Back to Helen
Add Helen to your IDE.
Helen is a remote MCP server. Connect it once and ask your SIEM questions from your agent. Sign-in is Descope OAuth— your client runs the login flow, so there’s no API key to paste. Read-only SIEM access uses your own credentials, added below (optional).
Pick your client
OAuth onlyOne-click install (opens Cursor and prompts to add Helen):
Or add it manually to ~/.cursor/mcp.json (or a project .cursor/mcp.json):
{
"mcpServers": {
"helen": {
"url": "https://helen-mcp.dev.joon.co/mcp"
}
}
}Prefer plain text? The same instructions live in CONNECTORS.md. One connector maps to one SIEM — add a second connector for a second SIEM.