Listing Thumbnail

    Wiz MCP Server

     Info
    Sold by: Wiz 
    Deployed on AWS
    The Wiz Model Context Protocol (MCP) Server acts as an MCP-compatible service that translates plain-language queries into Wiz-specific operations, like querying resources, or assessing risks.
    4.7

    Overview

    The Wiz Model Context Protocol (MCP) Server elevates the impact of Wiz's security offerings by providing a unified security data source, enhanced cloud visibility, and contextual intelligence. The MCP Server connects multiple security data sources through a central host and server setup, creating a single, contextual view of the security posture to simplify investigations and accelerate incident response and remediation. It offers instant access to cloud inventory, configurations, and security issues via a single host with a simple prompt. By enriching security investigations with precise business context, the MCP Server allows security teams to prioritize responses based on relevance, drastically improving the accuracy and effectiveness of threat mitigation. The Wiz MCP Server enhances Wiz Code by translating plain-language queries into powerful workflows, streamlining everything from issue discovery to pull request creation. Integrated with Wiz Defend, the MCP Server helps security teams identify and contain active threats faster with AI generated insights and action paths.

    Highlights

    • Unified security data source for cloud security posture.
    • Completed visibility into cloud inventory, configurations, and security issues
    • Contextual intelligence that enriches security investigations with context, enabling security teams to prioritize responses to critical threats.

    Details

    Sold by

    Delivery method

    Type

    Supported services

    Delivery option
    v0.1.1s

    Latest version

    Operating system
    Linux

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Trust Center

    Trust Center
    Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Wiz MCP Server

     Info
    This product is available free of charge. Free subscriptions have no end date and may be canceled any time.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    Vendor refund policy

    n/a

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    v0.1.1s

    Supported services: Learn more 
    • Amazon Bedrock AgentCore
    Container image

    Containers are lightweight, portable execution environments that wrap server application software in a filesystem that includes everything it needs to run. Container applications run on supported container runtimes and orchestration services, such as Amazon Elastic Container Service (Amazon ECS) or Amazon Elastic Kubernetes Service (Amazon EKS). Both eliminate the need for you to install and operate your own container orchestration software by managing and scheduling containers on a scalable cluster of virtual machines.

    Version release notes

    We are excited to share that the Wiz Model Context Protocol (MCP) Server is now available in the new AWS Marketplace AI Agents and Tools category.

    The Wiz Model Context Protocol (MCP) Server is an innovative implementation that enables any MCP-compatible, LLM-powered application to interact with Wiz using plain language. It unifies diverse security data sources into a single, contextual view of your cloud security posture. This empowers teams to gain instant access to cloud inventory, configurations, and security issues, facilitating real-time cloud investigations, blast radius assessments, and AI-driven remediation actions through natural language prompts.

    Additional details

    Usage instructions

    To allow the Wiz Model Context Protocol (MCP) Server to access your Wiz tenant, you need to configure specific environment variables.

    Steps to Configure Wiz MCP Integration:

    Navigate to Integrations in Wiz:

    1. In the Wiz console, go to the Connect to Wiz > Integrations page. 2. Under the "Security Data Management" section, choose Wiz MCP. 3. On the "New Wiz MCP Integration" page: Enter a Display Name. Keep the default API scopes (Recommended). Click Add Integration. 4. After creation, copy the generated Client ID and Client Secret. These are crucial for authentication.

    Set Environment Variables:

    1. Using AWS CLI:

    Add the Client ID and Client Secret using the --environment-variables flag in your deployment command.

    --environment-variables '{ "WIZ_CLIENT_ID":"your_client_id", "WIZ_CLIENT_SECRET":"your_client_secret" }'

    2. Using GUI for Host Agent Deployment:

    If you are deploying via AWS Console GUI, 1) Click "Use on Amazon Bedrock AgentCore" 2) Click "Host Agent" add these variables under the "Advanced configurations" section.

    For more detailed instructions and customer-specific access, please refer to the official documentation at https://docs.wiz.io/docs/set-up-wiz-mcp-server  (Wiz customer access only).

    AWS command line examples:

    1. Create an agent/MCP server This command creates a new agent runtime for the Wiz MCP server. Ensure you replace placeholders like 'your AmazonBedrockAgentCoreRuntimeDefaultServiceRole arn', '{your wiz client id}', and '{your wiz client secret}' with your actual values.

    aws bedrock-agentcore-control create-agent-runtime --region us-east-1
    --agent-runtime-name "wiz-mcp-server-stateless"
    --description "Wiz MCP server"
    --agent-runtime-artifact '{ "containerConfiguration": { "containerUri": "709825985650.dkr.ecr.us-east-1.amazonaws.com/wiz/wiz-mcp:v0.1.1-stateless" } }'
    --role-arn "your AmazonBedrockAgentCoreRuntimeDefaultServiceRole arn"
    --network-configuration '{ "networkMode": "PUBLIC" }'
    --protocol-configuration '{ "serverProtocol": "MCP" }'
    --environment-variables '{ "WIZ_CLIENT_ID": "{your wiz client id}", "WIZ_CLIENT_SECRET": "{your wiz client secret}", "Wiz_MCP_TRANSPORT": "http", "Wiz_MCP_PORT": "8000", "Wiz_MCP_HOST": "0.0.0.0" }'

    1. List Agent Runtime Use this command to retrieve details about the created agent runtime. Replace '{your agentRuntimeId in the output of create command}' with the actual ID from the previous step.

    aws bedrock-agentcore-control get-agent-runtime
    --agent-runtime-id {your agentRuntimeId in the output of create command}
    --region us-east-1

    1. List Agent Runtime Endpoints This command lists the endpoints associated with your agent runtime. Replace '{your agentRuntimeId in the output of create command}' with the actual ID.

    aws bedrock-agentcore-control list-agent-runtime-endpoints
    --agent-runtime-id {your agentRuntimeId in the output of create command}
    --region us-east-1

    1. Invoke Agent Runtime This command invokes the agent runtime to perform an action, e.g., listing tools. Replace '{your agentRuntimeArn in the output of create command}' with the actual ARN.

    PAYLOAD_JSON='{"jsonrpc": "2.0", "id": 1, "method": "tools/list", "params": { "_meta": { "progressToken": 1}}}' PAYLOAD_BASE64=$(echo -n "$PAYLOAD_JSON" | base64) AGENT_ARN={your agentRuntimeArn in the output of create command}

    aws bedrock-agentcore invoke-agent-runtime
    --agent-runtime-arn "${AGENT_ARN}"
    --payload="${PAYLOAD_BASE64}"
    --content-type "application/json"
    --accept "application/json, text/event-stream"
    --qualifier "DEFAULT"
    "output.json"

    Resources

    Vendor resources

    Support

    Vendor support

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Similar products

    Customer reviews

    Ratings and reviews

     Info
    4.7
    835 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    84%
    15%
    1%
    0%
    0%
    0 AWS reviews
    |
    835 external reviews
    External reviews are from G2 .
    Facilities Services

    Clean UI, Powerful Cloud Visibility, and a Great CLI for CI/CD Security

    Reviewed on Jul 29, 2026
    Review provided by G2
    What do you like best about the product?
    What I like best about Wiz is its clean and intuitive user interface, which makes it easy to navigate across projects, cloud environments, and security findings.

    The project management capabilities are especially useful for organizing assets, separating environments, assigning ownership, and tracking remediation progress.

    Wiz CLI is another major advantage because it allows security checks to be integrated directly into developer workflows and CI/CD pipelines, helping identify vulnerabilities, secrets, misconfigurations, and other risks before deployment.

    The findings are clearly presented, prioritized by risk, and supported with useful context such as affected resources, attack paths, remediation guidance, and business impact.

    Overall, Wiz provides strong visibility across the cloud environment, reduces the time required to investigate findings, and helps security and engineering teams collaborate more effectively.
    What do you dislike about the product?
    I cant open jira tickets for all the findings only for issues.
    What problems is the product solving and how is that benefiting you?
    Vulnerability and patch management,
    Perfromance increase,
    All in one product
    Retail

    Powerful Attack-Path Visibility and AI Querying, but MCP and Jira Traceability Need Work

    Reviewed on Jul 29, 2026
    Review provided by G2
    What do you like best about the product?
    Wiz excels at cloud security posture visibility and attack path analysis. It clearly shows the complete access path from the internet to internal resources — not just a list of alerts, but actual exploitable paths. We have it integrated with AWS, GCP, GitHub, and Jira, and the integrations work smoothly for tracking findings through to remediation.

    The MCP integration with Claude AI is a standout feature — we can query security findings in natural language in real time, which saves the security team significant time compared to manually navigating the console. Being able to ask "is this asset exposed to the internet?" and get an immediate, accurate answer with full network path details is genuinely useful.
    What do you dislike about the product?
    The MCP API connection can drop mid-response when querying large datasets — for example, querying all HIGH/CRITICAL findings across the environment (140,000+ results) caused timeouts. Filtering options help, but better handling of large result sets would improve the experience. VPC Flow Logs visibility could also be surfaced more prominently in the UI when they are disabled, as this is an important gap for network traffic auditing. Additionally, reverse-lookup from a Jira ticket number to the corresponding Wiz resource is unreliable — sometimes the linked asset cannot be found, which breaks the traceability workflow between ticketing and security findings.
    What problems is the product solving and how is that benefiting you?
    Before Wiz, we lacked unified visibility across our AWS and GCP environments — we couldn't easily tell which assets were internet-exposed or had exploitable attack paths without waiting for external penetration test results. Wiz solved this by providing continuous, agentless scanning with clear attack path visualization. Since integrating Wiz with Claude AI via MCP, our security team can query findings in natural language in real time, significantly reducing the time spent navigating the console manually. This has shifted us from reactive (finding issues only during annual pentests) to proactive security posture management.
    Transportation/Trucking/Railroad

    Feature-Rich, User-Friendly Security Insights with Phenomenal Wiz Support

    Reviewed on Jul 29, 2026
    Review provided by G2
    What do you like best about the product?
    Feature-rich, with actionable reports that help remediate security exposure across multiple platforms. The interface and its built-in AI tool make it very user-friendly, even for non-technical users.

    Both Pre and Post sale support from Wiz team are phenomenon.
    What do you dislike about the product?
    I have not come across anything to dislike yet.
    What problems is the product solving and how is that benefiting you?
    It provides actionable exposure management and risk management across our environment.
    Food & Beverages

    Single-Pane Visibility for Overall Environment and Security Posture

    Reviewed on Jul 28, 2026
    Review provided by G2
    What do you like best about the product?
    A single-pane view that shows me what I need to know about my overall environment and security posture.
    What do you dislike about the product?
    There’s a big learning curve to fully understand how Wiz works, since it provides a vast amount of information.
    What problems is the product solving and how is that benefiting you?
    For us, it helped eliminate some of the tools we previously had to use separately, and in turn it helped us save costs.
    Information Technology and Services

    Wiz Helps Us Prioritize What Truly Matters

    Reviewed on Jul 28, 2026
    Review provided by G2
    What do you like best about the product?
    I like how Wiz helps prioritize what truly matters and needs to be fixed, rather than overwhelming teams with large volumes of difficult-to-manage findings.
    What do you dislike about the product?
    A key area for improvement is the limited functionality of ignore rules and custom threat detections. More advanced custom rules, ideally supporting correlation across multiple data sources, would be valuable.
    What problems is the product solving and how is that benefiting you?
    Wiz addresses most cloud security, CI/CD, and application security challenges by providing teams with the governance, visibility, and prioritization needed to manage risk effectively.
    View all reviews