squirrelscan MCP
- Endpoint
-
https://mcp.squirrelscan.com/mcp - Transport
- streamable-http
- Docs
- https://docs.squirrelscan.com/developers/mcp
OAuth · resolves from well-known metadata For the hosted MCP server, add https://mcp.squirrelscan.com/mcp to your MCP client with no auth header and let the client handle OAuth discovery from the authorization-server metadata. No pre-registration is needed: the client registers itself dynamically, runs authorization code + PKCE (S256), and you just sign in in the browser, choose an organization, and approve access.
Authorization: Bearer <credential> Create a key in Settings → API Keys, or run `squirrel auth login` and then `squirrel keys create`. Pick scopes and expiry, copy the key when shown (it is shown once), then supply it as Authorization: Bearer sq_... or set SQUIRRELSCAN_API_KEY for CLI/headless use. The legacy env alias SQUIRREL_API_TOKEN is also accepted by the CLI.
OAuth · resolves from well-known metadata MCP clients discover OAuth automatically via https://mcp.squirrelscan.com/.well-known/oauth-authorization-server. No pre-registration needed: dynamic client registration and client id metadata documents (client.dev) are both supported. Authorization code + PKCE (S256).
Authorization: Bearer <credential> Create a key at https://app.squirrelscan.com/settings/api-keys (or run squirrel keys create after squirrel auth login). Set it as SQUIRRELSCAN_API_KEY, or send it as Authorization: Bearer sq_... on any request. Local, unauthenticated audits are always free; a key is only needed for cloud features such as hosted crawling, publishing, and credits.