# Vanta MCP server

> Query Vanta controls, failing tests, vendors and compliance data, and remediate failing tests from your AI assistant.

- Listing: https://mcp.tc/i/vanta
- Connect: use the server's own URL `https://mcp.vanta.com/mcp` (OAuth sign-in at the server); clients connect to it directly. The listing link is a page, not an MCP endpoint.
- Type: remote (Streamable HTTP)
- Auth: OAuth sign-in
- Category: [Security & Compliance](https://mcp.tc/c/security)
- Vendor: Vanta
- Homepage: <https://developer.vanta.com/docs/vanta-mcp>

## About

Vanta's MCP server lets AI assistants call the Vanta API on your behalf. You can query controls, find and remediate failing tests, and work with vendors and other compliance data. The server is in beta.

It runs as a hosted streamable HTTP endpoint with a separate URL per region: https://mcp.vanta.com/mcp (US), https://mcp.eu.vanta.com/mcp (EU) and https://mcp.aus.vanta.com/mcp (Australia). Users sign in with OAuth and must hold the Vanta Admin role. It works with Claude Code, Cursor, Perplexity, Codex and other clients that support remote MCP.

## What it can do

- Query Vanta controls
- Find failing tests
- Remediate failing tests
- Look up vendors
- Act on compliance data through the Vanta API

## Example prompts

- "List my failing Vanta tests and group them by owner."
- "Which Vanta controls need attention this week?"
- "Help me fix the failing test for unencrypted storage."
- "Show the vendors in Vanta and their current status."

## Install

### Claude Code

1. Run this in a terminal, in your project folder:

```bash
claude mcp add --transport http vanta https://mcp.vanta.com/mcp
```

2. Start Claude Code, type `/mcp`, pick **vanta** and choose **Authenticate**. A browser window opens for the Vanta sign-in.

Add `--scope user` to make it available in every project, not just this one.

### Claude Desktop

1. Open **Settings → Connectors** and click **Add custom connector**.

2. Name it **Vanta** and paste this URL:

```url
https://mcp.vanta.com/mcp
```

3. Click **Add**, then **Connect**, and sign in when Vanta asks.

Claude Desktop’s JSON config file only starts local servers. Remote servers go through Connectors, and connectors you add on claude.ai show up here too.

### claude.ai

1. Open the connector form on claude.ai. This button fills in the name and URL for you:

[Add to claude.ai](<https://claude.ai/customize/connectors?modal=add-custom-connector&connectorName=Vanta&connectorUrl=https%3A%2F%2Fmcp.vanta.com%2Fmcp>) (opens connector settings)

2. Check that the URL reads `https://mcp.vanta.com/mcp` and click **Add**.

3. Click **Connect** and sign in when Vanta asks.

Free plans allow one custom connector. On Team and Enterprise plans an owner adds it under **Organization settings → Connectors**.

### ChatGPT

1. On chatgpt.com, open **Settings → Security and login** and turn on **Developer mode**.

2. Go to `chatgpt.com/plugins` and click **+** to create an app for a remote MCP server.

3. Paste `https://mcp.vanta.com/mcp` as the server URL and choose **OAuth**. ChatGPT sends you to Vanta to sign in.

Developer mode is available on the web for Plus, Pro, Business, Enterprise and Education accounts.

### Cursor

[Add to Cursor](<https://cursor.com/install-mcp?name=vanta&config=eyJ1cmwiOiJodHRwczovL21jcC52YW50YS5jb20vbWNwIn0%3D>) (opens Cursor)

Or add it by hand to `~/.cursor/mcp.json` (all projects) or `.cursor/mcp.json` (this project):

`mcp.json`:

```json
{
  "mcpServers": {
    "vanta": {
      "url": "https://mcp.vanta.com/mcp"
    }
  }
}
```

Cursor shows **Needs login** next to the server. Click it to sign in.

### VS Code

[Install in VS Code](<https://vscode.dev/redirect/mcp/install?name=vanta&config=%7B%22type%22%3A%22http%22%2C%22url%22%3A%22https%3A%2F%2Fmcp.vanta.com%2Fmcp%22%7D>) (opens VS Code)

Or from a terminal:

```bash
code --add-mcp '{"name":"vanta","type":"http","url":"https://mcp.vanta.com/mcp"}'
```

Or commit it to the repo in `.vscode/mcp.json`:

`.vscode/mcp.json`:

```json
{
  "servers": {
    "vanta": {
      "type": "http",
      "url": "https://mcp.vanta.com/mcp"
    }
  }
}
```

VS Code asks you to sign in the first time the server starts.

### Devin Desktop

1. Add it to `~/.config/devin/mcp_config.json` (macOS and Linux) or `%APPDATA%\devin\mcp_config.json` (Windows):

`mcp_config.json`:

```json
{
  "mcpServers": {
    "vanta": {
      "serverUrl": "https://mcp.vanta.com/mcp"
    }
  }
}
```

2. Refresh the MCP server list in Cascade and sign in when asked.

Devin Desktop is the new name for Windsurf. It reads `serverUrl` (or `url`) for remote servers.

### Codex

```bash
codex mcp add vanta --url https://mcp.vanta.com/mcp
codex mcp login vanta
```

Or edit `~/.codex/config.toml` directly:

`config.toml`:

```toml
[mcp_servers.vanta]
url = "https://mcp.vanta.com/mcp"
```

### Gemini CLI

```bash
gemini mcp add --transport http vanta https://mcp.vanta.com/mcp
```

Then, inside Gemini CLI, run `/mcp auth vanta` to sign in.

This adds it to the current project. Add `-s user` to use it everywhere.

### Any client

Most clients accept this shape. Some name the URL field differently: `serverUrl` in Devin Desktop, `httpUrl` in Gemini CLI’s settings file.

```json
{
  "mcpServers": {
    "vanta": {
      "type": "http",
      "url": "https://mcp.vanta.com/mcp"
    }
  }
}
```

Zed puts servers under `context_servers` in its settings. Cline needs `"type": "streamableHttp"`, or it assumes SSE.

Client only starts local servers? Bridge it with `npx -y mcp-remote https://mcp.vanta.com/mcp`.

## Details

- Last checked: 2026-10-03 (reachable, asks for credentials)
- Listed: 2026-10-03
- Updated: 2026-10-03

---
Source: https://mcp.tc/i/vanta (mcp.tc is an independent directory, not affiliated with this server's publisher). Corrections: https://mcp.tc/report
