Snyk · Codex

Add the Snyk MCP server to Codex

Scan code, dependencies, containers and IaC for vulnerabilities from the agent.

Official serverLocalSecurity & code quality

1. Add the server

Run in your terminal

# ~/.codex/config.toml
[mcp_servers.snyk]
command = "npx"
args = ["-y", "snyk", "mcp", "-t", "stdio"]

2. Sign in

Run codex mcp login <name> to complete OAuth for a remote server. Snyk runs locally; set any credentials Snyk asks for before starting Codex.

3. Try it

Ask Codex for something Snyk can do. Scan code, dependencies, containers and IaC for vulnerabilities from the agent. Approve the first tool call and check the result before allowing write actions automatically.

  • · Each server is a [mcp_servers.<name>] table in config.toml.
  • · Use enabled_tools or disabled_tools to keep the tool list short.

FAQ

How do I add the Snyk MCP server to Codex?
Run: # ~/.codex/config.toml …. Run codex mcp login <name> to complete OAuth for a remote server.
Is this the official Snyk MCP server?
Yes. It is published by Snyk as io.snyk/mcp in the official MCP registry.
Does the Snyk MCP server need an API key?
It runs locally from a package. See Snyk's docs for any credentials it needs.

Links

Snyk in other clients

More security & code quality for Codex

Work at Snyk?

Feature Snyk across the directory and its category from $49/month.

Feature this server

Reviewed Oct 5, 2026. Command generated from the registry record and checked against Codex's documented syntax.