openlane-mcp
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@openlane-mcplist all high-severity risks in my organization"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Openlane MCP Server
A secure, open-source Model Context Protocol server for the Openlane GRC platform.
This project is not an official Openlane product and is not endorsed by theopenlane, Inc.
Overview
openlane-mcp lets MCP clients such as Cursor and Claude Desktop query Openlane over stdio (default) or Streamable HTTP. It talks to Openlane Cloud or a self-hosted instance through the official Openlane Go client.
MCP Client
→ Openlane MCP Server (stdio or HTTP)
→ Official Openlane Go Client
→ Openlane APIThe server is read-only by default. Write and delete tools are opt-in and independent. Openlane authorization still applies to every request.
Related MCP server: Agentic Ops Platform MCP Server
Features
Openlane MCP access for programs, controls, evidence, policies, risks, standards, tasks, entities (vendors), assets, platforms, contacts, findings, assessments, control implementations, groups, users, and workflows
Enriched get tools with vendor/security fields and compact relationship summaries
List filters on entities, risks, findings, evidence, programs, assessments, implementations, and workflows
Opt-in create/update tools for controls, evidence, policies, risks, tasks, vendors/entities, contacts, vendor Risk Reviews, workflow definitions, workflow assignments, and native policy lifecycle
Opt-in delete tools for the same domains plus workflow definitions (except programs and standards)
Openlane Cloud and self-hosted Openlane (configurable base URL)
stdio transport (default) and opt-in Streamable HTTP transport
Native Go binary
Docker image (published with GitHub Releases)
MCP Registry listing on tagged releases (
io.github.GregDog/mcp-server-theopenlane)
Quick Start
Create an Openlane API token or PAT in console developer settings. Organization tokens start with tola_. Personal access tokens start with tolp_.
export OPENLANE_API_TOKEN="tola_..."
# Optional for multi-org PATs:
export OPENLANE_ORGANIZATION_ID="..."
openlane-mcp serveThen connect an MCP client. See Client configuration.
Installation
From source
go install github.com/GregDog/mcp-server-theopenlane/cmd/openlane-mcp@latestRequires Go 1.27 or later.
GitHub Releases
Binary archives will be published on tagged GitHub Releases (linux/darwin amd64+arm64, windows amd64) with SHA256 checksums.
Docker
docker run --rm -i \
-e OPENLANE_API_TOKEN \
-e OPENLANE_ORGANIZATION_ID \
ghcr.io/gregdog/mcp-server-theopenlane serveImages are published with GitHub Releases to ghcr.io/gregdog/mcp-server-theopenlane.
Client configuration
Cursor (stdio, recommended)
This repository's .cursor/mcp.json uses scripts/mcp-serve.sh, which loads .env and runs the local binary:
{
"mcpServers": {
"openlane": {
"command": "bash",
"args": ["${workspaceFolder}/scripts/mcp-serve.sh"]
}
}
}Or install globally and pass env vars directly:
{
"mcpServers": {
"openlane": {
"command": "openlane-mcp",
"args": ["serve"],
"env": {
"OPENLANE_API_TOKEN": "${env:OPENLANE_API_TOKEN}",
"OPENLANE_ORGANIZATION_ID": "${env:OPENLANE_ORGANIZATION_ID}"
}
}
}
}Cursor (HTTP)
Start the server with bash scripts/mcp-http.sh (see HTTP transport), then use examples/cursor-http.mcp.json as a template.
Claude Desktop
Add to claude_desktop_config.json:
{
"mcpServers": {
"openlane": {
"command": "openlane-mcp",
"args": ["serve"],
"env": {
"OPENLANE_API_TOKEN": "tola_your_token_here"
}
}
}
}Prefer environment substitution or a local secrets store over committing tokens. Examples in this repository use fictional values only.
Security
Read tools are always available. Write tools require OPENLANE_ALLOW_WRITE=true or --allow-write. Delete tools require OPENLANE_ALLOW_DELETE=true or --allow-delete.
A successful read still requires:
An Openlane token with the relevant
object:readscope (or equivalent PAT permissions)Openlane authorization for that object in the selected organization
Writes and deletes additionally require server opt-in (OPENLANE_ALLOW_WRITE / OPENLANE_ALLOW_DELETE) and matching Openlane token permissions. Workflow definition writes, workflow assignment actions, native policy lifecycle actions, and workflow deletes also require confirm: true on the tool call.
Tokens are never logged. See docs/security.md.
Tool coverage
Tool | Description |
| List controls |
| Search controls by ref code, title, or description |
| Get a control by ID (with relationship summaries) |
| List programs (optional name filter) |
| Get a program by ID (with relationship summaries) |
| List evidence metadata (optional program/control filters) |
| Get evidence metadata by ID |
| List internal policies (optional status filter) |
| List policies awaiting approval (native NEEDS_APPROVAL + your pending workflow assignments) |
| Get a policy by ID |
| List risks (optional program/entity/control/status filters) |
| Get a risk by ID (with relationship summaries) |
| List findings (optional program/assessment/open/status/severity filters) |
| Get a finding by ID |
| List assessments |
| Get an assessment by ID |
| List control implementations |
| Get a control implementation by ID |
| List cross-framework control mappings ( |
| Get a control mapping by ID |
| List standards / frameworks |
| Get a standard by ID |
| List tasks |
| Get a task by ID |
| List entities (vendors; optional risk/tier/review/security filters) |
| Get an entity by ID (vendor/security/commercial fields) |
| List assets |
| Get an asset by ID |
| List platforms (system boundaries; optional name, display id, status, environment, region, criticality filters) |
| Get a platform by ID (narrative, owner roles, scope links, diagram metadata) |
| List contacts |
| Get a contact by ID |
| List vendor Risk Reviews (optional entity filter) |
| Get a vendor Risk Review by ID |
| List groups (optional name filter) |
| Get a group by ID |
| List users (optional name/email filters) |
| Get a user by ID |
| List workflow definitions (optional schema/kind/active filters) |
| Search workflow definitions by name or description |
| Get a workflow definition by ID (with plain-English summary) |
| List workflow instances (optional definition/state/object filters) |
| Get a workflow instance by ID (assignments, events, proposal preview) |
| List my workflow approval assignments |
| Get a workflow assignment by ID (targets, due date, object context) |
| Get workflow-eligible fields, edges, and resolver keys per object type |
Write tools (require OPENLANE_ALLOW_WRITE=true or --allow-write):
Tool | Description |
| Create or update a control |
| Create or update cross-framework control mappings ( |
| Create or update evidence; optional |
| Optional |
| Create or update an internal policy |
| Native InternalPolicy status transitions ( |
| Create or update a risk |
| Create or update a task |
| Create or update an entity (vendor); optional base64 logo upload or |
| Create or update a platform (system boundary); owner fields accept user id, email, name, or group id/name; optional scope link ids and base64 diagram uploads |
| Create a contact (optional |
| Create or update a vendor Risk Review |
| Create or update a WorkflowDefinition ( |
| Approve or reject a WorkflowAssignment ( |
| Request changes or reassign an assignment ( |
Delete tools (require OPENLANE_ALLOW_DELETE=true or --allow-delete):
Tool | Description |
| Delete a control by ID |
| Delete a control mapping by ID |
| Delete evidence by ID |
| Delete a policy by ID |
| Delete a risk by ID |
| Delete a task by ID |
| Delete a workflow definition by ID ( |
See docs/tools.md for full details. With all modes enabled there are 77 tools (44 read, 27 write, 6 delete).
Enriched get tools return bounded relationship summaries (count + items) so agents can answer program, vendor, control, and finding questions without chaining dozens of shallow calls.
List responses are paginated (items, next_cursor, has_more, total_count). Default page size is 20; maximum is 50.
There is no dedicated control search GraphQL operation in the current Openlane Go client. openlane_controls_search uses official ControlWhereInput contains-filters.
File contents and presigned download URLs are not returned from read tools. Write tools accept optional base64-encoded files[] on evidence create/update (default max 10 MiB decoded per file).
Linking evidence to controls
openlane_evidence_create accepts optional control_ids; openlane_evidence_update supports add_control_ids / remove_control_ids. Only org-owned controls (owner_id set) may be linked — system catalog copies are rejected (core#1647). Use openlane_controls_search with linkable_only: true to list linkable controls. Program-imported controls may still show source: FRAMEWORK when owner_id is set.
openlane_control_update accepts owner_id and delegate_id as user id, email, name, or group id; user identifiers resolve to managed personal groups (Openlane controlOwnerID / delegateID). Read responses include control_owner and delegate objects with resolved user_email — do not use openlane_user_get on group ids. See docs/openlane-assignee-ids.md (user vs group vs org; what is fixed globally vs controls-only).
For large files[] base64 uploads, prefer a direct MCP client or automation script that passes the payload machine-to-machine. Agent loops that copy content_base64 between tool calls may truncate or corrupt the data.
HTTP transport
By default the server uses stdio. For local HTTP testing:
export OPENLANE_MCP_TRANSPORT=http
export OPENLANE_MCP_HTTP_ADDR=127.0.0.1:8090
openlane-mcp serveThe default bind is loopback only (127.0.0.1:8090). Do not use 0.0.0.0 or bare :port addresses unless you understand the exposure.
HTTP mode has no built-in authentication. Do not expose it directly to the public internet. Anyone who can reach the endpoint can use the server's Openlane token. For remote or shared-network deployment, place a trusted authentication reverse proxy (or equivalent private network controls) in front of the server. See docs/security.md.
Increase OPENLANE_MCP_HTTP_MAX_BODY_BYTES when uploading large evidence files over HTTP.
MCP Registry
Published to the MCP Registry as io.github.GregDog/mcp-server-theopenlane on each tagged release. The OCI package is ghcr.io/gregdog/mcp-server-theopenlane.
Development
make test
make build
./bin/openlane-mcp versionSee docs/development.md.
Contributing
See CONTRIBUTING.md. To add or extend an MCP tool, see docs/adding-tools.md.
Issues labeled good first issue or help wanted are a good place to start.
Licence
Apache License 2.0. See LICENSE.
Openlane names are used only to describe compatibility. Do not copy Openlane logos or imply official endorsement.
This server cannot be deployed
Maintenance
Related MCP Connectors
The Cortex MCP server provides read-only access to real-time engineering context from the Cortex developer portal, allowing AI coding assistants to answer natural language questions about your organization's catalog (microservices, libraries, domains, teams, infrastructure), scorecards (engineering standards and best practices), initiatives (goals and deadlines), and Engineering Intelligence metrics. It includes tools for querying documentation, tracking personal entities, and accessing AI-assisted insights across the entire Cortex ecosystem.
The Remote MCP server acts as a standardized bridge between LLM applications (like Claude, ChatGPT, and Cursor) and external services, enabling AI agents to access external tools and resources. Its primary capability is providing a centralized search tool to discover other MCP servers and their respective tools. Unlike local implementations, it runs remotely with OAuth authentication and permission controls for security.
- QuallaaOAuthcom.quallaa
Talk to your public-facing AI from any MCP client — Claude, ChatGPT, Cursor, Cline, Windsurf.
An MCP server that provides an API to LLMs to manage their JumpCloud resources.
Related MCP Servers
- FlicenseNot gradedqualityBmaintenanceEnables AI agents to securely discover, execute, and observe tools with role-based access control and audit logging. Serves tools over MCP stdio and HTTP for integration with Claude Desktop, Cursor, and other clients.1-
- AlicenseNot gradedqualityCmaintenanceEnables MCP clients like Claude Desktop to drive order, inventory, and billing operations through the same human-approval-gated tools and risk policy as the platform's LangChain agents.MIT
- AlicenseNot gradedqualityBmaintenanceEnables MCP-compatible agents such as Claude and Cursor to retrieve permission-aware, structured context from local or hosted data stores. Exposes tools for semantic search, entity and relationship lookup, memory access, context pack compilation, source attribution, and retrieval explanation.1Apache 2.0
- AlicenseAqualityCmaintenanceEnables any MCP client to run natural-language queries and actions against CRM and ticket systems, with schema-validated tools, audit logging, and server-side write gating.7MIT