Connect your agent to Pensec.

Manage websites directly under an organization. Create tasks, request assessments, add external results to your dashboard, read statistics, and subscribe to email events.

Remote MCP

Add https://mcp.pensec.app/mcp to your MCP client. OAuth-capable clients open your browser for Pensec sign-in and consent. Choose account, organization, or selected website access.

For server-to-server or CI access, configure an organization or website key as an Authorization: Bearer header through your client's secret manager.

API keys

Open dashboard → API & agents → API keys. Choose organization-wide or one-website access, permissions, and expiry. Keys are shown once and can be revoked or rotated. A website key cannot create organizations or access another website.

Schema-driven REST API

Base URL: https://api.pensec.app/v1. Read the OpenAPI JSON contract. Route registration, validators, client operation names, reference documentation and MCP tools are generated from the same JSON source.

GET /v1/organizations
GET /v1/organizations/{organizationId}/websites
GET /v1/websites/{websiteId}/stats
POST /v1/websites/{websiteId}/tasks
POST /v1/websites/{websiteId}/assessment-requests
POST /v1/websites/{websiteId}/external-runs

Use an Idempotency-Key header for supported mutations. Reusing a key with different input returns a conflict. Task updates require expectedVersion. List endpoints expose bounded pagination; follow nextCursor for additional pages.

Tasks and imported results

Tasks record remediation work and comments. Task completion does not verify a deployed fix. External runs retain tool/version, deployment, timestamps, coverage limits and evidence provenance. Imported findings are candidates, not expert-reviewed Pensec findings. Reports preserve immutable editions and their actual review status.

Notifications

Configure email or signed webhook subscriptions in API & agents → Notifications. Inspect pending, sent or failed deliveries and retry failed attempts. Webhook destinations require a provisioned public hostname; notification delivery depends on the configured provider.

Agent skill and local tooling

Load the Pensec agent skill. The repository includes a local CLI/stdio MCP entrypoint at dashboard/tools/pensec.mjs. Run node tools/pensec.mjs login from the dashboard directory for browser approval, or node tools/pensec.mjs mcp for stdio. Browser-login credentials are saved in the OS keychain through Seal. This source distribution is not a published npm package.

Execution and review

Assessment requests do not start scans. Managed automated runs currently use the mocked runner. Application assessments are security expert-led; planned agent-led recurring checks have expert review once weekly on either schedule. API or MCP access does not change testing authority, scope or review readiness.

Connect your agent