{
  "markdown": "![SAW MCP Banner](./assets/Snyk_API_and_Web_Banner.webp)\n\n# Snyk API & Web MCP Server\n\nConnect your AI coding assistant to Snyk API & Web so it can onboard scan targets, configure authentication, run DAST scans, and triage findings — all through natural language.\n\nBuilt on FastMCP 2.0, works with Cursor, Claude Code, Devin, and any MCP-compatible client.\n\n> **Naming note:** Snyk API & Web was formerly known as Probely. The API endpoints (`api.probely.com`), web console (`plus.probely.app`), and MCP tool names (`probely_*`) still use the legacy domain and prefix. Environment variables and config sections use the new `SAW` / `saw` naming.\n\nSee **[USER_GUIDE.md](USER_GUIDE.md)** for usage, examples, and tool reference.\n\n> **This repository is closed to public contributions.** We appreciate community interest, but we do not accept pull requests, issues, or other contributions from external contributors at this time. If you have found a security issue, please see [SECURITY.md](SECURITY.md).\n\n## Requirements\n\n- Python 3.10+\n- Node.js 18+ and npm (for web target login recording via `playwright-cli`; optional if using Playwright MCP instead)\n- Snyk API & Web API key\n\n## Quick Start\n\n### 1. Get Your API Key\n\nGo to [https://plus.probely.app/api-keys](https://plus.probely.app/api-keys) and create an API key.\n\n> **Important**\n>\n> Use a **custom role, limited-scope API key** for the Snyk API & Web MCP Server.\n> Create the key only with the permissions required for the intended actions.\n> Do not use a highly privileged or global API key, as this can affect your entire account and its resources.\n\n### 2. Install\n\n#### Cursor Marketplace (recommended for Cursor users)\n\nInstall directly from the [Cursor Marketplace](https://cursor.com/marketplace/snyk/snyk-api-web):\n\n1. Open the [Snyk API & Web plugin page](https://cursor.com/marketplace/snyk/snyk-api-web) and click **Install**, or go to **Settings → Plugins** and search for **Snyk API & Web**\n2. Set your API key as an environment variable before launching Cursor:\n   ```bash\n   export MCP_SAW_API_KEY=\"your-api-key\"\n   ```\n\nThe plugin installs the MCP server, rules, and skills automatically.\n\n#### Devin MCP Marketplace (Devin users)\n\nInstall directly from Devin's MCP Marketplace:\n\n1. Open Devin and go to **Settings → Configuration**.\n2. Under **MCP servers**, click **Open MCP Marketplace**.\n3. Search for **Snyk API & Web** and click **Install**.\n4. When prompted, enter your API key.\n\nNo manual configuration needed — Devin handles the setup automatically.\n\n#### One-command install (any MCP client)\n\n```bash\nuvx --from git+https://github.com/snyk/saw-mcp.git saw-mcp\n```\n\nOr add to your MCP client configuration:\n\n```json\n{\n  \"mcpServers\": {\n    \"SAW\": {\n      \"command\": \"uvx\",\n      \"args\": [\"--from\", \"git+https://github.com/snyk/saw-mcp.git\", \"saw-mcp\"],\n      \"env\": {\n        \"MCP_SAW_API_KEY\": \"your-api-key\"\n      }\n    }\n  }\n}\n```\n\n<details>\n<summary>Alternative installation methods</summary>\n\n**Install from release tarball**\n\n```bash\ntar -xzvf SnykAPIWeb-<version>.tgz\ncd SnykAPIWeb\npython -m venv venv\nsource venv/bin/activate # On Windows: venv\\Scripts\\activate\npip install -r requirements.txt\n```\n\nDownload from [Releases](https://github.com/snyk/saw-mcp/releases) and replace `<version>` with the actual version number (e.g., `1.0.0`).\n\n**Clone from source**\n\n```bash\ngit clone https://github.com/snyk/saw-mcp.git\ncd saw-mcp\npython -m venv venv\nsource venv/bin/activate # On Windows: venv\\Scripts\\activate\npip install -r requirements.txt\n```\n\n</details>\n\n### 3. Store Your API Key\n\nThe server reads your API key from (in order of precedence): environment variable `MCP_SAW_API_KEY` → `.env` file → `config/config.yaml`.\n\n**Option A: Environment variable** (recommended for Marketplace / `uvx` installs)\n\n```bash\nexport MCP_SAW_API_KEY=\"your-api-key\"\n```\n\n**Option B: `.env` file** (recommended for source installs)\n\nRun the setup script (prompts securely, no key in shell history):\n\n```bash\n./scripts/setup-env.sh\n```\n\nOr pipe from a secret manager: `op read 'op://vault/item/key' | ./scripts/setup-env.sh`\n\nThis writes a `.env` file in the project root (gitignored). The server loads it automatically at startup.\n\n**Option C: Secret reference** (avoids storing the key in plaintext anywhere)\n\n`MCP_SAW_API_KEY` and the config `api_key` field also accept a reference that is resolved at runtime, so the literal key never sits in a file:\n\n```bash\nexport MCP_SAW_API_KEY=\"op://vault/saw-mcp/api-key\"   # resolved via the 1Password CLI (`op`)\nexport MCP_SAW_API_KEY=\"env:MY_SAW_KEY\"               # read from another environment variable\n```\n\n> Avoid committing a plaintext key. `config/config.yaml` is gitignored, and a plaintext key read from it logs a warning at startup.\n\n### 4. Install Browser Automation (web targets with login)\n\nWeb target onboarding records login sequences in a real browser. **Preferred for coding agents:** [`playwright-cli`](https://www.npmjs.com/package/@playwright/cli) via Shell:\n\n```bash\nnpm install -g @playwright/cli@latest\nplaywright-cli install-browser chromium\n```\n\nOr run `./scripts/setup-playwright.sh` from a cloned repo.\n\n**Alternative:** install [Playwright MCP](https://playwright.dev/docs/getting-started-mcp) as a second MCP server (better for MCP-only clients without Shell). See [Web target prerequisites](#web-target-prerequisites).\n\n### 5. Configure Your IDE\n\nIf you installed from the Cursor or Devin marketplace, configuration is automatic. For other clients, add to your MCP client configuration:\n\n```json\n{\n  \"mcpServers\": {\n    \"SAW\": {\n      \"command\": \"uvx\",\n      \"args\": [\"--from\", \"git+https://github.com/snyk/saw-mcp.git\", \"saw-mcp\"],\n      \"env\": {\n        \"MCP_SAW_API_KEY\": \"your-api-key\"\n      }\n    }\n  }\n}\n```\n\nFor host-specific setup see the [Installation Guides](docs/installation-guides/).\n\n<details>\n<summary>Additional configuration options</summary>\n\n- **Override the base URL:** add `\"MCP_SAW_BASE_URL\": \"https://your-instance-url\"` to the `env` block.\n- **Use a config file:** set `\"MCP_SAW_CONFIG_PATH\": \"/path/to/config.yaml\"` instead.\n- **Set log level:** add `\"MCP_SAW_LOG_LEVEL\": \"DEBUG\"` (options: DEBUG, INFO, WARNING, ERROR, CRITICAL; default: INFO).\n\n</details>\n\n### 6. Start Using\n\nAsk your AI assistant to:\n\n- \"Configure a Snyk API & Web API target from this OpenAPI schema / Swagger document / Postman collection.\"\n- \"Configure a Snyk API & Web web target for this authenticated application.\"\n\nSee **[prompts.md](prompts.md)** for a full catalog of example prompts — from simple one-liners to complex multi-target workflows.\n\n### Web target prerequisites\n\nThe SAW MCP server talks to the Snyk API & Web platform — it does not include a browser. To onboard **web targets with login sequences**, the AI needs browser automation via one of:\n\n| Path | Best for | Setup |\n|---|---|---|\n| **`playwright-cli`** (preferred) | Cursor, Devin, Claude Code, Cloud Agents with Shell | `npm install -g @playwright/cli@latest && playwright-cli install-browser chromium` |\n| **[Playwright MCP](https://playwright.dev/docs/getting-started-mcp)** (fallback) | MCP-only clients without Shell (e.g. Claude Desktop) | Add Playwright MCP to your IDE's MCP config |\n\n**Workflow:**\n\n1. Prompt with the target URL and credentials — e.g. *\"Add target example.com with credentials user@example.com / password123\"*.\n2. The AI records the login in a browser (`playwright-cli` or Playwright MCP).\n3. SAW MCP tools create the target and upload the sequence in the [Probely sequence-recorder format](https://github.com/Probely/sequence-recorder).\n\nWithout browser automation, the AI falls back to **form login** (`probely_configure_form_login`) — simple single-page login only; no multi-step flows or 2FA.\n\nSee the [Cursor installation guide](docs/installation-guides/install-cursor.md#browser-automation-for-web-targets) for setup details.\n\n## IDE Integration\n\nDetailed per-host guides live in [`docs/installation-guides/`](docs/installation-guides/):\n\n| Host | Guide |\n|------|-------|\n| **Cursor** | [install-cursor.md](docs/installation-guides/install-cursor.md) |\n| **Claude Desktop** | [install-claude.md](docs/installation-guides/install-claude.md) |\n| **Devin / Other IDEs** | [install-devin.md](docs/installation-guides/install-devin.md) |\n\n## Packaging\n\n```bash\nbash scripts/package.sh\n```\n\nCreates `dist/SnykAPIWeb-<version>.tgz` (version from `snyk_apiweb/__init__.py`).\n\n## Development & Testing\n\n### Run the Server (standalone)\n\nRunning the server directly starts it and waits for an MCP client connection. This is mainly useful for **development and debugging**:\n\n```bash\n./venv/bin/python -m snyk_apiweb.server\n```\n\n### Development Mode (hot reload)\n\nFor active development with automatic reload on file changes:\n\n```bash\n./scripts/dev.sh\n```\n\n## License\n\nThis project is licensed under the [Apache License 2.0](LICENSE).\n\n<!-- mcp-name: io.github.snyk/saw-mcp -->\n",
  "bytes": 8923,
  "sha": "27757b0ce7a3aec0eabc818f3e36c332591fb64c48a957e6f7a38526598c0a5f",
  "repo_slug": "snyk/saw-mcp",
  "fonte": "repo",
  "truncated": false,
  "api": "https://agentalog.com/api/listings/mcp_io_github_snyk_saw_mcp_b5487aa4/readme"
}