4,500+ servers built on MCP Fusion
Vinkius
Checkmarx logo
Vinkius
Claude Code logo

How to Use the Checkmarx MCP in Claude Code

Run Checkmarx security scans, check IaC configurations, and fetch scan details directly from your terminal using Claude Code and this MCP Server.

See Vinkius in Action

Works with every AI agent you already use

…and any MCP-compatible client

Checkmarx MCP on Cursor AI Code Editor MCP Client Checkmarx MCP on Claude Desktop App MCP Integration Checkmarx MCP on OpenAI Agents SDK MCP Compatible Checkmarx MCP on Visual Studio Code MCP Extension Client Checkmarx MCP on GitHub Copilot AI Agent MCP Integration Checkmarx MCP on Google Gemini AI MCP Integration Checkmarx MCP on Lovable AI Development MCP Client Checkmarx MCP on Mistral AI Agents MCP Compatible Checkmarx MCP on Amazon AWS Bedrock MCP Support
MCP Servers - Free for Subscribers
Claude Code

Connect Checkmarx MCP to Claude Code

Create your Vinkius account to connect Checkmarx to Claude Code and route execution through our secure gateway. The platform manages server hosting, runtime updates, and security layers. Configuration requires no manual server provisioning.

GDPR Free for Subscribers

Terminal-driven AppSec pipelines

Stop bouncing between your terminal and the Checkmarx web UI. Claude Code uses `run_scan` to trigger security runs directly from your shell, making it easy to audit code before a git push. If you realize you made a mistake right after starting a run, you can immediately call `cancel_scan` to kill the active job. By querying `list_scans` and `get_scan_details`, you can check the status of your security pipeline without leaving your terminal. Claude Code pipes these execution timings and engine statuses directly into your CLI workflow.

Command-line IaC security audits

Secure your cloud configurations before they get committed to your repository. Claude Code uses `get_kics_results` to pull targeted security findings for your Terraform, Kubernetes, and Dockerfile setups. The terminal agent lists these infrastructure issues clearly, highlighting high-risk configurations. You can then instruct Claude Code to rewrite the offending YAML or Dockerfile lines right from the command prompt.

Automate vulnerability analysis via MCP Server

Fetching vulnerability reports shouldn't require a browser. Claude Code calls `get_scan_results` to pull down detailed SAST findings, including the exact file paths and line numbers where security flaws exist. To make remediation faster, the MCP Server queries `list_bfl` to find the Best Fix Location. It tells you exactly which file and line to modify to resolve the security issue with the least amount of code changes.

Setup guide

Set up Checkmarx MCP in Claude Code

Prerequisites

  • Claude Code CLI installed (npm install -g @anthropic-ai/claude-code)
  • Active Vinkius subscription with a valid endpoint token
  1. 1

    Run the add command

    Open your terminal and run the command shown on the right. Replace [YOUR_TOKEN_HERE] with your endpoint token from cloud.vinkius.com. Use --scope user to make it available across all projects.

  2. 2

    Verify the connection

    Start a Claude Code session and type /mcp to list connected servers. You should see checkmarx-mcp with a green status indicator.

  3. 3

    Start using tools

    Ask Claude Code something like "Check my latest Checkmarx transactions." It will automatically discover and invoke the available Checkmarx tools.

Terminal
claude mcp add --transport http checkmarx-mcp https://edge.vinkius.com/[YOUR_TOKEN_HERE]/mcp

Why Choose Vinkius

Vinkius connects your tools to AI with real-time monitoring and automatic cost savings — all from one dashboard.

Real-time monitoring

Live

visibility into every interaction

Connect your favorite tools to your AI and see exactly what's happening — every request, every response, in real time.

Built-in savings

60%

lower AI costs

Vinkius compresses data between your apps and your AI automatically. Lower bills every month — no configuration required.

Single dashboard

One

place for every integration

Every tool your AI connects to, managed from a single screen. One account, complete control.

Common questions about Checkmarx MCP in Claude Code

You simply tell Claude Code to run a scan. The agent uses `run_scan` to queue a new security analysis for your project and returns the scan ID to your terminal.
Yes. Claude Code retrieves the vulnerabilities using `get_scan_results` and outputs them in a structured format, allowing you to easily pipe the findings into grep, jq, or local shell scripts.
The agent calls `list_bfl` with the scan and query IDs. Claude Code then displays the exact node in your codebase where a single patch will resolve the security issue.
Yes. You can ask Claude Code to check your scan status, and it will query `get_scan_details` to show you which engines are running and any execution errors.
Your API token is stored locally in your Claude Code configuration file. Your credentials are used by the local MCP Server to make direct HTTPS requests to your Checkmarx One instance, meaning no scan results or vulnerability payloads are ever processed by external third parties.

Start using the Checkmarx MCP today

We host it, we monitor it, we maintain it. You just paste one token.

Built & Managed by Vinkius 30s setup 10 tools

We've already built the connector for Checkmarx. Just plug in your AI agents and start using Vinkius.

No hosting. No infrastructure. No complex setup.
All 10 tools are live and waiting. You're up and running in seconds.

Claude Claude
ChatGPT ChatGPT
Cursor Cursor
Gemini Gemini
Windsurf Windsurf
VS Code VS Code
JetBrains JetBrains
Vercel Vercel
+ other MCP clients

Vinkius gives your AI agents access to the full catalog of app connectors, all fully managed, secure, and enterprise-ready. One subscription, every tool you need.

Zero hosting required Full MCP catalog included Enterprise-grade security Auto-updated by Vinkius

Built, hosted, and secured by Vinkius. You just connect and go.