#190 · MCP, API, and CLI: Agents and Pipelines Finish the Fix Loop
Availability: General Availability
Your coding agent and your pipeline now run the whole triage-and-fix loop through Escape. Retests start from the MCP, and a failed scan finally fails the build.
Breaking Changes¶
- Tag update (API):
PUT /tags/{tagId}/{tagId}is gone. UsePUT /tags/{tagId}.escape-cli tags updatereturns a 404 until you upgrade the CLI. - Audit log filters (API):
actionandactoronGET /audit/logsmatch exactly, andactormatches the ID, not the email. Filters combine, so calls return fewer rows. Move partial and email searches tosearch. - Project slug (API):
PUT /projects/{id}now validatesslug(lowercase alphanumerics and hyphens, up to 256 characters). It used to ignore it. - Scan watching (CLI):
scans watchandscans start --watchexit non-zero on failed, canceled, or unfinished scans, and errors print to stderr. The GitHub Action now enforcesfail_on_severities(defaultHIGH). - Lists (MCP): List tools return 50 results plus
nextCursor.scans_watchis removed: poll withscans_get.
What's New¶
- Fix loop: Start and read retests, cancel scans, read problems, run manual workflows, and record a reason with severity changes.
- Reliable tools: Schemas match inputs and outputs, and long waits return a pollable result.
- More reach: Stats, audit logs, tags, asset updates, and role bindings are tools. Deletes and bulk changes need
confirm: true. - API and CI:
DELETE /projects/{id}andDELETE /roles/{id}respond, audit logs filter bytarget, and--fail-on-severitygates a scan.
MCP Server Docs → Scans CLI Docs →
What's next: AI remediation from the MCP, schema upload and conversion, and target validation before a scan.
Questions?¶
Have a question? Reach out on your dedicated support channel, or email us at support@escape.tech.