Set up Qdrant MCP Server
Set up Qdrant semantic search through MCP, limit collection permissions, and control writes.
- Skill Road
- Set up Qdrant MCP Server
Published on 18.09.2026
The Qdrant MCP Server connects an MCP client to a Qdrant collection for semantic search. Start with a clearly scoped, non-production collection. That lets you check which text the client stores, which results return, and whether the data path to the selected AI model is acceptable. The server is not a replacement for source citations or access reviews.
Define prerequisites and the collection
Install uv so uvx mcp-server-qdrant can run the official server. Choose exactly one Qdrant route: QDRANT_URL for a Qdrant instance or QDRANT_LOCAL_PATH for a local database path. Also set COLLECTION_NAME. For a protected remote Qdrant, use only an API key with the collection permissions actually required. Keep keys out of Git, prompts, and screenshots.
Configure a local stdio client
Stdio is the default transport. In the MCP client, add command uvx with argument mcp-server-qdrant and pass environment variables only through the protected local client configuration. A test collection and harmless note are enough for the first run. Then check that qdrant-find returns only expected results. The README names sentence-transformers/all-MiniLM-L6-v2 as default; use only supported FastEmbed models.
Deliberately enable writes
qdrant-store writes data and can create a missing collection. For research, analysis, or code context without changes, set QDRANT_READ_ONLY=true; storing is then disabled. An agent should receive write access only after content, collection, and responsibility are clear. Treat metadata just like text: both can contain sensitive information and shape later search context.
Secure SSE or Streamable HTTP
The README also documents SSE and Streamable HTTP through --transport. These transports are intended for network clients, but they do not automatically make the process securely reachable. Bind the service as restrictively as possible, enforce authentication and TLS at a reverse proxy or infrastructure layer, and check that the API key reaches only expected collections. Test the network path without production content first.
Review the model path and results
Every search sends results to the MCP client. Review its model provider, logging, telemetry, and retention before storing or querying sensitive material. Local stdio alone does not mean the client will not process results further. Do not treat embeddings as anonymization, and validate semantic results against their sources. This keeps the installation a controlled search path rather than an opaque data export.
Frequently asked questions
Why begin with a test collection?
Because qdrant-store can write data and create a missing collection. A test collection exposes result quality, permissions, and the data path without changing production stores.
How do I prevent writes?
Set QDRANT_READ_ONLY=true. According to the README, that setting disables qdrant-store while leaving qdrant-find available for search.
What data does an external model see?
The MCP server returns results to the AI client. Whether and how they go to a model, logs, or telemetry depends on the client and its configuration and must be reviewed there.