jupyter-mcp-serverBLOCK
🪐 🔧 Model Context Protocol (MCP) Server for Jupyter.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://github.com/sponsors/datalayer)
An [MCP](https://modelcontextprotocol.io) server developed for AI to connect and manage [Jupyter](https://jupyter.org) Notebooks in real-time — and scale your [Code Sandbox](https://jupyter-mcp-server.datalayer.tech/code-sandboxes) from local to the cloud (Datalayer, Kaggle, Google Colab, Modal, Daytona, E2B, CoreWeave, Cloudflare...)
Developed by [Datalayer](https://datalayer.ai) - Join our [Discord](https://discord.gg/YQFwvmSSuR)
[](https://pypi.org/project/jupyter-mcp-server) [](https://pepy.tech/project/jupyter-mcp-server) [](https://hub.docker.com/r/datalayer/jupyter-mcp-server) [](https://opensource.org/licenses/BSD-3-Clause)
[](https://datalayer.ai)
📖 Documentation · 🔧 Tools
f36b91356ee4OBSERVED · 2026-09-25Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add jupyter-mcp-server-docs --env MCP_TOKEN=${MCP_TOKEN} -- npx -y @datalayer/[email protected]{
"mcpServers": {
"jupyter-mcp-server-docs": {
"command": "npx",
"args": [
"-y",
"@datalayer/[email protected]"
],
"env": {
"MCP_TOKEN": "${MCP_TOKEN}"
}
}
}
}Exposed tools (2)
1 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
read_cell | read | Read a cell. |
touch_the_notebook | write | Publish, exactly as a writing tool |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (10 observation(s))
- Shell
- declared (3 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (25)
typer.Option("--insecure-mcp-noauth", envvar="INSECURE_MCP_NOAUTH"),help="Token for authenticating MCP clients (Bearer scheme). Required for streamable-http unless --insecure-mcp-noauth is set.",
module = importlib.import_module(module_name)
module = importlib.import_module(module_name)
module = importlib.import_module(module_name)
.licenserc.yaml
.pre-commit-config.yaml
.yarnrc.yml
.mcpbignore
importlib.import_module(mod.name)
exec("import ast\n" + text[start:end], namespace) # noqa: S102expected_result = eval(code_content)
expected_result = eval(code_content)
Svg: require('../../static/img/feature_1.svg').default,Svg: require('../../static/img/feature_2.svg').default,Svg: require('../../static/img/feature_3.svg').default,Svg: require('../../static/img/product_1.svg').default,Svg: require('../../static/img/product_2.svg').default,This starts JupyterLab at [http://127.0.0.1:4040](http://127.0.0.1:4040) with the MCP server integrated.
claude mcp add jupyter --transport http http://127.0.0.1:4040/mcp \
"http://127.0.0.1:4040/mcp",
claude mcp add jupyter --transport http http://127.0.0.1:4040/mcp \
"http://127.0.0.1:4040/mcp",
`- \`streamable-http\` — served by uvicorn on \`--port\`; requires \`--mcp-token\` unless \`--insecure-mcp-noauth\` is passed.`,
@echo " start-noauth - Start everything with --insecure-mcp-noauth (local dev only)"
Gates applied: no_behavioural_pass.
f36b91356ee4full audit observations/trust-audit/mcp-server/datalayer__jupyter-mcp-server.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-25 | f36b91356ee4 | BLOCK | D | 69 | first audit |
Questions
What is the jupyter-mcp-server MCP server?
🪐 🔧 Model Context Protocol (MCP) Server for Jupyter.
What tools does jupyter-mcp-server expose?
2 in total: 1 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is jupyter-mcp-server safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does jupyter-mcp-server need?
It reads MCP_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does jupyter-mcp-server run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @datalayer/jupyter-mcp-server-docs at 0.0.1.
How current is this page?
The grade is for one exact copy of the source (f36b91356ee4), read on 2026-09-25. The repository is watched and re-audited when it changes.