Skip to main content
Corridor’s MCP server provides tools that enable AI coding assistants to directly interact with your security data. When you use Claude Code, Cursor, or other MCP-compatible tools, the AI assistant can access and manage your Corridor findings and guardrails.

Available tools

Owner and Admin can use every tool listed above. Writes need custom guardrails on your plan. Standard Users can use analyzePlan only. They can also use getFinding and updateFindingState on development findings from their own Corridor scans. They cannot list, create, edit, restore, or archive guardrails.

Guardrail versioning through MCP

Guardrail versioning is in private beta. Corridor must enable it for your team.
Versioning is available in the Corridor app and through these MCP tools. Use them when a Scheduled Agent or an assistant changes a guardrail and you want to see what changed or go back:
  • getGuardrailVersions — list version history, newest first. Read-only.
  • restoreGuardrailVersion — copy an earlier version onto the live guardrail. This writes a new current version. History stays.
restoreGuardrailVersion needs custom guardrails on your plan.

Update and archive through MCP

Updating and archiving guardrails through MCP is a separate private beta feature. Corridor must enable it for your team.
These tools let an AI assistant edit or archive a custom guardrail. That is the assistant path for the same kinds of edits a Scheduled Agent can make when it tightens coverage:
  • updateGuardrail — edit name, overview, or text. Available when versioning is on.
  • archiveGuardrail — archive a guardrail so it stops running. Needs archive enabled as well.
There is no MCP tool to un-archive a guardrail. Un-archive it on the dashboard. See Guardrails for the dashboard archive behavior.

analyzePlan

The analyzePlan tool is the core tool that AI coding assistants call before generating code. It takes a description of what you plan to implement and returns relevant security context from your project’s guardrails and context documents. This helps prevent vulnerabilities by giving the AI assistant project-specific security guidance at the point of code generation. Parameters: Example:
The AI assistant uses this security context to write safer code from the start, following your team’s specific guardrails.

Example conversation

Your AI assistant can also:
  • “Add a new API endpoint” → calls analyzePlan for security context before writing code
  • “Show me details about finding X” → calls getFinding
  • “Mark this finding as a false positive” → calls updateFindingState
  • “What guardrails should I follow?” → calls getGuardrails
  • “Create a guardrail for SQL injection prevention” → calls createGuardrail
  • “Show me this guardrail’s versions” → calls getGuardrailVersions
  • “Restore this guardrail to an earlier version” → calls restoreGuardrailVersion
  • “Update this guardrail” → calls updateGuardrail
  • “Archive this guardrail” → calls archiveGuardrail

Requirements

  • Corridor extension installed and authenticated
  • MCP enabled for your team (team setting)
  • IDE Extension Support entitlement on your plan
  • User must be a member of a team that owns the project

Security notes

  • Tools validate team membership before granting access
  • Uniform 404 responses prevent information leakage
  • Admin operations reject API tokens (require user auth)

Next steps

Findings

Track and remediate security issues

Guardrails

Configure security guardrails