Does Semgrep have an MCP server?

Yes Official

Semgrep maintains an official MCP server.

The widely cited semgrep/mcp repo is archived; the MCP server now ships inside the Semgrep CLI as `semgrep mcp`.

Verified 2026-09-29 against vendor docs
Access
Built into the product
Endpoint
Built into the Semgrep CLI — run semgrep mcp
Repository
semgrep/semgrep
Maintainer
Semgrep
License
LGPL-2.1
Language
C
Stars
17k
Last commit
yesterday
What it does
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.
— how semgrep/semgrep describes itself

Project site: semgrep.dev

The receipts
In-product Built into the Semgrep CLI — run semgrep mcp

Ships inside Semgrep's own product rather than as a standalone server. Documented at docs.semgrep.dev.

Official repository semgrep/semgrep

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

★ 17k pushed 2026-09-29 LGPL-2.1 Active
Connect it

Ships inside the vendor's own app or CLI rather than as a standalone download.

Add it from the terminal, then restart your session:

terminal
claude mcp add semgrep -- npx -y <package-from-readme>

Swap in the exact package and flags from the repo README — most servers need an API key passed as an environment variable.

Add --scope user to make it available in every project.

Setup sponsor · open Put your product right here, under the setup steps of all 645 verdict pages. One sponsor at a time. $149 first month, then $399/mo →
Questions
Does Semgrep have an official MCP server?

Yes. Semgrep maintains an official MCP server. The source lives at semgrep/semgrep on GitHub.

How do I connect Semgrep to Claude?

Run the server locally and register it in Claude's MCP config. In Claude Code that's a single "claude mcp add" command; in Claude Desktop you add it to claude_desktop_config.json.

How is this verdict verified?

Semgrep documents its MCP server as part of Semgrep Guardian at docs.semgrep.dev/semgrep-guardian/overview. The server code is in semgrep/semgrep (cli/src/semgrep/mcp) and runs as `semgrep mcp` from the Semgrep-published semgrep PyPI package. GitHub metadata is refreshed every six hours.

How we know

Semgrep documents its MCP server as part of Semgrep Guardian at docs.semgrep.dev/semgrep-guardian/overview. The server code is in semgrep/semgrep (cli/src/semgrep/mcp) and runs as `semgrep mcp` from the Semgrep-published semgrep PyPI package.

  • github data refreshed 2026-09-29, then every 6 hours
  • vendor docs verified on 2026-09-29

Spotted something out of date? Tell us — corrections ship same-day.

Also in Developer Tools

See all Developer Tools servers →