MongoDB MCP server
Last verified: 2026-09
Query MongoDB collections.
Community Databases & data Needs a secret Claude Desktop, Cursor, Windsurf, Claude Code, VS Code
What it does
Official MongoDB MCP. Local npx talks to any connection string; Atlas also has a hosted OAuth path. Can find, aggregate, write, and manage Atlas clusters depending on flags. README's install button uses --readOnly — start there.
It sits in Databases & data: A database MCP is SQL or an API with your credentials.
Good for
- find / aggregate on a staging cluster with --readOnly.
- Inspect collection-schema before writing an application query.
- List databases the URI can see, then one collection.
- Atlas extras only after you have seen the local read path work.
Tools
- find / aggregate / count — Read documents.
- insert-many / update-many / delete-many — Writes — off if you pass --readOnly.
- list-databases / list-collections / collection-schema / collection-indexes — Discover the cluster.
- Atlas cluster / user tools — When Atlas credentials are set.
Config (Claude Desktop / Cursor / Windsurf)
Paste the JSON below. Same mcpServers shape. Replace placeholder paths and secrets.
Windows paths look like C:\\Users\\you\\project, not /path/to.
Host-side steps →
Claude Desktop
| OS | Config file |
|---|---|
| macOS | ~/Library/Application Support/Claude/claude_desktop_config.json |
| Windows | %APPDATA%\Claude\claude_desktop_config.json
(usually C:\Users\<you>\AppData\Roaming\Claude\) |
| Linux | ~/.config/Claude/claude_desktop_config.json |
Cursor
| Scope | macOS / Linux | Windows |
|---|---|---|
| This project | .cursor/mcp.json in the repo root | |
| This user | ~/.cursor/mcp.json |
%USERPROFILE%\.cursor\mcp.json |
Windsurf
| OS | Config file |
|---|---|
| macOS / Linux | ~/.codeium/windsurf/mcp_config.json |
| Windows | %USERPROFILE%\.codeium\windsurf\mcp_config.json |
{
"mcpServers": {
"mongodb": {
"command": "npx",
"args": [
"-y",
"mongodb-mcp-server",
"--readOnly"
],
"env": {
"MDB_MCP_CONNECTION_STRING": "mongodb://..."
}
}
}
}
Windsurf remote MCP: use serverUrl instead of url if the block below is HTTP.
One-liner: npx -y mongodb-mcp-server
Secrets it wants: MDB_MCP_CONNECTION_STRING
How to get started
- Put a least-privilege URI in MDB_MCP_CONNECTION_STRING.
- Add --readOnly to args until you actually want writes.
- Ask it to list databases, then one collection schema.
Access risk
A URI with readWriteAnyDatabase is production access. --readOnly is the default you want.
When to skip it
Skip it for Postgres/SQLite (official servers) or a hosted Neon/Supabase project.
Instead: PostgreSQL, Supabase, Neon.
Vs alternatives
| Server | Official? | Needs a secret? | Best for |
|---|---|---|---|
| MongoDB | No | Yes | Query MongoDB collections. |
| PostgreSQL | Yes | Yes | Run SQL against a Postgres database. |
| Supabase | No | Yes | Talk to a Supabase project: tables, auth, edge functions. |
| Neon | No | Yes | Manage and query Neon Postgres. |
More in Databases & data
FAQ
How do I keep it from writing?
The README install uses --readOnly. Keep that flag until you want inserts. A URI with readWriteAnyDatabase is production access.
Local npx or Atlas hosted?
Hosted Atlas MCP via OAuth if you only use Atlas. Local mongodb-mcp-server for any connection string.
Mongo or Postgres?
Whichever the app already uses. Do not add both write paths.
Does find return the whole collection?
It can return a lot. Ask for a filter and a limit. Huge dumps waste tokens and may include PII.