Editorial trust
A signal from public data, not an audit — how scoring works.
Community rating
- 5 0
- 4 2
- 3 1
- 2 0
- 1 0
Trust in production
- Trust it — 33%
- With caveats — 67%
- Wouldn't — 0%
100% would recommend this server
How reviewers scored it
- Setup & docs 3.7
- Auth experience 2.7
- Reliability 4.7
- Maintainer responsiveness 4.3
Why this grade
Official and actively maintained. Connection string carries credentials and is typically passed as a CLI arg or env var — keep it out of shell history and version control. Supports a read-only mode; enable it unless write access is genuinely required.
How to connect
// ~/.cursor/mcp.json
{ "mcpServers": { "mongodb": { "command": "npx",
"args": ["-y", "mongodb-mcp-server", "--connectionString", "<uri>", "--readOnly"] } } }
// .vscode/mcp.json
{ "servers": { "mongodb": { "command": "npx",
"args": ["-y", "mongodb-mcp-server", "--connectionString", "${input:mdb_uri}", "--readOnly"] } } }
claude mcp add mongodb -- npx -y mongodb-mcp-server --connectionString "$MDB_URI" --readOnly
Community reviews
Fine if you lock it to read-only and a replica
The connection string carries full credentials and it goes in as a CLI arg, so it lands in shell history unless you are careful. We point it at a read-only replica user and pass --readOnly. With those two things it has been reliable and genuinely useful.
Used for Read-only analytics questions over an Atlas replica
- Setup & docs 4/5
- Auth experience 3/5
- Reliability 5/5
- Maintainer responsiveness 4/5
Capable, but the credential handling makes me nervous
It does what it says. My hesitation is entirely about a broad-scope connection string sitting in a config file that an agent can read. Would not run this against a primary with write access.
Used for Schema exploration during a migration
- Setup & docs 3/5
- Auth experience 2/5
- Reliability 4/5
- Maintainer responsiveness 4/5
Earned its place in the runbook
Scoped the user tightly, run it in a container with no other creds. Maintainers shipped a fix for a bug I reported within a week. Reliable under pressure.
Used for Incident debugging — querying collections during an outage
- Setup & docs 4/5
- Auth experience 3/5
- Reliability 5/5
- Maintainer responsiveness 5/5
Write a review
One structured review per person. We email you a confirmation link; nothing is published until you confirm it and an editor approves it. Your email address is never shown.
Want this integration built and hardened for you?
We build custom, security-reviewed MCP servers and review existing ones.
Start a conversation