Wiz is a cloud security platform that gives security teams a single view of the risks across their cloud environments, from misconfigurations and exposures to vulnerabilities and threats.
Agen.co connects to Wiz through Wiz's own hosted MCP server as an Official connector. Each user signs in with their own Wiz account, so there is no app to register and no credentials to copy. The connector requests read-only access, so agents can query your Wiz data but cannot change anything in Wiz.
Prerequisites
Prerequisites
- A Wiz tenant where the Remote MCP Server is turned on. In Wiz, go to Settings → Tenant → AI Features and enable it before you connect. Without it, the connection is not accepted.
- A Wiz account for each person whose agents will use the connector.
- Your tenant's Wiz environment: production tenants use
app.
Wiz registers Agen.co automatically, so there is no client ID or secret to copy and no callback URL to register.
In the Agen.co portal, go to Connectors → My connectors and click Add connector.
In the Select connector drawer, search for
Wizand select it. The Add Wiz panel opens.Fill in the fields:
Field Required Description Instance Slug Yes Namespaces this instance — it prefixes each imported tool as slug__tool, so several instances of the same MCP can coexist. Prefilled withwiz. Use lowercase kebab-case. You can change it later from the connector's settings.Wiz environment Yes The Wiz environment hosting your tenant — appfor production. Options:app(Production - mcp.app.wiz.io, the default),demo(Demo - mcp.demo.wiz.io), ortest(Test - mcp.test.wiz.io).Click Connect. Wiz opens in a new tab, and the panel shows Waiting for authorization — complete it in the opened tab…
Sign in to your Wiz account and approve read access.
Back in Agen.co, the panel switches to Select the tools to import from Wiz. Every tool is toggled on; turn off any you don't want to import, then click Add.
The connector is created and its tools imported only when you click Add. If you close the panel before that, nothing is saved, even if the Wiz tab reported success.
Each connector instance connects to exactly one Wiz environment. To connect another environment, such as a demo tenant alongside production, add the Wiz connector again with a different Instance Slug and the other environment.
Agen.co requests Wiz's read:all scope, so agents can read the data your Wiz account can see — such as cloud inventory, configurations, and security issues.
The Wiz MCP server also offers a create:penetration_test_findings scope for submitting penetration test findings. Agen.co does not request it, so this connector cannot create findings.
Wiz keeps its tool list behind sign-in and does not publish one, so no tool table is given here. The tool selection screen that appears after Connect shows exactly what your account serves, and you can turn off any tool you do not want agents to use. Results are limited to what the signed-in Wiz user is allowed to see.
Enabling the Wiz connector isn't enough on its own. Tool calls remain denied until you create a policy that grants access to the specific tools you want to expose.