C

checkmarx.com

Checkmarx provides application security products for scanning source code, open source dependencies, infrastructure as code, secrets, APIs, and related software risk. Its Checkmarx One platform centralizes these AppSec capabilities for enterprise development and security workflows.

4 integrations · MCP · REST · CLI

Checkmarx exposes documented REST APIs for Checkmarx One and SCA, a Checkmarx One CLI, and markets an MCP server; developer auth is via Checkmarx-issued API keys or OAuth clients, while MCP connection details were not publicly documented.

discovered 2mo ago
MCP servers1
REST · OpenAPI2
CLI1
Credentials
Checkmarx One API key / refresh tokenapi_keyGet key

In the Checkmarx One web portal, go to Creating an API Key for Checkmarx One Integrations. Sign in, open SettingsAPI Keys (or Identity and Access Management in older docs), click Create Key, and copy the generated key. The CLI docs describe this API key as a refresh-token style credential that can be used for CLI and plugin authentication.

Checkmarx One OAuth clientoauth2Set up OAuth

Create an OAuth client in Checkmarx One using Creating OAuth Clients. Sign in to Checkmarx One, open SettingsIdentity and Access Management, create a client, and save the client credentials. Authentication for Checkmarx One CLI and Plugins says OAuth clients can be used instead of API keys and let you scope permissions more precisely.

conventions · 1/7 published

Publish these signals → /publishing