Terraform

Terraform

Official

Look up Terraform Registry providers and modules, and manage HCP Terraform workspaces from an AI agent.

Score 90(?)HashiCorpMPL-2.01.5kVerified Top MCPs for Cloud & Infrastructure

Quick answer

What it does

Exposes Terraform Registry APIs (providers, modules, policies) and, with a token, HCP Terraform / Enterprise workspace management (create, update, delete, variables, tags, runs) as MCP tools.

Best for

  • Grounding generated HCL in real provider schemas
  • Looking up module inputs and outputs
  • HCP Terraform workspace + run management
  • Discovering resources and data sources

Not for

  • Unattended `terraform apply`
  • Cloud-console operations (use AWS/Azure MCP)

Source: top-mcps.com/mcp/terraform — verified Jul 2026

Setup recipe

Pick your client, then follow the three steps.

  1. 1

    Install

    claude_desktop_config.json
    {
      "mcpServers": {
        "terraform": {
          "command": "docker",
          "args": [
            "run",
            "-i",
            "--rm",
            "hashicorp/terraform-mcp-server"
          ]
        }
      }
    }

    Paste under mcpServers. Fully quit and reopen Claude after editing.

    CLI or .mcp.json
    claude mcp add terraform -- docker run -i --rm hashicorp/terraform-mcp-server

    Run from your repo. Commit .mcp.json to share with your team.

    .cursor/mcp.json
    {
      "mcpServers": {
        "terraform": {
          "command": "docker",
          "args": [
            "run",
            "-i",
            "--rm",
            "hashicorp/terraform-mcp-server"
          ]
        }
      }
    }

    Global path: ~/.cursor/mcp.json. Reload window after editing.

    .vscode/mcp.json
    {
      "servers": {
        "terraform": {
          "command": "docker",
          "args": [
            "run",
            "-i",
            "--rm",
            "hashicorp/terraform-mcp-server"
          ]
        }
      }
    }

    VS Code uses the "servers" key (not "mcpServers").

    ~/.codeium/windsurf/mcp_config.json
    {
      "mcpServers": {
        "terraform": {
          "command": "docker",
          "args": [
            "run",
            "-i",
            "--rm",
            "hashicorp/terraform-mcp-server"
          ]
        }
      }
    }

    Open via Cascade → hammer icon → Configure.

    cline_mcp_settings.json
    {
      "mcpServers": {
        "terraform": {
          "command": "docker",
          "args": [
            "run",
            "-i",
            "--rm",
            "hashicorp/terraform-mcp-server"
          ]
        }
      }
    }

    Open via the Cline sidebar → MCP Servers → Edit.

    ~/.continue/config.json
    {
      "experimental": {
        "modelContextProtocolServers": [
          {
            "transport": {
              "type": "stdio",
              "command": "docker",
              "args": [
                "run",
                "-i",
                "--rm",
                "hashicorp/terraform-mcp-server"
              ]
            }
          }
        ]
      }
    }

    Continue uses modelContextProtocolServers with a transport block.

    ~/.codex/config.toml
    # ~/.codex/config.toml
    [mcp_servers.terraform]
    command = "docker"
    args = [
      "run",
      "-i",
      "--rm",
      "hashicorp/terraform-mcp-server",
    ]

    Codex uses TOML. Each server is a [mcp_servers.<name>] subtable.

    ~/.config/zed/settings.json
    {
      "context_servers": {
        "terraform": {
          "command": {
            "path": "docker",
            "args": [
              "run",
              "-i",
              "--rm",
              "hashicorp/terraform-mcp-server"
            ]
          }
        }
      }
    }

    Zed calls them "context_servers". Settings live-reload on save.

    ChatGPT → Apps directory

    Terraform doesn't ship a hosted HTTPS endpoint today. ChatGPT supports remote MCP servers only — to use this server in ChatGPT you'll need to deploy it to a public HTTPS URL first (e.g. via Cloudflare Workers or Vercel) or wait for an official remote build.

  2. 2

    Set required secrets

    No credentials required — this MCP runs over stdio without authentication.

  3. 3

    Try a minimum working prompt

    Minimum working prompt pending verification. Try any prompt from the MCP’s README once installed.

Tools & permissions

ToolDescriptionArgsSide effects
search_providersSearch the Terraform Registry for providers.Read
get_latest_provider_versionGet the latest published version of a provider.Read
search_modulesSearch the Terraform Registry for modules.Read
get_module_detailsGet documentation and inputs/outputs for a registry module.Read
search_policiesSearch Sentinel policy libraries in the registry.Read
list_workspacesList HCP Terraform / Enterprise workspaces in an organization.Read
create_workspaceCreate a new workspace.Write
create_runQueue a plan/apply run on a workspace.Write
get_plan_detailsGet the details of a run plan.Read

Security & scope

Access scope
Read + write
Sandbox
Runs over stdio or streamable-http. Registry search needs no credentials; HCP Terraform and Enterprise operations authenticate with a Terraform token whose org and workspace permissions bound what the tools can touch. HashiCorp's own README warns the server may expose Terraform data to the MCP client and LLM, and says not to use it with untrusted clients or models.
Gotchas
  • create_run queues real plan/apply runs — on an auto-apply workspace that is a live infrastructure change, not a dry run.
  • Workspace variables are readable through the tools and frequently contain secrets; scope the token to workspaces you are willing to expose.

Agent prompt pack

— copy into Claude, Cursor, or ChatGPT.
Paste into Claude, Cursor, or ChatGPT. Edit the [brackets] before sending.
Recommend the best MCP servers for [task: e.g. cloud & infrastructure work] in [client: Claude].

Constraints:
- Prefer tools that are [official | open-source | read-only] — pick what matters for my use case.
- Exclude MCPs that require [e.g. a paid plan, OAuth-only flows, remote-only transport].
- Return at most 3 picks, ranked.

For each pick include:
1. One-sentence rationale.
2. The ready-to-paste install snippet for my client.
3. Any required secrets I need to create before installing.

Cross-check the top-mcps.com listing: https://top-mcps.com/top-mcps-for-cloud-infrastructure
Compare Terraform against a real alternative. Swap the second MCP in [brackets] if you want a different match.
Compare Terraform MCP vs [AWS MCP] for the following job: [describe the job, e.g. "let an agent create GitHub issues on bug triage"].

Judge them on:
- Setup time and complexity (what a new user hits first).
- Auth model (none / API key / OAuth 2.1) and credential risk.
- Transport (stdio / Streamable HTTP / SSE) and where the server runs.
- Required secrets and the blast radius if they leak.
- Operational risk in an unattended agent loop.
- Which one is "good enough" for a weekend prototype vs. production.

End with one sentence: which should I pick for my scenario, which is: [my scenario].

References:
- https://top-mcps.com/mcp/terraform
- top-mcps.com listing for AWS
Asks the agent to install and verify. Works inside Claude Code, Cursor Agent, Codex CLI.
Install the Terraform MCP server for my [client: Claude] at the default config path for that client.

Use the exact install snippet published at https://top-mcps.com/mcp/terraform (fetch https://top-mcps.com/mcp/terraform.json for the canonical server.json if you can read URLs).

Before finishing:
1. Create the required secrets (no secrets) and put them in the appropriate env block — do not hard-code them.
2. Restart or reload the client so it picks up the new server.
3. Verify the server is connected (green / running state) and at least one tool is listed.
4. If anything fails, read the client's MCP logs and report the exact error — do not silently retry.

Confirm when done and list the tools the server now exposes.

Frequently asked questions

What changed

3 updates tracked.
  1. v1.2.0 released

  2. v1.1.0 released

  3. v1.0.0 released

More Cloud & Infrastructure MCPs

Other tools in the same category worth evaluating.

Full Supabase access: database, auth, storage, and edge functions.

supabase, database, backend, postgres
5 minLow
Official

Manage payments, customers, and subscriptions through Stripe.

stripe, payments, billing, invoicing
5 minMedium
Cloudflare
Official

Manage Workers, R2 buckets, DNS, and edge policies on Cloudflare.

cloudflare, edge, workers, dns
10 minMedium

Compared with Terraform

Side-by-side breakdowns for the choices people most often weigh against this MCP.

Exploring Top MCPs for Cloud & Infrastructure? See all Cloud & Infrastructure MCPs →