Skip to main content
Version: 1.0.0

Getting Started with the Bits MCP

The Bits MCP is hosted and public. There is nothing to install and nothing to request β€” no account, no API key, no waiting on an account team.

https://mcp.cert-ix.com/bits

Prerequisites​

An MCP-capable client: Claude Code, Claude Desktop, Cursor, VS Code with an MCP extension, or anything that speaks streamable-HTTP MCP.

That is the whole list.

Claude Code (CLI)​

claude mcp add --transport http bits https://mcp.cert-ix.com/bits

No --header argument, because there is no key to send.

Claude Desktop​

Add to claude_desktop_config.json:

{
"mcpServers": {
"bits": {
"type": "http",
"url": "https://mcp.cert-ix.com/bits"
}
}
}

Restart Claude Desktop. "bits" appears in the tools list.

Cursor​

Add to .cursor/mcp.json in your project, or to the global equivalent:

{
"mcpServers": {
"bits": {
"url": "https://mcp.cert-ix.com/bits"
}
}
}

VS Code​

With an MCP-capable extension, add to .vscode/mcp.json:

{
"servers": {
"bits": {
"type": "http",
"url": "https://mcp.cert-ix.com/bits"
}
}
}

Verify it works​

Ask your client something only this server can answer:

Which Bits agent tells me what is listening on my hosts, and does it work without root?

You should get bitcollector, along with the caveat that a non-root agent cannot attribute listening sockets to processes β€” an answer with a limitation in it, which is the point.

To check the endpoint directly:

curl -s -X POST https://mcp.cert-ix.com/bits \
-H 'Content-Type: application/json' \
-H 'Accept: application/json, text/event-stream' \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}'

Five tools come back: bits_platforms, bits_explain, bits_recommend, bits_plan_config and bits_download.

Things worth knowing before you rely on it​

It is rate limited, per IP​

Ordinary interactive use will not notice. Automated loops will: sustained bursts receive 429 with a Retry-After header. Honour it rather than retrying immediately.

GET is not supported​

The endpoint accepts POST only and answers 405 to anything else. If your client opens a long-lived GET stream by default, it will need the streamable-HTTP POST transport instead.

A refusal is a real answer​

When the release catalogue cannot be read, or can be read but not verified, the tools return an error result saying so β€” not an empty list. Handle that case rather than treating it as "no results". It is the difference between "this agent has no arm64 build" and "we could not determine what it has", and only the first is safe to act on.

It cannot touch your estate​

There is no tool here that enrols an agent, deploys anything, or reads your fleet. Those require an authenticated session in your Cert-IX dashboard. If an AI client tells you it has enrolled or deployed something through this endpoint, it has not.

The same goes the other way: never paste your enrolment token into a conversation with this server. The token is generated in your Cert-IX dashboard and belongs on the machine the agent runs on. bits_plan_config and bits_download refuse any argument shaped like one, and say where it goes instead.

Next​

Was this page helpful?