What is the DefectDojo MCP server?
MCP server for DefectDojo: 24 tools with RBAC, HMAC audit chain, and SIEM forwarding
How to install DefectDojo
Copy-paste configuration for popular MCP clients.
DEFECTDOJO_URLrequiredBase URL of the DefectDojo instance (must use https:// unless ALLOW_INSECURE_HTTP=true)
DEFECTDOJO_API_KEYrequiredsecretAPI key for DefectDojo (generate at DefectDojo > API v2 > Your API Key). Use DEFECTDOJO_READ_API_KEY + DEFECTDOJO_WRITE_API_KEY for least-privilege dual-key mode.
DEFECTDOJO_READ_API_KEYsecretOptional read-only API key (used for GET requests in dual-key mode)
DEFECTDOJO_WRITE_API_KEYsecretOptional write API key (used for POST/PATCH in dual-key mode)
MCP_AUTH_TOKENsecretBearer token granting admin-role access (legacy single-token mode — prefer MCP_ROLE_<NAME>=<token>:<role> for RBAC)
AUDIT_HMAC_KEYsecretHMAC key for audit log integrity chain. Required for cross-restart log verification on network transports. Generate with: python3 -c 'import secrets; print(secrets.token_hex(32))'
Related MCP servers

Rootr
Connect your team's living knowledge base — docs, data, issues, CRM — to Claude and ChatGPT.

INSSIST
Drive your own logged-in Instagram session via the INSSIST extension: read, publish, DMs, analytics.

io.github.instagitai/instagit
AI-powered Git repository analysis for coding agents — understand any codebase instantly with ground truth.

RankCLI
Free, local SEO + GEO audits for AI assistants - no signup, nothing leaves your machine.

io.github.integsec/turbopentest
AI-powered penetration testing. Launch scans, review findings, download reports.
Run the Intelliverse platform from any agent: apps, API keys, knowledge bases, email, media, chat.
