• TRIAGE
  • AUDIT
  • REMEDIATION
  • HUMAN

How to analyze API conformance scans with your AI

Connect 42Crunch to your AI client to turn raw scan data into actionable security insights.

Ask AI about this page

Short answer

How can I use my AI to check API conformance scans?

Your AI uses the 42Crunch MCP to pull scan history and specific report details. It then compares those results against your API specifications to spot implementation gaps. You get a clear breakdown of where your code deviates from your documentation.

Scan outcomes.

Where your scan data goes.

The AI processes raw scan results into these specific outcomes.

TRIAGE

Identify security flaws

The AI reads scan reports to find vulnerabilities. It highlights exactly where your API implementation fails conformance tests.

AUDIT

Spot undocumented behavior

By comparing scan data to your spec, the AI finds endpoints or parameters that exist in code but aren't in your documentation.

REMEDIATION

Draft fix instructions

The AI translates technical scan errors into plain language instructions. You get specific steps to align your implementation with the spec.

HUMAN

Final validation

The AI identifies high-risk discrepancies that require a security engineer to review. You decide which flaws to prioritize for the next sprint.

The workflow

What your AI does when a scan is ready.

The AI handles the heavy lifting of data retrieval and comparison.

  1. Fetch scan history

    The AI looks up your recent activity to find the specific conformance tests you want to investigate.

    list_scans
  2. Pull detailed reports

    Once a scan is identified, the AI pulls the full technical report containing all findings and errors.

    get_scan_report
  3. Compare against spec

    The AI analyzes the report to find mismatches between your actual API behavior and your intended design.

    get_scan_report
  4. Summarize findings

    The AI condenses the technical data into a summary of implementation flaws and undocumented endpoints.

    get_scan_report

Try it

Copy these to start.

Use these prompts to begin your analysis.

Starting points

Replace the bracketed text with your specific scan IDs or API names.

42Crunch Connector

You're all set. Choose your MCP client and follow the setup instructions.

Connector linkhttps://edge.vinkius.com/vk_preview_Gi3PrK2xNbiurYu9rVegSxEQmPykAdCxogXvksIV/mcp

Claude Desktop

Follow the steps below to connect in seconds.

  1. 1In Claude Desktop, open Settings → Connectors.
  2. 2Click “Add custom connector” and paste the connector link above as the remote MCP server URL.
  3. 3Click Add and start a new chat — 42Crunch capabilities are ready to use.
Configuration · claude_desktop_config.jsonCopy
{
  "mcpServers": {
    "42crunch-mcp": {
      "url": "https://edge.vinkius.com/vk_preview_Gi3PrK2xNbiurYu9rVegSxEQmPykAdCxogXvksIV/mcp"
    }
  }
}
Copy into chat04
  • List my recent 42Crunch scans so I can pick one to analyze.

  • Get the report for scan ID [ID] and tell me if there are any undocumented parameters.

  • Analyze the results from scan [ID] and find any implementation flaws that violate my API spec.

  • Summarize the most critical security issues found in the latest 42Crunch scan report.

  • Claude
  • ChatGPT
  • Cursor
  • VS Code
  • Windsurf
  • Claude Code
  • JetBrains
  • Cline

Start here

Connect 42Crunch once, then ask.

Log in to your 42Crunch account through the Vinkius interface. Your credentials stay encrypted, and you can immediately start asking your AI about your scan data.

Connect 42Crunch to your AI

FAQ

Common questions

  • 01

    Can the AI fix the API flaws automatically?

    No. The AI identifies the flaws and suggests fixes, but you must manually update your code or configuration.

  • 02

    Can I delete old scans using the AI?

    No. This MCP only provides tools to list scans and retrieve reports. It cannot modify or delete data in 42Crunch.

  • 03

    How does the AI know what my API is supposed to do?

    The AI uses the data within the scan reports to identify discrepancies between the actual implementation and the expected behavior defined in your API specification.

  • 04

    Does the AI see my full API source code?

    No. The AI only sees the data provided by the 42Crunch scan reports and the specific tools used to fetch that data.

  • 05

    Can I use this with any AI client?

    Yes, you can use this with any MCP-compatible client like Claude, Cursor, or Windsurf once you connect it via Vinkius.

  • More questions about 42Crunch? The Connector page answers them. See everything the 42Crunch Connector can do

Connect 42Crunch to Claude, Cursor, ChatGPT & more