
The MongoDB MCP Server provides LLM-based access to MongoDB databases by exposing tools for querying, inserting, updating, and deleting documents through the Model Context Protocol. It enables AI assistants to interact with MongoDB instances by accepting a connection string and offering read-only or read-write operations depending on configuration. This server solves the problem of integrating database operations into AI workflows by allowing language models to perform structured data manipulation without direct code execution.
A Model Context Protocol server for interacting with MongoDB Databases and MongoDB Atlas.
MongoDB MCP Server comes bundled with the official MongoDB plugins for AI agents. The following plugins are available:
mongodb-atlas — connects to the MongoDB-hosted Atlas MCP server over OAuth. This does not require you to run anything locally, and is the recommended way to connect to MongoDB Atlas from your AI agent:
⇧⌘X / Ctrl+Shift+X), search for @agentPlugins, and install mongodb-atlas./plugins and install mongodb-atlas.copilot plugin install mongodb-atlas./marketplace in Grok Build and install mongodb-atlas.mongodb — runs the MongoDB MCP server locally and connects to any self-managed deployment:
codex plugin marketplace add mongodb/agent-skills, then open /plugins and install mongodb.copilot plugin install mongodb./marketplace in Grok Build and install mongodb.You can manually set up the local MCP server by running the following command:
npx -y mongodb-mcp-server@latest setup
This will guide you through an interactive setup process, including configuring your MongoDB connection string or Atlas API credentials.
For more advanced setup options, see the Manual Setup section below.
You can add and use the MongoDB MCP Server setup skill to configure your local MCP server using an AI agent.
npx skills add https://github.com/mongodb/agent-skills --skill mongodb-mcp-setup
See Manual Setup for instructions on how to manually configure the MongoDB MCP Server.
[!NOTE] Node 20.x support is deprecated and will be removed in a future release. Please upgrade to Node 22.13 or later. See https://nodejs.org/en/blog/migrations/v20-to-v22 for migration details.
Node.js
node -v.A MongoDB connection string or Atlas API credentials.
🔒 Security Recommendation 1: When using Atlas API credentials, be sure to assign only the minimum required permissions to your service account. See Atlas API Permissions for details.
🔒 Security Recommendation 2: For enhanced security, we strongly recommend using environment variables to pass sensitive configuration such as connection strings and API credentials instead of command line arguments. Command line arguments can be visible in process lists and logged in various system locations, potentially exposing your secrets. Environment variables provide a more secure way to handle sensitive information.
Most MCP clients require a configuration file to be created or modified to add the MCP server.
Note: The configuration file syntax can be different across clients. Please refer to the following links for the latest expected syntax:
Default Safety Notice: All examples below include
--readOnlyby default to ensure safe, read-only access to your data. Remove--readOnlyif you need to enable write operations.
You can pass your connection string via environment variables, make sure to use a valid username and password.
{
"mcpServers": {
"MongoDB": {
"command": "npx",
"args": ["-y", "mongodb-mcp-server@latest", "--readOnly"],
"env": {
"MDB_MCP_CONNECTION_STRING": "mongodb://localhost:27017/myDatabase"
}
}
}
}
NOTE: The connection string can be configured to connect to any MongoDB cluster, whether it's a local instance or an Atlas cluster.
When working with MongoDB Atlas, the recommended approach is to install the mongodb-atlas plugin for your AI agent, which handles OAuth authentication automatically.
For manual configuration, see the client-specific instructions for setting up the Atlas Remote MCP server with OAuth. Alternatively, you can connect using the mongodb-atlas-mcp-remote package with Service Account credentials — see the package README for setup instructions.
Note: You cannot authenticate to the remote MongoDB MCP server using a static API key over HTTP. You must either:
- Use a client that supports the OAuth flow.
- Use the
mongodb-atlas-mcp-remotestdio server, which you can authenticate into using the staticMDB_MCP_API_CLIENT_IDandMDB_MCP_API_CLIENT_SECRETenvironment variables.
To connect with the mongodb-atlas-mcp-remote stdio server using Service Account credentials, add it to your client's MCP configuration:
{
"mcpServers": {
"mongodb-atlas-mcp-remote": {
"type": "stdio",
"command": "npx",
"args": ["-y", "mongodb-atlas-mcp-remote@latest"],
"env": {
"MDB_MCP_API_CLIENT_ID": "$CLIENT_ID",
"MDB_MCP_API_CLIENT_SECRET": "$SECRET"
}
}
}
}
Use your Atlas API Service Accounts credentials. Must follow all the steps in Atlas API Access section.
{
"mcpServers": {
"MongoDB": {
"command": "npx",
"args": ["-y", "mongodb-mcp-server@latest", "--readOnly"],
"env": {
"MDB_MCP_API_CLIENT_ID": "your-atlas-service-accounts-client-id",
"MDB_MCP_API_CLIENT_SECRET": "your-atlas-service-accounts-client-secret"
}
}
}
}
You can source environment variables defined in a config file or explicitly set them like we do in the example below and run the server via npx.
# Set your credentials as environment variables first
export MDB_MCP_API_CLIENT_ID="your-atlas-service-accounts-client-id"
export MDB_MCP_API_CLIENT_SECRET="your-atlas-service-accounts-client-secret"
# Then start the server
npx -y mongodb-mcp-server@latest --readOnly
💡 Platform Note: The examples above use Unix/Linux/macOS syntax. For Windows users, see Environment Variables for platform-specific instructions.
You can run the MongoDB MCP Server in a Docker container, which provides isolation and doesn't require a local Node.js installation.
You may provide either a MongoDB connection string OR Atlas API credentials:
docker run --rm -i \
mongodb/mongodb-mcp-server:latest
# Set your credentials as environment variables first
export MDB_MCP_CONNECTION_STRING="mongodb+srv://username:password@cluster.mongodb.net/myDatabase"
# Then start the docker container
docker run --rm -i \
-e MDB_MCP_CONNECTION_STRING \
-e MDB_MCP_READ_ONLY="true" \
mongodb/mongodb-mcp-server:latest
💡 Platform Note: The examples above use Unix/Linux/macOS syntax. For Windows users, see Environment Variables for platform-specific instructions.
# Set your credentials as environment variables first
export MDB_MCP_API_CLIENT_ID="your-atlas-service-accounts-client-id"
export MDB_MCP_API_CLIENT_SECRET="your-atlas-service-accounts-client-secret"
# Then start the docker container
docker run --rm -i \
-e MDB_MCP_API_CLIENT_ID \
-e MDB_MCP_API_CLIENT_SECRET \
-e MDB_MCP_READ_ONLY="true" \
mongodb/mongodb-mcp-server:latest
💡 Platform Note: The examples above use Unix/Linux/macOS syntax. For Windows users, see Environment Variables for platform-specific instructions.
Without options:
{
"mcpServers": {
"MongoDB": {
"command": "docker",
"args": [
"run",
"--rm",
"-e",
"MDB_MCP_READ_ONLY=true",
"-i",
"mongodb/mongodb-mcp-server:latest"
]
}
}
}
With connection string:
{
"mcpServers": {
"MongoDB": {
"command": "docker",
"args": [
"run",
"--rm",
"-i",
"-e",
"MDB_MCP_CONNECTION_STRING",
"-e",
"MDB_MCP_READ_ONLY=true",
"mongodb/mongodb-mcp-server:latest"
],
"env": {
"MDB_MCP_CONNECTION_STRING": "mongodb+srv://username:password@cluster.mongodb.net/myDatabase"
}
}
}
}
With Atlas API credentials:
{
"mcpServers": {
"MongoDB": {
"command": "docker",
"args": [
"run",
"--rm",
"-i",
"-e",
"MDB_MCP_READ_ONLY=true",
"-e",
"MDB_MCP_API_CLIENT_ID",
"-e",
"MDB_MCP_API_CLIENT_SECRET",
"mongodb/mongodb-mcp-server:latest"
],
"env": {
"MDB_MCP_API_CLIENT_ID": "your-atlas-service-accounts-client-id",
"MDB_MCP_API_CLIENT_SECRET": "your-atlas-service-accounts-client-secret"
}
}
}
}
aggregate - Run an aggregation against a MongoDB collectionaggregate-db - Run an aggregation against a MongoDB databasecollection-indexes - Describe the indexes for a collectioncollection-schema - Describe the schema for a collectioncollection-storage-size - Gets the size of the collectionconnect - Connect to a MongoDB instancecount - Gets the number of documents in a MongoDB collection using db.collection.count() and query as an optional filter parametercreate-collection - Creates a new collection in a database. If the database doesn't exist, it will be created automatically.create-index - Create an index for a collectiondb-stats - Returns statistics that reflect the use state of a single databasedelete-many - Removes all documents that match the filter from a MongoDB collectiondisconnect - Close a MongoDB connection and revoke its connectionId.drop-collection - Removes a collection or view from the database. The method also removes any indexes associated with the dropped collection.drop-database - Removes the specified database, deleting the associated data filesdrop-index - Drop an index for the provided database and collection.explain - Returns statistics describing the execution of the winning plan chosen by the query optimizer for the evaluated methodexport - Export a query or aggregation results in the specified EJSON format.find - Run a find query against a MongoDB collectioninsert-many - Insert an array of documents into a MongoDB collection. If the list of documents is above com.mongodb/maxRequestPayloadBytes, consider inserting them in batches.list-collections - List all collections for a given databaselist-connections - List the active MongoDB connections and their connectionIds. Use this to find a connectionId established earlier.list-databases - List all databases for a MongoDB connectionmongodb-logs - Returns the most recent logged mongod eventsrename-collection - Renames a collection in a MongoDB databaseupdate-many - Updates all documents that match the specified filter for a collection. If the list of documents is above com.mongodb/maxRequestPayloadBytes, consider updating them in batches.atlas-connect-cluster - Connect to MongoDB Atlas cluster and get back a connectionId to pass to the other MongoDB tools. Each call establishes a new, independent connection — multiple connections can be active at the same time.atlas-create-access-list - Allow Ip/CIDR ranges to access your MongoDB Atlas clusters.atlas-create-cluster - Create a MongoDB Atlas cluster (M10–M80, replica set or single shard). Compute autoscaling is enabled by default: min instance size is set to the selected instance size, max is set two tiers above. Disk autoscaling is always enabled. Encryption at rest with customer-managed keys (CMK) is supported, the CMK provider must already have a valid encryption at rest configuration in the project. The tool returns immediately, use the atlas-inspect-cluster tool to poll the cluster state for readiness (state: IDLE). Connection strings are unavailable until the cluster reaches IDLE state.atlas-create-db-user - Create an MongoDB Atlas database useratlas-create-free-cluster - Create a free MongoDB Atlas clusteratlas-create-project - Create a MongoDB Atlas projectatlas-get-performance-advisor - Get MongoDB Atlas performance advisor recommendations and suggestions, which includes the operations: suggested indexes, drop index suggestions, schema suggestions, and a sample of the most recent (max 50) slow query logsatlas-get-regions - List supported MongoDB Atlas regions for a cloud provider.atlas-inspect-access-list - Inspect Ip/CIDR ranges with access to your MongoDB Atlas clusters.atlas-inspect-cluster - Inspect metadata of a MongoDB Atlas clusteratlas-list-alerts - List triggered alerts for a MongoDB Atlas project. These are alerts Atlas has raised, not the alert configurations that define them. Defaults to OPEN alerts; set status to TRACKING or CLOSED to see others.atlas-list-clusters - List MongoDB Atlas clustersatlas-list-db-users - List MongoDB Atlas database usersatlas-list-orgs - List MongoDB Atlas organizationsatlas-list-projects - List MongoDB Atlas projects.atlas-load-sample-dataset - Load a MongoDB sample dataset into an Atlas cluster, or check the status of a previously-initiated load. To start a new load, provide clusterName — the load runs asynchronously and the response includes a jobId and initial state. To check progress, call this tool again with jobId (sample dataset loads typically take 1–5 minutes). State can be WORKING, COMPLETED, or FAILED.atlas-pause-resume-cluster - Pause or resume a dedicated (M10+) MongoDB Atlas cluster.atlas-streams-build - Create Atlas Stream Processing resources. Use this tool for 'set up a Kafka pipeline', 'create a workspace', 'add a connection', or 'deploy a processor'. Use resource='workspace' to create a new workspace (specify cloud provider, region, and tier). Use resource='connection' to add a data source or sink to an existing workspace. Use resource='processor' to deploy a stream processor with a pipeline. Use resource='privatelink' to set up private networking. Typical workflow: create workspace → add connections → deploy processor.atlas-streams-discover - Discover and inspect Atlas Stream Processing resources. Also use for 'why is my processor failing', 'what workspaces do I have', 'show processor stats', or 'check processor health'. Use 'list-workspaces' to see all workspaces in a project. Use inspect actions for details on a specific resource. Use 'diagnose-processor' for a combined health report including state, stats, connection health, and recent errors. Use 'get-networking' for PrivateLink and account details.atlas-streams-manage - Manage Atlas Stream Processing resources: start/stop processors, modify pipelines, update configurations. Also use for 'change the pipeline', 'scale up my processor', or 'update my workspace tier'. Common workflow: action='stop-processor' → action='modify-processor' → action='start-processor'. Use atlas-streams-discover with action 'inspect-processor' to check state before managing.atlas-streams-teardown - Delete Atlas Stream Processing resources. Also use for 'remove my workspace', 'disconnect a source', 'delete all processors', or 'clean up my streams environment'. Performs basic safety checks before deletion: summarizes counts of processors and connections, highlights connections referenced by processors where possible, and surfaces API errors if processors are still running when deletion is attempted. Use atlas-streams-discover to review resources before deleting.atlas-upgrade-cluster - Upgrade or scale a MongoDB Atlas cluster. Free and Flex clusters can be upgraded to Flex or M10 Dedicated. Dedicated clusters can be scaled to a different instance size, and compute autoscaling settings can be updated. When scaling a Dedicated cluster, at least one of targetTier, computeAutoScaling, minInstanceSize, or maxInstanceSize must be provided. Compute autoscaling defaults to enabled when upgrading to M10 Dedicated: min instance size is set to the selected instance size, max is set two tiers above, unless overridden. Note to LLM: If provider and region are not already known, ask for both together in a single question before calling this tool. Use atlas-get-regions to resolve natural-language locations or uncertain region codes before calling this tool.NOTE: atlas tools are only available when you set credentials on configuration section.
atlas-local-connect-deployment - Connect to a MongoDB Atlas Local deployment and get back a connectionId to pass to the other MongoDB toolsatlas-local-create-deployment - Create a MongoDB Atlas local deployment. Default image is preview. When the user does not specify an image tag, inform them that preview is used by default and provide this link for more information: https://hub.docker.com/r/mongodb/mongodb-atlas-localatlas-local-delete-deployment - Delete a MongoDB Atlas local deploymentatlas-local-list-deployments - List MongoDB Atlas local deploymentslist-knowledge-sources - List available data sources in the MongoDB Assistant knowledge base. Use this to explore available data sources or to find search filter parameters to use in search-knowledge.search-knowledge - Search for information in the MongoDB Assistant knowledge base. This includes official documentation, curated expert guidance, and other resources provided by MongoDB. Supports filtering by data source and version.config - Server configuration, supplied by the user either as environment variables or as startup arguments with sensitive parameters redacted. The resource can be accessed under URI config://config.debug - Debugging information for MongoDB connectivity issues. Tracks the last connectivity attempt and error information. The resource can be accessed under URI debug://mongodb.exported-data - A resource template to access the data exported using the export tool. The template can be accessed under URI exported-data://{exportName} where exportName is the unique name for an export generated by the export tool.🔒 Security Best Practice: We strongly recommend using environment variables for sensitive configuration such as API credentials (
MDB_MCP_API_CLIENT_ID,MDB_MCP_API_CLIENT_SECRET) and connection strings (MDB_MCP_CONNECTION_STRING) instead of command-line arguments. Environment variables are not visible in process lists and provide better security for your sensitive data.
The MongoDB MCP Server can be configured using multiple methods, with the following precedence (highest to lowest):
MDB_MCP_ALLOW_REQUEST_OVERRIDESWhen set to true, allows configuration values to be overridden via request headers and query parameters.
MDB_MCP_API_CLIENT_IDsecretAtlas API client ID for authentication. Required for running Atlas tools.
MDB_MCP_API_CLIENT_SECRETsecretAtlas API client secret for authentication. Required for running Atlas tools.
MDB_MCP_ASSISTANT_BASE_URLBase URL for the MongoDB Assistant API.
MDB_MCP_ATLAS_TEMPORARY_DATABASE_USER_LIFETIME_MSTime in milliseconds that temporary database users created when connecting to MongoDB Atlas clusters will remain active before being automatically deleted.
MDB_MCP_CONFIRMATION_REQUIRED_TOOLSComma separated values of tool names that require user confirmation before execution. Requires the client to support elicitation.
MDB_MCP_CONNECTION_STRINGsecretMongoDB connection string for direct database connections. Optional, if not set, you'll need to call the connect tool before interacting with MongoDB data.
MDB_MCP_DISABLED_TOOLSComma separated values of tool names, operation types, and/or categories of tools that will be disabled.
MDB_MCP_DRY_RUNWhen true, runs the server in dry mode: dumps configuration and enabled tools, then exits without starting the server.
MDB_MCP_EXPORT_CLEANUP_INTERVAL_MSTime in milliseconds between export cleanup cycles that remove expired export files.
MDB_MCP_EXPORT_TIMEOUT_MSTime in milliseconds after which an export is considered expired and eligible for cleanup.
MDB_MCP_EXPORTS_PATHFolder to store exported data files.
MDB_MCP_EXTERNALLY_MANAGED_SESSIONSWhen true, the HTTP transport allows requests with a session ID supplied externally through the 'mcp-session-id' header. When an external ID is supplied, the initialization request is optional.
MDB_MCP_HEALTH_CHECK_HOSTDeprecated. Use `monitoringServerHost` instead. Host address to bind the healthCheck HTTP server to (only used when transport is 'http'). If provided, `healthCheckPort` must also be set.
MDB_MCP_HEALTH_CHECK_PORTDeprecated. Use `monitoringServerPort` instead. Port number for the healthCheck HTTP server (only used when transport is 'http'). If provided, `healthCheckHost` must also be set.
MDB_MCP_HTTP_BODY_LIMITMaximum size of the HTTP request body in bytes (only used when transport is 'http'). This value is passed as the optional limit parameter to the Express.js json() middleware.
MDB_MCP_HTTP_HEADERSHeader that the HTTP server will validate when making requests (only used when transport is 'http').
MDB_MCP_HTTP_HOSTHost address to bind the HTTP server to (only used when transport is 'http').
MDB_MCP_HTTP_PORTPort number for the HTTP server (only used when transport is 'http'). Use 0 for a random port.
MDB_MCP_HTTP_RESPONSE_TYPEThe HTTP response type for tool responses: 'sse' for Server-Sent Events, 'json' for standard JSON responses.
MDB_MCP_IDLE_TIMEOUT_MSIdle timeout for a client to disconnect (only applies to http transport).
MDB_MCP_INDEX_CHECKWhen set to true, enforces that query operations must use an index, rejecting queries that perform a collection scan.
MDB_MCP_LOG_PATHFolder to store logs.
MDB_MCP_LOGGERSComma separated values of logger types.