# How to connect an MCP security tool to your AI editor

Set up Hi AUDIT through your account, connect a compatible MCP client, and check the analysis workflow before sharing a sensitive repository.

Canonical: https://hiaudit.io/en/guides/mcp-security-setup
Hi AUDIT documentation · Updated: 2026-10-03

## The practical answer

Create or sign in to a Hi AUDIT account, open Projects, and follow the installation guide supplied in your account. Configure your MCP client with those instructions, check that the expected tools are available, and begin with a small repository you are authorized to analyze. Keep installation credentials private and review the tool’s data handling before connecting confidential code.

Who this is for: Developers and team leads connecting Hi AUDIT to an AI editor for the first time.

## What the MCP connection does

Model Context Protocol is a way for an AI application to connect to tools and context. The editor or application is the client; the connected service supplies the tools. In a security workflow, the client can request analysis and present findings alongside the developer’s work.

MCP support alone does not establish that a particular editor version supports every connection or authentication option. Check the instructions for your client and your account. A successful connection also does not prove that an analysis covers your entire application. Connectivity, analysis coverage, and the quality of a finding are separate checks.

## Prepare the account and review scope

Decide which repository and revision you intend to review, who owns that review, and whether the team permits its code to be processed by the service. Start with a small, non-sensitive project when learning the workflow. Record the language and framework so you can confirm relevant coverage rather than assuming that any repository will work.

- Use the intended account and the correct Projects context.
- Confirm the editor’s MCP support and the operating system used for installation.
- Ask which source files and metadata are transferred, where they are processed, and how retention and deletion work.
- Store credentials through the documented account and client settings. Do not paste them into public repositories, screenshots, or shared chat transcripts.

## Connect Hi AUDIT using the account guide

The public documentation links to the account’s installation tab. That page requires sign-in and may show instructions specific to the account, operating system, or client. Use its current commands and configuration.

1. Create an account or sign in at app.hiaudit.io. Follow any availability message shown on the signup page.
2. Open Projects and confirm that you are working in the intended account.
3. Open the installation guide at app.hiaudit.io/api-keys?tab=install while signed in. Follow the instructions for your client and operating system.
4. Open the client’s MCP settings. Check the connection state and the expected Hi AUDIT tools before beginning an analysis.
5. Run a first review on your authorized sample project, then inspect the result and any errors. Keep a record of the target revision and analysis configuration.

## Check the connection before expanding use

When the client does not show the service or its tools, compare the active configuration with the account guide. Check the selected account, the client version, the credential state, and any network restrictions. Restart or reconnect only as the client’s documentation directs. A general chat response is not evidence that the security tool actually ran.

When asking for support, describe the client and operating system, the stage that failed, and a redacted error message. Do not send tokens or an entire confidential repository as a troubleshooting shortcut. Once the connection works, review findings with the same ownership and validation process you use for other security tools.

| Check | Evidence to look for |
| --- | --- |
| Connection | The MCP client reports the configured service as available. |
| Tool execution | An analysis result or explicit tool error identifies what was requested. |
| Review context | The target repository, revision, and configuration are recorded. |
| Next action | A person owns the finding review and subsequent validation. |

## Common questions

### Does connecting an MCP server automatically make my code secure?

No. The connection enables access to tools. You still need to establish coverage, inspect results, review proposed changes, and validate application behavior.

### Where do I get the installation command?

Use the installation tab in your signed-in Hi AUDIT account. The public documentation links to it; account credentials and client configuration should come from that current guide.

### Can I connect a confidential repository immediately?

First confirm your organization’s approval and the service’s data handling and contractual terms. Use a non-sensitive sample to learn the connection and review workflow.

## Sources and further reading

- [Hi AUDIT installation documentation](https://hiaudit.io/en/docs#install)
- [Hi AUDIT product identity and limits](https://hiaudit.io/en/about)
- [Model Context Protocol introduction](https://modelcontextprotocol.io/docs/getting-started/intro)
