
Research
/Security News
Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack
Popular npm packages keyv and cacheable compromised.
@qase/mcp-server
Advanced tools
Official Model Context Protocol (MCP) server for Qase Test Management Platform — connect AI assistants to your test cases, runs, defects, and more.
The Qase MCP Server lets AI assistants (Claude, Cursor, Codex, and any other MCP client) read and write Qase test cases, runs, results, defects, suites, milestones, and more — through a standardized protocol, with no custom integration code.
Features:
qase_discover_tools) — consolidated from 83 v1 tools for lower token usage and better LLM accuracyhttps://mcp.qase.io/mcp with just your Qase login, or run the server locally with your own API tokenqase_api| Scenario | Example prompt | Tool |
|---|---|---|
| Bootstrap project context | "Show me the structure of project DEMO — suites, milestones, environments" | qase_project_context |
| Create or update a test case | "Create a high-priority smoke test case in project DEMO titled 'Login with valid credentials'" | qase_case_upsert |
| Report CI results | "Report these CI results for project DEMO: case 1 passed, case 2 failed with 'timeout error'" | qase_ci_report |
| Triage a failed test | "Create a critical defect for the login timeout failure in run #42" | qase_triage_defect |
| Search with QQL | "Find all failed test results from the last 7 days in project DEMO" | qql_search |
See Tools and docs/tools.md for the full reference.
No install, no API token — connect to the Qase-hosted server and sign in with your Qase account.
Note: The hosted Qase MCP is available on the Enterprise plan in Qase. On other plans, run the server yourself with your own API token.
{"mcpServers": {"qase": {"url": "https://mcp.qase.io/mcp"}}} to .cursor/mcp.json.https://mcp.qase.io/mcp in Settings → MCPs → Add server, or configure ~/.codex/config.toml for the CLI.{"servers": {"qase": {"type": "http", "url": "https://mcp.qase.io/mcp"}}} to .vscode/mcp.json, or run MCP: Add Server.Full per-client steps, other clients, and the active-workspace model: docs/connect.md.
Install the package and provide your own API token:
npm install -g @qase/mcp-server
export QASE_API_TOKEN=your_api_token_here
Then point your MCP client's stdio config at the @qase/mcp-server binary. Full install options, client configs (Claude Desktop, Cursor, Claude Code, Codex, OpenCode), environment variables, and transports (stdio/SSE/streamable-HTTP): docs/self-run.md.
v2 consolidates 83 v1 tools into 29 task-oriented tools (30 total, including a discovery tool). Tool names and response shapes have changed. See MIGRATION.md for the complete tool mapping table, response format changes, and before/after examples.
30 tools across 6 groups (29 task-oriented tools plus qase_discover_tools for on-demand activation of secondary tools):
| Group | Count | Description |
|---|---|---|
| Read | 2 | Fetch any entity by type/ID, or bootstrap full project context in one call |
| QQL | 2 | Search across cases, runs, results, defects, and plans with Qase Query Language |
| Write | 21 | Create, update, and delete cases, runs, results, defects, suites, milestones, plans, shared steps, environments, and attachments |
| Composite | 3 | Multi-step workflows in one call: CI reporting, defect triage, regression run setup |
| Escape hatch | 1 | Direct REST API access for any endpoint not covered by the tools above |
| Meta | 1 | qase_discover_tools — find and activate secondary tools on demand |
Full tool-by-tool reference with parameters and the discovery model: docs/tools.md.
Contributions are welcome! See CONTRIBUTING.md for development setup, testing, and linting guidelines.
MIT License — see LICENSE for details.
FAQs
Official MCP server for Qase Test Management Platform
The npm package @qase/mcp-server receives a total of 2,191 weekly downloads. As such, @qase/mcp-server popularity was classified as popular.
We found that @qase/mcp-server demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Popular npm packages keyv and cacheable compromised.

Security News
A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to PyPI.

Security News
/Company News
Socket has joined the new Composer and Packagist sponsorship program as a launch sponsor, supporting the team that keeps PHP's package ecosystem secure.