Integration · Developer tools
Connect Claude & ChatGPT to Cloudsmith
Ask your AI which packages in a Cloudsmith repository have vulnerabilities, who changed what in the audit log, or how close you are to your storage quota. It can search repositories and packages, read scan results and dependencies, and quarantine, tag, copy or move packages. It can also list members, teams and entitlement tokens, and invite people to your organization.
Free plan, no credit card. Takes about a minute.
Try asking
“Which packages in our production repo have vulnerability findings?”
The AI lists the scan results for all packages in the repository and opens the scans with findings.
“Quarantine version 2.4.1 of our api-client package.”
It finds the package in the repository and quarantines it so it cannot be downloaded. You can release it again later.
“Promote the latest build from staging to production.”
It searches the staging repository for the package, copies it to the production repository and checks the sync status.
What your AI can do
Repositories and packages
Search repositories and packages, read package details, dependencies and sync status, and copy, move, tag or delete packages.
Security and scans
List vulnerability scans for an owner, a repository or a package, read full findings, start a new scan and quarantine packages.
Organization and access
List orgs, members, teams and pending invites, invite members, read entitlement tokens, search the audit log and check storage quota.
“Who deleted packages in our org last week?”
It searches the audit log for the organization and shows who did what and when.
“How much storage and bandwidth have we used this month?”
It reads your storage and bandwidth usage against your plan quota.
“Invite [email protected] to our org as a Member on the platform team.”
It invites her with the Member role and the team you name. Cloudsmith sends her an invitation email.
29 tools for Cloudsmith
These tools are switched on when you connect. You can switch any of them off, or require your approval before it runs.
copy_packageVisible to othersCopy a package to another repository in the same namespace (destination repo slug). Set republish to overwrite an existing package with the same version.delete_packageDeletesDelete a package from a repository by owner, repo and package_identifier. Check the package identifier first; treat this as irreversible.get_current_userGet the profile of the Cloudsmith user the connection belongs to (name, slug, email).get_entitlementGet one entitlement token's details and limits by owner, repo and entitlement_identifier.get_orgGet details of one organization by its slug (org).get_packageGet one package's full details by owner, repo and package_identifier (slug_perm).get_package_statusCheck a package's sync/processing status by owner, repo and package_identifier, e.g. after an upload, copy or move.get_repoGet one repository's details by owner and repo_identifier (slug).get_storage_quotaGet storage and bandwidth usage against plan quota for an owner (user or org).get_vulnerability_scanGet the full findings of one vulnerability scan by owner, repo, package and scan identifier.invite_memberChanges dataInvite someone to an organization by email or user slug with a role (Owner, Manager, Member, Collaborator) and optional teams. Sends them an invitation email.list_entitlementsList entitlement tokens (download access for customers) in a repository, with an optional name search and active-only filter.list_invitesList pending invitations to an organization.list_membersList or search members of an organization (org slug), optionally filtered to active or inactive users.list_my_reposList all repositories you can access across your account and organizations.list_orgsList the organizations you belong to, with their slugs.list_package_dependenciesList the dependencies of one package by owner, repo and package_identifier.list_package_groupsList packages in a repository grouped by name (one row per package with its versions), with an optional search query.list_package_vulnerability_scansList vulnerability scan results for one package (owner, repo, package).list_repo_vulnerability_scansList vulnerability scan results for all packages in one repository (owner, repo).list_teamsList or search teams in an organization (org slug).list_vulnerability_scansList vulnerability scan results across all repositories of an owner (user or org).move_packageChanges dataMove a package to another repository in the same namespace (destination repo slug); it is removed from the source repository.quarantine_packageChanges dataQuarantine a package so it cannot be downloaded, or set release to true to release it from quarantine.scan_packageChanges dataStart a new vulnerability scan of a package by owner, repo and package_identifier.search_audit_logSearch the audit log for an owner (user or org): who did what and when, with an optional query on events, actors or dates.search_packagesList or search packages in a repository (owner, repo), with a query on name, version, format, status, tag and more.search_reposList or search repositories within one owner (user or org slug), with an optional query by name or slug and sorting.tag_packageChanges dataAdd, replace, remove or clear tags on a package (action + tags), by owner, repo and package_identifier. Immutable tags cannot be removed later.
Set up in three steps
- 1
Pick the app
Create a free PipMCP account and choose Cloudsmith from the app list.
- 2
Paste your key
Paste your Cloudsmith API key. In Cloudsmith, click your user icon in the top right, choose Personal API Keys and click Refresh to reveal the key, then copy it. Refreshing disables your previous key, so update anything else that used it.
- 3
Add the link to your AI
You get a personal MCP link. Add it to Claude, ChatGPT or Cursor:
- Click your name, then Settings › Connectors › Add custom connector.
- Paste your link as the Remote MCP server URL.
- Switch it on from the + menu in a chat.
Questions
What can the AI do in Cloudsmith?
The AI can search and read repositories, packages, package groups, dependencies, vulnerability scans, entitlement tokens, organizations, members, teams, invites, the audit log and storage quota. It can start scans, quarantine, tag, copy and move packages, and invite members. It can also delete a package if you switch that tool on.
Does the AI see my Cloudsmith API key?
No. Your Cloudsmith API key is encrypted at rest and never shown to the AI. After you save it, it is not shown again, not even to you. The AI only sees the results of the tools it calls.
Can I control what the AI is allowed to do?
Yes. You choose which tools are switched on, so you can start read-only. Deleting a package cannot be undone, and copying with republish overwrites an existing version, so those can require your approval before they run. Every tool call is logged.
Does it work with ChatGPT?
Yes. In ChatGPT go to Settings › Apps & Connectors › Advanced and turn on Developer mode, then add your PipMCP link. Developer mode needs a paid ChatGPT plan: Plus, Pro, Business or Enterprise. The same link also works in Claude (Settings › Connectors › Add custom connector), Cursor and other MCP clients.
What does it cost?
PipMCP has a free plan with no credit card required. Paid plans bill per completed task. You also need your own Cloudsmith account.
Will refreshing my API key break other tools?
It can. In Cloudsmith, clicking Refresh under Personal API Keys reveals a new key and disables the previous one. Anything else that used the old key, such as a CI pipeline, needs the new key too.
Let your AI work in Cloudsmith today.
Start free. Your key stays encrypted, and you decide what the AI may do.
Connect Cloudsmith freePipMCP is not affiliated with Cloudsmith. Product names are trademarks of their owners.






