Does Semgrep have an MCP server?
Semgrep maintains an official MCP server.
The widely cited semgrep/mcp repo is archived; the MCP server now ships inside the Semgrep CLI as `semgrep mcp`.
- Access
- Built into the product
- Endpoint
- Built into the Semgrep CLI — run semgrep mcp
- Repository
- semgrep/semgrep
- Maintainer
- Semgrep
- License
- LGPL-2.1
- Language
- C
- Stars
- 17k
- Last commit
- yesterday
- Category
- Developer Tools
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.
Project site: semgrep.dev
Ships inside Semgrep's own product rather than as a standalone server. Documented at docs.semgrep.dev.
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.
Ships inside the vendor's own app or CLI rather than as a standalone download.
Add it from the terminal, then restart your session:
claude mcp add semgrep -- npx -y <package-from-readme>Swap in the exact package and flags from the repo README — most servers need an API key passed as an environment variable.
Add --scope user to make it available in every project.
Open Settings → Developer → Edit Config and add the server to claude_desktop_config.json:
{
"mcpServers": {
"semgrep": {
"command": "npx",
"args": [
"-y",
"<package-from-readme>"
],
"env": {
"API_KEY": "…"
}
}
}
}Restart Claude Desktop after saving.
Add to .cursor/mcp.json in your project, or ~/.cursor/mcp.json for
every project:
{
"mcpServers": {
"semgrep": {
"command": "npx",
"args": [
"-y",
"<package-from-readme>"
],
"env": {
"API_KEY": "…"
}
}
}
}A green dot in Settings → MCP means it connected.
Add to .vscode/mcp.json:
{
"servers": {
"semgrep": {
"type": "stdio",
"command": "npx",
"args": [
"-y",
"<package-from-readme>"
]
}
}
}Then pick the server from the tools menu in Copilot's agent mode.
Does Semgrep have an official MCP server?
Yes. Semgrep maintains an official MCP server. The source lives at semgrep/semgrep on GitHub.
How do I connect Semgrep to Claude?
Run the server locally and register it in Claude's MCP config. In Claude Code that's a single "claude mcp add" command; in Claude Desktop you add it to claude_desktop_config.json.
How is this verdict verified?
Semgrep documents its MCP server as part of Semgrep Guardian at docs.semgrep.dev/semgrep-guardian/overview. The server code is in semgrep/semgrep (cli/src/semgrep/mcp) and runs as `semgrep mcp` from the Semgrep-published semgrep PyPI package. GitHub metadata is refreshed every six hours.
Semgrep documents its MCP server as part of Semgrep Guardian at docs.semgrep.dev/semgrep-guardian/overview. The server code is in semgrep/semgrep (cli/src/semgrep/mcp) and runs as `semgrep mcp` from the Semgrep-published semgrep PyPI package.
- github data refreshed 2026-09-29, then every 6 hours
- vendor docs verified on 2026-09-29
Spotted something out of date? Tell us — corrections ship same-day.