Terraform MCP Server

HashiCorp’s official MCP server for Terraform Registry, HCP Terraform, workspaces, and IaC automation.

Description

Terraform MCP Server is HashiCorp’s official Model Context Protocol server for Terraform. It connects MCP-capable AI clients to the Terraform ecosystem, including Terraform Registry, HCP Terraform, and Terraform Enterprise. The direct product link points to HashiCorp Developer documentation; the source code is in hashicorp/terraform-mcp-server. For Skill Road, this entry matters because infrastructure as code is a place where an agent needs more than fluent text generation: it must understand available modules, providers, workspaces, variables, and operational boundaries. Without a controlled source, a model can easily guess around current Terraform syntax or an organization’s real structure.

Terraform context for agents

According to HashiCorp, the server integrates public Registry APIs for providers, modules, and policies as well as HCP Terraform or Terraform Enterprise. It can list workspaces and, depending on the enabled toolset, support workspace operations. The README also documents resources, tool filtering, and metrics for tool calls. In practice, a coding agent can ask more targeted questions while writing or reviewing Terraform configuration, instead of relying only on training data. That is especially useful for teams that standardize modules, manage many workspaces, or need to reason about infrastructure changes without leaving the agent workflow.

Installation and transports

The documented local entry path is containerized, for example docker run -i --rm hashicorp/terraform-mcp-server. The README gives a direct claude mcp add command for Claude Code and separate examples for Codex CLI, Cursor, and VS Code. Alongside stdio, the server supports Streamable HTTP for centralized or distributed deployments. That is where security decisions become more important: address, token, allowed origins, TLS certificates, rate limits, and organization allowlists should be controlled server-side. A local developer setup is simpler; a central deployment needs explicit operating rules.

Permissions, tokens, and security limits

The server can expose Terraform data to the MCP client and LLM. HashiCorp itself warns not to use it with untrusted MCP clients or LLMs. In Streamable HTTP setups, TFE_ADDRESS cannot be supplied by clients through headers or query parameters; the server rejects those attempts so tokens are not redirected to a malicious Terraform address. Tokens should never be passed through query parameters. For centralized deployments, TLS, MCP_ALLOWED_ORIGINS, organization allowlists, and least-privilege Terraform permissions are essential. An agent should receive only the toolsets needed for the current task.

License, version, and GitHub stars

The repository is MPL-2.0 licensed. The GitHub API reported exactly 1,522 stars on 2026-09-07; that number is a snapshot, not proof of security, maintainability, or fit. Version 1.3.0 was used in the documented container examples. The server itself is open source, but useful capabilities depend on Terraform Registry, HCP Terraform or Terraform Enterprise, and the selected client. This entry does not state fixed prices; the official provider plans and the organization’s own infrastructure are decisive. The server is especially suitable for DevOps and platform teams that want IaC work in Claude Code, Codex, or Cursor to be grounded in official Terraform sources.

Requirements

Docker, an MCP client, and a suitably scoped API token for HCP Terraform or Terraform Enterprise.

Installation instructions

Run locally via Docker over stdio and connect the chosen client using the official guide. For centralized HTTP setups, configure TLS, allowed origins, and an organization allowlist.

docker run -i --rm hashicorp/terraform-mcp-server

Authentication

Some Registry functions work without a token; HCP Terraform/Terraform Enterprise requires TFE_TOKEN and a fixed TFE_ADDRESS.

Required access permissions

Permissions follow the Terraform token and enabled toolsets. Toolsets and individual tools can be filtered.

Transmitted or stored data

The server calls Terraform Registry and HCP/TFE APIs and returns results to the MCP client.

Security risks

Broad tokens, untrusted clients, or centralized HTTP endpoints without TLS/origin controls can expose or change infrastructure information.

License and costs

License
MPL-2.0
Cost
free

The server is open source. Costs depend on Terraform products, HCP/TFE usage, infrastructure, and the selected AI client.

Alternatives

Not recorded yet.

At a glance

Provider
HashiCorp
Status
Official server
Deployment
Local and remote
Current version
1.3.0
GitHub stars
1,533
Last reviewed
07.09.2026

Repository and documentation

Categories

Supported clients