CrowdSec MCP Server for Claude CodeGive Claude Code instant access to 3 tools to Get Cti Smoke, Get Decisions, Get Decisions Stream
Claude Code is Anthropic's agentic CLI for terminal-first development. Add CrowdSec as an MCP server in one command and Claude Code will discover every tool at runtime. ideal for automation pipelines, CI/CD integration, and headless workflows via Vinkius.
Ask AI about this MCP Server for Claude Code
The CrowdSec MCP Server for Claude Code is a standout in the Fort Knox category — giving your AI agent 3 tools to work with, ready to go from day one.
Vinkius delivers Streamable HTTP and SSE to any MCP client
# Your Vinkius token. get it at cloud.vinkius.com
claude mcp add crowdsec --transport http "https://edge.vinkius.com/[YOUR_TOKEN_HERE]/mcp"Vinkius Desktop App
The modern way to manage MCP Servers — no config files, no terminal commands. Install CrowdSec and 4,000+ MCP Servers from a single visual interface.





* Every MCP server runs on Vinkius-managed infrastructure inside AWS - a purpose-built runtime with per-request V8 isolates, Ed25519 signed audit chains, and sub-40ms cold starts optimized for native MCP execution. See our infrastructure
About CrowdSec MCP Server
Connect your CrowdSec security engine to any AI agent to take full control of your threat intelligence and network defense through natural conversation.
Claude Code registers CrowdSec as an MCP server in a single terminal command. Once connected, Claude Code discovers all 3 tools at runtime and can call them headlessly. ideal for CI/CD pipelines, cron jobs, and automated workflows where CrowdSec data drives decisions without human intervention.
What you can do
- Local Decisions — Query your Local API (LAPI) for active blocks or decisions on specific IPs, ranges, or scopes to understand current local threats.
- Decision Streaming — Poll for real-time updates on new and deleted decisions from your local database to keep your security context synchronized.
- Global CTI Reputation — Fetch global IP reputation data, behaviors, and classifications from the CrowdSec Community Threat Intelligence (CTI) network.
- Security Auditing — Inspect metadata and classifications for suspicious actors directly from your command interface or code editor.
The CrowdSec MCP Server exposes 3 tools through the Vinkius. Connect it to Claude Code in under two minutes — credentials fully managed, no infrastructure to provision, no vendor lock-in. Your configuration, your data, your control.
All 3 CrowdSec tools available for Claude Code
When Claude Code connects to CrowdSec through Vinkius, your AI agent gets direct access to every tool listed below — spanning threat-intelligence, firewall-management, ip-reputation, and more. Every call runs in a secure, isolated environment with full audit visibility. Beyond a simple connection, you get real-time monitoring of agent activity, enterprise governance, and optimized token usage.
Get cti smoke on CrowdSec
Get CTI reputation for an IP
Get decisions on CrowdSec
Query CrowdSec LAPI for decisions
Get decisions stream on CrowdSec
Poll for new and deleted decisions from LAPI
Connect CrowdSec to Claude Code via MCP
Follow these steps to wire CrowdSec into Claude Code. The entire setup takes under two minutes — your credentials stay safe behind Vinkius.
Install Claude Code
npm install -g @anthropic-ai/claude-code if not already installedAdd the MCP Server
Verify the connection
claude mcp to list connected servers, or type /mcp inside a sessionStart using CrowdSec
Why Use Claude Code with the CrowdSec MCP Server
Claude Code provides unique advantages when paired with CrowdSec through the Model Context Protocol.
Single-command setup: `claude mcp add` registers the server instantly. no config files to edit or applications to restart
Terminal-native workflow means MCP tools integrate seamlessly into shell scripts, CI/CD pipelines, and automated DevOps tasks
Claude Code runs headlessly, enabling unattended batch processing using CrowdSec tools in cron jobs or deployment scripts
Built by the same team that created the MCP protocol, ensuring first-class compatibility and the fastest adoption of new protocol features
CrowdSec + Claude Code Use Cases
Practical scenarios where Claude Code combined with the CrowdSec MCP Server delivers measurable value.
CI/CD integration: embed CrowdSec tool calls in your deployment pipeline to validate configurations or fetch secrets before shipping
Headless batch processing: schedule Claude Code to query CrowdSec nightly and generate reports without human intervention
Shell scripting: pipe CrowdSec outputs into other CLI tools for data transformation, filtering, and aggregation
Infrastructure monitoring: run Claude Code in a cron job to query CrowdSec status endpoints and alert on anomalies
Example Prompts for CrowdSec in Claude Code
Ready-to-use prompts you can give your Claude Code agent to start working with CrowdSec immediately.
"Check if there are any active decisions for IP 1.2.3.4 in our local CrowdSec database."
"Get the latest stream of decisions from CrowdSec to see recent blocks."
"What is the global reputation of IP 185.220.101.101 according to CrowdSec CTI?"
Troubleshooting CrowdSec MCP Server with Claude Code
Common issues when connecting CrowdSec to Claude Code through Vinkius, and how to resolve them.
Command not found: claude
npm install -g @anthropic-ai/claude-codeConnection timeout
CrowdSec + Claude Code FAQ
Common questions about integrating CrowdSec MCP Server with Claude Code.
How do I add an MCP server to Claude Code?
claude mcp add --transport http "" in your terminal. Claude Code registers the server and discovers all tools immediately.Can Claude Code run MCP tools in headless mode?
How do I list all connected MCP servers?
claude mcp in your terminal to see all registered servers and their status, or type /mcp inside an active Claude Code session.Explore More MCP Servers
View all →
Porsline
12 toolsAutomate surveys and feedback via Porsline — manage surveys, responses, and reports directly from any AI agent.

Google Firestore Collection
3 toolsThis MCP does exactly one thing: it manages documents in a single Google Firestore Collection. That's its only function, and nothing else. Incredible for giving your AI a secure NoSQL database.

ScreenshotAPI
12 toolsCapture full-page website screenshots programmatically with custom viewport sizes, delays, and rendering options via a simple API.

CourtListener
10 toolsManage your legal research — search court opinions, dockets, and citations via AI.
