Saltar al contenido principal
Version: 1.0.0

Connect your assistant to DepCheck

DepCheck is one hosted endpoint, and every client on this page connects to the same address. You do not need an account or a key: add the address to your assistant and it can check dependencies straight away.

Endpointhttps://mcp.cert-ix.com/depcheck
TransportStreamable HTTP (MCP protocol version 2025-06-18). There is no separate SSE endpoint: when a client asks, choose HTTP or Streamable HTTP.
Without a keyEach IP address can make 60 requests per minute, with a burst allowance of 30.
With a key (optional)Free from cert-ix.com/tools/depcheck-mcp, valid for 90 days, sent as Authorization: Bearer <key>. A key raises the limits.
Toolscheck_package, scan_dependencies, suggest_safe_version, get_advisory, get_cve_intel
A wrong key is not ignored

If you send a key, it must be valid. An invalid or expired key is rejected with 401 Unauthorized: DepCheck does not fall back to the no-key tier. If you have no valid key, remove the Authorization header from your configuration.

Choose your client​

ClientWhere you set it upWithout a keyWith a key
ChatGPTDeveloper mode, then ChatGPT PluginsYesNo: ChatGPT cannot send a fixed header
Claude (claude.ai and Claude Desktop)Customize → ConnectorsYesYes, as a request header
Claude Codeclaude mcp addYesYes, --header
Cursor~/.cursor/mcp.jsonYesYes, headers
VS Code (GitHub Copilot).mcp.jsonYesYes, headers
Windsurf (Devin Desktop)~/.config/devin/mcp_config.jsonYesYes, headers
ClineMCP Servers → Remote ServersYesYes, headers
Continue.continue/mcpServers/depcheck.yamlYesYes, requestOptions.headers
ZedSettings → AI → MCP ServersYesYes, headers
Codexcodex mcp addYesYes, bearer_token_env_var
Gemini CLIgemini mcp addYesYes, --header

Each section below says where the configuration goes, gives the snippet without a key and the snippet with a key, shows how to confirm it worked, and lists the limitations we know of. It also names the vendor documentation it was checked against, and says whether Cert-IX has tested it.

Before you start​

  • Replace YOUR_DEPCHECK_KEY in the with-key snippets with your own key. The no-key snippets contain nothing secret, so you can commit them to a repository and your whole team gets DepCheck.
  • Never commit a key. Put it in a user-level file, a secret prompt or an environment variable — not in a file that goes into version control.
  • Set environment variables before you start the client. When a key is read from a variable that is not set, most clients send an empty or literal value, which DepCheck rejects with 401. Codex does not connect at all.
  • The quickest check for any client: once connected, ask your assistant "Which DepCheck tools can you use?" It should name the five tools. Then try a real question: "Use DepCheck to check whether express 4.17.1 on npm has known vulnerabilities, and suggest a safe version."

ChatGPT​

ChatGPT connects to DepCheck as a custom app in developer mode.

Requirements. A Plus, Pro, Business, Enterprise or Education account, on the web at chatgpt.com. In Business and Enterprise workspaces, an administrator may have to allow developer mode first.

Where the configuration goes. In ChatGPT's settings, not in a file.

Without a key

  1. Open Settings → Security and login and turn on Developer mode.
  2. Go to chatgpt.com/plugins and select the + button.
  3. Enter a name, DepCheck, and a short description, for example Checks dependency versions for known vulnerabilities.
  4. Under Connection, enter the MCP server URL: https://mcp.cert-ix.com/depcheck.
  5. For authentication, choose No Authentication.
  6. Create the app, then review the tools ChatGPT discovered.

With a key. Not possible. ChatGPT apps authenticate with OAuth or not at all; they cannot send a fixed Authorization header, so ChatGPT always uses the no-key tier.

Check that it worked. The app appears under Drafts in your app settings, and its details page lists the five tools. In a new conversation, open the + menu, choose Developer mode, select DepCheck, and ask "Which DepCheck tools can you use?"

Known limitations

  • ChatGPT calls DepCheck from OpenAI's servers, not from your computer. The no-key limit therefore applies to OpenAI's addresses, which other ChatGPT users share. If a call fails with Too Many Requests, wait a minute and try again.
  • DepCheck marks its five tools as read-only, so ChatGPT does not ask you to confirm each call the way it does for write actions.
  • OpenAI labels developer mode an elevated-risk feature for developers. Read its warnings before you turn it on.
  • If ChatGPT does not pick DepCheck on its own, name it in the prompt: "Use the DepCheck app's check_package tool to…".

Configuration checked against https://developers.openai.com/api/docs/guides/developer-mode on 3 October 2026.

Not yet tested by Cert-IX.


Claude (claude.ai and Claude Desktop)​

On claude.ai and in the Claude Desktop app, DepCheck is added as a custom connector. Connectors belong to your Claude account, so one setup works in both places.

Where the configuration goes. Customize → Connectors, in claude.ai or in Claude Desktop. Do not use claude_desktop_config.json: that file only starts local (stdio) servers on your computer and does not take a remote URL.

Without a key (Free, Pro and Max plans)

  1. Open Customize → Connectors.
  2. Select + Add, then Add custom connector.
  3. Enter the name DepCheck and the remote MCP server URL https://mcp.cert-ix.com/depcheck, then select Continue.
  4. Review the authentication settings Claude detected and select Continue.
  5. Under Authentication, choose No sign in.
  6. Leave Request headers empty and select Add.

On Team and Enterprise plans, an Owner first adds the connector under Organization settings → Connectors → Add → Custom → Web (on Enterprise, people with a custom role that includes Manage access to Libraries can do it too). Members then connect it from Customize → Connectors.

With a key. Same steps, but at step 6 add one request header:

Header nameValue
AuthorizationBearer YOUR_DEPCHECK_KEY

Check that it worked. In a new chat, select + at the lower left, then Connectors, and make sure DepCheck is switched on. Ask "Which DepCheck tools can you use?" — Claude should list the five tools.

Known limitations

  • The Free plan allows one custom connector.
  • Claude reaches DepCheck from Anthropic's cloud, not from your computer, so the no-key limit applies to Anthropic's addresses, which other users share. If you see Too Many Requests errors, add a key as a request header.
  • On Team and Enterprise plans, only the roles named above can add the connector.

Configuration checked against https://support.claude.com/en/articles/11175166-get-started-with-custom-connectors-using-remote-mcp on 3 October 2026.

Not yet tested by Cert-IX.


Claude Code​

Where the configuration goes. claude mcp add writes to ~/.claude.json: by default for you in the current project (local scope), or for you in every project with --scope user. With --scope project it writes .mcp.json at the project root, which you can share through version control.

Without a key

claude mcp add --transport http depcheck https://mcp.cert-ix.com/depcheck

Add --scope user to use DepCheck in every project. To share it with your team, use --scope project, which writes this .mcp.json:

{
"mcpServers": {
"depcheck": {
"type": "http",
"url": "https://mcp.cert-ix.com/depcheck"
}
}
}

With a key

claude mcp add --transport http depcheck https://mcp.cert-ix.com/depcheck \
--header "Authorization: Bearer YOUR_DEPCHECK_KEY"

In a shared .mcp.json, reference an environment variable instead of the key itself:

{
"mcpServers": {
"depcheck": {
"type": "http",
"url": "https://mcp.cert-ix.com/depcheck",
"headers": {
"Authorization": "Bearer ${DEPCHECK_API_KEY}"
}
}
}
}

Check that it worked

claude mcp list

The output shows depcheck: https://mcp.cert-ix.com/depcheck (HTTP) - ✔ Connected. Inside a session, /mcp shows DepCheck with five tools; Claude sees them as mcp__depcheck__check_package, mcp__depcheck__scan_dependencies, and so on.

Known limitations

  • A .mcp.json entry must keep "type": "http". Without it, Claude Code treats the entry as a local command and skips it.
  • If DEPCHECK_API_KEY is not set, Claude Code sends the text ${DEPCHECK_API_KEY} as the key and DepCheck answers 401. Set the variable, or remove the headers block.
  • Servers from a project .mcp.json wait for your approval the first time you run claude in that folder (⏸ Pending approval).

Configuration checked against https://code.claude.com/docs/en/mcp on 3 October 2026.

Tested by Cert-IX on 3 October 2026 with Claude Code 2.1.277 and 2.1.288: configuration, connection and the five tools, against a DepCheck test instance.


Cursor​

Where the configuration goes. ~/.cursor/mcp.json for every project, or .cursor/mcp.json in a single project.

Without a key

{
"mcpServers": {
"depcheck": {
"url": "https://mcp.cert-ix.com/depcheck"
}
}
}

With a key. Cursor replaces ${env:NAME} in url and headers with the value of the environment variable:

{
"mcpServers": {
"depcheck": {
"url": "https://mcp.cert-ix.com/depcheck",
"headers": {
"Authorization": "Bearer ${env:DEPCHECK_API_KEY}"
}
}
}
}

Check that it worked. Open Customize in the sidebar: DepCheck should be listed and enabled. With the Cursor CLI, agent mcp list shows the server and agent mcp list-tools depcheck lists the five tools. If something fails, open the Output panel and choose MCP Logs.

Known limitations

  • Cursor asks for your approval before it runs an MCP tool, unless your run mode allows it.
  • The variable must exist in the environment Cursor starts from. An app opened from the Dock, the Start menu or a launcher may not see variables that are only set in your shell profile.

Configuration checked against https://cursor.com/docs/mcp and https://cursor.com/docs/cli/mcp on 3 October 2026.

Not yet tested by Cert-IX.


VS Code (GitHub Copilot)​

In VS Code, DepCheck's tools are used by GitHub Copilot in agent mode.

Where the configuration goes. Since VS Code 1.140 (September 2026), VS Code prefers the portable files that other Copilot tools read too:

  • .mcp.json at the root of your workspace, for one project;
  • ~/.copilot/mcp-config.json (or $COPILOT_HOME/mcp-config.json), for every project.

Both files use a top-level mcpServers key. The older .vscode/mcp.json file uses a top-level servers key instead; VS Code still reads it, but marks it as deprecated for new servers. Mixing up the two keys is the most common reason a server does not appear.

The quickest route is the guided flow: run MCP: Add Server from the Command Palette, choose the HTTP server type, paste https://mcp.cert-ix.com/depcheck, name it depcheck, and save it to .mcp.json (this project) or Copilot Global (every project).

Without a key — in .mcp.json or ~/.copilot/mcp-config.json:

{
"mcpServers": {
"depcheck": {
"type": "http",
"url": "https://mcp.cert-ix.com/depcheck"
}
}
}

If you keep using .vscode/mcp.json, note the different top-level key:

{
"servers": {
"depcheck": {
"type": "http",
"url": "https://mcp.cert-ix.com/depcheck"
}
}
}

With a key — in your user-level ~/.copilot/mcp-config.json, never in a workspace file:

{
"mcpServers": {
"depcheck": {
"type": "http",
"url": "https://mcp.cert-ix.com/depcheck",
"headers": {
"Authorization": "Bearer YOUR_DEPCHECK_KEY"
}
}
}
}

VS Code can also prompt for a key and store it securely, through an inputs entry and a ${input:…} reference. That only works in .vscode/mcp.json or the user-profile mcp.json, and VS Code does not pass such servers to sessions that run on its Agent Host. For DepCheck, the user-level file above is the dependable choice.

Check that it worked. Run MCP: List Servers, select depcheck and choose Show Output to see whether it started. In the Chat view, select Configure Tools: DepCheck's five tools are listed.

Known limitations

  • You need GitHub Copilot. Your organisation's Copilot policy, or the chat.mcp.access setting, can switch MCP servers off.
  • Servers in workspace files start only once you trust the workspace.
  • Claude Code reads .mcp.json at the project root too; the no-key snippet above works in both.

Configuration checked against https://code.visualstudio.com/docs/agent-customization/mcp-servers and https://code.visualstudio.com/docs/agents/reference/mcp-configuration on 3 October 2026.

Not yet tested by Cert-IX.


Windsurf (now Devin Desktop)​

Windsurf has been renamed Devin Desktop. New conversations use the Devin Local agent, which reads MCP servers from the Devin CLI configuration files; the legacy Cascade agent reads its own mcp_config.json. Both read the same user-level file, so one entry covers both agents.

Where the configuration goes. ~/.config/devin/mcp_config.json on macOS and Linux, %APPDATA%\devin\mcp_config.json on Windows. For a single project, Devin Local also reads .devin/mcp_config.json (shared) and .devin/mcp_config.local.json (personal, ignored by Git).

Without a key

{
"mcpServers": {
"depcheck": {
"url": "https://mcp.cert-ix.com/depcheck"
}
}
}

If you have the Devin CLI, devin mcp add -s user depcheck https://mcp.cert-ix.com/depcheck writes the same entry.

With a key — in the user-level file or in .devin/mcp_config.local.json:

{
"mcpServers": {
"depcheck": {
"url": "https://mcp.cert-ix.com/depcheck",
"headers": {
"Authorization": "Bearer YOUR_DEPCHECK_KEY"
}
}
}
}

Check that it worked. Restart Devin Desktop. In a Devin Local conversation, the customizations view lists the MCP servers the session loaded; with the Devin CLI, devin mcp list and devin mcp get depcheck show the same. Then ask "Which DepCheck tools can you use?" In the legacy Cascade agent, the MCPs section of the … menu shows DepCheck and its number of tools.

Known limitations

  • Devin Local asks for approval before each MCP tool call. You can allow one tool or the whole server, for the session or permanently.
  • On enterprise teams, an administrator may have to enable MCP, or add DepCheck to the team's MCP allowlist or registry.
  • Older Windsurf guides use ~/.codeium/windsurf/mcp_config.json and the serverUrl key. Current versions read the files above, and url works for both agents.
  • Cascade can use at most 100 tools across all servers.

Configuration checked against https://docs.devin.ai/desktop/devin-local, https://docs.devin.ai/cli/extensibility/mcp/configuration and https://docs.devin.ai/desktop/cascade/mcp on 3 October 2026.

Not yet tested by Cert-IX.


Cline​

Where the configuration goes. In the Cline extension for VS Code or JetBrains, select the MCP Servers icon in the Cline panel. Use the Remote Servers tab, or Configure → Configure MCP Servers to edit the JSON. The Cline CLI uses ~/.cline/mcp.json, or the cline mcp wizard.

Without a key. On the Remote Servers tab, enter the server name depcheck and the server URL https://mcp.cert-ix.com/depcheck, choose the Streamable HTTP transport, and select Add Server. The equivalent JSON:

{
"mcpServers": {
"depcheck": {
"type": "streamableHttp",
"url": "https://mcp.cert-ix.com/depcheck",
"disabled": false,
"autoApprove": []
}
}
}

With a key. The Remote Servers form has no field for headers, so add them in the JSON (the CLI wizard asks for headers):

{
"mcpServers": {
"depcheck": {
"type": "streamableHttp",
"url": "https://mcp.cert-ix.com/depcheck",
"headers": {
"Authorization": "Bearer YOUR_DEPCHECK_KEY"
},
"disabled": false,
"autoApprove": []
}
}
}

Check that it worked. In MCP Servers, DepCheck shows as connected with its five tools. In the CLI, cline config mcp lists the configured servers.

Known limitations

  • Keep "type": "streamableHttp". Without it, Cline uses the legacy SSE transport, which DepCheck does not offer, and the connection fails.
  • Cline asks before each tool call. DepCheck's tools only read data, so you may list them in autoApprove if you prefer.

Configuration checked against https://docs.cline.bot/mcp/mcp-overview on 3 October 2026.

Not yet tested by Cert-IX.


Continue​

Where the configuration goes. A block file in your workspace, .continue/mcpServers/depcheck.yaml, or the mcpServers list of your user configuration, ~/.continue/config.yaml.

Without a key — .continue/mcpServers/depcheck.yaml:

name: DepCheck
version: 0.0.1
schema: v1
mcpServers:
- name: DepCheck
type: streamable-http
url: https://mcp.cert-ix.com/depcheck

In ~/.continue/config.yaml, add only the list entry (from - name: DepCheck) under your existing mcpServers: key.

With a key

name: DepCheck
version: 0.0.1
schema: v1
mcpServers:
- name: DepCheck
type: streamable-http
url: https://mcp.cert-ix.com/depcheck
requestOptions:
headers:
Authorization: Bearer ${{ secrets.DEPCHECK_API_KEY }}

Then store the key in ~/.continue/.env:

DEPCHECK_API_KEY=YOUR_DEPCHECK_KEY

Check that it worked. MCP tools only work in Agent mode. Switch the chat to Agent and ask "Which DepCheck tools can you use?"

Known limitations

  • Continue in VS Code or JetBrains cannot read variables from your shell. Use a .env file: Continue looks in the workspace .env, then .continue/.env in the workspace, then ~/.continue/.env.
  • A block file in .continue/mcpServers/ needs its name, version and schema lines.

Configuration checked against https://docs.continue.dev/customize/deep-dives/mcp, https://docs.continue.dev/reference and https://docs.continue.dev/faqs on 3 October 2026.

Not yet tested by Cert-IX.


Zed​

Where the configuration goes. Settings → AI → MCP Servers → Add Server → Add Remote Server writes a context_servers entry in your settings file. You can also edit that file directly: run zed: open settings file from the command palette.

Without a key

{
"context_servers": {
"depcheck": {
"url": "https://mcp.cert-ix.com/depcheck"
}
}
}

With a key — in your user settings, not in a project's .zed/settings.json that you commit:

{
"context_servers": {
"depcheck": {
"url": "https://mcp.cert-ix.com/depcheck",
"headers": {
"Authorization": "Bearer YOUR_DEPCHECK_KEY"
}
}
}
}

Check that it worked. In Settings → AI → MCP Servers, the dot next to DepCheck turns green and its tooltip reads Server is active. Then ask in the Agent Panel "Which DepCheck tools can you use?"

Known limitations

  • Zed offers an OAuth sign-in when a server answers 401. DepCheck has no sign-in: if Zed asks you to authenticate, your key was rejected. Correct it, or remove the headers block to use the no-key tier.
  • Zed asks for approval before each tool call by default (agent.tool_permissions.default).
  • Mentioning DepCheck by name in your prompt helps the model choose its tools.

Configuration checked against https://zed.dev/docs/ai/mcp on 3 October 2026.

Not yet tested by Cert-IX.


Codex (CLI, IDE extension and ChatGPT desktop app)​

Where the configuration goes. ~/.codex/config.toml, or .codex/config.toml in a trusted project. The Codex CLI, the Codex IDE extension and the ChatGPT desktop app share this file.

Without a key

codex mcp add depcheck --url https://mcp.cert-ix.com/depcheck

This writes:

[mcp_servers.depcheck]
url = "https://mcp.cert-ix.com/depcheck"

In the ChatGPT desktop app, the same server can be added from Settings → MCP servers → Add server: choose Streamable HTTP, enter the URL, save, then select Restart.

With a key. Codex reads the key from an environment variable, so the key itself never goes into the file:

export DEPCHECK_API_KEY=YOUR_DEPCHECK_KEY
codex mcp add depcheck --url https://mcp.cert-ix.com/depcheck \
--bearer-token-env-var DEPCHECK_API_KEY

This writes:

[mcp_servers.depcheck]
url = "https://mcp.cert-ix.com/depcheck"
bearer_token_env_var = "DEPCHECK_API_KEY"

Check that it worked. codex mcp list shows depcheck as enabled. It only reads your configuration and does not contact the server; Auth: Unknown is normal without a key. Start codex, type /mcp to see the active servers, and ask "Which DepCheck tools can you use?"

Known limitations

  • After codex mcp add, Codex says the server "may or may not require login". DepCheck has no login: do not run codex mcp login depcheck.
  • If DEPCHECK_API_KEY is not set when Codex starts, Codex does not connect to DepCheck at all, and in our test it showed no error. Set the variable first, or use the no-key entry.
  • A project-level .codex/config.toml is only read in trusted projects.

Configuration checked against https://learn.chatgpt.com/docs/extend/mcp on 3 October 2026.

Tested by Cert-IX on 3 October 2026 with Codex CLI 0.160.0: configuration, connection and the five tools, against a DepCheck test instance.


Gemini CLI​

Where the configuration goes. ~/.gemini/settings.json for you, or .gemini/settings.json in a project. gemini mcp add writes to the project file unless you pass --scope user.

Without a key

gemini mcp add --scope user --transport http depcheck https://mcp.cert-ix.com/depcheck

This writes:

{
"mcpServers": {
"depcheck": {
"url": "https://mcp.cert-ix.com/depcheck",
"type": "http"
}
}
}

With a key

gemini mcp add --scope user --transport http \
--header "Authorization: Bearer YOUR_DEPCHECK_KEY" \
depcheck https://mcp.cert-ix.com/depcheck

In settings.json you can reference an environment variable instead: "Authorization": "Bearer $DEPCHECK_API_KEY" inside the server's headers.

Check that it worked

gemini mcp list

The output shows ✓ depcheck: https://mcp.cert-ix.com/depcheck (http) - Connected. In a session, /mcp lists DepCheck and its tools; the model sees them as mcp_depcheck_check_package, mcp_depcheck_scan_dependencies, and so on.

Known limitations

  • In a folder you have not trusted, Gemini CLI disables MCP servers, including user-level ones, and gemini mcp list shows Disabled. Start gemini in the folder and trust it when asked.
  • In headless runs (gemini -p), Gemini CLI leaves out tools that would need your confirmation, which includes DepCheck's, unless you trust the server: add --trust to gemini mcp add, or "trust": true to the entry. DepCheck's tools only read data, but trusting a server skips every confirmation for it.
  • Gemini's documentation still shows the httpUrl key. Gemini CLI 0.62 still accepts it, but its code marks it as deprecated in favour of url with "type": "http", which is what gemini mcp add writes.
  • If DEPCHECK_API_KEY is not set, Gemini CLI sends an empty key and DepCheck answers 401.
  • Do not use underscores in the server name.

Configuration checked against https://geminicli.com/docs/tools/mcp-server/ and https://geminicli.com/docs/reference/configuration/ on 3 October 2026.

Tested by Cert-IX on 3 October 2026 with Gemini CLI 0.62.0: configuration, connection and the five tools, against a DepCheck test instance.


Troubleshooting​

What you seeWhat it meansWhat to do
401 Unauthorized, Needs authentication, or a sign-in promptA key was sent and rejected: it is wrong, expired or revoked, or an unset variable was sent as textFix the key, or remove the Authorization header to use the no-key tier
429 Too Many RequestsYou went over the no-key limit (60 requests per minute per IP address) or your key's limitWait a minute and retry; for sustained use, add a key
The client tries SSE, or reports a transport errorThe client is set to the legacy SSE transportChoose HTTP or Streamable HTTP (in Cline: "type": "streamableHttp")
Connected, but the tools never appearThe client is waiting for approval, folder trust or agent modeSee your client's known limitations above
Nothing connects from an office networkA proxy or firewall blocks the addressAllow HTTPS to mcp.cert-ix.com

To test the endpoint without any client, use the curl sanity check.

Next steps​

¿Te resultó útil esta página?