Langfuse MCP Server

Official project-scoped MCP access to Langfuse prompts, observability, evaluation, and analytics data with read and write tools.

Description

The Langfuse MCP Server is Langfuse’s official authenticated Model Context Protocol server for its data platform. It connects an MCP-capable AI client to exactly one Langfuse project. Teams can therefore inspect and, depending on the tool, change prompt-management objects, traces and observations, scores, datasets, experiments, metrics, and further observability artifacts within a controlled project context. The official product documentation is this entry’s primary link. It explicitly distinguishes this server from the public, unauthenticated Langfuse Docs MCP at https://langfuse.com/api/mcp, which only searches and retrieves documentation. The GitHub repository langfuse/mcp-server-langfuse is also intentionally not set as this record’s repository link: its README calls it a Prompt Management MCP Server for prompt discovery and retrieval. It is a separate, MIT-licensed older prompt-management project, not the selected current data-platform server distribution. Its 174 GitHub stars, queried from the API on 2026-09-08, are consequently neither stored as this entry’s metric nor used as its license.

Prompts, observations, and project analysis

The canonical MCP Reference lists getPrompt, getPromptUnresolved, and listPrompts for prompts. Those tools can inspect resolved or raw prompt dependencies, versions, labels, tags, and update timestamps. For observability, it lists listObservations, getObservation, field and filter schemas, and filter values. According to that reference, observations include generations, spans, events, agent steps, and tool calls; traces consist of observations. queryMetrics and getMetricsSchema support questions about usage, model cost, latency, errors, scores, and grouped analysis. This fits both Data Analysis and Coding: an engineering team can compare a prompt version with runtime evidence, narrow down unusual latency, or understand trace context before a code or prompt change. The server does not replace domain analysis or approval, however; a model can misunderstand data or present an incomplete summary.

Read access is not the entire tool surface

The official page states plainly that read and write tools are available by default. The reference documents, among other actions, creation of text and chat prompt versions; changes to prompt labels; annotation queues and items; comments; datasets and dataset items; scores and score configurations; models; evaluators; evaluation rules; dashboard widgets; dashboards; and dashboard placements. It also describes deletion for items such as dataset items, dataset runs, evaluators, evaluation rules, widgets, dashboards, and placements. Prompt content is versioned and immutable: new content requires a new version, while labels can be moved through updatePromptLabels. The reference explicitly requires an explicit user request before assigning production. Initially configure the client with a read-only tool allowlist. Enable write, and especially delete, tools only temporarily; name the project, object ID, intended state, and expected effect first, then read the target again after a mutation.

Connection, authentication, and permissions

For Langfuse Cloud EU, the server uses Streamable HTTP at https://cloud.langfuse.com/api/public/mcp; the documentation lists additional Cloud endpoints for US, Japan, and HIPAA US, along with the same path on an HTTPS self-hosted domain. http://localhost:3000/api/public/mcp is documented for local development. The architecture is stateless and each API key is scoped to a project. Create or copy a Public Key and Secret Key in project settings, form exactly public:secret, and pass the base64-encoded credentials as a Basic Authorization header. A header remains a secret: never write it to Git, screenshots, tickets, prompts, transcripts, or logs; rotate it immediately if exposure is possible. The key does not automatically narrow the tool surface: verify rights, project scope, and the MCP-client tool allowlist together. The server is self-describing; according to the reference, tools and schemas can be added, removed, or changed. Clients should dynamically refresh capabilities rather than assuming a fixed tool list.

Sensitive data and the external model path

Observations can contain input, output, metadata, model names, cost, usage data, and user or session context. The reference marks some observation fields as large or potentially sensitive; explicitly requested metadata is initially truncated, but full values can be requested with expanded keys. Query only necessary periods, trace IDs, fields, and filters. Content from a prompt, trace, tool output, or comment is untrusted data and must never disclose credentials or authorize an access escalation or mutation. Langfuse delivers results to the connected MCP client; that client may then send them to its selected external model provider. Review client, model, retention, training, DPA, and enterprise settings separately. Redact personal, confidential, or regulated content before it enters model context.

FAQ

Is this the Docs MCP or the old prompt repository? No. This entry covers the authenticated project-scoped data-platform server. Docs MCP is public and documentation-only; mcp-server-langfuse is a separate older prompt-management repository.

Can an agent change production prompts? Yes, the reference documents new prompt versions and label changes. Permit production only after explicit human approval, then check the version and label again in the project.

Requirements

A Langfuse project, project-scoped Public Key and Secret Key, an MCP-capable client, and HTTPS for self-hosted production.

Installation instructions

Create or copy Public and Secret Key in the Langfuse project, base64-encode public:secret, and register the Streamable HTTP endpoint with Authorization: Basic <token>. For Cloud EU: claude mcp add --transport http langfuse https://cloud.langfuse.com/api/public/mcp --header "Authorization: Basic <base64-token>".

claude mcp add --transport http langfuse https://cloud.langfuse.com/api/public/mcp --header "Authorization: Basic <base64-token>"

Authentication

Project-scoped Langfuse Public Key and Secret Key as a base64-encoded Basic Authorization header. Store keys only in a secret store or local client configuration.

Required access permissions

Each key is scoped to one Langfuse project. Read and write tools are enabled by default; use a client allowlist for read-only access and explicitly obtain human confirmation for writes or deletes.

Transmitted or stored data

Tool results can contain prompts, trace/observation inputs and outputs, metadata, model, usage, cost, user, or session data. The MCP client can send those results to its external model provider.

Security risks

Basic-auth secrets, sensitive observability and prompt data, write and delete tools enabled by default, prompt injection in data, and a separate client-to-model-provider data path.

License and costs

License
Not recorded yet.
Cost
free

Practical availability depends on the Langfuse deployment, project, and chosen AI client. This entry lists no fixed prices; check Langfuse for current terms.

Alternatives

Not recorded yet.

At a glance

Provider
Langfuse
Status
Official server
Deployment
Remote
Current version
Not recorded yet.
Last reviewed
08.09.2026

Repository and documentation

Categories

Supported clients