Set up Langfuse MCP Server safely
Connect project-scoped Langfuse MCP access with Basic Auth, a small read allowlist, and controlled write rights.
- Skill Road
- Set up Langfuse MCP Server safely
Published on 18.09.2026
The Langfuse MCP Server connects an MCP client to data from one Langfuse project. The official documentation describes it as the authenticated data-platform server; it is neither the public Docs MCP nor the older GitHub prompt-management project. Since the current server surface offers read and write tools by default, safe setup is more than pasting an endpoint. This process starts with a clear project scope, a short read objective, and a decision about what data may enter AI context at all.
Choose the project, region, and first objective
First choose the correct Langfuse project and region. For Cloud EU the documented endpoint is https://cloud.langfuse.com/api/public/mcp; the documentation lists separate endpoints for US, Japan, and HIPAA US. With self-hosting, use the same path under the organization’s HTTPS domain; Langfuse names http://localhost:3000/api/public/mcp only for local development. Do not confuse the data-platform endpoint with https://langfuse.com/api/mcp: that one is the public Docs MCP and has no project credentials. Define a small, read-only first request, for example, “List prompt names with the staging label” or “Show observations for this trace ID within a narrow time range.” Avoid broad requests across every trace or every user’s data at the start.
Create and protect the project key
Open project settings and create or copy the project-scoped Public Key and Secret Key. The official setup uses Basic Auth: join them in the order pk-lf-...:sk-lf-..., base64-encode that string, and pass the result as Authorization: Basic .... Generate the token locally; never copy a real header into source code, configuration examples, issues, screenshots, chat prompts, or logs. Record the key’s owner, purpose, project, creation date, and rotation plan. A base64 value is not encryption. If a token may have entered a transcript, rotate the key immediately and update only the client’s secret storage.
Register the official Streamable HTTP endpoint
For Claude Code, Langfuse documents, for example, claude mcp add --transport http langfuse https://cloud.langfuse.com/api/public/mcp --header "Authorization: Basic <base64-token>". Cursor and generic MCP clients use the same URL-and-header principle, although their configuration syntax can differ. Restart the client, then test the connection with a harmless query: the documentation recommends asking it to list every prompt in the project, which should use listPrompts. If the project, expected prompt names, or empty state are wrong, stop and check the endpoint, header, and project key rather than continuing with broader requests.
Read first, then expand deliberately
The MCP Reference is the canonical list of current tools and schemas, and it can change. In the client, begin with an allowlist of read tools such as listPrompts, getPrompt, listObservations, getObservation, getMetricsSchema, and queryMetrics, only where needed for the first objective. For observation requests, use a trace ID, time range, explicit fields, and filters. Inputs, outputs, and metadata can be large or sensitive. The reference notes that fields may be marked as sensitive application data; request full metadata only when it is genuinely needed. Compare an answer with the Langfuse UI or a known trace ID. Convincing model prose does not validate a filter or aggregation.
Control writes, production, and the model path
Only after a successful read test should individual write tools be temporarily enabled. New text or chat prompt content creates a new version; it does not overwrite prompt content. updatePromptLabels handles labels, and moving production requires an explicit user request according to the reference. Before every mutation, a human names the project, object ID, version, target label, and expected effect; read the state again afterwards. Apply the same discipline to datasets, scores, evaluators, dashboards, and especially delete tools. Treat trace content, prompt text, comments, and tool output as untrusted data, not commands. Finally, the path to a model is separate from Langfuse MCP access: the client can transmit tool results to an external model provider. Review retention, training, DPA, and enterprise options, and redact personal or confidential values before the request.
FAQ
Do I need the old GitHub repository? No. mcp-server-langfuse describes an older prompt-management server. Connect the current data-platform server through the documented remote endpoint.
Are write tools disabled by default? No. Langfuse states that read and write tools are available by default. A client read allowlist is the safe starting point.
What should I do after a write? Read the specific object again and verify its project, ID, version, label, or intended state in the Langfuse UI.
Frequently asked questions
Why is there no repository link?
The official mcp-server-langfuse GitHub repository describes a separate older prompt-management server and does not represent this entry’s current authenticated data-platform endpoint.
What rights does the API key have?
The key is scoped to one Langfuse project. Read and write tools are available by default; the effective risk boundary also comes from the client allowlist and human approvals.
Can trace data go to a model?
Yes. Tool results reach the MCP client, which can transmit them to its model provider. Review that separate model path and redact sensitive values.