MongoDB MCP Server
Official MCP server connecting agents to MongoDB databases and Atlas clusters for queries, aggregation, and admin.
MongoDB MCP Server
The official MongoDB Model Context Protocol server lets AI agents work directly with MongoDB databases and MongoDB Atlas clusters. It covers day-to-day data operations plus Atlas control-plane management, so an agent can both read documents and provision infrastructure.
Key features
- Document operations: find, insert, update, delete, and run aggregation pipelines
- Collection and index management, including creating and inspecting indexes
- Schema introspection so agents can discover collections and field shapes before querying
- Atlas admin tools for listing clusters, projects, and database users via the Atlas API
- Read-only mode and connection-string scoping to constrain what agents can touch
- Distributed as an npm package for quick wiring into Claude, Cursor, and other MCP clients
Because it speaks native MongoDB and the Atlas API, it fits both application developers exploring a database and operators automating cluster management from an agent.
Curated mirror of the open-source mongodb-mcp-server (Apache-2.0). Get it from the source.
Compromise signals — malicious or tampered code (leaked secrets, backdoors, a dropped executable) — reduce the score, and known dependency CVEs carry a bounded penalty (they warrant review but never QUARANTINE — update the dependency to clear). Other dangerous-by-capability traits are risk surface, expected for some capabilities. Every finding is mapped to its OWASP control below.
Findings mapped to the OWASP Top 10 for LLM Applications (2025) and the OWASP Machine Learning Security Top 10. Expand any flagged control for the exact findings — compromise reduces the score; expected/risk-surface do not, except a known CVE, which carries a small bounded penalty (high/critical → Review).
The same gate an agent runs before installing (POST /api/v1/trust/mongodb-mcp-server/check). Click a policy:
Consume MongoDB MCP Server programmatically. Authenticate with an API key or session — see Authorize an agent.
# Agents: CHECK BEFORE YOU INSTALL (no auth) — score, grade, level, capability manifest
curl https://ai-supply.store/api/v1/trust/mongodb-mcp-server
# Gate against your org policy (returns { pass, violations })
curl -X POST https://ai-supply.store/api/v1/trust/mongodb-mcp-server/check \
-H "Content-Type: application/json" \
-d '{"minGrade":"B","denyPermissions":["shell"],"denyUnknownEgress":true}'
# CLI
npx ai-supply add mongodb-mcp-server
# REST (install → download)
curl -X POST https://ai-supply.store/api/v1/listings/mongodb-mcp-server/install \
-H "Authorization: Bearer $AIM_KEY"
# MCP tool
install_listing({ "slug": "mongodb-mcp-server" })OpenAPI spec →Curated mirror — latest upstream source. See the repository for tagged releases.