Getting Started
Connect Claude Code, Cursor, Claude Desktop, or ChatGPT to SpyCloud Investigations in five steps.
Early AccessSpyCloud Investigations MCP is in Early Access. Setup steps and supported clients may change before general availability.
Before you begin
You need:
- A SpyCloud Investigations API entitlement. Your organization must have an active SpyCloud Investigations API subscription.
- A SpyCloud Console user account with the Operator or Admin role.
- Approval to use your MCP client. Confirm your organization permits the client you plan to use with SpyCloud data.
- Outbound HTTPS from your machine to the SpyCloud MCP endpoint.
- Node.js, for Claude Desktop only.
Supported clients
| Client | Authentication | How you connect |
|---|---|---|
| Claude Code | OAuth | One CLI command |
| Cursor | OAuth | mcp.json entry |
| Claude Desktop | OAuth through the mcp-remote bridge | Config file entry; requires Node.js |
| ChatGPT | OAuth | Custom connector in Developer Mode; requires a ChatGPT plan that supports custom connectors |
Other MCP clients may work if they support remote HTTP transport and OAuth 2.1 with Dynamic Client Registration (DCR) or Client ID Metadata Documents (CIMD). They are not formally supported during Early Access.
Using an AI gateway?SpyCloud accepts sign-in only from approved client redirect URLs. If your organization routes AI traffic through a gateway, contact Product Success before you connect so the gateway's callback URL can be reviewed.
Step 1: Get onboarded
Investigations API users who have access to the new SpyCloud Console can use the Investigations MCP Early Access interface. If your SpyCloud account has not yet been migrated to the new Console, that migration must happen before your account can be enabled for MCP access.
MCP access uses your user authentication. To set this up, your SpyCloud administrator (or SpyCloud support) creates a user account for every MCP user. Each MCP user then assigns the Investigations API key that their MCP calls will use.
Your scopes determine which tools you can use:
| Scope | Grants access to |
|---|---|
mcp:breach | Breach data tools |
mcp:infostealer | Infostealer log tools |
mcp:idlink | Identity graph tools |
mcp:stats | Domain and exposure analytics tools |
Step 2: Add SpyCloud to your client
The Early Access endpoint is:
https://mcp.spycloud.io/mcpIf Product Success gives you a different endpoint for your environment, use that one.
Claude Code
Run:
claude mcp add inv-mcp --transport http https://mcp.spycloud.io/mcpCursor
Add the server to .cursor/mcp.json in your project, or to ~/.cursor/mcp.json to make it available in every project:
{
"mcpServers": {
"inv-mcp": {
"url": "https://mcp.spycloud.io/mcp",
"headers": {}
}
}
}Open Cursor's MCP settings to confirm the server is listed. If it doesn't appear, restart Cursor.
Claude Desktop
Claude Desktop connects to SpyCloud through the mcp-remote bridge, which runs locally through npx and requires Node.js.
Open the configuration file from Settings > Developer > Edit Config, or directly:
- macOS:
~/Library/Application Support/Claude/claude_desktop_config.json - Windows:
%APPDATA%\Claude\claude_desktop_config.json
Add:
{
"mcpServers": {
"inv-mcp": {
"command": "npx",
"args": ["-y", "mcp-remote", "https://mcp.spycloud.io/mcp"]
}
}
}Save the file, then fully quit and relaunch Claude Desktop.
ChatGPT
ChatGPT connects to remote MCP servers as custom connectors, which require Developer Mode and a ChatGPT plan that supports custom connectors. On Business, Enterprise, and Edu workspaces, an admin may need to enable Developer Mode or approve the connector first.
- In ChatGPT, open Settings and go to Apps & Connectors.
- Under Advanced settings, turn on Developer Mode.
- Create a new connector with these values:
- Name: SpyCloud Investigations
- MCP server URL:
https://mcp.spycloud.io/mcp - Authentication: OAuth
- Save the connector, then connect it and complete sign-in.
- Start a new chat and enable the SpyCloud connector from the tools menu.
OpenAI updates these menu labels from time to time. If a step doesn't match what you see, check OpenAI's help center for the current path.
Step 3: Sign in
- Claude Code: run
/mcp, selectinv-mcp, and choose to authenticate. - Cursor and Claude Desktop: your first SpyCloud tool call starts sign-in.
- ChatGPT: sign-in starts when you connect the connector.
Your browser opens the SpyCloud sign-in page. Sign in with your SpyCloud Console credentials. If your organization uses single sign-on for the Console, you'll sign in through your identity provider. When sign-in completes, return to your client.
Access tokens are short-lived and refresh tokens aren't issued by default, so expect to sign in again periodically.
Step 4: Verify your connection
- Confirm the SpyCloud server shows as connected in your client.
- Ask your assistant: "Which SpyCloud tools do you have access to?"
- Confirm the tools match the datasets you were onboarded for.
- Run a test: "Show exposure statistics for example.com over the last 12 weeks."
Each test call draws one query from your Investigations API key. If sign-in succeeds but no SpyCloud tools appear, your user may not have dataset scopes yet. See Troubleshooting.
Step 5: Run your first investigation
Ask in plain language. Name the asset, and say what you want back. For example:
- "What credentials are exposed for [email protected]? Group the results by source and severity."
- "Show weekly exposure for example.com over the last 12 weeks and tell me whether it's trending up or down."
- "For infected machine ID
<id>, list every log, then show which collections each log contains and how large they are." - "Run an IDLink pivot on [email protected] at depth 1 and summarize the most strongly connected identities."
Your assistant selects the tools, runs them, and responds. Keep asking follow-up questions to pivot into related data.
Next steps
Updated about 2 hours ago