Connect ZipLoom To Your Coding Agent
Your agent writes the code. With ZipLoom connected over MCP, it can also scan it, read what is wrong, and fix the right thing first — without leaving the editor.
1. Create An IDE Agent Key
In ZipLoom, open Settings → API Keys, choose IDE Agent (MCP) and create a key. Owners and admins can create keys; the key is shown once and ZipLoom keeps only a hash. CI keys made for the GitHub Action do not work here, by design.
Put it in your environment so config files never contain it:
export ZIPLOOM_API_KEY="zlk_…"
2. Add The Server To Your Agent
Server URL: https://ziploom.dev/api/mcp — Streamable HTTP, authenticated with Authorization: Bearer.
Claude Code
Run in a terminal:
claude mcp add --transport http --scope user ziploom https://ziploom.dev/api/mcp \ --header "Authorization: Bearer $ZIPLOOM_API_KEY"
Your shell fills in $ZIPLOOM_API_KEY when you run the command, and Claude Code stores the resulting header.
OpenAI Codex (CLI and IDE extension)
In ~/.codex/config.toml:
[mcp_servers.ziploom] url = "https://ziploom.dev/api/mcp" bearer_token_env_var = "ZIPLOOM_API_KEY"
Or run: codex mcp add ziploom --url https://ziploom.dev/api/mcp --bearer-token-env-var ZIPLOOM_API_KEY. Codex reads the key from the environment each time it starts.
Cursor
In ~/.cursor/mcp.json (or .cursor/mcp.json in a project):
{
"mcpServers": {
"ziploom": {
"url": "https://ziploom.dev/api/mcp",
"headers": {
"Authorization": "Bearer ${env:ZIPLOOM_API_KEY}"
}
}
}
}VS Code (GitHub Copilot agent mode)
In .vscode/mcp.json:
{
"inputs": [
{
"type": "promptString",
"id": "ziploom-api-key",
"description": "ZipLoom API key",
"password": true
}
],
"servers": {
"ziploom": {
"type": "http",
"url": "https://ziploom.dev/api/mcp",
"headers": {
"Authorization": "Bearer ${input:ziploom-api-key}"
}
}
}
}VS Code asks for the key once and stores it in its secret storage, not in the file.
Windsurf
In ~/.codeium/windsurf/mcp_config.json:
{
"mcpServers": {
"ziploom": {
"serverUrl": "https://ziploom.dev/api/mcp",
"headers": {
"Authorization": "Bearer ${env:ZIPLOOM_API_KEY}"
}
}
}
}Gemini CLI
Run in a terminal:
gemini mcp add --transport http --scope user \ --header "Authorization: Bearer $ZIPLOOM_API_KEY" ziploom https://ziploom.dev/api/mcp
Gemini CLI does not expand environment variables inside headers, so the key is written into ~/.gemini/settings.json. Keep that file out of version control.
Any other agent (Cline, Roo Code, Zed, JetBrains AI, Continue…)
In the agent's MCP settings — a local (stdio) server:
{
"mcpServers": {
"ziploom": {
"command": "npx",
"args": [
"-y",
"mcp-remote",
"https://ziploom.dev/api/mcp",
"--header",
"Authorization:${ZIPLOOM_AUTH}"
],
"env": {
"ZIPLOOM_AUTH": "Bearer <your ZIPLOOM_API_KEY>"
}
}
}
}mcp-remote bridges a local stdio server to ZipLoom over HTTPS. Needs Node.js 18+. The header value has no space after the colon on purpose — some clients split arguments on spaces.
3. What Your Agent Can Do
list_projects— Your organization's projects, with repository and live URL.scan_project— Start a code scan of the default branch or an exact commit (uses your plan's monthly scans).get_scan_status— Progress, then counts and open findings — title, severity, file, line and fix.get_findings— The latest open findings, plus attack chains: findings that together form one exploitable path, with the step to fix first.deploy_status— Recent deployments and the verdict of each deploy gate.posture— The latest live-site check: security headers, TLS, DNS and email records.
Try: “Scan this project with ZipLoom and fix whatever the attack chains say to fix first.”
Security
Every request is scoped to the organization that owns the key; a project in another organization reads as not found. Results carry what is wrong, where and how to fix it. Agent-started scans reuse a scan already in progress and are limited to five an hour per organization, so a looping agent cannot use up the scans your CI depends on. Revoke a key in Settings at any time and it stops working immediately.