The Ostorlab MCP Server: Ask Your Security Data Anything
Give your AI assistants scoped, permission-checked access to your scans, vulnerabilities, and remediation data — no custom integration code.
- Zero-install via MCP Streamable HTTP
- Strict API key auth & granular access control
- Direct access to scans, vulnerabilities, remediation & assets
Trusted by security teams at
OFFICIAL MODEL CONTEXT PROTOCOL SERVER
Does Ostorlab Have an MCP Server?
Yes, Ostorlab provides an official Model Context Protocol (MCP) server that connects AI clients directly to your security organization.
What is the Ostorlab MCP Server?
The Ostorlab MCP Server is a hosted integration server built on the Model Context Protocol (MCP) with streamable HTTP transport. Instead of requiring AI models to navigate web UIs or write custom API integration code, it exposes a curated set of typed tools that turn AI intent into scoped, permission-checked actions on your security data.
Direct Security Workflow Automation
By connecting an MCP-capable client (such as Claude Code, Claude Desktop, Cursor, VS Code, Windsurf or Zed), your AI assistant can read, manage and automate Ostorlab workflows across scans, vulnerabilities, remediation tickets, asset inventories and PDF reports, using the same organization API keys and access rules that govern the rest of the Ostorlab platform.
STREAMABLE HTTP TRANSPORT
How the Ostorlab MCP ServerWorks
Built for simplicity, performance, and long-running security tasks
Zero-Install Connection & Auto-Discovery
Point any MCP client at https://api.ostorlab.co/apis/mcp/YOUR_API_KEY/ (the trailing slash is required). Available tools and their arguments are discovered automatically.
Stateless & Async Safe Execution
Every request carries its own authentication context with no session state to manage. Single HTTP calls stay open for long-running operations without polling loops.
Predictable & Resilient Error Handling
Tool failures return clean, structured data objects ({ "error": "description" }), allowing AI clients to handle issues and recover gracefully.
What Your AI Can Do
A comprehensive suite of tools grouped by security capability
Core Security Operations
- Scans: List, filter, inspect progress, start, or stop scans.
- Vulnerabilities: Search, inspect findings, update risk ratings and triage states.
- Remediation & Tickets: Create, read, update, or delete tickets and checklists.
Assets & Integrations
- Asset Inventory: List and manage asset targets and assigned owner attribution.
- Automation & Integrations: Configure automation rules, scheduled scans, tags, and Jira, Slack, ServiceNow and Linear connectors.
- Agentic Deep Scan & Risks: Inspect an Agentic Deep Scan's state, token usage and the risks it surfaced.
Reporting & Evidence
- Scan Reports: Generate a PDF report for a scan and get the download link in chat.
- Data Exports: Export findings as CSV or SARIF, tickets and assets as CSV, or a full scan archive.
- Scan Artefacts: Pull captured HTTP traffic, discovered API endpoints and runtime logs from a scan.
COPY-AND-PASTE PROMPT TEMPLATES
Prompt Inspiration: What Can You Ask?
Here are ready-to-use prompt templates for the Ostorlab MCP server. Replace the [Bracketed Placeholders] to adapt them to your unique environments, compliance needs, and workflows.
Security Audits & Compliance
Generate compliance mappings, check release gates, or gather proof-grade evidence.
You have access to the Ostorlab MCP server. Generate an audit-ready compliance report for our target environment and verify security release gates before deployment.
Audit Parameters:
- Target Assets: [Asset Type & Identifier, e.g., mobile apps / web services / domain.com]
- Compliance Frameworks: [Primary Framework 1, e.g., OWASP MASVS] and [Framework 2, e.g., PCI-DSS v4.0]
- Target Release Milestone: [Environment, e.g., iOS and Android production release v3.4.0]
- Focus Vulnerabilities: [Vulnerability Focus, e.g., authentication/2FA bypass / SQL injection]
Execution Steps:
1. Query Ostorlab MCP for all completed scans and open findings matching [Target Assets] and [Target Release Milestone].
2. Map each identified finding to the corresponding security requirements of [Primary Framework 1] and [Framework 2].
3. Evaluate security release gate criteria: verify if any open Critical or High findings block the release for [Target Release Milestone].
4. Pull the vulnerability details and captured HTTP traffic for all [Focus Vulnerabilities].
5. Generate the PDF scan report with Ostorlab MCP and export the findings as CSV or SARIF.
Required Output & Constraints:
- Provide an Executive Audit Summary table with: Framework Control ID, Finding Title, Severity, Gate Status (PASSED/BLOCKED).
- Include an explicit Release Gate Decision with justification.
- Attach raw evidence logs and reproduction steps formatted for board/auditor review.
- Do not pass release gates if un-triaged Critical findings remain unresolved.Built for Security and Trust
Designed to ensure your organization's data remains strictly controlled and audited, even with autonomous agents at the wheel.
Strict API Key Authentication
Authentication uses organization API keys. The key's role (reader, user, admin or attack-surface auditor) decides which tools the AI can call.
Secrets Are Never Returned
Tokens, passwords, OAuth secrets and webhook URLs are never returned in tool responses.
Granular Access Scoping & Audit Trails
With object-level access enabled, a key only sees the scans, tickets and assets it has been granted. Changes can be reviewed in your organization audit log.
Destructive Action Hints
Irreversible tools (like deleting tickets or assets) are annotated as destructive, so your MCP client can ask for confirmation before running them.
Works with Any MCP-Capable Client
Connect Claude Code, Claude Desktop, Cursor, VS Code, Windsurf, Zed or your own agents over streamable HTTP.
Jira
Linear
Jenkins
GitHub
GitLab
Bitbucket
SAML
Azure DevOps
Microsoft AppCenterCircleCI
GoCDTeamCity
Okta
Google Workspace
OneLogin
Azure Active DirectorySlack
VantaServiceNow
Bitrise
Harness
ZERO-INSTALL SETUP
Get Started in Minutes
Connect your AI assistants in 3 simple steps
1. Generate an API Key
Create an organization API key under Integrations/API → API Keys, with the role your AI client needs.
2. Connect Your Client
Add https://api.ostorlab.co/apis/mcp/YOUR_API_KEY/ to your client's MCP configuration (Claude Code, Claude Desktop, Cursor, VS Code and others).
3. Start Prompting
Your AI assistant automatically discovers available tools and can immediately query and manage security data.
Why Teams Choose Us
Support, Scalability, Transparency
Accompanied at Every Step
Hands-on guidance and support from onboarding to outcome to ensure seamless usage of features evolved through customer feedback.
Free Unlimited Invites
Collaborate without constraints by adding as many profiles as needed per application, enabling teams to work together seamlessly with no user number restrictions and no additional costs.
Continuous Monitoring
Apps previously added to Ostorlab are automatically rescanned whenever updates are pushed. No need to manually trigger scans, ensuring continuous security validation with minimal effort.
No Hidden Fees
Simple, transparent pricing with no hidden costs. Know what you pay for, and back it with a full refund guarantee if unsatisfied.
Curious what we've been up to ...
Very efficient team, the support engineers are very good and knowledgeable. The product is always evolving and they take customer input very seriously.
A reliable product with unique features and a personalized approach to products.
The platform helped us evaluate our internal mobile applications easily and efficiently. The onboarding was smooth and the UI dynamic automation is great.
The product meets our needs perfectly and is easy to set up and use. The team is very reactive.
Very professional and technical. Five star. Excellent delivery.
We selected Ostorlab as our sole partner in providing mobile applications and web vulnerability scans. We have a very good partnership.
Their customer service is top notch and their product is constantly improving.
Easy to use and getting better with new updates, they are also quick to help and very efficient.
Great product, with amazing customer service, very useful, accurate, and straightforward to use.
Prompt support and personalized features highlighted.
I had a very excellent experience with Ostorlab as a MAST solution.
Very efficient team, the support engineers are very good and knowledgeable. The product is always evolving and they take customer input very seriously.
A reliable product with unique features and a personalized approach to products.
The platform helped us evaluate our internal mobile applications easily and efficiently. The onboarding was smooth and the UI dynamic automation is great.
The product meets our needs perfectly and is easy to set up and use. The team is very reactive.
Very professional and technical. Five star. Excellent delivery.
We selected Ostorlab as our sole partner in providing mobile applications and web vulnerability scans. We have a very good partnership.
Their customer service is top notch and their product is constantly improving.
Easy to use and getting better with new updates, they are also quick to help and very efficient.
Great product, with amazing customer service, very useful, accurate, and straightforward to use.
Prompt support and personalized features highlighted.
I had a very excellent experience with Ostorlab as a MAST solution.
Very efficient team, the support engineers are very good and knowledgeable. The product is always evolving and they take customer input very seriously.
A reliable product with unique features and a personalized approach to products.
The platform helped us evaluate our internal mobile applications easily and efficiently. The onboarding was smooth and the UI dynamic automation is great.
The product meets our needs perfectly and is easy to set up and use. The team is very reactive.
Very professional and technical. Five star. Excellent delivery.
We selected Ostorlab as our sole partner in providing mobile applications and web vulnerability scans. We have a very good partnership.
Their customer service is top notch and their product is constantly improving.
Easy to use and getting better with new updates, they are also quick to help and very efficient.
Great product, with amazing customer service, very useful, accurate, and straightforward to use.
Prompt support and personalized features highlighted.
I had a very excellent experience with Ostorlab as a MAST solution.
Frequently asked questions
Straight answers on coverage, setup, and how results reach your team.
Can't find your answer? Book a demo or contact us.
Connect AI Directly to Your Security Workflows
Generate an API key in Ostorlab and start querying your security data in minutes.







