Getting Started

Connect Claude Code, Cursor, Claude Desktop, or ChatGPT to SpyCloud Investigations in five steps.

🚧

Early Access

SpyCloud Investigations MCP is in Early Access. Setup steps and supported clients may change before general availability.

Before you begin

You need:

  1. A SpyCloud Investigations API entitlement. Your organization must have an active SpyCloud Investigations API subscription.
  2. A SpyCloud Console user account with the Operator or Admin role.
  3. Approval to use your MCP client. Confirm your organization permits the client you plan to use with SpyCloud data.
  4. Outbound HTTPS from your machine to the SpyCloud MCP endpoint.
  5. Node.js, for Claude Desktop only.

Supported clients

ClientAuthenticationHow you connect
Claude CodeOAuthOne CLI command
CursorOAuthmcp.json entry
Claude DesktopOAuth through the mcp-remote bridgeConfig file entry; requires Node.js
ChatGPTOAuthCustom connector in Developer Mode; requires a ChatGPT plan that supports custom connectors

Other MCP clients may work if they support remote HTTP transport and OAuth 2.1 with Dynamic Client Registration (DCR) or Client ID Metadata Documents (CIMD). They are not formally supported during Early Access.

📘

Using an AI gateway?

SpyCloud accepts sign-in only from approved client redirect URLs. If your organization routes AI traffic through a gateway, contact Product Success before you connect so the gateway's callback URL can be reviewed.

Step 1: Get onboarded

Investigations API users who have access to the new SpyCloud Console can use the Investigations MCP Early Access interface. If your SpyCloud account has not yet been migrated to the new Console, that migration must happen before your account can be enabled for MCP access.

MCP access uses your user authentication. To set this up, your SpyCloud administrator (or SpyCloud support) creates a user account for every MCP user. Each MCP user then assigns the Investigations API key that their MCP calls will use.

Your scopes determine which tools you can use:

ScopeGrants access to
mcp:breachBreach data tools
mcp:infostealerInfostealer log tools
mcp:idlinkIdentity graph tools
mcp:statsDomain and exposure analytics tools

Step 2: Add SpyCloud to your client

The Early Access endpoint is:

https://mcp.spycloud.io/mcp

If Product Success gives you a different endpoint for your environment, use that one.

Claude Code

Run:

claude mcp add inv-mcp --transport http https://mcp.spycloud.io/mcp

Cursor

Add the server to .cursor/mcp.json in your project, or to ~/.cursor/mcp.json to make it available in every project:

{
  "mcpServers": {
    "inv-mcp": {
      "url": "https://mcp.spycloud.io/mcp",
      "headers": {}
    }
  }
}

Open Cursor's MCP settings to confirm the server is listed. If it doesn't appear, restart Cursor.

Claude Desktop

Claude Desktop connects to SpyCloud through the mcp-remote bridge, which runs locally through npx and requires Node.js.

Open the configuration file from Settings > Developer > Edit Config, or directly:

  • macOS: ~/Library/Application Support/Claude/claude_desktop_config.json
  • Windows: %APPDATA%\Claude\claude_desktop_config.json

Add:

{
  "mcpServers": {
    "inv-mcp": {
      "command": "npx",
      "args": ["-y", "mcp-remote", "https://mcp.spycloud.io/mcp"]
    }
  }
}

Save the file, then fully quit and relaunch Claude Desktop.

ChatGPT

ChatGPT connects to remote MCP servers as custom connectors, which require Developer Mode and a ChatGPT plan that supports custom connectors. On Business, Enterprise, and Edu workspaces, an admin may need to enable Developer Mode or approve the connector first.

  1. In ChatGPT, open Settings and go to Apps & Connectors.
  2. Under Advanced settings, turn on Developer Mode.
  3. Create a new connector with these values:
    • Name: SpyCloud Investigations
    • MCP server URL: https://mcp.spycloud.io/mcp
    • Authentication: OAuth
  4. Save the connector, then connect it and complete sign-in.
  5. Start a new chat and enable the SpyCloud connector from the tools menu.

OpenAI updates these menu labels from time to time. If a step doesn't match what you see, check OpenAI's help center for the current path.

Step 3: Sign in

  • Claude Code: run /mcp, select inv-mcp, and choose to authenticate.
  • Cursor and Claude Desktop: your first SpyCloud tool call starts sign-in.
  • ChatGPT: sign-in starts when you connect the connector.

Your browser opens the SpyCloud sign-in page. Sign in with your SpyCloud Console credentials. If your organization uses single sign-on for the Console, you'll sign in through your identity provider. When sign-in completes, return to your client.

Access tokens are short-lived and refresh tokens aren't issued by default, so expect to sign in again periodically.

Step 4: Verify your connection

  1. Confirm the SpyCloud server shows as connected in your client.
  2. Ask your assistant: "Which SpyCloud tools do you have access to?"
  3. Confirm the tools match the datasets you were onboarded for.
  4. Run a test: "Show exposure statistics for example.com over the last 12 weeks."

Each test call draws one query from your Investigations API key. If sign-in succeeds but no SpyCloud tools appear, your user may not have dataset scopes yet. See Troubleshooting.

Step 5: Run your first investigation

Ask in plain language. Name the asset, and say what you want back. For example:

  • "What credentials are exposed for [email protected]? Group the results by source and severity."
  • "Show weekly exposure for example.com over the last 12 weeks and tell me whether it's trending up or down."
  • "For infected machine ID <id>, list every log, then show which collections each log contains and how large they are."
  • "Run an IDLink pivot on [email protected] at depth 1 and summarize the most strongly connected identities."

Your assistant selects the tools, runs them, and responds. Keep asking follow-up questions to pivot into related data.

Next steps


Did this page help you?