MCP Tools Directory
← Browse integrations

Developer tools

Snyk API & Web MCP Server

Free account · sign-in required

Contact Snyk API & Web MCP Server

Loading secure sign-in…

Tools for autonomous AI agents

About this integration

MCP server for Snyk API & Web — DAST scanning, findings management, and vulnerability triage

Transport
stdio
Authentication
api-key
Initial setup
credentials
Runtime
unattended
Evidence
documented
Version
1.1.2
Package
snyk-apiweb-mcp
Last compatibility test
Not independently tested

Connect your agent

snyk-apiweb-mcp

Publisher documentation reviewed offline; package, browser automation, credentials, and Snyk service were not executed. Publisher recommends a custom least-privilege key because actions can affect account resources.

Capabilities: Onboard API and web scan targets, Configure target authentication and login sequences, Run DAST scans and triage findings

Connected profiles

Additional details

Registry identifier

io.github.snyk/saw-mcp

Source ↗ · Checked 2026-09-17
Published version

1.1.2

Source ↗ · Checked 2026-09-17
Metadata license

CC0-1.0; package licenses are separate

Source ↗ · Checked 2026-09-17
Package ecosystem

pypi

Source ↗ · Checked 2026-09-17
Required configuration names

MCP_SAW_API_KEY

Source ↗ · Checked 2026-09-17
Source artifact

snyk-apiweb-mcp

Source ↗ · Checked 2026-09-19
Source manifest version

1.3.0

Source ↗ · Checked 2026-09-19
Unattended configuration

Python 3.10+ local MCP process; the documented standalone server starts and waits for an MCP client connection. Browser automation is a separate prerequisite for recorded multi-step web logins.

Source ↗ · Checked 2026-09-19
Authentication and prerequisites

MCP_SAW_API_KEY is required and can be supplied via environment, secret reference, .env, or configuration; a limited-scope key is recommended.

Source ↗ · Checked 2026-09-19
Connection configuration

Configure an MCP client to invoke saw-mcp through uvx from the publisher repository and pass MCP_SAW_API_KEY in the environment.

Source ↗ · Checked 2026-09-19
Review scope

Publisher documentation reviewed; package and integration endpoint not executed or independently security-audited.

Source ↗ · Checked 2026-09-19