general MCP Server
🍃🔎 MongoDB Lens: Full Featured MCP Server for MongoDB Databases
Discovered via unknown and last synced 3mo ago.
1. Install the package
npx mongodb-lens
2. Add to claude_desktop_config.json
{
"mcpServers": {
"mongodb-lens": {
"command": "npx",
"args": [
"mongodb-lens"
]
}
}
}Config file location: ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) / %APPDATA%\Claude\claude_desktop_config.json (Windows)
`CONFIG_MONGO_URI`
`CONFIG_LOG_LEVEL`
`CONFIG_DEFAULT_DB_NAME`
For environment variable values: - For boolean settings, use string values `'true'` or `'false'`. - For numeric settings, use string representations. - For nested objects or arrays, use JSON strings. Example NPX usage: ```console CONFIG_DEFAULTS_QUERY_LIMIT='25' npx -y mongodb-lens@latest ``` Example Docker Hub usage: ```console docker run --rm -i --network=host --pull=always -e CONFIG_DEFAULTS_QUERY_LIMIT='25' furey/mongodb-lens ``` ### Configuration: Cross-Platform Environment Variables For consistent environment variable usage across Windows, macOS, and Linux, consider using `cross-env`: 1. Install cross-env globally:<br> ```console # Using NPM npm install -g cross-env # Using Volta (see: https://volta.sh) volta install cross-env ``` 1. Prefix any NPX or Node.js environment variables in this document's examples:<br> ```console # Example NPX usage with cross-env cross-env CONFIG_DEFAULTS_QUERY_LIMIT='25' npx -y mongodb-lens@latest # Example Node.js usage with cross-env cross-env CONFIG_DEFAULTS_QUERY_LIMIT='25' node mongodb-lens.js ``` ## Client Setup - [Claude Desktop](#client-setup-claude-desktop) - [MCP Inspector](#client-setup-mcp-inspector) - [Other MCP Clients](#client-setup-other-mcp-clients) ### Client Setup: Claude Desktop To use MongoDB Lens with Claude Desktop: 1. Install [Claude Desktop](https://claude.ai/download) 1. Open `claude_desktop_config.json` (create if it doesn't exist): - macOS: `~/Library/Application Support/Claude/claude_desktop_config.json` - Windows: `%APPDATA%\Claude\claude_desktop_config.json` 1. Add the MongoDB Lens server configuration as per [configuration options](#claude-desktop-configuration-options) 1. Restart Claude Desktop 1. Start a conversation with Claude about your MongoDB data #### Claude Desktop Configuration Options - [Option 1: NPX (Recommended)](#option-1-npx-recommended) - [Option 2: Docker Hub Image](#option-2-docker-hub-image) - [Option 3: Local Node.js Installation](#option-3-local-nodejs-installation) - [Option 4: Local Docker Image](#option-4-local-docker-image) For each option: - Replace `mongodb://your-connection-string` with your MongoDB connection string or omit it to use the default `mongodb://localhost:27017`. - To use a custom config file, set [`CONFIG_PATH`](#configuration-config-file) environment variable. - To include environment variables: - For NPX or Node.js add `"env": {}` with key-value pairs, for example:<br> ```json "command": "/path/to/npx", "args": [ "-y", "mongodb-lens@latest", "mongodb://your-connection-string" ], "env": { "CONFIG_LOG_LEVEL": "verbose" } ``` - For Docker add `-e` flags, for example:<br> ```json "command": "docker", "args": [ "run", "--rm", "-i", "--network=host", "--pull=always", "-e", "CONFIG_LOG_LEVEL=verbose", "furey/mongodb-lens", "mongodb://your-connection-string" ] ``` ##### Option 1: NPX (Recommended) ```json { "mcpServers": { "mongodb-lens": { "command": "/path/to/npx", "args": [ "-y", "mongodb-lens@latest", "mongodb://your-connection-string" ] } } } ``` ##### Option 2: Docker Hub Image ```json { "mcpServers": { "mongodb-lens": { "command": "docker", "args": [ "run", "--rm", "-i", "--network=host", "--pull=always", "furey/mongodb-lens", "mongodb://your-connection-string" ] } } } ``` ##### Option 3: Local Node.js Installation ```json { "mcpServers": { "mongodb-lens": { "command": "/path/to/node", "args": [ "/path/to/mongodb-lens.js", "mongodb://your-connection-string" ] } } } ``` ##### Option 4: Local Docker Image ```json { "mcpServers": { "mongodb-lens": { "command": "docker", "args": [ "run", "--rm", "-i", "--network=host", "mongodb-lens", "mongodb://your-connection-string" ] } } } ``` ### Client Setup: MCP Inspector [MCP Inspector](https://github.com/modelcontextprotocol/inspector) is a tool designed for testing and debugging MCP servers. > [!NOTE]<br> > MCP Inspector starts a proxy server on port 3000 and web client on port 5173. Example NPX usage: 1. Run MCP Inspector:<br> ```console # Using default connection string mongodb://localhost:27017 npx -y @modelcontextprotocol/inspector npx -y mongodb-lens@latest # Using custom connection string npx -y @modelcontextprotocol/inspector npx -y mongodb-lens@latest mongodb://your-connection-string # Using custom ports SERVER_PORT=1234 CLIENT_PORT=5678 npx -y @modelcontextprotocol/inspector npx -y mongodb-lens@latest ``` 1. Open MCP Inspector: http://localhost:5173 MCP Inspector should support the full range of MongoDB Lens capabilities, including autocompletion for collection names and query fields. For more, see: [MCP Inspector](https://modelcontextprotocol.io/docs/tools/inspector) ### Client Setup: Other MCP Clients MongoDB Lens should be usable with any MCP-compatible client. For more, see: [MCP Documentation: Example Clients](https://modelcontextprotocol.io/clients) ## Data Protection To protect your data while using MongoDB Lens, consider the following: - [Read-Only User Accounts](#data-protection-read-only-user-accounts) - [Working with Database Backups](#data-protection-working-with-database-backups) - [Data Flow Considerations](#data-protection-data-flow-considerations) - [Confirmation for Destructive Operations](#data-protection-confirmation-for-destructive-operations) - [Disabling Destructive Operations](#data-protection-disabling-destructive-operations) ### Data Protection: Read-Only User Accounts When connecting MongoDB Lens to your database, the permissions granted to the user in the MongoDB connection string dictate what actions can be performed. When the use case fits, a read-only user can prevent unintended writes or deletes, ensuring MongoDB Lens can query data but not alter it. To set this up, create a user with the `read` role scoped to the database(s) you're targeting. In MongoDB shell, you'd run something like: ```js use admin db.createUser({ user: 'readonly', pwd: 'eXaMpLePaSsWoRd', roles: [{ role: 'read', db: 'mydatabase' }] }) ``` Then, apply those credentials to your MongoDB connection string: ```txt mongodb://readonly:eXaMpLePaSsWoRd@localhost:27017/mydatabase ``` Using read-only credentials is a simple yet effective way to enforce security boundaries, especially when you're poking around schemas or running ad-hoc queries. ### Data Protection: Working with Database Backups When working with MongoDB Lens, consider connecting to a backup copy of your data hosted on a separate MongoDB instance. Start by generating the backup with `mongodump`. Next, spin up a fresh MongoDB instance (e.g. on a different port like `27018`) and restore the backup there using `mongorestore`. Once it's running, point MongoDB Lens to the backup instance's connection string (e.g. `mongodb://localhost:27018/mydatabase`). This approach gives you a sandbox to test complex or destructive operations against without risking accidental corruption of your live data. ### Data Protection: Data Flow Considerations - [How Your Data Flows Through the System](#data-flow-considerations-how-your-data-flows-through-the-system) - [Protecting Sensitive Data with Projection](#data-flow-considerations-protecting-sensitive-data-with-projection) - [Connection Aliases and Passwords](#data-flow-considerations-connection-aliases-and-passwords) - [Local Setup for Maximum Safety](#data-flow-considerations-local-setup-for-maximum-safety) #### Data Flow Considerations: How Your Data Flows Through the System When using an MCP Server with a remote LLM provider (such as Anthropic via Claude Desktop) understanding how your data flows through the system is key to protecting sensitive information from unintended exposure. When you send a MongoDB related query through your MCP client, here’s what happens: > [!NOTE]<br> > While this example uses a local MongoDB instance, the same principles apply to remote MongoDB instances. ```mermaid sequenceDiagram actor User box Local Machine #d4f1f9 participant Client as MCP Client participant Lens as MongoDB Lens participant MongoDB as MongoDB Instance end box Remote Server #ffe6cc participant LLM as Remote LLM Provider end User->>Client: 1. Submit request<br>"Show me all users older than 30" Client->>LLM: 2. User request + available tools Note over LLM: Interprets request<br>Chooses appropriate tool LLM->>Client: 3. Tool selection (find-documents) Client->>Lens: 4. Tool run with parameters Lens->>MongoDB: 5. Database query MongoDB-->>Lens: 6. Database results Lens-->>Client: 7. Tool results (formatted data) Client->>LLM: 8. Tool results Note over LLM: Processes results<br>Formats response LLM-->>Client: 9. Processed response Client-->>User: 10. Final answer ``` 1. You submit a request<br><sup>➥ e.g. "Show me all users older than 30"</sup> 1. Your client sends the request to the remote LLM<br><sup>➥ The LLM provider receives your exact words along with a list of available MCP tools and their parameters.</sup> 1. The remote LLM interprets your request<br><sup>➥ It determines your intent and instructs the client to use a specific MCP tool with appropriate parameters.</sup> 1. The client asks MongoDB Lens to run the tool<br><sup>➥ This occurs locally on your machine via stdio.</sup> 1. MongoDB Lens queries your MongoDB database 1. MongoDB Lens retrieves your MongoDB query results 1. MongoDB Lens sends the data back to the client<br><sup>➥ The client receives results formatted by MongoDB Lens.</sup> 1. The client forwards the data to the remote LLM<br><sup>➥ The LLM provider sees the exact data returned by MongoDB Lens.</sup> 1. The remote LLM processes the data<br><sup>➥ It may summarize or format the results further.</sup> 1. The remote LLM sends the final response to the client<br><sup>➥ The client displays the answer to you.</sup> The remote LLM provider sees both your original request and the full response from MongoDB Lens. If your database includes sensitive fields (e.g. passwords, personal details, etc) this data could be unintentionally transmitted to the remote provider unless you take precautions. #### Data Flow Considerations: Protecting Sensitive Data with Projection To prevent sensitive data from being sent to the remote LLM provider, use the concept of projection when using tools like `find-documents`, `aggregate-data`, or `export-data`. Projection allows you to specify which fields to include or exclude in query results, ensuring sensitive information stays local. Example projection usage: - _"Show me all users older than 30, but use projection to hide their passwords."_<br> <sup>➥ Uses `find-documents` tool with projection</sup> #### Data Flow Considerations: Connection Aliases and Passwords When adding new connection aliases using the `add-connection-alias` tool, avoid added aliases to URIs that contain passwords if you're using a remote LLM provider. Since your request is sent to the LLM, any passwords in the URI could be exposed. Instead, define aliases with passwords in the MongoDB Lens [config file](#configuration-multiple-mongodb-connections), where they remain local and are not transmitted to the LLM. #### Data Flow Considerations: Local Setup for Maximum Safety While outside the scope of this document, for the highest level of data privacy, consider using a local MCP client paired with a locally hosted LLM model. This approach keeps all requests and data within your local environment, eliminating the risk of sensitive information being sent to a remote provider. ### Data Protection: Confirmation for Destructive Operations MongoDB Lens implements a token-based confirmation system for potentially destructive operations, requiring a two-step process to execute tools that may otherwise result in unchecked data loss: 1. First tool invocation: Returns a 4-digit confirmation token that expires after 5 minutes 1. Second tool invocation: Executes the operation if provided with the valid token For an example of the confirmation process, see: [Working with Confirmation Protection](#tutorial-5-working-with-confirmation-protection) Tools that require confirmation include: - `drop-user`: Remove a database user - `drop-index`: Remove an index (potential performance impact) - `drop-database`: Permanently delete a database - `drop-collection`: Delete a collection and all its documents - `delete-document`: Delete one or multiple documents - `bulk-operations`: When including delete operations - `rename-collection`: When the target collection exists and will be dropped This protection mechanism aims to prevent accidental data loss from typos and unintended commands. It's a safety net ensuring you're aware of the consequences before proceeding with potentially harmful actions. > [!NOTE]<br> > If you're working in a controlled environment where data loss is acceptable, you can configure MongoDB Lens to [bypass confirmation](#bypassing-confirmation-for-destructive-operations) and perform destructive operations immediately. #### Bypassing Confirmation for Destructive Operations You might want to bypass the token confirmation system. Set the environment variable `CONFIG_DISABLE_DESTRUCTIVE_OPERATION_TOKENS` to `true` to execute destructive operations immediately without confirmation: ```console # Using NPX CONFIG_DISABLE_DESTRUCTIVE_OPERATION_TOKENS=true npx -y mongodb-lens@latest # Using Docker docker run --rm -i --network=host --pull=always -e CONFIG_DISABLE_DESTRUCTIVE_OPERATION_TOKENS='true' furey/mongodb-lens ``` > [!WARNING]<br> > Disabling confirmation tokens removes an important safety mechanism. It's strongly recommended to only use this option in controlled environments where data loss is acceptable, such as development or testing. Disable at your own risk. ### Data Protection: Disabling Destructive Operations - [Disabling Tools](#disabling-tools) - [High-Risk Tools](#high-risk-tools) - [Medium-Risk Tools](#medium-risk-tools) - [Read-Only Configuration](#read-only-configuration) - [Selective Component Enabling](#selective-component-enabling) #### Disabling Tools MongoDB Lens includes several tools that can modify or delete data. To disable specific tools, add them to the `disabled.tools` array in your [configuration file](#configuration-config-file): ```json { "disabled": { "tools": [ "drop-user", "drop-index", "drop-database", "drop-collection", "delete-document", "bulk-operations", "rename-collection" ] } } ``` > [!NOTE]<br> > Resources and prompts can also be disabled via `disabled.resources` and `disabled.prompts` settings. #### High-Risk Tools These tools can cause immediate data loss and should be considered for disabling in sensitive environments: - `drop-user`: Removes database users and their access permissions - `drop-index`: Removes indexes (can impact query performance) - `drop-database`: Permanently deletes entire databases - `drop-collection`: Permanently deletes collections and all their documents - `delete-document`: Removes documents matching specified criteria - `bulk-operations`: Can perform batch deletions when configured to do so - `rename-collection`: Can overwrite existing collections when using the drop target option #### Medium-Risk Tools These tools can modify data but typically don't cause immediate data loss: - `create-user`: Creates users with permissions that could enable further changes - `transaction`: Executes multiple operations in a transaction (potential for complex changes) - `update-document`: Updates documents which could overwrite existing data #### Read-Only Configuration For a complete read-only configuration, disable all potentially destructive tools: ```json { "disabled": { "tools": [ "drop-user", "drop-index", "create-user", "transaction", "create-index", "drop-database", "drop-collection", "insert-document", "update-document", "delete-document", "bulk-operations", "create-database", "gridfs-operation", "create-collection", "rename-collection", "create-timeseries" ] } } ``` This configuration allows MongoDB Lens to query and analyze data while preventing any modifications, providing multiple layers of protection against accidental data loss. #### Selective Component Enabling In addition to [disabling components](#disabling-tools), specify exactly which components should be enabled (implicitly disabling all others) using the `enabled` settings in your [configuration file](#configuration-config-file): ```json { "enabled": { "tools": [ "use-database", "find-documents", "count-documents", "aggregate-data" ] }, "disabled": { "resources": true, "prompts": true } } ``` > [!IMPORTANT]<br> > If a component appears in both `enabled` and `disabled` lists, the `enabled` setting takes precedence. ## Tutorial This following tutorial guides you through setting up a MongoDB container with sample data, then using MongoDB Lens to interact with it through natural language queries: 1. [Start Sample Data Container](#tutorial-1-start-sample-data-container) 1. [Import Sample Data](#tutorial-2-import-sample-data) 1. [Connect MongoDB Lens](#tutorial-3-connect-mongodb-lens) 1. [Example Queries](#tutorial-4-example-queries) 1. [Working With Confirmation Protection](#tutorial-5-working-with-confirmation-protection) ### Tutorial: 1. Start Sample Data Container > [!NOTE]<br> > This tutorial assumes you have [Docker](https://docs.docker.com/get-started/get-docker/) installed and running on your system. > [!IMPORTANT]<br> > If Docker is already running a container on port 27017, stop it before proceeding. 1. Initialise the sample data container:<br> ```console docker run --name mongodb-sampledata -d -p 27017:27017 mongo:6 ``` 1. Verify the container is running without issue:<br> ```console docker ps
Description
Detect and exploit NoSQL injection vulnerabilities in MongoDB, CouchDB, and other NoSQL databases to demonstrate authentication bypass, data extraction, and unauthorized access risks.
Azure.ResourceManager.MongoDBAtlas SDK workflow skill. Use this skill when the user needs Manage MongoDB Atlas Organizations as Azure ARM resources with unified billing through Azure Marketplace and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
Learn how to use the exploiting-nosql-injection-vulnerabilities Claude skill. Complete guide with installation instructions and examples.
Learn how to use the azure-mgmt-mongodbatlas-dotnet-v2 Claude skill. Complete guide with installation instructions and examples.