ReplicateCAUTION
Model Context Protocol server for Replicate's API
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A Model Context Protocol server implementation for Replicate. Run Replicate models through a simple tool-based interface.
NOT IN ACTIVE DEVELOPMENT
This repo was an experiment in MCP tooling for Replicate. The company now offers an official MCP server. This repo will stay up for those who find it useful or want to fork it, but it's not in active development and issues won't be addressed. Contributions might be folded in but no promises. Enjoy at your own risk.
Quickstart
- Install the server:
npm install -g mcp-replicate
- Get your Replicate API token:
- Go to Replicate API tokens page
- Create a new token if you don't have one
- Copy the token for the next step
- Configure Claude Desktop:
- Open Claude Desktop Settings (⌘,)
- Select the "Developer" section in the sidebar
- Click "Edit Config" to open the configuration file
- Add the following configuration, replacing
your_token_herewith your actual Replicate API token:
{
"mcpServers": {
"replicate": {
"command": "mcp-replicate",
"env": {
"REPLICATE_API_TOKEN": "your_token_here"
}
}
}
}- Start Claude Desktop. You should see a 🔨 hammer icon in the bottom right corner of new chat windows, indicating the tools are available.
(You can also use any other MCP client, such as Cursor, Cline, or Continue.)
Alternative Installation Methods
Install from source
git clone https://github.com/deepfates/mcp-replicate cd mcp-replicate npm install npm run build npm start
Run with npx
npx mcp-replicate
Features
Models
- Search models using semantic search
- Browse models and collections
- Get detailed model information and versions
Predictions
- Create predictions with text or structured input
- Track predict
396ecc8f584fOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-replicate --env REPLICATE_API_TOKEN=${REPLICATE_API_TOKEN} -- npx -y [email protected]{
"mcpServers": {
"mcp-replicate": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"REPLICATE_API_TOKEN": "${REPLICATE_API_TOKEN}"
}
}
}
}Exposed tools (28)
25 read · 2 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
Anime | read | Japanese anime and manga style |
Balanced | read | Good balance between quality and speed |
Cinematic | read | Movie-like scenes with dramatic lighting |
Draft | read | Quick, low-quality preview with minimal steps |
Extreme | read | Maximum quality with extensive steps |
Landscape | read | Horizontal format for landscapes |
Minimalist | read | Clean, simple minimalist style |
Panoramic | read | Extra wide format for panoramas |
Photorealistic | read | Highly detailed, realistic photography style |
Portrait | read | Vertical format for portraits |
Quality | read | High-quality output with more steps |
Square | read | Perfect square format |
Watercolor | read | Soft watercolor painting style |
Widescreen | read | 16:9 format for modern displays |
cancel_prediction | read | Cancel a running prediction |
clear_image_cache | destructive | Clear the image viewer cache |
create_and_poll_prediction | write | Create a new prediction and wait until it |
create_prediction | write | Create a new prediction using either a model version (for community models) or model name (for official models) |
get_collection | read | Get details of a specific collection |
get_image_cache_stats | read | Get statistics about the image cache |
get_model | read | Get details of a specific model including available versions |
get_prediction | read | Get details about a specific prediction |
list_collections | read | List available model collections |
list_models | read | List available models with optional filtering |
list_predictions | read | List recent predictions |
sdxl | read | Test model |
search_models | read | Search for models using semantic search |
view_image | read | Display an image in the system |
Trust audit
CAUTIONgrade B · trust 85/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (2 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (6)
mcp-replicate-0.1.0.tgz
mcp-replicate-0.1.1.tgz
secret: "1234567890abcdef1234567890abcdef",
clear_image_cache
import type { MCPMessage } from "../../types/mcp.js";@modelcontextprotocol/sdk, replicate, @biomejs/biome, @types/node, typescript, vitest
Gates applied: no_behavioural_pass.
396ecc8f584ffull audit observations/trust-audit/mcp-server/deepfates__replicate-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 396ecc8f584f | CAUTION | B | 85 | first audit |
Questions
What is the Replicate MCP server?
Model Context Protocol server for Replicate's API
What tools does Replicate expose?
28 in total: 25 read-only, 2 that write, and 1 that can delete or overwrite (clear_image_cache). Every one is listed on this page with its risk.
Is Replicate safe to connect to an agent?
With care. The audit graded it B (85/100) and found 6 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Replicate need?
It reads REPLICATE_API_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Replicate run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as mcp-replicate at 0.1.1.
How current is this page?
The grade is for one exact copy of the source (396ecc8f584f), read on 2026-10-07. The repository is watched and re-audited when it changes.