Redis MCP setup: Docker, TLS and key permissions
Check one known test key before exploring more data. Verify permissions, data type and connection settings as separate steps.
The first Redis test is not about finding as many keys as possible. It should establish whether the connection can read the intended key from the right database. Prepare a harmless value in a test environment and record its name, data type and contents. Use a dedicated user for this first request. The following steps are a test plan for your environment, not a claim that your account has been tested.
Choose the connection and user
The official Redis MCP server supports local stdio startup. Its project documents the mcp/redis Docker image and environment variables for the host, port, username and password. TLS can be enabled through REDIS_SSL. Confirm which hostname and port your Redis environment actually provides before preparing the client configuration.
Complete VS Code example
This example targets a remote Redis host using TLS. Replace the hostname, port and username. Docker must already be running. Merge the configuration into .vscode/mcp.json; VS Code prompts for the password. The -i option keeps the stdio input channel open. Each environment variable is forwarded to the container without writing the password into the argument list.
{
"servers": {
"redis": {
"type": "stdio",
"command": "docker",
"args": [
"run",
"--rm",
"-i",
"-e",
"REDIS_HOST",
"-e",
"REDIS_PORT",
"-e",
"REDIS_USERNAME",
"-e",
"REDIS_PWD",
"-e",
"REDIS_SSL",
"mcp/redis"
],
"env": {
"REDIS_HOST": "YOUR_REDIS_HOST",
"REDIS_PORT": "6379",
"REDIS_USERNAME": "YOUR_READ_USER",
"REDIS_PWD": "${input:redis-password}",
"REDIS_SSL": "true"
}
}
},
"inputs": [
{
"id": "redis-password",
"type": "promptString",
"description": "Redis password",
"password": true
}
]
}
A Redis service running on your computer still needs a hostname reachable from inside the container. Container localhost refers to the container itself. The Docker guide explains that distinction. Match TLS settings to your actual environment instead of disabling certificate verification after an error. Record the working image version so later tests can use the same software.
Limit permissions at the database
Redis ACLs can restrict both commands and key patterns. Have a user prepared for the required test scope and check its effective permissions. Asking a client to perform only reads does not change those permissions. The read-only guide explains these separate layers. Reading one known test key should not require broad administrative access.
Record the complete test key and expected contents. Choose a value that will remain valid long enough to complete the check.
Start the MCP server and inspect its available tools. Choose a read operation matching the known data type.
Retrieve that exact key. Compare the output with your notes and record when the request was made.
For a missing key, check the database selection, spelling and expiry. Only expand the data scope after those checks.
Separate network, permissions and type errors
| Observation | Check |
|---|---|
| Connection fails | Host, port, container network and TLS. |
| NOPERM | User permissions for the command and key pattern. |
| WRONGTYPE | Key data type and selected operation. |
Use the database planner to prepare a limited first read. The Redis registry search lists more entries, but a name alone establishes neither the publisher nor suitable permissions. Compare each declared source with the linked vendor project before adopting a different configuration.
- Is Redis MCP read-only automatically?
- No. Limit the Redis user permissions. A written request to read data is not a technical access boundary.
- Why does localhost fail in the Docker example?
- Inside the container, localhost refers to that container. Use a hostname that can reach your Redis environment from there.
- What does WRONGTYPE mean?
- The chosen operation does not match the key data type. Check the type before changing connection settings.
- Why is a previously available key missing?
- Check database selection, spelling, permissions and expiry. A missing value by itself does not prove a connection failure.
Vendor documentation checked on 2 October 2026. No authenticated account test.
- Redis: MCP server
Show retrieval command
curl -s https://github.com/redis/mcp-redis - Redis: Access control lists
Show retrieval command
curl -s https://redis.io/docs/latest/operate/oss_and_stack/management/security/acl/