Bitsight MCP: Connect Your AI Assistant to Bitsight Data

What is the Bitsight MCP?

MCP, short for Model Context Protocol, is an open standard that lets AI assistants connect directly to outside tools and data sources instead of relying only on what a person types into the conversation.

The Bitsight MCP is Bitsight's own MCP server. It gives an MCP-compatible AI assistant direct access to your organization's Bitsight data and the full Bitsight API, so you can ask questions and get answers in plain language instead of building a custom integration or writing API calls by hand.

What can you do with it?

Once connected, your AI assistant can:

  • Find an API operation:  Describe what you want in plain language ("get our vendor's risk rating," "list open alerts from this week") and the assistant locates the matching Bitsight API operation across the full catalog of endpoints, spanning ratings, findings, alerts, third-party risk, threat intelligence, and more.
  • Read Bitsight data: Pull company ratings, findings, alerts, vendor portfolios, and threat intelligence data into the conversation.
  • Required confirmation: Anything that changes data such as creating an alert, updating a vendor record, or other similar actions, always shows you the exact action and its parameters first and waits for your go-ahead before running. You can approve a single action, or extend standing approval for a set period of time.
  • Search the Bitsight Knowledge Base: The assistant can look up relevant help articles without leaving the conversation.

What do I need before I connect?

Prerequisites for using the Bitsight MCP include:

  • An MCP-compatible AI assistant that supports a remote MCP server.
  • Access to at least one supported Bitsight product: Security Posture Management (SPM), Continuous Monitoring (CM), Vendor Risk Monitoring (VRM), or Threat Intelligence (CTI).
  • An authentication method supported by your AI assistant:
    • OAuth: Sign in through your browser when prompted. You can select Bitsight, CTI, or both, depending on your access.
    • API credentials: Use a Bitsight user API token for SPM, CM, or VRM. For CTI, use a CTI API client ID and client secret. To access both product groups through one connection, provide both sets of credentials.

Your account permissions determine which data and tools are available through the MCP. You can connect even if you have access to only one product group.

How do I connect an AI assistant to the Bitsight MCP?

  1. Add a remote MCP server in your assistant’s connector or MCP settings.
  2. Enter https://mcp.bitsighttech.com/mcp as the server URL.
  3. Choose an authentication method; exact steps depend on your assistant.
    • OAuth: Sign in through your browser when your assistant prompts you.
    • API credentials: Add the API credential headers for the products you use.
  4. Confirm that bitsight-mcp is connected, then ask a question about a product you can access.
  5. Ask a question.

The exact steps to connect depend on your assistant. For client-specific steps and configuration examples, see the Connect to the Bitsight MCP server.

Example prompts to try

  • "What's the current Bitsight Rating for [company name]?"
  • "Show me open alerts from the last 7 days."
  • "List the vendors in my portfolio with a rating drop this month."
  • "Search the Knowledge Base for how to generate a company API token."

Data access, permissions, and safety

  • The Bitsight MCP only has access to the data your Bitsight account and API token already permit. It doesn't expand what you can see or do.
  • Read-only requests (looking things up) run without extra prompts.
  • Any request that would create, change, or delete data always pauses for your explicit confirmation first, showing you exactly what will run before it runs.
  • You control how long an approval lasts: a single action or a longer trust window for one endpoint or all endpoints.

Frequently asked questions

Does this replace the Bitsight API?

No. The Bitsight MCP is a natural-language layer on top of the same Bitsight API you already have access to. Anything available through the API is reachable through the MCP connection, using your existing permissions.

Will my AI assistant do anything without me asking first?
No. Read requests run automatically, but any action that modifies your Bitsight data requires your explicit approval before it executes.
What data can the assistant see?
Only what your account's role and API token already permit. The MCP connection doesn't grant any additional access.
Was this article helpful?
0 out of 0 found this helpful

Comments

0 comments

Please sign in to leave a comment.