Atlas / MCP servers / mrwyndham / PocketBase

PocketBaseCAUTION

mcp/mrwyndham/pocketbase-2

MCP server for building PocketBase apps really quickly - Need a front end quick consider FastPocket

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
24 13r · 7w · 4d
Transport
stdio
License
MIT
Stars
152
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A very much in progress MCP server based off of the Dynamics one that I have been testing and refining. That provides sophisticated tools for interacting with PocketBase databases. This server enables advanced database operations, schema management, and data manipulation through the Model Context Protocol (MCP).

Here is a video of me using it: https://www.youtube.com/watch?v=ZuTIO3I7rTM&t=345s

Why This And Not DynamicsEndpoints?

This has actually been tested on the latest version. Currently 26.1 of PocketBase and is built off of the type definitions in the JS-SDK and not the arbitrary and wrong definitions found in the Dynamics one. Many of the methods don't even work.

Setup MCP Server Locally (Only Way Supported for Now)

To set up the MCP server locally, you'll need to configure it within your cline_mcp_settings.json or whatever you use (claude, cursor, the config looks identical you just need to find where it is stored) file. Here's how:

  1. Locate your `cline_mcp_settings.json` file: This file is usually located in your Cursor user settings directory. For example:

/Users/yourusername/Library/Application Support/Cursor/User/globalStorage/saoudrizwan.claude-dev/settings/cline_mcp_settings.json

  1. Configure the server: Add a new entry to the mcpServers object in your cline_mcp_settings.json file. The key should be a unique name for your server (e.g., "pocketbase-server"), and the value should be an object containing the server's configuration.
{
"mcpServers": {
"pocketbase-server": {
"command": "node",
"args": ["build/index.js"],
"env": {
"POCKETBASE_URL": "http://127.0.0.1:8090",
"POCKETBASE_ADMIN_EMAIL": "[email protected]",
"POCKETBASE_ADMIN_PASSWORD": "admin_password"
},
"disabled": false,
"autoApprove": ["create_record", "create_collection"]
}
}
}
Read from source at commit 0c885b932434OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add pocketbase-server --env POCKETBASE_ADMIN_PASSWORD=${POCKETBASE_ADMIN_PASSWORD} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "pocketbase-server": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "POCKETBASE_ADMIN_PASSWORD": "${POCKETBASE_ADMIN_PASSWORD}"
      }
    }
  }
}
03

Exposed tools (24)

13 read · 7 write · 4 destructive. Blast radius: 4 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
auth_refreshreadRefresh authentication token
authenticate_userreadAuthenticate a user with email and password
authenticate_with_oauth2readAuthenticate a user with OAuth2
authenticate_with_otpreadAuthenticate a user with one-time password
backup_databasewriteCreate a backup of the PocketBase database
confirm_email_changereadConfirm email change with token
confirm_password_resetdestructiveConfirm password reset with token
confirm_verificationreadConfirm email verification with token
create_collectionwriteCreate a new collection in PocketBase note never use created and updated because these are already created
create_recordwriteCreate a new record in a collection
create_userwriteCreate a new user account
delete_collectiondestructiveDelete a collection from PocketBase (admin only)
delete_recorddestructiveDelete a record
get_collectionreadGet details for a collection
impersonate_userreadImpersonate another user (admin only)
import_datawriteImport data into a collection
list_auth_methodsreadList all available authentication methods
list_collectionsreadList all collections in PocketBase
list_recordsreadList records from a collection with optional filters
request_email_changereadRequest email change
request_password_resetdestructiveRequest password reset
request_verificationreadRequest email verification
update_collectionwriteUpdate an existing collection in PocketBase (admin only)
update_recordwriteUpdate an existing record
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (3 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (7)

MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
.env.example:2
# Example: http://127.0.0.1:8090 for local development
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
.env.example:3
POCKETBASE_URL=http://127.0.0.1:8090
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
Dockerfile:37
ENV POCKETBASE_URL=http://127.0.0.1:8090
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
confirm_password_reset, delete_collection, delete_record, request_password_reset
Why it matters. 4 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:27
"POCKETBASE_URL": "http://127.0.0.1:8090",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:73
"POCKETBASE_URL": "http://127.0.0.1:8090",
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, pocketbase, @types/node, dotenv, esbuild, typescript
Why it matters. 6 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 0c885b932434full audit observations/trust-audit/mcp-server/mrwyndham__pocketbase-2.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-070c885b932434CAUTIONB89first audit
06

Questions

What is the PocketBase MCP server?

MCP server for building PocketBase apps really quickly - Need a front end quick consider FastPocket

What tools does PocketBase expose?

24 in total: 13 read-only, 7 that write, and 4 that can delete or overwrite (confirm_password_reset, delete_collection, delete_record, request_password_reset). Every one is listed on this page with its risk.

Is PocketBase safe to connect to an agent?

With care. The audit graded it B (89/100) and found 7 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 4 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does PocketBase need?

It reads POCKETBASE_ADMIN_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does PocketBase run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as pocketbase-server at 0.1.0.

How current is this page?

The grade is for one exact copy of the source (0c885b932434), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement