Terraform MCP Server
HashiCorp’s official MCP server for Terraform Registry, HCP Terraform, workspaces, and IaC automation.
- Skill Road
- Terraform MCP Server
Description
Terraform MCP Server is HashiCorp’s official Model Context Protocol server for Terraform. It connects MCP-capable AI clients to the Terraform ecosystem, including Terraform Registry, HCP Terraform, and Terraform Enterprise. The direct product link points to HashiCorp Developer documentation; the source code is in hashicorp/terraform-mcp-server. For Skill Road, this entry matters because infrastructure as code is a place where an agent needs more than fluent text generation: it must understand available modules, providers, workspaces, variables, and operational boundaries. Without a controlled source, a model can easily guess around current Terraform syntax or an organization’s real structure.
Terraform context for agents
According to HashiCorp, the server integrates public Registry APIs for providers, modules, and policies as well as HCP Terraform or Terraform Enterprise. It can list workspaces and, depending on the enabled toolset, support workspace operations. The README also documents resources, tool filtering, and metrics for tool calls. In practice, a coding agent can ask more targeted questions while writing or reviewing Terraform configuration, instead of relying only on training data. That is especially useful for teams that standardize modules, manage many workspaces, or need to reason about infrastructure changes without leaving the agent workflow.
Installation and transports
The documented local entry path is containerized, for example docker run -i --rm hashicorp/terraform-mcp-server. The README gives a direct claude mcp add command for Claude Code and separate examples for Codex CLI, Cursor, and VS Code. Alongside stdio, the server supports Streamable HTTP for centralized or distributed deployments. That is where security decisions become more important: address, token, allowed origins, TLS certificates, rate limits, and organization allowlists should be controlled server-side. A local developer setup is simpler; a central deployment needs explicit operating rules.
Permissions, tokens, and security limits
The server can expose Terraform data to the MCP client and LLM. HashiCorp itself warns not to use it with untrusted MCP clients or LLMs. In Streamable HTTP setups, TFE_ADDRESS cannot be supplied by clients through headers or query parameters; the server rejects those attempts so tokens are not redirected to a malicious Terraform address. Tokens should never be passed through query parameters. For centralized deployments, TLS, MCP_ALLOWED_ORIGINS, organization allowlists, and least-privilege Terraform permissions are essential. An agent should receive only the toolsets needed for the current task.
License, version, and GitHub stars
The repository is MPL-2.0 licensed. The GitHub API reported exactly 1,522 stars on 2026-09-07; that number is a snapshot, not proof of security, maintainability, or fit. Version 1.3.0 was used in the documented container examples. The server itself is open source, but useful capabilities depend on Terraform Registry, HCP Terraform or Terraform Enterprise, and the selected client. This entry does not state fixed prices; the official provider plans and the organization’s own infrastructure are decisive. The server is especially suitable for DevOps and platform teams that want IaC work in Claude Code, Codex, or Cursor to be grounded in official Terraform sources.
Requirements
Docker, an MCP client, and a suitably scoped API token for HCP Terraform or Terraform Enterprise.
Installation instructions
Run locally via Docker over stdio and connect the chosen client using the official guide. For centralized HTTP setups, configure TLS, allowed origins, and an organization allowlist.
docker run -i --rm hashicorp/terraform-mcp-server
Authentication
Some Registry functions work without a token; HCP Terraform/Terraform Enterprise requires TFE_TOKEN and a fixed TFE_ADDRESS.
Required access permissions
Permissions follow the Terraform token and enabled toolsets. Toolsets and individual tools can be filtered.
Transmitted or stored data
The server calls Terraform Registry and HCP/TFE APIs and returns results to the MCP client.
Security risks
Broad tokens, untrusted clients, or centralized HTTP endpoints without TLS/origin controls can expose or change infrastructure information.
License and costs
- License
- MPL-2.0
- Cost
- free
The server is open source. Costs depend on Terraform products, HCP/TFE usage, infrastructure, and the selected AI client.
Alternatives
Not recorded yet.
At a glance
- Provider
- HashiCorp
- Status
- Official server
- Deployment
- Local and remote
- Current version
- 1.3.0
- GitHub stars
- 1,533
- Last reviewed
- 07.09.2026
Repository and documentation
Categories
Supported clients
Related guides
Guides and background related to this entry.
Set up the Fakechat plugin for Claude Code
Install the Fakechat plugin, start Claude Code with the channels flag, and test messages and files through a local browser interface.
30.09.2026
Setting up Laravel Boost
Install Laravel Boost in a Laravel application and connect it to Claude Code, Cursor, or Codex.
29.09.2026
Set up the Azure DevOps MCP Server
Start Set up the Azure DevOps MCP Server with verified links, minimal permissions, and a safe first test.
25.09.2026
Installing a Claude Code plugin
Installing a plugin from the official Anthropic marketplace – using the Code Review plugin as an example.
24.09.2026