MongoDB MCP Server: query collections and manage Atlas
MongoDB's official MCP server: agents query, aggregate and read plans, and with Atlas credentials manage clusters and users. Examples default to read-only.
Project and installation docs
View projecthttps://github.com/mongodb-js/mongodb-mcp-server
A document database has no fixed schema, so before an agent writes a query it needs to learn what each collection actually holds. MongoDB MCP Server, maintained by MongoDB, infers collection schemas, runs queries and aggregations, and with Atlas credentials manages cloud projects and clusters too. It had about 1.1k stars as of 2026-10-06.
What it does
- Reading data:
find,aggregateandcountfor queries,collection-schemato describe a collection,explainfor plans andexportfor EJSON output. - Writes and schema changes:
insert-many,update-many,delete-many,create-index,drop-collectionand more, none of which register in read-only mode. - Atlas management: with service account credentials, list and create clusters, database users and IP access lists, read Performance Advisor suggestions and manage stream processing.
- Local Atlas: the
atlas-local-*tools create and connect to an Atlas Local deployment on your machine.
Who it’s for
- Developers building on MongoDB who want Claude Code or Cursor to read a collection’s shape before writing queries.
- Operators managing Atlas projects who’d like to check alerts and performance advice in plain language.
Setup
Needs Node.js 22.13 or newer, plus a connection string or Atlas service account credentials. The quickest path is the interactive setup:
npx -y mongodb-mcp-server@latest setup
Or configure a connection string by hand; the README’s examples all include --readOnly:
{
"mcpServers": {
"MongoDB": {
"command": "npx",
"args": ["-y", "mongodb-mcp-server@latest", "--readOnly"],
"env": {
"MDB_MCP_CONNECTION_STRING": "mongodb://localhost:27017/myDatabase"
}
}
}
}
Our take
For the document-database slot the official server is the obvious pick: its tools run from queries to Atlas operations, and the safety defaults are thoughtful. Examples are read-only by default. Dangerous tools such as drop-database and delete-many ask for confirmation by default, and so do aggregation pipelines with an $out or $merge stage, but only if your client supports elicitation; otherwise they just run. Think before dropping --readOnly or granting a powerful Atlas service account, because it can delete databases and create clusters, and clusters cost money. Usage telemetry is on by default; DO_NOT_TRACK=1 turns it off. Licensed Apache-2.0.