Suggest a server AI tools directory →

Terraform MCP server

Last verified: 2026-09

Inspect Terraform plans and state.

Community Cloud & infra No API key Claude Desktop, Cursor, Windsurf, Claude Code

What it does

HashiCorp Terraform MCP. Can talk to Terraform CLI locally and/or Terraform Cloud/Enterprise via TFE_TOKEN. Tool names follow the current server — treat Cloud tokens as org admin until scoped.

It sits in Cloud & infra: Most of these are admin APIs.

Good for

  • Read provider/module docs without applying anything.
  • Inspect a Terraform Cloud workspace with a team token on one workspace.
  • Queue a plan you then review in the TFC UI.
  • Run the server with no TFE_TOKEN if you only wanted docs.

Tools

  • workspace / run / plan helpers — Inspect and queue runs when Cloud is connected.
  • provider / module docs — Local knowledge without applying.

Config (Claude Desktop / Cursor / Windsurf)

Paste the JSON below. Same mcpServers shape. Replace placeholder paths and secrets. Windows paths look like C:\\Users\\you\\project, not /path/to. Host-side steps →

Claude Desktop

OSConfig file
macOS~/Library/Application Support/Claude/claude_desktop_config.json
Windows%APPDATA%\Claude\claude_desktop_config.json (usually C:\Users\<you>\AppData\Roaming\Claude\)
Linux~/.config/Claude/claude_desktop_config.json

Cursor

ScopemacOS / LinuxWindows
This project.cursor/mcp.json in the repo root
This user~/.cursor/mcp.json %USERPROFILE%\.cursor\mcp.json

Windsurf

OSConfig file
macOS / Linux~/.codeium/windsurf/mcp_config.json
Windows%USERPROFILE%\.codeium\windsurf\mcp_config.json
{
  "mcpServers": {
    "terraform": {
      "command": "npx",
      "args": [
        "-y",
        "terraform-mcp-server"
      ],
      "env": {
        "TFE_TOKEN": "optional",
        "TFE_ADDRESS": "https://app.terraform.io"
      }
    }
  }
}

Windsurf remote MCP: use serverUrl instead of url if the block below is HTTP.

One-liner: npx -y terraform-mcp-server

Secrets it wants: none — local terraform

Source repo →

How to get started

  1. For docs-only, run the server with no TFE_TOKEN.
  2. For Cloud, create a team token scoped to one workspace.
  3. Never let it apply a workspace you cannot recreate from git.

Access risk

A TFE token can plan and apply infrastructure. That is production.

When to skip it

Skip it if you only needed kubectl or the AWS API.

Instead: AWS, Kubernetes, Git.

Vs alternatives

ServerOfficial?Needs a secret?Best for
TerraformNoNoInspect Terraform plans and state.
AWSNoYesCall AWS APIs with the default credential chain.
KubernetesNoYeskubectl-style cluster access.
GitYesNoRead a local git repo: log, diff, status.

More in Cloud & infra

All 15 in this category →

FAQ

Will it apply?

If Cloud/CLI tools that apply are connected, yes. Review the plan. A TFE token can be org-shaped until you scope it.

Local state?

HashiCorp's server covers CLI and/or TFC/TFE. Do not point it at state that contains production secrets without a plan.

Terraform or the AWS MCP?

Terraform if the source of truth is .tf. AWS MCP if you want live AWS APIs without a plan file.

Official HashiCorp?

Yes — hashicorp/terraform-mcp-server.