Base44
Build and edit Base44 apps from an AI assistant, and query data your app's users submit.
Read Pi Security findings, threat models and Code Gatekeeper reviews, and submit design reviews or reports back.
Opens Agent Studio, where connecting is one click. The connector URL below works in any MCP client.
Paste it into any MCP client. Setup docs
The Pi Security MCP server connects a Pi application-security tenant to Claude and any MCP-compatible agent. Its 21 tools read security findings, threat models, Code Gatekeeper pull-request reviews and secure-development playbooks, and five of them write back — starting design reviews, uploading reports and requesting remediation plans. Sign-in is OAuth against your own Pi tenant.
Verified connector
Listed by Anthropic as a partner connector in its Connectors Directory.
Connection checked by Agentman on .
Anthropic states this reflects the level of review a connector received, not a security audit.
Tool names from Anthropic's directory listing. This server requires sign-in, so we could not read tool descriptions or parameter schemas.
mcp:access is the only application scope either the resource or the authorization server advertises. You cannot grant the 16 read tools while withholding the 5 write tools — the consent screen has nothing to narrow. We did not find a narrower scope defined at Pi's platform level, but absence of evidence is not evidence Pi could not define one.readOnlyHint, destructiveHint, idempotentHint or openWorldHint. The read/write split above comes from Pi's documentation and from the tool names, not from the protocol. Treat it as well-sourced, not as machine-verified.file:// URIs, PDFs, DOCX files and images are rejected.pi.security and its subdomains and describes visitor data. Tenant data handling is governed by the separate Data Processing Agreement, which names Nebari Inc. as the processor.No. Every tool reads records already held in your Pi tenant — findings, threat models, Gatekeeper reviews, playbooks — not your repository. Pi ingests code through its own platform integrations, which you configure outside the connector. Pi's plugin documentation states plainly that Pi never edits your local code, and no tool in the listing takes file contents as input.
Yes, five of its twenty-one tools write to Pi. They start a design review from a URL or Markdown, upload a Markdown report, request generation of a package remediation plan, and record playbook feedback. All five create new records in your Pi tenant. None deletes anything, and none touches your repository, your code or any system outside Pi.
Call the whoami tool. Pi's setup documentation describes it as returning the authenticated subject, tenant and granted scopes without exposing credentials. Your tenant comes only from the OAuth session, so Claude cannot infer or switch it from your working directory, git remotes or anything you type. Re-authenticate if the tenant is wrong.
No. Pi's documentation restricts hosted submission to two shapes: a supported Confluence or Notion document URL, or content pasted inline as Markdown or plain text. Chat attachments, local file paths, file:// URIs, PDFs, DOCX files and images are not accepted. Use the Pi web app or Pi's CLI for those formats instead.
Exactly one, mcp:access. Pi's RFC 9728 descriptor and its authorization server both advertise that single scope and nothing else, verified on 2026-08-21. There is no read-only variant, so the consent screen offers no way to grant reads while withholding the five write tools. Granting access grants all twenty-one.
Yes. Sloane is Pi's own product name, used across pi.security and in Pi's CLI. The organisation's repositories carry contact@pi.security, point their homepage at pi.security, and declare the same endpoint the Anthropic directory lists. The directory's own author field independently names Pi Security at pi.security, so three sources agree.
b400427ad1efb91c3721669d26d3830c08ec4f0c (retrieved 2026-08-21) · retrieved 2026-08-21initialize returning 401 with WWW-Authenticate (2026-08-21) · retrieved 2026-08-21scopes_supported and claims — auth.pi.security OAuth 2.0 / OpenID discovery documents (retrieved 2026-08-21) · retrieved 2026-08-21registry.npmjs.org (retrieved 2026-08-21) · retrieved 2026-08-21www.pi.security/robots.txt — served 200 with an empty body, so no crawl restriction and no Content-Signal (retrieved 2026-08-21) · retrieved 2026-08-21Connect Pi Security once and your agents call these tools on their own: on a schedule, in a workflow, with nobody at the keyboard.