Snyk · VS Code (GitHub Copilot)

Add the Snyk MCP server to VS Code (GitHub Copilot)

Scan code, dependencies, containers and IaC for vulnerabilities from the agent.

Official serverLocalSecurity & code quality

1. Add the server

Run in your terminal

code --add-mcp '{"name":"snyk","command":"npx","args":["-y","snyk","mcp","-t","stdio"]}'

2. Sign in

VS Code opens the sign-in flow when Copilot first calls a remote OAuth server. Snyk runs locally; set any credentials Snyk asks for before starting VS Code (GitHub Copilot).

3. Try it

Ask VS Code (GitHub Copilot) for something Snyk can do. Scan code, dependencies, containers and IaC for vulnerabilities from the agent. Approve the first tool call and check the result before allowing write actions automatically.

  • · mcp.json uses a top-level servers key, not mcpServers.
  • · code --add-mcp installs a server into your user profile from the terminal.

FAQ

How do I add the Snyk MCP server to VS Code (GitHub Copilot)?
Run: code --add-mcp '{"name":"snyk","command":"npx","args":["-y","snyk","mcp","-t","stdio"]}'. VS Code opens the sign-in flow when Copilot first calls a remote OAuth server.
Is this the official Snyk MCP server?
Yes. It is published by Snyk as io.snyk/mcp in the official MCP registry.
Does the Snyk MCP server need an API key?
It runs locally from a package. See Snyk's docs for any credentials it needs.

Links

Snyk in other clients

More security & code quality for VS Code (GitHub Copilot)

Work at Snyk?

Feature Snyk across the directory and its category from $49/month.

Feature this server

Reviewed Oct 5, 2026. Command generated from the registry record and checked against VS Code (GitHub Copilot)'s documented syntax.