Terraform MCP server
Last verified: 2026-09
Inspect Terraform plans and state.
Community Cloud & infra No API key Claude Desktop, Cursor, Windsurf, Claude Code
What it does
HashiCorp Terraform MCP. Can talk to Terraform CLI locally and/or Terraform Cloud/Enterprise via TFE_TOKEN. Tool names follow the current server — treat Cloud tokens as org admin until scoped.
It sits in Cloud & infra: Most of these are admin APIs.
Good for
- Read provider/module docs without applying anything.
- Inspect a Terraform Cloud workspace with a team token on one workspace.
- Queue a plan you then review in the TFC UI.
- Run the server with no TFE_TOKEN if you only wanted docs.
Tools
- workspace / run / plan helpers — Inspect and queue runs when Cloud is connected.
- provider / module docs — Local knowledge without applying.
Config (Claude Desktop / Cursor / Windsurf)
Paste the JSON below. Same mcpServers shape. Replace placeholder paths and secrets.
Windows paths look like C:\\Users\\you\\project, not /path/to.
Host-side steps →
Claude Desktop
| OS | Config file |
|---|---|
| macOS | ~/Library/Application Support/Claude/claude_desktop_config.json |
| Windows | %APPDATA%\Claude\claude_desktop_config.json
(usually C:\Users\<you>\AppData\Roaming\Claude\) |
| Linux | ~/.config/Claude/claude_desktop_config.json |
Cursor
| Scope | macOS / Linux | Windows |
|---|---|---|
| This project | .cursor/mcp.json in the repo root | |
| This user | ~/.cursor/mcp.json |
%USERPROFILE%\.cursor\mcp.json |
Windsurf
| OS | Config file |
|---|---|
| macOS / Linux | ~/.codeium/windsurf/mcp_config.json |
| Windows | %USERPROFILE%\.codeium\windsurf\mcp_config.json |
{
"mcpServers": {
"terraform": {
"command": "npx",
"args": [
"-y",
"terraform-mcp-server"
],
"env": {
"TFE_TOKEN": "optional",
"TFE_ADDRESS": "https://app.terraform.io"
}
}
}
}
Windsurf remote MCP: use serverUrl instead of url if the block below is HTTP.
One-liner: npx -y terraform-mcp-server
Secrets it wants: none — local terraform
How to get started
- For docs-only, run the server with no TFE_TOKEN.
- For Cloud, create a team token scoped to one workspace.
- Never let it apply a workspace you cannot recreate from git.
Access risk
A TFE token can plan and apply infrastructure. That is production.
When to skip it
Skip it if you only needed kubectl or the AWS API.
Instead: AWS, Kubernetes, Git.
Vs alternatives
| Server | Official? | Needs a secret? | Best for |
|---|---|---|---|
| Terraform | No | No | Inspect Terraform plans and state. |
| AWS | No | Yes | Call AWS APIs with the default credential chain. |
| Kubernetes | No | Yes | kubectl-style cluster access. |
| Git | Yes | No | Read a local git repo: log, diff, status. |
More in Cloud & infra
FAQ
Will it apply?
If Cloud/CLI tools that apply are connected, yes. Review the plan. A TFE token can be org-shaped until you scope it.
Local state?
HashiCorp's server covers CLI and/or TFC/TFE. Do not point it at state that contains production secrets without a plan.
Terraform or the AWS MCP?
Terraform if the source of truth is .tf. AWS MCP if you want live AWS APIs without a plan file.
Official HashiCorp?
Yes — hashicorp/terraform-mcp-server.