Terraform MCP Server: check the Registry before writing IaC
HashiCorp's official server lets agents look up current providers, modules and policies in the Terraform Registry, and manage HCP Terraform workspaces and runs.
Project and installation docs
View projecthttps://github.com/hashicorp/terraform-mcp-server
The classic failure when a model writes Terraform is stale memory: provider arguments it learned have since changed, resource names don’t match and attributes are deprecated, so terraform plan fails on the first run. Terraform MCP Server lets the agent check the Terraform Registry for current provider docs, modules and policies before writing anything, and, if you use HCP Terraform or Terraform Enterprise, read and manage workspaces too. HashiCorp maintains it; it had about 1.5k stars as of 2026-10-06.
What it does
- Registry lookups: search providers, read provider details and resource docs, and analyze public modules and policies. The
registrytoolset is the only one on by default. - Private registry: the
registry-privatetoolset reads your organization’s private modules and providers. - HCP Terraform and TFE: the
terraformtoolset lists organizations and projects, creates, updates and deletes workspaces, and manages variables, tags and runs. - Opt-in operations: tools that change infrastructure state are gated by
ENABLE_TF_OPERATIONS, which defaults to off. - Two transports: local stdio, or StreamableHTTP for a central deployment with rate limits, CORS and an organization allowlist.
Who it’s for
- Platform engineers having Claude Code or Cursor draft or upgrade Terraform, who want arguments to match current docs.
- Teams running many HCP Terraform workspaces who want to check status and trigger runs in plain language.
Setup
Needs Docker. Local stdio in Claude Code:
claude mcp add terraform -s user -t stdio -- docker run -i --rm hashicorp/terraform-mcp-server
For HCP Terraform or TFE, pass a token through TFE_TOKEN (and TFE_ADDRESS when needed), and enable workspace tools with --toolsets=registry,terraform.
Our take
For infrastructure as code, the official server’s advantage is simple: the data comes from the Registry itself, so the resource arguments an agent writes match the current release. Only the read-only Registry tools load by default, and workspace management and execution have to be switched on, which is a sensible default. Heed the README’s warnings: depending on the query, Terraform data is exposed to the MCP client and model, so don’t use it with untrusted clients, and review generated configuration against your security, cost and compliance rules. With TFE_TOKEN set the agent can delete workspaces, so scope the token. Licensed MPL-2.0.