Connect Claude Code
Run Poliogo inside Claude Code, with the same six tools available as CLI subcommands so CI hits the same code path.
npx poliogo-mcp initRun this in your project, then ask your agent to check your compliance. MCP access is included from the Starter plan.
How the connection works
- Run one commandnpx poliogo-mcp init registers the server in your editor, once per project.
- Ask your agentIt calls check_compliance and scans the workspace locally.
- Detection on demandRe-ask any time — or wire the same tools into CI as subcommands.
What it looks like once connected
An illustration of this connection inside your Poliogo dashboard — not live data.
Detected in this project
- Next.jsnext in package.json
- Pineconesrc/lib/vectors.ts
- OpenAIfetch to api.openai.com
- ResendRESEND_API_KEY in .env.example
Exact permissions requested
Every permission this connection asks for, named as Claude Code names it on its own consent screen — so you can compare this table to what you are shown.
| Permission | Grant | What it is used for |
|---|---|---|
| No account grant | Not requested | There is no OAuth step. The MCP server runs on your machine under your own user. |
| Workspace files | Read | Read locally, in the folder you ran the scan in. Nothing is uploaded. |
| Writing documents | Write | Only when you ask the agent to. generate_docs and install_pages write into your project, and you review the diff. |
Setting it up
What you do, and what you will be looking at while you do it.
Run the command in your project
It registers the Poliogo MCP server with Claude Code. No OAuth, no token — the scan happens on your machine.
Ask Claude about your compliance
“Is my app compliant?” It calls check_compliance, scans locally, and names the services your documents do not yet cover.
Let it write the documents
generate_docs and install_pages put your policies and their routes into the project. explain_clause will tell you why any individual clause is there, with the file and line it was proved from.
Use the same tools in CI
Every one of the six is also a CLI subcommand, so a pipeline runs the identical scan your editor ran. A build can fail on a new undisclosed service instead of shipping it.
Refresh the rules block
inject_rules maintains a fenced compliance block in CLAUDE.md and AGENTS.md, so the agent keeps new integrations declared as it writes them.
Choose how to scan your app
Pick one. We scan your code and settings to find the services your app uses — the scan keeps that list, not your files.
Generate your licence key
MCP Server Access
The licence key the poliogo-mcp package uses in Cursor, Windsurf and Claude Code. Included from Starter.
Copy it now — it is never shown again.
poliogo_••••••••••••••••••••••••Set it as POLIOGO_API_KEY in the environment your editor launches npx poliogo-mcp with.
Paste this into Claude Code
npx poliogo-mcp initCopyYour agent runs it and writes the server into .mcp.json — nothing else in that file is touched.
{
"mcpServers": {
"poliogo": {
"command": "npx",
"args": [
"-y",
"poliogo-mcp"
]
}
}
}Ask your editor to scan
What Poliogo detects from Claude Code
The right-hand column is the part worth reading: it is what this connection cannot reach even if we wanted it to.
What it reads
- The workspace open in your editor, scanned on your own machine.
- Manifests and source text, exactly as a repository scan reads them.
- Drift against the last snapshot your documents were generated from.
What it never reads
- Your source code. It never leaves the machine — only the list of detected services is sent.
- Anything outside the workspace you ran the scan in.
- Any file, unless you ask the agent to write the documents.
Ready to connect Claude Code?
The free plan covers one project with no credit card. You approve everything before a single document is written.
Poliogo is a compliance management platform, not a law firm. What it produces is not legal advice. See exactly what each connection reads.