Developer platform
MCP server
A thin, local MCP server that speaks to your AI coding agent on one side and the Goosy scan engine on the other — no scanning logic runs on your machine.
goosy-mcp is a local stdio process your MCP host (Claude Code, Claude Desktop, Cursor) spawns — no separate service to run. Every tool call becomes an authenticated request to Goosy's API; the package itself holds no rules and makes no model calls.
Install
Or skip the install step entirely and let your MCP host fetch it on demand with npx — both work with the same config below.
Add it to your MCP host
Already ran npm i goosy-mcp? Point command at the installed binary directly instead of going through npx — for a global install (npm i -g goosy-mcp), that's just "command": "goosy-mcp", "args": [].
Authenticate
AUTH_REQUIRED error carrying a verification URL and a short code, written for the agent to relay to you directly in the conversation — approve it once in your browser and the agent's retry just works. Concurrent tool calls share the same pending device code rather than issuing a confusing second one.The six tools
goosy_generate_fix hands back a patch as text — this server never writes to your filesystem, commits, or opens a pull request. There is no create_pr, apply_patch, or dismiss_finding tool: an agent acting in a loop must not be able to mutate your repository or silently suppress a security finding unattended. This is enforced mechanically in the package's own test suite, not just documented.Security model
Two invariants worth knowing as a user: a failed scan is always reported as failed, never as “clean” — the difference between “your code is clean” and “we didn't look” is the point of the tool — and every excluded file is counted and reported back in the tool response's warnings, not silently dropped.
Token storage
Tokens live at ${XDG_CONFIG_HOME:-~/.config}/goosy/config.json (%APPDATA%\goosy\config.json on Windows), mode 0600, keyed by API base so production and a local stack can coexist — the same path the CLI uses, so a goosy login from the terminal may already satisfy this. Refresh on expiry is transparent and serialized by a file lock so two processes can't race a rotation.
Already have the CLI installed?
The Goosy CLI also has a built-in goosy mcp subcommand that starts an MCP server in-process, reusing whatever session goosy login already created. Reach for goosy-mcp (this page) when you just want MCP without installing the CLI binary first.
- Package: npmjs.com/package/goosy-mcp