Snyk · Cursor
Add the Snyk MCP server to Cursor
Scan code, dependencies, containers and IaC for vulnerabilities from the agent.
Official serverLocalSecurity & code quality
1. Add the server
Paste into .cursor/mcp.json (project) or ~/.cursor/mcp.json (global)
{
"mcpServers": {
"snyk": {
"command": "npx",
"args": [
"-y",
"snyk",
"mcp",
"-t",
"stdio"
]
}
}
}2. Sign in
Cursor prompts you to sign in the first time a remote OAuth server is used. Snyk runs locally; set any credentials Snyk asks for before starting Cursor.
3. Try it
Ask Cursor for something Snyk can do. Scan code, dependencies, containers and IaC for vulnerabilities from the agent. Approve the first tool call and check the result before allowing write actions automatically.
- · Remote servers take a url; local servers take command and args.
- · Values can reference ${env:NAME} so secrets stay out of the file.
FAQ
- How do I add the Snyk MCP server to Cursor?
- Run: { …. Cursor prompts you to sign in the first time a remote OAuth server is used.
- Is this the official Snyk MCP server?
- Yes. It is published by Snyk as io.snyk/mcp in the official MCP registry.
- Does the Snyk MCP server need an API key?
- It runs locally from a package. See Snyk's docs for any credentials it needs.
Links
Snyk in other clients
More security & code quality for Cursor
Work at Snyk?
Feature Snyk across the directory and its category from $49/month.
Reviewed Oct 5, 2026. Command generated from the registry record and checked against Cursor's documented syntax.