MongoDB MCP Server
A Model Context Protocol server for interacting with MongoDB Databases and MongoDB Atlas.
📚 Table of Contents
- 🚀 Getting Started
- 🛠️ Supported Tools
- 📄 Supported Resources
- ⚙️ Configuration
- 🚀 Deploy on Public Clouds
- 🤝 Contributing
Prerequisites
[!NOTE] Node 20.x support is deprecated and will be removed in a future release. Please upgrade to Node 22.13 or later. See https://nodejs.org/en/blog/migrations/v20-to-v22 for migration details.
-
Node.js
- At least v22.13.0. Check with
node -v.
- At least v22.13.0. Check with
-
A MongoDB connection string or Atlas API credentials.
- Service Accounts Atlas API credentials are required to use the Atlas tools. You can create a service account in MongoDB Atlas and use its credentials for authentication. See Atlas API Access for more details.
- If you have a MongoDB connection string, you can use it directly to connect to your MongoDB instance.
Setup
Quick Start
🔒 Security Recommendation 1: When using Atlas API credentials, be sure to assign only the minimum required permissions to your service account. See Atlas API Permissions for details.
🔒 Security Recommendation 2: For enhanced security, we strongly recommend using environment variables to pass sensitive configuration such as connection strings and API credentials instead of command line arguments. Command line arguments can be visible in process lists and logged in various system locations, potentially exposing your secrets. Environment variables provide a more secure way to handle sensitive information.
Most MCP clients require a configuration file to be created or modified to add the MCP server.
Note: The configuration file syntax can be different across clients. Please refer to the following links for the latest expected syntax:
- Windsurf: https://docs.windsurf.com/windsurf/mcp
- VSCode: https://code.visualstudio.com/docs/copilot/chat/mcp-servers
- Claude Desktop: https://modelcontextprotocol.io/quickstart/user
- Cursor: https://docs.cursor.com/context/model-context-protocol
- Copilot CLI: https://docs.github.com/en/copilot/concepts/agents/about-copilot-cli
- Opencode CLI: https://opencode.ai/docs/mcp-servers
Default Safety Notice: All examples below include
--readOnlyby default to ensure safe, read-only access to your data. Remove--readOnlyif you need to enable write operations.
Option 1: Connection String
You can pass your connection string via environment variables, make sure to use a valid username and password.
{
"mcpServers": {
"MongoDB": {
"command": "npx",
"args": ["-y", "mongodb-mcp-server@latest", "--readOnly"],
"env": {
"MDB_MCP_CONNECTION_STRING": "mongodb://localhost:27017/myDatabase"
}
}
}
}
NOTE: The connection string can be configured to connect to any MongoDB cluster, whether it's a local instance or an Atlas cluster.
Option 2: Atlas API Credentials
Use your Atlas API Service Accounts credentials. Must follow all the steps in Atlas API Access section.
{
"mcpServers": {
"MongoDB": {
"command": "npx",
"args": ["-y", "mongodb-mcp-server@latest", "--readOnly"],
"env": {
"MDB_MCP_API_CLIENT_ID": "your-atlas-service-accounts-client-id",
"MDB_MCP_API_CLIENT_SECRET": "your-atlas-service-accounts-client-secret"
}
}
}
}
Option 3: Standalone Service using environment variables and command line arguments
You can source environment variables defined in a config file or explicitly set them like we do in the example below and run the server via npx.
# Set your credentials as environment variables first
export MDB_MCP_API_CLIENT_ID="your-atlas-service-accounts-client-id"
export MDB_MCP_API_CLIENT_SECRET="your-atlas-service-accounts-client-secret"
# Then start the server
npx -y mongodb-mcp-server@latest --readOnly
💡 Platform Note: The examples above use Unix/Linux/macOS syntax. For Windows users, see Environment Variables for platform-specific instructions.
- For a complete list of configuration options see Configuration Options
- To configure your Atlas Service Accounts credentials please refer to Atlas API Access
- Connection String via environment variables in the MCP file example
- Atlas API credentials via environment variables in the MCP file example
Option 4: Using Docker
You can run the MongoDB MCP Server in a Docker container, which provides isolation and doesn't require a local Node.js installation.
Run with Environment Variables
You may provide either a MongoDB connection string OR Atlas API credentials:
Option A: No configuration
docker run --rm -i \
mongodb/mongodb-mcp-server:latest
Option B: With MongoDB connection string
# Set your credentials as environment variables first
export MDB_MCP_CONNECTION_STRING="mongodb+srv://username:[email protected]/myDatabase"
# Then start the docker container
docker run --rm -i \
-e MDB_MCP_CONNECTION_STRING \
-e MDB_MCP_READ_ONLY="true" \
mongodb/mongodb-mcp-server:latest
💡 Platform Note: The examples above use Unix/Linux/macOS syntax. For Windows users, see Environment Variables for platform-specific instructions.
Option C: With Atlas API credentials
# Set your credentials as environment variables first
export MDB_MCP_API_CLIENT_ID="your-atlas-service-accounts-client-id"
export MDB_MCP_API_CLIENT_SECRET="your-atlas-service-accounts-client-secret"
# Then start the docker container
docker run --rm -i \
-e MDB_MCP_API_CLIENT_ID \
-e MDB_MCP_API_CLIENT_SECRET \
-e MDB_MCP_READ_ONLY="true" \
mongodb/mongodb-mcp-server:latest
💡 Platform Note: The examples above use Unix/Linux/macOS syntax. For Windows users, see Environment Variables for platform-specific instructions.
Docker in MCP Configuration File
Without options:
{
"mcpServers": {
"MongoDB": {
"command": "docker",
"args": [
"run",
"--rm",
"-e",
"MDB_MCP_READ_ONLY=true",
"-i",
"mongodb/mongodb-mcp-server:latest"
]
}
}
}
With connection string:
{
"mcpServers": {
"MongoDB": {
"command": "docker",
"args": [
"run",
"--rm",
"-i",
"-e",
"MDB_MCP_CONNECTION_STRING",
"-e",
"MDB_MCP_READ_ONLY=true",
"mongodb/mongodb-mcp-server:latest"
],
"env": {
"MDB_MCP_CONNECTION_STRING": "mongodb+srv://username:[email protected]/myDatabase"
}
}
}
}
With Atlas API credentials:
{
"mcpServers": {
"MongoDB": {
"command": "docker",
"args": [
"run",
"--rm",
"-i",
"-e",
"MDB_MCP_READ_ONLY=true",
"-e",
"MDB_MCP_API_CLIENT_ID",
"-e",
"MDB_MCP_API_CLIENT_SECRET",
"mongodb/mongodb-mcp-server:latest"
],
"env": {
"MDB_MCP_API_CLIENT_ID": "your-atlas-service-accounts-client-id",
"MDB_MCP_API_CLIENT_SECRET": "your-atlas-service-accounts-client-secret"
}
}
}
}
Option 5: Running as an HTTP Server
⚠️ Security Notice: This server now supports Streamable HTTP transport for remote connections. HTTP transport is NOT recommended for production use without implementing proper authentication and security measures.
Suggested Security Measures Examples:
- Implement authentication (e.g., API gateway, reverse proxy)
- Use HTTPS/TLS encryption
- Deploy behind a firewall or in private networks
- Implement rate limiting
- Never expose directly to the internet
For more details, see MCP Security Best Practices.
You can run the MongoDB MCP Server as an HTTP server instead of the default stdio transport. This is useful if you want to interact with the server over HTTP, for example from a web client or to expose the server on a specific port.
To start the server with HTTP transport, use the --transport http option:
npx -y mongodb-mcp-server@latest --transport http
By default, the server will listen on http://127.0.0.1:3000. You can customize the host and port using the --httpHost and --httpPort options:
npx -y mongodb-mcp-server@latest --transport http --httpHost=0.0.0.0 --httpPort=8080
--httpHost(default: 127.0.0.1): The host to bind the HTTP server.--httpPort(default: 3000): The port number for the HTTP server.
Note: The default transport is
stdio, which is suitable for integration with most MCP clients. Usehttptransport if you need to interact with the server over HTTP.
Option 6: Copilot CLI
You can use the Copilot CLI to interactively add the MCP server:
/mcp add
Alternatively, create or edit the configuration file ~/.copilot/mcp-config.json and add:
{
"mcpServers": {
"MongoDB": {
"command": "npx",
"args": ["-y", "mongodb-mcp-server@latest", "--readOnly"],
"env": {
"MDB_MCP_CONNECTION_STRING": "mongodb://localhost:27017/myDatabase"
}
}
}
}
For more information, see the Copilot CLI documentation.
Option 7: OpenCode
Create or edit your OpenCode config file (~/.config/opencode/opencode.json or project-specific ./opencode.json):
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"MongoDB": {
"type": "local",
"command": ["npx", "-y", "mongodb-mcp-server@latest", "--readOnly"],
"enabled": true,
"environment": {
"MDB_MCP_CONNECTION_STRING": "mongodb://localhost:27017/myDatabase"
}
}
}
}
For more information about configuring OpenCode as an MCP client, including the expected syntax and options, see the OpenCode MCP servers documentation.
🛠️ Supported Tools
Tool List
MongoDB Database Tools
aggregate- Run an aggregation against a MongoDB collectionaggregate-db- Run an aggregation against a MongoDB databasecollection-indexes- Describe the indexes for a collectioncollection-schema- Describe the schema for a collectioncollection-storage-size- Gets the size of the collectionconnect- Connect to a MongoDB instancecount- Gets the number of documents in a MongoDB collection using db.collection.count() and query as an optional filter parametercreate-collection- Creates a new collection in a database. If the database doesn't exist, it will be created automatically.create-index- Create an index for a collectiondb-stats- Returns statistics that reflect the use state of a single databasedelete-many- Removes all documents that match the filter from a MongoDB collectiondisconnect- Close a MongoDB connection and revoke its connectionId.drop-collection- Removes a collection or view from the database. The method also removes any indexes associated with the dropped collection.drop-database- Removes the specified database, deleting the associated data filesdrop-index- Drop an index for the provided database and collection.explain- Returns statistics describing the execution of the winning plan chosen by the query optimizer for the evaluated methodexport- Export a query or aggregation results in the specified EJSON format.find- Run a find query against a MongoDB collectioninsert-many- Insert an array of documents into a MongoDB collection. If the list of documents is above com.mongodb/maxRequestPayloadBytes, consider inserting them in batches.list-collections- List all collections for a given databaselist-connections- List the active MongoDB connections and their connectionIds. Use this to find a connectionId established earlier.list-databases- List all databases for a MongoDB connectionmongodb-logs- Returns the most recent logged mongod eventsrename-collection- Renames a collection in a MongoDB databaseupdate-many- Updates all documents that match the specified filter for a collection. If the list of documents is above com.mongodb/maxRequestPayloadBytes, consider updating them in batches.
MongoDB Atlas Tools
atlas-connect-cluster- Connect to MongoDB Atlas cluster and get back a connectionId to pass to the other MongoDB tools. Each call establishes a new, independent connection — multiple connections can be active at the same time.atlas-create-access-list- Allow Ip/CIDR ranges to access your MongoDB Atlas clusters.atlas-create-cluster- Create a MongoDB Atlas cluster (M10–M80, replica set or single shard). Compute autoscaling is enabled by default: min instance size is set to the selected instance size, max is set two tiers above. Disk autoscaling is always enabled. The tool returns immediately, use the atlas-inspect-cluster tool to poll the cluster state for readiness (state: IDLE). Connection strings are unavailable until the cluster reaches IDLE state.atlas-create-db-user- Create an MongoDB Atlas database useratlas-create-free-cluster- Create a free MongoDB Atlas clusteratlas-create-project- Create a MongoDB Atlas projectatlas-get-performance-advisor- Get MongoDB Atlas performance advisor recommendations and suggestions, which includes the operations: suggested indexes, drop index suggestions, schema suggestions, and a sample of the most recent (max 50) slow query logsatlas-inspect-access-list- Inspect Ip/CIDR ranges with access to your MongoDB Atlas clusters.atlas-inspect-cluster- Inspect metadata of a MongoDB Atlas clusteratlas-list-alerts- List triggered alerts for a MongoDB Atlas project. These are alerts Atlas has raised, not the alert configurations that define them. Defaults to OPEN alerts; set status to TRACKING or CLOSED to see others.atlas-list-clusters- List MongoDB Atlas clustersatlas-list-db-users- List MongoDB Atlas database usersatlas-list-orgs- List MongoDB Atlas organizationsatlas-list-projects- List MongoDB Atlas projectsatlas-load-sample-dataset- Load a MongoDB sample dataset into an Atlas cluster, or check the status of a previously-initiated load. To start a new load, provideclusterName— the load runs asynchronously and the response includes ajobIdand initial state. To check progress, call this tool again withjobId(sample dataset loads typically take 1–5 minutes). State can be WORKING, COMPLETED, or FAILED.atlas-pause-resume-cluster- Pause or resume a dedicated (M10+) MongoDB Atlas cluster.atlas-streams-build- Create Atlas Stream Processing resources. Use this tool for 'set up a Kafka pipeline', 'create a workspace', 'add a connection', or 'deploy a processor'. Use resource='workspace' to create a new workspace (specify cloud provider, region, and tier). Use resource='connection' to add a data source or sink to an existing workspace. Use resource='processor' to deploy a stream processor with a pipeline. Use resource='privatelink' to set up private networking. Typical workflow: create workspace → add connections → deploy processor.atlas-streams-discover- Discover and inspect Atlas Stream Processing resources. Also use for 'why is my processor failing', 'what workspaces do I have', 'show processor stats', or 'check processor health'. Use 'list-workspaces' to see all workspaces in a project. Use inspect actions for details on a specific resource. Use 'diagnose-processor' for a combined health report including state, stats, connection health, and recent errors. Use 'get-networking' for PrivateLink and account details.atlas-streams-manage- Manage Atlas Stream Processing resources: start/stop processors, modify pipelines, update configurations. Also use for 'change the pipeline', 'scale up my processor', or 'update my workspace tier'. Common workflow: action='stop-processor' → action='modify-processor' → action='start-processor'. Useatlas-streams-discoverwith action 'inspect-processor' to check state before managing.atlas-streams-teardown- Delete Atlas Stream Processing resources. Also use for 'remove my workspace', 'disconnect a source', 'delete all processors', or 'clean up my streams environment'. Performs basic safety checks before deletion: summarizes counts of processors and connections, highlights connections referenced by processors where possible, and surfaces API errors if processors are still running when deletion is attempted. Useatlas-streams-discoverto review resources before deleting.atlas-upgrade-cluster- Upgrade a MongoDB Atlas cluster tier. Upgrades Free (M0) clusters to Flex or M10 Dedicated, or Flex clusters to M10 Dedicated. The upgrade path is determined automatically from the current tier unless overridden with targetTier. Note to LLM: If provider and region are not already known, ask for both together in a single question before calling this tool. Common region mappings by provider (default recommendation: AWS US_EAST_1): AWS: "East Coast"/"Virginia"/"US East" → US_EAST_1, "Ohio" → US_EAST_2, "California"/"West Coast" → US_WEST_2, "Southeast Asia"/"APAC"/"Singapore" → AP_SOUTHEAST_1, "Europe"/"EU"/"Ireland" → EU_WEST_1. GCP: "Central US" → CENTRAL_US, "Western US" → WESTERN_US, "Southeast Asia"/"APAC" → SOUTHEASTERN_ASIA_PACIFIC, "Europe"/"EU" → WESTERN_EUROPE. AZURE: "East US" → US_EAST_2, "West US" → US_WEST_2, "Europe"/"EU" → EUROPE_NORTH.
NOTE: atlas tools are only available when you set credentials on configuration section.
MongoDB Atlas Local Tools
atlas-local-connect-deployment- Connect to a MongoDB Atlas Local deployment and get back a connectionId to pass to the other MongoDB toolsatlas-local-create-deployment- Create a MongoDB Atlas local deployment. Default image is preview. When the user does not specify an image tag, inform them that preview is used by default and provide this link for more information: https://hub.docker.com/r/mongodb/mongodb-atlas-localatlas-local-delete-deployment- Delete a MongoDB Atlas local deploymentatlas-local-list-deployments- List MongoDB Atlas local deployments
MongoDB Assistant Tools
list-knowledge-sources- List available data sources in the MongoDB Assistant knowledge base. Use this to explore available data sources or to find search filter parameters to use in search-knowledge.search-knowledge- Search for information in the MongoDB Assistant knowledge base. This includes official documentation, curated expert guidance, and other resources provided by MongoDB. Supports filtering by data source and version.
📄 Supported Resources
config- Server configuration, supplied by the user either as environment variables or as startup arguments with sensitive parameters redacted. The resource can be accessed under URIconfig://config.debug- Debugging information for MongoDB connectivity issues. Tracks the last connectivity attempt and error information. The resource can be accessed under URIdebug://mongodb.exported-data- A resource template to access the data exported using the export tool. The template can be accessed under URIexported-data://{exportName}whereexportNameis the unique name for an export generated by the export tool.
Configuration
🔒 Security Best Practice: We strongly recommend using environment variables for sensitive configuration such as API credentials (
MDB_MCP_API_CLIENT_ID,MDB_MCP_API_CLIENT_SECRET) and connection strings (MDB_MCP_CONNECTION_STRING) instead of command-line arguments. Environment variables are not visible in process lists and provide better security for your sensitive data.
The MongoDB MCP Server can be configured using multiple methods, with the following precedence (highest to lowest):
- Command-line arguments
- Environment variables
- Configuration File
Configuration Options
| Environment Variable / CLI Option | Default | Description |
|---|---|---|
MDB_MCP_ALLOW_REQUEST_OVERRIDES / --allowRequestOverrides |
false |
When set to true, allows configuration values to be overridden via request headers and query parameters. |
MDB_MCP_API_CLIENT_ID / --apiClientId |
<not set> |
Atlas API client ID for authentication. Required for running Atlas tools. |
MDB_MCP_API_CLIENT_SECRET / --apiClientSecret |
<not set> |
Atlas API client secret for authentication. Required for running Atlas tools. |
MDB_MCP_ASSISTANT_BASE_URL / --assistantBaseUrl |
"https://knowledge.mongodb.com/api/v1/" |
Base URL for the MongoDB Assistant API. |
MDB_MCP_ATLAS_TEMPORARY_DATABASE_USER_LIFETIME_MS / --atlasTemporaryDatabaseUserLifetimeMs |
14400000 |
Time in milliseconds that temporary database users created when connecting to MongoDB Atlas clusters will remain active before being automatically deleted. |
MDB_MCP_CONFIRMATION_REQUIRED_TOOLS / --confirmationRequiredTools |
"atlas-create-access-list,atlas-create-db-user,drop-database,drop-collection,delete-many,drop-index,atlas-streams-manage,atlas-streams-teardown" |
Comma separated values of tool names that require user confirmation before execution. Requires the client to support elicitation. |
MDB_MCP_CONNECTION_SCOPE / --connectionScope |
"session" |
Visibility scope for MongoDB connections created at runtime. With 'session' (the default), each MCP session only sees the connections it created (plus the shared 'preconfigured' one) and they are closed when the session ends — recommended when the HTTP transport is exposed to multiple clients without authentication. With 'global', connections are shared across all sessions and survive session rotation. |
MDB_MCP_CONNECTION_STRING / --connectionString |
<not set> |
MongoDB connection string for direct database connections. Optional, if not set, you'll need to call the connect tool before interacting with MongoDB data. |
MDB_MCP_DISABLE_SERVER_SIDE_JS / --disableServerSideJs |
true |
When set to true, disallows the use of server-side JavaScript operators (such as $where, $function, and $accumulator) in query filters and aggregation pipelines. |
MDB_MCP_DISABLED_TOOLS / --disabledTools |
"" |
Comma separated values of tool names, operation types, and/or categories of tools that will be disabled. |
MDB_MCP_DRY_RUN / --dryRun |
false |
When true, runs the server in dry mode: dumps configuration and enabled tools, then exits without starting the server. |
MDB_MCP_ELICITATION_TIMEOUT_MS / --elicitationTimeoutMs |
300000 |
Time in milliseconds the user has to respond to an elicitation request (such as a tool confirmation prompt) before it fails. |
MDB_MCP_EXPORT_CLEANUP_INTERVAL_MS / --exportCleanupIntervalMs |
120000 |
Time in milliseconds between export cleanup cycles that remove expired export files. |
MDB_MCP_EXPORT_TIMEOUT_MS / --exportTimeoutMs |
300000 |
Time in milliseconds after which an export is considered expired and eligible for cleanup. |
MDB_MCP_EXPORTS_PATH / --exportsPath |
see below* | Folder to store exported data files. |
MDB_MCP_EXTERNALLY_MANAGED_SESSIONS / --externallyManagedSessions |
false |
When true, the HTTP transport allows requests with a session ID supplied externally through the 'mcp-session-id' header. When an external ID is supplied, the initialization request is optional. |
MDB_MCP_HEALTH_CHECK_HOST / --healthCheckHost |
<not set> |
Deprecated. Use monitoringServerHost instead. Host address to bind the healthCheck HTTP server to (only used when transport is 'http'). If provided, healthCheckPort must also be set. |
MDB_MCP_HEALTH_CHECK_PORT / --healthCheckPort |
<not set> |
Deprecated. Use monitoringServerPort instead. Port number for the healthCheck HTTP server (only used when transport is 'http'). If provided, healthCheckHost must also be set. |
MDB_MCP_HTTP_BODY_LIMIT / --httpBodyLimit |
102400 |
Maximum size of the HTTP request body in bytes (only used when transport is 'http'). This value is passed as the optional limit parameter to the Express.js json() middleware. |
MDB_MCP_HTTP_HEADERS / --httpHeaders |
"{}" |
Header that the HTTP server will validate when making requests (only used when transport is 'http'). |
MDB_MCP_HTTP_HOST / --httpHost |
"127.0.0.1" |
Host address to bind the HTTP server to (only used when transport is 'http'). |
No comments yet
Be the first to share your take.