Qiskit ServersSAFE
A collection of MCP servers to allow LLMs to use the qiskit,qiskit-ibm-runtime library, qiskit-ibm-transpiler, qiskit-code-assistant service library and others
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://github.com/Qiskit/mcp-servers/actions/workflows/test.yml) [](https://opensource.org/licenses/Apache-2.0) [](https://www.python.org/downloads/) [](https://github.com/astral-sh/ruff) [](http://mypy-lang.org/)
[](https://registry.modelcontextprotocol.io/?q=io.github.Qiskit%2Fqiskit-mcp-server) [](https://registry.modelcontextprotocol.io/?q=io.github.Qiskit%2Fqiskit-ibm-runtime-mcp-server) [](https://registry.modelcontextprotocol.io/?q=io.github.Qiskit%2Fqiskit-ibm-transpiler-mcp-server) [
56 read · 12 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
active_account_info_tool | read | Get information about the currently active IBM Quantum account. |
active_instance_info_tool | read | Get the Cloud Resource Name (CRN) of the currently active instance. |
ai_clifford_synthesis_tool | read | AI-powered synthesis for Clifford circuits (H, S, and CX gate blocks, up to 9 qubits). |
ai_linear_function_synthesis_tool | read | AI-powered synthesis for Linear Function circuits (CX and SWAP gate blocks, up to 9 qubits). |
ai_pauli_network_synthesis_tool | read | AI-powered synthesis for Pauli Network circuits (H, S, SX, CX, RX, RY, RZ gate blocks, up to 6 qubits). |
ai_permutation_synthesis_tool | read | AI-powered synthesis for Permutation circuits (SWAP gate blocks, supports 27, 33, and 65 qubit blocks). |
ai_routing_tool | read | Route a quantum circuit by inserting SWAP operations for backend compatibility. Use this FIRST before other synthesis tools. |
analyze_circuit_tool | read | Analyze a quantum circuit without transpiling it. |
available_instances_tool | read | List all IBM Quantum instances available to the active account. |
batch_train_environments_tool | read | Train multiple environments in sequence. |
cancel_job_tool | read | Cancel a specific job. |
compare_optimization_levels_tool | read | Compare transpilation results across all optimization levels (0-3). |
convert_qasm3_to_qpy_tool | read | Convert a QASM3 (or QASM2) circuit to base64-encoded QPY format. |
convert_qpy_to_qasm3_tool | read | Convert a QPY circuit to human-readable QASM3 format. |
create_clifford_env_tool | write | Create a CliffordGym environment for learning Clifford circuit synthesis. |
create_coupling_map_tool | write | Create a custom coupling map. |
create_linear_function_env_tool | write | Create a LinearFunctionGym environment for learning CNOT synthesis. |
create_permutation_env_tool | write | Create a PermutationGym environment for learning qubit routing with SWAP gates. |
delete_environment_tool | destructive | Delete an environment. |
delete_model_tool | destructive | Delete a model. |
delete_saved_account_tool | destructive | Delete a saved IBM Quantum account from disk. |
export_circuit_to_qasm_tool | read | Export a Qiskit circuit to OpenQASM format. |
extract_subtopologies_tool | read | Extract connected subtopologies of N qubits from a hardware preset. |
find_optimal_qubit_chains_tool | read | Find optimal linear qubit chains for quantum experiments. |
find_optimal_qv_qubits_tool | read | Find optimal qubit subgraphs for Quantum Volume experiments. |
generate_random_clifford_tool | read | Generate a random Clifford element for testing. |
generate_random_linear_function_tool | read | Generate a random invertible linear function for testing. |
generate_random_permutation_tool | read | Generate a random permutation for testing synthesis. |
get_backend_calibration_tool | read | Get calibration data for a backend including T1, T2 times and error rates. |
get_backend_properties_tool | read | Get detailed properties of a specific backend. |
get_coupling_map_tool | read | Get the coupling map (qubit connectivity) for an IBM Quantum backend. |
get_environment_info_tool | read | Get detailed information about a specific environment. |
get_fake_backend_coupling_map_tool | read | Get the exact coupling map from a fake IBM backend (no credentials needed). |
get_job_results_tool | read | Get measurement results from a completed quantum job. |
get_job_status_tool | read | Get status of a specific job. |
get_model_info_tool | read | Get detailed information about a model. |
get_page_tool | read | Fetch a Qiskit documentation page and return its content as markdown. |
get_tensorboard_metrics_tool | read | Get training metrics from TensorBoard logs for historical runs. |
get_tensorboard_status_tool | read | Check the status of the TensorBoard process. |
get_training_metrics_tool | read | Get detailed training metrics from TensorBoard logs. |
get_training_status_tool | read | Get the status and metrics of a training session. |
hybrid_ai_transpile_tool | read | Transpile a circuit using a hybrid pass manager combining Qiskit heuristics with AI-powered passes. |
least_busy_backend_tool | read | Find the least busy operational backend. |
list_available_fake_backends_tool | read | List all available fake backends for offline topology access. |
list_backends_tool | read | List available IBM Quantum backends. |
list_environments_tool | read | List all active RL environments. |
list_loaded_models_tool | read | List all models currently loaded in memory. |
list_my_jobs_tool | read | List user |
list_saved_accounts_tool | read | List all IBM Quantum accounts saved on disk. |
list_saved_models_tool | read | List all models saved to disk. |
list_subtopology_shapes_tool | read | List available subtopology shapes for a given hardware and qubit count. |
list_tensorboard_experiments_tool | read | List available TensorBoard experiments from past training runs. |
list_training_sessions_tool | read | List all training sessions. |
load_circuit_from_qasm_tool | read | Load a quantum circuit from an OpenQASM 2.0 or 3.0 string. |
load_model_tool | read | Load a saved model from disk. |
lookup_error_code_tool | read | Look up a Qiskit or IBM Quantum error code to get its description and solution. |
run_estimator_tool | write | Run a quantum circuit using the Qiskit Runtime EstimatorV2 primitive. |
run_sampler_tool | write | Run a quantum circuit using the Qiskit Runtime SamplerV2 primitive. |
save_model_tool | write | Save a trained model to disk. |
search_docs_tool | read | Search across the entire Qiskit documentation for relevant content. |
setup_ibm_quantum_account_tool | write | Set up IBM Quantum account with credentials. |
start_tensorboard_tool | write | Start TensorBoard to visualize training metrics. |
start_training_tool | write | Start training an RL agent on a created environment. |
stop_tensorboard_tool | write | Stop the running TensorBoard process. |
stop_training_tool | write | Stop a training session. |
synthesize_clifford_tool | read | Synthesize an optimal quantum circuit for a Clifford operation. |
synthesize_linear_function_tool | read | Synthesize an optimal quantum circuit for a linear Boolean function. |
synthesize_permutation_tool | read | Synthesize an optimal quantum circuit for a qubit permutation. |
transpile_circuit_tool | read | Transpile a quantum circuit using Qiskit |
usage_info_tool | read | Get usage statistics and quota information for the active instance. |
wait_for_training_tool | read | Wait for a background training session to complete. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (3 observation(s))
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (11)
delete_environment_tool, delete_model_tool, delete_saved_account_tool
decoded = base64.b64decode(stripped)
buffer = io.BytesIO(base64.b64decode(qpy_b64))
decoded = base64.b64decode(qpy_str)
docs/videos/QiskitMCPServers-ClaudeCode.mp4
docs/videos/QiskitMCPServers-IBMBob.mp4
uv.lock
| **Qiskit IBM Runtime** | Full access to IBM Quantum hardware via [Qiskit IBM Runtime](https://github.com/Qiskit/qiskit-ibm-runtime/) | [`qiskit-ibm-runtime-mcp-server/`](./qiskit-ibm-runtime-mcp-ser
# Load environment variables (QISKIT_IBM_TOKEN, OPENAI_API_KEY, etc.)
# Load environment variables (QISKIT_IBM_TOKEN, OPENAI_API_KEY, etc.)
# Load environment variables (OPENAI_API_KEY, etc.)
Gates applied: no_behavioural_pass.
7936efca1054full audit observations/trust-audit/mcp-server/qiskit__qiskit-servers.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 7936efca1054 | SAFE | B | 89 | first audit |
Questions
What is the Qiskit Servers MCP server?
A collection of MCP servers to allow LLMs to use the qiskit,qiskit-ibm-runtime library, qiskit-ibm-transpiler, qiskit-code-assistant service library and others
What tools does Qiskit Servers expose?
71 in total: 56 read-only, 12 that write, and 3 that can delete or overwrite (delete_environment_tool, delete_model_tool, delete_saved_account_tool). Every one is listed on this page with its risk.
Is Qiskit Servers safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Qiskit Servers need?
It reads OPENAI_COMPATIBLE_API_KEY and QISKIT_IBM_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Qiskit Servers run?
It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as qiskit-mcp-server.
How current is this page?
The grade is for one exact copy of the source (7936efca1054), read on 2026-10-08. The repository is watched and re-audited when it changes.