Elastic Agent Builder MCP Server

Official MCP server built into Kibana: exposes Elastic Agent Builder tools such as ES|QL queries and custom search tools to external AI clients.

Description

The Elastic Agent Builder MCP Server is the official interface, operated by Elastic itself, through which external AI clients such as Claude Desktop, Claude Code, Cursor, or VS Code can reach the tools of Elastic Agent Builder. According to Elastic, Agent Builder is a "conversational AI platform" for answering questions and taking actions over your own Elasticsearch data in natural language — across observability logs, security alerts, or internal documents. Rather than installing a separate program, the MCP server simply exposes an endpoint that already exists inside Kibana: any Kibana instance with Agent Builder enabled automatically makes every tool configured there available through a standardized MCP interface, with no extra code to write and no dedicated server process to run.

Requirements and availability

Per the official documentation, the MCP server is generally available on Elastic Cloud Serverless; within the classic Elastic Stack, the feature reached general availability in version 9.3, after shipping as a preview in 9.2. It works with Elasticsearch and Kibana deployments as well as with the specialized Elastic Observability and Elastic Security solutions, since Agent Builder builds on the same data and index structures across products.

Tools and feature set

According to Elastic, Agent Builder ships with ready-to-use, built-in tools out of the box — for example, running ES|QL queries against indices — and also lets you build targeted, custom tools through the Kibana UI or via APIs. An example shown in Elastic's own engineering blog wires up a semantic search over internal engineering documentation as a standalone tool. Through the MCP server, the complete tool catalog authorized for a given role, including so-called Elastic Workflows, becomes available to external clients, so automations can be bundled instead of wiring up every tool one by one.

Access, endpoint, and authentication

The endpoint follows the pattern {KIBANA_URL}/api/agent_builder/mcp, extended with the space name for custom Kibana spaces. Per the documentation, two authentication paths are available: an Elastic API key, which works with both classic Stack deployments and Serverless projects and suits automation and machine-to-machine access, and — for Serverless projects only — OAuth 2.1 with short-lived, auto-refreshing tokens and individually revocable permissions per person. Which tools a given call can actually see and run depends on the Kibana permissions tied to the API key or the signed-in user.

Difference from the older community repository

Before this integrated approach, Elastic maintained a standalone, open-source repository at github.com/elastic/mcp-server-elasticsearch that ran locally or as a Docker container against an Elasticsearch cluster. That repository now describes itself as deprecated, receiving only critical security updates, and explicitly points to the Agent-Builder-integrated MCP endpoint described here as its successor. This entry covers only the current, Kibana-built-in service, which is not itself published as standalone open-source code — so the entry carries no repository and no license field.

Cost

According to Elastic, Agent Builder is a feature gated behind the appropriate Elastic Stack subscription or Serverless project tier: for self-managed deployments and Elastic Cloud Hosted, it is normally tied to the Enterprise license tier, though the vendor currently offers it at no additional charge under promotional pricing. On Elastic Cloud Serverless, usage is instead billed per completed agent interaction, with every Serverless project including, per the documentation, a free monthly allocation plus volume discounts at higher usage. Concrete amounts are listed on Elastic's official pricing page.

Who the server is for

The Elastic Agent Builder MCP Server suits teams already running Elasticsearch, Kibana, Elastic Observability, or Elastic Security who want to make the data stored there — logs, security alerts, internal documents, or structured indices — accessible to AI assistants and agents without operating a separate bridging component themselves. For organizations without an existing Elastic environment, the server is naturally irrelevant; those looking for a lightweight, open-source connection to their own search database can find alternatives such as the Qdrant MCP Server or the ClickHouse MCP Server elsewhere in this catalog.

Requirements

A Kibana instance (self-managed from 9.3 GA/9.2 preview, Elastic Cloud Hosted, or Elastic Cloud Serverless) with Agent Builder enabled and at least one configured tool; an API key or, on Serverless, an OAuth 2.1 client with the appropriate Kibana Agent Builder permissions; an MCP-capable client.

Installation instructions

In Kibana, open the Agent Builder Tools UI to find the server URL ({KIBANA_URL}/api/agent_builder/mcp, including the space name in the path for custom spaces). Configure this URL in your MCP client (e.g. ~/.cursor/mcp.json) together with an Elastic API key for authorization; on Serverless projects, use OAuth 2.1 instead for interactive, multi-user scenarios.

claude mcp add --transport http elastic-agent-builder https://<kibana-url>/api/agent_builder/mcp

Authentication

API key (Stack deployments and Serverless, ideal for automation/machine-to-machine access) or OAuth 2.1 with short-lived, auto-refreshing tokens and per-person, individually revocable permissions (Serverless projects only).

Required access permissions

A tool call runs with exactly the Kibana permissions attached to the API key or the signed-in user; only the tools and indices that identity is authorized for in Kibana are visible and executable.

Transmitted or stored data

Requests and model-generated tool calls (e.g. ES|QL queries, search terms) go to the Kibana/Elasticsearch environment; results such as query data, search hits, and workflow outputs flow back to the MCP client and the connected AI provider. The exact data involved depends entirely on the tools and indices configured in Agent Builder.

Security risks

Because every tool acts with the permissions of the connected API key or user, an overly broad key exposes the entire underlying dataset; a dedicated, narrowly scoped Kibana role is recommended for MCP access instead of reusing an existing, broadly privileged account. Tools that return text content from documents or logs can also carry embedded, misleading instructions (prompt injection) before that content reaches the model.

License and costs

License
Not recorded yet.
Cost
paid

Normally tied to the Enterprise license tier (self-managed/Elastic Cloud Hosted), currently offered by the vendor at no additional charge under promotional pricing; on Elastic Cloud Serverless, usage-based billing per agent interaction with a free monthly base allocation. Concrete amounts are listed on Elastic's official pricing page.

Alternatives

Not recorded yet.

At a glance

Provider
Elastic
Status
Official server
Deployment
Remote
Current version
Not recorded yet.
Last reviewed
20.09.2026

Repository and documentation

Categories

Supported clients