Can AI agents automate Checkmarx One?

Checkmarx · saas · developer-toolsquality-management

Checkmarx One is automatable today through the Checkmarx One REST APIs. This record is the Checkmarx One platform for SAST, SCA, IaC Security, and Secrets Detection, including the vendor-hosted Checkmarx MCP. It is not Snyk, Semgrep, or Black Duck Signal. Checkmarx MCP is not a standalone product; vendor docs require an active Checkmarx One tenant. REST calls use Authorization: Bearer after exchanging an API Key or an OAuth client for an access token. Documented REST flows include POST /api/uploads, zip upload, POST /api/scans, GET /api/scans/{scanId}, and GET /api/results. Vendor docs state REST APIs cover project and application CRUD, scans, results, vulnerability management, and webhook creation. Container Security results are called out as GraphQL on a separate article that was not used for kinds. The official cx CLI wraps those REST tasks, installs on Windows, Linux, and macOS (and as checkmarx/ast-cli), and authenticates with interactive login, API Key, or OAuth client credentials. `cx results show` writes JSON by default and can emit SARIF. The hosted MCP is at {CX_BASE_URL}/api/security-mcp/mcp, with OAuth tenant URLs under /mcp/{tenant_name}. MCP auth is API Key, predefined client cx-mcp-client, or Dynamic Client Registration. Documented MCP tools cover scan workflow, findings, projects, applications, and licensed remediation. Vendor limits: initial-phase tools, no triage state changes, scanners limited to SAST/SCA/IaC/Secrets, local directory scanning needs the CLI, and remediation tools need Assist / AI Protection / Developer Assist. Outbound tenant webhooks exist for completed, failed, and partial scans and project created. iPaaS catalogs were not opened. Computer-use viability is unassessed. API and CLI both score 8. API is the best path because it is the native contract the CLI wraps and the MCP translates, with no extra binary for remote tenant automation.

Best path today: api · Overall automatability: 8/10

Modalities

ModalityStatusDetail
APIyesrestapi-keyoauth-client
coverage: partial · docs
SDKunknown
official: unknown
MCPyes
verdict: official
Integrationsunknown
CLIyes
Extensibilityyes
webhooks: True
Data access
export: json, sarif · import: unknown
RPA / UI automationunknownweb-dom
No repeatable UI probe was run. Checkmarx One's REST APIs, official cx CLI, outbound webhooks, and hosted first-party MCP cover scan and findings automation without browser control.
Computer useunknown
measured verdicts only — "unknown" means not yet probed by us

Scores

apimcpintegrationsclirpacomputer useoverall
8788

Evidence

FactTierSourceDate
homepagedeclaredsource2026-09-06
licensedeclaredsource2026-09-06
platformsdeclaredsource2026-09-06
modalities.api.existsdeclaredsource2026-09-06
modalities.api.kinds[0]declaredsource2026-09-06
modalities.api.auth[0]declaredsource2026-09-06
modalities.api.auth[1]declaredsource2026-09-06
modalities.api.coveragedeclaredsource2026-09-06
modalities.mcp.first_partydeclaredsource2026-09-06
modalities.mcp.first_partydeclaredsource2026-09-06
modalities.cli.existsdeclaredsource2026-09-06
modalities.extensibility.webhooksdeclaredsource2026-09-06
modalities.data_access.export[0]declaredsource2026-09-06
modalities.data_access.export[1]declaredsource2026-09-06
modalities.agent_docs.llms_txtdeclaredsource2026-09-06
verdict.scores.apideclaredsource2026-09-06
verdict.scores.mcpdeclaredsource2026-09-06
verdict.scores.clideclaredsource2026-09-06
freshness.watch[0].urldeclaredsource2026-09-06
freshness.watch[1].urldeclaredsource2026-09-06
freshness.watch[2].urldeclaredsource2026-09-06
freshness.watch[3].urldeclaredsource2026-09-06

Related tools

Other products in this database that share a category with Checkmarx One.

Last verified 2026-09-06 · volatility high · JSON record