Ask inside your agent.
Ask for the Casco data you need without leaving your coding agent.
Casco tool selectedMCP for AppSec workflows
Give your agent direct access to Casco findings and evidence, so developers can understand risk and move to a fix without leaving their workflow.
See Casco MCP at work
Type the request inside Codex.
CAPTURED IN CODEX / JULY 26, 2026Ask for the Casco data you need without leaving your coding agent.
Casco tool selectedMove from applications to findings to the exact context needed for the task.
Read-only tools readyCasco context stays available in the agent that is already doing the work.
Casco context availableYour agent, now with Casco context
Each setup feels native to the agent you already use. The Casco connection stays secure, read-only, and scoped to your organization.
Add Casco to Codex, complete the browser sign-in, and keep security context in the same workflow as the code.
› codex mcp add casco --url https://mcp.casco.com
Added global MCP server 'casco'.
› Use Casco to list my applications.
codex mcp add casco --url https://mcp.casco.comThree steps. One browser sign-in.
Add the hosted Casco server to Codex.
Complete OAuth in the browser and choose your organization.
Open Codex and use /mcp to confirm Casco is ready.
Use Casco to list my applications.Evidence in. Judgment stays.
Bring the relevant result and supporting context into the agent, not an undifferentiated data dump.
Preserve the connection between the analysis and the security material that supports it.
Use the agent to assemble and draft. Keep consequential security decisions with the right owner.
Casco MCP FAQ
Direct answers about connecting Casco to compatible AI assistants, retrieving security context, and using it responsibly.
Casco MCP removes the manual handoff between a security finding and the agent used to understand or remediate it. Compatible assistants can request the relevant Casco result, evidence, and application context without asking a person to find, copy, and paste each piece.
Use the installation tabs on this page to add https://mcp.casco.com to Codex, Claude Code, or Cursor. Your client will open a browser-based OAuth flow where you sign in and select your Casco organization. No API key needs to be copied into the configuration.
Yes. Casco MCP exposes an explicit read-only tool set. It can retrieve approved Casco findings, evidence, application context, risks, assets, and integrations, but it does not register mutation tools or grant write capabilities.
Casco MCP is designed for compatible MCP clients, including Codex, Claude Code, Cursor, and custom internal agent workflows.
A compatible agent can request Casco findings, supporting evidence, and relevant application context. It can use that material to explain business impact, plan remediation, answer security questions, and draft internal reports.
No. The workflow retrieves the context requested for the task rather than pushing an undifferentiated export into the conversation. Access is resolved from the verified organization selected during sign-in, so the connection stays within the corresponding Casco tenant.
The agent can bring the finding, evidence, and application context into the same workflow used to inspect or change code. That gives the developer a clearer explanation of why the issue matters and what to fix without starting a separate research session.
Yes. A compatible agent can use source-linked Casco context to draft an impact summary, remediation brief, or internal report. The appropriate owner can review and edit the output before it is distributed.
MCP is an open standard for connecting AI applications to external systems. Casco exposes one MCP endpoint so compatible clients can discover and request security context through a shared protocol instead of requiring a separate bespoke handoff for every assistant.
No. MCP gives the agents used by engineering and security teams better context. Security engineers still control access, validate consequential decisions, and decide how findings are remediated or communicated.
MCP for security work