Getting Started with the Bits MCP
The Bits MCP is hosted and public. There is nothing to install and nothing to request — no account, no API key, no waiting on an account team.
https://mcp.cert-ix.com/bits
Prerequisites
An MCP-capable client: Claude Code, Claude Desktop, Cursor, VS Code with an MCP extension, or anything that speaks streamable-HTTP MCP.
That is the whole list.
Claude Code (CLI)
claude mcp add --transport http bits https://mcp.cert-ix.com/bits
No --header argument, because there is no key to send.
Claude Desktop
Add to claude_desktop_config.json:
{
"mcpServers": {
"bits": {
"type": "http",
"url": "https://mcp.cert-ix.com/bits"
}
}
}
Restart Claude Desktop. "bits" appears in the tools list.
Cursor
Add to .cursor/mcp.json in your project, or to the global equivalent:
{
"mcpServers": {
"bits": {
"url": "https://mcp.cert-ix.com/bits"
}
}
}
VS Code
With an MCP-capable extension, add to .vscode/mcp.json:
{
"servers": {
"bits": {
"type": "http",
"url": "https://mcp.cert-ix.com/bits"
}
}
}
Verify it works
Ask your client something only this server can answer:
Which Bits agent tells me what is listening on my hosts, and does it work without root?
You should get bitcollector, along with the caveat that a non-root agent cannot attribute listening sockets to processes — an answer with a limitation in it, which is the point.
To check the endpoint directly:
curl -s -X POST https://mcp.cert-ix.com/bits \
-H 'Content-Type: application/json' \
-H 'Accept: application/json, text/event-stream' \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}'
Five tools come back: bits_platforms, bits_explain, bits_recommend,
bits_plan_config and bits_download.
Things worth knowing before you rely on it
It is rate limited, per IP
Ordinary interactive use will not notice. Automated loops will: sustained bursts
receive 429 with a Retry-After header. Honour it rather than retrying
immediately.
GET is not supported
The endpoint accepts POST only and answers 405 to anything else. If your
client opens a long-lived GET stream by default, it will need the
streamable-HTTP POST transport instead.
A refusal is a real answer
When the release catalogue cannot be read, or can be read but not verified, the tools return an error result saying so — not an empty list. Handle that case rather than treating it as "no results". It is the difference between "this agent has no arm64 build" and "we could not determine what it has", and only the first is safe to act on.
It cannot touch your estate
There is no tool here that enrols an agent, deploys anything, or reads your fleet. Those require an authenticated session in your Cert-IX dashboard. If an AI client tells you it has enrolled or deployed something through this endpoint, it has not.
The same goes the other way: never paste your enrolment token into a
conversation with this server. The token is generated in your Cert-IX
dashboard and belongs on the machine the agent runs on. bits_plan_config and
bits_download refuse any argument shaped like one, and say where it goes
instead.
Next
- Tools reference — parameters, outputs, failure shapes
- Bits overview — what the four agents are
¿Te resultó útil esta página?