CASCO / MCP SERVER AVAILABLE NOW

MCP for AppSec workflows

No more security scavenger hunts.

Give your agent direct access to Casco findings and evidence, so developers can understand risk and move to a fix without leaving their workflow.

BUILT FOR TEAMS THAT BUILD WITH AGENTS
Archil
Blaxel
Crewai
Daytona
Gusto
Levelsfyi
Novig
Scout
Sixtyfour
Spreedly
Whop

See Casco MCP at work

Ask once. Casco brings the receipts.

01 / 03Prompt
REAL PRODUCT CAPTURECODEX / CASCO MCP
PROMPT

Type the request inside Codex.

CAPTURED IN CODEX / JULY 26, 2026
01Prompt

Ask inside your agent.

Ask for the Casco data you need without leaving your coding agent.

Casco tool selected
02Tools

Choose the next Casco call.

Move from applications to findings to the exact context needed for the task.

Read-only tools ready
03Context

Keep the source attached.

Casco context stays available in the agent that is already doing the work.

Casco context available

Your agent, now with Casco context

Choose where you build.

Each setup feels native to the agent you already use. The Casco connection stays secure, read-only, and scoped to your organization.

Browser-based OAuth No API key to paste Tenant-scoped access
CLI / STREAMABLE HTTP CLIENT SETUP

Casco inside Codex

Add Casco to Codex, complete the browser sign-in, and keep security context in the same workflow as the code.

Codex~/your-project

codex mcp add casco --url https://mcp.casco.com

Added global MCP server 'casco'.

cascoAuth: OAuth · Tools: 7
READY

Use Casco to list my applications.

COPY + RUNhttps://mcp.casco.com
codex mcp add casco --url https://mcp.casco.com
CODEX / SETUP

From command to connected.

Three steps. One browser sign-in.

  1. 01
    Run the command

    Add the hosted Casco server to Codex.

  2. 02
    Sign in

    Complete OAuth in the browser and choose your organization.

  3. 03
    Check the connection

    Open Codex and use /mcp to confirm Casco is ready.

READYREAD-ONLY / ORG-SCOPED
Ask Casco from Codex.
Use Casco to list my applications.

Evidence in. Judgment stays.

The agent gets context. Your team keeps the decision.

Ask for what the task needs.

Bring the relevant result and supporting context into the agent, not an undifferentiated data dump.

Keep the evidence attached.

Preserve the connection between the analysis and the security material that supports it.

Review before it ships.

Use the agent to assemble and draft. Keep consequential security decisions with the right owner.

Casco MCP FAQ

Everything your agent needs to know.

Direct answers about connecting Casco to compatible AI assistants, retrieving security context, and using it responsibly.

01

What problem does the Casco MCP server solve?

Casco MCP removes the manual handoff between a security finding and the agent used to understand or remediate it. Compatible assistants can request the relevant Casco result, evidence, and application context without asking a person to find, copy, and paste each piece.

02

How do I connect an AI assistant to Casco MCP?

Use the installation tabs on this page to add https://mcp.casco.com to Codex, Claude Code, or Cursor. Your client will open a browser-based OAuth flow where you sign in and select your Casco organization. No API key needs to be copied into the configuration.

03

Is Casco MCP read-only?

Yes. Casco MCP exposes an explicit read-only tool set. It can retrieve approved Casco findings, evidence, application context, risks, assets, and integrations, but it does not register mutation tools or grant write capabilities.

04

Which AI assistants and coding agents can use Casco MCP?

Casco MCP is designed for compatible MCP clients, including Codex, Claude Code, Cursor, and custom internal agent workflows.

05

What security context can an agent request from Casco?

A compatible agent can request Casco findings, supporting evidence, and relevant application context. It can use that material to explain business impact, plan remediation, answer security questions, and draft internal reports.

06

Does Casco MCP send every finding to the AI model?

No. The workflow retrieves the context requested for the task rather than pushing an undifferentiated export into the conversation. Access is resolved from the verified organization selected during sign-in, so the connection stays within the corresponding Casco tenant.

07

How does Casco MCP help developers remediate findings?

The agent can bring the finding, evidence, and application context into the same workflow used to inspect or change code. That gives the developer a clearer explanation of why the issue matters and what to fix without starting a separate research session.

08

Can Casco MCP create remediation briefs and internal reports?

Yes. A compatible agent can use source-linked Casco context to draft an impact summary, remediation brief, or internal report. The appropriate owner can review and edit the output before it is distributed.

09

Why use MCP instead of building a custom integration?

MCP is an open standard for connecting AI applications to external systems. Casco exposes one MCP endpoint so compatible clients can discover and request security context through a shared protocol instead of requiring a separate bespoke handoff for every assistant.

010

Does Casco MCP replace security engineers?

No. MCP gives the agents used by engineering and security teams better context. Security engineers still control access, validate consequential decisions, and decide how findings are remediated or communicated.

MCP for security work

Bring Casco into your agent.

Book a demo Explore Email Triage