---
bezeichner: "io.github.couchbase/mcp-server-couchbase"
art: "mcp_server"
slug: "io-github-couchbase-mcp-server-couchbase"
paketkoordinate: "pypi:couchbase-mcp-server"
status: "aktiv"
homepage: "https://mcp-server.couchbase.com/"
erhebungsstand: "2026-10-10T01:17:01.464Z"
namensraum: "io.github.couchbase"
registerseite: "https://tracevero.com/mcp/io-github-couchbase-mcp-server-couchbase"
abgerufen_am: "2026-10-10"
zugangsdaten_erforderlich: false
ausfuehrungsort: "lokal"
dateisystem_pfadargument: false
quelloffen_einsehbar: true
roh_beschreibung: "Couchbase MCP Server - Enable AI agents to connect to and interact with Couchbase clusters."
version: "1.0.1"
roh_umgebungsvariablen: "CB_CONNECTION_STRING, CB_USERNAME, CB_PASSWORD, CB_CA_CERT_PATH, CB_CLIENT_CERT_PATH, CB_CLIENT_KEY_PATH, CB_MCP_READ_ONLY_MODE, CB_MCP_TRANSPORT, CB_MCP_HOST, CB_MCP_PORT, CB_MCP_DISABLED_TOOLS, CB_MCP_CONFIRMATION_REQUIRED_TOOLS, CB_MCP_LOG_LEVEL, CB_MCP_LOG_SINKS, CB_MCP_LOG_FILE, CB_MCP_LOG_ROTATION_MAX_SIZE_MB, CB_MCP_LOG_MAX_BYTES, CB_MCP_LOG_ERROR_ROTATION_MAX_SIZE_MB, CB_MCP_LOG_WARNING_ROTATION_MAX_SIZE_MB, CB_MCP_LOG_INFO_ROTATION_MAX_SIZE_MB, CB_MCP_LOG_DEBUG_ROTATION_MAX_SIZE_MB, CB_MCP_LOG_RETENTION_BACKUP_COUNT, CB_MCP_LOG_ERROR_RETENTION_BACKUP_COUNT, CB_MCP_LOG_WARNING_RETENTION_BACKUP_COUNT, CB_MCP_LOG_INFO_RETENTION_BACKUP_COUNT, CB_MCP_LOG_DEBUG_RETENTION_BACKUP_COUNT, CB_MCP_OAUTH_JWT_JWKS_URI, CB_MCP_OAUTH_JWT_ISSUER, CB_MCP_OAUTH_JWT_AUDIENCE, CB_MCP_OAUTH_JWT_ALGORITHM, CB_MCP_OAUTH_MCP_BASE_URL, CB_MCP_OAUTH_SCOPE_READ_LABEL, CB_MCP_OAUTH_SCOPE_WRITE_LABEL, CB_CONNECTION_STRING, CB_USERNAME, CB_PASSWORD, CB_CA_CERT_PATH, CB_CLIENT_CERT_PATH, CB_CLIENT_KEY_PATH, CB_MCP_READ_ONLY_MODE, CB_MCP_TRANSPORT, CB_MCP_HOST, CB_MCP_PORT, CB_MCP_DISABLED_TOOLS, CB_MCP_CONFIRMATION_REQUIRED_TOOLS, CB_MCP_LOG_LEVEL, CB_MCP_LOG_SINKS, CB_MCP_LOG_FILE, CB_MCP_LOG_ROTATION_MAX_SIZE_MB, CB_MCP_LOG_MAX_BYTES, CB_MCP_LOG_ERROR_ROTATION_MAX_SIZE_MB, CB_MCP_LOG_WARNING_ROTATION_MAX_SIZE_MB, CB_MCP_LOG_INFO_ROTATION_MAX_SIZE_MB, CB_MCP_LOG_DEBUG_ROTATION_MAX_SIZE_MB, CB_MCP_LOG_RETENTION_BACKUP_COUNT, CB_MCP_LOG_ERROR_RETENTION_BACKUP_COUNT, CB_MCP_LOG_WARNING_RETENTION_BACKUP_COUNT, CB_MCP_LOG_INFO_RETENTION_BACKUP_COUNT, CB_MCP_LOG_DEBUG_RETENTION_BACKUP_COUNT, CB_MCP_OAUTH_JWT_JWKS_URI, CB_MCP_OAUTH_JWT_ISSUER, CB_MCP_OAUTH_JWT_AUDIENCE, CB_MCP_OAUTH_JWT_ALGORITHM, CB_MCP_OAUTH_MCP_BASE_URL, CB_MCP_OAUTH_SCOPE_READ_LABEL, CB_MCP_OAUTH_SCOPE_WRITE_LABEL"
roh_geheime_pflichtvariablen: ""
roh_transportarten: "stdio, stdio"
roh_pfadargumente: ""
roh_repository_url: "https://github.com/couchbase/mcp-server-couchbase"
roh_paketquellen: "oci, pypi"
roh_geheime_pflichtkopfzeilen: ""
roh_pfad_umgebungsvariablen: ""
roh_remote_adressen: ""
roh_remote_hosts: ""
roh_statusmeldung: ""
roh_veroeffentlicht_am: "2026-08-13"
roh_aktualisiert_am: "2026-08-13"
roh_schemafassung: "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json"
roh_bereitstellungsform: "paket"
roh_repository_quelle: "github"
roh_repository_unterordner: ""
roh_paketbezeichner: "couchbase-mcp-server, docker.io/couchbase/mcp-server:1.0.1"
roh_paketversionen: "1.0.1"
roh_laufzeithinweise: ""
roh_umgebungsformate: "boolean, number, string"
roh_umgebungsbeschreibungen: "CB_CA_CERT_PATH=Couchbase CA certificate path. Required for TLS authentication in non Capella clusters. · CB_CLIENT_CERT_PATH=Couchbase client certificate path. Required for mTLS authentication. · CB_CLIENT_KEY_PATH=Couchbase client key path. Required for mTLS authentication. · CB_CONNECTION_STRING=Couchbase connection string. Required for connecting to the cluster. · CB_MCP_CONFIRMATION_REQUIRED_TOOLS=Comma-separated tool names that require user confirmation before execution. Also accepts a file path containing one tool name per line. Requires the MCP client to support elicitation. · CB_MCP_DISABLED_TOOLS=Tools to disable. Accepts comma-separated tool names (e.g., 'tool_1,tool_2') or a file path containing one tool name per line. · CB_MCP_HOST=Host to run the MCP server on (default: 127.0.0.1). Used only for HTTP and SSE transport modes. · CB_MCP_LOG_DEBUG_RETENTION_BACKUP_COUNT=Rotated backups kept for the DEBUG log file. Overrides CB_MCP_LOG_RETENTION_BACKUP_COUNT for DEBUG; inherits it when unset. · CB_MCP_LOG_DEBUG_ROTATION_MAX_SIZE_MB=Rotation size in MB for the DEBUG log file. Overrides CB_MCP_LOG_ROTATION_MAX_SIZE_MB for DEBUG; inherits it when unset. 0 is invalid and falls back to the inherited global with a startup warning. · CB_MCP_LOG_ERROR_RETENTION_BACKUP_COUNT=Rotated backups kept for the ERROR log file. Overrides CB_MCP_LOG_RETENTION_BACKUP_COUNT for ERROR; inherits it when unset. · CB_MCP_LOG_ERROR_ROTATION_MAX_SIZE_MB=Rotation size in MB for the ERROR log file. Overrides CB_MCP_LOG_ROTATION_MAX_SIZE_MB for ERROR; inherits it when unset. 0 is invalid and falls back to the inherited global with a startup warning. · CB_MCP_LOG_FILE=Base path for the per-level log files. One rotating file is written per level (e.g. mcp_server.info.log, mcp_server.error.log). Only used when 'file' is in CB_MCP_LOG_SINKS. Default is mcp_server.log. · CB_MCP_LOG_INFO_RETENTION_BACKUP_COUNT=Rotated backups kept for the INFO log file. Overrides CB_MCP_LOG_RETENTION_BACKUP_COUNT for INFO; inherits it when unset. · CB_MCP_LOG_INFO_ROTATION_MAX_SIZE_MB=Rotation size in MB for the INFO log file. Overrides CB_MCP_LOG_ROTATION_MAX_SIZE_MB for INFO; inherits it when unset. 0 is invalid and falls back to the inherited global with a startup warning. · CB_MCP_LOG_LEVEL=Logging level for the MCP server. One of off, debug, info, warning, error. Use 'off' to disable logging entirely. Invalid values fall back to info. Default is info. · CB_MCP_LOG_MAX_BYTES=[DEPRECATED] Global rotation size in bytes; use CB_MCP_LOG_ROTATION_MAX_SIZE_MB (MB) instead. Still honored for backward compatibility but ignored when CB_MCP_LOG_ROTATION_MAX_SIZE_MB is also set. A value of 0 is invalid and falls back to the default with a startup warning. · CB_MCP_LOG_RETENTION_BACKUP_COUNT=Number of rotated backup files kept per-level log file, excluding the live file. Applies to every level unless overridden per level. Set to 0 to keep only the live file (still capped by the rotation size). Default is 1. · CB_MCP_LOG_ROTATION_MAX_SIZE_MB=Global maximum size in MB per-level log file before it rotates, inherited by every level unless overridden by a per-level CB_MCP_LOG_<LEVEL>_ROTATION_MAX_SIZE_MB. A value of 0 is invalid and falls back to the default (1 MB) with a startup warning. Default is 1 (1 MB). · CB_MCP_LOG_SINKS=Comma-separated list of log destinations. Allowed values: stderr, file. Include 'file' to write per-level log files; include 'stderr' to write to the console. Default is stderr. · CB_MCP_LOG_WARNING_RETENTION_BACKUP_COUNT=Rotated backups kept for the WARNING log file. Overrides CB_MCP_LOG_RETENTION_BACKUP_COUNT for WARNING; inherits it when unset. · CB_MCP_LOG_WARNING_ROTATION_MAX_SIZE_MB=Rotation size in MB for the WARNING log file. Overrides CB_MCP_LOG_ROTATION_MAX_SIZE_MB for WARNING; inherits it when unset. 0 is invalid and falls back to the inherited global with a startup warning. · CB_MCP_OAUTH_JWT_ALGORITHM=JWT signing algorithm. One of RS256/384/512, ES256/384/512, PS256/384/512. Default is RS256. · CB_MCP_OAUTH_JWT_AUDIENCE=Expected JWT 'aud' claim value. Required to enable OAuth. · CB_MCP_OAUTH_JWT_ISSUER=Expected JWT 'iss' claim value. Also advertised as the authorization server in Protected Resource Metadata when CB_MCP_OAUTH_MCP_BASE_URL is set. Required to enable OAuth. · CB_MCP_OAUTH_JWT_JWKS_URI=JWKS endpoint of the identity provider used to verify bearer JWT signatures. Required to enable OAuth, along with CB_MCP_OAUTH_JWT_ISSUER and CB_MCP_OAUTH_JWT_AUDIENCE. Only honored when CB_MCP_TRANSPORT=http. · CB_MCP_OAUTH_MCP_BASE_URL=Public base URL of this MCP server. When set, the server publishes RFC 9728 Protected Resource Metadata at <base_url>/.well-known/oauth-protected-resource/mcp so PRM-aware clients can discover the authorization server. Optional. · CB_MCP_OAUTH_SCOPE_READ_LABEL=Override the OAuth scope label the server treats as 'read' access; advertised in PRM and matched against the token's scope/scp claim. Use when your IdP cannot emit the canonical form. Default is couchbase-mcp:read. · CB_MCP_OAUTH_SCOPE_WRITE_LABEL=Override the OAuth scope label the server treats as 'write' access; same semantics as CB_MCP_OAUTH_SCOPE_READ_LABEL. Default is couchbase-mcp:write. · CB_MCP_PORT=Port to run the MCP server on (default: 8000). Used only for HTTP and SSE transport modes. · CB_MCP_READ_ONLY_MODE=Couchbase read only mode. Set to true to allow disable write operations across both KV and query. KV write tools are not loaded and SQL++ queries that modify data are blocked. Set to false to allow data modification queries and tools. · CB_MCP_READ_ONLY_MODE=Couchbase read only mode. Set to true to disable write operations across both KV and query. KV write tools are not loaded and SQL++ queries that modify data are blocked. Set to false to allow data modification queries and tools. · CB_MCP_TRANSPORT=Transport mode for the server (stdio, http or sse). Default is stdio · CB_PASSWORD=Couchbase database password. Required for basic authentication. · CB_USERNAME=Couchbase database username. Required for basic authentication."
roh_symbolformate: ""
roh_verbindungswege: "{\"packages\":[{\"registryType\":\"pypi\",\"identifier\":\"couchbase-mcp-server\",\"version\":\"1.0.1\",\"transport\":\"stdio\",\"environment\":[{\"name\":\"CB_CONNECTION_STRING\",\"description\":\"Couchbase connection string. Required for connecting to the cluster.\",\"format\":\"string\",\"required\":false,\"secret\":false},{\"name\":\"CB_USERNAME\",\"description\":\"Couchbase database username. Required for basic authentication.\",\"format\":\"string\",\"required\":false,\"secret\":false},{\"name\":\"CB_PASSWORD\",\"description\":\"Couchbase database password. Required for basic authentication.\",\"format\":\"string\",\"required\":false,\"secret\":true},{\"name\":\"CB_CA_CERT_PATH\",\"description\":\"Couchbase CA certificate path. Required for TLS authentication in non Capella clusters.\",\"format\":\"string\",\"required\":false,\"secret\":false},{\"name\":\"CB_CLIENT_CERT_PATH\",\"description\":\"Couchbase client certificate path. Required for mTLS authentication.\",\"format\":\"string\",\"required\":false,\"secret\":false},{\"name\":\"CB_CLIENT_KEY_PATH\",\"description\":\"Couchbase client key path. Required for mTLS authentication.\",\"format\":\"string\",\"required\":false,\"secret\":false},{\"name\":\"CB_MCP_READ_ONLY_MODE\",\"description\":\"Couchbase read only mode. Set to true to allow disable write operations across both KV and query. KV write tools are not loaded and SQL++ queries that modify data are blocked. Set to false to allow data modification queries and tools.\",\"format\":\"boolean\",\"required\":false,\"secret\":false},{\"name\":\"CB_MCP_TRANSPORT\",\"description\":\"Transport mode for the server (stdio, http or sse). Default is stdio\",\"format\":\"string\",\"required\":false,\"secret\":false},{\"name\":\"CB_MCP_HOST\",\"description\":\"Host to run the MCP server on (default: 127.0.0.1). Used only for HTTP and SSE transport modes.\",\"format\":\"string\",\"required\":false,\"secret\":false},{\"name\":\"CB_MCP_PORT\",\"description\":\"Port to run the MCP server on (default: 8000). Used only for HTTP and SSE transport modes.\",\"format\":\"number\",\"required\":false,\"secret\":false},{\"name\":\"CB_MCP_DISABLED_TOOLS\",\"description\":\"Tools to disable. Accepts comma-separated tool names (e.g., 'tool_1,tool_2') or a file path containing one tool name per line.\",\"format\":\"string\",\"required\":false,\"secret\":false},{\"name\":\"CB_MCP_CONFIRMATION_REQUIRED_TOOLS\",\"description\":\"Comma-separated tool names that require user confirmation before execution. Also accepts a file path containing one tool name per line. Requires the MCP client to support elicitation.\",\"format\":\"string\",\"required\":false,\"secret\":false},{\"name\":\"CB_MCP_LOG_LEVEL\",\"description\":\"Logging level for the MCP server. One of off, debug, info, warning, error. Use 'off' to disable logging entirely. Invalid values fall back to info. Default is info.\",\"format\":\"string\",\"required\":false,\"secret\":false},{\"name\":\"CB_MCP_LOG_SINKS\",\"description\":\"Comma-separated list of log destinations. Allowed values: stderr, file. Include 'file' to write per-level log files; include 'stderr' to write to the console. Default is stderr.\",\"format\":\"string\",\"required\":false,\"secret\":false},{\"name\":\"CB_MCP_LOG_FILE\",\"description\":\"Base path for the per-level log files. One rotating file is written per level (e.g. mcp_server.info.log, mcp_server.error.log). Only used when 'file' is in CB_MCP_LOG_SINKS. Default is mcp_server.log.\",\"format\":\"string\",\"required\":false,\"secret\":false},{\"name\":\"CB_MCP_LOG_ROTATION_MAX_SIZE_MB\",\"description\":\"Global maximum size in MB per-level log file before it rotates, inherited by every level unless overridden by a per-level CB_MCP_LOG_<LEVEL>_ROTATION_MAX_SIZE_MB. A value of 0 is invalid and falls back to the default (1 MB) with a startup warning. Default is 1 (1 MB).\",\"format\":\"number\",\"required\":false,\"secret\":false},{\"name\":\"CB_MCP_LOG_MAX_BYTES\",\"description\":\"[DEPRECATED] Global rotation size in bytes; use CB_MCP_LOG_ROTATION_MAX_SIZE_MB (MB) instead. Still honored for backward compatibility but ignored when CB_MCP_LOG_ROTATION_MAX_SIZE_MB is also set. A value of 0 is invalid and falls back to the default with a startup warning.\",\"format\":\"number\",\"required\":false,\"secret\":false},{\"name\":\"CB_MCP_LOG_ERROR_ROTATION_MAX_SIZE_MB\",\"description\":\"Rotation size in MB for the ERROR log file. Overrides CB_MCP_LOG_ROTATION_MAX_SIZE_MB for ERROR; inherits it when unset. 0 is invalid and falls back to the inherited global with a startup warning.\",\"format\":\"number\",\"required\":false,\"secret\":false},{\"name\":\"CB_MCP_LOG_WARNING_ROTATION_MAX_SIZE_MB\",\"description\":\"Rotation size in MB for the WARNING log file. Overrides CB_MCP_LOG_ROTATION_MAX_SIZE_MB for WARNING; inherits it when unset. 0 is invalid and falls back to the inherited global with a startup warning.\",\"format\":\"number\",\"required\":false,\"secret\":false},{\"name\":\"CB_MCP_LOG_INFO_ROTATION_MAX_SIZE_MB\",\"description\":\"Rotation size in MB for the INFO log file. Overrides CB_MCP_LOG_ROTATION_MAX_SIZE_MB for INFO; inherits it when unset. 0 is invalid and falls back to the inherited global with a startup warning.\",\"format\":\"number\",\"required\":false,\"secret\":false},{\"name\":\"CB_MCP_LOG_DEBUG_ROTATION_MAX_SIZE_MB\",\"description\":\"Rotation size in MB for the DEBUG log file. Overrides CB_MCP_LOG_ROTATION_MAX_SIZE_MB for DEBUG; inherits it when unset. 0 is invalid and falls back to the inherited global with a startup warning.\",\"format\":\"number\",\"required\":false,\"secret\":false},{\"name\":\"CB_MCP_LOG_RETENTION_BACKUP_COUNT\",\"description\":\"Number of rotated backup files kept per-level log file, excluding the live file. Applies to every level unless overridden per level. Set to 0 to keep only the live file (still capped by the rotation size). Default is 1.\",\"format\":\"number\",\"required\":false,\"secret\":false},{\"name\":\"CB_MCP_LOG_ERROR_RETENTION_BACKUP_COUNT\",\"description\":\"Rotated backups kept for the ERROR log file. Overrides CB_MCP_LOG_RETENTION_BACKUP_COUNT for ERROR; inherits it when unset.\",\"format\":\"number\",\"required\":false,\"secret\":false},{\"name\":\"CB_MCP_LOG_WARNING_RETENTION_BACKUP_COUNT\",\"description\":\"Rotated backups kept for the WARNING log file. Overrides CB_MCP_LOG_RETENTION_BACKUP_COUNT for WARNING; inherits it when unset.\",\"format\":\"number\",\"required\":false,\"secret\":false},{\"name\":\"CB_MCP_LOG_INFO_RETENTION_BACKUP_COUNT\",\"description\":\"Rotated backups kept for the INFO log file. Overrides CB_MCP_LOG_RETENTION_BACKUP_COUNT for INFO; inherits it when unset.\",\"format\":\"number\",\"required\":false,\"secret\":false},{\"name\":\"CB_MCP_LOG_DEBUG_RETENTION_BACKUP_COUNT\",\"description\":\"Rotated backups kept for the DEBUG log file. Overrides CB_MCP_LOG_RETENTION_BACKUP_COUNT for DEBUG; inherits it when unset.\",\"format\":\"number\",\"required\":false,\"secret\":false},{\"name\":\"CB_MCP_OAUTH_JWT_JWKS_URI\",\"description\":\"JWKS endpoint of the identity provider used to verify bearer JWT signatures. Required to enable OAuth, along with CB_MCP_OAUTH_JWT_ISSUER and CB_MCP_OAUTH_JWT_AUDIENCE. Only honored when CB_MCP_TRANSPORT=http.\",\"format\":\"string\",\"required\":false,\"secret\":false},{\"name\":\"CB_MCP_OAUTH_JWT_ISSUER\",\"description\":\"Expected JWT 'iss' claim value. Also advertised as the authorization server in Protected Resource Metadata when CB_MCP_OAUTH_MCP_BASE_URL is set. Required to enable OAuth.\",\"format\":\"string\",\"required\":false,\"secret\":false},{\"name\":\"CB_MCP_OAUTH_JWT_AUDIENCE\",\"description\":\"Expected JWT 'aud' claim value. Required to enable OAuth.\",\"format\":\"string\",\"required\":false,\"secret\":false},{\"name\":\"CB_MCP_OAUTH_JWT_ALGORITHM\",\"description\":\"JWT signing algorithm. One of RS256/384/512, ES256/384/512, PS256/384/512. Default is RS256.\",\"format\":\"string\",\"required\":false,\"secret\":false},{\"name\":\"CB_MCP_OAUTH_MCP_BASE_URL\",\"description\":\"Public base URL of this MCP server. When set, the server publishes RFC 9728 Protected Resource Metadata at <base_url>/.well-known/oauth-protected-resource/mcp so PRM-aware clients can discover the authorization server. Optional.\",\"format\":\"string\",\"required\":false,\"secret\":false},{\"name\":\"CB_MCP_OAUTH_SCOPE_READ_LABEL\",\"description\":\"Override the OAuth scope label the server treats as 'read' access; advertised in PRM and matched against the token's scope/scp claim. Use when your IdP cannot emit the canonical form. Default is couchbase-mcp:read.\",\"format\":\"string\",\"required\":false,\"secret\":false},{\"name\":\"CB_MCP_OAUTH_SCOPE_WRITE_LABEL\",\"description\":\"Override the OAuth scope label the server treats as 'write' access; same semantics as CB_MCP_OAUTH_SCOPE_READ_LABEL. Default is couchbase-mcp:write.\",\"format\":\"string\",\"required\":false,\"secret\":false}],\"additional_arguments_declared\":true},{\"registryType\":\"oci\",\"identifier\":\"docker.io/couchbase/mcp-server:1.0.1\",\"transport\":\"stdio\",\"environment\":[{\"name\":\"CB_CONNECTION_STRING\",\"description\":\"Couchbase connection string. Required for connecting to the cluster.\",\"format\":\"string\",\"required\":false,\"secret\":false},{\"name\":\"CB_USERNAME\",\"description\":\"Couchbase database username. Required for basic authentication.\",\"format\":\"string\",\"required\":false,\"secret\":false},{\"name\":\"CB_PASSWORD\",\"description\":\"Couchbase database password. Required for basic authentication.\",\"format\":\"string\",\"required\":false,\"secret\":true},{\"name\":\"CB_CA_CERT_PATH\",\"description\":\"Couchbase CA certificate path. Required for TLS authentication in non Capella clusters.\",\"format\":\"string\",\"required\":false,\"secret\":false},{\"name\":\"CB_CLIENT_CERT_PATH\",\"description\":\"Couchbase client certificate path. Required for mTLS authentication.\",\"format\":\"string\",\"required\":false,\"secret\":false},{\"name\":\"CB_CLIENT_KEY_PATH\",\"description\":\"Couchbase client key path. Required for mTLS authentication.\",\"format\":\"string\",\"required\":false,\"secret\":false},{\"name\":\"CB_MCP_READ_ONLY_MODE\",\"description\":\"Couchbase read only mode. Set to true to disable write operations across both KV and query. KV write tools are not loaded and SQL++ queries that modify data are blocked. Set to false to allow data modification queries and tools.\",\"format\":\"boolean\",\"required\":false,\"secret\":false},{\"name\":\"CB_MCP_TRANSPORT\",\"description\":\"Transport mode for the server (stdio, http or sse). Default is stdio\",\"format\":\"string\",\"required\":false,\"secret\":false},{\"name\":\"CB_MCP_HOST\",\"description\":\"Host to run the MCP server on (default: 127.0.0.1). Used only for HTTP and SSE transport modes.\",\"format\":\"string\",\"required\":false,\"secret\":false},{\"name\":\"CB_MCP_PORT\",\"description\":\"Port to run the MCP server on (default: 8000). Used only for HTTP and SSE transport modes.\",\"format\":\"number\",\"required\":false,\"secret\":false},{\"name\":\"CB_MCP_DISABLED_TOOLS\",\"description\":\"Tools to disable. Accepts comma-separated tool names (e.g., 'tool_1,tool_2') or a file path containing one tool name per line.\",\"format\":\"string\",\"required\":false,\"secret\":false},{\"name\":\"CB_MCP_CONFIRMATION_REQUIRED_TOOLS\",\"description\":\"Comma-separated tool names that require user confirmation before execution. Also accepts a file path containing one tool name per line. Requires the MCP client to support elicitation.\",\"format\":\"string\",\"required\":false,\"secret\":false},{\"name\":\"CB_MCP_LOG_LEVEL\",\"description\":\"Logging level for the MCP server. One of off, debug, info, warning, error. Use 'off' to disable logging entirely. Invalid values fall back to info. Default is info.\",\"format\":\"string\",\"required\":false,\"secret\":false},{\"name\":\"CB_MCP_LOG_SINKS\",\"description\":\"Comma-separated list of log destinations. Allowed values: stderr, file. Include 'file' to write per-level log files; include 'stderr' to write to the console. Default is stderr.\",\"format\":\"string\",\"required\":false,\"secret\":false},{\"name\":\"CB_MCP_LOG_FILE\",\"description\":\"Base path for the per-level log files. One rotating file is written per level (e.g. mcp_server.info.log, mcp_server.error.log). Only used when 'file' is in CB_MCP_LOG_SINKS. Default is mcp_server.log.\",\"format\":\"string\",\"required\":false,\"secret\":false},{\"name\":\"CB_MCP_LOG_ROTATION_MAX_SIZE_MB\",\"description\":\"Global maximum size in MB per-level log file before it rotates, inherited by every level unless overridden by a per-level CB_MCP_LOG_<LEVEL>_ROTATION_MAX_SIZE_MB. A value of 0 is invalid and falls back to the default (1 MB) with a startup warning. Default is 1 (1 MB).\",\"format\":\"number\",\"required\":false,\"secret\":false},{\"name\":\"CB_MCP_LOG_MAX_BYTES\",\"description\":\"[DEPRECATED] Global rotation size in bytes; use CB_MCP_LOG_ROTATION_MAX_SIZE_MB (MB) instead. Still honored for backward compatibility but ignored when CB_MCP_LOG_ROTATION_MAX_SIZE_MB is also set. A value of 0 is invalid and falls back to the default with a startup warning.\",\"format\":\"number\",\"required\":false,\"secret\":false},{\"name\":\"CB_MCP_LOG_ERROR_ROTATION_MAX_SIZE_MB\",\"description\":\"Rotation size in MB for the ERROR log file. Overrides CB_MCP_LOG_ROTATION_MAX_SIZE_MB for ERROR; inherits it when unset. 0 is invalid and falls back to the inherited global with a startup warning.\",\"format\":\"number\",\"required\":false,\"secret\":false},{\"name\":\"CB_MCP_LOG_WARNING_ROTATION_MAX_SIZE_MB\",\"description\":\"Rotation size in MB for the WARNING log file. Overrides CB_MCP_LOG_ROTATION_MAX_SIZE_MB for WARNING; inherits it when unset. 0 is invalid and falls back to the inherited global with a startup warning.\",\"format\":\"number\",\"required\":false,\"secret\":false},{\"name\":\"CB_MCP_LOG_INFO_ROTATION_MAX_SIZE_MB\",\"description\":\"Rotation size in MB for the INFO log file. Overrides CB_MCP_LOG_ROTATION_MAX_SIZE_MB for INFO; inherits it when unset. 0 is invalid and falls back to the inherited global with a startup warning.\",\"format\":\"number\",\"required\":false,\"secret\":false},{\"name\":\"CB_MCP_LOG_DEBUG_ROTATION_MAX_SIZE_MB\",\"description\":\"Rotation size in MB for the DEBUG log file. Overrides CB_MCP_LOG_ROTATION_MAX_SIZE_MB for DEBUG; inherits it when unset. 0 is invalid and falls back to the inherited global with a startup warning.\",\"format\":\"number\",\"required\":false,\"secret\":false},{\"name\":\"CB_MCP_LOG_RETENTION_BACKUP_COUNT\",\"description\":\"Number of rotated backup files kept per-level log file, excluding the live file. Applies to every level unless overridden per level. Set to 0 to keep only the live file (still capped by the rotation size). Default is 1.\",\"format\":\"number\",\"required\":false,\"secret\":false},{\"name\":\"CB_MCP_LOG_ERROR_RETENTION_BACKUP_COUNT\",\"description\":\"Rotated backups kept for the ERROR log file. Overrides CB_MCP_LOG_RETENTION_BACKUP_COUNT for ERROR; inherits it when unset.\",\"format\":\"number\",\"required\":false,\"secret\":false},{\"name\":\"CB_MCP_LOG_WARNING_RETENTION_BACKUP_COUNT\",\"description\":\"Rotated backups kept for the WARNING log file. Overrides CB_MCP_LOG_RETENTION_BACKUP_COUNT for WARNING; inherits it when unset.\",\"format\":\"number\",\"required\":false,\"secret\":false},{\"name\":\"CB_MCP_LOG_INFO_RETENTION_BACKUP_COUNT\",\"description\":\"Rotated backups kept for the INFO log file. Overrides CB_MCP_LOG_RETENTION_BACKUP_COUNT for INFO; inherits it when unset.\",\"format\":\"number\",\"required\":false,\"secret\":false},{\"name\":\"CB_MCP_LOG_DEBUG_RETENTION_BACKUP_COUNT\",\"description\":\"Rotated backups kept for the DEBUG log file. Overrides CB_MCP_LOG_RETENTION_BACKUP_COUNT for DEBUG; inherits it when unset.\",\"format\":\"number\",\"required\":false,\"secret\":false},{\"name\":\"CB_MCP_OAUTH_JWT_JWKS_URI\",\"description\":\"JWKS endpoint of the identity provider used to verify bearer JWT signatures. Required to enable OAuth, along with CB_MCP_OAUTH_JWT_ISSUER and CB_MCP_OAUTH_JWT_AUDIENCE. Only honored when CB_MCP_TRANSPORT=http.\",\"format\":\"string\",\"required\":false,\"secret\":false},{\"name\":\"CB_MCP_OAUTH_JWT_ISSUER\",\"description\":\"Expected JWT 'iss' claim value. Also advertised as the authorization server in Protected Resource Metadata when CB_MCP_OAUTH_MCP_BASE_URL is set. Required to enable OAuth.\",\"format\":\"string\",\"required\":false,\"secret\":false},{\"name\":\"CB_MCP_OAUTH_JWT_AUDIENCE\",\"description\":\"Expected JWT 'aud' claim value. Required to enable OAuth.\",\"format\":\"string\",\"required\":false,\"secret\":false},{\"name\":\"CB_MCP_OAUTH_JWT_ALGORITHM\",\"description\":\"JWT signing algorithm. One of RS256/384/512, ES256/384/512, PS256/384/512. Default is RS256.\",\"format\":\"string\",\"required\":false,\"secret\":false},{\"name\":\"CB_MCP_OAUTH_MCP_BASE_URL\",\"description\":\"Public base URL of this MCP server. When set, the server publishes RFC 9728 Protected Resource Metadata at <base_url>/.well-known/oauth-protected-resource/mcp so PRM-aware clients can discover the authorization server. Optional.\",\"format\":\"string\",\"required\":false,\"secret\":false},{\"name\":\"CB_MCP_OAUTH_SCOPE_READ_LABEL\",\"description\":\"Override the OAuth scope label the server treats as 'read' access; advertised in PRM and matched against the token's scope/scp claim. Use when your IdP cannot emit the canonical form. Default is couchbase-mcp:read.\",\"format\":\"string\",\"required\":false,\"secret\":false},{\"name\":\"CB_MCP_OAUTH_SCOPE_WRITE_LABEL\",\"description\":\"Override the OAuth scope label the server treats as 'write' access; same semantics as CB_MCP_OAUTH_SCOPE_READ_LABEL. Default is couchbase-mcp:write.\",\"format\":\"string\",\"required\":false,\"secret\":false}],\"additional_arguments_declared\":false}],\"remotes\":[]}"
---

# io.github.couchbase/mcp-server-couchbase

## Measured values

| Property | Value | Source | Collected on | Level of trust | Raw declaration |
| --- | --- | --- | --- | --- | --- |
| Required secrets declared | false | MCP-Register | 2026-08-06T13:57:41.838Z | abgeleitet | roh_geheime_pflichtvariablen: ; roh_geheime_pflichtkopfzeilen: |
| Execution location | lokal | MCP-Register | 2026-08-06T13:57:41.838Z | abgeleitet | roh_transportarten: stdio, stdio |
| Path argument present | false | MCP-Register | 2026-08-06T13:57:41.838Z | abgeleitet | roh_pfadargumente: ; roh_pfad_umgebungsvariablen: |
| Repository URL listed | true | MCP-Register | 2026-08-06T13:57:41.838Z | abgeleitet | roh_repository_url: https://github.com/couchbase/mcp-server-couchbase |
| Description (raw) | Couchbase MCP Server - Enable AI agents to connect to and interact with Couchbase clusters. | MCP-Register | 2026-08-26T16:45:01.514Z | selbstauskunft |  |
| Declared version | 1.0.1 | MCP-Register | 2026-08-14T01:17:01.879Z | selbstauskunft |  |
| Environment variables (raw) | CB_CONNECTION_STRING, CB_USERNAME, CB_PASSWORD, CB_CA_CERT_PATH, CB_CLIENT_CERT_PATH, CB_CLIENT_KEY_PATH, CB_MCP_READ_ONLY_MODE, CB_MCP_TRANSPORT, CB_MCP_HOST, CB_MCP_PORT, CB_MCP_DISABLED_TOOLS, CB_MCP_CONFIRMATION_REQUIRED_TOOLS, CB_MCP_LOG_LEVEL, CB_MCP_LOG_SINKS, CB_MCP_LOG_FILE, CB_MCP_LOG_ROTATION_MAX_SIZE_MB, CB_MCP_LOG_MAX_BYTES, CB_MCP_LOG_ERROR_ROTATION_MAX_SIZE_MB, CB_MCP_LOG_WARNING_ROTATION_MAX_SIZE_MB, CB_MCP_LOG_INFO_ROTATION_MAX_SIZE_MB, CB_MCP_LOG_DEBUG_ROTATION_MAX_SIZE_MB, CB_MCP_LOG_RETENTION_BACKUP_COUNT, CB_MCP_LOG_ERROR_RETENTION_BACKUP_COUNT, CB_MCP_LOG_WARNING_RETENTION_BACKUP_COUNT, CB_MCP_LOG_INFO_RETENTION_BACKUP_COUNT, CB_MCP_LOG_DEBUG_RETENTION_BACKUP_COUNT, CB_MCP_OAUTH_JWT_JWKS_URI, CB_MCP_OAUTH_JWT_ISSUER, CB_MCP_OAUTH_JWT_AUDIENCE, CB_MCP_OAUTH_JWT_ALGORITHM, CB_MCP_OAUTH_MCP_BASE_URL, CB_MCP_OAUTH_SCOPE_READ_LABEL, CB_MCP_OAUTH_SCOPE_WRITE_LABEL, CB_CONNECTION_STRING, CB_USERNAME, CB_PASSWORD, CB_CA_CERT_PATH, CB_CLIENT_CERT_PATH, CB_CLIENT_KEY_PATH, CB_MCP_READ_ONLY_MODE, CB_MCP_TRANSPORT, CB_MCP_HOST, CB_MCP_PORT, CB_MCP_DISABLED_TOOLS, CB_MCP_CONFIRMATION_REQUIRED_TOOLS, CB_MCP_LOG_LEVEL, CB_MCP_LOG_SINKS, CB_MCP_LOG_FILE, CB_MCP_LOG_ROTATION_MAX_SIZE_MB, CB_MCP_LOG_MAX_BYTES, CB_MCP_LOG_ERROR_ROTATION_MAX_SIZE_MB, CB_MCP_LOG_WARNING_ROTATION_MAX_SIZE_MB, CB_MCP_LOG_INFO_ROTATION_MAX_SIZE_MB, CB_MCP_LOG_DEBUG_ROTATION_MAX_SIZE_MB, CB_MCP_LOG_RETENTION_BACKUP_COUNT, CB_MCP_LOG_ERROR_RETENTION_BACKUP_COUNT, CB_MCP_LOG_WARNING_RETENTION_BACKUP_COUNT, CB_MCP_LOG_INFO_RETENTION_BACKUP_COUNT, CB_MCP_LOG_DEBUG_RETENTION_BACKUP_COUNT, CB_MCP_OAUTH_JWT_JWKS_URI, CB_MCP_OAUTH_JWT_ISSUER, CB_MCP_OAUTH_JWT_AUDIENCE, CB_MCP_OAUTH_JWT_ALGORITHM, CB_MCP_OAUTH_MCP_BASE_URL, CB_MCP_OAUTH_SCOPE_READ_LABEL, CB_MCP_OAUTH_SCOPE_WRITE_LABEL | MCP-Register | 2026-08-14T01:17:01.879Z | selbstauskunft |  |
| Required secret variables (raw) |  | MCP-Register | 2026-08-06T13:57:41.838Z | selbstauskunft |  |
| Transports (raw) | stdio, stdio | MCP-Register | 2026-08-06T13:57:41.838Z | selbstauskunft |  |
| Path arguments (raw) |  | MCP-Register | 2026-08-06T13:57:41.838Z | selbstauskunft |  |
| Repository (raw) | https://github.com/couchbase/mcp-server-couchbase | MCP-Register | 2026-08-06T13:57:41.838Z | selbstauskunft |  |
| Package registries (raw) | oci, pypi | MCP-Register | 2026-08-06T13:57:41.838Z | selbstauskunft |  |
| Required secret headers (raw) |  | MCP-Register | 2026-08-16T01:17:01.420Z | selbstauskunft |  |
| Path environment variables (raw) |  | MCP-Register | 2026-08-16T01:17:01.420Z | selbstauskunft |  |
| Remote URLs (raw) |  | MCP-Register | 2026-08-16T01:17:01.420Z | selbstauskunft |  |
| Remote hosts (raw) |  | MCP-Register | 2026-08-16T01:17:01.420Z | selbstauskunft |  |
| Registry status message (raw) |  | MCP-Register | 2026-08-16T01:17:01.420Z | selbstauskunft |  |
| First listed in the registry (raw) | 2026-08-13 | MCP-Register | 2026-08-16T01:17:01.420Z | selbstauskunft |  |
| Last changed in the registry (raw) | 2026-08-13 | MCP-Register | 2026-08-16T01:17:01.420Z | selbstauskunft |  |
| Schema version of the raw record (raw) | https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json | MCP-Register | 2026-08-16T01:17:01.420Z | selbstauskunft |  |
| Delivery form (raw) | paket | MCP-Register | 2026-08-16T01:17:01.420Z | selbstauskunft |  |
| Repository platform (raw) | github | MCP-Register | 2026-08-16T01:17:01.420Z | selbstauskunft |  |
| Repository subfolder (raw) |  | MCP-Register | 2026-08-16T01:17:01.420Z | selbstauskunft |  |
| Package identifiers (raw) | couchbase-mcp-server, docker.io/couchbase/mcp-server:1.0.1 | MCP-Register | 2026-08-16T01:17:01.420Z | selbstauskunft |  |
| Package versions (raw) | 1.0.1 | MCP-Register | 2026-08-16T01:17:01.420Z | selbstauskunft |  |
| Runtime hints (raw) |  | MCP-Register | 2026-08-16T01:17:01.420Z | selbstauskunft |  |
| Environment variable formats (raw) | boolean, number, string | MCP-Register | 2026-08-16T01:17:01.420Z | selbstauskunft |  |
| Environment variable descriptions (raw) | CB_CA_CERT_PATH=Couchbase CA certificate path. Required for TLS authentication in non Capella clusters. · CB_CLIENT_CERT_PATH=Couchbase client certificate path. Required for mTLS authentication. · CB_CLIENT_KEY_PATH=Couchbase client key path. Required for mTLS authentication. · CB_CONNECTION_STRING=Couchbase connection string. Required for connecting to the cluster. · CB_MCP_CONFIRMATION_REQUIRED_TOOLS=Comma-separated tool names that require user confirmation before execution. Also accepts a file path containing one tool name per line. Requires the MCP client to support elicitation. · CB_MCP_DISABLED_TOOLS=Tools to disable. Accepts comma-separated tool names (e.g., 'tool_1,tool_2') or a file path containing one tool name per line. · CB_MCP_HOST=Host to run the MCP server on (default: 127.0.0.1). Used only for HTTP and SSE transport modes. · CB_MCP_LOG_DEBUG_RETENTION_BACKUP_COUNT=Rotated backups kept for the DEBUG log file. Overrides CB_MCP_LOG_RETENTION_BACKUP_COUNT for DEBUG; inherits it when unset. · CB_MCP_LOG_DEBUG_ROTATION_MAX_SIZE_MB=Rotation size in MB for the DEBUG log file. Overrides CB_MCP_LOG_ROTATION_MAX_SIZE_MB for DEBUG; inherits it when unset. 0 is invalid and falls back to the inherited global with a startup warning. · CB_MCP_LOG_ERROR_RETENTION_BACKUP_COUNT=Rotated backups kept for the ERROR log file. Overrides CB_MCP_LOG_RETENTION_BACKUP_COUNT for ERROR; inherits it when unset. · CB_MCP_LOG_ERROR_ROTATION_MAX_SIZE_MB=Rotation size in MB for the ERROR log file. Overrides CB_MCP_LOG_ROTATION_MAX_SIZE_MB for ERROR; inherits it when unset. 0 is invalid and falls back to the inherited global with a startup warning. · CB_MCP_LOG_FILE=Base path for the per-level log files. One rotating file is written per level (e.g. mcp_server.info.log, mcp_server.error.log). Only used when 'file' is in CB_MCP_LOG_SINKS. Default is mcp_server.log. · CB_MCP_LOG_INFO_RETENTION_BACKUP_COUNT=Rotated backups kept for the INFO log file. Overrides CB_MCP_LOG_RETENTION_BACKUP_COUNT for INFO; inherits it when unset. · CB_MCP_LOG_INFO_ROTATION_MAX_SIZE_MB=Rotation size in MB for the INFO log file. Overrides CB_MCP_LOG_ROTATION_MAX_SIZE_MB for INFO; inherits it when unset. 0 is invalid and falls back to the inherited global with a startup warning. · CB_MCP_LOG_LEVEL=Logging level for the MCP server. One of off, debug, info, warning, error. Use 'off' to disable logging entirely. Invalid values fall back to info. Default is info. · CB_MCP_LOG_MAX_BYTES=[DEPRECATED] Global rotation size in bytes; use CB_MCP_LOG_ROTATION_MAX_SIZE_MB (MB) instead. Still honored for backward compatibility but ignored when CB_MCP_LOG_ROTATION_MAX_SIZE_MB is also set. A value of 0 is invalid and falls back to the default with a startup warning. · CB_MCP_LOG_RETENTION_BACKUP_COUNT=Number of rotated backup files kept per-level log file, excluding the live file. Applies to every level unless overridden per level. Set to 0 to keep only the live file (still capped by the rotation size). Default is 1. · CB_MCP_LOG_ROTATION_MAX_SIZE_MB=Global maximum size in MB per-level log file before it rotates, inherited by every level unless overridden by a per-level CB_MCP_LOG_<LEVEL>_ROTATION_MAX_SIZE_MB. A value of 0 is invalid and falls back to the default (1 MB) with a startup warning. Default is 1 (1 MB). · CB_MCP_LOG_SINKS=Comma-separated list of log destinations. Allowed values: stderr, file. Include 'file' to write per-level log files; include 'stderr' to write to the console. Default is stderr. · CB_MCP_LOG_WARNING_RETENTION_BACKUP_COUNT=Rotated backups kept for the WARNING log file. Overrides CB_MCP_LOG_RETENTION_BACKUP_COUNT for WARNING; inherits it when unset. · CB_MCP_LOG_WARNING_ROTATION_MAX_SIZE_MB=Rotation size in MB for the WARNING log file. Overrides CB_MCP_LOG_ROTATION_MAX_SIZE_MB for WARNING; inherits it when unset. 0 is invalid and falls back to the inherited global with a startup warning. · CB_MCP_OAUTH_JWT_ALGORITHM=JWT signing algorithm. One of RS256/384/512, ES256/384/512, PS256/384/512. Default is RS256. · CB_MCP_OAUTH_JWT_AUDIENCE=Expected JWT 'aud' claim value. Required to enable OAuth. · CB_MCP_OAUTH_JWT_ISSUER=Expected JWT 'iss' claim value. Also advertised as the authorization server in Protected Resource Metadata when CB_MCP_OAUTH_MCP_BASE_URL is set. Required to enable OAuth. · CB_MCP_OAUTH_JWT_JWKS_URI=JWKS endpoint of the identity provider used to verify bearer JWT signatures. Required to enable OAuth, along with CB_MCP_OAUTH_JWT_ISSUER and CB_MCP_OAUTH_JWT_AUDIENCE. Only honored when CB_MCP_TRANSPORT=http. · CB_MCP_OAUTH_MCP_BASE_URL=Public base URL of this MCP server. When set, the server publishes RFC 9728 Protected Resource Metadata at <base_url>/.well-known/oauth-protected-resource/mcp so PRM-aware clients can discover the authorization server. Optional. · CB_MCP_OAUTH_SCOPE_READ_LABEL=Override the OAuth scope label the server treats as 'read' access; advertised in PRM and matched against the token's scope/scp claim. Use when your IdP cannot emit the canonical form. Default is couchbase-mcp:read. · CB_MCP_OAUTH_SCOPE_WRITE_LABEL=Override the OAuth scope label the server treats as 'write' access; same semantics as CB_MCP_OAUTH_SCOPE_READ_LABEL. Default is couchbase-mcp:write. · CB_MCP_PORT=Port to run the MCP server on (default: 8000). Used only for HTTP and SSE transport modes. · CB_MCP_READ_ONLY_MODE=Couchbase read only mode. Set to true to allow disable write operations across both KV and query. KV write tools are not loaded and SQL++ queries that modify data are blocked. Set to false to allow data modification queries and tools. · CB_MCP_READ_ONLY_MODE=Couchbase read only mode. Set to true to disable write operations across both KV and query. KV write tools are not loaded and SQL++ queries that modify data are blocked. Set to false to allow data modification queries and tools. · CB_MCP_TRANSPORT=Transport mode for the server (stdio, http or sse). Default is stdio · CB_PASSWORD=Couchbase database password. Required for basic authentication. · CB_USERNAME=Couchbase database username. Required for basic authentication. | MCP-Register | 2026-08-16T01:17:01.420Z | selbstauskunft |  |
| Icon formats (raw) |  | MCP-Register | 2026-08-16T01:17:01.420Z | selbstauskunft |  |
| Connection paths (source structure) | {"packages":[{"registryType":"pypi","identifier":"couchbase-mcp-server","version":"1.0.1","transport":"stdio","environment":[{"name":"CB_CONNECTION_STRING","description":"Couchbase connection string. Required for connecting to the cluster.","format":"string","required":false,"secret":false},{"name":"CB_USERNAME","description":"Couchbase database username. Required for basic authentication.","format":"string","required":false,"secret":false},{"name":"CB_PASSWORD","description":"Couchbase database password. Required for basic authentication.","format":"string","required":false,"secret":true},{"name":"CB_CA_CERT_PATH","description":"Couchbase CA certificate path. Required for TLS authentication in non Capella clusters.","format":"string","required":false,"secret":false},{"name":"CB_CLIENT_CERT_PATH","description":"Couchbase client certificate path. Required for mTLS authentication.","format":"string","required":false,"secret":false},{"name":"CB_CLIENT_KEY_PATH","description":"Couchbase client key path. Required for mTLS authentication.","format":"string","required":false,"secret":false},{"name":"CB_MCP_READ_ONLY_MODE","description":"Couchbase read only mode. Set to true to allow disable write operations across both KV and query. KV write tools are not loaded and SQL++ queries that modify data are blocked. Set to false to allow data modification queries and tools.","format":"boolean","required":false,"secret":false},{"name":"CB_MCP_TRANSPORT","description":"Transport mode for the server (stdio, http or sse). Default is stdio","format":"string","required":false,"secret":false},{"name":"CB_MCP_HOST","description":"Host to run the MCP server on (default: 127.0.0.1). Used only for HTTP and SSE transport modes.","format":"string","required":false,"secret":false},{"name":"CB_MCP_PORT","description":"Port to run the MCP server on (default: 8000). Used only for HTTP and SSE transport modes.","format":"number","required":false,"secret":false},{"name":"CB_MCP_DISABLED_TOOLS","description":"Tools to disable. Accepts comma-separated tool names (e.g., 'tool_1,tool_2') or a file path containing one tool name per line.","format":"string","required":false,"secret":false},{"name":"CB_MCP_CONFIRMATION_REQUIRED_TOOLS","description":"Comma-separated tool names that require user confirmation before execution. Also accepts a file path containing one tool name per line. Requires the MCP client to support elicitation.","format":"string","required":false,"secret":false},{"name":"CB_MCP_LOG_LEVEL","description":"Logging level for the MCP server. One of off, debug, info, warning, error. Use 'off' to disable logging entirely. Invalid values fall back to info. Default is info.","format":"string","required":false,"secret":false},{"name":"CB_MCP_LOG_SINKS","description":"Comma-separated list of log destinations. Allowed values: stderr, file. Include 'file' to write per-level log files; include 'stderr' to write to the console. Default is stderr.","format":"string","required":false,"secret":false},{"name":"CB_MCP_LOG_FILE","description":"Base path for the per-level log files. One rotating file is written per level (e.g. mcp_server.info.log, mcp_server.error.log). Only used when 'file' is in CB_MCP_LOG_SINKS. Default is mcp_server.log.","format":"string","required":false,"secret":false},{"name":"CB_MCP_LOG_ROTATION_MAX_SIZE_MB","description":"Global maximum size in MB per-level log file before it rotates, inherited by every level unless overridden by a per-level CB_MCP_LOG_<LEVEL>_ROTATION_MAX_SIZE_MB. A value of 0 is invalid and falls back to the default (1 MB) with a startup warning. Default is 1 (1 MB).","format":"number","required":false,"secret":false},{"name":"CB_MCP_LOG_MAX_BYTES","description":"[DEPRECATED] Global rotation size in bytes; use CB_MCP_LOG_ROTATION_MAX_SIZE_MB (MB) instead. Still honored for backward compatibility but ignored when CB_MCP_LOG_ROTATION_MAX_SIZE_MB is also set. A value of 0 is invalid and falls back to the default with a startup warning.","format":"number","required":false,"secret":false},{"name":"CB_MCP_LOG_ERROR_ROTATION_MAX_SIZE_MB","description":"Rotation size in MB for the ERROR log file. Overrides CB_MCP_LOG_ROTATION_MAX_SIZE_MB for ERROR; inherits it when unset. 0 is invalid and falls back to the inherited global with a startup warning.","format":"number","required":false,"secret":false},{"name":"CB_MCP_LOG_WARNING_ROTATION_MAX_SIZE_MB","description":"Rotation size in MB for the WARNING log file. Overrides CB_MCP_LOG_ROTATION_MAX_SIZE_MB for WARNING; inherits it when unset. 0 is invalid and falls back to the inherited global with a startup warning.","format":"number","required":false,"secret":false},{"name":"CB_MCP_LOG_INFO_ROTATION_MAX_SIZE_MB","description":"Rotation size in MB for the INFO log file. Overrides CB_MCP_LOG_ROTATION_MAX_SIZE_MB for INFO; inherits it when unset. 0 is invalid and falls back to the inherited global with a startup warning.","format":"number","required":false,"secret":false},{"name":"CB_MCP_LOG_DEBUG_ROTATION_MAX_SIZE_MB","description":"Rotation size in MB for the DEBUG log file. Overrides CB_MCP_LOG_ROTATION_MAX_SIZE_MB for DEBUG; inherits it when unset. 0 is invalid and falls back to the inherited global with a startup warning.","format":"number","required":false,"secret":false},{"name":"CB_MCP_LOG_RETENTION_BACKUP_COUNT","description":"Number of rotated backup files kept per-level log file, excluding the live file. Applies to every level unless overridden per level. Set to 0 to keep only the live file (still capped by the rotation size). Default is 1.","format":"number","required":false,"secret":false},{"name":"CB_MCP_LOG_ERROR_RETENTION_BACKUP_COUNT","description":"Rotated backups kept for the ERROR log file. Overrides CB_MCP_LOG_RETENTION_BACKUP_COUNT for ERROR; inherits it when unset.","format":"number","required":false,"secret":false},{"name":"CB_MCP_LOG_WARNING_RETENTION_BACKUP_COUNT","description":"Rotated backups kept for the WARNING log file. Overrides CB_MCP_LOG_RETENTION_BACKUP_COUNT for WARNING; inherits it when unset.","format":"number","required":false,"secret":false},{"name":"CB_MCP_LOG_INFO_RETENTION_BACKUP_COUNT","description":"Rotated backups kept for the INFO log file. Overrides CB_MCP_LOG_RETENTION_BACKUP_COUNT for INFO; inherits it when unset.","format":"number","required":false,"secret":false},{"name":"CB_MCP_LOG_DEBUG_RETENTION_BACKUP_COUNT","description":"Rotated backups kept for the DEBUG log file. Overrides CB_MCP_LOG_RETENTION_BACKUP_COUNT for DEBUG; inherits it when unset.","format":"number","required":false,"secret":false},{"name":"CB_MCP_OAUTH_JWT_JWKS_URI","description":"JWKS endpoint of the identity provider used to verify bearer JWT signatures. Required to enable OAuth, along with CB_MCP_OAUTH_JWT_ISSUER and CB_MCP_OAUTH_JWT_AUDIENCE. Only honored when CB_MCP_TRANSPORT=http.","format":"string","required":false,"secret":false},{"name":"CB_MCP_OAUTH_JWT_ISSUER","description":"Expected JWT 'iss' claim value. Also advertised as the authorization server in Protected Resource Metadata when CB_MCP_OAUTH_MCP_BASE_URL is set. Required to enable OAuth.","format":"string","required":false,"secret":false},{"name":"CB_MCP_OAUTH_JWT_AUDIENCE","description":"Expected JWT 'aud' claim value. Required to enable OAuth.","format":"string","required":false,"secret":false},{"name":"CB_MCP_OAUTH_JWT_ALGORITHM","description":"JWT signing algorithm. One of RS256/384/512, ES256/384/512, PS256/384/512. Default is RS256.","format":"string","required":false,"secret":false},{"name":"CB_MCP_OAUTH_MCP_BASE_URL","description":"Public base URL of this MCP server. When set, the server publishes RFC 9728 Protected Resource Metadata at <base_url>/.well-known/oauth-protected-resource/mcp so PRM-aware clients can discover the authorization server. Optional.","format":"string","required":false,"secret":false},{"name":"CB_MCP_OAUTH_SCOPE_READ_LABEL","description":"Override the OAuth scope label the server treats as 'read' access; advertised in PRM and matched against the token's scope/scp claim. Use when your IdP cannot emit the canonical form. Default is couchbase-mcp:read.","format":"string","required":false,"secret":false},{"name":"CB_MCP_OAUTH_SCOPE_WRITE_LABEL","description":"Override the OAuth scope label the server treats as 'write' access; same semantics as CB_MCP_OAUTH_SCOPE_READ_LABEL. Default is couchbase-mcp:write.","format":"string","required":false,"secret":false}],"additional_arguments_declared":true},{"registryType":"oci","identifier":"docker.io/couchbase/mcp-server:1.0.1","transport":"stdio","environment":[{"name":"CB_CONNECTION_STRING","description":"Couchbase connection string. Required for connecting to the cluster.","format":"string","required":false,"secret":false},{"name":"CB_USERNAME","description":"Couchbase database username. Required for basic authentication.","format":"string","required":false,"secret":false},{"name":"CB_PASSWORD","description":"Couchbase database password. Required for basic authentication.","format":"string","required":false,"secret":true},{"name":"CB_CA_CERT_PATH","description":"Couchbase CA certificate path. Required for TLS authentication in non Capella clusters.","format":"string","required":false,"secret":false},{"name":"CB_CLIENT_CERT_PATH","description":"Couchbase client certificate path. Required for mTLS authentication.","format":"string","required":false,"secret":false},{"name":"CB_CLIENT_KEY_PATH","description":"Couchbase client key path. Required for mTLS authentication.","format":"string","required":false,"secret":false},{"name":"CB_MCP_READ_ONLY_MODE","description":"Couchbase read only mode. Set to true to disable write operations across both KV and query. KV write tools are not loaded and SQL++ queries that modify data are blocked. Set to false to allow data modification queries and tools.","format":"boolean","required":false,"secret":false},{"name":"CB_MCP_TRANSPORT","description":"Transport mode for the server (stdio, http or sse). Default is stdio","format":"string","required":false,"secret":false},{"name":"CB_MCP_HOST","description":"Host to run the MCP server on (default: 127.0.0.1). Used only for HTTP and SSE transport modes.","format":"string","required":false,"secret":false},{"name":"CB_MCP_PORT","description":"Port to run the MCP server on (default: 8000). Used only for HTTP and SSE transport modes.","format":"number","required":false,"secret":false},{"name":"CB_MCP_DISABLED_TOOLS","description":"Tools to disable. Accepts comma-separated tool names (e.g., 'tool_1,tool_2') or a file path containing one tool name per line.","format":"string","required":false,"secret":false},{"name":"CB_MCP_CONFIRMATION_REQUIRED_TOOLS","description":"Comma-separated tool names that require user confirmation before execution. Also accepts a file path containing one tool name per line. Requires the MCP client to support elicitation.","format":"string","required":false,"secret":false},{"name":"CB_MCP_LOG_LEVEL","description":"Logging level for the MCP server. One of off, debug, info, warning, error. Use 'off' to disable logging entirely. Invalid values fall back to info. Default is info.","format":"string","required":false,"secret":false},{"name":"CB_MCP_LOG_SINKS","description":"Comma-separated list of log destinations. Allowed values: stderr, file. Include 'file' to write per-level log files; include 'stderr' to write to the console. Default is stderr.","format":"string","required":false,"secret":false},{"name":"CB_MCP_LOG_FILE","description":"Base path for the per-level log files. One rotating file is written per level (e.g. mcp_server.info.log, mcp_server.error.log). Only used when 'file' is in CB_MCP_LOG_SINKS. Default is mcp_server.log.","format":"string","required":false,"secret":false},{"name":"CB_MCP_LOG_ROTATION_MAX_SIZE_MB","description":"Global maximum size in MB per-level log file before it rotates, inherited by every level unless overridden by a per-level CB_MCP_LOG_<LEVEL>_ROTATION_MAX_SIZE_MB. A value of 0 is invalid and falls back to the default (1 MB) with a startup warning. Default is 1 (1 MB).","format":"number","required":false,"secret":false},{"name":"CB_MCP_LOG_MAX_BYTES","description":"[DEPRECATED] Global rotation size in bytes; use CB_MCP_LOG_ROTATION_MAX_SIZE_MB (MB) instead. Still honored for backward compatibility but ignored when CB_MCP_LOG_ROTATION_MAX_SIZE_MB is also set. A value of 0 is invalid and falls back to the default with a startup warning.","format":"number","required":false,"secret":false},{"name":"CB_MCP_LOG_ERROR_ROTATION_MAX_SIZE_MB","description":"Rotation size in MB for the ERROR log file. Overrides CB_MCP_LOG_ROTATION_MAX_SIZE_MB for ERROR; inherits it when unset. 0 is invalid and falls back to the inherited global with a startup warning.","format":"number","required":false,"secret":false},{"name":"CB_MCP_LOG_WARNING_ROTATION_MAX_SIZE_MB","description":"Rotation size in MB for the WARNING log file. Overrides CB_MCP_LOG_ROTATION_MAX_SIZE_MB for WARNING; inherits it when unset. 0 is invalid and falls back to the inherited global with a startup warning.","format":"number","required":false,"secret":false},{"name":"CB_MCP_LOG_INFO_ROTATION_MAX_SIZE_MB","description":"Rotation size in MB for the INFO log file. Overrides CB_MCP_LOG_ROTATION_MAX_SIZE_MB for INFO; inherits it when unset. 0 is invalid and falls back to the inherited global with a startup warning.","format":"number","required":false,"secret":false},{"name":"CB_MCP_LOG_DEBUG_ROTATION_MAX_SIZE_MB","description":"Rotation size in MB for the DEBUG log file. Overrides CB_MCP_LOG_ROTATION_MAX_SIZE_MB for DEBUG; inherits it when unset. 0 is invalid and falls back to the inherited global with a startup warning.","format":"number","required":false,"secret":false},{"name":"CB_MCP_LOG_RETENTION_BACKUP_COUNT","description":"Number of rotated backup files kept per-level log file, excluding the live file. Applies to every level unless overridden per level. Set to 0 to keep only the live file (still capped by the rotation size). Default is 1.","format":"number","required":false,"secret":false},{"name":"CB_MCP_LOG_ERROR_RETENTION_BACKUP_COUNT","description":"Rotated backups kept for the ERROR log file. Overrides CB_MCP_LOG_RETENTION_BACKUP_COUNT for ERROR; inherits it when unset.","format":"number","required":false,"secret":false},{"name":"CB_MCP_LOG_WARNING_RETENTION_BACKUP_COUNT","description":"Rotated backups kept for the WARNING log file. Overrides CB_MCP_LOG_RETENTION_BACKUP_COUNT for WARNING; inherits it when unset.","format":"number","required":false,"secret":false},{"name":"CB_MCP_LOG_INFO_RETENTION_BACKUP_COUNT","description":"Rotated backups kept for the INFO log file. Overrides CB_MCP_LOG_RETENTION_BACKUP_COUNT for INFO; inherits it when unset.","format":"number","required":false,"secret":false},{"name":"CB_MCP_LOG_DEBUG_RETENTION_BACKUP_COUNT","description":"Rotated backups kept for the DEBUG log file. Overrides CB_MCP_LOG_RETENTION_BACKUP_COUNT for DEBUG; inherits it when unset.","format":"number","required":false,"secret":false},{"name":"CB_MCP_OAUTH_JWT_JWKS_URI","description":"JWKS endpoint of the identity provider used to verify bearer JWT signatures. Required to enable OAuth, along with CB_MCP_OAUTH_JWT_ISSUER and CB_MCP_OAUTH_JWT_AUDIENCE. Only honored when CB_MCP_TRANSPORT=http.","format":"string","required":false,"secret":false},{"name":"CB_MCP_OAUTH_JWT_ISSUER","description":"Expected JWT 'iss' claim value. Also advertised as the authorization server in Protected Resource Metadata when CB_MCP_OAUTH_MCP_BASE_URL is set. Required to enable OAuth.","format":"string","required":false,"secret":false},{"name":"CB_MCP_OAUTH_JWT_AUDIENCE","description":"Expected JWT 'aud' claim value. Required to enable OAuth.","format":"string","required":false,"secret":false},{"name":"CB_MCP_OAUTH_JWT_ALGORITHM","description":"JWT signing algorithm. One of RS256/384/512, ES256/384/512, PS256/384/512. Default is RS256.","format":"string","required":false,"secret":false},{"name":"CB_MCP_OAUTH_MCP_BASE_URL","description":"Public base URL of this MCP server. When set, the server publishes RFC 9728 Protected Resource Metadata at <base_url>/.well-known/oauth-protected-resource/mcp so PRM-aware clients can discover the authorization server. Optional.","format":"string","required":false,"secret":false},{"name":"CB_MCP_OAUTH_SCOPE_READ_LABEL","description":"Override the OAuth scope label the server treats as 'read' access; advertised in PRM and matched against the token's scope/scp claim. Use when your IdP cannot emit the canonical form. Default is couchbase-mcp:read.","format":"string","required":false,"secret":false},{"name":"CB_MCP_OAUTH_SCOPE_WRITE_LABEL","description":"Override the OAuth scope label the server treats as 'write' access; same semantics as CB_MCP_OAUTH_SCOPE_READ_LABEL. Default is couchbase-mcp:write.","format":"string","required":false,"secret":false}],"additional_arguments_declared":false}],"remotes":[]} | MCP-Register | 2026-09-08T01:17:01.649Z | selbstauskunft |  |

## Links

- Namespace: [[namensraum/io-github-couchbase|io.github.couchbase]]

---

- Registry page: <https://tracevero.com/mcp/io-github-couchbase-mcp-server-couchbase>
- Retrieved on: 2026-10-10
