MCP server for managing Modal apps, containers, volumes, and secrets.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
We haven't yet run this listing's install command through our automated sandbox check. This isn't a red flag β we're steadily working through the catalog.
π‘ Paste the JSON block into your client's configuration file under mcpServers, then restart the application.
An MCP server for managing Modal β apps, containers, volumes, and secrets β and for deploying & running Modal apps directly from Claude Code and other MCP clients.
Every tool shells out to your local modal CLI, so it operates against whatever Modal profile and credentials are configured on your machine. There are no extra tokens to manage.
The server is published on PyPI as mcp-modal. No manual install is needed β the recommended way to run it is with uvx, which fetches and launches it on demand. Just point your MCP client at the command below (see Configuration).
Every version is also tagged and published on the
Releases page, with release notes and
the same .whl / .tar.gz that PyPI serves attached β useful for pinning, air-gapped
installs, or reading what changed between two versions.
This server uses your local Modal credentials. If you haven't authenticated yet, run:
This opens a browser to log in and stores a token in ~/.modal.toml. Already logged in elsewhere? Check with modal profile current.
Add the server to Claude Code with the claude mcp CLI:
Or add it to a .mcp.json file in your project root, which is the better option for a team
β everyone who opens the repo gets the same configuration:
@latest, and when to pin insteaduvx caches the environment it builds on the first run and does not check PyPI again:
"uvx will use the latest available version of the requested tool on the first invocation. After that, uvx will use the cached version of the tool unless a different version is requested, the cache is pruned, or the cache is refreshed." β uv docs
So a plain uvx mcp-modal means latest at install time, frozen forever after β restarting
the client or rebooting changes nothing, because the cache lives on disk. Different people
end up on different versions depending on when they first ran it, with no warning.
mcp-modal@latest re-resolves on every launch, so a restart picks up new releases.
Costs one network round-trip at startup. Use it while the tool surface is still moving.mcp-modal@0.4.0 (an explicit version) is reproducible and upgrades become a
deliberate one-line change. Use it once you want stability, or for a wider audience.To move a machine that is already stuck on an old cached build, switching it to either form
above is enough β requesting a version invalidates the cache. Otherwise
uv cache clean mcp-modal forces a refresh.
uv (provides uvx)modal setup) β 1.5 is
where modal billing summary/rates landed and where the billing report switched to
snake_case columns; the cost tool reads both spellings but needs 1.5 for those two viewsuv for dependency managementmodal must be installed in that project's virtual environmentThis server shells out to your local modal CLI using whatever credentials are in
~/.modal.toml. A few tools are powerful by design β if the MCP client driving the server
is ever prompt-injected (for example by malicious text inside logs it fetched), these are
the escalation paths and should stay behind your client's tool-approval prompts rather
than being auto-approved:
deploy_modal_app / run_modal_app β execute arbitrary local Python on the host
(modal deploy imports the app file; uv run resolves and installs the target project's
dependencies).modal_volume_files with action="put" β can read any local file (e.g. ~/.ssh/id_rsa,
~/.modal.toml) and upload it to a cloud volume (a data-exfiltration primitive).modal_volume_files with action="get" and force=True β can overwrite any local path
(e.g. ~/.zshrc or a shell profile, a persistence primitive).manage_modal_container with action="exec" β runs arbitrary commands inside a
container, by design.Every tool declares MCP tool annotations,
so a client can distinguish the four read-only tools (list_modal_resources,
get_modal_logs, search_modal_logs, analyze_modal_costs β all readOnlyHint: true)
from the eight that change remote state or start compute. Six of those eight are
destructiveHint: true; the exceptions are run_modal_app and inspect_modal_secret,
which start compute without removing or overwriting anything. Auto-approve the reads; keep
the rest behind a prompt.
To contain the two filesystem-touching volume tools, set the
MCP_MODAL_ALLOWED_LOCAL_PATHS environment variable to an
os.pathsep-separated list of
directories (: on macOS/Linux). When it is set, modal_volume_files is refused for any
local path β local_path on action="put", the destination on action="get" β unless the
resolved path, after expanding ~ and collapsing ../symlinks, falls inside one of those
roots. The download target "-" (return contents instead of writing a file) is exempt
because nothing is written to disk.
When the variable is unset (the default) there is no restriction, so existing setups are unaffected. Configure it in your MCP client, e.g.:
All tools also pass user-supplied names/paths after a -- end-of-options separator, so a
value beginning with - is always treated as data, never as a modal CLI flag. Secret
values handed to manage_modal_secret are redacted from the echoed command, logs, and any
error output.
12 tools. Related operations are grouped behind an action/resource argument rather than
split one-per-CLI-subcommand: every tool schema is loaded into the model's context for the
whole session, so a smaller surface leaves more room for your actual work (and gives the
model fewer near-identical tools to choose between).
Tools that talk to environment-scoped resources take an optional env argument to target a
specific Modal environment; if omitted, they
use the profile's default (or MODAL_ENVIRONMENT). The exception is manage_modal_container
and container logs β a container ID is globally unique and the CLI accepts no environment
there.
List Modal Resources (list_modal_resources) β one lookup for the whole account.
resource (required), name, path (default /), envresource values:
| value | returns | name means |
|---|---|---|
apps | deployed/running/recently-stopped apps | β |
app_history | one app's deployment versions (for rollback) | app name/ID |
containers | running containers (ta-...) | app ID to filter by |
volumes | named volumes | β |
volume_files | files inside a volume (with path) | volume name |
secrets | secret names (values are never exposed) | β |
environments | valid env values for this workspace | β |
profile | active profile + all profiles | β |
volume_files sets empty: true with a message when a listing genuinely returns
nothing, so an empty directory is distinguishable from a wrong path.omitted_items giving the number dropped.Get Modal Logs (get_modal_logs) β fetch or stream logs for an app or a container.
identifier (required), target (auto/app/container, default
auto β anything starting ta- is a container), timeout_seconds (default 30),
env, since, until, tail, source (stdout/stderr/system), timestamps,
followsince without tail fetches every entry in the range; pass until as well (max
range 35 days, tail max 20,000) to keep a busy app's output bounded.follow=True, logs stream until the app/container stops or timeout_seconds is
reached, returning a snapshot with truncated: true.No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/mcp-modal-server)<a href="https://allmcps.com/mcp/mcp-modal-server"><img src="https://allmcps.com/api/badge/mcp-modal-server?style=directory" alt="MCP Modal Server on AllMCPs" /></a>