- Home
- Resources
- Integrations
- Conviso MCP Server
Claude Conviso connectorWhat Claude can do in your Conviso account.
The Claude Conviso connector exposes 42 tools: 30 read, 8 write, 4 undocumented. Claude reads your vulnerabilities, projects, and scans, and can open tickets or launch tests. Below: what it sees, what it changes, and who stays in charge.
Verified Trustpilot reviews · AI, automation & growth agency
What changes for your security team
Conviso Platform pulls together a company's vulnerabilities, assets, and application security projects. With this desktop extension, you ask Claude instead of clicking from screen to screen: it reads the platform's data with your key, cross-checks results, and can also run certain operations the publisher has opened up.
Triage today's findings. get_top_vulnerabilities gives the count by severity, get_issues filters by project, asset, or status, and get_issue returns a finding's technical detail, code snippets included.
Report on the trend. get_mttr_over_time tracks mean time to resolution by severity, and get_overall_risk_score_history follows the overall risk score.
Act without leaving the chat. create_ticket opens a ticket, change_issue_status moves a finding to a new status, run_dast launches a dynamic test, and execute_mutation runs an operation the publisher allows.
What Claude won't do here: it only acts within what your key allows, and the publisher deliberately exposes just part of the platform's operations. The software supply chain and scans stay read-only. Nothing runs on its own either: no critical finding fires an alert from Claude. That kind of continuous watch belongs to an automation tool, a different job covered on the Integrations hub.
The vocabulary in one minute
Five words before you install the Conviso extension.
- Connector
- The link you set up once between Claude and an account you already have, so Claude can work in it while it answers you.
- Tool
- A named capability the connector opens to Claude. Claude picks the ones it needs by itself; the directory sheet lists them by name.
- Authorization
- The access you hand Claude when you connect, here through your Conviso key. Given once per person, revocable whenever you want.
- Approval
- The confirmation Claude waits for before completing anything that changes an account, shown in the conversation at the right moment.
- MCP
- The shared standard behind connectors: it's what lets an assistant like Claude talk to an outside service.
Plug Conviso into Claude in three steps
- 01
Find the extension
In Claude Desktop, open Customize, then Connectors, and look for Conviso MCP Server in the list. On a Team or Enterprise workspace, an Owner or Primary Owner has to enable it for the organization first.
- 02
Start the connection
Click Connect on its row and follow the window that opens. If the extension ever stops responding, use Disconnect, then connect it again from that same row.
- 03
Read what you open up
Read the authorization screen before you confirm: that screen, not Claude, sets what the access covers. Here, the key you provide decides everything Claude will be able to read or change in Conviso.
The 42 tools of the Claude Conviso connector
Conviso MCP Server gives Claude 42 tools: 30 that read your account, 8 that change something in it, and 4 no official source describes.
Thirty tools that read, eight that change the platform, four nobody describes. Names stay exactly as Claude shows them.
- 30 read
- 8 write
- 4 not documented
Tools index
- get_companies
- get_company_info
- get_issue
- get_issues
- get_top_vulnerabilities
- get_projects
- get_project
- get_asset
- get_assets
- create_project_url
- create_issue_url
- get_mttr_over_time
- get_overall_risk_score_history
- get_tickets
- get_ticket
- get_requirements
- get_requirement
- get_project_requirements
- get_applications
- get_application
- get_scan_histories
- get_asset_scans_count
- get_sbom_components
- get_pentest_artifacts
- get_pentest_artifact
- get_pentest_execution
- get_threat_model_artifacts
- get_threat_model_artifact
- list_mutations
- describe_mutation
What Claude reads (30)
30 toolsThirty tools that look up your Conviso data without touching it.
get_companies
Lists the companies your key can reach, with their IDs.
get_company_info
Returns a company's details on the platform: its Conviso plan, its integrations, and its branding information.
get_issue
Brings back a vulnerability's full technical record, including vulnerable code snippets and raw requests and responses. Claude can then explain the flaw and its fix.
get_issues
Lists a company's vulnerabilities, filterable by project, asset, severity, status, dates, and more. Claude starts there to sort or count.
get_top_vulnerabilities
Gives a risk overview as a count of vulnerabilities by severity. It's the number people quote in steering meetings.
get_projects
Lists the platform's active security projects. Claude gets the big picture of the work currently underway across the company.
get_project
Returns a specific project from its Conviso ID. Claude can then detail its content or compare it with another.
get_asset
Returns one specific platform asset from its ID. Claude gets its record to review it or tie it to findings.
get_assets
Lists the assets mapped in the platform. Claude gets the inventory of what Conviso watches.
create_project_url
Generates a direct link to a project on the Conviso platform. Despite its name, it only builds an address and touches nothing.
create_issue_url
Builds the direct address of a vulnerability in Conviso, so you can point someone straight to it. No record is touched.
get_mttr_over_time
Tracks mean time to resolution for vulnerabilities over time, broken down by severity level.
get_overall_risk_score_history
Traces a company's overall risk score history, with the current score and the gap from the previous period.
get_tickets
Lists the support or bug tickets recorded in the platform. Claude can then sort or summarize them.
get_ticket
Fetches a single ticket from the platform, so Claude can read it and summarize it for you.
get_requirements
Browses the requirements and checklists defined in the platform. Claude sees the baseline your projects must meet.
get_requirement
Pulls up a single requirement and its full content, so Claude can explain in plain words what it asks of your team.
get_project_requirements
Returns the requirements attached to a given project, with the ID needed to dig further. Conviso advises starting here when only the project is known.
get_applications
Lists the applications registered in the platform and their assets. Claude gets the map of your application portfolio.
get_application
Brings up a single application and the assets attached to it in Conviso, so Claude can sketch its profile for you.
get_scan_histories
Traces the execution history of scans. Claude sees when analyses ran and what they produced.
get_asset_scans_count
Counts scans per asset to measure coverage. Claude spots assets that are rarely or never analyzed.
get_sbom_components
Surfaces a company's components and dependencies from its software bill of materials, or SBOM. Claude can spot one specific library.
get_pentest_artifacts
Pulls up the list of artifacts from penetration tests held in Conviso, with their scope, for a first overview.
get_pentest_artifact
Retrieves a single penetration test artifact and its scope, so Claude can sum it up for you.
get_pentest_execution
Returns the results of a penetration test run. Claude can summarize what was found.
get_threat_model_artifacts
Takes stock of the company's threat modeling artifacts, version by version, so Claude knows what has already been modeled.
get_threat_model_artifact
Opens one specific threat modeling artifact and its versions for Claude, so it can walk you through the key points.
list_mutations
Searches the catalog of operations Conviso allows through this connector. It's the first step of the discover, describe, execute path.
describe_mutation
Describes one allowed operation from that catalog: its required fields, permitted values, and what it returns. Claude prepares an accurate call this way.
What Claude changes (8)
8 toolsEight tools that create, modify, or launch something in Conviso. No source describes a confirmation step of their own, so the general rule below applies.
execute_mutation
Approval: see the ruleRuns one of the write operations Conviso allows: create, update, or delete findings, projects, assets, requirements, or applications, or launch a test.
change_issue_status
Approval: see the ruleMoves a vulnerability from one status to another. It's a publisher shortcut for a common write.
create_source_code_vulnerability
Approval: see the ruleRecords a new source code vulnerability in Conviso, without going through the generic path.
create_project
Approval: see the ruleCreates a new security project in the platform.
create_asset
Approval: see the ruleAdds an asset to Conviso's map.
create_ticket
Approval: see the ruleOpens a ticket in the Conviso platform, right from the conversation.
run_dast
Approval: see the ruleLaunches a dynamic application security test, or DAST, which probes the running application for flaws.
trigger_pentest
Approval: see the ruleTriggers a penetration test run by Conviso's AI.
Undocumented (4)
4 toolsThe directory sheet publishes these four names, and no official source says what they do. We won't guess from the name.
get_project_types
This name sits on the directory sheet, and that's all anyone knows. Neither Conviso's README nor any Claude page describes it, so no source documents what it returns and this page won't say more.
get_project_statuses
Same silence here: listed on the sheet, missing from the publisher's tool table. No official source lets us say what it returns, and we won't guess from its name.
get_today_date
The directory displays this name, but Conviso's tool table skips it and no official page explains it. Nothing published today says what it's for, what it returns, or when Claude would call it.
create_pentest_artifact
One more name the directory displays without any explanation: it appears neither in the README's table nor among the shortcuts named on the sheet. No source documents its behavior, so this page stops there.
What Claude asks before it acts
By default, Claude stops and asks for your go-ahead before any action it takes on an account for you. With eight tools that write to Conviso, that's the rule that matters.
On a Team or Enterprise workspace, owners decide whether a member can let certain actions through without being asked again. They can also cap what a connector does for the whole organization, for example keeping reads and blocking writes. On Conviso's side, every write requires the company ID so the platform can check its write policy. And Claude works with your key's permissions, nothing more, whatever you ask.
Which plans it's available on
None of the 819 sheets in the official directory shows availability by plan. A connector-by-connector answer isn't published anywhere.
The general rule is sourced: desktop extensions install on Claude Desktop, open to all of its users, while remote connectors run on Claude, Cowork, Claude Desktop, and mobile. On Team and Enterprise, an Owner or Primary Owner enables them for the organization. For the current status, check the Conviso MCP Server sheet in the official directory.
Where Conviso stops
A connector isn't an automation. Claude calls these tools while it answers you: no new finding sets anything off by itself.
Only the publisher documents this connector, in its repository README: neither Claude's help center nor Anthropic's documentation covers it. Writes are deliberately limited to the client-facing operations Conviso picked, with the rest of the platform left unexposed. The directory badge isn't a security audit, and Anthropic can't vouch for how a publisher's tools behave. The same reading grid applies to other sheets, such as the Claude affinity connector page.
Is the README's tool list the same as the directory's?
- Claude directory sheet ↗October 202642 tools, including write shortcuts such as change_issue_status, create_project, run_dast, and trigger_pentest.
- Publisher's repository README ↗October 2026The table describes two tools missing from the sheet and routes every write through execute_mutation, without detailing the shortcuts.
What this page followsThe two lists don't match, and neither is dated older than the other. This page follows the directory sheet, which describes the installable extension, and flags as undocumented the names nobody explains. The version installed on your machine is what counts.
Need help connecting Conviso MCP Server to Claude?
A person reads every message.