Atlas / MCP servers / redis / Redis

RedisCAUTION

mcp/redis/redis-2

The official Redis MCP Server is a natural language interface designed for agentic applications to manage and search data in Redis efficiently

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
55 29r · 16w · 10d
Transport
stdio
License
MIT
Stars
629
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://github.com/redis/mcp-redis/actions/workflows/ci.yml) [](https://pypi.org/project/redis-mcp-server/) [](https://www.python.org/downloads/) [](./LICENSE.txt) [](https://mseep.ai/app/70102150-efe0-4705-9f7d-87980109a279) [](https://hub.docker.com/r/mcp/redis) [](https://codecov.io/gh/redis/mcp-redis)

[](https://discord.gg/redis) [](https://www.twitch.tv/redisinc) [](https://www.youtube.com/redisinc) [](https://twitter.com/redisinc) [](https://stackoverflow.com/questions/tagged/mcp-redis)

Overview

The Redis MCP Server is a natural language interface designed for agentic applications to efficiently manage and search data in Redis. It integrates seamlessly with MCP (Model Content Protocol) clients, enabling AI-driven workflows to interact with structured and unstructured data in Redis. Using this MCP Server, you can ask questions like:

  • "Store the entire conversation in a stream"
Read from source at commit 4bea726ac02bOBSERVED · 2026-09-29
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (pypi)
claude mcp add redis-mcp-server -- None redis-mcp-server==$VERSION
claude-code (oci)
claude mcp add redis:latest -- docker run -i --rm docker.io/mcp/redis:latest:None
03

Exposed tools (55)

29 read · 16 write · 10 destructive. Blast radius: 10 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
client_listreadGet a list of connected clients to the Redis server.
create_vector_index_hashwrite
dbsizereadGet the number of keys stored in the Redis database
deletedestructiveDelete a Redis key.
expirewriteSet an expiration time for a Redis key.
getreadGet a Redis string value.
get_index_inforeadRetrieve schema and information about a specific Redis index using FT.INFO.
get_indexed_keys_numberreadRetrieve the number of indexed keys by the index
get_indexesreadList of indexes in the Redis database
get_vector_from_hashreadRetrieve a vector from a Redis hash and convert it back from binary blob.
hdeldestructiveDelete a field from a Redis hash.
hexistsreadCheck if a field exists in a Redis hash.
hgetreadGet the value of a field in a Redis hash.
hgetallreadGet all fields and values from a Redis hash.
hsetwriteSet a field in a hash stored at key with an optional expiration time.
hybrid_searchread
inforeadGet Redis server information and statistics.
json_deldestructiveDelete a JSON value from Redis at a given path.
json_getreadRetrieve a JSON value from Redis at a given path.
json_setwriteSet a JSON value in Redis at a given path with an optional expiration time.
llenreadGet the length of a Redis list.
lpopdestructiveRemove and return the first element from a Redis list.
lpushwritePush a value onto the left of a Redis list and optionally set an expiration time.
lrangereadGet elements from a Redis list within a specific range.
lremdestructiveRemove elements from a Redis list.
psubscribereadSubscribe to Redis channels using a pattern.
publishwritePublish a message to a Redis channel.
read_messagesreadRead pending pub/sub messages for an existing subscription.
renamewrite
rpopdestructiveRemove and return the last element from a Redis list.
rpushwritePush a value onto the right of a Redis list and optionally set an expiration time.
saddwriteAdd a value to a Redis set with an optional expiration time.
scan_all_keysread
scan_keysread
search_redis_documentsreadSearch Redis documentation and knowledge base to learn about Redis concepts and use cases.
setwriteSet a Redis string value with an optional expiration time.
set_vector_in_hashwriteStore a vector as a field in a Redis hash.
smemberswriteGet all members of a Redis set.
sremdestructiveRemove a value from a Redis set.
subscribereadSubscribe to a Redis channel and return a reusable subscription handle.
test_toolreadTest tool for decorator functionality.
test_tool_with_paramsreadTest tool with parameters.
typereadReturns the string representation of the type of the value stored at key
unsubscribereadUnsubscribe and close an existing pub/sub subscription.
vector_search_hashread
xackreadAcknowledge entries that were processed by a consumer group.
xaddwriteAdd an entry to a Redis stream with an optional expiration time.
xdeldestructiveDelete an entry from a Redis stream.
xgroup_createwriteCreate a consumer group for a Redis stream.
xgroup_destroydestructiveDestroy a consumer group for a Redis stream.
xrangereadRead entries from a Redis stream.
xreadgroupreadRead entries from a Redis stream using a consumer group.
zaddwriteAdd a member to a Redis sorted set with an optional expiration time.
zrangewriteRetrieve a range of members from a Redis sorted set.
zremdestructiveRemove a member from a Redis sorted set.
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (5 observation(s))
Shell
declared (1 observation(s))
Dependencies
pinned
Secrets in source
found

Findings (3)

MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
src/common/server.py:10
importlib.import_module(f"src.tools.{module_name}")
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
GEMINI.md:104
export REDIS_URL=redis://default:[email protected]:12345/0
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete, hdel, json_del, lpop, lrem, rpop, srem, xdel, xgroup_destroy, zrem
Why it matters. 10 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius

Gates applied: no_behavioural_pass.

Audited 2026-09-29 · audit v0.4.1 · source sha 4bea726ac02bfull audit observations/trust-audit/mcp-server/redis__redis-2.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-294bea726ac02bCAUTIONB89first audit
06

Questions

What is the Redis MCP server?

The official Redis MCP Server is a natural language interface designed for agentic applications to manage and search data in Redis efficiently

What tools does Redis expose?

55 in total: 29 read-only, 16 that write, and 10 that can delete or overwrite (delete, hdel, json_del, lpop, lrem). Every one is listed on this page with its risk.

Is Redis safe to connect to an agent?

With care. The audit graded it B (89/100) and found 3 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 10 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Redis need?

It reads REDIS_ENTRAID_AUTH_FLOW, REDIS_ENTRAID_CLIENT_SECRET, REDIS_ENTRAID_TOKEN_EXPIRATION_REFRESH_RATIO, REDIS_ENTRAID_TOKEN_REQUEST_EXECUTION_TIMEOUT_MS and REDIS_SSL_KEYFILE from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Redis run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as redis-mcp-server.

How current is this page?

The grade is for one exact copy of the source (4bea726ac02b), read on 2026-09-29. The repository is watched and re-audited when it changes.

Advertisement