The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the Maven Tools MCP listing page.
Maven Tools MCP Server gives MCP-capable clients a practical way to inspect JVM dependencies using live Maven Central data.
It is built for developers and agents that need more than a plain version lookup: stability filtering, upgrade comparisons, dependency health signals, license data, CVE checks, and optional documentation lookups through Context7.

Coordinate-based tools work with Maven, Gradle, SBT, and Mill projects. The POM analysis and upgrade-planning tools take Maven pom.xml files.
Prerequisite: Docker installed and running. No local Java installation is required. For a Docker-free setup, see building and running the JAR.
Add the maven-tools entry to your Claude Desktop config (see config file locations):
Add the following server to .vscode/mcp.json in your workspace:
| Tag | Transport | Context7 | Best For |
|---|---|---|---|
:latest | STDIO | Yes | Default desktop MCP usage |
:latest-noc7 | STDIO | No | Networks where Context7 is blocked or not wanted |
:latest-http | HTTP | Yes | Streamable HTTP clients and sidecar workflows |
CONTEXT7_API_KEY is optional. Most setups can start without it. If your environment requires Context7 auth, or you want to avoid anonymous limits, pass it through Docker with -e CONTEXT7_API_KEY.
For fuller setup guidance, including JAR and native-container usage, Docker Compose, and environment notes, see docs/setup.md.
The default image exposes 11 MCP tools; -noc7 exposes the 9 core tools.
| Tool | What It Does |
|---|---|
get_latest_version | Find the latest version with stability-aware selection |
check_version_exists | Verify a specific version and classify its stability |
check_multiple_dependencies | Bulk lookup for dependency coordinates |
compare_dependency_versions | Compare current versions against available upgrades |
analyze_dependency_age | Classify how old a dependency is |
analyze_release_patterns | Look at release cadence and maintenance signals |
analyze_project_health | Run a broader dependency health audit |
analyze_pom_dependencies | Resolve declared dependency versions, identify their source, and surface BOM conflicts |
recommend_pom_upgrades | Produce actionable POM upgrade recommendations and flag changes needing review |
| Tool | What It Does |
|---|---|
resolve_library_id | Find a documentation library identifier |
query_docs | Fetch docs by Context7 library ID |
For parameters, examples, and tool-by-tool notes, see docs/tools.md.
Both POM tools use Apache Maven Model Builder for parent inheritance, properties, and dependency management, including imported BOMs. They accept raw POM XML and an optional sideloadedPoms bundle for unreleased parents or sibling modules.
analyze_pom_dependencies returns effective versions, classifies declarations as EXPLICIT, MANAGED, or EXPLICIT_OVERRIDE, and identifies managing BOMs and conflicts.recommend_pom_upgrades returns deterministicActions for mechanical edits and needsAttention for major upgrades, BOM conflicts, and explicit overrides. Actions identify the version field or property to edit in the input POM.Recommendations cover editable parent/BOM versions, explicit dependencies, root dependency-management entries, and direct build/plugin dependencies. Declarations without an unambiguous edit location in the input POM are skipped. The server returns recommendations; the client or agent validates and applies them.
Analysis covers declared dependencies, not the full transitive dependency graph. Profile activation is limited to active-by-default profiles. See POM analysis details and limits.
A common prompt in Copilot or Claude is:
Check all latest versions of the dependencies in my
pom.xmland call out anything risky.
The client can combine tool results to report:
For broader questions like "which library should I choose?", combine Maven metadata with Context7 documentation and client-side web search for ecosystem context.
See more prompt examples or the maven-tools agent skill for guidance on choosing and combining tools.
This repository uses its own tools in a weekly dependency-update workflow. A Python agent sends the POM to recommend_pom_upgrades, validates and applies minor/patch actions, and opens a PR for review. Its XML editor checks current versions and preserves formatting. Manual major-upgrade reviews use the GitHub Copilot SDK; routine updates do not require an LLM.
See the dogfooding guide for the agent, GitHub Actions workflow, credentials, and manual triggers.
For a few more usage notes, see the FAQ section in docs/examples.md.
The effective POM resolver under com.arvindand.mcp.maven.pom follows the resolution
shape of maxxq-org/maxxq-maven (MIT,
Guy Chauliac), scoped here to declared-dep resolution. See NOTICE.
docs/setup.md - installation, client configuration, image variants, build-from-source optionsdocs/tools.md - full tool catalog, parameters, and response behaviordocs/examples.md - practical prompts, advanced use cases, reusable commands, and FAQ notesdocs/dogfooding.md - weekly self-update workflow and agent integrationdocs/troubleshooting.md - common environment issues and fixesdocs/architecture.md - design principles, transport/runtime options, and technical notesCORPORATE-CERTIFICATES.md - custom CA certificate support for locked-down networksIf you want to build or test locally, start with docs/setup.md and the helper scripts in build/.
Project history and release notes live in CHANGELOG.md.
This project is licensed under the MIT License. See LICENSE.
Arvind Menon