SafeWeave runs inside your editor as an MCP server: your AI assistant can scan your project, explain findings and fix them in the same chat. Set your license key so you get every scanner your plan includes.
Prefer no install? Use Cloud MCP instead.
Before you start
- Node.js 20 or later.
- Your license key, from the Welcome to SafeWeave page or your email. Lost it? See Your account.
Claude Code
Run this in your project folder:
claude mcp add safeweave -e SAFEWEAVE_LICENSE_KEY=your-license-key -- npx -y safeweave-mcp
Restart Claude Code. For slash commands and a pre-push check as well, add the Claude plugin.
Cursor
- Open Settings → MCP, or create
.cursor/mcp.jsonin your project (or~/.cursor/mcp.jsonfor every project). - Add:
{
"mcpServers": {
"safeweave": {
"command": "npx",
"args": ["-y", "safeweave-mcp"],
"env": { "SAFEWEAVE_LICENSE_KEY": "your-license-key" }
}
}
}
- Restart Cursor.
VS Code
For GitHub Copilot in VS Code, create .vscode/mcp.json. Note the top-level key is servers, not mcpServers:
{
"servers": {
"safeweave": {
"command": "npx",
"args": ["-y", "safeweave-mcp"],
"env": { "SAFEWEAVE_LICENSE_KEY": "your-license-key" }
}
}
}
Then run Cmd+Shift+P → Reload Window (Ctrl+Shift+P on Windows and Linux).
Windsurf
Edit ~/.codeium/windsurf/mcp_config.json:
{
"mcpServers": {
"safeweave": {
"command": "npx",
"args": ["-y", "safeweave-mcp"],
"env": { "SAFEWEAVE_LICENSE_KEY": "your-license-key" }
}
}
}
Restart Windsurf.
Warp
- Open Warp Settings → MCP Servers → Add Server.
- Paste:
{
"safeweave": {
"command": "npx",
"args": ["-y", "safeweave-mcp"],
"env": { "SAFEWEAVE_LICENSE_KEY": "your-license-key" }
}
}
- Save and start the server.
Use it
Ask your assistant:
- "Scan this project for security vulnerabilities"
- "Fix the critical findings"
- "Check my dependencies for known vulnerabilities"
- "Switch to the SOC 2 compliance profile" (Cloud and Cloud Plus; see Compliance profiles)
Findings come back with severity, file and line. Ask the assistant to fix one and it pulls the fix guidance and scans again to check.
If something goes wrong
- The assistant doesn't see SafeWeave: restart your editor, and check the config file is where your editor expects it. Ask "What SafeWeave tools are available?" to confirm.
- "Unauthorized" or missing scanners: check the license key in the
envblock is your current one. - Scans are slow on a large project: ask the assistant to scan one file or folder first.