Azure Cosmos DBSAFE
This repository contains a collection of sample implementations of the MCP across multiple programming languages, all backed by Azure Cosmos DB. These examples demonstrate how to create, query, update, and delete documents using the Azure Cosmos DB SDKs
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
What is this? 🤔
This repo showcases how to build Model Context Protocol (MCP) servers using Azure Cosmos DB. Explore ready-to-run samples in multiple programming languages including TypeScript,GoLang and Java.
- JavaScript MCP Server Sample for Azure Cosmos DB
- GoLang MCP Server Sample for Azure Cosmos DB
- Java MCP Server Sample for Azure Cosmos DB
- Python MCP Server Sample for Azure Cosmos DB
📦 Official Azure Cosmos DB MCP Toolkit
A Model Context Protocol (MCP) server that enables AI agents to interact with Azure Cosmos DB through natural language queries. Features enterprise-grade security with Azure Entra ID authentication, document operations, vector search, and schema discovery.
Contributing
This project welcomes contributions and suggestions. Most contributions require you to agree to a Contributor License Agreement (CLA) declaring that you have the right to, and actually do, grant us the rights to use your contribution. For details, visit https://cla.opensource.microsoft.com.
When you submit a pull request, a CLA bot will automatically determine whether you need to provide a CLA and decorate the PR appropriately (e.g., status check, comment). Simply follow the instructions provided by the bot. You will only need to do this once across all repos using our CLA.
This project has adopted the Microsoft Open Source Code of Conduct. For more information see the Code of Conduct FAQ or contact [email protected] with any additional questions or comments.
Trademarks
This project may contain trademarks or logos for projects, produc
e88bd157bc8bOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add cosmosdb-mcp-server --env COSMOSDB_KEY=${COSMOSDB_KEY} --env COSMOS_KEY=${COSMOS_KEY} -- npx -y [email protected]{
"mcpServers": {
"cosmosdb-mcp-server": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"COSMOSDB_KEY": "${COSMOSDB_KEY}",
"COSMOS_KEY": "${COSMOS_KEY}"
}
}
}
}Exposed tools (13)
11 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
count_documents | read | |
describe_container | read | |
find_implied_links | read | |
get_indexing_policy | read | |
get_item | read | Retrieves an item from a Azure Cosmos DB container by its ID |
get_partition_key_info | read | |
get_sample_documents | read | |
list_collections | read | |
list_distinct_values | read | |
put_item | write | Inserts or replaces an item in a Azure Cosmos DB container |
query_container | read | Queries an Azure Cosmos DB container using SQL-like syntax |
query_cosmos | read | |
update_item | write | Updates specific attributes of an item in a Azure Cosmos DB container |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (11)
Your server will be running at `http://127.0.0.1:8080/mcp/` 🚀
url: http://127.0.0.1:8080/mcp/
mcp = FastMCP.as_proxy("http://127.0.0.1:8080/mcp/", name="Azure Cosmos DB Explorer")**Endpoint**: `http://127.0.0.1:8080/mcp/`
- Ensure server is running: `curl http://127.0.0.1:8080/mcp/`
@azure/cosmos, @azure/identity, @modelcontextprotocol/sdk, dotenv, @types/dotenv, @types/node, shx, ts-node
azure-cosmos, pandas, mcp, fastmcp, azure-identity, python-dotenv
golang/images/demo.png
img/logo.png
java/media/demo.gif
> - Load configuration from `.env` file or environment variables
Gates applied: no_behavioural_pass.
e88bd157bc8bfull audit observations/trust-audit/mcp-server/azurecosmosdb__azure-cosmos-db.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | e88bd157bc8b | SAFE | B | 89 | first audit |
Questions
What is the Azure Cosmos DB MCP server?
This repository contains a collection of sample implementations of the MCP across multiple programming languages, all backed by Azure Cosmos DB. These examples demonstrate how to create, query, update, and delete documents using the Azure Cosmos DB SDKs
What tools does Azure Cosmos DB expose?
13 in total: 11 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Azure Cosmos DB safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Azure Cosmos DB need?
It reads COSMOSDB_KEY and COSMOS_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Azure Cosmos DB run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as cosmosdb-mcp-server at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (e88bd157bc8b), read on 2026-10-08. The repository is watched and re-audited when it changes.