AivenCAUTION
Model Context Protocol server for Aiven
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A Model Context Protocol (MCP) server for the Aiven cloud data platform.
Manage PostgreSQL, Apache Kafka, applications, and other Aiven services directly from AI assistants like Claude, Cursor, and VS Code Copilot.
[!WARNING] Use with care. This MCP server can create, modify, and delete Aiven services and data on your behalf. AI agents may execute destructive actions (dropping databases, deleting services, producing messages) based on their interpretation of your prompts. You are fully responsible for the actions taken through this tool. Permissions: Access is governed by the Aiven user permissions associated with the authenticated account. The MCP server can only perform actions that your Aiven user is allowed to do. AI Agent Security: AI agents may need access credentials (database connection strings, streaming tokens) to act on your behalf. Review what your agent is doing, especially in production environments. Follow your organization's security policies and do a risk assessment before giving AI agents access to sensitive resources.
Quick Start
Option 1: Remote (hosted by Aiven)
The MCP server is hosted at https://mcp.aiven.live/mcp. Your MCP client will prompt you to authorize on Aiven.
Claude Code
claude mcp add --scope user --transport http aiven-mcp "https://mcp.aiven.live/mcp"
Cursor
[](https://cursor.com/en-US/install-mcp?name=aiven-mcp&config=eyJ1cmwiOiJodHRwczovL21jcC5haXZlbi5saXZlL21jcCJ9)
Or manually add to Cursor MCP settings:
{
"mcpServers": {
"aiven-mcp": {
"url": "https://mcp.aiven.live/mcp"
}
}
}VS Code / Copilot
Add to .vscode/mcp.json in your workspace:
{
"servers": {
"aiven-mcp": {
"type": "http",
"url": "https://mcp.aiven.live/mcp"
}
}
}Read-Only Mode
f28780bd906aOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-aiven --env AIVEN_TOKEN=${AIVEN_TOKEN} -- npx -y [email protected]Trust audit
CAUTIONgrade D · trust 69/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (18)
service_uri: 'postgres://u:p@h:5432/defaultdb',
expect(scrubReasoning('use postgres://admin:[email protected]:5432/main to query')).toBe(message: 'error connecting to postgres://avnadmin:AVNS_secret@pg-host:5432/defaultdb',
password: 'resolved-password-must-not-be-returned',
access_key: '-----BEGIN PRIVATE KEY-----\nkey\n-----END PRIVATE KEY-----',
const key = '-----BEGIN PRIVATE KEY-----\nMIIBVwIBADANBg\n-----END PRIVATE KEY-----';
.lintstagedrc
.prettierignore
.release-please-manifest.json
import type { AivenClient } from '../../client.js';import type { ToolDefinition, ToolResult, HandlerContext, RequestOptions } from '../../types.js';} from '../../types.js';
import { errorMessage } from '../../errors.js';import { redactSensitiveData } from '../../security.js';@modelcontextprotocol/sdk, express, google-auth-library, express-rate-limit, libpg-query, openapi-fetch, yaml, zod
Production HTTP traffic is rate-limited in two layers: Cloudflare enforces a per-client-IP limit (configured in the Cloudflare dashboard), and this server enforces `MCP_HTTP_RATE_LIMIT_*` per bearer t
> **AI Agent Security:** AI agents may need access credentials (database connection strings, streaming tokens) to act on your behalf. Review what your agent is doing, especially in production environm
Gates applied: no_behavioural_pass.
f28780bd906afull audit observations/trust-audit/mcp-server/aiven-open__aiven.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | f28780bd906a | CAUTION | D | 69 | first audit |
Questions
What is the Aiven MCP server?
Model Context Protocol server for Aiven
Is Aiven safe to connect to an agent?
With care. The audit graded it D (69/100) and found 18 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Aiven need?
It reads AIVEN_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Aiven run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as mcp-aiven at 1.17.1.
How current is this page?
The grade is for one exact copy of the source (f28780bd906a), read on 2026-10-08. The repository is watched and re-audited when it changes.