RedisCAUTION
The official Redis MCP Server is a natural language interface designed for agentic applications to manage and search data in Redis efficiently
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://github.com/redis/mcp-redis/actions/workflows/ci.yml) [](https://pypi.org/project/redis-mcp-server/) [](https://www.python.org/downloads/) [](./LICENSE.txt) [](https://mseep.ai/app/70102150-efe0-4705-9f7d-87980109a279) [](https://hub.docker.com/r/mcp/redis) [](https://codecov.io/gh/redis/mcp-redis)
[](https://discord.gg/redis) [](https://www.twitch.tv/redisinc) [](https://www.youtube.com/redisinc) [](https://twitter.com/redisinc) [](https://stackoverflow.com/questions/tagged/mcp-redis)
Overview
The Redis MCP Server is a natural language interface designed for agentic applications to efficiently manage and search data in Redis. It integrates seamlessly with MCP (Model Content Protocol) clients, enabling AI-driven workflows to interact with structured and unstructured data in Redis. Using this MCP Server, you can ask questions like:
- "Store the entire conversation in a stream"
4bea726ac02bOBSERVED · 2026-09-29Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add redis-mcp-server -- None redis-mcp-server==$VERSION
claude mcp add redis:latest -- docker run -i --rm docker.io/mcp/redis:latest:None
Exposed tools (55)
29 read · 16 write · 10 destructive. Blast radius: 10 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
client_list | read | Get a list of connected clients to the Redis server. |
create_vector_index_hash | write | |
dbsize | read | Get the number of keys stored in the Redis database |
delete | destructive | Delete a Redis key. |
expire | write | Set an expiration time for a Redis key. |
get | read | Get a Redis string value. |
get_index_info | read | Retrieve schema and information about a specific Redis index using FT.INFO. |
get_indexed_keys_number | read | Retrieve the number of indexed keys by the index |
get_indexes | read | List of indexes in the Redis database |
get_vector_from_hash | read | Retrieve a vector from a Redis hash and convert it back from binary blob. |
hdel | destructive | Delete a field from a Redis hash. |
hexists | read | Check if a field exists in a Redis hash. |
hget | read | Get the value of a field in a Redis hash. |
hgetall | read | Get all fields and values from a Redis hash. |
hset | write | Set a field in a hash stored at key with an optional expiration time. |
hybrid_search | read | |
info | read | Get Redis server information and statistics. |
json_del | destructive | Delete a JSON value from Redis at a given path. |
json_get | read | Retrieve a JSON value from Redis at a given path. |
json_set | write | Set a JSON value in Redis at a given path with an optional expiration time. |
llen | read | Get the length of a Redis list. |
lpop | destructive | Remove and return the first element from a Redis list. |
lpush | write | Push a value onto the left of a Redis list and optionally set an expiration time. |
lrange | read | Get elements from a Redis list within a specific range. |
lrem | destructive | Remove elements from a Redis list. |
psubscribe | read | Subscribe to Redis channels using a pattern. |
publish | write | Publish a message to a Redis channel. |
read_messages | read | Read pending pub/sub messages for an existing subscription. |
rename | write | |
rpop | destructive | Remove and return the last element from a Redis list. |
rpush | write | Push a value onto the right of a Redis list and optionally set an expiration time. |
sadd | write | Add a value to a Redis set with an optional expiration time. |
scan_all_keys | read | |
scan_keys | read | |
search_redis_documents | read | Search Redis documentation and knowledge base to learn about Redis concepts and use cases. |
set | write | Set a Redis string value with an optional expiration time. |
set_vector_in_hash | write | Store a vector as a field in a Redis hash. |
smembers | write | Get all members of a Redis set. |
srem | destructive | Remove a value from a Redis set. |
subscribe | read | Subscribe to a Redis channel and return a reusable subscription handle. |
test_tool | read | Test tool for decorator functionality. |
test_tool_with_params | read | Test tool with parameters. |
type | read | Returns the string representation of the type of the value stored at key |
unsubscribe | read | Unsubscribe and close an existing pub/sub subscription. |
vector_search_hash | read | |
xack | read | Acknowledge entries that were processed by a consumer group. |
xadd | write | Add an entry to a Redis stream with an optional expiration time. |
xdel | destructive | Delete an entry from a Redis stream. |
xgroup_create | write | Create a consumer group for a Redis stream. |
xgroup_destroy | destructive | Destroy a consumer group for a Redis stream. |
xrange | read | Read entries from a Redis stream. |
xreadgroup | read | Read entries from a Redis stream using a consumer group. |
zadd | write | Add a member to a Redis sorted set with an optional expiration time. |
zrange | write | Retrieve a range of members from a Redis sorted set. |
zrem | destructive | Remove a member from a Redis sorted set. |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (5 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- pinned
- Secrets in source
- found
Findings (3)
importlib.import_module(f"src.tools.{module_name}")export REDIS_URL=redis://default:[email protected]:12345/0
delete, hdel, json_del, lpop, lrem, rpop, srem, xdel, xgroup_destroy, zrem
Gates applied: no_behavioural_pass.
4bea726ac02bfull audit observations/trust-audit/mcp-server/redis__redis-2.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-29 | 4bea726ac02b | CAUTION | B | 89 | first audit |
Questions
What is the Redis MCP server?
The official Redis MCP Server is a natural language interface designed for agentic applications to manage and search data in Redis efficiently
What tools does Redis expose?
55 in total: 29 read-only, 16 that write, and 10 that can delete or overwrite (delete, hdel, json_del, lpop, lrem). Every one is listed on this page with its risk.
Is Redis safe to connect to an agent?
With care. The audit graded it B (89/100) and found 3 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 10 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Redis need?
It reads REDIS_ENTRAID_AUTH_FLOW, REDIS_ENTRAID_CLIENT_SECRET, REDIS_ENTRAID_TOKEN_EXPIRATION_REFRESH_RATIO, REDIS_ENTRAID_TOKEN_REQUEST_EXECUTION_TIMEOUT_MS and REDIS_SSL_KEYFILE from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Redis run?
It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as redis-mcp-server.
How current is this page?
The grade is for one exact copy of the source (4bea726ac02b), read on 2026-09-29. The repository is watched and re-audited when it changes.