CrowdSec Connector for AI agents.
3 live capabilities
Manage network security and threat intelligence through natural conversation.
Waiting for input…
Why people use CrowdSec
CrowdSec Threat Intelligence for Faster Incident Response
This Connector changes that by putting your security data into a single chat. You just ask your agent what's happening with a specific IP, and it pulls the local decisions and global reputation into one answer. You get a clear picture of the threat without the tab-hopping.
What Vinkius changes
You get a conversational interface for your entire CrowdSec security engine.
Use it from Claude, ChatGPT, Cursor or another AI client you already have.
One account · 5,900+ Connectors
- Real-world use case 01
Rapid Incident Response
An engineer asks "Why is this IP blocked?
- Real-world use case 02
Proactive Defense Verification
A dev asks "Is this new range known for scanning?
- Real-world use case 03
Automated Security Auditing
An admin asks "Show me all new blocks from the last hour" to spot a new pattern of attack using get_decisions_stream.
Complete set · 3capabilities
The complete CrowdSec capability set.
These are the exact actions your AI can choose when you ask it to work with CrowdSec.
01—03
3 capabilities in this set.
Part of 3 available through CrowdSec.
- 01 Capability
Get cti smoke
Get the global reputation and behavior scores for a specific IP address. This helps you decide if a connection is a known threat.
- 02 Capability
Get decisions stream
Poll for a live feed of new and deleted security decisions from your local API. Use this to stay updated on active blocks in real-time.
- 03 Capability
Get decisions
Query your local CrowdSec database for specific decisions on an IP or range. This lets you see the exact reason why a block was applied.
Set up in minutes
One URL. Then ask CrowdSec to work.
Claude and ChatGPT only need the Connector URL. Copy it once, add it in settings, and use CrowdSec from the conversation.
Choose your client
Live previewAdvanced clients IDE · CLI
Claude · Web + desktop
Connector URL · ready to paste
Streamable HTTPhttps://edge.vinkius.com/vk_preview_2elfrol73nICZiMR18YQg2LgVuwctPXwaxqoZfA4/mcp - Step 01
Open Connectors
In Claude Web or Claude Desktop, open Settings and choose Connectors.
- Step 02
Add the URL
Choose Add custom connector, name it CrowdSec, and paste the URL above.
- Step 03
Turn it on in chat
Select +, open Connectors, and enable CrowdSec for the conversation.
ChatGPT · Web + desktop
Connector URL · ready to paste
Streamable HTTPhttps://edge.vinkius.com/vk_preview_2elfrol73nICZiMR18YQg2LgVuwctPXwaxqoZfA4/mcp - Step 01
Open MCP settings
On desktop, open Settings and MCP servers. On web, open your workspace app or connector settings.
- Step 02
Add the URL
Choose Add server with Streamable HTTP, or create a custom MCP app, then paste the CrowdSec URL.
- Step 03
Save and start
Save the connection and enable CrowdSec in your conversation. Desktop may ask you to restart once.
Cursor · IDE configuration
Advanced setup
{
"mcpServers": {
"crowdsec": {
"url": "https://edge.vinkius.com/vk_preview_2elfrol73nICZiMR18YQg2LgVuwctPXwaxqoZfA4/mcp"
}
}
} - Step 01
Open MCP Settings
Press Cmd+Shift+P (macOS) or Ctrl+Shift+P (Windows/Linux) → search "MCP Settings"
- Step 02
Add the server config
Paste the JSON configuration above into the mcp.json file that opens
- Step 03
Save the file
Cursor will automatically detect the new Connector
- Step 04
Start using CrowdSec
Open Agent mode in chat and ask: "Using CrowdSec, help me...". 3 tools available
VS Code Copilot · IDE configuration
Advanced setup
{
"mcpServers": {
"crowdsec": {
"url": "https://edge.vinkius.com/vk_preview_2elfrol73nICZiMR18YQg2LgVuwctPXwaxqoZfA4/mcp"
}
}
} - Step 01
Create MCP config
Create a .vscode/mcp.json file in your project root
- Step 02
Add the server config
Paste the JSON configuration above
- Step 03
Enable Agent mode
Open GitHub Copilot Chat and switch to Agent mode using the dropdown
- Step 04
Start using CrowdSec
Ask Copilot: "Using CrowdSec, help me...". 3 tools available
Windsurf · IDE configuration
Advanced setup
{
"mcpServers": {
"crowdsec": {
"url": "https://edge.vinkius.com/vk_preview_2elfrol73nICZiMR18YQg2LgVuwctPXwaxqoZfA4/mcp"
}
}
} - Step 01
Open MCP Settings
Go to Settings → MCP Configuration or press Cmd+Shift+P and search "MCP"
- Step 02
Add the server
Paste the JSON configuration above into mcp_config.json
- Step 03
Save and reload
Windsurf will detect the new server automatically
- Step 04
Start using CrowdSec
Open Cascade and ask: "Using CrowdSec, help me...". 3 tools available
Cline · IDE configuration
Advanced setup
{
"mcpServers": {
"crowdsec": {
"url": "https://edge.vinkius.com/vk_preview_2elfrol73nICZiMR18YQg2LgVuwctPXwaxqoZfA4/mcp"
}
}
} - Step 01
Open Cline MCP Settings
Click the Connectors icon in the Cline sidebar panel
- Step 02
Add remote server
Click "Add Connector" and paste the configuration above
- Step 03
Enable the server
Toggle the server switch to ON
- Step 04
Start using CrowdSec
Ask Cline: "Using CrowdSec, help me...". 3 tools available
Claude Code · Terminal command
Advanced setup
claude mcp add crowdsec --transport http "https://edge.vinkius.com/vk_preview_2elfrol73nICZiMR18YQg2LgVuwctPXwaxqoZfA4/mcp" - Step 01
Install Claude Code
Run npm install -g @anthropic-ai/claude-code if not already installed
- Step 02
Add the Connector
Run the command above in your terminal
- Step 03
Verify the connection
Run claude mcp to list connected servers, or type /mcp inside a session
- Step 04
Start using CrowdSec
Ask Claude: "Using CrowdSec, show me...". 3 tools are ready
Where the request belongs
Work CrowdSec can move forward.
The security engineer who's tired of clicking through dashboards at 2am to find out why a specific range is being blocked. It's for the person who needs to make fast calls on network defense during an active incident.
Security Engineer
Investigates active blocks and global reputations during incident response to identify threats quickly.
DevOps Engineer
Monitors security streams to ensure new deployments aren't getting flagged or blocked by mistake.
System Administrator
Audits blocked ranges and suspicious activity using natural language commands to maintain network health.
Build the capability set
Add more capabilities.
Each Connector adds new actions and data without changing how you work.
Browse ConnectorsTrend Micro
Equip your AI agent with Vision One telemetry to investigate threats, audit endpoint activities, and manage security alerts natively.
Intruder
Automate vulnerability scanning and security monitoring via Intruder.io API.
UpGuard
Monitor your attack surface and assess vendor security risks with continuous scanning that identifies vulnerabilities before attackers do.
CrowdStrike Falcon
Detect threats, manage endpoints, investigate incidents, and query telemetry from CrowdStrike Falcon. the #1 endpoint detection and response platform.
Halo Security
Automate attack surface management via Halo Security. monitor assets, scans, and vulnerabilities directly from any AI agent.
Salt Security
Integrate Salt Security directly with your AI for comprehensive API threat vector discovery, posture management, and active remediation in real-time.
Bring your own AI
Change the model, client or framework. Keep CrowdSec connected.
-
Claude -
ChatGPT -
Gemini -
Cursor -
VS Code -
Windsurf -
ZCode -
Cline -
Zed -
Continue -
Kiro -
Roo Code -
Zencoder -
Goose -
Void -
Augment Code -
Amp -
Qodo -
Tabnine -
Pieces -
Sourcegraph Cody -
JetBrains -
Warp -
Amazon Q -
Antigravity -
BoltAI -
Raycast -
Jan -
LM Studio -
AnythingLLM -
Open WebUI -
Msty -
Cherry Studio -
LibreChat -
TypingMind -
Chorus -
5ire -
n8n -
LangChain -
LlamaIndex -
CrewAI -
Vercel AI SDK
Before you connect
Questions about CrowdSec.
The practical details behind the request, access and result.
What is the CrowdSec MCP?
It's a way to let your AI agent talk directly to your CrowdSec security engine to check blocks and reputation.
Can I use CrowdSec MCP to see why an IP was blocked?
Yes, it lets your agent query your local API to show the exact reason and metadata for any decision.
Does CrowdSec MCP work with my local LAPI?
It's designed specifically to connect to your local API so you can manage your own security data.
How does CrowdSec MCP help with incident response?
It speeds things up by letting you ask questions about active threats and IP reputations in plain English.
Can I get real-time updates with CrowdSec MCP?
Yes, you can poll for a live stream of new and deleted decisions to keep your agent's context current.
Is CrowdSec MCP for global threat intelligence?
It connects to the CrowdSec CTI network to give you global reputation and behavior data for any IP.
Can I check if a specific IP address is currently blocked in my local CrowdSec instance?
Yes! Use the get_decisions capability providing the IP address. Your agent will query your Local API and return any active decisions, including the reason and duration of the block.
How do I see the latest security threats detected by my server in real-time?
You can use the get_decisions_stream capability. This allows your agent to poll for new and deleted decisions, giving you a clear view of recent security activity on your infrastructure.
Can I verify an IP's global reputation even if it hasn't attacked my server yet?
Absolutely. The get_cti_smoke capability queries the global CrowdSec CTI network. It provides background information, attack behaviors, and risk scores for any IP based on community data.
One connection away
Give your agent a direct line to CrowdSec.
Connect CrowdSec once. Keep it beside 5,900+ managed Connectors when the next task needs more.
Explore every Connector No credit card required · Free tier available