Bring Code Security
to VS Code Copilot
Create your Vinkius account to connect Aikido Security to VS Code Copilot and start using all 16 AI tools in minutes. Fully managed, enterprise secure, and ready to use without writing a single line of code. No hosting, no server setup — just connect and start using.
Compatible with every major AI agent and IDE
What is the Aikido Security MCP Server?
Connect your Aikido Security account to any AI agent and take full control of your security posture monitoring through natural conversation.
What you can do
- Open Issues — List all open security vulnerabilities (CVEs, leaked secrets, cloud misconfigs, SAST findings) ordered by priority
- Repository Scanning — View all connected code repositories and their scanning status across GitHub, GitLab, Bitbucket
- Cloud Asset Monitoring — List cloud infrastructure assets from AWS, GCP, and Azure being monitored for misconfigurations
- Container Security — Monitor container images and registries for known vulnerabilities
- Compliance Tracking — Get ISO 27001 and SOC2 compliance overviews for audit preparation
- Export Issues — Bulk export all security findings for reporting and analysis
- Webhook Management — List configured webhooks for Slack, Jira, and other integrations
How it works
- Subscribe to this server
- Enter your Aikido API token from User Settings > Personal Access Tokens
- Start monitoring security issues, checking compliance, and auditing your posture from Claude, Cursor, or any MCP-compatible client
No more navigating the Aikido dashboard for every security review. Your AI acts as a dedicated security analyst.
Who is this for?
- Security Engineers — instantly triage open vulnerabilities by severity and priority without opening the Aikido dashboard
- DevOps Teams — monitor cloud assets and container images for misconfigurations and known CVEs
- Compliance Officers — check ISO 27001 and SOC2 compliance status before audits
- Engineering Managers — export security reports and track remediation progress across teams
Built-in capabilities (16)
This provides a comprehensive snapshot of your organization's security posture. Use this for compliance reporting, audit preparation, or bulk analysis of vulnerabilities. Export all security issues from Aikido
Shows which controls are passing, failing, or need attention. Use this for compliance monitoring, audit preparation, and security posture reporting. This endpoint is available on all paid Aikido plans. Get ISO 27001 compliance overview for your organization
The issue group ID can be obtained from list_open_issues. Each issue group represents a category of related vulnerabilities (e.g., the same CVE across multiple repositories). Use this to deep-dive into a specific security finding before deciding on remediation steps. Get detailed information about a specific security issue group
Shows which trust service criteria are met and which need remediation. Use this for SOC2 audit preparation and compliance monitoring. This endpoint is available on all paid Aikido plans. Get SOC2 compliance overview for your organization
Use this to verify your workspace setup and check for any configuration errors. Get workspace information and configuration
Shows which apps have active protection and their configuration status. Use this to verify your web applications are properly secured against common attacks (SQL injection, XSS, etc.). List all web applications protected by Aikido firewall
You can paginate through results and optionally search by text or sort by name, asset type, region, etc. Use this to understand your cloud attack surface and identify misconfigurations or vulnerabilities. List cloud infrastructure assets monitored by Aikido
This includes repositories connected from GitHub, GitLab, Bitbucket, etc. Use this to discover which repositories are being monitored for vulnerabilities and security issues. List all active code repositories connected to Aikido
Shows which cloud environments are being monitored for security misconfigurations and vulnerabilities. Use this to verify cloud integrations are properly configured. List all cloud accounts connected to Aikido
This includes Docker images from registries like Docker Hub, ECR, GCR, etc. Use this to monitor container security and identify vulnerable base images or dependencies. List all container images and repositories scanned by Aikido
Custom rules allow you to define organization-specific security checks beyond the default scanner. Use this to audit your custom rule coverage and ensure your security policies are properly enforced. List all custom SAST scanning rules in Aikido
Issues include vulnerabilities from code scanning, container scanning, cloud security, SAST, IaC, DAST, and more. You can optionally filter by issue type (open_source, leaked_secret, cloud, sast, iac, docker_container, etc.), by team ID, or by repository. Supports pagination with page and per_page parameters. Use this to get a comprehensive view of your organization's security posture and prioritize remediation efforts. List all open security issues (vulnerabilities) in your Aikido account
Teams are used to organize repositories, assign issues, and manage security workflows. Use this to understand how your organization structures its security responsibilities. List all teams in your Aikido organization
Shows user roles, permissions, and access levels. Use this to audit user access and ensure proper security team membership. List all users in your Aikido organization
Use this to understand your VM attack surface and identify security gaps. List all virtual machines monitored by Aikido
Webhooks are used to send security event notifications to external systems (Slack, Jira, etc.). Use this to verify integrations are properly configured and troubleshoot notification delivery. List all configured webhooks in Aikido
Why VS Code Copilot?
GitHub Copilot Agent mode brings Aikido Security data directly into your VS Code workflow. With a project-scoped config, the entire team shares access to 16 tools. Copilot queries live data, generates typed code, and writes tests from actual API responses, all without leaving the editor.
- —
VS Code is used by over 70% of developers. adding MCP tools to Copilot means your team can leverage external data without leaving their primary editor
- —
Project-scoped MCP configs (
.vscode/mcp.json) let you commit server configurations to your repository, ensuring the entire team shares the same tool access - —
Copilot's Agent mode integrates MCP tools seamlessly with file editing, terminal commands, and workspace search in a single agentic loop
- —
GitHub's enterprise compliance and audit features extend to MCP tool usage, providing visibility into how AI interacts with external services
Aikido Security in VS Code Copilot
Why run Aikido Security with Vinkius?
The Aikido Security connection runs on our fully managed, secure cloud infrastructure. We handle the hosting, maintenance, and security so you don't have to deal with servers or code. All 16 tools are ready to work instantly without any complex setup.
You stay in complete control of your data. Your AI only accesses the information you approve, keeping your sensitive passwords and private details completely safe. Plus, with automatic optimizations, your AI works faster and more efficiently.

* Every connection is hosted and maintained by Vinkius. We handle the security, updates, and infrastructure so you don't have to write code or manage servers. See our infrastructure
Over 4,000 integrations ready for AI agents
Explore a vast library of pre-built integrations, optimized and ready to deploy.
Connect securely in under 30 seconds
Generate tokens to authenticate and link external services in a single step.
Complete visibility into every agent action
Audit live requests, latency, success rates, and active security compliance policies.
Optimize spending and track token ROI
Analyze real-time token consumption and cost metrics detailed by connection.




Explore our live AI Agents Analytics dashboard to see it all working
This dashboard is included when you connect Aikido Security using Vinkius. You will never be left in the dark about what your AI agents are doing with your tools.
Aikido Security and 4,000+ other AI tools. No hosting, no code, ready to use.
Professionals who connect Aikido Security to VS Code Copilot through Vinkius don't need to write code, manage servers, or worry about security. Everything is pre-configured, secure, and runs automatically in the background.
Raw MCP | Vinkius | |
|---|---|---|
| Ready-to-use MCPs | Find and configure each manually | 4,000+ MCPs ready to use |
| Connection Setup | Manual coding & server setup | 1-click instant connection |
| Server Hosting | You host it yourself (needs 24/7 uptime) | 100% hosted & managed by Vinkius |
| Security & Privacy | Stored in plaintext config files | Bank-grade encrypted vault |
| Activity Visibility | Blind execution (no logs or tracking) | Live dashboard with real-time logs |
| Cost Control | Runaway AI token spend risk | Automatic budget limits |
| Revoking Access | Must delete files or code to stop | 1-click disconnect button |
How Vinkius secures
Aikido Security for VS Code Copilot
Every request between VS Code Copilot and Aikido Security is protected by our secure gateway. We automatically keep your sensitive data private, prevent unauthorized access, and let you disconnect instantly at any time.
Frequently asked questions
How do I get an Aikido API token and where do I find it?
Log in to your Aikido dashboard, click on User Settings in the header, then navigate to Personal Access Tokens. Click to create a new token and copy it immediately — you'll only see it once. The token typically starts with aik_. Paste it into the API token field below.
What types of security issues can Aikido detect?
Aikido detects a wide range of security issues including: open source vulnerabilities (CVEs in dependencies), leaked secrets and API keys, cloud misconfigurations (AWS, GCP, Azure), SAST findings (code-level vulnerabilities), IaC issues (Terraform, CloudFormation), container vulnerabilities, DAST findings, malware detection, end-of-life dependencies, SCM security issues, and license compliance. You can filter issues by type when querying.
Can I check my compliance status for ISO 27001 and SOC2?
Yes! Use the get_iso_compliance tool for ISO 27001 and get_soc2_compliance for SOC2. These endpoints provide a complete compliance overview showing which controls or criteria are passing, failing, or need attention. Both are available on all paid Aikido plans and are perfect for audit preparation and ongoing compliance monitoring.
How does Aikido prioritize security issues?
Aikido automatically prioritizes open issue groups by priority (descending). The prioritization considers factors like severity (critical, high, medium, low), exploitability, whether the vulnerability is actively exploited in the wild, and the context of the affected resource. This means you always see the most dangerous and actionable vulnerabilities first, helping your team focus on what matters most.
Which VS Code version supports MCP?
MCP support requires VS Code 1.99 or later with the GitHub Copilot extension. Ensure both are updated to the latest version. Older versions of Copilot may not expose the Agent mode toggle.
How do I switch to Agent mode?
Open the Copilot Chat panel and look for two mode options: "Ask" and "Agent". Click "Agent" to enable autonomous tool calling. In Ask mode, Copilot provides conversational answers but cannot invoke MCP tools.
Can I restrict which MCP tools Copilot can access?
Yes. VS Code shows a tool consent dialog before any MCP tool is invoked for the first time. You can also configure tool access policies at the organization level through GitHub Copilot settings.
Does MCP work in VS Code Remote or Codespaces?
Yes. MCP servers configured via .vscode/mcp.json work in Remote SSH, WSL, and GitHub Codespaces environments. The MCP connection is established from the remote host, so ensure the server URL is accessible from that environment.
MCP tools not available
Ensure you are in Agent mode in Copilot Chat. MCP tools only appear in Agent mode.
Explore More MCP Servers
View all →
Zerion (DeFi Portfolio)
16 toolsTrack DeFi portfolios, NFT holdings, and transaction history across 500+ protocols and multiple chains via Zerion.

Arlo Smart
11 toolsControl Arlo security cameras — view recordings, arm/disarm devices, and manage security modes via Arlo Smart API.

Plane Alternative
12 toolsManage projects, issues, and product roadmaps via Plane — create projects, toggle features, and organize workspaces directly from your AI agent.

SaveDay
4 toolsCapture, organize, and summarize content from URLs, text, and images directly into your SaveDay knowledge base.
