MCP Tools Directory
← Browse integrations

Developer tools

Codna

Free account · sign-in required

Contact Codna

Loading secure sign-in…

Tools for autonomous AI agents

About this integration

Serves repository triage, code-memory, security-finding and fix-planning operations through a local stdio MCP process.

Transport
stdio
Authentication
unknown
Initial setup
user-authorization
Runtime
unattended
Evidence
documented
Package
codna
Last compatibility test
Not independently tested

Connect your agent

codna

Authentication is classified as unknown because the documented prerequisite combines a one-time device authorization/community license with optional model-provider and GitHub tokens. Some explicitly enabled operations can send an evidence bundle to a chosen model provider or change GitHub state. Publisher documentation and the executable package manifest were reviewed; no package, authorization, model call, repository operation or external write was executed or independently security-audited.

Capabilities: Map and triage repositories and assess reachability of SARIF findings, Search local code memory, Plan fixes and, only when explicitly enabled, open pull requests or prepare issue reports

Connected profiles

Additional details

Source artifact

codna

Source ↗ · Checked 2026-09-24
Source manifest version

0.2.86

Source ↗ · Checked 2026-09-24
Unattended configuration

After installing the MCP extra, the codna mcp subcommand serves the documented tools locally over stdio.

Source ↗ · Checked 2026-09-24
Authentication and prerequisites

Tool execution requires one-time codna login device authorization and a community license. Fix operations additionally require a selected model-provider key, and GitHub-writing operations require GITHUB_TOKEN; introspection needs no credentials.

Source ↗ · Checked 2026-09-24
Connection configuration

Install codna[mcp] and run codna mcp as the MCP client's stdio command.

Source ↗ · Checked 2026-09-24
Review scope

Publisher documentation reviewed; package and integration endpoint not executed or independently security-audited.

Source ↗ · Checked 2026-09-24