MongoDB MCP
MongoDB's official MCP server for queries, aggregations and Atlas admin
BestMCPTools
MongoDB MCP
bestmcptools.org
Last verified: October 8, 2026
Maintenance status
Repository link unavailableThe GitHub link we had for this server no longer resolves.
How to Install MongoDB MCP
$npx -y mongodb-mcp-server@latest setupRequires Claude Desktop, Cursor, Windsurf, or another MCP-compatible client.
Setup by client
Claude Desktop (claude_desktop_config.json)
{
"mcpServers": {
"mongodb-mcp": {
"command": "npx",
"args": [
"-y",
"mongodb-mcp-server@latest",
"setup"
]
}
}
}Cursor (~/.cursor/mcp.json)
{
"mcpServers": {
"mongodb-mcp": {
"command": "npx",
"args": [
"-y",
"mongodb-mcp-server@latest",
"setup"
]
}
}
}VS Code (.vscode/mcp.json)
{
"servers": {
"mongodb-mcp": {
"type": "stdio",
"command": "npx",
"args": [
"-y",
"mongodb-mcp-server@latest",
"setup"
]
}
}
}Claude Code (terminal)
claude mcp add mongodb-mcp -- npx -y mongodb-mcp-server@latest setupAdd any API keys or environment variables the server's README lists.
About MongoDB MCP
MongoDB MCP Server is MongoDB's official Model Context Protocol server, maintained in the mongodb-js/mongodb-mcp-server repository and published on npm as mongodb-mcp-server. It lets an AI client query and manage MongoDB data (find, aggregate, insert, update, indexes, schema) and, with Atlas credentials, list Atlas organizations and manage projects, clusters, database users and access lists. It works with Atlas, Atlas Local, Community Edition and Enterprise Advanced deployments.
MongoDB now offers it two ways: Local MCP, which you run yourself with npx or Docker, and the Atlas Managed MCP Server at https://mcp.mongodb.com, which MongoDB hosts for Atlas only. This page covers both, with most detail on the local server. The Atlas Vector Search docs page this listing used to link to is not the MCP server's documentation.
Quick facts (as of October 8, 2026)
| MongoDB MCP Server | |
|---|---|
| Maker | MongoDB |
| Type | Local stdio (or local HTTP) server; separate hosted Atlas Managed server |
| Install | npx -y mongodb-mcp-server@latest setup, or Docker image mongodb/mongodb-mcp-server |
| Hosted URL | https://mcp.mongodb.com (Atlas only) |
| Auth | MongoDB connection string for database tools; Atlas service account client ID and secret for Atlas tools; OAuth for the hosted server |
| Tools | Our count from the README: 25 database tools, 22 Atlas tools, 4 Atlas Local tools, 2 Assistant tools |
| Access | Read and write by default; --readOnly removes create, update and delete tools |
| Latest npm version | 3.0.5 (October 1, 2026) |
| Node.js | 22.13 or later per the README; Node 20 support is deprecated |
| License | Apache 2.0 |
| Price | Open source, no license fee. MongoDB publishes no price for the MCP server itself in the docs we read. |
Tools
The README splits tools into four groups.
| Group | Example tools | Needs |
|---|---|---|
| Database tools | find, aggregate, count, explain, collection-schema, collection-indexes, insert-many, update-many, delete-many, create-index, drop-collection, drop-database, export, mongodb-logs | A connection string, or a connection made with connect or atlas-connect-cluster |
| Atlas tools | atlas-list-orgs, atlas-list-projects, atlas-list-clusters, atlas-create-free-cluster, atlas-create-cluster (M10 to M80), atlas-upgrade-cluster, atlas-pause-resume-cluster, atlas-create-db-user, atlas-create-access-list, atlas-get-performance-advisor, atlas-list-alerts, atlas-streams-* | Atlas service account credentials |
| Atlas Local tools | atlas-local-create-deployment, atlas-local-connect-deployment, atlas-local-list-deployments, atlas-local-delete-deployment | Docker |
| Assistant tools | list-knowledge-sources, search-knowledge (searches MongoDB's knowledge base) | Nothing extra |
The server also exposes three resources: config (configuration with secrets redacted), debug (last connection attempt) and exported-data for files written by export. MongoDB's tools page says not every Atlas and database tool is available on both the managed and the local server, and lists a separate remote-atlas-connect tool for the hosted server.
Database tools vs Atlas tools
The two groups use different credentials, and you can supply either or both.
- Connection string (
MDB_MCP_CONNECTION_STRING): connects the database tools to any MongoDB deployment, local or Atlas. If you leave it out, the agent must callconnectbefore it can touch data. - Atlas service account (
MDB_MCP_API_CLIENT_IDandMDB_MCP_API_CLIENT_SECRET): turns on the Atlas tools, which call the Atlas Administration API. You create the service account in Atlas, copy the secret (shown once), and add the IP address of the machine running the server to the API access list.
If you give only Atlas credentials, atlas-connect-cluster creates a temporary database user with a random password to reach the cluster. The default lifetime for these users is 14,400,000 ms (4 hours), set by atlasTemporaryDatabaseUserLifetimeMs.
MongoDB's prerequisites page recommends project-level roles, such as Project Read Only to view clusters or Project Cluster Manager to create them, and warns that Organization Owner is rarely needed. It also notes that the server does not hide tools the service account cannot use; those calls simply fail.
Setup
The quickest path is the interactive setup utility, which asks about read-only mode and your connection string and writes the client config:
npx -y mongodb-mcp-server@latest setup
A manual config with a connection string, from the README:
{
"mcpServers": {
"MongoDB": {
"command": "npx",
"args": ["-y", "mongodb-mcp-server@latest", "--readOnly"],
"env": {
"MDB_MCP_CONNECTION_STRING": "mongodb://localhost:27017/myDatabase"
}
}
}
}
For Atlas tools, replace the env block with MDB_MCP_API_CLIENT_ID and MDB_MCP_API_CLIENT_SECRET. To skip Node.js, run the Docker image with the same environment variables and MDB_MCP_READ_ONLY=true.
MongoDB also ships plugins. In Claude Code, /plugin install mongodb@claude-plugins-official installs the local server, and /plugin install mongodb-atlas@claude-plugins-official connects to the Atlas Managed server over OAuth, which MongoDB recommends for Atlas. An Atlas organization owner must first turn on the AI Clients setting under Organization Settings, App Connections.
MongoDB's get started guide has client-specific steps for Claude Code, Claude Desktop and Claude on the web, ChatGPT Desktop and Web, Cursor, Codex, Devin AI, Grok Build and the fx CLI, plus a generic path for other clients. The README adds plugin installs for VS Code, GitHub Copilot CLI and Gemini CLI. ChatGPT and Devin AI are documented for Atlas only, not self-managed MongoDB.
The Atlas Managed MCP Server
The hosted server runs at https://mcp.mongodb.com, works only with Atlas, and controls access up to the project level (the local server goes down to collection level). Two ways in:
- Plugin with user-delegated access. OAuth 2.1 with PKCE, acting with your full Atlas role, subject to the access mode your Organization Owner sets. You cannot delegate a subset of your permissions. Access ends after 7 days of inactivity or 30 days after you grant it, and you can revoke it in the Atlas UI.
- Client credentials for programmatic agents. An Organization Owner or Project Owner creates a configuration that returns a client ID and secret, with its own roles, IP access list and a read-only flag that is on by default. Clients that lack the OAuth client-credentials flow use the
mongodb-atlas-mcp-remotenpm package. The README says you cannot authenticate to the remote server with a static API key over HTTP.
Read-only mode and confirmations
--readOnly (or MDB_MCP_READ_ONLY=true) keeps only tools with read, connect and metadata operation types. Tools with create, update or delete types are not registered at all, so the agent never sees them: that covers tools such as insert-many, update-many, delete-many, drop-collection, rename-collection, create-index and the atlas-create-* tools. The server logs which tools it skipped. Read-only mode is off by default, though every README example adds --readOnly. MongoDB's security page also recommends connecting with a read-only database user.
Other controls:
disabledToolsturns off tools by name, by category (atlas,mongodb) or by operation type (create,update,delete,read,metadata,connect).confirmationRequiredToolsdefaults todrop-database,drop-collection,delete-many,drop-index,atlas-create-db-user,atlas-create-access-list,atlas-streams-manageandatlas-streams-teardown. This only works if your client supports MCP elicitation. Otherwise those tools run without asking.aggregateasks before running a pipeline with$outor$merge.disableServerSideJsis on by default and blocks$where,$functionand$accumulator.indexCheck(off by default) rejects queries that would scan a whole collection when you turn it on.- Results from
findandaggregateare capped at 100 documents and 16 MB by default.
Telemetry
Telemetry is enabled by default and sends usage data to MongoDB. Turn it off with MDB_MCP_TELEMETRY=disabled, --telemetry disabled or DO_NOT_TRACK=1.
Limitations and things to watch
- No built-in authentication on the local server. The README says the CLI is meant for single-user, localhost use. It refuses to bind to a non-loopback host unless you set
MDB_MCP_DANGEROUS_HOST_BINDING=true, and it should not be exposed as a shared endpoint without your own auth layer. - Writes are on by default. Add
--readOnlyunless you need changes. - Tool annotations are advisory. MongoDB's security page says
readOnlyHintanddestructiveHintdo not block anything. - Some create tools widen access. An access list entry of
0.0.0.0/0exposes a cluster to every IP address. - Secrets on the command line. MongoDB recommends environment variables over CLI arguments, which can appear in process lists.
- Node.js version wording differs. The README says 22.13, the get started page says 22.12, and the npm engines field accepts ^20.19.0, ^22.13.0 or 24 and later.
Pros and cons
Pros
- Official and Apache 2.0 licensed.
- Covers data work and Atlas administration in one server.
- Read-only mode unregisters create, update and delete tools instead of relying on the model.
- Hosted option for Atlas with OAuth and revocable access.
Cons
- Read-only and telemetry defaults both need changing for a cautious setup.
- Confirmation prompts depend on client elicitation support.
- Atlas tools require creating and scoping a service account.
- The local server has no authentication for shared use.
Who it is for
A good fit if:
- You use MongoDB or Atlas and want an agent to explore schemas, write queries and aggregations, or check slow queries and index advice.
- You manage Atlas projects and want cluster and user tasks from your AI client.
- You want a hosted Atlas option with OAuth instead of storing connection strings.
Not the right tool if:
- You need to serve many users from one self-hosted endpoint without building your own auth.
- Your data lives in Postgres or Redis. Look at PostgreSQL MCP, Supabase MCP or Redis MCP instead.
What we could not verify
- Which exact tools the Atlas Managed server offers. The availability columns on MongoDB's tools page did not render in the copy we read.
- What data telemetry collects. The README does not list it.
- Whether the hosted server or Atlas App Connections carry any separate charge. Atlas resources the tools create, such as dedicated clusters, follow your normal Atlas billing, which we did not check.
How this page was put together
We read the mongodb-mcp-server README, the npm registry entry, and MongoDB's MCP Server docs (overview, get started, prerequisites, tools, local security best practices and remote security pages) on October 8, 2026. We did not run the server.
Sources
- GitHub: mongodb-js/mongodb-mcp-server README
- npm: mongodb-mcp-server
- MongoDB docs: MCP Server overview
- MongoDB docs: Get started
- MongoDB docs: Prerequisites for Atlas tools
- MongoDB docs: MCP Server tools
- MongoDB docs: Security best practices (local)
- MongoDB docs: Security, governance and auditability (managed)
Pricing
Open Source: from Free (open source; no MCP price published as of October 2026)
Our Take on MongoDB MCP
A sensible first choice if your data is in MongoDB or Atlas: it is official, Apache 2.0 licensed, and covers both database work and Atlas administration. Start with --readOnly and a read-only database user, because writes are on by default and confirmation prompts only appear in clients that support elicitation. The local server has no authentication, so do not expose it as a shared endpoint.