MCP server for CTFd v3: list challenges, submit flags, and query scoreboards via AI agents.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
One-click editor setup isnβt available for this listing yet β we donβt have a confirmed install command, and weβd rather show nothing than point your editor at the wrong package or host. Follow the projectβs own setup instructions, linked above.
A Model Context Protocol (MCP) server for interacting with any CTFd v3 instance. It lets AI tools (Claude Desktop, Cursor, custom agents, ...) authenticate, list and inspect challenges, submit flags, and query instance state through a stable, type-safe interface.
The project ships two interfaces built on the same client library:
ctfd_mcp_server.py, used over stdio or sse.server/main.py, a FastAPI mirror for scripting,
debugging, and Docker deployments.Credentials (token / cookie / password) live in memory only and are never
echoed in tool output, written to server_state.json, or logged.
category, search (name),
and solved/unsolved filters, plus per-challenge detail retrieval.confirm=True, returns clear
success/failure, and surfaces rate-limit errors. Flags are never logged.AuthenticationError, CTFdAPIError,
ChallengeNotFoundError, SubmissionError, ValidationError,
ConfigurationError.GETs,
no retries for POSTs (no duplicate submissions), strict JSON/content parsing.BASE_URL is validated and configurable at startup
and at runtime.Requires Python 3.10+.
The fastest way is to install from PyPI:
For MCP clients, point your config at the packaged entry point:
Or run from source:
| Variable | Default | Meaning |
|---|---|---|
CTFD_BASE_URL | (empty) | CTFd instance root, e.g. https://ctf.example.com (without /api/v1) |
CTFD_ADMIN_TOKEN | (empty) | API token (preferred auth) |
CTFD_SESSION_COOKIE | (empty) | Session cookie, e.g. session=abc... |
CTFD_USERNAME | (empty) | Username for form login |
CTFD_PASSWORD | (empty) | Password for form login |
CTFD_HTTP_TIMEOUT | 15 | Per-request HTTP timeout (seconds) |
CTFD_HTTP_MAX_REDIRECTS | 5 | Max redirects followed per request |
CTFD_STATE_FILE | ~/.local/state/ctfd-mcp/server_state.json | File used to cache auth state |
CTFD_MCP_TRANSPORT | stdio | MCP transport: stdio or sse |
MCP_HOST / MCP_PORT | 127.0.0.1 / 8000 | REST server bind settings (loopback by default) |
CTFD_API_TOKEN | (empty) | Optional bearer token protecting the optional REST API (/api/v1/*) |
CTFD_ALLOW_PRIVATE_IPS | false | Allow connections to private/loopback/metadata addresses (e.g. local CTFd test instances) |
CTFD_DOWNLOAD_DIR | ./downloads | Directory where challenge attachments are saved by download_file |
CTFD_PERSIST_SECRETS | false | β Strongly discouraged: write secrets to disk |
CTFD_BASE_URLmay include a path prefix (e.g.https://host/ctfd); the client appends/api/v1automatically.
Most MCP clients launch the server themselves via a command/args config.
For that, your client config should reference ctfd_mcp_server.py:
Manual launch:
| Tool | Parameters | Description |
|---|---|---|
set_base_url | url | Point the server at a CTFd instance |
set_token | token | Adopt an API token (memory only) |
set_cookie | cookie | Adopt a session cookie (memory only) |
login | username, password | Form login; keeps the session cookie |
challenges | category, search, solved, page, per_page | Paginated challenge list with filters |
challenge | identifier (id or name) | Full detail of one challenge |
submit_flag | flag, challenge_name/challenge_id, confirm | Submit a flag (requires confirm=True) |
download_file | file_url, dest_dir | Download a challenge attachment over the CTFd /files/β¦ route |
unlock_hint | hint_id | Unlock and read a hint (paid hints cost points) |
scoreboard | β | Public scoreboard standings |
progress | β | Your score + solved challenges |
instance_info | β | Safe public instance metadata |
auth_status | β | Auth mode + validity (no secrets) |
health | β | Reachability, API and auth checks |
With token auth, requests are sent with
Content-Type: application/json(CTFd only honoursAuthorization: Token ...on JSON requests). With cookie/credentials auth, state-changing requests echo the session CSRF nonce as theCSRF-Tokenheader, which is re-fetched from the site after login.
Tools return JSON text. Errors are structured, e.g.:
Endpoints (all under /api/v1):
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/ctfd)<a href="https://allmcps.com/mcp/ctfd"><img src="https://allmcps.com/api/badge/ctfd?style=directory" alt="CTFd on AllMCPs" /></a>