protocol guides SIP reference

Pro and Team plans

Connect your AI assistant (MCP)

hiccup is an MCP server: Claude Code, Claude Desktop, Cursor — anything that speaks the Model Context Protocol — can read your captures through the same tools hiccup's own chat uses. Your assistant does the reasoning with whatever model you pay for; hiccup supplies what it is authoritative about: the parsed messages, the deterministic findings, and advice with real citations.

What you need

  1. A Pro or Team account.
  2. An API token: Settings → AI assistant access (MCP) → name it after the machine it will live on → Create token. It is shown once; hiccup keeps only a hash.
Endpoint. https://hiccup.monster/mcp — POST only, authenticated with Authorization: Bearer hk_…. Tokens are per-user: your assistant sees exactly the captures your account sees.

Claude Code

One command:

claude mcp add --transport http hiccup https://hiccup.monster/mcp \
  --header "Authorization: Bearer hk_YOUR_TOKEN"

Then ask, in any session: "Using hiccup, list my captures and tell me why the newest one failed."

Cursor

Add to ~/.cursor/mcp.json (or the project's .cursor/mcp.json):

{
  "mcpServers": {
    "hiccup": {
      "url": "https://hiccup.monster/mcp",
      "headers": { "Authorization": "Bearer hk_YOUR_TOKEN" }
    }
  }
}

Claude Desktop

Desktop's own remote-connector UI expects OAuth, which hiccup does not offer for MCP (tokens are simpler to reason about and to revoke). Bridge it with mcp-remote in claude_desktop_config.json:

{
  "mcpServers": {
    "hiccup": {
      "command": "npx",
      "args": ["-y", "mcp-remote", "https://hiccup.monster/mcp",
               "--header", "Authorization: Bearer hk_YOUR_TOKEN"]
    }
  }
}

What your assistant can do

Eleven tools, all read-only — nothing over MCP can upload, change or delete anything:

ToolWhat it returns
list_capturesevery capture in the account — the starting point; all other tools take a capture_id from here
list_findingsevery finding, with severity and the messages that prove it
get_advicehiccup's deterministic advice: what is wrong, why, vendor fixes, and the only citations worth trusting
list_calls / get_callcorrelated calls, legs, the message sequence, and what changed between ingress and egress
search_messages / get_messagefind and read raw SIP messages (credentials already redacted)
get_media_qualityRTP/RTCP loss, jitter, estimated MOS, one-way audio, DNS/ICE/Diameter observations
search_kbkeyword search over your own uploaded vendor guides
generate_hmr_rule / simulate_hmrdraft a header-manipulation rule from plain English, then run it against a real message from the capture and see exactly what changes

Limits and revocation

Why this beats a bigger built-in chatbot

hiccup's findings, correlation and citations are computed deterministically — the same input always produces the same verdict, and every RFC reference is hand-verified. That is precisely what makes them safe ground truth for a large language model to reason over. Your assistant brings the model; hiccup makes sure it cannot hallucinate the pcap.

← back to hiccup