MongoDB MCP Server
1,137 starsMongoDB's official MCP server: operate MongoDB databases and Atlas clusters in natural language — query documents, inspect schema, perform database operations. A --readOnly flag restricts the tool surface to reads; Atlas management features can be wired with separate Atlas API credentials.
- First published:2025-04-04
- data as of:
- 2026-09-30
- Licence:
- Apache-2.0
- Transport:
- stdio
- Primitives exposed:
- tools
What it can touch
It can operate whichever database the connection string points at: reading and modifying documents, collections and schema (writes included unless --readOnly is set). The connection string is itself a credential containing username/password, stored in client config or environment; Atlas API credentials additionally reach cloud cluster management.
Risk
Pointing it at production hands read/write/delete over your data to the agent: injection can drive bulk rewrites or exfiltration. Notably the official VS Code install entry defaults to --readOnly — take the hint: outside a dev database, start read-only. A leaked connection string is a leaked database.
Install prompt
從官方倉庫 README 取得客戶端設定片段(以 npx 啟動 mongodb-mcp-server,用 MDB_MCP_CONNECTION_STRING 環境變數傳入連線字串;唯讀用途加 --readOnly 參數),加進你的 MCP 客戶端設定檔後重啟客戶端。Paste this to your agent. It deliberately contains no tool subcommands — check the tool's official docs for commands.