Weaviate MCP Server
Official MCP endpoint built into Weaviate for schema inspection, hybrid search, and controlled object changes.
- Skill Road
- Weaviate MCP Server
Categories
Description
Weaviate MCP Server is Weaviate's official Model Context Protocol endpoint. It is not a separate package or an unofficial wrapper: since Weaviate 1.38 it has been built into the Weaviate database server. Once enabled, the same REST port exposes the Streamable HTTP endpoint at /v1/mcp. According to Weaviate, an MCP-capable client can inspect collections and tenants, run hybrid searches, and—only when write access is explicitly allowed—insert or replace objects. This entry covers that current built-in server. The older weaviate/mcp-server-weaviate repository says its standalone implementation is deprecated; maintained source now lives in the main weaviate/weaviate repository.
Vector data for analysis and coding
Weaviate stores objects with vectors and can combine vector search with BM25 keyword search, filters, and metadata. The weaviate-query-hybrid MCP tool searches a named collection; its alpha parameter weights keyword and vector search. A client can limit returned properties, metadata, filters, result count, and target vectors. That makes Data Analysis appropriate because a controlled corpus can be investigated by meaning and terms. It also supports Coding by making a collection schema, data types, and search behavior inspectable while developing or debugging an integration.
A result is not a source review, however. Vector similarity measures proximity in the chosen representation, not truth, recency, permission to disclose, or domain relevance. Restrict return_properties so full long text does not unnecessarily enter chat context, and validate consequential results against the original data and access rules. Data Analysis and Coding are deliberately the only categories: the server works with data collections and technical schema or search workflows. It is neither a general research service nor a promise that a model response will be correct.
Operation, credentials, and permissions
On self-hosted Weaviate, the MCP server is disabled by default for security. Set MCP_SERVER_ENABLED=true to enable it; by default, access remains limited to read tools. On Weaviate Cloud, documentation says the endpoint is enabled and is reached at the cluster URL with /v1/mcp appended. When anonymous access is off, the client supplies a Bearer token or API key. Do not give an agent a root or broadly valid credential. For read-only use, Weaviate documents the Viewer role with MCP and data-read permissions; roles and collection access should be reduced to the specific purpose.
A local or self-hosted database process performs its database work in its own Weaviate environment. That does not automatically mean content never leaves a computer or private network. The MCP client receives schema and search results and may pass them into model context, logs, telemetry, or a connected model provider. If Weaviate uses an external vectorizer during imports or upserts, that vectorizer can have a separate data path as well. Self-provided vectors and locally run vectorization change that assessment, but do not replace review of the connected client and model.
Mutations, schema, and prompt injection
weaviate-objects-upsert is visible only when write access is enabled. An upsert replaces an object instead of merging omitted properties, so omitted properties can be lost. Without supplied vectors, Weaviate can re-vectorize an object in a collection with a vectorizer; without one, a stored vector can be dropped. With auto-schema enabled, unknown properties can extend a schema, and a mistyped collection name can create a collection. Therefore test against a non-production collection, keep writes disabled for analysis-only work, and independently confirm the target, collection, complete object, and expected effect rather than trusting an agent summary.
Data fields and search results can contain text intended to steer a model into further tool calls. That is prompt injection, not a trustworthy instruction. Treat collection content, metadata, and customized tool descriptions as data; never give them priority over user or security instructions. Limit write permissions, review tool calls in the client, separate test and production keys, and never place Bearer tokens in prompts, Git, screenshots, or shared configuration files. The main repository is BSD-3-Clause licensed. On 2026-09-08, the GitHub API reported exactly 16,793 stars for the entire Weaviate repository; this is a point-in-time popularity signal, not evidence of quality or security.
FAQ
Is this a local stdio server? No. The current official MCP server is built into Weaviate and uses Streamable HTTP at the REST endpoint /v1/mcp. Self-hosted Weaviate can run locally or on a private network, while the client connects over HTTP.
Can a search expose sensitive vector data? It can return properties and requested metadata from an authorized collection to the MCP client. Embeddings are not automatic anonymization. Limit roles, fields, result counts, and the subsequent model path.
How do I prevent changes? On self-hosted Weaviate, do not enable MCP_SERVER_WRITE_ACCESS_ENABLED. On Weaviate Cloud, use the cluster-wide read-only switch or give the agent a Viewer key.
Requirements
Weaviate version 1.38 or later, an MCP-capable HTTP client, and, for a protected instance, a Bearer token or API key with minimal MCP and collection permissions.
Installation instructions
For self-hosted Weaviate, set MCP_SERVER_ENABLED=true, then connect the client to http://<host>:8080/v1/mcp and supply a minimally privileged Bearer token as a header. Enable writes only with MCP_SERVER_WRITE_ACCESS_ENABLED=true after testing against a non-production collection.
MCP_SERVER_ENABLED=true weaviate
Authentication
When anonymous access is disabled, the client uses a Bearer token or API key. With RBAC, appropriate MCP and collection permissions are also required; a Viewer key suits read-only access.
Required access permissions
Weaviate enforces permissions through the API key, role, and collection access. Seeing a tool in the list does not prove permission; write access must be enabled separately.
Transmitted or stored data
Weaviate processes objects, vectors, and queries in the connected instance. Results go to the MCP client and can reach its logs, telemetry, or a connected model; external vectorizers can add another data path.
Security risks
Broad Bearer tokens, write upserts, auto-schema, sensitive object or vector data, prompt injection in results, and forwarding to the connected model path increase risk.
License and costs
- License
- BSD-3-Clause
- Cost
- free
The MCP source integrated into Weaviate follows the main repository’s BSD-3-Clause license. Infrastructure, Weaviate Cloud, vectorization, and the selected AI client can have separate terms; consult the respective providers for current details. This public entry states no specific prices.
Alternatives
Not recorded yet.
At a glance
- Provider
- Weaviate
- Status
- Official server
- Deployment
- Local and remote
- Current version
- 1.39.0
- GitHub stars
- 16,854
- Last reviewed
- 08.09.2026
Repository and documentation
Categories
Supported clients
Not recorded yet.
Related guides
Guides and background related to this entry.
Set up Mapbox MCP Server
Set up the Mapbox MCP Server: hosted endpoint or local token, a first test, and sensible limits.
30.09.2026
Set up the Fakechat plugin for Claude Code
Install the Fakechat plugin, start Claude Code with the channels flag, and test messages and files through a local browser interface.
30.09.2026
Setting up Laravel Boost
Install Laravel Boost in a Laravel application and connect it to Claude Code, Cursor, or Codex.
29.09.2026
Set up the Azure DevOps MCP Server
Start Set up the Azure DevOps MCP Server with verified links, minimal permissions, and a safe first test.
25.09.2026