CheckMyLaunch MCP server
README.md
# CheckMyLaunch MCP server
Lets an AI coding tool (Claude Code, Claude Desktop, Cursor, etc.) run a
CheckMyLaunch scan and read back findings + repair prompts without leaving
the chat.
**This is a paid feature.** Every tool call is gated behind a CheckMyLaunch
API key from a paid account (one-time Launch Check purchase or the
Continuous Guard subscription) — get one at
[checkmylaunch.com/account](https://www.checkmylaunch.com/account) after
signing in and upgrading. Without a valid key configured, every tool refuses
with a message pointing you there instead of running.
## Tools
- **scan_repo** `{ repoUrl }` — scans a public GitHub repo.
- **scan_url** `{ url }` — scans a live site.
- **get_repair_prompt** `{ scanId, findingId }` — fetches the paste-back fix
prompt for one finding.
## Setup
1. Sign in at [checkmylaunch.com](https://www.checkmylaunch.com), upgrade to
a paid plan, then go to your account page and generate an API key.
2. Add this to your MCP client's config:
```json
{
"mcpServers": {
"checkmylaunch": {
"command": "npx",
"args": ["github:matdtools-code/checkmylaunch-mcp"],
"env": { "CHECKMYLAUNCH_API_KEY": "cml_live_..." }
}
}
}
```
Claude Code: `claude mcp add` or edit `.claude/mcp.json` /
`~/.claude.json`. Claude Desktop / Cursor: same JSON shape in their
respective MCP config files.
## Try it locally
```
npm install
CHECKMYLAUNCH_API_KEY=cml_live_... node test/smoke.js
```
## Config
- `CHECKMYLAUNCH_API_KEY` — required. From your CheckMyLaunch account page.
- `CHECKMYLAUNCH_API_URL` — override the API base URL (defaults to
`https://www.checkmylaunch.com`); useful for pointing at `localhost:8899`
during development.
## How the gate works
Every tool call first verifies the key against `GET /api/auth/api-key` on
the CheckMyLaunch server, which only resolves for a signed-in, paid account
(see `server/src/routes/auth.js` in the main app repo). A missing, invalid,
or free-plan key stops the call before any scan runs.
This doesn't (and can't) prevent someone from calling CheckMyLaunch's public
`/api/scan/public-github` / `/api/scan/url` endpoints directly without this
plugin — those intentionally stay open, capped at a small free weekly quota
with truncated findings, as the website's own no-signup teaser. What the key
unlocks is the difference that actually matters for real use: uncapped
findings and no weekly quota, from inside your coding tool.
TDQS
A4.6/5.0
Scored across 3 tools
Disambiguation5/5
Each tool has a distinct purpose: scan_repo scans a repository, scan_url scans a live URL, and get_repair_prompt provides repair instructions. No overlap.
Naming Consistency5/5
All tools follow a consistent verb_noun snake_case pattern: scan_repo, scan_url, get_repair_prompt. Highly predictable.
Tool Count4/5
Three tools is a reasonable minimal set for a security scanning server. While it could be expanded, the count is appropriate for the core functionality.
Completeness4/5
The set covers scanning code (repo) and live sites (URL), plus remediation (repair prompt). A minor gap is lack of result listing or management, but core workflows are covered.
Maintenance
ActivityStale
ResponsivenessNo issues