Back to Browse

Onyx MCP Server

Developer ToolsLow Risk8.0MCP RegistryLocal
Free

Server data from the Official MCP Registry

Secure MCP access to Onyx search, chat, projects, and administration.

About

Secure MCP access to Onyx search, chat, projects, and administration.

Security Report

8.0
Low Risk8.0Low Risk

Valid MCP server (2 strong, 1 medium validity signals). 1 known CVE in dependencies (1 critical, 0 high severity) Package registry verified. Imported from the Official MCP Registry.

10 files analyzed · 2 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

What You'll Need

Set these up before or after installing:

Onyx API base URL, for example https://onyx.example.com/apiOptional

Environment variable: ONYX_API_URL

Onyx Personal Access Token or API keyRequired

Environment variable: ONYX_API_TOKEN

Default Onyx agent ID for new chatsOptional

Environment variable: ONYX_DEFAULT_PERSONA_ID

Enable web search and allowlisted URL fetchingOptional

Environment variable: ONYX_MCP_ENABLE_WEB_FETCH

Comma-separated hostnames permitted for HTTPS URL fetchingOptional

Environment variable: ONYX_MCP_WEB_FETCH_ALLOWLIST

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-bywaleed-onyx-mcp": {
      "env": {
        "ONYX_API_URL": "your-onyx-api-url-here",
        "ONYX_API_TOKEN": "your-onyx-api-token-here",
        "ONYX_DEFAULT_PERSONA_ID": "your-onyx-default-persona-id-here",
        "ONYX_MCP_ENABLE_WEB_FETCH": "your-onyx-mcp-enable-web-fetch-here",
        "ONYX_MCP_WEB_FETCH_ALLOWLIST": "your-onyx-mcp-web-fetch-allowlist-here"
      },
      "args": [
        "-y",
        "onyx-mcp"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

Onyx MCP

CI License: MIT

MCP Registry name: io.github.ByWaleed/onyx-mcp

A comprehensive, secure Model Context Protocol server for Onyx, formerly Danswer.

This project exposes Onyx search, chat, agents, projects, documents, connectors, ingestion, and deployment-specific APIs to MCP clients. It is an independent community project and is not an official Onyx package.

Why This Server

  • Uses the current /chat/send-chat-message contract.
  • Defaults to Onyx's built-in assistant, persona 0.
  • Supports scoped Personal Access Tokens and legacy API keys.
  • Starts read-only.
  • Separately gates writes, administration, destructive actions, and raw API access.
  • Applies request timeouts and response-size limits.
  • Never logs authorization headers or tokens.
  • Includes an advanced raw API tool for deployment-specific endpoints.

Install

npx -y onyx-mcp@0.2.1

The pinned command is recommended for reproducible execution. Use npx -y onyx-mcp@latest only if you intentionally want automatic upgrades.

Versioned tarballs are attached to GitHub Releases. The previous scoped package, @bywaleed/onyx-mcp, is deprecated in favor of onyx-mcp.

Configuration

Required:

VariableDescription
ONYX_API_URLOnyx API base URL, for example https://onyx.example.com/api
ONYX_API_TOKENOnyx PAT or API key

Optional:

VariableDefaultDescription
ONYX_DEFAULT_PERSONA_ID0Default agent used for new chats
ONYX_MCP_ENABLE_WRITEfalseRegisters tools that create or modify data
ONYX_MCP_ENABLE_ADMINfalseRegisters administrative tools
ONYX_MCP_ENABLE_DESTRUCTIVEfalseRegisters destructive tools; write must also be enabled
ONYX_MCP_ENABLE_RAW_APIfalseRegisters the advanced raw API tool; admin access is also required
ONYX_MCP_ENABLE_WEB_FETCHfalseRegisters web search and URL-fetching tools
ONYX_MCP_WEB_FETCH_ALLOWLISTemptyComma-separated hostnames allowed for HTTPS URL fetching
ONYX_MCP_TIMEOUT_MS30000Request timeout
ONYX_MCP_MAX_RESPONSE_BYTES1000000Maximum accepted response body
ONYX_MCP_MAX_CONCURRENCY8Maximum concurrent requests to Onyx
ONYX_MCP_MAX_QUEUE100Maximum requests waiting for a concurrency slot

Onyx still enforces the permissions attached to the supplied token. Enabling a profile cannot grant additional Onyx privileges.

OpenCode

{
  "mcp": {
    "onyx": {
      "type": "local",
      "command": ["npx", "-y", "onyx-mcp@0.2.1"],
      "environment": {
        "ONYX_API_URL": "https://onyx.example.com/api",
        "ONYX_API_TOKEN": "{env:ONYX_API_TOKEN}"
      },
      "enabled": true
    }
  }
}

Claude Desktop

{
  "mcpServers": {
    "onyx": {
      "command": "npx",
      "args": ["-y", "onyx-mcp@0.2.1"],
      "env": {
        "ONYX_API_URL": "https://onyx.example.com/api",
        "ONYX_API_TOKEN": "your-token"
      }
    }
  }
}

Tool Profiles

The read-only profile includes health, identity, permissions, search, chat history, agents, projects, files, tools, document sets, and connector status.

The write profile adds chat creation, chat messages, feedback, and project updates.

The admin profile adds connector, credential, user, agent, and direct-ingestion administration.

The destructive profile adds individually confirmed deletion tools. Bulk deletion is intentionally not exposed as a first-class tool.

The raw API profile adds onyx_api_request. It covers APIs specific to an Onyx edition or version. Every raw request requires the admin profile. Every non-GET request also requires write and destructive access plus confirmation because arbitrary endpoint semantics cannot be inferred safely.

Tools

The default profile provides health, version, identity, permission, indexed search, agent, chat-history, project, file, document-set, tool, source, and connector-status tools. Write mode adds chat, feedback, and project mutations. Admin mode adds connector, credential, user, agent, and ingestion tools. Web search and URL fetching require a separate web-fetch opt-in. URL fetching accepts only HTTPS destinations matching the configured hostname allowlist; Onyx must also validate redirects and resolved addresses to prevent DNS rebinding.

Run onyx_capabilities to inspect the active profile. MCP clients can also call tools/list for complete machine-readable schemas and safety annotations.

Authentication

Prefer an Onyx PAT with the smallest required scope:

  • read:search for search.
  • read:chat for chat history.
  • write:chat for chat creation and messages.

Some Onyx endpoints still use legacy role checks and need an unrestricted PAT or API key. Use a separate administrative server configuration for those operations.

Treat client configuration files as sensitive when they contain a token. Use a dedicated least-privilege token and restrict file permissions to your user account.

Development

npm ci
npm run verify

Compatibility

ComponentSupported
Node.js20 and 22
MCP SDK/protocolTypeScript SDK 1.x, MCP through 2025-11-25
OnyxCurrent community and enterprise APIs; tested against the repository version documented in releases
TransportLocal stdio

The server uses non-streaming Onyx chat responses for a stable MCP result. Onyx editions and releases expose different administrative routes. The raw API tool provides an escape hatch while first-class tools remain curated and safe. MCP SDK 2.x migration is planned as a separate breaking compatibility release.

Support And Security

License

MIT

Reviews

No reviews yet

Be the first to review this server!