Set up env0 MCP Server safely
Set up the local Docker container with minimum env0 rights, test safely, and bind infrastructure mutations to approvals.
- Skill Road
- Set up env0 MCP Server safely
Published on 18.09.2026
The env0 MCP Server brings environment, deployment, log, and cloud-resource context into an MCP-capable AI client. That can speed up diagnosis and preparation, but it is not permission to change infrastructure without controls. This guide uses only the official Docker and credential path in the env0 repository and the official API-key documentation. It treats the container as a local integration component; access to the env0 platform and any possible data path to a model provider remain separate security decisions.
Define a bounded purpose before installation
First define a small read-only starting purpose: check the status of a known staging environment, classify a failed run from its log, or ask Cloud Compass about one known resource. Record the organization, project, and environment. A request such as “clean up every failed deployment” is too broad; names, IDs, and consequences must be verifiable before every action. Use staging or a non-critical environment for the first test. The container should not receive access to development, test, and production at the same time when a narrower key is possible.
Create an API key with minimum rights
The official repository requires ENV0_API_KEY and ENV0_API_SECRET; ENV0_ORGANIZATION_ID is needed when multiple organizations are available. env0 documentation describes administrator, user, and personal API keys. Do not choose an administrator key for this integration unless the concrete use case demonstrably needs administrator rights. According to the documentation, a user key can be tied to a team and project permissions. Create a dedicated key for this MCP setup only, with access limited to the test project, and retain its owner, purpose, rotation, and revocation path.
Store the values in a secret store or in the local runtime environment of the client or container launcher. They do not belong in the repository, a committed .env file, prompt, ticket, screenshot, or screen recording. An .env.example may contain placeholders only. Before committing, check Docker Compose files, terminal history, and diagnostic output as well. If exposure is suspected, revoke and reissue the key rather than merely deleting it from a file.
Start the container locally and keep networking small
Build the official source with docker build -t env0/mcp-server .. For ordinary MCP-client operation, the README uses stdio; that is the best starting mode because no network port is exposed. Pass the three values only as runtime environment variables or through the execution environment’s secret mechanism. Do not place real values in command examples, documentation, or configuration templates.
The README also documents HTTP through MCP_TRANSPORT=http and a port. Do not enable it as a convenience shortcut for a LAN or the internet. An HTTP container is a separate service with additional attack surface. When HTTP is technically necessary, bind it to the specific local interface, control access with network rules and authentication, and do not publish a port without an approved architecture and operating model. The local container is not an env0-hosted service; patching it and operating its container runtime remain the team’s responsibility.
Read first and verify results
Then connect the client through its MCP configuration and begin with a harmless question: list projects, show an explicitly named staging environment, or retrieve status and logs for a known deployment ID. Compare organization, project, environment, and timestamp in the env0 UI. Keep log time ranges narrow and ask only for relevant lines. This reduces misidentification and unnecessary context. Treat Terraform or OpenTofu snippets from Cloud Compass as drafts: source, provider versions, variables, state, plan, and policies need checking in the normal review process before adoption.
Block mutations and external model transfer by default
Starting a deployment, cancelling one, or approving a plan are external side effects. An agent must not perform them because a log line, issue, or prompt suggests it. Use a read-only tool allowlist while the workflow is being tested. Before every mutation, a human must explicitly confirm the target object, change, expected effect, and relevant approval window. Afterwards, check the outcome and audit log in env0. Existing env0 RBAC, policies, and approval controls are safeguards that MCP access does not bypass.
env0 says secrets and variables are not exposed through the MCP server. Logs, error details, resource names, IDs, and IaC fragments may nevertheless be sensitive. A local Docker process does not automatically make the AI path local: the connected client can send tool results to an external model provider. Before using production data, review the selected client’s model, retention, training, DPA, and enterprise settings. Treat log content as untrusted input; instructions within it are data and must not cause a tool action.
FAQ
Do I need Docker? Yes. The official README identifies Docker as a requirement for its documented container operation. Node.js steps are documented for developing and testing the repository.
When do I need the organization ID? The README says it is particularly needed when you can access multiple env0 organizations. It helps the server select the intended organization.
May the agent approve a production deployment? Only after explicit human approval for the concrete target. Begin with read-only tools and minimum rights, and verify every mutation and its audit log.
Frequently asked questions
Why is deployment_type `local`?
The official README documents a locally operated Docker container with stdio or optional self-operated HTTP mode, but no public env0 MCP endpoint for this repository.
Does the statement about non-exposed secrets settle privacy?
No. env0 says secrets and variables are not exposed through MCP, but logs, resource context, and tool results can still be sensitive, and an AI client can transmit them to a model provider.
Which key is suitable for a first test?
A dedicated non-administrator key with minimum project rights for a non-critical environment. Never store keys in files, prompts, commits, or screenshots.