The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the Nowsecure MCP Server listing page.
Made by Tatavarthi Tarun · LinkedIn
A small Model Context Protocol (MCP) server for NowSecure Platform. Built to work
around the broken UI PDF export
(Failed to load report data: Enum "JiraIntegrationCustomFieldType" cannot represent value: "")
by pulling findings through the REST + GraphQL APIs and, when needed, rendering
the remediation PDF locally instead of relying on NowSecure's report service.
npx fetches the package on demand)| Tool | What it does |
|---|---|
list_applications | Lists your portfolio apps (REST). Find app refs + latest assessment. |
get_remediation_findings | Returns findings needing remediation as JSON (GraphQL). Ideal for feeding an agent. |
generate_remediation_pdf | Renders a clean PDF locally from the findings. Works even when NowSecure's renderer fails. |
download_assessment_pdf | Tries NowSecure's REST PDF endpoint (separate path from the broken UI export). |
Every user generates their own NowSecure Platform API bearer token (PAT) and puts it in their local MCP config. No token is bundled with this package.
Create one in Platform: Profile icon (top right) > Tokens.
NOWSECURE_TOKEN (required) — your personal PATNOWSECURE_API_BASE (optional) — defaults to https://api.nowsecure.comNo clone or manual install needed — npx fetches and runs the latest version.
You just need Node.js >= 18.
All examples run the package via npx (no clone/install needed — just Node.js
= 18). Replace the token with your own personal PAT.
Use the CLI (recommended — it validates and writes to the right file):
Add --scope user to make it available across all your projects. Or edit
.mcp.json (project) / ~/.claude.json (user) directly:
Edit ~/.cursor/mcp.json (global) or .cursor/mcp.json (per project):
In the agent panel / Settings, open MCP Servers → Manage / Raw Config to edit
mcp_config.json, then add:
VS Code uses a top-level servers key (not mcpServers). Add to .vscode/mcp.json
in your workspace, or your user mcp.json (Command Palette → MCP: Open User
Configuration):
Add to ~/.kiro/settings/mcp.json (global) or .kiro/settings/mcp.json (workspace):
If published to a private/scoped registry, use the scoped name instead, e.g.
"args": ["-y", "@your-scope/nowsecure-mcp-server"].
First list your apps with list_applications to find an app ref, then ask your
agent (placeholders shown — substitute your own refs):
Generate a remediation PDF for app
<app-ref-uuid>to ./remediation.pdf
If you omit the assessment ref, the latest assessment for that app is used.
Tatavarthi Tarun 🎈💜 linkedin.com/in/tatav
If this saved you from NowSecure's broken PDF export, a connect on LinkedIn is appreciated!