marimo MCP Server
Official experimental local MCP access to running marimo notebook sessions.
- Skill Road
- marimo MCP Server
Categories
Description
The marimo MCP Server is marimo's documented, currently experimental interface for external MCP-compatible applications. It is not operated as a standalone SaaS endpoint: starting a local marimo notebook with --mcp makes the running marimo process serve an HTTP endpoint. A connected client such as Claude Code or Cursor can use marimo's AI tools against active notebook sessions. The official documentation explicitly calls this feature experimental and under active development, so tool definitions, availability, and APIs can change. That is a reason to re-check the version, client, and configuration before every production use involving confidential data.
Notebook inspection, not notebook execution
The MCP server is intended for low-level, read-only interaction with a live notebook. It can list active notebooks with session IDs and file paths, inspect cell structure, retrieve complete cell code and runtime data, inspect outputs, trace dependencies, inspect variables and table metadata, and summarise errors or lint findings. This can support debugging, data analysis, code review, and orientation inside reactive Python notebooks. It is not notebook execution: marimo documents run_stale_cells, notebook editing, and Code mode execution for its own chat UI, not as an exposed MCP write interface. The MCP guide specifically calls the external server lower-level read-only tools and points people who want a coding agent to drive a live notebook to marimo pair.
This boundary matters. A model may analyse code, variables, table metadata, errors, and cell outputs and suggest changes, but this endpoint should not be treated as authority to run or modify cells. Review suggestions separately in the notebook and version-control system. Even read-only results can contain sensitive research data, personal values, credentials printed in output, internal file paths, or proprietary Python code. Limit started notebooks and exposed data to the smallest test scope that answers the task.
Local HTTP endpoint and network boundary
The official guide shows, for example, uv run --with="marimo[mcp]" marimo edit notebook.py --mcp. For local development it also permits --no-token, but marimo warns that this removes authentication and should not be used in production environments. The endpoint is http://localhost:PORT/mcp/server for the marimo server port; with authentication enabled, the client must include the documented access token. A local process is not synonymous with a secure or automatically private interface. Publishing its host or port through a reverse proxy exposes network access to notebook tools.
marimo enables DNS-rebinding protection and validates incoming Host headers. --mcp-allow-remote disables that check for proxies, gateways, or custom domains. It is not a harmless convenience switch: use remote exposure only with an authenticated client, restrictive firewall and bind configuration, TLS at the appropriate boundary, and a documented trust boundary. Do not combine --no-token and --mcp-allow-remote merely to make an endpoint quickly reachable. For a personal test, authenticated localhost has the smallest attack surface.
Code, data, prompt injection, and the model path
Cell code, Markdown, table values, HTML output, tracebacks, and file paths are untrusted content. They can contain misleading instructions or prompt injection, such as requests to ignore rules, read local secrets, or invoke more tools. A client or agent must treat that material only as data. Constrain tool permissions, query only necessary sessions, review sources and code changes with a human, and never treat an embedded notebook instruction as authorization. A read-only MCP server also does not protect against a client that has shell, Git, or write-capable tools in parallel.
The data path does not automatically stop at the local marimo process. marimo returns tool results to the connected MCP client, which can put them in logs, telemetry, or the context of a local or hosted model provider. A local notebook and local endpoint therefore do not guarantee local model processing. Identify the client, model provider, retention, training settings, contract, and regional processing before notebook content is transmitted. The public source is Apache-2.0 licensed. On 2026-09-08, the GitHub API reported exactly 22,685 stars for marimo-team/marimo; that count covers the complete marimo monorepo, including the notebook platform, not the MCP server alone, and is not evidence of security or quality.
FAQ
Can an external MCP client execute notebook cells? The MCP guide describes the external server as access to low-level, read-only tools. Execution and editing are not a documented MCP-server permission.
When is --no-token acceptable? marimo says it is only for local development. Keep authentication enabled for a reachable or production endpoint.
Does localhost keep data local to the model? Not automatically. The MCP client can pass tool results to its selected model provider, logs, or telemetry.
Requirements
A Python environment with marimo and its MCP extras, a running marimo notebook, an MCP-compatible client, and local access to the marimo HTTP port.
Installation instructions
Start the notebook with uv run --with="marimo[mcp]" marimo edit notebook.py --mcp. Leave authentication enabled, identify the displayed port, and configure the client with http://localhost:PORT/mcp/server. In Claude Code use claude mcp add --transport http marimo http://localhost:PORT/mcp/server. Add --no-token only for a local development test.
uv run --with="marimo[mcp]" marimo edit notebook.py --mcp
Authentication
marimo uses an access token unless --no-token is set. The official guide limits disabling authentication to local development.
Required access permissions
Read-oriented access to active notebook sessions, cell code, runtime data, outputs, dependencies, variables, table metadata, and error/lint information. Notebook execution and editing are not documented as external MCP write capabilities.
Transmitted or stored data
marimo sends requested notebook information to the MCP client. That client can pass results to logs, telemetry, or a local or hosted model provider; localhost does not automatically constrain that downstream path.
Security risks
Cell code, outputs, data, and errors can expose sensitive information or prompt injection. Further risks come from --no-token, remote exposure, and a client with additional write tools. Keep authentication, localhost, least privilege, and human review.
License and costs
- License
- Apache-2.0 (marimo monorepo)
- Cost
- free
marimo source code is Apache-2.0 licensed. Infrastructure, model providers, and optional services can have separate terms; check them directly with the respective operator before use.
Alternatives
Not recorded yet.
At a glance
- Provider
- marimo
- Status
- Official server
- Deployment
- Local
- Current version
- 0.24.0
- GitHub stars
- 22,917
- Last reviewed
- 08.09.2026
Repository and documentation
Categories
Supported clients
Related guides
Guides and background related to this entry.
Set up Mapbox MCP Server
Set up the Mapbox MCP Server: hosted endpoint or local token, a first test, and sensible limits.
30.09.2026
Set up the Fakechat plugin for Claude Code
Install the Fakechat plugin, start Claude Code with the channels flag, and test messages and files through a local browser interface.
30.09.2026
Setting up Laravel Boost
Install Laravel Boost in a Laravel application and connect it to Claude Code, Cursor, or Codex.
29.09.2026
Set up the Azure DevOps MCP Server
Start Set up the Azure DevOps MCP Server with verified links, minimal permissions, and a safe first test.
25.09.2026