Resources · Claude connector

Claude Conviso connectorWhat Claude can do in your Conviso account.

The Claude Conviso connector exposes 42 tools: 30 read, 8 write, 4 undocumented. Claude reads your vulnerabilities, projects, and scans, and can open tickets or launch tests. Below: what it sees, what it changes, and who stays in charge.

Verified Trustpilot reviews · AI, automation & growth agency

Overview

What changes for your security team

Conviso Platform pulls together a company's vulnerabilities, assets, and application security projects. With this desktop extension, you ask Claude instead of clicking from screen to screen: it reads the platform's data with your key, cross-checks results, and can also run certain operations the publisher has opened up.

Triage today's findings. get_top_vulnerabilities gives the count by severity, get_issues filters by project, asset, or status, and get_issue returns a finding's technical detail, code snippets included.

Report on the trend. get_mttr_over_time tracks mean time to resolution by severity, and get_overall_risk_score_history follows the overall risk score.

Act without leaving the chat. create_ticket opens a ticket, change_issue_status moves a finding to a new status, run_dast launches a dynamic test, and execute_mutation runs an operation the publisher allows.

What Claude won't do here: it only acts within what your key allows, and the publisher deliberately exposes just part of the platform's operations. The software supply chain and scans stay read-only. Nothing runs on its own either: no critical finding fires an alert from Claude. That kind of continuous watch belongs to an automation tool, a different job covered on the Integrations hub.

Vocabulary

The vocabulary in one minute

Five words before you install the Conviso extension.

Connector
The link you set up once between Claude and an account you already have, so Claude can work in it while it answers you.
Tool
A named capability the connector opens to Claude. Claude picks the ones it needs by itself; the directory sheet lists them by name.
Authorization
The access you hand Claude when you connect, here through your Conviso key. Given once per person, revocable whenever you want.
Approval
The confirmation Claude waits for before completing anything that changes an account, shown in the conversation at the right moment.
MCP
The shared standard behind connectors: it's what lets an assistant like Claude talk to an outside service.
Connect

Plug Conviso into Claude in three steps

  1. 01

    Find the extension

    In Claude Desktop, open Customize, then Connectors, and look for Conviso MCP Server in the list. On a Team or Enterprise workspace, an Owner or Primary Owner has to enable it for the organization first.

  2. 02

    Start the connection

    Click Connect on its row and follow the window that opens. If the extension ever stops responding, use Disconnect, then connect it again from that same row.

  3. 03

    Read what you open up

    Read the authorization screen before you confirm: that screen, not Claude, sets what the access covers. Here, the key you provide decides everything Claude will be able to read or change in Conviso.

Tools

The 42 tools of the Claude Conviso connector

Conviso MCP Server gives Claude 42 tools: 30 that read your account, 8 that change something in it, and 4 no official source describes.

Thirty tools that read, eight that change the platform, four nobody describes. Names stay exactly as Claude shows them.

  • 30 read
  • 8 write
  • 4 not documented

What Claude reads (30)

30 tools

Thirty tools that look up your Conviso data without touching it.

get_companies

Lists the companies your key can reach, with their IDs.

When it helps
you manage several subsidiaries in Conviso and Claude needs to know which one you mean.
Watch out
scope follows your key: an entity missing from the list stays out of reach.

Sourcegithub.com · October 1, 2026 ↗

get_company_info

Returns a company's details on the platform: its Conviso plan, its integrations, and its branding information.

When it helps
before a meeting with an internal client, you want to check which integrations are connected on their side.
Watch out
this is platform information, not a security audit of the company.

Sourcegithub.com · October 1, 2026 ↗

get_issue

Brings back a vulnerability's full technical record, including vulnerable code snippets and raw requests and responses. Claude can then explain the flaw and its fix.

When it helps
a developer asks why their API route got flagged and what they need to fix.
Watch out
Conviso warns that vulnerable code may come back when asked for analysis, so mind what you share.

Sourcegithub.com · October 1, 2026 ↗

get_issues

Lists a company's vulnerabilities, filterable by project, asset, severity, status, dates, and more. Claude starts there to sort or count.

When it helps
you want every high-severity finding still open on the payments app.
Watch out
without filters the list can run long, so say what you're after.

Sourcegithub.com · October 1, 2026 ↗

get_top_vulnerabilities

Gives a risk overview as a count of vulnerabilities by severity. It's the number people quote in steering meetings.

When it helps
the CISO wants to know, in one line, how many critical findings are still open.
Watch out
a count doesn't say which findings are involved; you need the list for that.

Sourcegithub.com · October 1, 2026 ↗

get_projects

Lists the platform's active security projects. Claude gets the big picture of the work currently underway across the company.

When it helps
you're preparing your weekly review and want every project still open.
Watch out
only active projects come back, per the publisher's description.

Sourcegithub.com · October 1, 2026 ↗

get_project

Returns a specific project from its Conviso ID. Claude can then detail its content or compare it with another.

When it helps
a project lead gives you an ID and you want to know where that work stands.
Watch out
you need the ID; without it, go through the project list first.

Sourcegithub.com · October 1, 2026 ↗

get_asset

Returns one specific platform asset from its ID. Claude gets its record to review it or tie it to findings.

When it helps
an alert mentions an asset by number and you want to know what it is.
Watch out
the ID is required; the asset list helps you find it.

Sourcegithub.com · October 1, 2026 ↗

get_assets

Lists the assets mapped in the platform. Claude gets the inventory of what Conviso watches.

When it helps
an auditor asks for the inventory of what your team's tests cover.
Watch out
an asset not mapped in Conviso won't show up.

Sourcegithub.com · October 1, 2026 ↗

create_project_url

Generates a direct link to a project on the Conviso platform. Despite its name, it only builds an address and touches nothing.

When it helps
you want to paste into a team message the exact link to the project Claude just mentioned.

Sourcegithub.com · October 1, 2026 ↗

create_issue_url

Builds the direct address of a vulnerability in Conviso, so you can point someone straight to it. No record is touched.

When it helps
you're flagging a finding to a developer and want to give them the link that lands right on it.
Watch out
the recipient needs their own rights to view the finding.

Sourcegithub.com · October 1, 2026 ↗

get_mttr_over_time

Tracks mean time to resolution for vulnerabilities over time, broken down by severity level.

When it helps
leadership wants to know whether the team fixes critical findings faster than last year.
Watch out
it's an average, so one very long case can drag the curve.

Sourcegithub.com · October 1, 2026 ↗

get_overall_risk_score_history

Traces a company's overall risk score history, with the current score and the gap from the previous period.

When it helps
you want to show in a meeting what a quarter of fixes did to overall risk.
Watch out
the README doesn't describe how the score is calculated.

Sourcegithub.com · October 1, 2026 ↗

get_tickets

Lists the support or bug tickets recorded in the platform. Claude can then sort or summarize them.

When it helps
you want to know which tickets are still waiting on the security team.
Watch out
the README doesn't detail the available filters.

Sourcegithub.com · October 1, 2026 ↗

get_ticket

Fetches a single ticket from the platform, so Claude can read it and summarize it for you.

When it helps
a colleague points you to a ticket and you want the gist without opening it.
Watch out
you need to know which ticket; the list helps you find it.

Sourcegithub.com · October 1, 2026 ↗

get_requirements

Browses the requirements and checklists defined in the platform. Claude sees the baseline your projects must meet.

When it helps
you're preparing an audit and want to reread the security requirements in force.
Watch out
these are the generic requirements, not their tracking project by project.

Sourcegithub.com · October 1, 2026 ↗

get_requirement

Pulls up a single requirement and its full content, so Claude can explain in plain words what it asks of your team.

When it helps
a developer doesn't understand a requirement cited in their project.
Watch out
the requirement's ID is needed.

Sourcegithub.com · October 1, 2026 ↗

get_project_requirements

Returns the requirements attached to a given project, with the ID needed to dig further. Conviso advises starting here when only the project is known.

When it helps
you want to know how far a project has come on its checklist.
Watch out
it's the required step to reach a requirement's activities inside a project.

Sourcegithub.com · October 1, 2026 ↗

get_applications

Lists the applications registered in the platform and their assets. Claude gets the map of your application portfolio.

When it helps
you need to say how many applications Conviso tracks.
Watch out
an application not declared in the platform won't appear.

Sourcegithub.com · October 1, 2026 ↗

get_application

Brings up a single application and the assets attached to it in Conviso, so Claude can sketch its profile for you.

When it helps
a product team asks what Conviso knows about their app.
Watch out
you need to know which one; the application list helps.

Sourcegithub.com · October 1, 2026 ↗

get_scan_histories

Traces the execution history of scans. Claude sees when analyses ran and what they produced.

When it helps
you want to confirm that the scan planned before release actually ran.
Watch out
Conviso keeps scans read-only, so this tool doesn't relaunch one.

Sourcegithub.com · October 1, 2026 ↗

get_asset_scans_count

Counts scans per asset to measure coverage. Claude spots assets that are rarely or never analyzed.

When it helps
you're hunting for assets that have dodged scans for too long.
Watch out
a count says nothing about the quality of each scan.

Sourcegithub.com · October 1, 2026 ↗

get_sbom_components

Surfaces a company's components and dependencies from its software bill of materials, or SBOM. Claude can spot one specific library.

When it helps
a flaw hits an open source library and you want to know whether your team uses it.
Watch out
the supply chain stays read-only, per the publisher.

Sourcegithub.com · October 1, 2026 ↗

get_pentest_artifacts

Pulls up the list of artifacts from penetration tests held in Conviso, with their scope, for a first overview.

When it helps
you want to see which penetration tests were prepared this month.
Watch out
the README doesn't describe this list's filters.

Sourcegithub.com · October 1, 2026 ↗

get_pentest_artifact

Retrieves a single penetration test artifact and its scope, so Claude can sum it up for you.

When it helps
someone asks what exactly a past penetration test covered.
Watch out
you need to know which one; the artifact list helps.

Sourcegithub.com · October 1, 2026 ↗

get_pentest_execution

Returns the results of a penetration test run. Claude can summarize what was found.

When it helps
last night's test finished and you want its conclusions.
Watch out
the README doesn't say what format or level of detail these results come in.

Sourcegithub.com · October 1, 2026 ↗

get_threat_model_artifacts

Takes stock of the company's threat modeling artifacts, version by version, so Claude knows what has already been modeled.

When it helps
you want to know which applications already have a threat model.
Watch out
only artifacts already created in Conviso show up.

Sourcegithub.com · October 1, 2026 ↗

get_threat_model_artifact

Opens one specific threat modeling artifact and its versions for Claude, so it can walk you through the key points.

When it helps
an architecture review is coming and you want to reread the current threat model.
Watch out
several versions can coexist, so say which one you mean.

Sourcegithub.com · October 1, 2026 ↗

list_mutations

Searches the catalog of operations Conviso allows through this connector. It's the first step of the discover, describe, execute path.

When it helps
Claude needs to find the operation that matches what you asked for.
Watch out
it only searches: nothing goes out until execute_mutation is called.

Sourcegithub.com · October 1, 2026 ↗

describe_mutation

Describes one allowed operation from that catalog: its required fields, permitted values, and what it returns. Claude prepares an accurate call this way.

When it helps
before handling a finding, Claude checks which values are accepted.
Watch out
the description triggers nothing; it only sets up the next step.

Sourcegithub.com · October 1, 2026 ↗

What Claude changes (8)

8 tools

Eight tools that create, modify, or launch something in Conviso. No source describes a confirmation step of their own, so the general rule below applies.

execute_mutation

Approval: see the rule

Runs one of the write operations Conviso allows: create, update, or delete findings, projects, assets, requirements, or applications, or launch a test.

What Claude asks for
Conviso flags this tool as destructive; on Claude's side, the general approval rule applies, since no confirmation of its own is described.
When it helps
after review, you want to close a batch of findings as false positives.
Watch out
Conviso advises confirming intent before any destructive or bulk operation.

Sourcegithub.com · October 1, 2026 ↗

change_issue_status

Approval: see the rule

Moves a vulnerability from one status to another. It's a publisher shortcut for a common write.

What Claude asks for
no source describes a prompt specific to this tool, so the general approval rule covers it.
When it helps
after a fix, you want Conviso to reflect the finding's real state.

Sourceclaude.com · October 1, 2026 ↗

create_source_code_vulnerability

Approval: see the rule

Records a new source code vulnerability in Conviso, without going through the generic path.

What Claude asks for
for confirmation, nothing is published beyond the general approval rule.
When it helps
a manual code review turned up a problem and you want it on record.

Sourceclaude.com · October 1, 2026 ↗

create_project

Approval: see the rule

Creates a new security project in the platform.

What Claude asks for
the publisher describes no specific confirmation, so the general approval rule holds.
When it helps
a new application is arriving and needs its own security project.
Watch out
per the README, a project opened by mistake later goes away through a removal operation.

Sourceclaude.com · October 1, 2026 ↗

create_asset

Approval: see the rule

Adds an asset to Conviso's map.

What Claude asks for
on confirmation, the sheet points back to the general approval rule.
When it helps
a new service goes live and needs to be tracked.
Watch out
a badly named asset muddies the whole team's searches afterward.

Sourceclaude.com · October 1, 2026 ↗

create_ticket

Approval: see the rule

Opens a ticket in the Conviso platform, right from the conversation.

What Claude asks for
no rule of its own is published; the general approval rule is what applies.
When it helps
you want to flag a blocker to the Conviso team without leaving Claude.
Watch out
the README only describes creating tickets, not updating them.

Sourceclaude.com · October 1, 2026 ↗

run_dast

Approval: see the rule

Launches a dynamic application security test, or DAST, which probes the running application for flaws.

What Claude asks for
with no published rule for this tool, the general approval rule applies.
When it helps
you want a fresh test right before a release.

Sourceclaude.com · October 1, 2026 ↗

trigger_pentest

Approval: see the rule

Triggers a penetration test run by Conviso's AI.

What Claude asks for
the sources say nothing specific, so the general approval rule takes over.
When it helps
you want to test a new feature exposed to the internet.
Watch out
scope is prepared beforehand, so review the matching artifact.

Sourceclaude.com · October 1, 2026 ↗

Undocumented (4)

4 tools

The directory sheet publishes these four names, and no official source says what they do. We won't guess from the name.

get_project_types

This name sits on the directory sheet, and that's all anyone knows. Neither Conviso's README nor any Claude page describes it, so no source documents what it returns and this page won't say more.

Watch out
whatever it does, the general approval rule covers it.

get_project_statuses

Same silence here: listed on the sheet, missing from the publisher's tool table. No official source lets us say what it returns, and we won't guess from its name.

Watch out
the general approval rule covers it like the others.

get_today_date

The directory displays this name, but Conviso's tool table skips it and no official page explains it. Nothing published today says what it's for, what it returns, or when Claude would call it.

Watch out
the general approval rule applies here too.

create_pentest_artifact

One more name the directory displays without any explanation: it appears neither in the README's table nor among the shortcuts named on the sheet. No source documents its behavior, so this page stops there.

Watch out
the general approval rule holds for it.
Approvals

What Claude asks before it acts

By default, Claude stops and asks for your go-ahead before any action it takes on an account for you. With eight tools that write to Conviso, that's the rule that matters.

On a Team or Enterprise workspace, owners decide whether a member can let certain actions through without being asked again. They can also cap what a connector does for the whole organization, for example keeping reads and blocking writes. On Conviso's side, every write requires the company ID so the platform can check its write policy. And Claude works with your key's permissions, nothing more, whatever you ask.

Plans

Which plans it's available on

None of the 819 sheets in the official directory shows availability by plan. A connector-by-connector answer isn't published anywhere.

The general rule is sourced: desktop extensions install on Claude Desktop, open to all of its users, while remote connectors run on Claude, Cowork, Claude Desktop, and mobile. On Team and Enterprise, an Owner or Primary Owner enables them for the organization. For the current status, check the Conviso MCP Server sheet in the official directory.

Limits

Where Conviso stops

A connector isn't an automation. Claude calls these tools while it answers you: no new finding sets anything off by itself.

Only the publisher documents this connector, in its repository README: neither Claude's help center nor Anthropic's documentation covers it. Writes are deliberately limited to the client-facing operations Conviso picked, with the rest of the platform left unexposed. The directory badge isn't a security audit, and Anthropic can't vouch for how a publisher's tools behave. The same reading grid applies to other sheets, such as the Claude affinity connector page.

Two official sources disagree

Is the README's tool list the same as the directory's?

  • Claude directory sheet ↗October 202642 tools, including write shortcuts such as change_issue_status, create_project, run_dast, and trigger_pentest.
  • Publisher's repository README ↗October 2026The table describes two tools missing from the sheet and routes every write through execute_mutation, without detailing the shortcuts.

What this page followsThe two lists don't match, and neither is dated older than the other. This page follows the directory sheet, which describes the installable extension, and flags as undocumented the names nobody explains. The version installed on your machine is what counts.

Need help

Need help connecting Conviso MCP Server to Claude?

A person reads every message.

FAQ

Claude Conviso connector FAQ

01What can Claude do with the Conviso connector?
Claude can query your Conviso application security platform and launch certain operations in it. Thirty tools only read: companies, findings and their technical detail, projects, assets, tickets, requirements, applications, scan history, software components, penetration tests, and threat models, plus mean time to fix and the risk score. Eight tools write, from opening a ticket to launching a dynamic security test against a running app. Four names on the sheet aren't described by any source.
02Can Claude create, change, or delete things in Conviso?
Yes, eight tools act on the platform. Shortcuts open a ticket, a project, or an asset, log a source code finding, move its status, or launch a dynamic test or an AI penetration test. The execute_mutation engine goes further: per the README, it can create, update, or delete findings and projects, and adjust requirements, applications, and threat models. Everything stays bounded by your key's permissions, and the publisher keeps some areas read-only.
03Does Claude ask before it acts in Conviso?
By default, Claude stops and asks for your go-ahead before any action it takes on an account for you. No source describes a confirmation specific to a Conviso tool, so this general rule is what applies. The publisher does flag execute_mutation as destructive and advises confirming intent before any destructive or bulk operation. On Team and Enterprise, owners decide whether a member can let some actions through without a new prompt.
04Which plans is the Conviso connector available on?
No official source publishes plan availability connector by connector, and none of the 819 directory sheets shows it. The general rule is that desktop extensions install on Claude Desktop for all of its users, while remote connectors are open on Claude, Cowork, Claude Desktop, and mobile. On Team and Enterprise, an Owner or Primary Owner enables them first. Only the directory sheet shows the current status for your own account, so start there.
05Does Claude see all the data in my Conviso platform?
No, Claude works with the permissions of the API key you provide at install, and nothing more. Whatever your key can't reach, Claude can't reach either. Keep in mind, though, that a finding's detail can bring vulnerable code snippets into the conversation. On the organization side, an owner of a Team or Enterprise workspace can disable the extension or block writing for everyone, and a member can't lift that setting alone.
06Why can't Claude update a finding in Conviso?
Several safeguards can get in the way. Every write requires the company ID, which Conviso uses to check its write policy: without it, the operation stops. Next, the API key itself needs the right permissions, because the platform's normal authorization still applies. Finally, not every platform operation is exposed: the publisher deliberately limits writes to a list of client-facing operations, and keeps scans and software dependencies read-only no matter what.
07Claude or an automation tool for Conviso?
They don't do the same job. With Claude, you query Conviso and act on demand, in the flow of a conversation: a question about risk, a ticket, a test launched. After that, nothing happens until you type again. The connector doesn't watch for new findings and doesn't notify anyone. For an automatic alert or an event-driven process, that's an automation tool's role. To analyze and decide, the connector does the work.