
Security News
Ruby's Bundler 4.0.18 Extends Cooldown to bundle lock and bundle cache
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.
mcp-server-codecov
Advanced tools
MCP server for querying Codecov coverage data with configurable URL support
A Model Context Protocol (MCP) server that provides tools for querying Codecov coverage data. Supports both codecov.io and self-hosted Codecov instances with configurable URL endpoints.
📦 Published on npm: mcp-server-codecov
📖 Learn More: Read about building this MCP server with AI in just 2 hours.
Get started in under 2 minutes:
Create an API token (not an upload token) from your Codecov account:
Add to your shell profile (~/.zshrc or ~/.bashrc):
export CODECOV_TOKEN="your-api-token-here"
Then reload: source ~/.zshrc
claude mcp add --transport stdio codecov \
--env CODECOV_BASE_URL=https://codecov.io \
--env CODECOV_TOKEN=${CODECOV_TOKEN} \
-- npx -y mcp-server-codecov
claude mcp get codecov
Expected output: codecov: mcp-server-codecov - ✓ Connected
That's it! You can now use Codecov tools in Claude Code. See Available Tools below.
Important: Codecov has two different types of tokens:
This MCP server requires an API token, not an upload token.
Get line-by-line coverage data for a specific file.
Parameters:
owner (required): Repository owner (username or organization)repo (required): Repository namefile_path (required): Path to the file within the repository (e.g., 'src/index.ts')ref (optional): Git reference (branch, tag, or commit SHA)Example:
Get coverage for src/index.ts in owner/repo on main branch
Get coverage data for a specific commit.
Parameters:
owner (required): Repository ownerrepo (required): Repository namecommit_sha (required): Commit SHAExample:
Get coverage for commit abc123 in owner/repo
Get overall coverage statistics for a repository.
Parameters:
owner (required): Repository ownerrepo (required): Repository namebranch (optional): Branch name (defaults to repository's default branch)Example:
Get overall coverage for owner/repo on main branch
Get coverage data for a specific pull request, including coverage changes and file-level impact.
Parameters:
owner (required): Repository owner (username or organization)repo (required): Repository namepull_number (required): Pull request numberExample:
Get coverage for pull request #123 in owner/repo
Use Cases:
Compare coverage between two git references (branches, commits, or tags).
Parameters:
owner (required): Repository owner (username or organization)repo (required): Repository namebase (required): Base reference (e.g., 'main', commit SHA)head (required): Head reference to compare against baseExample:
Compare coverage between main branch and feature-branch in owner/repo
Use Cases:
Important Note: Before a repository can receive coverage uploads, it must be activated in Codecov. This is a one-time setup step that cannot be automated via API.
To activate a repository for coverage tracking:
Why manual activation is required: The Codecov API v2 does not provide a /activate endpoint. Repository activation must be done through the web UI or happens automatically on first coverage upload (depending on your Codecov configuration).
1. 401 Unauthorized Error
CODECOV_BASE_URL2. Environment Variable Not Expanding
~/.zshrc or ~/.bashrc)echo $CODECOV_TOKEN3. Connection Failed
echo $CODECOV_TOKENclaude mcp get codecov4. HTTP vs HTTPS
Always use https:// for the CODECOV_BASE_URL, not http://:
https://your-codecov-instance.comhttp://your-codecov-instance.comFor self-hosted Codecov instances, use your instance URL:
claude mcp add --transport stdio codecov \
--env CODECOV_BASE_URL=https://codecov.your-company.com \
--env CODECOV_TOKEN=${CODECOV_TOKEN} \
-- npx -y mcp-server-codecov
Add to your Claude Desktop configuration file:
macOS: ~/Library/Application Support/Claude/claude_desktop_config.json
Windows: %APPDATA%\Claude\claude_desktop_config.json
{
"mcpServers": {
"codecov": {
"command": "npx",
"args": ["-y", "mcp-server-codecov"],
"env": {
"CODECOV_BASE_URL": "https://codecov.io",
"CODECOV_TOKEN": "your-codecov-token-here"
}
}
}
}
Add to ~/.claude.json:
{
"mcpServers": {
"codecov": {
"command": "npx",
"args": ["-y", "mcp-server-codecov"],
"env": {
"CODECOV_BASE_URL": "https://codecov.io",
"CODECOV_TOKEN": "${CODECOV_TOKEN}"
}
}
}
}
Notes:
${VAR} syntax${CODECOV_TOKEN} will be read from your shell environment-y flag for npx automatically accepts the package installation promptnpm install -g mcp-server-codecov
Benefits:
npm update -g mcp-server-codecovVerify installation:
npm list -g mcp-server-codecov
which mcp-server-codecov
npm view mcp-server-codecov version
Only use this method if you're contributing to the project:
git clone https://github.com/egulatee/mcp-server-codecov.git
cd mcp-server-codecov
npm install
npm run build
Then configure with the built path:
Claude Code CLI:
claude mcp add --transport stdio codecov \
--env CODECOV_BASE_URL=https://codecov.io \
--env CODECOV_TOKEN=${CODECOV_TOKEN} \
-- node /absolute/path/to/codecov-mcp/dist/index.js
Manual (~/.claude.json):
{
"mcpServers": {
"codecov": {
"command": "node",
"args": ["/absolute/path/to/codecov-mcp/dist/index.js"],
"env": {
"CODECOV_BASE_URL": "https://codecov.io",
"CODECOV_TOKEN": "${CODECOV_TOKEN}"
}
}
}
}
Claude Desktop:
{
"mcpServers": {
"codecov": {
"command": "node",
"args": ["/path/to/mcp-server-codecov/dist/index.js"],
"env": {
"CODECOV_BASE_URL": "https://codecov.io",
"CODECOV_TOKEN": "your-codecov-token-here"
}
}
}
}
This project maintains 97%+ code coverage with comprehensive unit tests using Vitest.
For detailed testing documentation, including how to run tests, coverage requirements, CI integration, and writing tests, see TESTING.md.
# Install dependencies
npm install
# Build the project
npm run build
# Watch mode for development
npm run watch
This project uses an automated release workflow via GitHub Actions. Releases are published to npm automatically when you push a version tag.
For detailed release instructions, including prerequisites, creating releases, manual releases, and version numbering, see RELEASE.md.
This server uses Codecov's API v2. The API endpoints follow this pattern:
/api/v2/gh/{owner}/repos/{repo}/file_report/{file_path}/api/v2/gh/{owner}/repos/{repo}/commits/{commit_sha}/api/v2/gh/{owner}/repos/{repo}/api/v2/gh/{owner}/repos/{repo}/pulls/{pull_number}/api/v2/gh/{owner}/repos/{repo}/compare/{base}...{head}Currently supports GitHub repositories (gh). Support for other providers (GitLab, Bitbucket) can be added by modifying the API paths.
MIT
FAQs
MCP server for querying Codecov coverage data with configurable URL support
We found that mcp-server-codecov demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.

Security News
During a UK cyber test, a Mythos 5 agent used sockpuppets, social engineering, and prompt injection to try to get a maintainer to merge malware.

Company News
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.