Terraform MCP server

The Terraform MCP server gives AI agents current Terraform Registry data on providers, modules and policies, and with a token manages HCP Terraform and Terraform Enterprise workspaces, runs and plans.

Connect Terraform

Claude Code, local Docker server

Terminal
claude mcp add terraform -s user -t stdio -- docker run -i --rm hashicorp/terraform-mcp-server

Codex, local Docker server

Terminal
codex mcp add terraform -- docker run -i --rm hashicorp/terraform-mcp-server

Gemini CLI extension

Terminal
gemini extensions install https://github.com/hashicorp/terraform-mcp-server

For HCP Terraform or Terraform Enterprise tools, add -e TFE_TOKEN and -e TFE_ADDRESS to the docker run command, with the token from your HCP Terraform user settings and the address including https. Choose toolsets with --toolsets, for example registry,terraform.

Or paste this into your coding agent: Connect the Terraform MCP server to my coding agent using its documented setup: https://github.com/hashicorp/terraform-mcp-server.

What the Terraform MCP server does

The Terraform MCP server is HashiCorp's own server for connecting AI agents to Terraform data. Its default toolset looks up the public Terraform Registry: providers and their resource docs, modules and policies, so the agent writes HCL against the current provider version instead of guessing at arguments that changed.

With an HCP Terraform or Terraform Enterprise token set in TFE_TOKEN, the Terraform server adds tools for your organization: list and manage workspaces, their variables and tags, read the private registry, and inspect runs. get_plan_details, get_plan_logs and get_plan_json_output let the agent read what a plan will change and why it failed. Tools that need explicit approval stay off unless ENABLE_TF_OPERATIONS is set to true.

HashiCorp ships the Terraform server as a Docker image and a Go binary. It runs over stdio by default or over Streamable HTTP for a shared deployment, with per-session rate limits, CORS rules and an organization allowlist. The README warns that the server may expose Terraform data to the LLM and should not be used with untrusted clients. The repo had 1,539 GitHub stars on 2026-10-01.

Tools it gives your agent

  • search_providers
  • get_provider_details
  • list_workspaces
  • get_plan_details
  • get_plan_logs
  • get_plan_json_output

When to use Terraform

  • You want the agent to write a module using the current version of a provider's resources.
  • You need to compare community modules in the registry for a job.
  • A plan failed in HCP Terraform and you want the agent to read its logs.
  • You want to know which workspaces use a variable or tag.

When to pick something else

  • Teams on plain open-source Terraform with local state only: the workspace and plan tools need HCP Terraform or Terraform Enterprise.
  • Running applies unattended: with ENABLE_TF_OPERATIONS on and a broad token, the agent can change workspaces and start runs, so keep tokens scoped.

What Terraform needs

  • Docker, or the terraform-mcp-server binary
  • An HCP Terraform or Terraform Enterprise API token, only for the organization tools

What the Terraform MCP server costs

Free and open source under MPL-2.0; public registry lookups need no account, and the HCP Terraform and Terraform Enterprise tools need an account HashiCorp prices separately.

Current prices: github.com . We do not list prices: vendors change them often, so check the publisher's own page.

  • AWS: The AWS MCP servers give AI agents access to AWS: a managed AWS MCP Server for API calls and docs, plus more than 50 open-source servers for services like CDK, EKS, Lambda and DynamoDB.
  • Cloudflare: The Cloudflare MCP servers give AI agents access to a Cloudflare account through hosted endpoints: read Workers logs and builds, manage bindings, check DNS analytics, search the docs and render web pages.
  • Kubernetes: The Kubernetes MCP server gives AI agents direct access to Kubernetes and OpenShift clusters: list and edit any resource, read pod logs, exec into pods, view events and install Helm charts.
  • Sentry: The Sentry MCP server gives AI coding agents access to your Sentry account: search errors and events, read issue details and stack traces, look at performance data and triage issues while fixing code.