Terraform MCP server
The Terraform MCP server gives AI agents current Terraform Registry data on providers, modules and policies, and with a token manages HCP Terraform and Terraform Enterprise workspaces, runs and plans.
Connect Terraform
Claude Code, local Docker server
claude mcp add terraform -s user -t stdio -- docker run -i --rm hashicorp/terraform-mcp-serverCodex, local Docker server
codex mcp add terraform -- docker run -i --rm hashicorp/terraform-mcp-serverGemini CLI extension
gemini extensions install https://github.com/hashicorp/terraform-mcp-serverFor HCP Terraform or Terraform Enterprise tools, add -e TFE_TOKEN and -e TFE_ADDRESS to the docker run command, with the token from your HCP Terraform user settings and the address including https. Choose toolsets with --toolsets, for example registry,terraform.
Or paste this into your coding agent: Connect the Terraform MCP server to my coding agent using its documented setup: https://github.com/hashicorp/terraform-mcp-server.
What the Terraform MCP server does
The Terraform MCP server is HashiCorp's own server for connecting AI agents to Terraform data. Its default toolset looks up the public Terraform Registry: providers and their resource docs, modules and policies, so the agent writes HCL against the current provider version instead of guessing at arguments that changed.
With an HCP Terraform or Terraform Enterprise token set in TFE_TOKEN, the Terraform server adds tools for your organization: list and manage workspaces, their variables and tags, read the private registry, and inspect runs. get_plan_details, get_plan_logs and get_plan_json_output let the agent read what a plan will change and why it failed. Tools that need explicit approval stay off unless ENABLE_TF_OPERATIONS is set to true.
HashiCorp ships the Terraform server as a Docker image and a Go binary. It runs over stdio by default or over Streamable HTTP for a shared deployment, with per-session rate limits, CORS rules and an organization allowlist. The README warns that the server may expose Terraform data to the LLM and should not be used with untrusted clients. The repo had 1,539 GitHub stars on 2026-10-01.
Tools it gives your agent
search_providersget_provider_detailslist_workspacesget_plan_detailsget_plan_logsget_plan_json_output
When to use Terraform
- You want the agent to write a module using the current version of a provider's resources.
- You need to compare community modules in the registry for a job.
- A plan failed in HCP Terraform and you want the agent to read its logs.
- You want to know which workspaces use a variable or tag.
When to pick something else
- Teams on plain open-source Terraform with local state only: the workspace and plan tools need HCP Terraform or Terraform Enterprise.
- Running applies unattended: with ENABLE_TF_OPERATIONS on and a broad token, the agent can change workspaces and start runs, so keep tokens scoped.
What Terraform needs
- Docker, or the terraform-mcp-server binary
- An HCP Terraform or Terraform Enterprise API token, only for the organization tools
What the Terraform MCP server costs
Free and open source under MPL-2.0; public registry lookups need no account, and the HCP Terraform and Terraform Enterprise tools need an account HashiCorp prices separately.
Current prices: github.com . We do not list prices: vendors change them often, so check the publisher's own page.
Other MCP servers for cloud and devops
- AWS: The AWS MCP servers give AI agents access to AWS: a managed AWS MCP Server for API calls and docs, plus more than 50 open-source servers for services like CDK, EKS, Lambda and DynamoDB.
- Cloudflare: The Cloudflare MCP servers give AI agents access to a Cloudflare account through hosted endpoints: read Workers logs and builds, manage bindings, check DNS analytics, search the docs and render web pages.
- Kubernetes: The Kubernetes MCP server gives AI agents direct access to Kubernetes and OpenShift clusters: list and edit any resource, read pod logs, exec into pods, view events and install Helm charts.
- Sentry: The Sentry MCP server gives AI coding agents access to your Sentry account: search errors and events, read issue details and stack traces, look at performance data and triage issues while fixing code.