What is the Bitsight MCP?
MCP, short for Model Context Protocol, is an open standard that lets AI assistants connect directly to outside tools and data sources instead of relying only on what a person types into the conversation.
The Bitsight MCP is Bitsight's own MCP server. It gives an MCP-compatible AI assistant direct access to your organization's Bitsight data and the full Bitsight API, so you can ask questions and get answers in plain language instead of building a custom integration or writing API calls by hand.
What can you do with it?
Once connected, your AI assistant can:
- Find an API operation: Describe what you want in plain language ("get our vendor's risk rating," "list open alerts from this week") and the assistant locates the matching Bitsight API operation across the full catalog of endpoints, spanning ratings, findings, alerts, third-party risk, threat intelligence, and more.
- Read Bitsight data: Pull company ratings, findings, alerts, vendor portfolios, and threat intelligence data into the conversation.
- Required confirmation: Anything that changes data such as creating an alert, updating a vendor record, or other similar actions, always shows you the exact action and its parameters first and waits for your go-ahead before running. You can approve a single action, or extend standing approval for a set period of time.
- Search the Bitsight Knowledge Base: The assistant can look up relevant help articles without leaving the conversation.
What do I need before I connect?
Prerequisites for using the Bitsight MCP include:
- An MCP-compatible AI assistant that supports a remote MCP server.
- Access to at least one supported Bitsight product: Security Posture Management (SPM), Continuous Monitoring (CM), Vendor Risk Monitoring (VRM), or Threat Intelligence (CTI).
- An authentication method supported by your AI assistant:
- OAuth: Sign in through your browser when prompted. You can select Bitsight, CTI, or both, depending on your access.
- API credentials: Use a Bitsight user API token for SPM, CM, or VRM. For CTI, use a CTI API client ID and client secret. To access both product groups through one connection, provide both sets of credentials.
Your account permissions determine which data and tools are available through the MCP. You can connect even if you have access to only one product group.
How do I connect an AI assistant to the Bitsight MCP?
- Add a remote MCP server in your assistant’s connector or MCP settings.
- Enter
https://mcp.bitsighttech.com/mcpas the server URL. - Choose an authentication method; exact steps depend on your assistant.
- OAuth: Sign in through your browser when your assistant prompts you.
- API credentials: Add the API credential headers for the products you use.
- Confirm that bitsight-mcp is connected, then ask a question about a product you can access.
- Ask a question.
The exact steps to connect depend on your assistant. For client-specific steps and configuration examples, see the Connect to the Bitsight MCP server.
Example prompts to try
- "What's the current Bitsight Rating for [company name]?"
- "Show me open alerts from the last 7 days."
- "List the vendors in my portfolio with a rating drop this month."
- "Search the Knowledge Base for how to generate a company API token."
Data access, permissions, and safety
- The Bitsight MCP only has access to the data your Bitsight account and API token already permit. It doesn't expand what you can see or do.
- Read-only requests (looking things up) run without extra prompts.
- Any request that would create, change, or delete data always pauses for your explicit confirmation first, showing you exactly what will run before it runs.
- You control how long an approval lasts: a single action or a longer trust window for one endpoint or all endpoints.
Frequently asked questions
No. The Bitsight MCP is a natural-language layer on top of the same Bitsight API you already have access to. Anything available through the API is reachable through the MCP connection, using your existing permissions.
Comments
Please sign in to leave a comment.