Secobserve MCP Server
by nh4ttruongio.github.nh4ttruong/secobserve-mcpv1.0.0
SecObserve vulnerability and license management: triage observations, manage products and rules, import scan reports and SBOMs, run scans and generate VEX.
context tax
queued
security
queued
cold start
queued
freshness
Active14d ago
Install Secobserve MCP server
Install in Claude Code
claude mcp add secobserve -e SECOBSERVE_BASE_URL='<secobserve-base-url>' -e SECOBSERVE_API_TOKEN='<secobserve-api-token>' -- uvx secobserve-mcpInstall in Cursor
{
"mcpServers": {
"secobserve": {
"command": "uvx",
"args": [
"secobserve-mcp"
],
"env": {
"SECOBSERVE_BASE_URL": "<secobserve-base-url>",
"SECOBSERVE_API_TOKEN": "<secobserve-api-token>"
}
}
}
}Add to ~/.cursor/mcp.json (global) or .cursor/mcp.json (project).
Install in Claude Desktop
{
"mcpServers": {
"secobserve": {
"command": "uvx",
"args": [
"secobserve-mcp"
],
"env": {
"SECOBSERVE_BASE_URL": "<secobserve-base-url>",
"SECOBSERVE_API_TOKEN": "<secobserve-api-token>"
}
}
}
}Settings → Developer → Edit Config (claude_desktop_config.json), then restart.
Install in VS Code
{
"servers": {
"secobserve": {
"type": "stdio",
"command": "uvx",
"args": [
"secobserve-mcp"
],
"env": {
"SECOBSERVE_BASE_URL": "<secobserve-base-url>",
"SECOBSERVE_API_TOKEN": "<secobserve-api-token>"
}
}
}
}Add to .vscode/mcp.json in your workspace.
Install in Windsurf
{
"mcpServers": {
"secobserve": {
"command": "uvx",
"args": [
"secobserve-mcp"
],
"env": {
"SECOBSERVE_BASE_URL": "<secobserve-base-url>",
"SECOBSERVE_API_TOKEN": "<secobserve-api-token>"
}
}
}
}Add to ~/.codeium/windsurf/mcp_config.json.
Configuration
| Variable | Required | Secret | Description |
|---|---|---|---|
| SECOBSERVE_BASE_URL | yes | — | SecObserve base URL without /api, e.g. https://secobserve.example.com |
| SECOBSERVE_API_TOKEN | yes | yes | SecObserve user or product API token |
| SECOBSERVE_READ_ONLY | — | — | Set to true to refuse every write operation |
| SECOBSERVE_ALLOW_DELETE | — | — | Set to true to enable the delete tool; deletion cascades and is irreversible |
Freshness
Active — last maintenance signal 14d ago. The newest of the signals below sets the band.
Last commit (default branch)
2026-09-25 · 14d ago · GitHub
Latest release
2026-09-21 · 18d ago · GitHub · v1.0.0
Package published
no data · npm/PyPI
Registry entry updated
2026-09-21 · 18d ago · official registry · v1.0.0
FAQ
›How do I install the Secobserve MCP server in Claude Code?
Run: claude mcp add secobserve -e SECOBSERVE_BASE_URL='<secobserve-base-url>' -e SECOBSERVE_API_TOKEN='<secobserve-api-token>' -- uvx secobserve-mcp. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.
›Does Secobserve require an API key?
Yes. It expects SECOBSERVE_BASE_URL, SECOBSERVE_API_TOKEN, of which 1 is a secret.
›Can I use Secobserve as a remote (hosted) MCP server?
No hosted endpoint is published; it runs locally over stdio.
›Is Secobserve in the official MCP registry?
Yes, as io.github.nh4ttruong/secobserve-mcp.
Alternatives to Secobserve
Other security MCP servers.