Connect to the Bitsight MCP server

This article covers how to connect an AI client to the MCP server  For an overview, please see Bitsight MCP: Connect Your AI Assistant to Bitsight Data.

Credentials

The Bitsight MCP can be configured to access one or both of the following product sets:

  • Bitsight Security Posture Management, Continuous Monitoring, and Vendor Risk Monitoring (SPM, CM, and /or VRM)
  • Bitsight Threat Intelligence (CTI)

You can still connect to the MCP even if you only have access to one of the products.

Each product uses its own credentials:

Bitsight (SPM, CM, and /or VRM)

Required credentials: API Token
 

Bitsight Threat Intelligence (CTI)

Required credentials: API Client ID and Secret
 

You can configure the MCP for either product individually or for both, depending on the products available to your account. 

Authentication Methods

Users can authenticate using OAuth or API credentials.

OAuth

If your MCP client supports OAuth and does not allow custom HTTP Authorization headers, simply enter the MCP server URL and complete the web-based authentication flow when prompted. This method provides access to either product individually or for both.

API credentials 

If your MCP client supports configuring HTTP Authorization headers, this is the recommended authentication method. It provides the most reliable authentication and allows access to both Bitsight and CTI through a single MCP connection.

Bitsight API Token

Required for:

  • Bitsight (SPM, CM, and /or VRM) 
  • Combined authentication

If you use any of the following products, you'll need a Bitsight API token associated with your account or demo environment:

  • Security Posture Management (SPM)
  • Continuous Monitoring (CM)
  • Vendor Risk Monitoring (VRM)

To obtain your API token:

  1. Sign in to https://service.bitsighttech.com/.
  2. Click your profile name in the upper-right corner and select Account Settings > User API Token.
  3. If an API token already exists, copy it.
  4. If no token is available, click Generate.
  5. If you cannot generate a token, contact your Bitsight administrator to enable API access for your account.
CTI API Client ID and Secret

Required for:

  • Bitsight Threat Intelligence (CTI) only
  • Combined auth

If you use Threat Intelligence (CTI), you'll need an API Client ID and API Client Secret.

To generate these credentials:

  1. Go to https://developer.cybersixgill.com.
  2. Click BITSIGHT CTI.
  3. Sign in using your CTI credentials.
  4. Click LOGIN.
  5. Select GENERATE API CLIENT AND SECRET.
  6. Save both the API Client ID and API Client Secret in a secure location. You'll need them when configuring the MCP or making API requests.

To rotate your credentials later, select GENERATE NEW SECRET. Remember to update any applications that use the previous secret. If you do not see the GENERATE API CLIENT AND SECRET button and instead see an empty blue notification box, your account may not currently have API access. Contact your Bitsight administrator or account representative to request API permissions before generating credentials.

Configure your AI client

Quick Start

First, choose whether you want to authenticate with an API token or OAuth. Then give your AI assistant a link to this document and ask, “Can you help me set up the Bitsight MCP using [API token/OAuth]?” You can also follow the steps in this document yourself.

If the setup fails, ask the assistant, “Why did the setup fail?” Share the error log and/or your mcp.json file to help it troubleshoot.

CLI Tools - Simple mcp.json implementation

Generic Bitsight MCP 

A standard MCP configuration (mcp.json) containing the MCP URL and optional authentication headers is available below for use with most CLI and IDE agents. 

CLI and IDE agents can be configured with global configuration and per-folder/context/project configuration. 

Preferably, configure this MCP in a dedicated folder so the context is cleaner, with other MCP/skills/knowledge not affecting this test, nor this MCP affecting other projects.

This means the mcp.json will be either directly at the local folder, or inside a .<appname>/mcp.json folder (notice the initial dot). 

Support for OAuth-based authentication, which is mandatory for some agents, is available. 

MCP is hosted at https://mcp.bitsighttech.com/mcp

Choose the assistant you use. The setup process is essentially the same across all supported assistants: simply paste a small JSON configuration snippet into a config file and add your credentials.

If your assistant is not listed, the generic implementation will likely work. You can also ask your assistant to help configure the MCP by referencing one of the provided MCP configuration examples for a supported assistant.  The implementation will be the same for both Mac and Windows. 

Note: In case your settings files already exist, you should have something similar to:

{
  "mcpServers": {
      "other-mcp-server": {
      <other-mcp-configuration>
    }
  },
  <remaining-configuration>
}

The mcp.json file is common for all CLI tools:

Bitsight (SPM, CM, VRM) only

{ 
    "mcpServers": { 
        "bitsight-mcp": { 
            "url": "https://mcp.bitsighttech.com/mcp", 
            "type": "http",
            "headers": { 
                "X-Bitsight-API-Token": "<api-token>" 
            } 
        } 
    } 
} 

Bitsight CTI only

{ 
    "mcpServers": { 
        "bitsight-mcp": { 
            "url": "https://mcp.bitsighttech.com/mcp", 
            "type": "http",
            "headers": { 
                "X-CTI-Client-ID": "<your-cti-client-id>",
                "X-CTI-Client-Secret": "<your-cti-client-secret>"
            } 
        } 
    } 
} 

Combined (Bitsight SPM, CM, VRM, CTI)

{ 
    "mcpServers": { 
        "bitsight-mcp": { 
            "url": "https://mcp.bitsighttech.com/mcp",
            "type": "http",
            "headers": { 
                "X-Bitsight-API-Token": "<your-api-token>",
                "X-CTI-Client-ID": "<your-cti-client-id>",
                "X-CTI-Client-Secret": "<your-cti-client-secret>"
            } 
        } 
    } 
} 

Bitsight and/or CTI - OAuth

{ 
    "mcpServers": { 
        "bitsight-mcp": {
            "type": "http",
            "url": "https://mcp.bitsighttech.com/mcp"
        } 
    } 
} 
  • Click on the “Authenticate” option in your client
  • Your browser will open to a page where you can select “Bitsight”, “CTI”, or “Bitsight+CTI”
  • If Bitsight or combined is selected:
    • Your browser will go to the Bitsight login page (if not yet authenticated)
    • Your browser will go to a “MCP consent” page
  • If CTI or combined is selected:
    • Your browser will go to the CTI login page (if not yet authenticated)

Claude Desktop (Code)

  • Select the “Code” option at the top left corner
  • Start a new session and select a new and empty folder
  • Create a file named .mcp.json (note the initial dot) in that empty folder, with the contents above, adjusting the API Token
  • Ask Claude a question like “Using the Bitsight MCP, what is my user info at Bitsight?” 
  • Claude Desktop app (in “code” mode) should automatically load and understand the MCP configuration – if not, restart the app and create a new session.

Claude Code (CLI)

  • Create a file named .mcp.json (note the initial dot) in that empty folder, with the contents above, adjusting the API Token
  • Alternatively, use the claude mcp …  command to let Claude manage the mcp.json itself

Run this command to register bitsight-mcp in the project-scoped config, replacing the placeholder with your real API token:

Combined (Bitsight SPM, CM, VRM, and CTI)

claude mcp add --scope project bitsight-mcp --transport http 
https://mcp.bitsighttech.com/mcp --header "X-Bitsight-API-Token: <your-api-token>" 
--header "X-CTI-Client-ID: <your-cti-client-id>" --header "X-CTI-Client-Secret: 
<your-cti-client-secret>"

Bitsight (SPM, CM, VRM) only

claude mcp add --scope project bitsight-mcp --transport 
http https://mcp.bitsighttech.com/mcp --header "X-Bitsight-API-Token: <api-token>"

CTI Only

claude mcp add --scope project bitsight-mcp --transport 
http https://mcp.bitsighttech.com/mcp --header "X-CTI-Client-ID: <your-cti-client-id>"
--header "X-CTI-Client-Secret: <your-cti-client-secret>"

This writes to .mcp.json in the project root (project-scoped, not user-global). 

At some point, you may want a global MCP.  You can switch the --scope flag to user to make it global. Without it, it defaults to project-scope (which means it will only work in that project)

To remove or re-add (to switch MCPs):

claude mcp remove <mcp-name>

VSCode, Cursor, Kiro (IDE)

  • Open or create a file:
    • VSCode: ~/.vscode/mcp.json
    • Cursor: ~/.cursor/mcp.json
    • Kiro: ~/.kiro/settings/mcp.json
  • Paste the snippet above into the opened file, replacing the placeholder with your real credentials:
  • If the file has no HTTP Authorization headers, the IDE will ask to open the browser to authenticate. If the headers are to be added, cancel the pop-up and update the file. If the OAuth is intended, proceed with the web auth flow.
  • You will now see bitsight-mcp under Installed MCP Servers; it should be listed as connected with tools enabled.

 

  • Each IDE has its own MCP menus that can help configure the JSON file or help identify where the file is.
  • VSCode: Cmd-Shift-P (or Ctrl-Shift-P) to “Show and run commands”, select “MCP: Add server”, “HTTP”, enter the MCP URL and name
  • Cursor: Menu Cursor → Cursor Settings → Tools & MCPs → New MCP Server.

Web / Desktop Tools

Claude Desktop (Chat and Cowork)

  • Select the “Chat” option at the top left corner (or “Cowork”)
  • Select “Customize” in the left menu
  • Select “Connectors” in the updated left menu
  • In the middle view with the title “Connectors”, there is a “+” icon
  • This should show a pop-up with “Add custom connector”
    • If this option is not available, use the workaround in the next section.
      • Free accounts can only add a single custom connector
      • Enterprise accounts may have this option disabled by IT
  • In the custom connector view, add the name and URL
    • Name: bitsight-mcp
    • URL: https://mcp.bitsighttech.com/mcp
  • Click on the Authenticate button

Claude Desktop (no “Custom Connector” available) (Chat and Cowork)

  • Select the “Chat” option at the top left corner (or Cowork)
  • This configuration needs the npx command-line tool - install Node.js from Download Node.js
    • Installing Node requires local admin permissions
    • Alternatively, install npx via Homebrew if this is already installed
      • Install Node.js via Homebrew with:
      • bash
      • brew install node
      • To verify the installation worked:
      • bash
      • node --version
        npm --version
  • This works for macOS and should also work for Windows
  • Open Claude Desktop → Settings → Developer → Edit Config.
  • This will open the file explorer, choose claude_desktop_config.json, and open it with your preferred editor.
  • Paste the snippet below into the opened file, replacing the placeholder with your real credentials:

Bitsight (SPM, CM, VRM) only

{ 
    "mcpServers": { 
        "bitsight-mcp": {
            "command": "npx",
            "args": [
                "-y",
                "@ownid/mcp-remote",
                "https://mcp.bitsighttech.com/mcp",
                "--header",
                "X-Bitsight-API-Token: <your-api-token-here>"
            ] 
        } 
    } 
} 

CTI Only

{ 
    "mcpServers": { 
        "bitsight-mcp": {
            "command": "npx",
            "args": [
                "-y",
                "@ownid/mcp-remote",
                "https://mcp.bitsighttech.com/mcp",
                "--header",
                "X-CTI-Client-ID: <your-cti-client-id>",
                "--header",
                "X-CTI-Client-Secret: <your-cti-client-secret>"
            ] 
        } 
    } 
} 

Combined (Bitsight SPM, CM, VRM, and CTI)

{ 
    "mcpServers": { 
        "bitsight-mcp": {
            "command": "npx",
            "args": [
                "-y",
                "@ownid/mcp-remote",
                "https://mcp.bitsighttech.com/mcp",
                "--header",
                "X-Bitsight-API-Token: <your-api-token-here>",
                "--header",
                "X-CTI-Client-ID: <your-cti-client-id>",
                "--header",
                "X-CTI-Client-Secret: <your-cti-client-secret>"
            ] 
        } 
    } 
} 
  • Quit Claude Desktop fully and reopen it.
  • Start a new chat. Click the tools icon. You should see bitsight-mcp.

Microsoft Windows (via mcp-proxy)

MCP Proxy Set Up (Windows)

For Claude Desktop, here are the instructions to install mcp-proxy:

Installing mcp-proxy (via uv + Git)

1. Install uv: Run the following command in the terminal, then restart your terminal:

powershell -ExecutionPolicy ByPass -c "irm https://astral.sh/uv/install.ps1 | iex"

2. Install Git: Run the following command, then restart your terminal:

winget install --id Git.Git -e --source winget

3. Install mcp-proxy:

uv tool install git+https://github.com/sparfenyuk/mcp-proxy

4. Configure the path: Run where mcp-proxy to get the executable path. Copy this path into your configuration file to replace the <mcp-proxy-path> placeholder.

:warning: Important: In JSON configuration files, you must escape Windows backslashes by doubling them (e.g., change C:\Users\user\.local\bin\mcp-proxy.exe to C:\\Users\\user\\.local\\bin\\mcp-proxy.exe).

Combined (Bitsight + CTI)

{ 
    "mcpServers": { 
        "bitsight-mcp": { 
            "command": "<mcp-proxy-path>", 
            "args": [ 
                "--transport", 
                "streamablehttp", 
                "-H", 
                "X-Bitsight-API-Token", 
                "<your-api-token>",
                "-H", 
                "X-CTI-Client-ID", 
                "<your-cti-client-id>",
                "-H",
                "X-CTI-Client-Secret",
                "<your-cti-client-secret>",
                "https://mcp.bitsighttech.com/mcp" 
            ] 
        } 
    } 
}

Bitsight (SPM, CM, and/or VRM) only

{ 
    "mcpServers": { 
        "bitsight-mcp": { 
            "command": "<mcp-proxy-path>", 
            "args": [ 
                "--transport", 
                "streamablehttp", 
                "-H", 
                "X-Bitsight-API-Token", 
                "<your-api-token-here>", 
                "https://mcp.bitsighttech.com/mcp" 
            ] 
        } 
    } 
}

CTI Only

{ 
    "mcpServers": { 
        "bitsight-mcp": { 
            "command": "<mcp-proxy-path>", 
            "args": [ 
                "--transport", 
                "streamablehttp", 
                "-H", 
                "X-CTI-Client-ID", 
                "<your-cti-client-id>",
                "-H",
                "X-CTI-Client-Secret",
                "<your-cti-client-secret>",
                "https://mcp.bitsighttech.com/mcp" 
            ] 
        } 
    } 
}

ChatGPT

  • To set up an MCP server in ChatGPT, you need Developer mode/custom MCP apps enabled for your workspace. It’s currently for ChatGPT Business, Enterprise, and Edu workspaces, with admins/owners controlling availability. OpenAI Help Center
  • Click on your account (bottom left), “Settings”, “Apps”, “Advanced Settings”, and enable “Developer mode”

  • Go back to “Apps” and click on “Create app” next to “Advanced Settings”
  • Give it a name (Bitsight MCP), the Server URL (https://mcp.bitsighttech.com/mcp), and select either “OAuth” or “Access token / API key“
  • For “Access Token / API key”, select “Custom Header” and enter X-Bitsight-API-Token

  • Click “Create” and, if using an API Token, then paste your API Token in the next screen:

  • Confirm the MCP is connected and then close the settings dialogue:

Was this article helpful?
0 out of 0 found this helpful

Comments

0 comments

Please sign in to leave a comment.