Attestd MCP Server
by attestd-ioio.github.attestd-io/attestd-mcpv0.3.1
CVE checks, supply chain signals, live catalog, and CVE detail for MCP clients (infra, PyPI, npm).
context tax
queued
security
queued
cold start
queued
freshness
Active1d ago
Install Attestd MCP server
Install in Claude Code
claude mcp add attestd -e ATTESTD_API_KEY='<attestd-api-key>' -- npx -y @attestd/mcpInstall in Cursor
{
"mcpServers": {
"attestd": {
"command": "npx",
"args": [
"-y",
"@attestd/mcp"
],
"env": {
"ATTESTD_API_KEY": "<attestd-api-key>"
}
}
}
}Add to ~/.cursor/mcp.json (global) or .cursor/mcp.json (project).
Install in Claude Desktop
{
"mcpServers": {
"attestd": {
"command": "npx",
"args": [
"-y",
"@attestd/mcp"
],
"env": {
"ATTESTD_API_KEY": "<attestd-api-key>"
}
}
}
}Settings → Developer → Edit Config (claude_desktop_config.json), then restart.
Install in VS Code
{
"servers": {
"attestd": {
"type": "stdio",
"command": "npx",
"args": [
"-y",
"@attestd/mcp"
],
"env": {
"ATTESTD_API_KEY": "<attestd-api-key>"
}
}
}
}Add to .vscode/mcp.json in your workspace.
Install in Windsurf
{
"mcpServers": {
"attestd": {
"command": "npx",
"args": [
"-y",
"@attestd/mcp"
],
"env": {
"ATTESTD_API_KEY": "<attestd-api-key>"
}
}
}
}Add to ~/.codeium/windsurf/mcp_config.json.
Configuration
| Variable | Required | Secret | Description |
|---|---|---|---|
| ATTESTD_API_KEY | — | yes | Attestd API key (atst_...). Required for check_package_vulnerability, check_batch_vulnerabilities, get_cve_details, and live list_covered_products. Get one at https://api.attestd.io/portal |
| ATTESTD_BASE_URL | — | — | Optional API base URL override. Defaults to https://api.attestd.io |
Freshness
Active — last maintenance signal 1d ago. The newest of the signals below sets the band.
Last commit (default branch)
2026-10-08 · 1d ago · GitHub
Latest release
no data · GitHub
Package published
no data · npm/PyPI
Registry entry updated
2026-09-26 · 13d ago · official registry · v0.3.1
FAQ
›How do I install the Attestd MCP server in Claude Code?
Run: claude mcp add attestd -e ATTESTD_API_KEY='<attestd-api-key>' -- npx -y @attestd/mcp. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.
›Does Attestd require an API key?
Yes. It expects ATTESTD_API_KEY, of which 1 is a secret.
›Can I use Attestd as a remote (hosted) MCP server?
No hosted endpoint is published; it runs locally over stdio.
›Is Attestd in the official MCP registry?
Yes, as io.github.attestd-io/attestd-mcp.
Alternatives to Attestd
Other security MCP servers.