Connect your agent / MCP
When an AI SOC or security agent reaches an executable, payload, or firmware image, let it investigate the compiled code. Use our agents, bring your own through MCP/API, or let analysts work alongside them in the same persistent investigation.
Set up your connection
Authenticated MCP and hosted agents require Pro, with one active durable mission per account. Hosted runs require a provider key or available gateway funding; model and budget limits apply.
The Pro account endpoint discovers authorized sessions and routes every tool with an explicit session_id. Teams get one connection model without per-session credentials or hidden selected-session state.
| Connection | Use it for | Access |
|---|---|---|
/mcp/account over HTTP | Current stateless clients with OAuth | Pro | all visible sessions, using your role on each |
revspace-mcp over stdio | Installed local connector builds that need workstation file access | Pro | account tools plus local binary and PDB upload |
/mcp/v/<token> over HTTP | Pro-sponsored public shares with no viewer account | One shared session, always read-only |
session_id, so parallel calls cannot drift into the wrong binary./2026 remain available to older stateful clients.Claude Code and Codex
Add the account URL to your client, then sign in and approve the connection in your browser. Choose your client below.
Add - one account server across all your projects
claude mcp add --transport http --scope user reverser \
https://api.reverser.space/mcp/account
Authenticate - choose reverser, then authenticate
/mcp
Claude Code stores and refreshes the OAuth credentials for the remote server. Use --scope local instead if you want the connection only in the current project, or --scope project to share its URL through .mcp.json. Teammates authorize their own accounts.
Add - save the remote account server
codex mcp add reverser \
--url https://api.reverser.space/mcp/account
Authenticate - complete OAuth in the browser
codex mcp login reverser
Verify - inspect the saved connection
codex mcp list
Codex stores the server in ~/.codex/config.toml. The Codex CLI, IDE extension, and ChatGPT desktop app share that MCP configuration on the same Codex host. In either UI, open MCP servers and choose Authenticate if sign-in is still required; in the Codex terminal UI, use /mcp to inspect active servers.
Cursor, Windsurf, and other clients
Clients that support remote HTTP MCP and OAuth take the same endpoint. Add it in the client's MCP settings, then use its Connect or Authenticate action:
{
"mcpServers": {
"reverser": {
"url": "https://api.reverser.space/mcp/account"
}
}
}
https://api.reverser.space/mcp/v/<token>. The final segment is the capability; the viewer needs no account or header.Start working
Verify - check the connection in your client
claude mcp get reverser
claude mcp list
codex mcp list
Discover and analyze - start with list_sessions
List my reverser.space sessions. Find target.exe, start its
analysis if needed, wait until it is ready, then triage it
and explain the top-ranked function.
Continue working - every routed tool uses the returned session id
Rename FUN_00104020 to parse_header and document why.
Start a debug run and break on that function.
The account server lists the common tool surface once and requires session_id on routed calls. Analysis is asynchronous: ask for get_session until its status is ready. Writes such as write_notes and renames require editor access; debugger tools also require an enabled debugger and a role that can drive it.
Disconnect
claude mcp remove reverser
codex mcp remove reverser
Removing the client configuration disconnects that client. To revoke its OAuth tokens too, remove the connection under Settings → Agents in the reverser.space app.
When it does not connect
| Symptom | Cause |
|---|---|
| Server needs authentication | In Claude Code, open /mcp. In Codex, run codex mcp login reverser or choose Authenticate in MCP servers |
| Browser does not open | Use the authentication URL shown by the client and finish the flow in a browser on the same machine |
| Authentication fails after working | The connection was revoked or expired - authenticate the server again from the client |
| Agent cannot see a local file | Remote MCP cannot read workstation paths; upload the file through the app first |
| Write returns role_required | Your account is only a viewer on that target session |
| First call is slow | The session was idle and is reopening from its saved Ghidra project - it settles after a few seconds |
Open a session and ask your agent to investigate a function or behavior. Follow its findings into the code, correct any mistakes, and save your notes for the next analyst.