GitGuardian Connector for AI agents.
49 live capabilities
Manage secret leaks and honeytokens to secure your infrastructure.
Waiting for input…
Why people use GitGuardian
GitGuardian Secret Incident Management for Security Teams
With the GitGuardian MCP, you can triage these alerts via your AI agent. You can list incidents, assign them to team members, and resolve them using simple commands, turning a manual chore into a conversation.
What Vinkius changes
You get a hands-on security assistant that handles the grunt work of secret management.
Use it from Claude, ChatGPT, Cursor or another AI client you already have.
One account · 5,900+ Connectors
- Real-world use case 01
Fast-tracking incident remediation
A security engineer needs to find all active leaks.
- Real-world use case 02
Checking code for hardcoded keys
A developer wants to check a snippet before a commit.
- Real-world use case 03
Setting up decoy credentials
A DevOps lead wants to set up decoys.
Complete set · 49capabilities
The complete GitGuardian capability set.
These are the exact actions your AI can choose when you ask it to work with GitGuardian.
01—04
4 capabilities in this set.
Part of 49 available through GitGuardian.
- 01 Capability
Get secret incident
Retrieve detailed information about a specific secret incident. Use this to get the full context of a leak.
- 02 Capability
Get self api token
Retrieve the details of your current API token. This helps you manage your own credentials for the Connector.
- 03 Capability
List sources
List all sources currently being monitored for secrets. Use this to see the scope of your security coverage.
- 04 Capability
List team memberships
List team members to see who belongs to which security groups. This helps with auditing internal permissions.
05—08
4 capabilities in this set.
Part of 49 available through GitGuardian.
- 05 Capability
Resolve secret incident
Resolve a secret incident to clear it from your active alert list. Use this once a leak has been fixed.
- 06 Capability
Revoke honeytoken
Revoke a honeytoken to remove it from your environment. Use this if a decoy is no longer needed or is compromised.
- 07 Capability
Ignore secret incident
Ignore a secret incident if it's a false positive or already handled. This keeps your active alert list clean.
- 08 Capability
List api tokens
List all active API tokens for your workspace. Use this to audit who has access to your GitGuardian account.
09—12
4 capabilities in this set.
Part of 49 available through GitGuardian.
- 09 Capability
List audit log event names
List all existing event names for your audit logs. This helps you understand what actions can be tracked.
- 10 Capability
List audit logs
List audit logs for your workspace to monitor recent activity. This is essential for compliance and security audits.
- 11 Capability
List custom tags
List all custom tags currently in use. Use this to see how your incidents are being organized.
- 12 Capability
List health check history
List health check history for a specific instance. This helps identify any recurring connectivity issues.
13—16
4 capabilities in this set.
Part of 49 available through GitGuardian.
- 13 Capability
List health checks
List all current health checks for your workspace. Use this to monitor the status of your security instances.
- 14 Capability
List honeytoken events
List all honeytoken events to see when decoys were triggered. This provides a timeline of unauthorized access attempts.
- 15 Capability
List honeytoken notes
List honeytoken notes to see context for your decoys. This helps your team understand the purpose of different traps.
- 16 Capability
List honeytoken sources
List sources where specific honeytokens appear. Use this to track where your decoys are being deployed.
17—20
4 capabilities in this set.
Part of 49 available through GitGuardian.
- 17 Capability
List honeytokens
List all honeytokens in your workspace. This gives you a full overview of your active decoy credentials.
- 18 Capability
List ips
List the IP addresses for the provider to help with firewall configuration. Use this to whitelist the necessary traffic.
- 19 Capability
List members
List all members of your workspace. Use this to verify who has access to your security capabilities.
- 20 Capability
List scim groups
List groups via SCIM for automated user management. This helps with large-scale organization syncing.
21—24
4 capabilities in this set.
Part of 49 available through GitGuardian.
- 21 Capability
List scim users
List members via SCIM to keep user access in sync. Use this for automated provisioning and deprovisioning.
- 22 Capability
List secret incidents
List all secret incidents to see what needs attention. This is your primary way to view active security leaks.
- 23 Capability
List teams
List all teams in your organization. Use this to manage your security department's structure.
- 24 Capability
Multiscan content
Scan multiple pieces of content at once for secrets to save time. This is great for checking multiple files quickly.
25—28
4 capabilities in this set.
Part of 49 available through GitGuardian.
- 25 Capability
Reset honeytoken
Reset a honeytoken to its original state after it's been triggered. This allows you to keep using the same decoy.
- 26 Capability
Revoke self api token
Revoke your current API token immediately if it's compromised. This is a critical safety feature for your account.
- 27 Capability
Scan and create incidents
Scan content and automatically create incidents for any secrets found. This automates the discovery and logging process.
- 28 Capability
Scan content
Scan a specific piece of content for secrets and sensitive data. Use this to check code snippets before they go live.
29—32
4 capabilities in this set.
Part of 49 available through GitGuardian.
- 29 Capability
Create honeytoken
Create a new honeytoken to act as a decoy for unauthorized access. This is a core defense for your private infrastructure.
- 30 Capability
Create honeytoken with context
Create a honeytoken within a specific context for better tracking. This allows for more granular decoy management.
- 31 Capability
Create team
Create a new team to organize security operations and permissions. Use this to structure your organization's security roles.
- 32 Capability
Delete custom tag
Delete a custom tag that is no longer needed for your workflow. Keep your workspace metadata clean and relevant.
33—36
4 capabilities in this set.
Part of 49 available through GitGuardian.
- 33 Capability
Delete custom tags key
Delete a custom tags key to clean up your workspace metadata. This helps manage your organizational taxonomy.
- 34 Capability
Get custom tag
Retrieve a custom tag to check its details or status. Use this to verify how specific incidents are categorized.
- 35 Capability
Get health
Check the current API health status to ensure your connection is active. This is a quick way to verify your setup.
- 36 Capability
Get honeytoken
Retrieve a specific honeytoken to see its current status. This helps you monitor which decoys are being targeted.
37—40
4 capabilities in this set.
Part of 49 available through GitGuardian.
- 37 Capability
Get quotas
Retrieve a quota overview to monitor your usage limits. Stay on top of your account's capacity and limits.
- 38 Capability
Assign secret incident
Assign a specific secret incident to a team member for faster remediation. This helps keep your triage workflow organized.
- 39 Capability
Bulk prefix lookup
Perform a bulk lookup for honeytoken HMSL hashes to identify compromised decoys. Use this to quickly audit multiple entries.
- 40 Capability
Create custom tag
Create a custom tag to organize and filter your security incidents. This helps group similar types of leaks together.
41—43
3 capabilities in this set.
Part of 49 available through GitGuardian.
- 41 Capability
Create honeytoken note
Create a note for a honeytoken to provide extra context on its purpose. This is useful for keeping your team informed.
- 42 Capability
List ip allowlist
List IP allowlist rules to manage access to your workspace. This is key for securing your administrative access.
- 43 Capability
Trigger health check
Trigger a manual health check to verify your workspace connection. Use this to test your setup on demand.
44—46
3 capabilities in this set.
Part of 49 available through GitGuardian.
- 44 Capability
Trigger source scans
Trigger new scans on your sources to find recent leaks. Use this to manually refresh your security data.
- 45 Capability
Update custom tag full
Perform a full update on a custom tag's metadata. This helps you refine how you categorize security incidents.
- 46 Capability
Update custom tag partial
Perform a partial update on a custom tag. Use this to quickly change a single piece of tag information.
47—49
3 capabilities in this set.
Part of 49 available through GitGuardian.
- 47 Capability
Update custom tags key
Update a custom tags key to reflect new organizational rules. This keeps your metadata in sync with company policy.
- 48 Capability
Update honeytoken
Update a honeytoken's configuration or details. Use this to modify your decoys without creating new ones.
- 49 Capability
Update secret incident
Update a secret incident with new details or status. This helps keep your incident records accurate and current.
Set up in minutes
One URL. Then ask GitGuardian to work.
Claude and ChatGPT only need the Connector URL. Copy it once, add it in settings, and use GitGuardian from the conversation.
Choose your client
Live previewAdvanced clients IDE · CLI
Claude · Web + desktop
Connector URL · ready to paste
Streamable HTTPhttps://edge.vinkius.com/vk_preview_NQtV8WXJZTZDwZLKUu4JIzBlR9PvO6RL6VjurLD6/mcp - Step 01
Open Connectors
In Claude Web or Claude Desktop, open Settings and choose Connectors.
- Step 02
Add the URL
Choose Add custom connector, name it GitGuardian, and paste the URL above.
- Step 03
Turn it on in chat
Select +, open Connectors, and enable GitGuardian for the conversation.
ChatGPT · Web + desktop
Connector URL · ready to paste
Streamable HTTPhttps://edge.vinkius.com/vk_preview_NQtV8WXJZTZDwZLKUu4JIzBlR9PvO6RL6VjurLD6/mcp - Step 01
Open MCP settings
On desktop, open Settings and MCP servers. On web, open your workspace app or connector settings.
- Step 02
Add the URL
Choose Add server with Streamable HTTP, or create a custom MCP app, then paste the GitGuardian URL.
- Step 03
Save and start
Save the connection and enable GitGuardian in your conversation. Desktop may ask you to restart once.
Cursor · IDE configuration
Advanced setup
{
"mcpServers": {
"gitguardian": {
"url": "https://edge.vinkius.com/vk_preview_NQtV8WXJZTZDwZLKUu4JIzBlR9PvO6RL6VjurLD6/mcp"
}
}
} - Step 01
Open MCP Settings
Press Cmd+Shift+P (macOS) or Ctrl+Shift+P (Windows/Linux) → search "MCP Settings"
- Step 02
Add the server config
Paste the JSON configuration above into the mcp.json file that opens
- Step 03
Save the file
Cursor will automatically detect the new Connector
- Step 04
Start using GitGuardian
Open Agent mode in chat and ask: "Using GitGuardian, help me...". 49 tools available
VS Code Copilot · IDE configuration
Advanced setup
{
"mcpServers": {
"gitguardian": {
"url": "https://edge.vinkius.com/vk_preview_NQtV8WXJZTZDwZLKUu4JIzBlR9PvO6RL6VjurLD6/mcp"
}
}
} - Step 01
Create MCP config
Create a .vscode/mcp.json file in your project root
- Step 02
Add the server config
Paste the JSON configuration above
- Step 03
Enable Agent mode
Open GitHub Copilot Chat and switch to Agent mode using the dropdown
- Step 04
Start using GitGuardian
Ask Copilot: "Using GitGuardian, help me...". 49 tools available
Windsurf · IDE configuration
Advanced setup
{
"mcpServers": {
"gitguardian": {
"url": "https://edge.vinkius.com/vk_preview_NQtV8WXJZTZDwZLKUu4JIzBlR9PvO6RL6VjurLD6/mcp"
}
}
} - Step 01
Open MCP Settings
Go to Settings → MCP Configuration or press Cmd+Shift+P and search "MCP"
- Step 02
Add the server
Paste the JSON configuration above into mcp_config.json
- Step 03
Save and reload
Windsurf will detect the new server automatically
- Step 04
Start using GitGuardian
Open Cascade and ask: "Using GitGuardian, help me...". 49 tools available
Cline · IDE configuration
Advanced setup
{
"mcpServers": {
"gitguardian": {
"url": "https://edge.vinkius.com/vk_preview_NQtV8WXJZTZDwZLKUu4JIzBlR9PvO6RL6VjurLD6/mcp"
}
}
} - Step 01
Open Cline MCP Settings
Click the Connectors icon in the Cline sidebar panel
- Step 02
Add remote server
Click "Add Connector" and paste the configuration above
- Step 03
Enable the server
Toggle the server switch to ON
- Step 04
Start using GitGuardian
Ask Cline: "Using GitGuardian, help me...". 49 tools available
Claude Code · Terminal command
Advanced setup
claude mcp add gitguardian --transport http "https://edge.vinkius.com/vk_preview_NQtV8WXJZTZDwZLKUu4JIzBlR9PvO6RL6VjurLD6/mcp" - Step 01
Install Claude Code
Run npm install -g @anthropic-ai/claude-code if not already installed
- Step 02
Add the Connector
Run the command above in your terminal
- Step 03
Verify the connection
Run claude mcp to list connected servers, or type /mcp inside a session
- Step 04
Start using GitGuardian
Ask Claude: "Using GitGuardian, show me...". 49 tools are ready
Where the request belongs
Work GitGuardian can move forward.
This is for the security engineer who's tired of manual triage and the developer who's terrified of pushing a live key to production.
Security Engineer
Triage alerts and deploy honeytokens across multiple environments during a high-pressure incident.
DevOps Engineer
Automate security audits and monitor workspace health directly from the terminal or IDE.
Software Developer
Scan code for secrets before committing to avoid embarrassing leaks and security vulnerabilities.
When one Connector is not enough
Carry the request into a workflow.
Combine GitGuardian with the systems that finish the task.
View all recipesBuild the capability set
Add more capabilities.
Each Connector adds new actions and data without changing how you work.
Browse ConnectorsAikido Security
Query security vulnerabilities via Aikido. list open issues, check repositories, monitor cloud assets, and track compliance directly from any AI agent.
Snyk
Bring your Snyk code security ecosystem directly to your AI. Analyze vulnerabilities, project metadata, and scan issues right from your editor.
Veracode
Bring Veracode AppSec to your AI. Analyze source code flaws, extract application profiles, and track vulnerabilities conversationaly.
Semgrep
Equip your AI agent with read/write access to Semgrep's SAST platform to audit code security findings, update triage statuses, and enforce custom semantic rules.
Google Deps.dev Security Hacker
Transform your AI into a Senior DevSecOps Engineer. Instantly audit any open-source package, hunt for hidden supply-chain threats in dependency trees, and analyze full GitHub repositories using Google's deps.dev API. No authentication required.
Security Audit Prover
An AI agent committed a Stripe API key to git, built SQL queries with string concatenation, and deployed an admin endpoint with no authentication. all in 4 minutes. The key was scraped from GitHub within 90 seconds. This capability forces input sanitization validation, secret management auditing, authentication enforcement, injection prevention, and dependency supply chain checks against OWASP Top 10.
Bring your own AI
Change the model, client or framework. Keep GitGuardian connected.
-
Claude -
ChatGPT -
Gemini -
Cursor -
VS Code -
Windsurf -
ZCode -
Cline -
Zed -
Continue -
Kiro -
Roo Code -
Zencoder -
Goose -
Void -
Augment Code -
Amp -
Qodo -
Tabnine -
Pieces -
Sourcegraph Cody -
JetBrains -
Warp -
Amazon Q -
Antigravity -
BoltAI -
Raycast -
Jan -
LM Studio -
AnythingLLM -
Open WebUI -
Msty -
Cherry Studio -
LibreChat -
TypingMind -
Chorus -
5ire -
n8n -
LangChain -
LlamaIndex -
CrewAI -
Vercel AI SDK
Before you connect
Questions about GitGuardian.
The practical details behind the request, access and result.
Can GitGuardian MCP help me find leaked keys?
Yes, it lets your AI agent list all active secret incidents in your workspace so you can see what needs attention immediately.
How do I use GitGuardian MCP for honeytokens?
You can ask your agent to create decoys that alert you when someone tries to use them, helping you catch intruders early.
Does GitGuardian MCP support team management?
Yes, it lets you manage members and teams to organize how your organization handles security and incident response.
Can I scan code for secrets with GitGuardian MCP?
You can ask your agent to scan specific code snippets or content for sensitive data before you commit them to your repository.
Is GitGuardian MCP good for audit logs?
It allows you to retrieve workspace activity logs to ensure your team stays compliant with your internal security policies.
How does GitGuardian MCP handle secret incidents?
Your agent can list, retrieve, and resolve incidents, making it much easier to triage high-priority leaks without leaving your workflow.
Can I resolve a secret incident directly through the AI?
Yes. You can use the resolve_secret_incident capability by providing the incident ID. You can also use assign_secret_incident to delegate the fix to a specific team member.
How do I create a decoy credential to catch attackers?
Use the create_honeytoken capability. You can specify the type and name of the honeytoken, and GitGuardian will generate a decoy that alerts you if it's ever used.
Is it possible to scan a text block for secrets before I commit it?
Absolutely. Use the scan_content capability. Provide the document content and a filename, and the AI will return any detected secrets or policy violations found by GitGuardian's engine.
One connection away
Give your agent a direct line to GitGuardian.
Connect GitGuardian once. Keep it beside 5,900+ managed Connectors when the next task needs more.
Explore every Connector No credit card required · Free tier available