Skip to main content
Claude Code is the recommended Semgrep Guardian setup. It uses Semgrep’s hosted remote server and authenticates through OAuth, so you do not need a local Semgrep CLI. If you use a different coding agent, see Choose your setup.

Prerequisites

  • A Semgrep account
  • Claude Code installed (claude command)
For Windows machines: Windows Subsystem for Linux (WSL) is required. Native Windows is unsupported.

Set up Guardian

1

Install the plugin

Install the Guardian plugin from the Claude Marketplace:
2

Sign in to Semgrep

Start a new Claude Code session:
You are prompted to log in to Semgrep through your browser. This is a one-time login; Semgrep refreshes access tokens automatically, so you rarely need to sign in again.
This integration uses Claude Code hooks and plugins. By default it uses Semgrep’s hosted remote server, so you don’t need to install the Semgrep CLI locally.

Next steps