The Ostorlab MCP Server: Ask Your Security Data Anything

Give your AI assistants scoped, permission-checked access to your scans, vulnerabilities, and remediation data — no custom integration code.

  • Zero-install via MCP Streamable HTTP
  • Strict API key auth & granular access control
  • Direct access to scans, vulnerabilities, remediation & assets
ostorlab-mcp ~ bash
Ask your AI:

OFFICIAL MODEL CONTEXT PROTOCOL SERVER

Does Ostorlab Have an MCP Server?

Yes, Ostorlab provides an official Model Context Protocol (MCP) server that connects AI clients directly to your security organization.

1

What is the Ostorlab MCP Server?

The Ostorlab MCP Server is a hosted integration server built on the Model Context Protocol (MCP) with streamable HTTP transport. Instead of requiring AI models to navigate web UIs or write custom API integration code, it exposes a curated set of typed tools that turn AI intent into scoped, permission-checked actions on your security data.

Model Context ProtocolStreamable HTTPZero API Code
2

Direct Security Workflow Automation

By connecting an MCP-capable client (such as Claude Code, Claude Desktop, Cursor, VS Code, Windsurf or Zed), your AI assistant can read, manage and automate Ostorlab workflows across scans, vulnerabilities, remediation tickets, asset inventories and PDF reports, using the same organization API keys and access rules that govern the rest of the Ostorlab platform.

Scans & VulnsTickets & AssetsAPI Key Scoped

STREAMABLE HTTP TRANSPORT

How the Ostorlab MCP ServerWorks

Built for simplicity, performance, and long-running security tasks

1

Zero-Install Connection & Auto-Discovery

Point any MCP client at https://api.ostorlab.co/apis/mcp/YOUR_API_KEY/ (the trailing slash is required). Available tools and their arguments are discovered automatically.

Streamable HTTPAuto-DiscoveryZero-Install
2

Stateless & Async Safe Execution

Every request carries its own authentication context with no session state to manage. Single HTTP calls stay open for long-running operations without polling loops.

StatelessAsync SafeNo Polling
3

Predictable & Resilient Error Handling

Tool failures return clean, structured data objects ({ "error": "description" }), allowing AI clients to handle issues and recover gracefully.

Structured OutputResilient

What Your AI Can Do

A comprehensive suite of tools grouped by security capability

Core Security Operations

  • Scans: List, filter, inspect progress, start, or stop scans.
  • Vulnerabilities: Search, inspect findings, update risk ratings and triage states.
  • Remediation & Tickets: Create, read, update, or delete tickets and checklists.

Assets & Integrations

  • Asset Inventory: List and manage asset targets and assigned owner attribution.
  • Automation & Integrations: Configure automation rules, scheduled scans, tags, and Jira, Slack, ServiceNow and Linear connectors.
  • Agentic Deep Scan & Risks: Inspect an Agentic Deep Scan's state, token usage and the risks it surfaced.

Reporting & Evidence

  • Scan Reports: Generate a PDF report for a scan and get the download link in chat.
  • Data Exports: Export findings as CSV or SARIF, tickets and assets as CSV, or a full scan archive.
  • Scan Artefacts: Pull captured HTTP traffic, discovered API endpoints and runtime logs from a scan.

COPY-AND-PASTE PROMPT TEMPLATES

Prompt Inspiration: What Can You Ask?

Here are ready-to-use prompt templates for the Ostorlab MCP server. Replace the [Bracketed Placeholders] to adapt them to your unique environments, compliance needs, and workflows.

Security Audits & Compliance

Generate compliance mappings, check release gates, or gather proof-grade evidence.

You have access to the Ostorlab MCP server. Generate an audit-ready compliance report for our target environment and verify security release gates before deployment.

Audit Parameters:
- Target Assets: [Asset Type & Identifier, e.g., mobile apps / web services / domain.com]
- Compliance Frameworks: [Primary Framework 1, e.g., OWASP MASVS] and [Framework 2, e.g., PCI-DSS v4.0]
- Target Release Milestone: [Environment, e.g., iOS and Android production release v3.4.0]
- Focus Vulnerabilities: [Vulnerability Focus, e.g., authentication/2FA bypass / SQL injection]

Execution Steps:
1. Query Ostorlab MCP for all completed scans and open findings matching [Target Assets] and [Target Release Milestone].
2. Map each identified finding to the corresponding security requirements of [Primary Framework 1] and [Framework 2].
3. Evaluate security release gate criteria: verify if any open Critical or High findings block the release for [Target Release Milestone].
4. Pull the vulnerability details and captured HTTP traffic for all [Focus Vulnerabilities].
5. Generate the PDF scan report with Ostorlab MCP and export the findings as CSV or SARIF.

Required Output & Constraints:
- Provide an Executive Audit Summary table with: Framework Control ID, Finding Title, Severity, Gate Status (PASSED/BLOCKED).
- Include an explicit Release Gate Decision with justification.
- Attach raw evidence logs and reproduction steps formatted for board/auditor review.
- Do not pass release gates if un-triaged Critical findings remain unresolved.

Built for Security and Trust

Designed to ensure your organization's data remains strictly controlled and audited, even with autonomous agents at the wheel.

Strict API Key Authentication

Authentication uses organization API keys. The key's role (reader, user, admin or attack-surface auditor) decides which tools the AI can call.

Secrets Are Never Returned

Tokens, passwords, OAuth secrets and webhook URLs are never returned in tool responses.

Granular Access Scoping & Audit Trails

With object-level access enabled, a key only sees the scans, tickets and assets it has been granted. Changes can be reviewed in your organization audit log.

Destructive Action Hints

Irreversible tools (like deleting tickets or assets) are annotated as destructive, so your MCP client can ask for confirmation before running them.

Works with Any MCP-Capable Client

Connect Claude Code, Claude Desktop, Cursor, VS Code, Windsurf, Zed or your own agents over streamable HTTP.

  • JiraJira
  • LinearLinear
  • JenkinsJenkins
  • GitHubGitHub
  • GitLabGitLab
  • BitbucketBitbucket
  • SAMLSAML
  • Azure DevOpsAzure DevOps
  • Microsoft AppCenterMicrosoft AppCenter
  • CircleCICircleCI
  • GoCDGoCD
  • TeamCityTeamCity
  • OktaOkta
  • Google WorkspaceGoogle Workspace
  • OneLoginOneLogin
  • Azure Active DirectoryAzure Active Directory
  • SlackSlack
  • VantaVanta
  • ServiceNowServiceNow
  • BitriseBitrise
  • HarnessHarness

ZERO-INSTALL SETUP

Get Started in Minutes

Connect your AI assistants in 3 simple steps

1

1. Generate an API Key

Create an organization API key under Integrations/API → API Keys, with the role your AI client needs.

Ostorlab SettingsScoped Permissions
2

2. Connect Your Client

Add https://api.ostorlab.co/apis/mcp/YOUR_API_KEY/ to your client's MCP configuration (Claude Code, Claude Desktop, Cursor, VS Code and others).

MCP configZero-Install
3

3. Start Prompting

Your AI assistant automatically discovers available tools and can immediately query and manage security data.

Auto-DiscoveryNatural Language

Why Teams Choose Us

Support, Scalability, Transparency

Accompanied at Every Step

Hands-on guidance and support from onboarding to outcome to ensure seamless usage of features evolved through customer feedback.

Free Unlimited Invites

Collaborate without constraints by adding as many profiles as needed per application, enabling teams to work together seamlessly with no user number restrictions and no additional costs.

Continuous Monitoring

Apps previously added to Ostorlab are automatically rescanned whenever updates are pushed. No need to manually trigger scans, ensuring continuous security validation with minimal effort.

No Hidden Fees

Simple, transparent pricing with no hidden costs. Know what you pay for, and back it with a full refund guarantee if unsatisfied.

Trusted by Security Teams Worldwide

Discover why industry experts love working with our platform

4.8 / 5
FAQ

Frequently asked questions

Straight answers on coverage, setup, and how results reach your team.

Can't find your answer? Book a demo or contact us.

Connect AI Directly to Your Security Workflows

Generate an API key in Ostorlab and start querying your security data in minutes.