Veracode MCP
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Veracode MCPShow me the high-severity findings from the last scan"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Veracode MCP
Quick Start
1. Install
pip install -r requirements.txt2. Add credentials to .env
VERACODE_API_ID=your_api_id
VERACODE_API_KEY=your_api_keyGet these from Veracode Platform → My Profile → API Credentials
3. Add to .cursor/mcp.json
{
"mcpServers": {
"veracode": {
"command": "python",
"args": ["server.py"],
"cwd": "C:/path/to/veracode-mcp"
}
}
}Set
cwdto the full path of theveracode-mcpfolder on your machine.
Examples:
Windows:
"cwd": "C:/Users/you/veracode-mcp"macOS/Linux:
"cwd": "/home/you/veracode-mcp"Not sure of the path? Run this in your terminal to print it:
# Windows (PowerShell) (Get-Item .\veracode-mcp).FullName # macOS / Linux realpath ./veracode-mcp
Restart Cursor — that's it. Ask Cursor to run a Veracode scan and it will use the tools automatically.
Related MCP server: Snyk MCP REST
What you can ask Cursor
"List my Veracode applications"
"Zip the bin folder and run a SAST scan on app 12345"
"Wait for the scan to finish and show me the findings"
"Show me SCA vulnerabilities from the last scan"
"List my SCA workspaces and get CVEs for my project"
This server cannot be deployed
Maintenance
Related MCP Connectors
Generate SBOMs, scan vulnerabilities, and analyze dependencies from local projects or Git repos.
Zero-config MCP security scanner for AI-generated apps. 25K+ vulnerability patterns.
Vulnerability management: scan projects, search sealed packages, manage sealing rules and reports.
AI pentesting: run scans, triage vulnerabilities, review PRs, manage schedules and assets.
Related MCP Servers
- AlicenseNot gradedqualityBmaintenanceIntegrates 15+ static application security testing tools (Semgrep, Bandit, TruffleHog, etc.) with Claude Code AI, enabling automated vulnerability scanning and security analysis through natural language commands. Supports cross-platform operation with remote execution on dedicated security VMs.6MIT
- AlicenseNot gradedqualityFmaintenanceProvides security scanning capabilities through Snyk CLI tools and REST API, enabling AI assistants to test projects for vulnerabilities, retrieve security issues, and manage Snyk projects with comprehensive SAST, container, and infrastructure as code scanning.2MIT
- AlicenseAqualityDmaintenanceEnables AI assistants to scan project dependencies and Infrastructure as Code files for security vulnerabilities and misconfigurations. It also provides automated fixing capabilities to remediate identified security issues.183MIT

Snyk API & Web MCP Serverofficial
AlicenseCqualityAmaintenanceConnects AI coding assistants to Snyk API & Web for onboarding scan targets, configuring authentication, running DAST scans, and triaging findings through natural language.518Apache 2.0