VendorMongoDB
Transportstdio

Editorial trust

Authentication yes
Maintenance Active · 2026-07
Known CVEs 0
Transport stdio

A signal from public data, not an audit — how scoring works.

Community rating

3.7 3 reviews
33% would trust it in production
  • 5 0
  • 4 2
  • 3 1
  • 2 0
  • 1 0

Trust in production

  • Trust it — 33%
  • With caveats — 67%
  • Wouldn't — 0%

100% would recommend this server

How reviewers scored it

  • Setup & docs 3.7
  • Auth experience 2.7
  • Reliability 4.7
  • Maintainer responsiveness 4.3

Why this grade

Official and actively maintained. Connection string carries credentials and is typically passed as a CLI arg or env var — keep it out of shell history and version control. Supports a read-only mode; enable it unless write access is genuinely required.

How to connect

// ~/.cursor/mcp.json
{ "mcpServers": { "mongodb": { "command": "npx",
  "args": ["-y", "mongodb-mcp-server", "--connectionString", "<uri>", "--readOnly"] } } }

Community reviews

Sven Aaltonen DBA, ecommerce
Trusts with caveats Recommends

Fine if you lock it to read-only and a replica

The connection string carries full credentials and it goes in as a CLI arg, so it lands in shell history unless you are careful. We point it at a read-only replica user and pass --readOnly. With those two things it has been reliable and genuinely useful.

Used for Read-only analytics questions over an Atlas replica

  • Setup & docs 4/5
  • Auth experience 3/5
  • Reliability 5/5
  • Maintainer responsiveness 4/5
Grace Okafor Backend engineer
Trusts with caveats Recommends

Capable, but the credential handling makes me nervous

It does what it says. My hesitation is entirely about a broad-scope connection string sitting in a config file that an agent can read. Would not run this against a primary with write access.

Used for Schema exploration during a migration

  • Setup & docs 3/5
  • Auth experience 2/5
  • Reliability 4/5
  • Maintainer responsiveness 4/5
Ravi Menon SRE
Trusts in production Recommends

Earned its place in the runbook

Scoped the user tightly, run it in a container with no other creds. Maintainers shipped a fix for a bug I reported within a week. Reliable under pressure.

Used for Incident debugging — querying collections during an outage

  • Setup & docs 4/5
  • Auth experience 3/5
  • Reliability 5/5
  • Maintainer responsiveness 5/5

Write a review

One structured review per person. We email you a confirmation link; nothing is published until you confirm it and an editor approves it. Your email address is never shown.

Overall rating
Would you trust this server in production?
Would you recommend it to another team?

Want this integration built and hardened for you?

We build custom, security-reviewed MCP servers and review existing ones.

Start a conversation