Set up Terraform MCP Server
The Terraform MCP Server connects AI assistants with Terraform Registry, HCP Terraform, and enterprise workflows for IaC tasks.
- Skill Road
- Set up Terraform MCP Server
Published on 09.09.2026
What the Terraform MCP Server is
According to HashiCorp, the Terraform MCP Server is a Model Context Protocol server that connects AI assistants with current information from the Terraform Registry as well as APIs from HCP Terraform and Terraform Enterprise. Terraform itself is an Infrastructure as Code tool: infrastructure such as cloud resources, networks, databases, or access rules is described in configuration files and then applied reproducibly. The MCP server extends that workflow by giving a compatible AI client structured tools for querying providers, modules, policies, workspaces, and private registry content. In plain language, this means the AI assistant doesn't have to guess from training data alone which Terraform resources or modules exist; during the task it can actively retrieve information from official Terraform sources and, where configured, from the user's own HCP Terraform organization. This is especially useful for fast-moving provider APIs, where outdated examples can easily lead to incorrect or insecure infrastructure.
Prerequisites
The official README states that an MCP-capable AI client is required, such as Claude Desktop, Claude Code, Cursor, VS Code, Amazon Q Developer, Kiro, Codex CLI, or Gemini extensions, depending on the integration being used. For containerized operation, Docker must be installed and running. The server supports two transport types: stdio, meaning communication over standard input and output, and Streamable HTTP, where an HTTP endpoint such as /mcp is exposed. For public Registry queries, an HCP Terraform token is not necessarily required, but organization, workspace, and private registry features require a valid Terraform Enterprise or HCP Terraform API token. Relevant environment variables include TFE_ADDRESS for the Terraform Enterprise or HCP Terraform instance address, TFE_TOKEN for the API token, TRANSPORT_MODE for the transport mode, and optional TLS, CORS, and rate-limit settings for HTTP operation.
Step-by-step setup
The exact configuration depends on the client. For local clients, setup usually means adding an MCP configuration block that either starts a Docker image or runs a locally installed binary with the appropriate arguments. In stdio mode, the server is intended for that one client process and is relatively easy to secure because no network address is opened. For centrally hosted environments, Streamable HTTP mode can be used; in that case host, port, endpoint, TLS certificate, allowed origins, session mode, and rate limits are configured via environment variables. HashiCorp also documents Helm charts and container builds for deployment scenarios. After configuration, it's wise to start with a harmless tool call, such as a provider or module search in the public Registry, before enabling features that can write to HCP Terraform or Terraform Enterprise or modify workspaces. This staged rollout lowers the risk that a misconfigured client can immediately perform broad actions.
Security and trust model
HashiCorp explicitly warns that, depending on the request, the MCP server may expose Terraform data to the MCP client and the LLM. That can include not only public Registry information but also organization, project, workspace, variable, and registry data when HCP Terraform is connected. For that reason the server should only be used with trusted clients and trusted language models. In HTTP mode, TLS, a tight CORS configuration, rate limits, and, where appropriate, an organization allowlist are among the most important protective measures. Token passthrough for centralized deployments is particularly sensitive: the server can forward requests on behalf of different users, which is only safe if headers, trusted proxy hops, and client IP forwarding are carefully controlled. API tokens should have minimal permissions, be rotated regularly, and never appear in repositories or prompt text.
Who should use it
The Terraform MCP Server is mainly useful for teams that already use Terraform professionally and want AI assistants to support them while writing, reviewing, or exploring infrastructure code. It is not so much a beginner tool that replaces Terraform, but rather an interface that brings official Terraform information into an assistant's working context. Compared with generic web search, it has the advantage of being focused directly on the Terraform Registry and HCP Terraform and of offering structured tools rather than freely interpreted web pages. Compared with custom scripts, it saves integration work, but it also requires trust in the MCP client chain. In production environments, every Terraform change proposed by the model should still go through terraform plan, code review, policy checks, and, where appropriate, manual approval.
Frequently asked questions
Do I need to check both links?
Yes. The product link points to official documentation, while the repository verifies source code, license, and GitHub stars. They serve different purposes.
Are GitHub stars a recommendation?
No. The stored star count is a snapshot from 2026-09-07 and only indicates repository popularity. Security and fit require separate review.
How do I reduce risk in the first test?
Use a test project, minimal tokens, read-only tools, and inspect responses. Enable write access or production resources only after a traceable review.