> For the complete documentation index, see [llms.txt](https://docs.natoma.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.natoma.ai/apps/checkmarx.md).

# Checkmarx

{% hint style="warning" %}
**Early Access** — Reach out to your Natoma representative for access.
{% endhint %}

**Type:** Official

**Source Type:** Remote URL

**Source:** `https://{checkmarxBaseUrl}/api/security-mcp/mcp`

**Description:** Checkmarx One MCP server provides AI assistants with access to your Checkmarx One application security platform. It enables querying scans, projects, vulnerabilities, and findings to support AppSec triage and reporting.

**Configuration Parameters:**

* **Checkmarx Base URL** \* - Admin-supplied. Your Checkmarx One host (e.g. `ast.checkmarx.net`, `eu.ast.checkmarx.net`).
* **Checkmarx One API Key** \* (sensitive) - Your personal Checkmarx One API key — generated in Checkmarx One.

## Setup

### Admin Setup

In Natoma, an admin adds **Checkmarx** under **Apps** and sets the **Checkmarx Base URL** for the org.

### User Setup

1. Log in to Checkmarx One.
2. Navigate to **Settings → Identity & Access Management → API Keys**.
3. Click **Create API Key** and scope it to the permissions you need.
4. Copy the generated key — Checkmarx will not show it again.
5. When creating the connection in Natoma, paste the API key and save.
