MCP for Balam
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
2026-09-08 22:58:27 +00:00
.forgejo/workflows Add security-scan CI workflow (matches balam) 2026-09-05 11:09:15 -05:00
.gitignore Package as an installable MCP server for uvx-based Claude Code install 2026-09-08 17:57:46 -05:00
pyproject.toml Package as an installable MCP server for uvx-based Claude Code install 2026-09-08 17:57:46 -05:00
README.md Package as an installable MCP server for uvx-based Claude Code install 2026-09-08 17:57:46 -05:00
server.py Add MCP server for Balam, generated from its OpenAPI spec via FastMCP 2026-09-05 10:09:03 -05:00
test_server.py Add MCP server for Balam, generated from its OpenAPI spec via FastMCP 2026-09-05 10:09:03 -05:00
uv.lock Package as an installable MCP server for uvx-based Claude Code install 2026-09-08 17:57:46 -05:00

balam-mcp

MCP server for Balam, generated from its own OpenAPI spec (GET /api/v2/oa3/openapi.yaml) via FastMCP. Every documented endpoint — products, engagements, findings, scan import, risk acceptance, tags/notes, etc. — becomes an MCP tool with no hand-written wrappers, and stays in sync automatically as Balam's API grows.

Setup

export BALAM_URL="http://localhost:8080"      # your running Balam instance
export BALAM_TOKEN="<personal API token>"     # Balam UI -> Settings -> API Tokens
uv run test_server.py                         # sanity check, no network needed

(uv run installs the dependencies declared in pyproject.toml into an ephemeral environment automatically. pip install -e . works too if you'd rather manage the environment yourself.)

Register with Claude Code

No clone needed — uvx fetches this repo and runs its balam-mcp console script directly:

claude mcp add balam -- uvx --from git+https://git.colibrisec.org/colibrisec/balam-mcp balam-mcp

Or, from a local checkout:

claude mcp add balam -- uv run --project "$(pwd)" balam-mcp

Either way, BALAM_URL / BALAM_TOKEN must be set in the environment Claude Code runs in.