Semgrep MCP Server
Secure code with Semgrep static analysis. Find vulnerabilities, enforce coding standards, and automate security reviews.
- Maintained by
- Semgrep
- Hosting
- Runs locally on your machine
- Authentication
- None beyond local access
- Last checked
Now built into the semgrep CLI (install Semgrep first); the standalone semgrep/mcp repo is deprecated.
How to connect the Semgrep MCP server
Pick your AI client and paste the snippet. New to this? Our guide to how MCP clients and servers fit together explains what each piece does.
Claude Code
claude mcp add --transport stdio semgrep \
-- semgrep mcp Claude Desktop
{
"mcpServers": {
"semgrep": {
"command": "semgrep",
"args": [
"mcp"
]
}
}
} Fully quit and reopen Claude Desktop after saving.
Full Claude Desktop setup guide →Cursor
{
"mcpServers": {
"semgrep": {
"command": "semgrep",
"args": [
"mcp"
]
}
}
} VS Code
{
"servers": {
"semgrep": {
"type": "stdio",
"command": "semgrep",
"args": [
"mcp"
]
}
}
} Frequently asked questions
What is the Semgrep MCP server?
It is a Model Context Protocol (MCP) server — a small piece of software that gives AI assistants like Claude a secure, governed connection to Semgrep. Secure code with Semgrep static analysis. Find vulnerabilities, enforce coding standards, and automate security reviews.
Is there an official Semgrep MCP server?
Yes. The Semgrep MCP server is an official integration, maintained by the vendor or the Model Context Protocol project, which makes it the safest default for business use. It is maintained by Semgrep.
Is the Semgrep MCP server hosted, or do I run it myself?
It runs locally. Your AI client starts it on your own machine with semgrep, and it talks to the client over standard input and output rather than the network.
Do I need an API key for the Semgrep MCP server?
No. It runs on your machine with your own permissions, so there is no key to create.
What can an AI assistant actually do with Semgrep?
Through this server an assistant can work with sast, security rules, code scanning, compliance — reading from and acting on Semgrep directly instead of you copy-pasting between windows. What you allow it to do is controlled by the permissions you grant.
How do I set this up for my business?
The setup section above has copy-paste config for Claude Code, Claude Desktop, Cursor and VS Code. If you want it rolled out across a team with permissions, governance and support handled, that is what Crox's Build engagement covers.
New to MCP? Start with our plain-English guide to the Model Context Protocol or see how to connect AI to your business tools without writing code .
Want this connected to your business — with governance handled?
Crox maps your processes, connects AI to the tools you already use, and keeps it working as models change. Start with a readiness assessment or talk to us about a build.