MCP server
Connect Kiket to Cursor, Claude Desktop, or any MCP-aware agent.
The Kiket MCP server exposes operational compliance tools over the Model Context Protocol. Agents can list cases and findings, run scans, import evidence, and generate audit reports — using the same authorized platform API as the web app.
Install and run
The server ships as @kiket/mcp and speaks MCP over stdio (one JSON-RPC message per line).
npx @kiket/mcpBuild from source is only needed for contributors; most users should use npx.
Required environment
| Variable | Purpose |
|---|---|
KIKET_API_KEY or KIKET_API_TOKEN | API key (preferred) or short-lived JWT |
KIKET_ORGANIZATION_ID | Organization UUID — tools always run in this tenant |
KIKET_API_URL | Optional; defaults to https://api.kiket.dev |
Create an API key in Settings → API Keys.
Cursor configuration
Add to .cursor/mcp.json (project) or Cursor Settings → MCP:
{
"mcpServers": {
"kiket": {
"command": "npx",
"args": ["-y", "@kiket/mcp"],
"env": {
"KIKET_API_KEY": "kik_...",
"KIKET_ORGANIZATION_ID": "org_...",
"KIKET_API_URL": "https://api.kiket.dev"
}
}
}
}Restart Cursor after saving. The server implements the standard MCP handshake (initialize, tools/list, tools/call).
Claude Desktop (and other MCP clients)
Use the same command, args, and env block in your client's MCP config file. Point KIKET_API_KEY at a scoped key with the minimum permissions your workflow needs.
Tool surface (plain language)
Read and navigate
- List workspaces, monitored processes, and operational cases
- List compliance findings, evidence records, and scanner runs
- List audit reports, anchor proofs, ingestion failures, and event sources
- Semantic search across indexed cases, evidence, findings, and reports
Act on the platform
- Validate process YAML and run what-if simulations
- Trigger scanner runs and import normalized evidence
- Generate and verify audit report snapshots
- Create and verify anchor proofs
Investigate
- Fetch case, finding, or evidence context bundles for grounded answers
- Build case graphs and evidence provenance chains
- Compare scanner run diffs and generate proof packets
Prompt
kiket_investigate_case— structured playbook for case investigation
Tool names in clients use the kiket_* prefix (for example kiket_list_cases, kiket_trigger_scan).
Security boundaries
The MCP server deliberately does not expose:
- Authentication, password, or session management
- API key creation or revocation
- Admin, billing, or raw bulk export endpoints
- Inbound webhook receivers or repository write/push tools
This keeps assistant integrations useful for day-to-day compliance work while limiting credential and GDPR exposure. Use the CLI or REST API directly when you need administrative actions.