Back to Browse

Jfrog MCP Server

by Jfrog
Developer ToolsLow Risk8.5MCP RegistryLocalRemote
Free

Server data from the Official MCP Registry

MCP Server for JFrog, providing tools for development and artifact management.

About

MCP Server for JFrog, providing tools for development and artifact management.

Remote endpoints: streamable-http: https://myPlatform.jfrog.github.io/mcp

Security Report

8.5
Low Risk8.5Low Risk

The JFrog MCP Server is a remote, cloud-hosted implementation with OAuth-based authentication and no exposed source code for analysis. Based on the documented architecture and setup requirements, the server demonstrates solid security practices: OAuth eliminates API key management, authentication is required for all operations, and permissions are appropriately scoped to JFrog platform resources. No code vulnerabilities or malicious patterns were identified in the available documentation.

1 file analyzed · 1 issue found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Documentation

View on GitHub

From the project's GitHub README.

MCP Client

JFrog Remote MCP Server

The Model Context Protocol (MCP) connects AI systems with external tools, data, and services using a standardized, lightweight interface.

JFrog MCP Server empowers developers, bringing the advanced capabilities of the JFrog platform to the development environment. The JFrog MCP Server integrates with IDEs and AI coding assistants such as VS Code, Cursor, Claude, Kiro, and Codex to respond to natural-language AI queries with rich, actionable information from the JFrog platform.

Among the capabilities you can access with direct, friendly AI interactions:

  • Resource Management: Create and view projects, repositories, and other JFrog components.
  • Artifact & Build Discovery: Find packages and their versions, locate where artifacts are stored, and search builds using AQL.
  • Catalog and Curation: Access package information, versions, and vulnerabilities, and check curation status.
  • Security Monitoring: Get Xray security summaries and policy violations for artifacts, check an artifact's scan/indexing status, and trace every resource impacted by a specific CVE or package.

Use these resources and real-time information for various use cases. For example:

  • Ensure that only approved packages are used by developers during coding.
  • Query the JFrog Catalog about OSS package versions, changes in reported vulnerabilities, and license requirements.
  • Track and manage JFrog Projects and artifacts.

And much more. See the full tool reference for everything the server exposes.

Note: The JFrog MCP Server is now generally available (GA) on JFrog Cloud (SaaS). The self-managed server is in Beta. Individual tools marked Beta in the tool reference are experimental and must be enabled for your environment.

Remote Server Implementation

The JFrog MCP Server is hosted on JFrog Cloud, and the tools it provides to the client are continuously updated — you automatically get new features and improvements as they are released, with no installation or upgrade required on the client side.

You connect to the JFrog MCP Server using OAuth for authentication. This eliminates the need to manage API keys.

Note: Because this is a remote server, the tool set evolves on the server. The TOOLS.md reference reflects the current tool surface.

Set up the JFrog MCP Server

The JFrog Remote MCP Server is generally available (GA) to JFrog users with a Cloud (SaaS) subscription.

Subscription information: Supported on the Cloud (SaaS) and Self-Managed platforms for all licenses.

Self-Managed (Beta): A self-managed JFrog MCP Server is also available. See MCP Server Installation for Helm and Docker Compose deployment.

  1. An Admin user must enable the JFrog MCP Server on a JPD in the subscription.
  2. You can then add the JFrog MCP Server to an MCP client.
  3. Save the configuration file.
  4. Restart or refresh your MCP client. An OAuth window opens in your browser.
  5. Follow the prompts to authorize your MCP client to access the JFrog MCP Server.

In the examples below, replace <JFROG_PLATFORM_URL> with your JFrog platform URL (for example, https://mycompany.jfrog.io).

Visual Studio Code

{
  "mcp": {
    "servers": {
      "jfrog": {
        "url": "https://<JFROG_PLATFORM_URL>/mcp"
      }
    }
  }
}

Cursor

{
  "mcpServers": {
    "jfrog": {
      "url": "https://<JFROG_PLATFORM_URL>/mcp"
    }
  }
}

For more MCP clients (Kiro, Claude, Codex, and others), see Add the JFrog MCP Server to an MCP client.

Tools

The server exposes over 100 tools across Access, Artifactory, Security, Curation, Distribution, Grid, Workers, OneModel, Event, Evidence, and AppTrust.

See the full reference in TOOLS.md.

Documentation

Reviews

No reviews yet

Be the first to review this server!