Ostorlab Logo
Pricing Partners

The Ostorlab MCP Server: Ask Your Security Data Anything

Give your AI assistants scoped, permission-checked access to your scans, vulnerabilities, and remediation data — no custom integration code.
Zero-install via MCP Streamable HTTP
Strict API key auth & granular access control
Direct access to scans, vulnerabilities, remediation & assets
ostorlab-mcp ~ bash
Ask your AI:

They trust us

Google
TikTok
BMW
Panasonic
Cisco
Rolex
Deloitte
Edenred
Ooredoo

OFFICIAL MODEL CONTEXT PROTOCOL SERVER

Does Ostorlab Have an MCP Server?

Yes, Ostorlab provides an official Model Context Protocol (MCP) server that connects AI clients directly to your security organization.

1

What is the Ostorlab MCP Server?

The Ostorlab MCP Server is a standardized, enterprise-grade integration server built on the Model Context Protocol (MCP) using streamable HTTP transport. Instead of requiring AI models to navigate web UIs or write custom API integration code, the server translates AI intent into scoped, permission-checked actions on your security data.

Model Context ProtocolStreamable HTTPZero API Code
2

Direct Security Workflow Automation

By connecting an MCP-capable client—such as Claude Desktop, Cursor IDE, Windsurf, or Google Antigravity—your AI system can directly read, manage, and automate Ostorlab security workflows across scans, vulnerabilities, remediation tickets, asset inventories, and compliance reporting using the exact same access rules and organization API keys that govern the rest of the Ostorlab platform.

Scans & VulnsTickets & AssetsAPI Key Scoped

STREAMABLE HTTP TRANSPORT

How the Ostorlab MCP ServerWorks

Built for simplicity, performance, and long-running security tasks

1

Zero-Install Connection & Auto-Discovery

Point any MCP client at our server endpoint (https://<host>/apis/mcp/<api-key>). Available tools and schemas are discovered automatically.

Streamable HTTPAuto-DiscoveryZero-Install
2

Stateless & Async Safe Execution

Every request carries its own authentication context with no session state to manage. Single HTTP calls stay open for long-running operations without polling loops.

StatelessAsync SafeNo Polling
3

Predictable & Resilient Error Handling

Tool failures return clean, structured data objects ({ "error": "description" }), allowing AI clients to handle issues and recover gracefully.

Structured OutputResilient

What Your AI Can Do

A comprehensive suite of tools grouped by security capability

Core Security Operations

  • Scans: List, filter, inspect progress, start, or stop scans.
  • Vulnerabilities: Search, inspect findings, update risk ratings and triage states.
  • Remediation & Tickets: Create, read, update, or delete tickets and checklists.

Assets & Integrations

  • Asset Inventory: List and manage asset targets and assigned owner attribution.
  • Automation & Integrations: Configure notification rules, tags, and Jira/Slack connectors.
  • AI Pentest & Risk: Inspect agentic deep-scan activities and surfaced risks.

Reporting & Compliance

  • Audit Reports: Generate PDF compliance reports directly in chat.
  • Data Exports: Stream machine-readable JSON/CSV evidence to AI context.
  • Evidence Logs: Extract raw HTTP request/response validation proofs.

COPY-AND-PASTE PROMPT TEMPLATES

Prompt Inspiration: What Can You Ask?

Here are ready-to-use prompt templates for the Ostorlab MCP server. Replace the [Bracketed Placeholders] to adapt them to your unique environments, compliance needs, and workflows.

Security Audits & Compliance

Generate compliance mappings, check release gates, or gather proof-grade evidence.

You have access to the Ostorlab MCP server. Generate an audit-ready compliance report for our target environment and verify security release gates before deployment.

Audit Parameters:
- Target Assets: [Asset Type & Identifier, e.g., mobile apps / web services / domain.com]
- Compliance Frameworks: [Primary Framework 1, e.g., OWASP MASVS] and [Framework 2, e.g., PCI-DSS v4.0]
- Target Release Milestone: [Environment, e.g., iOS and Android production release v3.4.0]
- Focus Vulnerabilities: [Vulnerability Focus, e.g., authentication/2FA bypass / SQL injection]

Execution Steps:
1. Query Ostorlab MCP for all completed scans and open findings matching [Target Assets] and [Target Release Milestone].
2. Map each identified finding to the corresponding security requirements of [Primary Framework 1] and [Framework 2].
3. Evaluate security release gate criteria: verify if any open Critical or High findings block the release for [Target Release Milestone].
4. Extract proof-grade reproduction logs and HTTP validation traces for all [Focus Vulnerabilities].
5. Generate the official audit report artifact using Ostorlab MCP's compliance export tool.

Required Output & Constraints:
- Provide an Executive Audit Summary table with: Framework Control ID, Finding Title, Severity, Gate Status (PASSED/BLOCKED).
- Include an explicit Release Gate Decision with justification.
- Attach raw evidence logs and reproduction steps formatted for board/auditor review.
- Do not pass release gates if un-triaged Critical findings remain unresolved.

Built for Security and Trust

Designed to ensure your organization's data remains strictly controlled and audited, even with autonomous agents at the wheel.

Strict API Key Authentication

Authentication is enforced via organization API keys with granular READ, WRITE, or ADMIN permissions.

Secrets Are Never Returned

Tokens, passwords, OAuth secrets, and webhook URLs are aggressively sanitized from all tool responses.

Granular Access Scoping & Audit Trails

AI clients only see explicitly granted assets. Every mutation is logged in your organization audit trail.

Destructive Action Protections

Irreversible actions (like deleting tickets or assets) are flagged to require explicit human confirmation.

Works with Any MCP-Capable Client

Seamlessly connect Claude Desktop, Cursor IDE, Windsurf, LangChain, and custom autonomous agents.

Jira

Jenkins

GitHub

GitLab

Bitbucket

SAML

Azure DevOps

Microsoft AppCenter

CircleCI

GoCD

TeamCity

Okta

Google Workspace

OneLogin

Azure Active Directory

Slack

Vanta

ServiceNow

Bitrise

Harness

ZERO-INSTALL SETUP

Get Started in Minutes

Connect your AI assistants in 3 simple steps

1

1. Generate an API Key

Create an organization API key in Ostorlab settings with the exact scopes required for your AI client.

Ostorlab SettingsScoped Permissions
2

2. Connect Your Client

Add https://<platform-host>/apis/mcp/<api-key> to your MCP config (e.g. mcp_config.json for Claude, Cursor, or AGY).

mcp_config.jsonZero-Install
3

3. Start Prompting

Your AI assistant automatically discovers available tools and can immediately query and manage security data.

Auto-DiscoveryNatural Language

Why Teams Choose Us

Support, Scalability, Transparency

Accompanied at Every Step

Hands-on guidance and support from onboarding to outcome to ensure seamless usage of features evolved through customer feedback.

Free Unlimited Invites

Collaborate without constraints by adding as many profiles as needed per application, enabling teams to work together seamlessly with no user number restrictions and no additional costs.

Continuous Monitoring

Apps previously added to Ostorlab are automatically rescanned whenever updates are pushed. No need to manually trigger scans, ensuring continuous security validation with minimal effort.

No Hidden Fees

Simple, transparent pricing with no hidden costs. Know what you pay for, and back it with a full refund guarantee if unsatisfied.

Trusted by Security Teams Worldwide

Discover why industry experts love working with our platform

Star 1
Star 2
Star 3
Star 4
Star 5
4.9 / 5

Curious what we've been up to ...

From Signal to the Android SDK: Chaining Path Traversal, Mimetype Confusion, Security Check Bypass and File Descriptor Bruteforce for Arbitrary File Access

Read more →

From Random to Intelligent: How AI-Powered Monkey Testing Achieves 10x Mobile App Coverage

Read more →

Automating Security Research: AI Engine Exploits Zulip Stored XSS (CVE-2025-52559)

Read more →

Frequently Asked Questions

If you have any questions that are not listed here, send them to us via contact

Get Started

Connect AI Directly to Your Security Workflows

Generate an API key in Ostorlab and start prompting your security data in under 2 minutes.