Skip to content
RingZero shield inside concentric rings

RingZero developer docs

Trust every MCP server your agents load — scan, allowlist, and audit them with the ringzero-mcp CLI. Then wire RingZero into your builds and infrastructure for dependency scanning and verified-ownership security scanning.

MCP security

Scan every MCP server your agents load — across Claude Code, OpenCode, VS Code, Cursor, and Claude Desktop — enforce an org allowlist, and audit real usage, all from the ringzero-mcp CLI.

MCP security overview →

Supply chain scanning

Map every open-source package your projects pull in — direct and transitive — and flag vulnerable versions with CVE and fixed-version data. Upload dependency snapshots straight from your Gradle builds, or integrate with the REST API directly.

Gradle plugin guide →

Security scanning

RingZero’s scan agents only ever touch infrastructure you can prove you own. Deploy the RingZero sidecar next to your app to register the host with your organization and make it eligible for scanning.

How host registration works →

Least-privilege credentials

Every API key is scoped — explicit permissions and a project restriction, fixed at creation. No credential grants org-wide access, so a leaked CI key never compromises your org.

Authentication & permissions →

One API

Everything talks to https://api.ringzero.tech/v1 with bearer authentication and JSON bodies — the same API our own build plugins and sidecar use.

REST API reference →


New to RingZero? The product overviews on the main site explain what each capability does and why: MCP security · AI penetration testing · supply chain security · automated remediation