Skip to main content
Glama
matdtools-code

CheckMyLaunch MCP server

README.md
# CheckMyLaunch MCP server

Lets an AI coding tool (Claude Code, Claude Desktop, Cursor, etc.) run a
CheckMyLaunch scan and read back findings + repair prompts without leaving
the chat.

**This is a paid feature.** Every tool call is gated behind a CheckMyLaunch
API key from a paid account (one-time Launch Check purchase or the
Continuous Guard subscription) — get one at
[checkmylaunch.com/account](https://www.checkmylaunch.com/account) after
signing in and upgrading. Without a valid key configured, every tool refuses
with a message pointing you there instead of running.

## Tools

- **scan_repo** `{ repoUrl }` — scans a public GitHub repo.
- **scan_url** `{ url }` — scans a live site.
- **get_repair_prompt** `{ scanId, findingId }` — fetches the paste-back fix
  prompt for one finding.

## Setup

1. Sign in at [checkmylaunch.com](https://www.checkmylaunch.com), upgrade to
   a paid plan, then go to your account page and generate an API key.
2. Add this to your MCP client's config:

```json
{
  "mcpServers": {
    "checkmylaunch": {
      "command": "npx",
      "args": ["github:matdtools-code/checkmylaunch-mcp"],
      "env": { "CHECKMYLAUNCH_API_KEY": "cml_live_..." }
    }
  }
}
```

Claude Code: `claude mcp add` or edit `.claude/mcp.json` /
`~/.claude.json`. Claude Desktop / Cursor: same JSON shape in their
respective MCP config files.

## Try it locally

```
npm install
CHECKMYLAUNCH_API_KEY=cml_live_... node test/smoke.js
```

## Config

- `CHECKMYLAUNCH_API_KEY` — required. From your CheckMyLaunch account page.
- `CHECKMYLAUNCH_API_URL` — override the API base URL (defaults to
  `https://www.checkmylaunch.com`); useful for pointing at `localhost:8899`
  during development.

## How the gate works

Every tool call first verifies the key against `GET /api/auth/api-key` on
the CheckMyLaunch server, which only resolves for a signed-in, paid account
(see `server/src/routes/auth.js` in the main app repo). A missing, invalid,
or free-plan key stops the call before any scan runs.

This doesn't (and can't) prevent someone from calling CheckMyLaunch's public
`/api/scan/public-github` / `/api/scan/url` endpoints directly without this
plugin — those intentionally stay open, capped at a small free weekly quota
with truncated findings, as the website's own no-signup teaser. What the key
unlocks is the difference that actually matters for real use: uncapped
findings and no weekly quota, from inside your coding tool.

TDQS

A4.6/5.0

Scored across 3 tools

Disambiguation5/5

Each tool has a distinct purpose: scan_repo scans a repository, scan_url scans a live URL, and get_repair_prompt provides repair instructions. No overlap.

Naming Consistency5/5

All tools follow a consistent verb_noun snake_case pattern: scan_repo, scan_url, get_repair_prompt. Highly predictable.

Tool Count4/5

Three tools is a reasonable minimal set for a security scanning server. While it could be expanded, the count is appropriate for the core functionality.

Completeness4/5

The set covers scanning code (repo) and live sites (URL), plus remediation (repair prompt). A minor gap is lack of result listing or management, but core workflows are covered.

Maintenance

ActivityStale
ResponsivenessNo issues