Prerequisites
- Node.js 18+ — the server runs via
npx, nothing to install globally. - An MCP-capable agent — Claude Code, Cursor, Codex, or any client that supports MCP servers.
- A paid kipmox plan with Agent access — the kipmox Agent tier, or Pro/Enterprise (which include it). See Plans & Limits.
- Optional, for your custom ruleset: the Salesforce CLI with the
code-analyzerplugin and Java 11+. kipmox’s native rules work without them — this is only needed to re-run your own Code Analyzer / PMD ruleset. See Custom rules.
1. Sign in
The easiest way is thelogin command — it uses a magic link, so you can click it on any device (handy on VDI or a remote box):
1
Enter your email
Run the command and enter the email for your kipmox account (or pass it inline:
npx @kipmox/mcp login you@company.com).2
Click the link
kipmox emails you a sign-in link. Open it on any device — the terminal polls until you click it (up to 5 minutes).
3
Done
The token is stored at
~/.kipmox/credentials.json, and the server picks it up automatically — no token needed in your MCP config. Sign out anytime with npx @kipmox/mcp logout.Prefer an explicit token? Set
KIPMOX_TOKEN in your MCP server config instead (see below). An env token always wins over the stored login — useful for CI or shared machines.2. Add the MCP server
- Claude Code
- Project .mcp.json
- Cursor / other MCP clients
If you signed in with Or pass a token explicitly:
login, add the server with no token:Don’t commit a real
KIPMOX_TOKEN to a shared repo. Use npx @kipmox/mcp login (per-developer, stored outside the repo), or inject the token from your secret store in CI.3. Run it
Restart your agent so it picks up the new server, then just ask — kipmox’s tools are called automatically:1
Call analyze_code
kipmox returns the findings — rule, line, and a remediation hint for each.
2
Write the fix
Your agent uses the findings to write the change.
3
Call verify_fix
kipmox re-checks the fix against the original and returns a verdict — checks-passed, review-recommended, validation-failed, or unable-to-verify — before the change is applied.
kipmox verifies the fix before it’s applied. If the verdict isn’t clean, a good prompt tells the agent to rewrite and re-verify until it passes — see
verify_fix.Configuration
All configuration is via environment variables in your MCP server’senv block.
Tools
What analyze_code and verify_fix take, and the verdicts
Troubleshooting
Server not showing up, sign-in, and custom rules