GeoServerSAFE
A Model Context Protocol (MCP) server implementation that connects LLMs to the GeoServer REST API
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://pypi.org/project/geoserver-mcp/) [](https://pepy.tech/project/geoserver-mcp)
A Model Context Protocol (MCP) server implementation that connects Large Language Models (LLMs) to the GeoServer REST API, enabling AI assistants to interact with geospatial data and services.
Version 0.5.0 (Beta) is under active development and will be released shortly. We are open to contributions and welcome developers to join us in building this project.
🎥 Demo
📋 Table of Contents
- Features
- Deployment Options
- Prerequisites
- Installation
- Docker Installation
- pip Installation
- Development Installation
- File Storage and
--storageUsage - Available Tools
- Resource Endpoints
- Workspace Management
- Datastore & Coveragestore Management
- Layer Management
- Layer Group Management
- User & User Group Management
- Feature Type & Attribute Management
- Style Management
- System & Service Operations
- Style XML Utilities
- [Client Dev
3bca0fc376e9OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add geoserver-mcp --env GEOSERVER_PASSWORD=${GEOSERVER_PASSWORD} --env OPENAI_API_KEY=${OPENAI_API_KEY} --env OPENROUTER_API_KEY=${OPENROUTER_API_KEY} -- uvx geoserver-mcp{
"mcpServers": {
"geoserver-mcp": {
"command": "uvx",
"args": [
"geoserver-mcp"
],
"env": {
"GEOSERVER_PASSWORD": "${GEOSERVER_PASSWORD}",
"OPENAI_API_KEY": "${OPENAI_API_KEY}",
"OPENROUTER_API_KEY": "${OPENROUTER_API_KEY}"
}
}
}
}Exposed tools (56)
25 read · 24 write · 7 destructive. Blast radius: 7 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
add_layer_to_layergroup | write | Add a specific layer to a layer group. |
create_catagorized_featurestyle | write | Create a categorized style for features (polygon, line, point) using column values. |
create_classified_featurestyle | write | Create a classified style for features using distinct column values/classes. |
create_coveragestore | write | Create a new coveragestore in a workspace. |
create_coveragestyle | write | Create a raster coverage style (colormap, ...) |
create_datastore | write | Create a new datastore in the given workspace. |
create_featurestore | write | Create a new featurestore in the given workspace. |
create_gpkg_datastore | write | Create a GeoPackage (GPKG) datastore. |
create_layer | write | Create a new layer in GeoServer. |
create_layergroup | write | Create a new layer group with specific layers and (optionally) styles. |
create_outline_featurestyle | write | Create a simple outline-only style for features. |
create_shp_datastore | write | Create an ESRI Shapefile datastore. |
create_style | write | Create a new SLD style in GeoServer. |
create_user | write | Create a new user for GeoServer security. |
create_usergroup | write | Create a new user group. |
create_workspace | write | Create a new workspace in GeoServer. |
delete_coveragestore | destructive | Delete a coveragestore from a workspace. |
delete_layergroup | destructive | Delete a layer group from a workspace. |
delete_resource | destructive | Delete a resource from GeoServer. |
delete_user | destructive | Delete a user by name. |
delete_usergroup | destructive | Delete a user group. |
edit_featuretype | write | Edit the settings of a feature type in a store. |
generate_map | read | Generate a map image using WMS GetMap. |
get_all_usergroups | read | Return all user groups. |
get_all_users | read | List all users in the GeoServer instance. |
get_coveragestore | read | Get details about a single coveragestore. |
get_coveragestores | read | Get all coveragestores in a workspace. |
get_datastore | read | Get a specific datastore by name. |
get_datastores | read | List all datastores in the given workspace. |
get_feature_attribute | read | Get feature attribute schema/details. |
get_featuretypes | read | List all feature types in a given store. |
get_layer_info | read | Get detailed information about a layer. |
get_layergroup | read | Get a layer group from a workspace. |
get_layergroups | read | List all layer groups in a workspace. |
get_manifest | read | Get GeoServer manifest metadata/details. |
get_status | read | Obtain general server status. |
get_system_status | read | Get system status overview/info from GeoServer. |
get_version | read | Fetch GeoServer version string. |
list_layers | read | List layers in GeoServer, optionally filtered by workspace. |
list_workspaces | read | List available workspaces in GeoServer. |
modify_user | write | Modify an existing user |
publish_featurestore | write | Publish an existing featurestore. |
publish_featurestore_sqlview | write | Publish a featurestore using a SQL view definition. |
publish_style | write | Assign/publish a style to a layer. |
publish_time_dimension_to_coveragestore | write | Add or update a time dimension for a coverage store (for time series). |
query_features | read | Query features from a vector layer using CQL filter. |
reload_geoserver | read | Reload catalog and config from disk. |
remove_layer_from_layergroup | destructive | Remove a layer from a group. |
reset_geoserver | destructive | Reset all GeoServer caches/connections. |
style_catagorize_xml | read | Generate SLD for categorized vector style (SVG fill/block display). |
style_classified_xml | read | Get SLD XML for classified vector style. |
style_coverage_style_colormapentry | read | Generate color map entries for raster SLD. |
style_coverage_style_xml | read | Generate XML for raster/coverage SLD. |
style_outline_only_xml | read | XML for outline-only style for a geometry. |
update_layergroup | write | Update a layer group |
update_service | write | Update selected OGC service options. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (2 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (3)
delete_coveragestore, delete_layergroup, delete_resource, delete_user, delete_usergroup, remove_layer_from_layergroup, reset_geoserver
"http://127.0.0.1:8080/geoserver/mcp (Python localhost can hit IPv6 and get 503).\n"
docs/geoserver-mcp.png
Gates applied: no_behavioural_pass.
3bca0fc376e9full audit observations/trust-audit/mcp-server/mahdin75__geoserver.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 3bca0fc376e9 | SAFE | B | 89 | first audit |
Questions
What is the GeoServer MCP server?
A Model Context Protocol (MCP) server implementation that connects LLMs to the GeoServer REST API
What tools does GeoServer expose?
56 in total: 25 read-only, 24 that write, and 7 that can delete or overwrite (delete_coveragestore, delete_layergroup, delete_resource, delete_user, delete_usergroup). Every one is listed on this page with its risk.
Is GeoServer safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 7 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does GeoServer need?
It reads GEOSERVER_PASSWORD, OPENAI_API_KEY and OPENROUTER_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does GeoServer run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on PyPI as geoserver-mcp.
How current is this page?
The grade is for one exact copy of the source (3bca0fc376e9), read on 2026-10-07. The repository is watched and re-audited when it changes.