Does IDA Pro have an MCP server?
IDA Pro does not maintain an official MCP server. Community-built servers exist.
No first-party Hex-Rays server — but the leading community server is listed on Hex-Rays' own plugin marketplace.
- Access
- Local server
- Repository
- mrexodia/ida-pro-mcp
- Maintainer
- Duncan Ogilvie
- License
- MIT
- Language
- Python
- Stars
- 11k
- Last commit
- 2d ago
- Category
- Developer Tools
AI-powered reverse engineering assistant that bridges IDA Pro with language models through MCP.
Project site: plugins.hex-rays.com
AI-powered reverse engineering assistant that bridges IDA Pro with language models through MCP.
Runs on your machine over stdio, launched by your MCP client.
Add it from the terminal, then restart your session:
claude mcp add idapro -- npx -y <package-from-readme>Swap in the exact package and flags from the repo README — most servers need an API key passed as an environment variable.
Add --scope user to make it available in every project.
Open Settings → Developer → Edit Config and add the server to claude_desktop_config.json:
{
"mcpServers": {
"idapro": {
"command": "npx",
"args": [
"-y",
"<package-from-readme>"
],
"env": {
"API_KEY": "…"
}
}
}
}Restart Claude Desktop after saving.
Add to .cursor/mcp.json in your project, or ~/.cursor/mcp.json for
every project:
{
"mcpServers": {
"idapro": {
"command": "npx",
"args": [
"-y",
"<package-from-readme>"
],
"env": {
"API_KEY": "…"
}
}
}
}A green dot in Settings → MCP means it connected.
Add to .vscode/mcp.json:
{
"servers": {
"idapro": {
"type": "stdio",
"command": "npx",
"args": [
"-y",
"<package-from-readme>"
]
}
}
}Then pick the server from the tools menu in Copilot's agent mode.
A community server is unaudited third-party code that will hold your IDA Pro API credentials and see whatever data they unlock. Independent research puts SSRF vulnerabilities in roughly a third of public MCP servers, and 41% ship with no authentication at all.
- Read the source before running it — especially any network calls it makes.
- Check who maintains it and whether commits are recent (this one: 2d ago).
- Issue a scoped, revocable API key rather than an account-wide token.
- Prefer read-only credentials until you trust it with writes.
Does IDA Pro have an official MCP server?
No. IDA Pro does not maintain one. Third-party developers have built community servers, the most established being mrexodia/ida-pro-mcp, but they are not endorsed or supported by IDA Pro.
How do I connect IDA Pro to Claude?
Run the server locally and register it in Claude's MCP config. In Claude Code that's a single "claude mcp add" command; in Claude Desktop you add it to claude_desktop_config.json.
Is it safe to use a community IDA Pro MCP server?
Treat it like any dependency that gets your API keys. Community MCP servers are unaudited third-party code: independent research has found roughly a third of public MCP servers carry SSRF vulnerabilities and 41% ship with no authentication. Read the source, check the maintainer and commit recency, and scope the credentials you hand it.
How is this verdict verified?
Hex-Rays ships no first-party MCP server; mrexodia/ida-pro-mcp (~11.2k stars, active) dominates and is featured on plugins.hex-rays.com. GitHub metadata is refreshed every six hours.
Hex-Rays ships no first-party MCP server; mrexodia/ida-pro-mcp (~11.2k stars, active) dominates and is featured on plugins.hex-rays.com.
- github data refreshed 2026-08-11, then every 6 hours
- vendor docs verified on 2026-08-10
Work at IDA Pro? The moment you ship an official server this page flips to Official — send us the link.