Suggest a server AI tools directory →

Docker MCP server

Last verified: 2026-09

List containers and images on the local daemon.

Community Cloud & infra No API key Claude Desktop, Cursor, Windsurf, Claude Code

What it does

Talks to the local Docker socket: compose, containers, images, networks, volumes. No cloud key — the socket is the secret.

It sits in Cloud & infra: Most of these are admin APIs.

Good for

  • list_containers and fetch_container_logs on a compose project you can recreate.
  • docker_compose up/down a dev stack from the chat.
  • pull_image only from registries you already trust.
  • Never start with remove_image or a socket you share with prod.

Tools

  • docker_compose — Up/down a compose file.
  • list_containers / create_container / run_container / start_container / stop_container / remove_container / recreate_container / fetch_container_logs — Containers.
  • list_images / pull_image / push_image / build_image / remove_image — Images.
  • list_networks / create_network / list_volumes / create_volume — Networks and volumes.

Config (Claude Desktop / Cursor / Windsurf)

Paste the JSON below. Same mcpServers shape. Replace placeholder paths and secrets. Windows paths look like C:\\Users\\you\\project, not /path/to. Host-side steps →

Claude Desktop

OSConfig file
macOS~/Library/Application Support/Claude/claude_desktop_config.json
Windows%APPDATA%\Claude\claude_desktop_config.json (usually C:\Users\<you>\AppData\Roaming\Claude\)
Linux~/.config/Claude/claude_desktop_config.json

Cursor

ScopemacOS / LinuxWindows
This project.cursor/mcp.json in the repo root
This user~/.cursor/mcp.json %USERPROFILE%\.cursor\mcp.json

Windsurf

OSConfig file
macOS / Linux~/.codeium/windsurf/mcp_config.json
Windows%USERPROFILE%\.codeium\windsurf\mcp_config.json
{
  "mcpServers": {
    "docker": {
      "command": "npx",
      "args": [
        "-y",
        "docker-mcp"
      ]
    }
  }
}

Windsurf remote MCP: use serverUrl instead of url if the block below is HTTP.

One-liner: npx -y docker-mcp

Secrets it wants: none — talks to the Docker socket

Source repo →

How to get started

  1. Docker Desktop or a rootless engine. The host user must be able to talk to the socket.
  2. Ask it to list_containers first. Do not start with remove_image.
  3. Point it at a compose project you can recreate.

Access risk

The Docker socket is root-equivalent on most machines. remove_container and push_image are live.

When to skip it

Skip it for Kubernetes or a PaaS (Vercel/Netlify) if you never run Docker locally.

Instead: Kubernetes, Vercel, Filesystem.

Vs alternatives

ServerOfficial?Needs a secret?Best for
DockerNoNoList containers and images on the local daemon.
KubernetesNoYeskubectl-style cluster access.
VercelNoYesProjects and deployments on Vercel.
FilesystemYesNoRead and write files inside a folder you choose.

More in Cloud & infra

All 15 in this category →

FAQ

Is the Docker socket root?

On most machines, yes. Whoever talks to the socket can mount the host. This server is that access.

Do I need a key?

No. The socket is the secret. The host user must be in the docker group or equivalent.

Docker or Kubernetes?

Local engine vs cluster. If you only run compose, skip kubeconfig.

Can it push images?

push_image is in the list. That can publish whatever is on the machine.