Pro and Team plans
Connect your AI assistant (MCP)
hiccup is an MCP server: Claude Code, Claude Desktop, Cursor — anything that speaks the Model Context Protocol — can read your captures through the same tools hiccup's own chat uses. Your assistant does the reasoning with whatever model you pay for; hiccup supplies what it is authoritative about: the parsed messages, the deterministic findings, and advice with real citations.
What you need
- A Pro or Team account.
- An API token: Settings → AI assistant access (MCP) → name it after the machine it will live on → Create token. It is shown once; hiccup keeps only a hash.
https://hiccup.monster/mcp — POST only,
authenticated with Authorization: Bearer hk_…. Tokens are
per-user: your assistant sees exactly the captures your account sees.
Claude Code
One command:
claude mcp add --transport http hiccup https://hiccup.monster/mcp \ --header "Authorization: Bearer hk_YOUR_TOKEN"
Then ask, in any session: "Using hiccup, list my captures and tell me why the newest one failed."
Cursor
Add to ~/.cursor/mcp.json (or the project's .cursor/mcp.json):
{
"mcpServers": {
"hiccup": {
"url": "https://hiccup.monster/mcp",
"headers": { "Authorization": "Bearer hk_YOUR_TOKEN" }
}
}
}
Claude Desktop
Desktop's own remote-connector UI expects OAuth, which hiccup does not offer
for MCP (tokens are simpler to reason about and to revoke). Bridge it with
mcp-remote in claude_desktop_config.json:
{
"mcpServers": {
"hiccup": {
"command": "npx",
"args": ["-y", "mcp-remote", "https://hiccup.monster/mcp",
"--header", "Authorization: Bearer hk_YOUR_TOKEN"]
}
}
}
What your assistant can do
Eleven tools, all read-only — nothing over MCP can upload, change or delete anything:
| Tool | What it returns |
|---|---|
list_captures | every capture in the account — the starting point; all other tools take a capture_id from here |
list_findings | every finding, with severity and the messages that prove it |
get_advice | hiccup's deterministic advice: what is wrong, why, vendor fixes, and the only citations worth trusting |
list_calls / get_call | correlated calls, legs, the message sequence, and what changed between ingress and egress |
search_messages / get_message | find and read raw SIP messages (credentials already redacted) |
get_media_quality | RTP/RTCP loss, jitter, estimated MOS, one-way audio, DNS/ICE/Diameter observations |
search_kb | keyword search over your own uploaded vendor guides |
generate_hmr_rule / simulate_hmr | draft a header-manipulation rule from plain English, then run it against a real message from the capture and see exactly what changes |
Limits and revocation
- 120 MCP calls per minute per token — generous for interactive use, a wall for a runaway agent loop.
- Revoke any token instantly on Settings; anything configured with it stops working on the next call.
- Phone-number and credential material follows the same redaction rules as the workbench — what your assistant sees is what you would see.
Why this beats a bigger built-in chatbot
hiccup's findings, correlation and citations are computed deterministically — the same input always produces the same verdict, and every RFC reference is hand-verified. That is precisely what makes them safe ground truth for a large language model to reason over. Your assistant brings the model; hiccup makes sure it cannot hallucinate the pcap.