Connect your assistant to DepCheck
DepCheck is one hosted endpoint, and every client on this page connects to the same address. You do not need an account or a key: add the address to your assistant and it can check dependencies straight away.
| Endpoint | https://mcp.cert-ix.com/depcheck |
| Transport | Streamable HTTP (MCP protocol version 2025-06-18). There is no separate SSE endpoint: when a client asks, choose HTTP or Streamable HTTP. |
| Without a key | Each IP address can make 60 requests per minute, with a burst allowance of 30. |
| With a key (optional) | Free from cert-ix.com/tools/depcheck-mcp, valid for 90 days, sent as Authorization: Bearer <key>. A key raises the limits. |
| Tools | check_package, scan_dependencies, suggest_safe_version, get_advisory, get_cve_intel |
If you send a key, it must be valid. An invalid or expired key is rejected with
401 Unauthorized: DepCheck does not fall back to the no-key tier. If you have
no valid key, remove the Authorization header from your configuration.
Choose your client​
| Client | Where you set it up | Without a key | With a key |
|---|---|---|---|
| ChatGPT | Developer mode, then ChatGPT Plugins | Yes | No: ChatGPT cannot send a fixed header |
| Claude (claude.ai and Claude Desktop) | Customize → Connectors | Yes | Yes, as a request header |
| Claude Code | claude mcp add | Yes | Yes, --header |
| Cursor | ~/.cursor/mcp.json | Yes | Yes, headers |
| VS Code (GitHub Copilot) | .mcp.json | Yes | Yes, headers |
| Windsurf (Devin Desktop) | ~/.config/devin/mcp_config.json | Yes | Yes, headers |
| Cline | MCP Servers → Remote Servers | Yes | Yes, headers |
| Continue | .continue/mcpServers/depcheck.yaml | Yes | Yes, requestOptions.headers |
| Zed | Settings → AI → MCP Servers | Yes | Yes, headers |
| Codex | codex mcp add | Yes | Yes, bearer_token_env_var |
| Gemini CLI | gemini mcp add | Yes | Yes, --header |
Each section below says where the configuration goes, gives the snippet without a key and the snippet with a key, shows how to confirm it worked, and lists the limitations we know of. It also names the vendor documentation it was checked against, and says whether Cert-IX has tested it.
Before you start​
- Replace
YOUR_DEPCHECK_KEYin the with-key snippets with your own key. The no-key snippets contain nothing secret, so you can commit them to a repository and your whole team gets DepCheck. - Never commit a key. Put it in a user-level file, a secret prompt or an environment variable — not in a file that goes into version control.
- Set environment variables before you start the client. When a key is read
from a variable that is not set, most clients send an empty or literal value,
which DepCheck rejects with
401. Codex does not connect at all. - The quickest check for any client: once connected, ask your assistant "Which DepCheck tools can you use?" It should name the five tools. Then try a real question: "Use DepCheck to check whether express 4.17.1 on npm has known vulnerabilities, and suggest a safe version."
ChatGPT​
ChatGPT connects to DepCheck as a custom app in developer mode.
Requirements. A Plus, Pro, Business, Enterprise or Education account, on the web at chatgpt.com. In Business and Enterprise workspaces, an administrator may have to allow developer mode first.
Where the configuration goes. In ChatGPT's settings, not in a file.
Without a key
- Open Settings → Security and login and turn on Developer mode.
- Go to chatgpt.com/plugins and select the + button.
- Enter a name,
DepCheck, and a short description, for example Checks dependency versions for known vulnerabilities. - Under Connection, enter the MCP server URL:
https://mcp.cert-ix.com/depcheck. - For authentication, choose No Authentication.
- Create the app, then review the tools ChatGPT discovered.
With a key. Not possible. ChatGPT apps authenticate with OAuth or not at
all; they cannot send a fixed Authorization header, so ChatGPT always uses the
no-key tier.
Check that it worked. The app appears under Drafts in your app settings, and its details page lists the five tools. In a new conversation, open the + menu, choose Developer mode, select DepCheck, and ask "Which DepCheck tools can you use?"
Known limitations
- ChatGPT calls DepCheck from OpenAI's servers, not from your computer. The no-key limit therefore applies to OpenAI's addresses, which other ChatGPT users share. If a call fails with Too Many Requests, wait a minute and try again.
- DepCheck marks its five tools as read-only, so ChatGPT does not ask you to confirm each call the way it does for write actions.
- OpenAI labels developer mode an elevated-risk feature for developers. Read its warnings before you turn it on.
- If ChatGPT does not pick DepCheck on its own, name it in the prompt: "Use the
DepCheck app's
check_packagetool to…".
Configuration checked against https://developers.openai.com/api/docs/guides/developer-mode on 3 October 2026.
Not yet tested by Cert-IX.
Claude (claude.ai and Claude Desktop)​
On claude.ai and in the Claude Desktop app, DepCheck is added as a custom connector. Connectors belong to your Claude account, so one setup works in both places.
Where the configuration goes. Customize → Connectors, in claude.ai or
in Claude Desktop. Do not use claude_desktop_config.json: that file only
starts local (stdio) servers on your computer and does not take a remote URL.
Without a key (Free, Pro and Max plans)
- Open Customize → Connectors.
- Select + Add, then Add custom connector.
- Enter the name
DepCheckand the remote MCP server URLhttps://mcp.cert-ix.com/depcheck, then select Continue. - Review the authentication settings Claude detected and select Continue.
- Under Authentication, choose No sign in.
- Leave Request headers empty and select Add.
On Team and Enterprise plans, an Owner first adds the connector under Organization settings → Connectors → Add → Custom → Web (on Enterprise, people with a custom role that includes Manage access to Libraries can do it too). Members then connect it from Customize → Connectors.
With a key. Same steps, but at step 6 add one request header:
| Header name | Value |
|---|---|
Authorization | Bearer YOUR_DEPCHECK_KEY |
Check that it worked. In a new chat, select + at the lower left, then Connectors, and make sure DepCheck is switched on. Ask "Which DepCheck tools can you use?" — Claude should list the five tools.
Known limitations
- The Free plan allows one custom connector.
- Claude reaches DepCheck from Anthropic's cloud, not from your computer, so the no-key limit applies to Anthropic's addresses, which other users share. If you see Too Many Requests errors, add a key as a request header.
- On Team and Enterprise plans, only the roles named above can add the connector.
Configuration checked against https://support.claude.com/en/articles/11175166-get-started-with-custom-connectors-using-remote-mcp on 3 October 2026.
Not yet tested by Cert-IX.
Claude Code​
Where the configuration goes. claude mcp add writes to ~/.claude.json:
by default for you in the current project (local scope), or for you in every
project with --scope user. With --scope project it writes .mcp.json at the
project root, which you can share through version control.
Without a key
claude mcp add --transport http depcheck https://mcp.cert-ix.com/depcheck
Add --scope user to use DepCheck in every project. To share it with your team,
use --scope project, which writes this .mcp.json:
{
"mcpServers": {
"depcheck": {
"type": "http",
"url": "https://mcp.cert-ix.com/depcheck"
}
}
}
With a key
claude mcp add --transport http depcheck https://mcp.cert-ix.com/depcheck \
--header "Authorization: Bearer YOUR_DEPCHECK_KEY"
In a shared .mcp.json, reference an environment variable instead of the key
itself:
{
"mcpServers": {
"depcheck": {
"type": "http",
"url": "https://mcp.cert-ix.com/depcheck",
"headers": {
"Authorization": "Bearer ${DEPCHECK_API_KEY}"
}
}
}
}
Check that it worked
claude mcp list
The output shows depcheck: https://mcp.cert-ix.com/depcheck (HTTP) - âś” Connected.
Inside a session, /mcp shows DepCheck with five tools; Claude sees them as
mcp__depcheck__check_package, mcp__depcheck__scan_dependencies, and so on.
Known limitations
- A
.mcp.jsonentry must keep"type": "http". Without it, Claude Code treats the entry as a local command and skips it. - If
DEPCHECK_API_KEYis not set, Claude Code sends the text${DEPCHECK_API_KEY}as the key and DepCheck answers401. Set the variable, or remove theheadersblock. - Servers from a project
.mcp.jsonwait for your approval the first time you runclaudein that folder (⏸ Pending approval).
Configuration checked against https://code.claude.com/docs/en/mcp on 3 October 2026.
Tested by Cert-IX on 3 October 2026 with Claude Code 2.1.277 and 2.1.288: configuration, connection and the five tools, against a DepCheck test instance.
Cursor​
Where the configuration goes. ~/.cursor/mcp.json for every project, or
.cursor/mcp.json in a single project.
Without a key
{
"mcpServers": {
"depcheck": {
"url": "https://mcp.cert-ix.com/depcheck"
}
}
}
With a key. Cursor replaces ${env:NAME} in url and headers with the
value of the environment variable:
{
"mcpServers": {
"depcheck": {
"url": "https://mcp.cert-ix.com/depcheck",
"headers": {
"Authorization": "Bearer ${env:DEPCHECK_API_KEY}"
}
}
}
}
Check that it worked. Open Customize in the sidebar: DepCheck should be
listed and enabled. With the Cursor CLI, agent mcp list shows the server and
agent mcp list-tools depcheck lists the five tools. If something fails, open
the Output panel and choose MCP Logs.
Known limitations
- Cursor asks for your approval before it runs an MCP tool, unless your run mode allows it.
- The variable must exist in the environment Cursor starts from. An app opened from the Dock, the Start menu or a launcher may not see variables that are only set in your shell profile.
Configuration checked against https://cursor.com/docs/mcp and https://cursor.com/docs/cli/mcp on 3 October 2026.
Not yet tested by Cert-IX.
VS Code (GitHub Copilot)​
In VS Code, DepCheck's tools are used by GitHub Copilot in agent mode.
Where the configuration goes. Since VS Code 1.140 (September 2026), VS Code prefers the portable files that other Copilot tools read too:
.mcp.jsonat the root of your workspace, for one project;~/.copilot/mcp-config.json(or$COPILOT_HOME/mcp-config.json), for every project.
Both files use a top-level mcpServers key. The older .vscode/mcp.json
file uses a top-level servers key instead; VS Code still reads it, but
marks it as deprecated for new servers. Mixing up the two keys is the most
common reason a server does not appear.
The quickest route is the guided flow: run MCP: Add Server from the Command
Palette, choose the HTTP server type, paste https://mcp.cert-ix.com/depcheck,
name it depcheck, and save it to .mcp.json (this project) or Copilot
Global (every project).
Without a key — in .mcp.json or ~/.copilot/mcp-config.json:
{
"mcpServers": {
"depcheck": {
"type": "http",
"url": "https://mcp.cert-ix.com/depcheck"
}
}
}
If you keep using .vscode/mcp.json, note the different top-level key:
{
"servers": {
"depcheck": {
"type": "http",
"url": "https://mcp.cert-ix.com/depcheck"
}
}
}
With a key — in your user-level ~/.copilot/mcp-config.json, never in a
workspace file:
{
"mcpServers": {
"depcheck": {
"type": "http",
"url": "https://mcp.cert-ix.com/depcheck",
"headers": {
"Authorization": "Bearer YOUR_DEPCHECK_KEY"
}
}
}
}
VS Code can also prompt for a key and store it securely, through an inputs
entry and a ${input:…} reference. That only works in .vscode/mcp.json or the
user-profile mcp.json, and VS Code does not pass such servers to sessions that
run on its Agent Host. For DepCheck, the user-level file above is the dependable
choice.
Check that it worked. Run MCP: List Servers, select depcheck and
choose Show Output to see whether it started. In the Chat view, select
Configure Tools: DepCheck's five tools are listed.
Known limitations
- You need GitHub Copilot. Your organisation's Copilot policy, or the
chat.mcp.accesssetting, can switch MCP servers off. - Servers in workspace files start only once you trust the workspace.
- Claude Code reads
.mcp.jsonat the project root too; the no-key snippet above works in both.
Configuration checked against https://code.visualstudio.com/docs/agent-customization/mcp-servers and https://code.visualstudio.com/docs/agents/reference/mcp-configuration on 3 October 2026.
Not yet tested by Cert-IX.
Windsurf (now Devin Desktop)​
Windsurf has been renamed Devin Desktop. New conversations use the Devin
Local agent, which reads MCP servers from the Devin CLI configuration files;
the legacy Cascade agent reads its own mcp_config.json. Both read the same
user-level file, so one entry covers both agents.
Where the configuration goes. ~/.config/devin/mcp_config.json on macOS
and Linux, %APPDATA%\devin\mcp_config.json on Windows. For a single project,
Devin Local also reads .devin/mcp_config.json (shared) and
.devin/mcp_config.local.json (personal, ignored by Git).
Without a key
{
"mcpServers": {
"depcheck": {
"url": "https://mcp.cert-ix.com/depcheck"
}
}
}
If you have the Devin CLI, devin mcp add -s user depcheck https://mcp.cert-ix.com/depcheck
writes the same entry.
With a key — in the user-level file or in .devin/mcp_config.local.json:
{
"mcpServers": {
"depcheck": {
"url": "https://mcp.cert-ix.com/depcheck",
"headers": {
"Authorization": "Bearer YOUR_DEPCHECK_KEY"
}
}
}
}
Check that it worked. Restart Devin Desktop. In a Devin Local conversation,
the customizations view lists the MCP servers the session loaded; with the Devin
CLI, devin mcp list and devin mcp get depcheck show the same. Then ask
"Which DepCheck tools can you use?" In the legacy Cascade agent, the MCPs
section of the … menu shows DepCheck and its number of tools.
Known limitations
- Devin Local asks for approval before each MCP tool call. You can allow one tool or the whole server, for the session or permanently.
- On enterprise teams, an administrator may have to enable MCP, or add DepCheck to the team's MCP allowlist or registry.
- Older Windsurf guides use
~/.codeium/windsurf/mcp_config.jsonand theserverUrlkey. Current versions read the files above, andurlworks for both agents. - Cascade can use at most 100 tools across all servers.
Configuration checked against https://docs.devin.ai/desktop/devin-local, https://docs.devin.ai/cli/extensibility/mcp/configuration and https://docs.devin.ai/desktop/cascade/mcp on 3 October 2026.
Not yet tested by Cert-IX.
Cline​
Where the configuration goes. In the Cline extension for VS Code or
JetBrains, select the MCP Servers icon in the Cline panel. Use the Remote
Servers tab, or Configure → Configure MCP Servers to edit the JSON. The
Cline CLI uses ~/.cline/mcp.json, or the cline mcp wizard.
Without a key. On the Remote Servers tab, enter the server name
depcheck and the server URL https://mcp.cert-ix.com/depcheck, choose the
Streamable HTTP transport, and select Add Server. The equivalent JSON:
{
"mcpServers": {
"depcheck": {
"type": "streamableHttp",
"url": "https://mcp.cert-ix.com/depcheck",
"disabled": false,
"autoApprove": []
}
}
}
With a key. The Remote Servers form has no field for headers, so add them in the JSON (the CLI wizard asks for headers):
{
"mcpServers": {
"depcheck": {
"type": "streamableHttp",
"url": "https://mcp.cert-ix.com/depcheck",
"headers": {
"Authorization": "Bearer YOUR_DEPCHECK_KEY"
},
"disabled": false,
"autoApprove": []
}
}
}
Check that it worked. In MCP Servers, DepCheck shows as connected with
its five tools. In the CLI, cline config mcp lists the configured servers.
Known limitations
- Keep
"type": "streamableHttp". Without it, Cline uses the legacy SSE transport, which DepCheck does not offer, and the connection fails. - Cline asks before each tool call. DepCheck's tools only read data, so you may
list them in
autoApproveif you prefer.
Configuration checked against https://docs.cline.bot/mcp/mcp-overview on 3 October 2026.
Not yet tested by Cert-IX.
Continue​
Where the configuration goes. A block file in your workspace,
.continue/mcpServers/depcheck.yaml, or the mcpServers list of your user
configuration, ~/.continue/config.yaml.
Without a key — .continue/mcpServers/depcheck.yaml:
name: DepCheck
version: 0.0.1
schema: v1
mcpServers:
- name: DepCheck
type: streamable-http
url: https://mcp.cert-ix.com/depcheck
In ~/.continue/config.yaml, add only the list entry (from - name: DepCheck)
under your existing mcpServers: key.
With a key
name: DepCheck
version: 0.0.1
schema: v1
mcpServers:
- name: DepCheck
type: streamable-http
url: https://mcp.cert-ix.com/depcheck
requestOptions:
headers:
Authorization: Bearer ${{ secrets.DEPCHECK_API_KEY }}
Then store the key in ~/.continue/.env:
DEPCHECK_API_KEY=YOUR_DEPCHECK_KEY
Check that it worked. MCP tools only work in Agent mode. Switch the chat to Agent and ask "Which DepCheck tools can you use?"
Known limitations
- Continue in VS Code or JetBrains cannot read variables from your shell. Use a
.envfile: Continue looks in the workspace.env, then.continue/.envin the workspace, then~/.continue/.env. - A block file in
.continue/mcpServers/needs itsname,versionandschemalines.
Configuration checked against https://docs.continue.dev/customize/deep-dives/mcp, https://docs.continue.dev/reference and https://docs.continue.dev/faqs on 3 October 2026.
Not yet tested by Cert-IX.
Zed​
Where the configuration goes. Settings → AI → MCP Servers → Add Server →
Add Remote Server writes a context_servers entry in your settings file. You
can also edit that file directly: run zed: open settings file from the command
palette.
Without a key
{
"context_servers": {
"depcheck": {
"url": "https://mcp.cert-ix.com/depcheck"
}
}
}
With a key — in your user settings, not in a project's .zed/settings.json
that you commit:
{
"context_servers": {
"depcheck": {
"url": "https://mcp.cert-ix.com/depcheck",
"headers": {
"Authorization": "Bearer YOUR_DEPCHECK_KEY"
}
}
}
}
Check that it worked. In Settings → AI → MCP Servers, the dot next to DepCheck turns green and its tooltip reads Server is active. Then ask in the Agent Panel "Which DepCheck tools can you use?"
Known limitations
- Zed offers an OAuth sign-in when a server answers
401. DepCheck has no sign-in: if Zed asks you to authenticate, your key was rejected. Correct it, or remove theheadersblock to use the no-key tier. - Zed asks for approval before each tool call by default
(
agent.tool_permissions.default). - Mentioning DepCheck by name in your prompt helps the model choose its tools.
Configuration checked against https://zed.dev/docs/ai/mcp on 3 October 2026.
Not yet tested by Cert-IX.
Codex (CLI, IDE extension and ChatGPT desktop app)​
Where the configuration goes. ~/.codex/config.toml, or
.codex/config.toml in a trusted project. The Codex CLI, the Codex IDE
extension and the ChatGPT desktop app share this file.
Without a key
codex mcp add depcheck --url https://mcp.cert-ix.com/depcheck
This writes:
[mcp_servers.depcheck]
url = "https://mcp.cert-ix.com/depcheck"
In the ChatGPT desktop app, the same server can be added from Settings → MCP servers → Add server: choose Streamable HTTP, enter the URL, save, then select Restart.
With a key. Codex reads the key from an environment variable, so the key itself never goes into the file:
export DEPCHECK_API_KEY=YOUR_DEPCHECK_KEY
codex mcp add depcheck --url https://mcp.cert-ix.com/depcheck \
--bearer-token-env-var DEPCHECK_API_KEY
This writes:
[mcp_servers.depcheck]
url = "https://mcp.cert-ix.com/depcheck"
bearer_token_env_var = "DEPCHECK_API_KEY"
Check that it worked. codex mcp list shows depcheck as enabled. It
only reads your configuration and does not contact the server; Auth: Unknown
is normal without a key. Start codex, type /mcp to see the active servers,
and ask "Which DepCheck tools can you use?"
Known limitations
- After
codex mcp add, Codex says the server "may or may not require login". DepCheck has no login: do not runcodex mcp login depcheck. - If
DEPCHECK_API_KEYis not set when Codex starts, Codex does not connect to DepCheck at all, and in our test it showed no error. Set the variable first, or use the no-key entry. - A project-level
.codex/config.tomlis only read in trusted projects.
Configuration checked against https://learn.chatgpt.com/docs/extend/mcp on 3 October 2026.
Tested by Cert-IX on 3 October 2026 with Codex CLI 0.160.0: configuration, connection and the five tools, against a DepCheck test instance.
Gemini CLI​
Where the configuration goes. ~/.gemini/settings.json for you, or
.gemini/settings.json in a project. gemini mcp add writes to the project
file unless you pass --scope user.
Without a key
gemini mcp add --scope user --transport http depcheck https://mcp.cert-ix.com/depcheck
This writes:
{
"mcpServers": {
"depcheck": {
"url": "https://mcp.cert-ix.com/depcheck",
"type": "http"
}
}
}
With a key
gemini mcp add --scope user --transport http \
--header "Authorization: Bearer YOUR_DEPCHECK_KEY" \
depcheck https://mcp.cert-ix.com/depcheck
In settings.json you can reference an environment variable instead:
"Authorization": "Bearer $DEPCHECK_API_KEY" inside the server's headers.
Check that it worked
gemini mcp list
The output shows âś“ depcheck: https://mcp.cert-ix.com/depcheck (http) - Connected.
In a session, /mcp lists DepCheck and its tools; the model sees them as
mcp_depcheck_check_package, mcp_depcheck_scan_dependencies, and so on.
Known limitations
- In a folder you have not trusted, Gemini CLI disables MCP servers, including
user-level ones, and
gemini mcp listshowsDisabled. Startgeminiin the folder and trust it when asked. - In headless runs (
gemini -p), Gemini CLI leaves out tools that would need your confirmation, which includes DepCheck's, unless you trust the server: add--trusttogemini mcp add, or"trust": trueto the entry. DepCheck's tools only read data, but trusting a server skips every confirmation for it. - Gemini's documentation still shows the
httpUrlkey. Gemini CLI 0.62 still accepts it, but its code marks it as deprecated in favour ofurlwith"type": "http", which is whatgemini mcp addwrites. - If
DEPCHECK_API_KEYis not set, Gemini CLI sends an empty key and DepCheck answers401. - Do not use underscores in the server name.
Configuration checked against https://geminicli.com/docs/tools/mcp-server/ and https://geminicli.com/docs/reference/configuration/ on 3 October 2026.
Tested by Cert-IX on 3 October 2026 with Gemini CLI 0.62.0: configuration, connection and the five tools, against a DepCheck test instance.
Troubleshooting​
| What you see | What it means | What to do |
|---|---|---|
401 Unauthorized, Needs authentication, or a sign-in prompt | A key was sent and rejected: it is wrong, expired or revoked, or an unset variable was sent as text | Fix the key, or remove the Authorization header to use the no-key tier |
429 Too Many Requests | You went over the no-key limit (60 requests per minute per IP address) or your key's limit | Wait a minute and retry; for sustained use, add a key |
| The client tries SSE, or reports a transport error | The client is set to the legacy SSE transport | Choose HTTP or Streamable HTTP (in Cline: "type": "streamableHttp") |
| Connected, but the tools never appear | The client is waiting for approval, folder trust or agent mode | See your client's known limitations above |
| Nothing connects from an office network | A proxy or firewall blocks the address | Allow HTTPS to mcp.cert-ix.com |
To test the endpoint without any client, use the curl sanity check.
Next steps​
- Tools reference — every tool, its parameters, and example responses.
- Agent workflows — the check-before-you-add discipline.
- Security & data handling — keys, rate limits, and what leaves the Cert-IX perimeter.
Questa pagina ti è stata utile?