opik-mcpCAUTION
Model Context Protocol (MCP) server for Opik, the open-source LLM observability and evaluation platform, built by Comet. Read traces, log scores, and manage prompts from Claude Code, Cursor, or VS Code.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
The official Model Context Protocol (MCP) server for [Opik](https://github.com/comet-ml/opik), the open-source LLM observability and evaluation platform, built by [Comet](https://www.comet.com). Plug your AI host (Claude Code, Cursor, VS Code Copilot, Codex, opencode, or any MCP client) directly into your Opik workspace: read traces, log scores, and save prompt versions, all from the chat.
Built for LLM engineers who already run Opik and want to drive it from the same AI assistant they code with.
You: "Which traces in project 'demo' failed today?" Claude: → list(entity_type="trace", project_name="demo") → "Three traces failed..." You: "Score trace 7f2e... 0.9 on helpfulness with reason 'great recovery'." Claude: → write(score.create) → done
Quick start
Asking a coding agent to set it up? It follows Install with a coding agent.
One command registers the server with the AI clients on your machine, installs the Opik skill pack, and verifies the connection. It needs `uv` and no Opik SDK:
uvx opik mcp configure
It detects Claude Code, Cursor, VS Code Copilot, Codex and opencode, and sets up the server that fits your Opik:
Clients load MCP servers when a session starts, so start a new session afterwards. Without a terminal, as from a coding agent or a script, name the client: uvx opik mcp configure --ai-client claude-code (or codex, cursor, vscode, opencode). Run that way it connects to the Opik saved in ~/.opik.config or one ans
ea629d016963OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add opik-mcp --env OPIK_API_KEY=${OPIK_API_KEY} -- uvx opik-mcp==0.0.0Exposed tools (2)
2 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
hello | read | return |
hi | read | return |
Trust audit
CAUTIONgrade B · trust 85/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (7 observation(s))
- Network
- declared (7 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- found
Findings (18)
print(f"BI capture listening on http://127.0.0.1:{port}/notify/event/", flush=True)opik_mcp_allowed_origins: str = "http://127.0.0.1:*,http://localhost:*,http://[::1]:*"
OpenAI(base_url="https://api.provider.com/v1", api_key="your-provider-api-key")
.helmignore
for rebuilt in (pickle.loads(pickle.dumps(error)), copy.copy(error), copy.deepcopy(error)):
cases = importlib.import_module(name).CASES
@pytest.mark.parametrize("name", ["x/../../..", "../sibling", "Upper", "a b", "-x", "a" * 60])"opik/../../../etc/passwd",
"opik/../../scripts/build_skills_pack.py",
"../../../../etc/passwd",
"opik://skills/../../../etc/passwd",
OPIK_URL=http://127.0.0.1:28080 make live
OPIK_URL=http://127.0.0.1:28080 uv run python scripts/seed_e2e_backend.py --prefix my-fixture
OPIK_URL=http://127.0.0.1:28080 uv run python scripts/seed_e2e_backend.py --prefix my-fixture --wipe
Each open issue becomes one shortlist item with `signal=diagnostics`: `trace_id` comes from the first `example_trace_ids` entry (read the top few issues to get them) and `trace_url` from `trace_url_te
Open question: a hosted request with an API key and no `Comet-Workspace` falls
curl -LsSf https://astral.sh/uv/install.sh | sh # macOS / Linux
curl -LsSf https://astral.sh/uv/install.sh | sh # macOS / Linux
Gates applied: no_behavioural_pass.
ea629d016963full audit observations/trust-audit/mcp-server/comet-ml__opik-mcp.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | ea629d016963 | CAUTION | B | 85 | first audit |
Questions
What is the opik-mcp MCP server?
Model Context Protocol (MCP) server for Opik, the open-source LLM observability and evaluation platform, built by Comet. Read traces, log scores, and manage prompts from Claude Code, Cursor, or VS Code.
What tools does opik-mcp expose?
2 in total: 2 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is opik-mcp safe to connect to an agent?
With care. The audit graded it B (85/100) and found 18 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does opik-mcp need?
It reads GH_TOKEN, OPENAI_API_KEY and OPIK_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does opik-mcp run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as opik-verify-eval-gate.
How current is this page?
The grade is for one exact copy of the source (ea629d016963), read on 2026-10-08. The repository is watched and re-audited when it changes.