Qdrant MCP Server
Official MCP server that stores information in Qdrant and retrieves it through semantic search.
- Skill Road
- Qdrant MCP Server
Categories
Description
The Qdrant MCP Server is Qdrant's official Model Context Protocol server. It connects an MCP-capable AI client to a Qdrant instance, a vector database for similarity and semantic search. According to the repository, it provides two tools: qdrant-store stores supplied information with optional metadata, while qdrant-find searches previously stored information relevant to a text query. It is not a general database explorer and does not promise that an agent will automatically produce correct answers. Its concrete role is to make selected context discoverable in a collection and let users inspect results ranked by semantic proximity.
Vector search, not blanket knowledge claims
When storing text, the server creates an embedding vector and saves it with the text and optional metadata in Qdrant. When searching, it embeds the query and compares it with the collection's vectors. The README names sentence-transformers/all-MiniLM-L6-v2 as the default and says the server currently supports FastEmbed models. What is found consequently depends on the collection, text quality, model, metadata, and search limit. Semantic proximity is not evidence of recency, authority, or factual correctness. Check material results against their original source, especially when they inform code, data analysis, or decisions.
The server can be useful for code snippets, technical notes, documentation, or research excerpts when those items have deliberately been managed in a Qdrant collection. Data Analysis, Coding, and Research describe those uses: data analysis for searching a curated text corpus, coding for recoverable project context, and research for comparing stored source notes. It replaces neither version control nor a database query nor source review. Blanket claims that it creates a finished RAG application would be misleading: the server provides storage and search tools; the surrounding application and data quality determine the actual workflow.
Deployment: local and network transports
The official README documents uvx mcp-server-qdrant with local stdio as the default transport. The same server also supports SSE and Streamable HTTP, so the documented deployment type is both. For an external Qdrant instance, configure QDRANT_URL, optionally QDRANT_API_KEY, and COLLECTION_NAME. As an alternative to QDRANT_URL, QDRANT_LOCAL_PATH can point to a local Qdrant database; the two settings must not be used together. The repository includes a Dockerfile. Under HTTP or SSE, the process listens on a network port, so an internet-reachable process needs deliberately configured access control and TLS at the appropriate network edge. The README documents transport and host/port; it does not automatically provide a complete public-internet hardening design.
Collections, mutations, and permissions
qdrant-store is a data mutation. If there is no configured default collection, the calling client can provide a collection name; according to the README, the server automatically creates that collection if it does not exist. That can change stored data and create new collections. For research-only use, set QDRANT_READ_ONLY=true, which disables qdrant-store. Do not broadly give an agent a key with access to every collection. Instead, use minimally privileged Qdrant access, separate collections by project or sensitivity, and confirm write requests in the client when its UX supports it.
Authorization is enforced by the Qdrant instance and the API key in use; the MCP server does not bypass it. Review in advance which collection the key can read, create, or modify. A mistaken collection name, unclear agent request, or injected text can otherwise produce unwanted records. Start with a non-production collection and enable write access only after an appropriate business approval.
Embeddings, data sharing, and limits
Embeddings are derived numerical representations, not automatic anonymization. Depending on the content, text, metadata, and vectors can still be sensitive. In the local default path, the server uses FastEmbed for the supported models named above; a different actual runtime environment requires its own data-path assessment. The MCP server returns search results to the connected AI client. That client may add them to model context; depending on the client, model provider, logging, telemetry, and retention, content can be shared with an external model or its service providers. A locally running MCP process therefore does not guarantee that results stay local.
Do not put API keys in prompts, metadata, Git repositories, or screenshots. Limit stored content to the necessary purpose, assess AI-client configuration, and remove or version outdated records under your own data policy. The repository is licensed Apache-2.0. On 2026-09-08, the GitHub API reported exactly 1,522 stars; this is a point-in-time repository-popularity signal, not evidence of quality or security.
FAQ
Can the server change data? Yes. qdrant-store writes information and, according to the README, can create a missing collection. For search-only scenarios, QDRANT_READ_ONLY=true disables the write tool.
Does local operation automatically keep content private? No. The Qdrant target, embedding runtime, and especially the connected AI client determine the data path. Search results can be processed and logged by the client or model provider.
Is every semantic result reliable? No. A result indicates vector similarity in the chosen corpus. Validate its source, recency, and context before making a decision or a change.
Requirements
A Qdrant instance or local Qdrant path, the Python tool uvx, an MCP-capable client, and, for protected Qdrant, an API key with minimal collection permissions.
Installation instructions
For local stdio, set QDRANT_URL, COLLECTION_NAME, and optionally QDRANT_API_KEY in the local client configuration and use uvx mcp-server-qdrant. For network operation, select the documented --transport sse or --transport streamable-http and secure access and TLS outside the process. Set QDRANT_READ_ONLY=true for search-only use.
uvx mcp-server-qdrant
Authentication
A protected Qdrant instance uses QDRANT_API_KEY; locally embedded Qdrant paths do not use the URL/API-key path. The Qdrant instance performs the actual authorization check.
Required access permissions
Read and write permissions follow the configured Qdrant instance and its API key. Limit the key to required collections; qdrant-store can write records and create a missing collection.
Transmitted or stored data
Text and optional metadata are stored in Qdrant and embedded for search. Results go to the MCP client and can enter model context, logs, or a model-provider data path there.
Security risks
Write access can alter records and collections. Broad API keys, sensitive content in embeddings or metadata, unprotected HTTP/SSE ports, and AI-client data sharing increase risk.
License and costs
- License
- Apache-2.0
- Cost
- free
The MCP server is Apache-2.0 licensed. Availability and terms for a Qdrant instance, infrastructure, and the selected AI client depend on the deployment and provider.
Alternatives
Not recorded yet.
At a glance
- Provider
- Qdrant
- Status
- Official server
- Deployment
- Local and remote
- Current version
- Not recorded yet.
- GitHub stars
- 1,539
- Last reviewed
- 08.09.2026
Repository and documentation
Categories
Supported clients
Related guides
Guides and background related to this entry.
Set up Mapbox MCP Server
Set up the Mapbox MCP Server: hosted endpoint or local token, a first test, and sensible limits.
30.09.2026
Set up the Fakechat plugin for Claude Code
Install the Fakechat plugin, start Claude Code with the channels flag, and test messages and files through a local browser interface.
30.09.2026
Setting up Laravel Boost
Install Laravel Boost in a Laravel application and connect it to Claude Code, Cursor, or Codex.
29.09.2026
Set up the Azure DevOps MCP Server
Start Set up the Azure DevOps MCP Server with verified links, minimal permissions, and a safe first test.
25.09.2026