Coding agents are great at functionality and syntax, but security is a different discipline. Salt Code gives your coding agent security expertise across APIs, MCP, LLM systems, and OpenAPI specs. Out of the box, no workflow changes required.
The gap between functional code and secure code is bigger than you think, and it grows with every AI-generated commit.
Of AI-generated code is syntactically correct
Of completed coding tasks introduce a security flaw
Of vibe-coded apps contain major vulnerabilities, averaging 7 per application
Sources: Veracode, 2026 GenAI Code Security Report; Deng, Fan & Meng, Understanding the (In)Security of Vibe-Coded Applications, 2026.
Add Salt Code once and your coding agent immediately becomes a security expert across API, MCP, LLM, and OpenAPI standards. No configuration. Active from your very next prompt.
Whether you're writing code, reviewing PRs, or owning AppSec policy. Salt Code works where you already work.
Let's configure your first coding agent.
Pick the one you use most. We'll give you a personalized setup in under 60 seconds. You can always add more later.
One field, no account setup. We use your work email to protect the free service from abuse and create your secure Salt Code access.
No password. No credit card. No token to copy.
Check and click the link to verify. We'll create your personal access token and provide you with personalized configuration instructions from there.
⚡ The link is only valid for 15 minutes — check your inbox now.
Follow the instructions below to install Salt Code into your coding agent. Your personal access token is shown below. Copy and store it somewhere safe. You can use it to configure any additional coding agents too. Every command already has your token embedded.
Your token was included in your setup confirmation email.
Using more than one coding agent? Click any card above to add Salt Code to it too.
Your coding agent is now an expert in API Security (OWASP Top 10), MCP Security, LLM Security, and OpenAPI Compliance — 40 guidelines, active from your very next prompt.
Please noteOn first use, your coding agent may ask you to authorize Salt Code tool permissions. Approve once, and you're set, no extra steps after that.
We're thrilled to put Salt Code in your hands, security expertise built into the assistants you already use, at no cost.
This is just the beginning. Tell us what works, what doesn't, and what you want next, your feedback shapes what we ship.
No catch. No credit card. All 40 policies, every supported coding agent. Free forever for individual use.
No. Salt Code injects security context into your agent's context window. Your code never leaves your machine.
No noticeable impact. Policy injection happens in the background with negligible latency.
Salt Code's purpose is to prevent insecure code from being generated in the first place. It injects security context directly into your agent's context window, so the code it writes is secure from the start — not flagged after the fact. Your coding agent can also reference Salt Code policies to review and fix existing code, making it useful for security hardening of code already written.
Yes, on the enterprise plan. Bring your own policy packs and push them to every developer's coding agent across your org.
No. Salt Code is a standalone free product. No existing account or contract needed.
No. DevSecOps teams use it in pipeline agents. AppSec teams use it to push their policies to the developer desktop.
Custom policy packs, org-wide management, prompt-time security reporting, SSO/SCIM, and dedicated support.