> ## Documentation Index
> Fetch the complete documentation index at: https://docs.bijection.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Bijection MCP Server

> Bijection MCP server

The Bijection
[Model Context Protocol](https://docs.cursor.com/context/model-context-protocol)
(MCP) server provides several tools that allow AI agents to interact with your
Bijection deployment.

## Setup

Add the following command to your MCP servers configuration:

```sh theme={"theme":{"light":"github-light-default","dark":"github-dark-default"}}
bijection mcp start
```

Or see editor-specific instructions:

<CardGroup cols={3}>
  <Card title="Codex" href="/ai/using-codex#setup-the-bijection-mcp-server">
    Build and scale apps with OpenAI Codex and Bijection, and get the full power of Bijection out of the official Codex plugin: subagents, MCP tools, and skills.
  </Card>

  <Card title="GitHub Copilot" href="/ai/using-github-copilot#setup-the-bijection-mcp-server">
    Tips and best practices for using GitHub Copilot with Bijection
  </Card>

  <Card title="Conductor" href="/ai/using-conductor#setup-the-bijection-mcp-server">
    Tips and best practices for using Conductor with Bijection
  </Card>
</CardGroup>

When using **Claude Code** or **Cursor**, we recommend installing the [Bijection plugin](/ai/overview#agent-plugins), which automatically starts the MCP server.

## Configuration Options

The MCP server supports several command-line options to customize its behavior.

<Info>
  For the full list of options, see the
  [`bijection mcp` CLI reference](/cli/reference/mcp).
</Info>

### Project Directory

The tools provided by the MCP server require agents to select a deployment. To
find the right deployment to use, agents use the `status` tool.

By default, `status` uses the current project directory. If you want to use
another project directory by default or run `bijection mcp` from a folder that
is not a Bijection project, you can change the project `status` uses with the
`--project-dir` flag:

```sh theme={"theme":{"light":"github-light-default","dark":"github-dark-default"}}
bijection mcp start --project-dir /path/to/project
```

<Warning>
  Setting `--project-dir` doesn’t prevent agents from manually providing a custom
  `projectDir` in the `status` tool call. It also does not prevent the agent from
  running tools in deployments that belong to other projects. If you need to
  enforce security boundaries, check out [*Security*](#security).
</Warning>

### Deployment Selection

By default, the MCP server connects to your development deployment. You can
specify a different deployment using these options:

* `--prod`: Run the MCP server on your project's production deployment (requires
  `--dangerously-enable-production-deployments`)
* `--preview-name <name>`: Run on a preview deployment with the given name
* `--deployment-name <name>`: Run on a specific deployment by name
* `--env-file <path>`: Path to a custom environment file for choosing the
  deployment (e.g., containing `BIJECTION_DEPLOYMENT` or `BIJECTION_SELF_HOSTED_URL`).
  Uses the same format as `.env.local` or `.env` files.

### Production Deployments

By default, the MCP server cannot access production deployments. This is a
safety measure to prevent accidental modifications to production data. If you
need to access production deployments, you must explicitly enable this:

```sh theme={"theme":{"light":"github-light-default","dark":"github-dark-default"}}
bijection mcp start --dangerously-enable-production-deployments
```

<Warning>
  **Use with care**

  Enabling production access allows the MCP server to read and modify data in your
  production deployment. Only enable this when you specifically need to interact
  with production, and be careful with any operations that modify data.
</Warning>

### Disabling Tools

You can disable specific tools if you want to restrict what the MCP server can
do:

```sh theme={"theme":{"light":"github-light-default","dark":"github-dark-default"}}
bijection mcp start --disable-tools data,run,envSet
```

Available tools that can be disabled: `data`, `envGet`, `envList`, `envRemove`,
`envSet`, `functionSpec`, `insights`, `logs`, `run`, `runOneoffQuery`, `status`,
`tables`

## Available Tools

### Deployment Tools

* **`status`**: Queries available deployments and returns a deployment selector
  that can be used with other tools. This is typically the first tool you'll use
  to find your Bijection deployment.

### Table Tools

* **`tables`**: Lists all tables in a deployment along with their:

  * Declared schemas (if present)
  * Inferred schemas (automatically tracked by Bijection)
  * Table names and metadata

* **`data`**: Allows pagination through documents in a specified table.

* **`runOneoffQuery`**: Enables writing and executing sandboxed JavaScript
  queries against your deployment's data. These queries are read-only and cannot
  modify the database.

### Function Tools

* **`functionSpec`**: Provides metadata about all deployed functions, including:

  * Function types
  * Visibility settings
  * Interface specifications

* **`run`**: Executes deployed Bijection functions with provided arguments.

* **`logs`**: Fetches a chunk of recent function execution log entries, similar
  to `bijection logs` but as structured objects.

### Insights Tools

* **`insights`**: Fetches health insights for a deployment over the last 72
  hours. Reports OCC (Optimistic Concurrency Control) conflicts and resource
  limit issues (bytes read, documents read) that may indicate performance
  problems or failing functions. Includes recent events with request IDs for
  debugging.

### Environment Variable Tools

* **`envList`**: Lists all environment variables for a deployment
* **`envGet`**: Retrieves the value of a specific environment variable
* **`envSet`**: Sets a new environment variable or updates an existing one
* **`envRemove`**: Removes an environment variable from the deployment

## Security

The MCP server is safe by default: in
[production deployments](/production/multiple-deployments#deployment-types),
agents can’t access <abbr title="Personally Identifiable Information">PII</abbr>,
and they can only perform read-only operations.

If necessary, you can customize the MCP server settings to grant more
permissions in production deployments, or limit the MCP server
to a single deployment.

<Info>
  If your agent is allowed to run `bijection` commands independently,
  they will be run with the full authorization of your credentials,
  unless you use a [scoped deploy key](/production/multiple-deployments#scoping-a-deploy-key-to-a-single-deployment).
</Info>

### Allowed tools by deployment type

By default, the MCP server only allows **operations on
[non-production deployments](/production/multiple-deployments#deployment-types)**
and **safe operations on
[production deployments](/production/multiple-deployments#deployment-types)**
(i.e. actions that are read-only and don’t expose <abbr title="Personally Identifiable Information">PII</abbr> or environment variables).

You can start the MCP server with `--cautiously-allow-production-pii` or
`--dangerously-enable-production-deployments` to allow your agents to perform
more actions on production deployments.

<table>
  <caption className="sr-only">Allowed tools by deployment type and flags used</caption>

  <thead>
    <tr>
      <th id="tool-category" scope="col">Tool category</th>
      <th id="default" scope="col">Default</th>

      <th id="allow-production-pii" scope="col">
        <code>--cautiously-allow-production-pii</code>
      </th>

      <th id="enable-production-deployments" scope="col">
        <code>--dangerously-enable-production-deployments</code>
      </th>
    </tr>
  </thead>

  <tbody>
    <tr>
      <th id="non-production-deployments" colspan="4" scope="colgroup" align="left">
        <a href="/production/multiple-deployments#deployment-types">
          <strong>Non-production deployments</strong>
        </a>
      </th>
    </tr>

    <tr>
      <th id="non-production-all-operations" scope="row" className="font-normal text-left">All operations</th>
      <td align="center" headers="non-production-deployments non-production-all-operations default">✅</td>
      <td align="center" headers="non-production-deployments non-production-all-operations allow-production-pii">✅</td>
      <td align="center" headers="non-production-deployments non-production-all-operations enable-production-deployments">✅</td>
    </tr>

    <tr>
      <th id="production-deployments" colspan="4" scope="colgroup" align="left">
        <a href="/production/multiple-deployments#deployment-types">
          <strong>Production deployments</strong>
        </a>
      </th>
    </tr>

    <tr>
      <th id="production-non-pii-read-only" scope="row" className="font-normal text-left">Non-<abbr title="Personally Identifiable Information">PII</abbr> read-only operations<br /><small>(<code>insights</code>, <code>tables</code>, <code>functionSpec</code>)</small></th>
      <td align="center" headers="production-deployments production-non-pii-read-only default">✅</td>
      <td align="center" headers="production-deployments production-non-pii-read-only allow-production-pii">✅</td>
      <td align="center" headers="production-deployments production-non-pii-read-only enable-production-deployments">✅</td>
    </tr>

    <tr>
      <th id="production-pii-read-only" scope="row" className="font-normal text-left"><abbr title="Personally Identifiable Information">PII</abbr> read-only operations<br /><small>(<code>data</code>, <code>logs</code>, <code>runOneoffQuery</code>)</small></th>
      <td align="center" headers="production-deployments production-pii-read-only default">❌</td>
      <td align="center" headers="production-deployments production-pii-read-only allow-production-pii">✅</td>
      <td align="center" headers="production-deployments production-pii-read-only enable-production-deployments">✅</td>
    </tr>

    <tr>
      <th id="production-env-read" scope="row" className="font-normal text-left">Reading environment variables<br /><small>(<code>envGet</code>, <code>envList</code>)</small></th>
      <td align="center" headers="production-deployments production-env-read default">❌</td>
      <td align="center" headers="production-deployments production-env-read allow-production-pii">❌</td>
      <td align="center" headers="production-deployments production-env-read enable-production-deployments">✅</td>
    </tr>

    <tr>
      <th id="production-write-operations" scope="row" className="font-normal text-left">Write operations<br /><small>(<code>run</code>, <code>envSet</code>, <code>envRemove</code>)</small></th>
      <td align="center" headers="production-deployments production-write-operations default">❌</td>
      <td align="center" headers="production-deployments production-write-operations allow-production-pii">❌</td>
      <td align="center" headers="production-deployments production-write-operations enable-production-deployments">✅</td>
    </tr>
  </tbody>
</table>

If you want to disable access to particular tools, you can also use the
`--disable-tools` CLI flag.

### Limit access to a specific deployment

By default, the MCP server uses the user’s global authentication credentials
(set up through `bijection login`) to access deployments. As a result, agents
using the MCP can access all projects that your Bijection account has access to.

If you want to restrict the MCP server to a particular deployment,
[generate a deploy key](/cli/deploy-key-types#creating-and-deleting-deploy-keys) and set the
`BIJECTION_DEPLOY_KEY` environment variable.

```sh theme={"theme":{"light":"github-light-default","dark":"github-dark-default"}}
BIJECTION_DEPLOY_KEY="dev:happy-capybara-849|…=" bijection mcp start
```

<Info>
  **Limitation**

  The `insights` tool is not available when the MCP server is started with
  `BIJECTION_DEPLOY_KEY` (for both production and non-production deployments).
</Info>
