Atlas / MCP servers / qiskit / Qiskit Servers

Qiskit ServersSAFE

mcp/qiskit/qiskit-servers

A collection of MCP servers to allow LLMs to use the qiskit,qiskit-ibm-runtime library, qiskit-ibm-transpiler, qiskit-code-assistant service library and others

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
71 56r · 12w · 3d
Transport
stdio
License
Apache-2.0
Stars
40
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://github.com/Qiskit/mcp-servers/actions/workflows/test.yml) [](https://opensource.org/licenses/Apache-2.0) [](https://www.python.org/downloads/) [](https://github.com/astral-sh/ruff) [](http://mypy-lang.org/)

[](https://registry.modelcontextprotocol.io/?q=io.github.Qiskit%2Fqiskit-mcp-server) [](https://registry.modelcontextprotocol.io/?q=io.github.Qiskit%2Fqiskit-ibm-runtime-mcp-server) [](https://registry.modelcontextprotocol.io/?q=io.github.Qiskit%2Fqiskit-ibm-transpiler-mcp-server) [![qiskit-docs-mcp-server](https://img.shields.io/badge/dynamic/json?url=https%3A%2F%2Fregistry.modelcontextprotocol.io%2Fv0.1%2Fservers%2Fio.github.Qiskit%252Fqiskit-docs-mcp-server%2Fversions%2Flatest&query=%24.serve

Read from source at commit 7936efca1054OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (pypi)
claude mcp add qiskit-docs-mcp-server -- uvx qiskit-docs-mcp-server==0.3.0
03

Exposed tools (71)

56 read · 12 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
active_account_info_toolreadGet information about the currently active IBM Quantum account.
active_instance_info_toolreadGet the Cloud Resource Name (CRN) of the currently active instance.
ai_clifford_synthesis_toolreadAI-powered synthesis for Clifford circuits (H, S, and CX gate blocks, up to 9 qubits).
ai_linear_function_synthesis_toolreadAI-powered synthesis for Linear Function circuits (CX and SWAP gate blocks, up to 9 qubits).
ai_pauli_network_synthesis_toolreadAI-powered synthesis for Pauli Network circuits (H, S, SX, CX, RX, RY, RZ gate blocks, up to 6 qubits).
ai_permutation_synthesis_toolreadAI-powered synthesis for Permutation circuits (SWAP gate blocks, supports 27, 33, and 65 qubit blocks).
ai_routing_toolreadRoute a quantum circuit by inserting SWAP operations for backend compatibility. Use this FIRST before other synthesis tools.
analyze_circuit_toolreadAnalyze a quantum circuit without transpiling it.
available_instances_toolreadList all IBM Quantum instances available to the active account.
batch_train_environments_toolreadTrain multiple environments in sequence.
cancel_job_toolreadCancel a specific job.
compare_optimization_levels_toolreadCompare transpilation results across all optimization levels (0-3).
convert_qasm3_to_qpy_toolreadConvert a QASM3 (or QASM2) circuit to base64-encoded QPY format.
convert_qpy_to_qasm3_toolreadConvert a QPY circuit to human-readable QASM3 format.
create_clifford_env_toolwriteCreate a CliffordGym environment for learning Clifford circuit synthesis.
create_coupling_map_toolwriteCreate a custom coupling map.
create_linear_function_env_toolwriteCreate a LinearFunctionGym environment for learning CNOT synthesis.
create_permutation_env_toolwriteCreate a PermutationGym environment for learning qubit routing with SWAP gates.
delete_environment_tooldestructiveDelete an environment.
delete_model_tooldestructiveDelete a model.
delete_saved_account_tooldestructiveDelete a saved IBM Quantum account from disk.
export_circuit_to_qasm_toolreadExport a Qiskit circuit to OpenQASM format.
extract_subtopologies_toolreadExtract connected subtopologies of N qubits from a hardware preset.
find_optimal_qubit_chains_toolreadFind optimal linear qubit chains for quantum experiments.
find_optimal_qv_qubits_toolreadFind optimal qubit subgraphs for Quantum Volume experiments.
generate_random_clifford_toolreadGenerate a random Clifford element for testing.
generate_random_linear_function_toolreadGenerate a random invertible linear function for testing.
generate_random_permutation_toolreadGenerate a random permutation for testing synthesis.
get_backend_calibration_toolreadGet calibration data for a backend including T1, T2 times and error rates.
get_backend_properties_toolreadGet detailed properties of a specific backend.
get_coupling_map_toolreadGet the coupling map (qubit connectivity) for an IBM Quantum backend.
get_environment_info_toolreadGet detailed information about a specific environment.
get_fake_backend_coupling_map_toolreadGet the exact coupling map from a fake IBM backend (no credentials needed).
get_job_results_toolreadGet measurement results from a completed quantum job.
get_job_status_toolreadGet status of a specific job.
get_model_info_toolreadGet detailed information about a model.
get_page_toolreadFetch a Qiskit documentation page and return its content as markdown.
get_tensorboard_metrics_toolreadGet training metrics from TensorBoard logs for historical runs.
get_tensorboard_status_toolreadCheck the status of the TensorBoard process.
get_training_metrics_toolreadGet detailed training metrics from TensorBoard logs.
get_training_status_toolreadGet the status and metrics of a training session.
hybrid_ai_transpile_toolreadTranspile a circuit using a hybrid pass manager combining Qiskit heuristics with AI-powered passes.
least_busy_backend_toolreadFind the least busy operational backend.
list_available_fake_backends_toolreadList all available fake backends for offline topology access.
list_backends_toolreadList available IBM Quantum backends.
list_environments_toolreadList all active RL environments.
list_loaded_models_toolreadList all models currently loaded in memory.
list_my_jobs_toolreadList user
list_saved_accounts_toolreadList all IBM Quantum accounts saved on disk.
list_saved_models_toolreadList all models saved to disk.
list_subtopology_shapes_toolreadList available subtopology shapes for a given hardware and qubit count.
list_tensorboard_experiments_toolreadList available TensorBoard experiments from past training runs.
list_training_sessions_toolreadList all training sessions.
load_circuit_from_qasm_toolreadLoad a quantum circuit from an OpenQASM 2.0 or 3.0 string.
load_model_toolreadLoad a saved model from disk.
lookup_error_code_toolreadLook up a Qiskit or IBM Quantum error code to get its description and solution.
run_estimator_toolwriteRun a quantum circuit using the Qiskit Runtime EstimatorV2 primitive.
run_sampler_toolwriteRun a quantum circuit using the Qiskit Runtime SamplerV2 primitive.
save_model_toolwriteSave a trained model to disk.
search_docs_toolreadSearch across the entire Qiskit documentation for relevant content.
setup_ibm_quantum_account_toolwriteSet up IBM Quantum account with credentials.
start_tensorboard_toolwriteStart TensorBoard to visualize training metrics.
start_training_toolwriteStart training an RL agent on a created environment.
stop_tensorboard_toolwriteStop the running TensorBoard process.
stop_training_toolwriteStop a training session.
synthesize_clifford_toolreadSynthesize an optimal quantum circuit for a Clifford operation.
synthesize_linear_function_toolreadSynthesize an optimal quantum circuit for a linear Boolean function.
synthesize_permutation_toolreadSynthesize an optimal quantum circuit for a qubit permutation.
transpile_circuit_toolreadTranspile a quantum circuit using Qiskit
usage_info_toolreadGet usage statistics and quota information for the active instance.
wait_for_training_toolreadWait for a background training session to complete.
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (3 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (11)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_environment_tool, delete_model_tool, delete_saved_account_tool
Why it matters. 3 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
qiskit-mcp-server/src/qiskit_mcp_server/circuit_serialization.py:110
decoded = base64.b64decode(stripped)
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
qiskit-mcp-server/src/qiskit_mcp_server/circuit_serialization.py:192
buffer = io.BytesIO(base64.b64decode(qpy_b64))
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
qiskit-mcp-server/tests/test_circuit_serialization.py:162
decoded = base64.b64decode(qpy_str)
INFOInventory / provenance · inv.oversize · CWE-1104
docs/videos/QiskitMCPServers-ClaudeCode.mp4
docs/videos/QiskitMCPServers-ClaudeCode.mp4
Why it matters. 1046826 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
docs/videos/QiskitMCPServers-IBMBob.mp4
docs/videos/QiskitMCPServers-IBMBob.mp4
Why it matters. 14220603 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
uv.lock
uv.lock
Why it matters. 1019055 bytes not read
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
README.md:193
| **Qiskit IBM Runtime** | Full access to IBM Quantum hardware via [Qiskit IBM Runtime](https://github.com/Qiskit/qiskit-ibm-runtime/) | [`qiskit-ibm-runtime-mcp-server/`](./qiskit-ibm-runtime-mcp-ser
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
qiskit-ibm-runtime-mcp-server/README.md:214
# Load environment variables (QISKIT_IBM_TOKEN, OPENAI_API_KEY, etc.)
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
qiskit-ibm-transpiler-mcp-server/README.md:118
# Load environment variables (QISKIT_IBM_TOKEN, OPENAI_API_KEY, etc.)
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
qiskit-mcp-server/README.md:174
# Load environment variables (OPENAI_API_KEY, etc.)
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 7936efca1054full audit observations/trust-audit/mcp-server/qiskit__qiskit-servers.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-087936efca1054SAFEB89first audit
06

Questions

What is the Qiskit Servers MCP server?

A collection of MCP servers to allow LLMs to use the qiskit,qiskit-ibm-runtime library, qiskit-ibm-transpiler, qiskit-code-assistant service library and others

What tools does Qiskit Servers expose?

71 in total: 56 read-only, 12 that write, and 3 that can delete or overwrite (delete_environment_tool, delete_model_tool, delete_saved_account_tool). Every one is listed on this page with its risk.

Is Qiskit Servers safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Qiskit Servers need?

It reads OPENAI_COMPATIBLE_API_KEY and QISKIT_IBM_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Qiskit Servers run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as qiskit-mcp-server.

How current is this page?

The grade is for one exact copy of the source (7936efca1054), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement