Weaviate MCP Server

Official MCP endpoint built into Weaviate for schema inspection, hybrid search, and controlled object changes.

Description

Weaviate MCP Server is Weaviate's official Model Context Protocol endpoint. It is not a separate package or an unofficial wrapper: since Weaviate 1.38 it has been built into the Weaviate database server. Once enabled, the same REST port exposes the Streamable HTTP endpoint at /v1/mcp. According to Weaviate, an MCP-capable client can inspect collections and tenants, run hybrid searches, and—only when write access is explicitly allowed—insert or replace objects. This entry covers that current built-in server. The older weaviate/mcp-server-weaviate repository says its standalone implementation is deprecated; maintained source now lives in the main weaviate/weaviate repository.

Vector data for analysis and coding

Weaviate stores objects with vectors and can combine vector search with BM25 keyword search, filters, and metadata. The weaviate-query-hybrid MCP tool searches a named collection; its alpha parameter weights keyword and vector search. A client can limit returned properties, metadata, filters, result count, and target vectors. That makes Data Analysis appropriate because a controlled corpus can be investigated by meaning and terms. It also supports Coding by making a collection schema, data types, and search behavior inspectable while developing or debugging an integration.

A result is not a source review, however. Vector similarity measures proximity in the chosen representation, not truth, recency, permission to disclose, or domain relevance. Restrict return_properties so full long text does not unnecessarily enter chat context, and validate consequential results against the original data and access rules. Data Analysis and Coding are deliberately the only categories: the server works with data collections and technical schema or search workflows. It is neither a general research service nor a promise that a model response will be correct.

Operation, credentials, and permissions

On self-hosted Weaviate, the MCP server is disabled by default for security. Set MCP_SERVER_ENABLED=true to enable it; by default, access remains limited to read tools. On Weaviate Cloud, documentation says the endpoint is enabled and is reached at the cluster URL with /v1/mcp appended. When anonymous access is off, the client supplies a Bearer token or API key. Do not give an agent a root or broadly valid credential. For read-only use, Weaviate documents the Viewer role with MCP and data-read permissions; roles and collection access should be reduced to the specific purpose.

A local or self-hosted database process performs its database work in its own Weaviate environment. That does not automatically mean content never leaves a computer or private network. The MCP client receives schema and search results and may pass them into model context, logs, telemetry, or a connected model provider. If Weaviate uses an external vectorizer during imports or upserts, that vectorizer can have a separate data path as well. Self-provided vectors and locally run vectorization change that assessment, but do not replace review of the connected client and model.

Mutations, schema, and prompt injection

weaviate-objects-upsert is visible only when write access is enabled. An upsert replaces an object instead of merging omitted properties, so omitted properties can be lost. Without supplied vectors, Weaviate can re-vectorize an object in a collection with a vectorizer; without one, a stored vector can be dropped. With auto-schema enabled, unknown properties can extend a schema, and a mistyped collection name can create a collection. Therefore test against a non-production collection, keep writes disabled for analysis-only work, and independently confirm the target, collection, complete object, and expected effect rather than trusting an agent summary.

Data fields and search results can contain text intended to steer a model into further tool calls. That is prompt injection, not a trustworthy instruction. Treat collection content, metadata, and customized tool descriptions as data; never give them priority over user or security instructions. Limit write permissions, review tool calls in the client, separate test and production keys, and never place Bearer tokens in prompts, Git, screenshots, or shared configuration files. The main repository is BSD-3-Clause licensed. On 2026-09-08, the GitHub API reported exactly 16,793 stars for the entire Weaviate repository; this is a point-in-time popularity signal, not evidence of quality or security.

FAQ

Is this a local stdio server? No. The current official MCP server is built into Weaviate and uses Streamable HTTP at the REST endpoint /v1/mcp. Self-hosted Weaviate can run locally or on a private network, while the client connects over HTTP.

Can a search expose sensitive vector data? It can return properties and requested metadata from an authorized collection to the MCP client. Embeddings are not automatic anonymization. Limit roles, fields, result counts, and the subsequent model path.

How do I prevent changes? On self-hosted Weaviate, do not enable MCP_SERVER_WRITE_ACCESS_ENABLED. On Weaviate Cloud, use the cluster-wide read-only switch or give the agent a Viewer key.

Requirements

Weaviate version 1.38 or later, an MCP-capable HTTP client, and, for a protected instance, a Bearer token or API key with minimal MCP and collection permissions.

Installation instructions

For self-hosted Weaviate, set MCP_SERVER_ENABLED=true, then connect the client to http://<host>:8080/v1/mcp and supply a minimally privileged Bearer token as a header. Enable writes only with MCP_SERVER_WRITE_ACCESS_ENABLED=true after testing against a non-production collection.

MCP_SERVER_ENABLED=true weaviate

Authentication

When anonymous access is disabled, the client uses a Bearer token or API key. With RBAC, appropriate MCP and collection permissions are also required; a Viewer key suits read-only access.

Required access permissions

Weaviate enforces permissions through the API key, role, and collection access. Seeing a tool in the list does not prove permission; write access must be enabled separately.

Transmitted or stored data

Weaviate processes objects, vectors, and queries in the connected instance. Results go to the MCP client and can reach its logs, telemetry, or a connected model; external vectorizers can add another data path.

Security risks

Broad Bearer tokens, write upserts, auto-schema, sensitive object or vector data, prompt injection in results, and forwarding to the connected model path increase risk.

License and costs

License
BSD-3-Clause
Cost
free

The MCP source integrated into Weaviate follows the main repository’s BSD-3-Clause license. Infrastructure, Weaviate Cloud, vectorization, and the selected AI client can have separate terms; consult the respective providers for current details. This public entry states no specific prices.

Alternatives

Not recorded yet.

At a glance

Provider
Weaviate
Status
Official server
Deployment
Local and remote
Current version
1.39.0
GitHub stars
16,854
Last reviewed
08.09.2026

Repository and documentation

Categories

Supported clients

Not recorded yet.