MCP Server for vmanomaly - VictoriaMetrics anomaly detection
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
π‘ Paste into ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows)
The implementation of Model Context Protocol (MCP) server for vmanomaly - VictoriaMetrics Anomaly Detection product.
This provides seamless integration with vmanomaly REST API and documentation for AI-assisted anomaly detection, model management, and observability insights.
This MCP server enables AI assistants like Claude to interact with vmanomaly for:
vmanomaly server health and build informationvmanomaly YAML configurationsvmalert alerting rules based on anomaly score metrics to simplify alerting setupvmanomaly documentation with fuzzy matchingThe MCP server contains embedded up-to-date vmanomaly documentation and is able to search it without online access.
The quality of the MCP Server and its responses depends very much on the capabilities of your client and the quality of the model you are using.
vmanomaly instance with REST API access:
Replace vX.Y.Z with the exact release you have reviewed.
Download the latest release from Releases page and put it to your PATH.
Example for Linux x86_64 (other architectures and platforms are also available). Select an
explicit release rather than a mutable latest URL, verify its checksum, and then verify its
GitHub build-provenance attestation:
Build-provenance attestations are available for releases produced by the hardened release workflow. Release tags must be annotated, cryptographically signed, and marked as verified by GitHub before that workflow publishes artifacts.
You can run vmanomaly MCP Server using Docker.
This is the easiest way to get started without needing to install Go or build from source.
Replace vX.Y.Z and the environment variables with your own parameters. When both services
run in Docker, prefer a private Docker network and use the vmanomaly service name as the endpoint.
Note that the MCP_SERVER_MODE=http flag is used to enable Streamable HTTP mode.
More details about server modes can be found in the Configuration section.
See available docker images in github registry.
Also see Using Docker instead of binary section for more details about using Docker with MCP server with clients in stdio mode.
For building binary from source code you can use the following approach:
Clone repo:
Build binary from cloned source code:
Build image from cloned source code:
For local UI/Copilot testing from the vmanomaly repository, build with a local tag:
Then run the vmanomaly repository helper with:
MCP Server for vmanomaly is configured via environment variables:
| Variable | Description | Required | Default | Allowed values |
|---|---|---|---|---|
VMANOMALY_ENDPOINT | vmanomaly server endpoint URL (e.g., http://localhost:8490) | Yes | - | - |
VMANOMALY_BEARER_TOKEN | Bearer token for authenticating with vmanomaly API (mutually exclusive with the token file) | No | - | - |
VMANOMALY_BEARER_TOKEN_FILE | Path to a bearer-token file, suitable for mounted container/orchestrator secrets | No | - | - |
VMANOMALY_HEADERS | Custom HTTP headers for requests (comma-separated key=value pairs, e.g., X-Custom=value1,X-Auth=value2) | No | - | - |
VMANOMALY_REQUEST_TIMEOUT | HTTP timeout for calls from MCP to vmanomaly, e.g. 60s | No | 30s | - |
MCP_SERVER_MODE | Server operation mode. See Modes for details. | No | stdio | stdio, http, sse |
MCP_LISTEN_ADDR | Address for HTTP server to listen on | No | localhost:8080 | - |
MCP_ENABLED_TOOLS | Positive comma-separated tool allowlist; empty enables all registered tools | No | - | - |
MCP_DISABLED_TOOLS | Comma-separated tool denylist; takes precedence over the allowlist | No | - | - |
MCP_DISABLE_RESOURCES | Disable all resources (documentation search will continue to work) | No | false | false, true |
MCP_HEARTBEAT_INTERVAL | Heartbeat interval for streamable-http protocol (keeps connection alive through network infrastructure) | No | 30s | - |
MCP_LOG_LEVEL | Log level: debug (verbose), info (default), warn, or error | No | info | - |
MCP_LOG_FILE | Log file path (empty = stderr) | No | stderr | - |
MCP Server supports the following modes of operation (transports):
stdio - Standard input/output mode, where the server reads commands from standard input and writes responses to standard output. This is the default mode and is suitable for local servers.http - Streamable HTTP. Server will expose the /mcp endpoint for HTTP connections.sse - Server-Sent Events. Server will expose the /sse and /message endpoints for SSE connections.[!NOTE] The
ssetransport mode was officially deprecated from MCP Specification (version 2025-03-26) and was replaced by Streamable HTTP transport (httpmode). In future releases its support can be deprecated, use Streamable HTTP transport if your client supports it.
More info about transports you can find in MCP docs:
In HTTP and SSE modes the MCP server provides the following endpoints:
| Endpoint | Description |
|---|---|
/mcp | HTTP endpoint for streaming messages in HTTP mode (for MCP clients that support Streamable HTTP) |
/metrics | Metrics in Prometheus format for monitoring the MCP server |
/health/liveness | Liveness check endpoint to ensure the server is running |
/health/readiness | Readiness check endpoint to ensure the server is ready to accept requests |
/sse + /message | Endpoints for messages in SSE mode (for MCP clients that support SSE) |
Treat an MCP client as an operator of every enabled tool. The server forwards requests to
vmanomaly with the process-wide bearer token and headers configured at startup; it does not add
an independent user identity or authorization boundary.
Use one of these routing models while preserving the invariant that each tool call reaches only the caller's trusted-domain vmanomaly installation:
A local per-user stdio process may use that user's token as its configured upstream token.
A remote MCP instance dedicated to one trusted domain may use a domain-scoped service token.
A shared remote MCP requires per-request forwarding of a verified user token so the gateway can route each call to the correct trusted domain. The current process-wide token configuration does not implement this pass-through mode; do not place multiple untrusted domains behind one static MCP credential.
Prefer stdio for a local, single-user integration. It has no network listener and inherits
access control from the process that launches it.
HTTP and SSE transports do not provide built-in client authentication. Keep the default
loopback bind where possible. If remote access is required, place the server behind an
authenticated TLS reverse proxy such as vmauth, restrict the network path, and do not expose
/mcp, /sse, or /message directly to an untrusted network.
Keep /metrics on an internal monitoring network or protect it at the proxy; health endpoints
can be exposed only as required by the deployment platform.
Give the configured vmanomaly credential the least privilege and trusted-domain scope available.
Prefer VMANOMALY_BEARER_TOKEN_FILE for mounted secrets; never put tokens in command-line
arguments, image layers, or committed client configuration.
Treat VMANOMALY_HEADERS as trusted operator configuration. Tools that set
pass_auth_headers=true can ask vmanomaly to forward authorization to a datasource, so permit
that only for approved datasource origins and enforce an outbound network policy.
Use MCP_ENABLED_TOOLS as a deployment allowlist. Both the allowlist and denylist are enforced
for discovery and direct invocation, so hidden tools cannot be called by name. An empty
allowlist retains backward compatibility by enabling every registered tool.
MCP_DISABLE_RESOURCES=true hides resource discovery and reads. The documentation-search tool
remains independent and can be separately disabled with the tool policy.
Logs and metrics intentionally omit tool arguments/results, raw errors, client metadata, and resource URIs. Treat MCP responses and downstream vmanomaly logs as sensitive nevertheless.
These controls reduce the MCP server's exposure but do not create tenant isolation. Treat one
logical vmanomaly installation, including its replicas or shards, as one trusted domain. Route
mutually untrusted domains to separate installations through vmauth or another authenticated
gateway. Users inside one trusted domain share its task and resource boundary.
Report suspected vulnerabilities using the private process in SECURITY.md.
Go to: Settings β Cursor Settings β MCP β Add new global MCP server and paste the following configuration into your Cursor ~/.cursor/mcp.json file:
See Cursor MCP docs for more info.
Add this to your Claude Desktop claude_desktop_config.json file (you can find it if open Settings β Developer β Edit config):
See Claude Desktop MCP docs for more info.
Run the command:
See Claude Code MCP docs for more info.
Add this to your VS Code MCP config file:
See VS Code MCP docs for more info.
Add the following to your Zed config file:
See Zed MCP docs for more info.
Settings β Tools β AI Assistant β Model Context Protocol (MCP).Add (+)As JSONAdd the following to your Windsurf MCP config file:
See Windsurf MCP docs for more info.
You can run vmanomaly MCP server using Docker instead of local binary.
You should replace run command in configuration examples above in the following way:
After installing and configuring the MCP server, you can start using it with your favorite MCP client.
You can start dialog with AI assistant from the phrase:
But it's not required, you can just start asking questions and the assistant will automatically use the tools and documentation to provide you with the best answers.
MCP vmanomaly provides tools organized into categories:
| Tool | Description |
|---|---|
vmanomaly_health_check | Check vmanomaly server health status |
vmanomaly_get_buildinfo | Get build information (version, build time, Go version) |
vmanomaly_get_server_queries | Get configured server query aliases and expressions |
vmanomaly_get_metrics | Get vmanomaly server metrics in Prometheus format |
| Tool | Description |
|---|---|
vmanomaly_list_models | List models exposed to VMUI and other UI-oriented flows |
vmanomaly_get_server_models | Get configured server models and their query attachments |
vmanomaly_get_model_schema | Get JSON schema for a specific model type |
vmanomaly_validate_model_config | Validate model configuration before using it |
| Tool | Description |
|---|---|
vmanomaly_validate_config | Validate complete vmanomaly YAML configuration |
| Tool | Description |
|---|---|
vmanomaly_search_docs | Full-text search across vmanomaly documentation with fuzzy matching |
| Tool | Description |
|---|---|
vmanomaly_check_compatibility | Check if persisted state is compatible with runtime version |
| Tool | Description |
|---|---|
vmanomaly_generate_alert_rule | Generate VMAlert rule YAML for anomaly score alerting |
| Tool | Description |
|---|---|
vmanomaly_timeseries_characteristics | Profile sampled query results for trends, seasonalities, spikiness, and gaps |
vmanomaly_create_autotune_task | Start tuning one requested model class on sampled series |
vmanomaly_get_autotune_task | Poll autotune progress and retrieve a completed recommendation |
vmanomaly_cancel_autotune_task | Request cooperative cancellation of an autotune task |
vmanomaly_create_autotune_task accepts optimization_n_trials, optimization_timeout, and advanced
optimization_params to bound Optuna work. The MCP tool uses interactive defaults of 32 trials and
8 seconds when no optimization budget is provided, and a conservative anomaly fraction of 0.02 when
anomaly_percentage is omitted; the vmanomaly API defaults are larger. Poll
vmanomaly_get_autotune_task until status is done, then use the recommendation under
result_data. Treat error and canceled as terminal statuses.
The list/schema endpoints intentionally expose only models supported by VMUI. Outside VMUI,
documented multivariate aliases such as temporal_envelope_multivariate can still be shared-autotuned
and validated as complete model configurations. Do not recommend multivariate models in VMUI.
For new configurations, prefer online models. Prophet, Holt-Winters, and Isolation Forest remain supported for existing deployments but are planned for future deprecation; use Temporal Envelope as the corresponding univariate or multivariate migration target.
This example shows data-driven model selection rather than choosing a model from the metric name:
You: Detect sustained CPU spikes for
avg by (instance) (1 - rate(node_cpu_seconds_total{mode="idle"}[5m]))at a5mstep.
Assistant: I profiled the exact query first. The sampled series contain a trend and recurring hour-of-day/day-of-week structure, so
temporal_envelopeis the best online starting point. If the profile had no meaningful trend or seasonality, I would prefermad_onlinefor robust data, orzscore_onlineonly for a stable light-tailed distribution.
Assistant: I verified the model and schema, then started shared autotune with the same
5mstep,anomaly_percentage=0.02, and causalexact=truevalidation. After sequentially polling the task to completion, I validated the returned model configuration before presenting it.The exact tuned parameters depend on the sampled data; the final model spec is always validated against the running vmanomaly instance.
During this dialog, the assistant used the following tools:
vmanomaly_timeseries_characteristics to measure the sampled data profilevmanomaly_list_models and vmanomaly_get_model_schema to verify the UI-compatible modelvmanomaly_create_autotune_task and vmanomaly_get_autotune_task to tune shared parametersvmanomaly_validate_model_config to validate the tuned modelvmanomaly_validate_config to validate the configurationIn HTTP and SSE modes the MCP Server provides metrics in Prometheus format at the /metrics endpoint.
Tracked operations:
mcp_vmanomaly_initialize_total - Client connectionsmcp_vmanomaly_call_tool_total{name,is_error} - Tool calls with success/error trackingmcp_vmanomaly_read_resource_total - Documentation resource readsmcp_vmanomaly_list_*_total - List operations (tools, resources, prompts)mcp_vmanomaly_error_total{method,error_class} - Errors by bounded, non-sensitive classExample:
AI services and agents along with MCP servers like this cannot guarantee the accuracy, completeness and reliability of results. You should double check the results obtained with AI.
The quality of the MCP Server and its responses depends very much on the capabilities of your client and the quality of the model you are using.
Contributions to the MCP vmanomaly project are welcome!
Please feel free to submit issues, feature requests, or pull requests.
For vmanomaly-specific questions, see the vmanomaly documentation.
For MCP server issues, please open an issue in this repository.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/mcp-vmanomaly)<a href="https://allmcps.com/mcp/mcp-vmanomaly"><img src="https://allmcps.com/api/badge/mcp-vmanomaly?style=directory" alt="Mcp Vmanomaly on AllMCPs" /></a>