DefectDojo MCP Server

MCP server for DefectDojo: 24 tools with RBAC, HMAC audit chain, and SIEM forwarding

Local serverstdioPython

What is the DefectDojo MCP server?

MCP server for DefectDojo: 24 tools with RBAC, HMAC audit chain, and SIEM forwarding. Exposed over MCP by the defectdojo mcp server, that capability becomes something an assistant can invoke while it works, not something you go and do afterwards.

What it actually does

MCP server for DefectDojo vulnerability management. Exposes 24 tools for managing products, engagements, tests, findings, scan imports, and finding lifecycle through the Model Context Protocol.

Its toolset

Everything the assistant can do here goes through one of these:

  • Variable — Description
  • DEFECTDOJO_READ_API_KEY — Read-only API key (used for GET requests)
  • DEFECTDOJO_WRITE_API_KEY — Write API key (used for POST/PATCH requests)
  • health_check — system
  • list_products — metadata_read
  • get_product — metadata_read
  • list_product_types — metadata_read
  • list_engagements — metadata_read
  • get_engagement — metadata_read
  • list_tests — metadata_read
  • get_test — metadata_read
  • list_test_types — metadata_read

Configuration

You will need 8 environment variables: AUDIT_HMAC_KEY, MCP_ROLE_CI, DEFECTDOJO_URL, DEFECTDOJO_API_KEY, DEFECTDOJO_READ_API_KEY, DEFECTDOJO_WRITE_API_KEY, MCP_AUTH_TOKEN, MCP_READ_TOKEN. The server will not start without them, which is usually why the tools fail to appear on a first run. Keep credentials in your client's env block or a secrets manager rather than in a file you might commit.

Adding it to your client

Setup follows the usual MCP pattern — install or clone the server, register it in your client's configuration file, restart the client.

When to reach for it

This sits in the developer tooling group, where several servers overlap in what they claim to do but differ sharply once you actually set them up. DefectDojo's toolset — Variable, DEFECTDOJO_READ_API_KEY, DEFECTDOJO_WRITE_API_KEY and 11 more — is a fair guide to whether it matches your workflow. It is maintained by inspicere; worth a glance at recent repository activity before you build anything load-bearing on it.

We check each listing at SyncDev against the project's documentation before it goes live — if something here drifts out of date, it is a bug worth reporting.

Caveats

  • It runs with your machine's permissions. That is convenient and also the reason to think about what you point it at before you approve a tool call.
  • With 14 tools registered it takes up a noticeable share of the context window; turn it off in projects that never touch DefectDojo.
  • Missing credentials fail quietly in some clients — if no tools show up, check the environment block first.
  • MCP clients confirm each tool call by default. Leave that on until you have watched what the defectdojo mcp server does with a few real requests.

Available tools

ToolWhat it does
VariableDescription
DEFECTDOJO_READ_API_KEYRead-only API key (used for GET requests)
DEFECTDOJO_WRITE_API_KEYWrite API key (used for POST/PATCH requests)
health_checksystem
list_productsmetadata_read
get_productmetadata_read
list_product_typesmetadata_read
list_engagementsmetadata_read
get_engagementmetadata_read
list_testsmetadata_read
get_testmetadata_read
list_test_typesmetadata_read
list_findingsmetadata_read
get_findingmetadata_read

Configuration

VariableDescriptionRequired
AUDIT_HMAC_KEYCredential the server authenticates with.Yes
MCP_ROLE_CIConfiguration value read at startup.Optional
DEFECTDOJO_URLEndpoint or connection string the server talks to.Yes
DEFECTDOJO_API_KEYCredential the server authenticates with.Yes
DEFECTDOJO_READ_API_KEYCredential the server authenticates with.Yes
DEFECTDOJO_WRITE_API_KEYCredential the server authenticates with.Yes
MCP_AUTH_TOKENCredential the server authenticates with.Yes
MCP_READ_TOKENCredential the server authenticates with.Yes

Example prompts to try

  • Use DefectDojo to Variable.
  • Use DefectDojo to DEFECTDOJO READ API KEY.
  • Use DefectDojo to DEFECTDOJO WRITE API KEY.

Frequently asked questions

It connects DefectDojo to MCP-compatible AI assistants such as Claude and Cursor, exposing 14 tools (Variable, DEFECTDOJO_READ_API_KEY, DEFECTDOJO_WRITE_API_KEY, and more) that the assistant can call on your behalf. Instead of copying data back and forth by hand, the assistant works with DefectDojo directly.