Atlas / MCP servers / vladimir-tutin / Plex

PlexBLOCK

mcp/vladimir-tutin/plex

MCP Server for Plex to allow LLMs to converse with Plex.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
55 38r · 12w · 5d
Transport
stdio
License
—
Stars
150
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A powerful Model-Context-Protocol (MCP) server for interacting with Plex Media Server. It provides a standardized JSON-based interface for automation, AI agents (like Claude), and custom integrations.

Features

  • Standardized API: Unified JSON responses for all Plex operations.
  • Multiple Transports: Supports both stdio and SSE (Server-Sent Events).
  • Comprehensive Control: Manage libraries, media, collections, playlists, clients, and users.
  • Remote Ready: Built-in OAuth 2.1 support for integration with remote AI platforms like Claude.ai.
  • Admin Tools: Access logs, monitor bandwidth, and run Butler tasks.

Installation

Option 1: Using uv (Recommended)

Run directly without installation:

uvx plex-mcp-server --transport stdio --plex-url http://your-server:32400 --plex-token your-token

Option 2: Install via pip

pip install plex-mcp-server

Option 3: Development / Source

git clone https://github.com/vladimir-tutin/plex-mcp-server.git
cd plex-mcp-server
pip install -e .

Configuration

Set your Plex server URL and Token using one of these methods:

1. Command Line Arguments

plex-mcp-server --plex-url "http://192.168.1.10:32400" --plex-token "ABC123XYZ"

2. Environment Variables (.env)

Create a .env file in the current directory or ~/.config/plex-mcp-server/.env:

PLEX_URL=http://localhost:32400
PLEX_TOKEN=your-authentication-token
MCP_OAUTH_ENABLED=false

or with OAuth Enabled

PLEX_URL=http://localhost:32400
PLEX_TOKEN=your-authentication-token
MCP_OAUTH_ENABLED=true
MCP_OAUTH_ISSUER=https://auth.example.com/application/o/plexmcp-oauth/
MCP_SERVER_URL=https://plexmcp.example.com

3. MCP Client Config

Example for Claude Desktop (%APPDATA%/Claude/claude_desktop_config.json):

{
"mcpServers": {
"plex": {
"command": "uvx",
"args": [
"plex-mcp-server",
"--transport",
"stdio
Read from source at commit b6cf27ea262eOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add plex-mcp-server --env MCP_OAUTH_ENABLED=${MCP_OAUTH_ENABLED} --env MCP_OAUTH_ISSUER=${MCP_OAUTH_ISSUER} --env MCP_OAUTH_JWKS_CACHE_TTL=${MCP_OAUTH_JWKS_CACHE_TTL} --env PLEX_TOKEN=${PLEX_TOKEN} -- uvx plex-mcp-server
claude-desktop
{
  "mcpServers": {
    "plex-mcp-server": {
      "command": "uvx",
      "args": [
        "plex-mcp-server"
      ],
      "env": {
        "MCP_OAUTH_ENABLED": "${MCP_OAUTH_ENABLED}",
        "MCP_OAUTH_ISSUER": "${MCP_OAUTH_ISSUER}",
        "MCP_OAUTH_JWKS_CACHE_TTL": "${MCP_OAUTH_JWKS_CACHE_TTL}",
        "PLEX_TOKEN": "${PLEX_TOKEN}"
      }
    }
  }
}
03

Exposed tools (55)

38 read · 12 write · 5 destructive. Blast radius: 5 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
client_control_playbackreadControl playback on a specified client.
client_get_detailsreadGet detailed information about a specific Plex client.
client_get_timelinesreadGet the current timeline information for a specific Plex client.
client_listreadList all available Plex clients including idle players.
client_navigatereadNavigate a Plex client interface.
client_set_streamswriteSet audio, subtitle, or video streams for current playback on a client.
client_start_playbackwriteStart playback of media on a specified client.
collection_add_towriteAdd items to an existing collection.
collection_createwriteCreate a new collection with specified items.
collection_deletedestructiveDelete a collection.
collection_editwriteComprehensively edit a collection
collection_listreadList all collections on the Plex server or in a specific library.
collection_remove_fromdestructiveRemove items from a collection.
library_get_contentsreadGet the filtered and paginated contents of a specific library.
library_get_detailsreadGet detailed information about a specific library, including folder paths and settings.
library_get_recently_addedreadGet recently added media across all libraries or in a specific library.
library_get_statsreadGet statistics for a specific library.
library_listreadList all available libraries on the Plex server.
library_refreshreadRefresh a specific library or all libraries.
library_scanreadScan a specific library or part of a library.
media_deletedestructiveDelete a media item from the Plex library.
media_edit_metadatawriteEdit metadata for a specific media item.
media_get_artworkreadGet images for a specific media item.
media_get_detailsreadGet detailed information about a specific media item using PlexAPI
media_list_available_artworkreadList all available artwork for a specific media item.
media_searchreadSearch for media across all libraries.
media_set_artworkwriteSet artwork for a specific media item.
playlist_add_towriteAdd items to a playlist.
playlist_copy_to_userreadCopy a playlist to another user account.
playlist_createwriteCreate a new playlist with specified items.
playlist_deletedestructiveDelete a playlist.
playlist_editwriteEdit a playlist
playlist_get_contentsreadGet the contents of a playlist.
playlist_listreadList all playlists on the Plex server.
playlist_remove_fromdestructiveRemove items from a playlist.
playlist_upload_posterwriteUpload a poster image for a playlist.
server_clean_bundlesreadClean unused media bundles.
server_empty_trashreadEmpty trash for a specific library or all libraries.
server_get_alertsreadGet real-time alerts from the Plex server by listening on a websocket.
server_get_bandwidthreadGet bandwidth statistics from the Plex server.
server_get_butler_tasksreadGet information about Plex Butler tasks.
server_get_current_resourcesreadGet resource usage information from the Plex server.
server_get_inforeadGet detailed information about the Plex server.
server_get_plex_logsreadGet Plex server logs.
server_optimize_databasereadOptimize the Plex database.
server_run_butler_taskwriteManually run a specific Plex Butler task now.
sessions_get_activereadGet information about current playback sessions, including IP addresses.
sessions_get_media_playback_historyreadGet playback history for a specific media item.
user_get_continue_watchingreadGet items the user has partially watched and can continue.
user_get_inforeadGet detailed information about a specific Plex user.
user_get_on_deckreadGet on deck (in progress) media for a specific user.
user_get_statisticsreadGet statistics about user watch activity over different time periods.
user_get_watch_historyreadGet recent watch history for a specific user.
user_list_all_usersreadList all users (owner, home users, and shared users) with their IDs and types.
user_search_usersreadSearch for users with names, usernames, or emails containing the search term, or list all users if no search term is provided.
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (7 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (6)

HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
modules/server.py:325
verify = False if base_url.startswith('https') else True
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
modules/server.py:474
verify = False if base_url.startswith('https') else True
Why it matters. certificate verification is disabled
Fix. leave verification on
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
plex_mcp_server.py:148
print(f"[OAuth] Token present: {bool(token)}")
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
collection_delete, collection_remove_from, media_delete, playlist_delete, playlist_remove_from
Why it matters. 5 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:42
plex-mcp-server --plex-url "http://192.168.1.10:32400" --plex-token "ABC123XYZ"

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-07 · audit v0.4.1 · source sha b6cf27ea262efull audit observations/trust-audit/mcp-server/vladimir-tutin__plex.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07b6cf27ea262eBLOCKD69first audit
06

Questions

What is the Plex MCP server?

MCP Server for Plex to allow LLMs to converse with Plex.

What tools does Plex expose?

55 in total: 38 read-only, 12 that write, and 5 that can delete or overwrite (collection_delete, collection_remove_from, media_delete, playlist_delete, playlist_remove_from). Every one is listed on this page with its risk.

Is Plex safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 5 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Plex need?

It reads MCP_OAUTH_ENABLED, MCP_OAUTH_ISSUER, MCP_OAUTH_JWKS_CACHE_TTL and PLEX_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Plex run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as plex-mcp-server.

How current is this page?

The grade is for one exact copy of the source (b6cf27ea262e), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement