Available tools
vibr_list_scans— list recent scansvibr_get_scan— retrieve findingsvibr_start_scan— queue a new authorised scan
Client configuration
{
"mcpServers": {
"vibr": {
"command": "node",
"args": ["/path/to/vibr/mcp-server/dist/index.js"],
"env": {
"VIBR_API_URL": "https://vibr.app",
"VIBR_ACCESS_TOKEN": "<confirmed-user-token>"
}
}
}
}The server uses the same organization isolation and scan limits as the dashboard. OAuth-based one-click authorization is the next production step; raw credentials are never accepted by the MCP server.