IBM i ServerBLOCK
MCP server for IBM i systems
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.typescriptlang.org/) [](https://github.com/modelcontextprotocol/typescript-sdk) [](https://github.com/modelcontextprotocol/modelcontextprotocol/blob/main/docs/specification/2025-06-18/changelog.mdx) [](https://opensource.org/licenses/Apache-2.0) [](https://github.com/IBM/ibmi-mcp-server.git) [](https://deepwiki.com/IBM/ibmi-mcp-server)
MCP server and CLI for IBM i
Overview
The IBM i MCP Server enables AI agents to interact with IBM i systems through the Model Context Protocol (MCP). It provides secure, SQL-based access to Db2 for i databases, allowing AI applications like Claude, VSCode Copilot, Bob, and custom agents to query system information, monitor performance, and execute database operations.
This repo also ships the `ibmi` CLI (`@ibm/ibmi-cli`) — a terminal-first sibling that shares the same YAML-driven SQL tool engine, so the same tool definitions work in both the MCP server and the CLI.
How it works: AI clients connect via MCP → Server executes YAML-defined SQL tools → Results stream back to the AI agent through Mapepire.
[!TIP] 📚 [Official Documentation](https://ibm-d95bab6e.mintlify.app/) | ⚠️ Docs are under active development The Docs are continuously evolving. Please check back f
4cf8304d9a2cOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add ibmi-mcp-server --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env IBMI_MCP_ACCESS_TOKEN=${IBMI_MCP_ACCESS_TOKEN} --env MCP_AUTH_TOKEN=${MCP_AUTH_TOKEN} --env MY_TEST_PASS=${MY_TEST_PASS} -- npx -y @ibm/[email protected]{
"mcpServers": {
"ibmi-mcp-server": {
"command": "npx",
"args": [
"-y",
"@ibm/[email protected]"
],
"env": {
"ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
"IBMI_MCP_ACCESS_TOKEN": "${IBMI_MCP_ACCESS_TOKEN}",
"MCP_AUTH_TOKEN": "${MCP_AUTH_TOKEN}",
"MY_TEST_PASS": "${MY_TEST_PASS}"
}
}
}
}Exposed tools (7)
7 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
1_test_tool | read | A test tool |
describe_sql_object | read | Generate the SQL DDL statement for an IBM i database object. Use this to see the full CREATE definition of a table, view, index, procedure, function, or other object. |
get_related_objects | read | Get all objects that depend on a database file — views, indexes, triggers, foreign keys, logical files, and more. Use for impact analysis before schema changes or to understand a table |
get_table_columns | read | Get column metadata for a table including names, data types, lengths, nullability, defaults, and descriptions. Use this to understand table structure before writing SQL queries. |
list_schemas | read | List available schemas/libraries on the IBM i system. Use this as the first step in schema discovery to find which schemas contain relevant tables. |
list_tables_in_schema | read | List tables, views, and physical files in a specific schema with metadata including row counts. Use after list_schemas to find tables before querying column details. |
test_tool | read | A test tool |
Trust audit
BLOCKgrade F · trust 39/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (9 observation(s))
- Network
- declared (16 observation(s))
- Shell
- declared (7 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
const parsed = yaml.load(raw);
const data = yaml.load(raw) as unknown;
const config = yaml.load(yamlContent);
# - NODE_TLS_REJECT_UNAUTHORIZED=0 # <- Node.js will accept your self-signed cert
rejectUnauthorized: false,
rejectUnauthorized: false,
url: str = "postgresql://postgres:mysecretpassword@localhost:5432/agno"
console.log(` Password: ${credentialSource.password}`);console.log(` Password: ${"*".repeat(TEST_CONFIG.password.length)}`);console.log(`export IBMI_MCP_ACCESS_TOKEN="${token}"`);console.log(` Token: ${token.substring(0, 20)}...`);console.log(` Length: ${token.length} bytes`);DEFAULT_MCP_URL = "http://127.0.0.1:3010/mcp"
# Optional: MCP server URL (default: http://127.0.0.1:3010/mcp)
IBMI_MCP_SERVER_URL=http://127.0.0.1:3010/mcp
xlinkHref="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAMgAAADICAIAAAAiOjnJAAAMPWlDQ1BJQ0MgUHJvZmlsZQAASImVVwdYU8kWnltSSWgBBKSE3gSRGkBKCC2A9CLYCEmAUGIMBBU7uqjg2kUEbOiqiGIHxI7YWRR7XyyoKOtiwa68SQFd95X
ANTHROPIC_API_KEY=sk-ant-your-anthropic-api-key
api_key="sk-hardcoded-key-bad" # Never do this
.ncurc.json
.prettierignore
.versionrc.json
return yaml.load(data) as object;
const parsedYaml = yaml.load(data) as object;
import { Button } from '../../../ui/button'- ../../.env # Load environment variables from root .env file
Gates applied: no_behavioural_pass.
4cf8304d9a2cfull audit observations/trust-audit/mcp-server/ibm__ibm-i-server.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 4cf8304d9a2c | BLOCK | F | 39 | first audit |
Questions
What is the IBM i Server MCP server?
MCP server for IBM i systems
What tools does IBM i Server expose?
7 in total: 7 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is IBM i Server safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (39/100) and found 7 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does IBM i Server need?
It reads ANTHROPIC_API_KEY, IBMI_MCP_ACCESS_TOKEN, MCP_AUTH_TOKEN, MY_TEST_PASS, NEXT_PUBLIC_OS_SECURITY_KEY, OPENAI_API_KEY, TEST_PASS and WATSONX_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does IBM i Server run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @ibm/ibmi-mcp-server at 0.6.1.
How current is this page?
The grade is for one exact copy of the source (4cf8304d9a2c), read on 2026-10-07. The repository is watched and re-audited when it changes.