Integration · Developer tools
Connect Claude & ChatGPT to Cantina
Ask your AI which findings are open in a Cantina security review, what changed on a finding, or how many findings came in this week. It can read repositories and their code files, submit and update findings, comment and escalate, and search published reports, using the permissions of the manager who created your API key.
Free plan, no credit card. Takes about a minute.
Try asking
“List the high-severity findings in our audit repository.”
The AI finds the repository and lists its findings with a severity filter.
“Summarize finding 42 and what has happened on it.”
It reads the finding with description, severity, status and assignee, plus its change history.
“Assign finding 42 to Alex and set severity to medium.”
It updates the finding's assignee and severity.
What your AI can do
Findings
List, read, submit and update findings, see their change history, comment on them and escalate them to reviewers.
Repositories and people
List and read repositories, their code files, comments, users and your own role, plus companies and company users.
Reports and insights
Search and read published security review reports, and get finding statistics for a repository.
“Reply to the latest comment on finding 17.”
It posts a comment on the finding as a reply to that comment. Other participants can see it.
“How many findings has the review received since Monday?”
It reads the repository's finding statistics and insights since that date.
“Show me the file the finding points to.”
It lists the repository's code files and reads the one you need.
24 tools for Cantina
These tools are switched on when you connect. You can switch any of them off, or require your approval before it runs.
comment_on_findingChanges dataPost a comment on a finding (`repo_id`, `finding_ref`) with `content`; optionally reply to a `parent` comment. Other participants can see it.create_findingChanges dataSubmit a new finding to a repository: `repo_id`, `title`, `severity`, `description`, plus optional impact, likelihood, category and related files.escalate_findingVisible to othersEscalate a finding (`repo_id`, `finding_ref`) with an explanatory `comment_content`. Notifies the reviewers.get_companyGet one company by `company_id`.get_findingGet one finding by `repo_id` and `finding_ref`, with description, severity, status and assignee.get_my_repository_roleGet your own membership and role in a repository (`repo_id`).get_reportGet one report by `report_id`; set `with_files` to include its files.get_repositoryGet one repository by `repo_id`, including scope, timeframe, status and reward settings.get_repository_fileGet the contents of one file in a repository by `repo_id` and `path`.get_repository_insightsGet finding statistics and insights for a repository (`repo_id`), optionally since a date.list_all_findingsList findings across all your repositories, with optional search/filter `s`.list_companiesList the Cantina companies (organisations) you belong to.list_company_repositoriesList all repositories belonging to a company (`company_id`).list_company_usersList users in a company (`company_id`), searchable with `q`.list_finding_eventsList the history of changes on a finding by `repo_id` and `finding_ref`.list_findingsList findings in a repository (`repo_id`), with optional search/filter `s` and paging.list_labelsList the finding labels used across your repositories.list_reportsList published security review reports, searchable by `q`.list_repositoriesList the security review repositories (audits, competitions, bounties) you can access, filtered by text `q`, kind, role or status.list_repository_commentsList comments in a repository (`repo_id`), filtered by text, resolved, pinged or author.list_repository_filesList the code files in a repository (`repo_id`).list_repository_usersList the people in a repository (`repo_id`), optionally filtered by name or role.update_findingChanges dataUpdate a finding by `repo_id` and `finding_ref`: status, severity, labels, assignee, title, description, duplicate link or fix info.update_finding_commentChanges dataEdit your comment `message_id` on a finding (`repo_id`, `finding_ref`) with new `content`.
Set up in three steps
- 1
Pick the app
Create a free PipMCP account and choose Cantina from the app list.
- 2
Paste your key
Paste a Cantina API key. Sign in as a Company Manager, open Settings > API keys, click Generate New API Key, set an expiration date and copy the key. It is shown only once.
- 3
Add the link to your AI
You get a personal MCP link. Add it to Claude, ChatGPT or Cursor:
- Click your name, then Settings › Connectors › Add custom connector.
- Paste your link as the Remote MCP server URL.
- Switch it on from the + menu in a chat.
Questions
What can the AI do in Cantina?
The AI can read repositories, their files, comments and users, findings and their history, labels, companies, company users, reports and repository insights. It can submit findings, update findings, comment on them, edit its own comments and escalate a finding to the reviewers.
Does the AI see my Cantina credentials?
No. Your Cantina credentials are encrypted at rest and never shown to the AI. After you save them, they are not shown again, not even to you. The AI only sees the results of the tools it calls.
Can I control what the AI is allowed to do?
Yes. You choose which tools are switched on, so you can start read-only. Escalating a finding notifies the reviewers, and comments are visible to other participants. These can require your approval before they run. Every tool call is logged.
Does it work with ChatGPT?
Yes. In ChatGPT go to Settings › Apps & Connectors › Advanced and turn on Developer mode, then add your PipMCP link. Developer mode needs a paid ChatGPT plan: Plus, Pro, Business or Enterprise. The same link also works in Claude (Settings › Connectors › Add custom connector), Cursor and other MCP clients.
What does it cost?
PipMCP has a free plan with no credit card required. Paid plans bill per completed task. You also need your own Cantina account.
What permissions does the Cantina API key have?
The key has the permissions of the Company Manager who created it. You set an expiration date when you generate it under Settings > API keys, and the key is shown only once. The tools you switch on in PipMCP limit the AI further.
Let your AI work in Cantina today.
Start free. Your key stays encrypted, and you decide what the AI may do.
Connect Cantina freePipMCP is not affiliated with Cantina. Product names are trademarks of their owners.






