This article covers how to connect an AI client to the MCP server For an overview, please see Bitsight MCP: Connect Your AI Assistant to Bitsight Data.
Credentials
The Bitsight MCP can be configured to access one or both of the following product sets:
- Bitsight Security Posture Management, Continuous Monitoring, and Vendor Risk Monitoring (SPM, CM, and /or VRM)
- Bitsight Threat Intelligence (CTI)
You can still connect to the MCP even if you only have access to one of the products.
Each product uses its own credentials:
- Bitsight (SPM, CM, and /or VRM)
Required credentials: API Token
- Bitsight Threat Intelligence (CTI)
Required credentials: API Client ID and Secret
You can configure the MCP for either product individually or for both, depending on the products available to your account.
Authentication Methods
Users can authenticate using OAuth or API credentials.
OAuth
If your MCP client supports OAuth and does not allow custom HTTP Authorization headers, simply enter the MCP server URL and complete the web-based authentication flow when prompted. This method provides access to either product individually or for both.
API credentials
If your MCP client supports configuring HTTP Authorization headers, this is the recommended authentication method. It provides the most reliable authentication and allows access to both Bitsight and CTI through a single MCP connection.
Bitsight API Token
Required for:
- Bitsight (SPM, CM, and /or VRM)
- Combined authentication
If you use any of the following products, you'll need a Bitsight API token associated with your account or demo environment:
- Security Posture Management (SPM)
- Continuous Monitoring (CM)
- Vendor Risk Monitoring (VRM)
To obtain your API token:
- Sign in to https://service.bitsighttech.com/.
- Click your profile name in the upper-right corner and select Account Settings > User API Token.
- Or navigate directly to: https://service.bitsighttech.com/app/account/
- If an API token already exists, copy it.
- If no token is available, click Generate.
- If you cannot generate a token, contact your Bitsight administrator to enable API access for your account.
CTI API Client ID and Secret
Required for:
- Bitsight Threat Intelligence (CTI) only
- Combined auth
If you use Threat Intelligence (CTI), you'll need an API Client ID and API Client Secret.
To generate these credentials:
- Go to https://developer.cybersixgill.com.
- Click BITSIGHT CTI.
- Sign in using your CTI credentials.
- Click LOGIN.
- Select GENERATE API CLIENT AND SECRET.
- Save both the API Client ID and API Client Secret in a secure location. You'll need them when configuring the MCP or making API requests.
To rotate your credentials later, select GENERATE NEW SECRET. Remember to update any applications that use the previous secret. If you do not see the GENERATE API CLIENT AND SECRET button and instead see an empty blue notification box, your account may not currently have API access. Contact your Bitsight administrator or account representative to request API permissions before generating credentials.
Configure your AI client
Quick Start
First, choose whether you want to authenticate with an API token or OAuth. Then give your AI assistant a link to this document and ask, “Can you help me set up the Bitsight MCP using [API token/OAuth]?” You can also follow the steps in this document yourself.
If the setup fails, ask the assistant, “Why did the setup fail?” Share the error log and/or your mcp.json file to help it troubleshoot.
CLI Tools - Simple mcp.json implementation
Generic Bitsight MCP
A standard MCP configuration (mcp.json) containing the MCP URL and optional authentication headers is available below for use with most CLI and IDE agents.
CLI and IDE agents can be configured with global configuration and per-folder/context/project configuration.
Preferably, configure this MCP in a dedicated folder so the context is cleaner, with other MCP/skills/knowledge not affecting this test, nor this MCP affecting other projects.
This means the mcp.json will be either directly at the local folder, or inside a .<appname>/mcp.json folder (notice the initial dot).
Support for OAuth-based authentication, which is mandatory for some agents, is available.
MCP is hosted at https://mcp.bitsighttech.com/mcp
Choose the assistant you use. The setup process is essentially the same across all supported assistants: simply paste a small JSON configuration snippet into a config file and add your credentials.
If your assistant is not listed, the generic implementation will likely work. You can also ask your assistant to help configure the MCP by referencing one of the provided MCP configuration examples for a supported assistant. The implementation will be the same for both Mac and Windows.
Note: In case your settings files already exist, you should have something similar to:
{
"mcpServers": {
"other-mcp-server": {
<other-mcp-configuration>
}
},
<remaining-configuration>
}The mcp.json file is common for all CLI tools:
Bitsight (SPM, CM, VRM) only
{
"mcpServers": {
"bitsight-mcp": {
"url": "https://mcp.bitsighttech.com/mcp",
"type": "http",
"headers": {
"X-Bitsight-API-Token": "<api-token>"
}
}
}
} Bitsight CTI only
{
"mcpServers": {
"bitsight-mcp": {
"url": "https://mcp.bitsighttech.com/mcp",
"type": "http",
"headers": {
"X-CTI-Client-ID": "<your-cti-client-id>",
"X-CTI-Client-Secret": "<your-cti-client-secret>"
}
}
}
} Combined (Bitsight SPM, CM, VRM, CTI)
{
"mcpServers": {
"bitsight-mcp": {
"url": "https://mcp.bitsighttech.com/mcp",
"type": "http",
"headers": {
"X-Bitsight-API-Token": "<your-api-token>",
"X-CTI-Client-ID": "<your-cti-client-id>",
"X-CTI-Client-Secret": "<your-cti-client-secret>"
}
}
}
} Bitsight and/or CTI - OAuth
{
"mcpServers": {
"bitsight-mcp": {
"type": "http",
"url": "https://mcp.bitsighttech.com/mcp"
}
}
} - Click on the “Authenticate” option in your client
- Your browser will open to a page where you can select “Bitsight”, “CTI”, or “Bitsight+CTI”
- If Bitsight or combined is selected:
- Your browser will go to the Bitsight login page (if not yet authenticated)
- Your browser will go to a “MCP consent” page
- If CTI or combined is selected:
- Your browser will go to the CTI login page (if not yet authenticated)
Claude Desktop (Code)
- Select the “Code” option at the top left corner
- Start a new session and select a new and empty folder
- Create a file named
.mcp.json (note the initial dot) in that empty folder, with the contents above, adjusting the API Token
- Ask Claude a question like “Using the Bitsight MCP, what is my user info at Bitsight?”
- Claude Desktop app (in “code” mode) should automatically load and understand the MCP configuration – if not, restart the app and create a new session.
Claude Code (CLI)
- Create a file named
.mcp.json (note the initial dot) in that empty folder, with the contents above, adjusting the API Token
- Alternatively, use the
claude mcp … command to let Claude manage the mcp.json itself
Run this command to register bitsight-mcp in the project-scoped config, replacing the placeholder with your real API token:
Combined (Bitsight SPM, CM, VRM, and CTI)
claude mcp add --scope project bitsight-mcp --transport http
https://mcp.bitsighttech.com/mcp --header "X-Bitsight-API-Token: <your-api-token>"
--header "X-CTI-Client-ID: <your-cti-client-id>" --header "X-CTI-Client-Secret:
<your-cti-client-secret>"Bitsight (SPM, CM, VRM) only
claude mcp add --scope project bitsight-mcp --transport
http https://mcp.bitsighttech.com/mcp --header "X-Bitsight-API-Token: <api-token>"CTI Only
claude mcp add --scope project bitsight-mcp --transport
http https://mcp.bitsighttech.com/mcp --header "X-CTI-Client-ID: <your-cti-client-id>"
--header "X-CTI-Client-Secret: <your-cti-client-secret>"This writes to .mcp.json in the project root (project-scoped, not user-global).
At some point, you may want a global MCP. You can switch the --scope flag to user to make it global. Without it, it defaults to project-scope (which means it will only work in that project)
To remove or re-add (to switch MCPs):
claude mcp remove <mcp-name>VSCode, Cursor, Kiro (IDE)
- Open or create a file:
- VSCode:
~/.vscode/mcp.json - Cursor:
~/.cursor/mcp.json - Kiro:
~/.kiro/settings/mcp.json
- VSCode:
- Paste the snippet above into the opened file, replacing the placeholder with your real credentials:
- If the file has no HTTP Authorization headers, the IDE will ask to open the browser to authenticate. If the headers are to be added, cancel the pop-up and update the file. If the OAuth is intended, proceed with the web auth flow.
- You will now see
bitsight-mcpunder Installed MCP Servers; it should be listed as connected with tools enabled.
- Each IDE has its own MCP menus that can help configure the JSON file or help identify where the file is.
- VSCode: Cmd-Shift-P (or Ctrl-Shift-P) to “Show and run commands”, select “MCP: Add server”, “HTTP”, enter the MCP URL and name
- Cursor: Menu Cursor → Cursor Settings → Tools & MCPs → New MCP Server.
Web / Desktop Tools
Claude Desktop (Chat and Cowork)
- Select the “Chat” option at the top left corner (or “Cowork”)
- Select “Customize” in the left menu
- Select “Connectors” in the updated left menu
- In the middle view with the title “Connectors”, there is a “+” icon
- This should show a pop-up with “Add custom connector”
- If this option is not available, use the workaround in the next section.
- Free accounts can only add a single custom connector
- Enterprise accounts may have this option disabled by IT
- If this option is not available, use the workaround in the next section.
- In the custom connector view, add the name and URL
- Name:
bitsight-mcp - URL:
https://mcp.bitsighttech.com/mcp
- Name:
- Click on the Authenticate button
Claude Desktop (no “Custom Connector” available) (Chat and Cowork)
- Select the “Chat” option at the top left corner (or Cowork)
- This configuration needs the
npxcommand-line tool - install Node.js from Download Node.js- Installing Node requires local admin permissions
- Alternatively, install
npxvia Homebrew if this is already installed- Install Node.js via Homebrew with:
- bash
brew install node- To verify the installation worked:
- bash
node --version npm --version
- This works for macOS and should also work for Windows
- Open Claude Desktop → Settings → Developer → Edit Config.
- This will open the file explorer, choose claude_desktop_config.json, and open it with your preferred editor.
- Paste the snippet below into the opened file, replacing the placeholder with your real credentials:
Bitsight (SPM, CM, VRM) only
{
"mcpServers": {
"bitsight-mcp": {
"command": "npx",
"args": [
"-y",
"@ownid/mcp-remote",
"https://mcp.bitsighttech.com/mcp",
"--header",
"X-Bitsight-API-Token: <your-api-token-here>"
]
}
}
} CTI Only
{
"mcpServers": {
"bitsight-mcp": {
"command": "npx",
"args": [
"-y",
"@ownid/mcp-remote",
"https://mcp.bitsighttech.com/mcp",
"--header",
"X-CTI-Client-ID: <your-cti-client-id>",
"--header",
"X-CTI-Client-Secret: <your-cti-client-secret>"
]
}
}
} Combined (Bitsight SPM, CM, VRM, and CTI)
{
"mcpServers": {
"bitsight-mcp": {
"command": "npx",
"args": [
"-y",
"@ownid/mcp-remote",
"https://mcp.bitsighttech.com/mcp",
"--header",
"X-Bitsight-API-Token: <your-api-token-here>",
"--header",
"X-CTI-Client-ID: <your-cti-client-id>",
"--header",
"X-CTI-Client-Secret: <your-cti-client-secret>"
]
}
}
} - Quit Claude Desktop fully and reopen it.
- Start a new chat. Click the tools icon. You should see
bitsight-mcp.
Microsoft Windows (via mcp-proxy)
MCP Proxy Set Up (Windows)
For Claude Desktop, here are the instructions to install mcp-proxy:
Installing mcp-proxy (via uv + Git)
1. Install uv: Run the following command in the terminal, then restart your terminal:
powershell -ExecutionPolicy ByPass -c "irm https://astral.sh/uv/install.ps1 | iex"
2. Install Git: Run the following command, then restart your terminal:
winget install --id Git.Git -e --source winget
3. Install mcp-proxy:
uv tool install git+https://github.com/sparfenyuk/mcp-proxy
4. Configure the path: Run where mcp-proxy to get the executable path. Copy this path into your configuration file to replace the <mcp-proxy-path> placeholder.
Important: In JSON configuration files, you must escape Windows backslashes by doubling them (e.g., change C:\Users\user\.local\bin\mcp-proxy.exe to C:\\Users\\user\\.local\\bin\\mcp-proxy.exe).
Combined (Bitsight + CTI)
{
"mcpServers": {
"bitsight-mcp": {
"command": "<mcp-proxy-path>",
"args": [
"--transport",
"streamablehttp",
"-H",
"X-Bitsight-API-Token",
"<your-api-token>",
"-H",
"X-CTI-Client-ID",
"<your-cti-client-id>",
"-H",
"X-CTI-Client-Secret",
"<your-cti-client-secret>",
"https://mcp.bitsighttech.com/mcp"
]
}
}
}Bitsight (SPM, CM, and/or VRM) only
{
"mcpServers": {
"bitsight-mcp": {
"command": "<mcp-proxy-path>",
"args": [
"--transport",
"streamablehttp",
"-H",
"X-Bitsight-API-Token",
"<your-api-token-here>",
"https://mcp.bitsighttech.com/mcp"
]
}
}
}CTI Only
{
"mcpServers": {
"bitsight-mcp": {
"command": "<mcp-proxy-path>",
"args": [
"--transport",
"streamablehttp",
"-H",
"X-CTI-Client-ID",
"<your-cti-client-id>",
"-H",
"X-CTI-Client-Secret",
"<your-cti-client-secret>",
"https://mcp.bitsighttech.com/mcp"
]
}
}
}ChatGPT
- To set up an MCP server in ChatGPT, you need Developer mode/custom MCP apps enabled for your workspace. It’s currently for ChatGPT Business, Enterprise, and Edu workspaces, with admins/owners controlling availability. OpenAI Help Center
- Click on your account (bottom left), “Settings”, “Apps”, “Advanced Settings”, and enable “Developer mode”
- Go back to “Apps” and click on “Create app” next to “Advanced Settings”
- Give it a name (
Bitsight MCP), the Server URL (https://mcp.bitsighttech.com/mcp), and select either “OAuth” or “Access token / API key“ - For “Access Token / API key”, select “Custom Header” and enter
X-Bitsight-API-Token
- Click “Create” and, if using an API Token, then paste your API Token in the next screen:
- Confirm the MCP is connected and then close the settings dialogue:
Comments
Please sign in to leave a comment.