SunoCAUTION
MCP server for Suno AI music generation, lyrics, and cover workflows via Ace Data Cloud.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://pypi.org/project/mcp-suno/) [](https://pypi.org/project/mcp-suno/) [](https://www.python.org/downloads/) [](https://opensource.org/licenses/MIT) [](https://modelcontextprotocol.io)
A Model Context Protocol (MCP) server for AI music generation using Suno through the AceDataCloud API.
Generate AI music, lyrics, and manage audio projects directly from Claude, VS Code, or any MCP-compatible client.
Features
- Music Generation - Create AI-generated songs from text prompts
- Custom Lyrics & Style - Full control over lyrics, title, and music style
- Song Extension - Continue existing songs from any timestamp
- Cover/Remix - Create cover versions with different styles
- Lyrics Generation - Generate structured lyrics from descriptions
- Persona Management - Save and reuse voice styles
- Custom Music Models - Create and reuse app-owned custom music models
- Task Tracking - Monitor generation progress and retrieve results
Tool Reference
bbbe696bc34aOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-suno --env ACEDATACLOUD_API_TOKEN=${ACEDATACLOUD_API_TOKEN} -- uvx mcp-suno==2026.3.19.7Exposed tools (10)
10 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
suno_archive_custom_model | read | Archive a custom music model so it can no longer be used. |
suno_get_custom_model | read | Retrieve a single custom music model by ID. |
suno_get_lyric_format_guide | read | Get guidance on formatting lyrics for Suno music generation. |
suno_get_mp4 | read | Get an MP4 video version of a generated song. |
suno_get_task | read | Query the status and result of a music generation task. |
suno_get_tasks_batch | read | Query multiple music generation tasks at once. |
suno_get_timing | read | Get timing and subtitle data for a generated song. |
suno_list_actions | read | List all available Suno API actions and corresponding tools. |
suno_list_models | read | List all available Suno models and their capabilities. |
suno_optimize_style | read | Optimize a music style description for better generation results. |
Trust audit
CAUTIONgrade B · trust 86/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (10)
gradle-wrapper.jar
logger.info(f"Revoked token: {token.token[:8]}...")if not request_payload.get("callback_url"):callback_url = f"{settings.server_url}/oauth/callback""redirect_uri": callback_url,
callback_url = f"{settings.server_url}/oauth/callback""redirect_uri": callback_url,
.ruff.toml
.vscodeignore
self._cipher = Fernet(base64.urlsafe_b64encode(bytes.fromhex(key)))
Gates applied: no_behavioural_pass.
bbbe696bc34afull audit observations/trust-audit/mcp-server/acedatacloud__suno-4.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | bbbe696bc34a | CAUTION | B | 86 | first audit |
Questions
What is the Suno MCP server?
MCP server for Suno AI music generation, lyrics, and cover workflows via Ace Data Cloud.
What tools does Suno expose?
10 in total: 10 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Suno safe to connect to an agent?
With care. The audit graded it B (86/100) and found 10 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Suno need?
It reads ACEDATACLOUD_API_TOKEN, ACEDATACLOUD_AUTH_BASE_URL, ACEDATACLOUD_OAUTH_CLIENT_ID, MCP_OAUTH_REDIS_PASSWORD, MCP_OAUTH_REDIS_URL and MCP_OAUTH_STATE_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Suno run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as mcp-suno at 0.3.0.
How current is this page?
The grade is for one exact copy of the source (bbbe696bc34a), read on 2026-10-08. The repository is watched and re-audited when it changes.