Back to Helen

Add Helen to your IDE.

Helen is a remote MCP server. Connect it once and ask your SIEM questions from your agent. Sign-in is Descope OAuth— your client runs the login flow, so there’s no API key to paste. Read-only SIEM access uses your own credentials, added below (optional).

Pick your client

OAuth only

One-click install (opens Cursor and prompts to add Helen):

Or add it manually to ~/.cursor/mcp.json (or a project .cursor/mcp.json):

{
  "mcpServers": {
    "helen": {
      "url": "https://helen-mcp.dev.joon.co/mcp"
    }
  }
}

Prefer plain text? The same instructions live in CONNECTORS.md. One connector maps to one SIEM — add a second connector for a second SIEM.