Model Context Protocol (MCP) scanning with DAST
Use manual explore workflows to test applications that use the Model Context Protocol (MCP) and analyze MCP tool calls during the scan.
AppScan now supports security testing for applications that use the Model Context Protocol (MCP). This capability is available through manual explore workflows and allows AppScan to capture traffic, analyze MCP tool calls, and perform a comprehensive security analysis for your integrations.
Workflow and configuration
- MCP scanning is supported through manual exploration workflows using tools such as Postman. For Postman-based workflows, use Postman version 11.42.3 or later.
- To use this capability, create a scan in AppScan Standard with the MCP template to ensure appropriate coverage for MCP-based traffic. Then, push it to HCL AppScan on Cloud through AppScan Connect.
- For AppScan Connect, first load the MCP template, then open Postman to perform manual crawling. You can then run the scan through AppScan Connect as usual.
Current limitations
- Direct import of Postman collections for MCP scanning is currently not supported because Postman cannot export collections that include MCP requests.
- The current implementation relies on a manual process and is intended as a specialized workflow for this release. Automatic scanning is planned for a future release.