ZipLoom
Home
PricingSign inGet Your Live URL
Integrations · MCP

Connect ZipLoom To Your Coding Agent

Your agent writes the code. With ZipLoom connected over MCP, it can also scan it, read what is wrong, and fix the right thing first — without leaving the editor.

1. Create An IDE Agent Key

In ZipLoom, open Settings → API Keys, choose IDE Agent (MCP) and create a key. Owners and admins can create keys; the key is shown once and ZipLoom keeps only a hash. CI keys made for the GitHub Action do not work here, by design.

Put it in your environment so config files never contain it:

export ZIPLOOM_API_KEY="zlk_…"

2. Add The Server To Your Agent

Server URL: https://ziploom.dev/api/mcp — Streamable HTTP, authenticated with Authorization: Bearer.

Claude Code

Run in a terminal:

claude mcp add --transport http --scope user ziploom https://ziploom.dev/api/mcp \
  --header "Authorization: Bearer $ZIPLOOM_API_KEY"

Your shell fills in $ZIPLOOM_API_KEY when you run the command, and Claude Code stores the resulting header.

OpenAI Codex (CLI and IDE extension)

In ~/.codex/config.toml:

[mcp_servers.ziploom]
url = "https://ziploom.dev/api/mcp"
bearer_token_env_var = "ZIPLOOM_API_KEY"

Or run: codex mcp add ziploom --url https://ziploom.dev/api/mcp --bearer-token-env-var ZIPLOOM_API_KEY. Codex reads the key from the environment each time it starts.

Cursor

In ~/.cursor/mcp.json (or .cursor/mcp.json in a project):

{
  "mcpServers": {
    "ziploom": {
      "url": "https://ziploom.dev/api/mcp",
      "headers": {
        "Authorization": "Bearer ${env:ZIPLOOM_API_KEY}"
      }
    }
  }
}

VS Code (GitHub Copilot agent mode)

In .vscode/mcp.json:

{
  "inputs": [
    {
      "type": "promptString",
      "id": "ziploom-api-key",
      "description": "ZipLoom API key",
      "password": true
    }
  ],
  "servers": {
    "ziploom": {
      "type": "http",
      "url": "https://ziploom.dev/api/mcp",
      "headers": {
        "Authorization": "Bearer ${input:ziploom-api-key}"
      }
    }
  }
}

VS Code asks for the key once and stores it in its secret storage, not in the file.

Windsurf

In ~/.codeium/windsurf/mcp_config.json:

{
  "mcpServers": {
    "ziploom": {
      "serverUrl": "https://ziploom.dev/api/mcp",
      "headers": {
        "Authorization": "Bearer ${env:ZIPLOOM_API_KEY}"
      }
    }
  }
}

Gemini CLI

Run in a terminal:

gemini mcp add --transport http --scope user \
  --header "Authorization: Bearer $ZIPLOOM_API_KEY" ziploom https://ziploom.dev/api/mcp

Gemini CLI does not expand environment variables inside headers, so the key is written into ~/.gemini/settings.json. Keep that file out of version control.

Any other agent (Cline, Roo Code, Zed, JetBrains AI, Continue…)

In the agent's MCP settings — a local (stdio) server:

{
  "mcpServers": {
    "ziploom": {
      "command": "npx",
      "args": [
        "-y",
        "mcp-remote",
        "https://ziploom.dev/api/mcp",
        "--header",
        "Authorization:${ZIPLOOM_AUTH}"
      ],
      "env": {
        "ZIPLOOM_AUTH": "Bearer <your ZIPLOOM_API_KEY>"
      }
    }
  }
}

mcp-remote bridges a local stdio server to ZipLoom over HTTPS. Needs Node.js 18+. The header value has no space after the colon on purpose — some clients split arguments on spaces.

3. What Your Agent Can Do

Try: “Scan this project with ZipLoom and fix whatever the attack chains say to fix first.”

Security

Every request is scoped to the organization that owns the key; a project in another organization reads as not found. Results carry what is wrong, where and how to fix it. Agent-started scans reuse a scan already in progress and are limited to five an hour per organization, so a looping agent cannot use up the scans your CI depends on. Revoke a key in Settings at any time and it stops working immediately.