Skip to content

Blog

Elasticsearch MCP setup: Kibana, spaces and API keys

Use the documented Kibana endpoint. Check the space and index permissions before retrieving your first test record.

Published on · by tracevero · Reading time 3 minutes (571 words)

Before starting a new Elasticsearch connection, check which access path you are installing. Elastic has deprecated the older elastic/mcp-server-elasticsearch project, with only critical security updates planned. Its notice points to the Agent Builder MCP endpoint as the successor, available in Elastic 9.2.0 or later and Elasticsearch Serverless projects. Confirm which version and features your actual environment provides.

Select the Kibana host and space

The current endpoint uses /api/agent_builder/mcp on the Kibana host. For a custom space, insert /s/SPACE_NAME before that path. Copy the exact address from your environment’s tools interface. A space selects the context; it does not replace index permissions. An Elasticsearch cluster address is therefore not automatically the correct address for this MCP connection.

Connect VS Code with an API key

Replace YOUR_KIBANA_HOST and YOUR_SPACE. For the default space, omit /s/YOUR_SPACE. Add the example to .vscode/mcp.json. Use the encoded API key intended for the Authorization header. VS Code requests it through a password input. Keep that value out of published configuration excerpts and troubleshooting reports.

{
  "servers": {
    "elasticsearch": {
      "type": "http",
      "url": "https://YOUR_KIBANA_HOST/s/YOUR_SPACE/api/agent_builder/mcp",
      "headers": {
        "Authorization": "ApiKey ${input:elastic-api-key}"
      }
    }
  },
  "inputs": [
    {
      "id": "elastic-api-key",
      "type": "promptString",
      "description": "Elastic API key (encoded)",
      "password": true
    }
  ]
}

The API key needs suitable Kibana application privileges and access to the intended data. Elastic documents feature_agentBuilder.read among these requirements; without it, the endpoint can return 403. Have permissions limited to your space and required indices. The VS Code setup guide explains the local file structure. Use the permission planner to prepare the intended scope.

Retrieve one known record

Select the target and permissions first 1. Kibana Select space 2. API key Index permissions 3. Query Read test value
Suggested checks for your own environment.
  1. Prepare a test index with harmless data. Record its name, a unique field and an expected value. Verify that value directly in your environment first.

  2. Start the connection and inspect the available tools. Check the configured URL against the intended Kibana host and space.

  3. Search the prepared index explicitly. Limit the selected fields and result count so that comparison with your known value is straightforward.

  4. Record the result and time. Repeat the same check after changing the space, key or server version.

Distinguish 403 responses from empty results

Choose the next check
ObservationCheck
Endpoint returns 404Kibana host, path, space and available version.
Connection returns 403The key’s Kibana application privileges.
Connection succeeds, record is missingIndex access, index name, filters and expected value.

Do not widen the index scope simply because a result is empty. Compare the query with your prepared test first. An accessible endpoint alone does not confirm that your intended index is visible. The troubleshooting navigator helps isolate the failing step. Use the Elasticsearch registry search to inspect further entries and compare their sources with the access path you selected.

Should I install the older Docker server for a new setup?
Check the documented successor first. Elastic marks the older project as deprecated; this guide uses the Kibana endpoint.
Is the Elasticsearch URL also the MCP URL?
No. The MCP service described here runs on the Kibana host under the Agent Builder path.
Does a space automatically restrict all data access?
No. Also check the API key permissions for the required indices and applications.
Does this prove my account works?
No. The sources document the access path. You still need to run the proposed limited data read in your own environment.

Vendor documentation checked on 2 October 2026. No authenticated account test.

  1. Elastic: MCP server status
    Show retrieval commandcurl -s https://github.com/elastic/mcp-server-elasticsearch
  2. Elastic: Agent Builder MCP endpoint
    Show retrieval commandcurl -s https://www.elastic.co/docs/explore-analyze/ai-features/agent-builder/mcp-server
  3. Elastic: MCP API key authentication
    Show retrieval commandcurl -s https://www.elastic.co/docs/explore-analyze/ai-features/agent-builder/mcp-server-api-keys

Put it into practice

All posts

tracevero · https://tracevero.com/blog/elasticsearch-mcp-setup