackhawk-mcp"
      ],
      "env": {
        "STACKHAWK_API_KEY": "${input:stackhawk-api-key}"
      }
    }
  },
  "inputs": [
    {
      "type": "promptString",
      "id": "stackhawk-api-key",
      "description": "STACKHAWK_API_KEY",
      "password": true
    }
  ]
}
```

Needs uv (Python) on your computer.

### Devin Desktop

1. Add it to `~/.config/devin/mcp_config.json` (macOS and Linux) or `%APPDATA%\devin\mcp_config.json` (Windows):

`mcp_config.json`:

```json
{
  "mcpServers": {
    "stackhawk": {
      "command": "uvx",
      "args": [
        "stackhawk-mcp"
      ],
      "env": {
        "STACKHAWK_API_KEY": "<YOUR_STACKHAWK_API_KEY>"
      }
    }
  }
}
```

2. Refresh the MCP server list in Cascade. Replace the placeholders with your own values.

Devin Desktop is the new name for Windsurf.

### Codex

```bash
codex mcp add stackhawk --env "STACKHAWK_API_KEY=<YOUR_STACKHAWK_API_KEY>" -- uvx stackhawk-mcp
```

Or edit `~/.codex/config.toml` directly:

`config.toml`:

```toml
[mcp_servers.stackhawk]
command = "uvx"
args = ["stackhawk-mcp"]
env = { STACKHAWK_API_KEY = "<YOUR_STACKHAWK_API_KEY>" }
```

Needs uv (Python) on your computer. Replace the placeholders with your own values.

### Gemini CLI

```bash
gemini mcp add -e "STACKHAWK_API_KEY=<YOUR_STACKHAWK_API_KEY>" stackhawk uvx stackhawk-mcp
```

This adds it to the current project. Add `-s user` to use it everywhere.

### Any client

Most clients that start local servers accept this shape:

```json
{
  "mcpServers": {
    "stackhawk": {
      "command": "uvx",
      "args": [
        "stackhawk-mcp"
      ],
      "env": {
        "STACKHAWK_API_KEY": "<YOUR_STACKHAWK_API_KEY>"
      }
    }
  }
}
```

Zed puts servers under `context_servers` in its settings, with the same `command`, `args` and `env` fields.

Needs uv (Python) on your computer. Replace the placeholders with your own values.

## Details

- Server version: 1.1.1
- Last checked: 2026-10-04
- Listed: 2026-10-04
- Updated: 2026-10-04

---
Source: https://mcp.tc/i/stackhawk (mcp.tc is an independent directory, not affiliated with this server's publisher). Corrections: https://mcp.tc/report
