Snyk · Cursor

Add the Snyk MCP server to Cursor

Scan code, dependencies, containers and IaC for vulnerabilities from the agent.

Official serverLocalSecurity & code quality

1. Add the server

Paste into .cursor/mcp.json (project) or ~/.cursor/mcp.json (global)

{
  "mcpServers": {
    "snyk": {
      "command": "npx",
      "args": [
        "-y",
        "snyk",
        "mcp",
        "-t",
        "stdio"
      ]
    }
  }
}

2. Sign in

Cursor prompts you to sign in the first time a remote OAuth server is used. Snyk runs locally; set any credentials Snyk asks for before starting Cursor.

3. Try it

Ask Cursor for something Snyk can do. Scan code, dependencies, containers and IaC for vulnerabilities from the agent. Approve the first tool call and check the result before allowing write actions automatically.

  • · Remote servers take a url; local servers take command and args.
  • · Values can reference ${env:NAME} so secrets stay out of the file.

FAQ

How do I add the Snyk MCP server to Cursor?
Run: { …. Cursor prompts you to sign in the first time a remote OAuth server is used.
Is this the official Snyk MCP server?
Yes. It is published by Snyk as io.snyk/mcp in the official MCP registry.
Does the Snyk MCP server need an API key?
It runs locally from a package. See Snyk's docs for any credentials it needs.

Links

Snyk in other clients

More security & code quality for Cursor

Work at Snyk?

Feature Snyk across the directory and its category from $49/month.

Feature this server

Reviewed Oct 5, 2026. Command generated from the registry record and checked against Cursor's documented syntax.