PluginBench
MCP Server
Active
MIT

arr-mcp MCP Server

io.github.bardesss/arr-mcp

One MCP server for your entire media stack: Radarr, Sonarr, Prowlarr, Bazarr, Jellyfin, Seerr and more.

What is the arr-mcp MCP server?

The arr-mcp MCP server unifies control over a complete media management stack—Radarr, Sonarr, Prowlarr, Bazarr, Jellyfin, Plex, Seerr, SABnzbd, Transmission, qBittorrent, Whisparr, and Profilarr—through a single endpoint. It correlates data across services to answer questions no single service can, diagnose missing content, validate quality profiles, and execute previewed writes with an audit trail.

arr-mcp bridges your entire media stack into one conversation. Instead of querying five services separately to answer "Why isn't my requested film showing up?", it walks the causal chain—requested, managed, monitored, downloaded, indexed, imported, scanned—and names the first thing that explains the absence. It offers 38 tools with consistent pagination and error messaging, treats indexer text as data (not instruction), makes all writes opt-in and previewed, and includes a browser config UI with diagnostics and audit logging.

How to install arr-mcp

Copy-paste configuration for popular MCP clients.

transport: stdio
Config generated by PluginBench — verify against the source before use.
Environment / auth
  • PUID

    User id owning the files in /config

  • PGID

    Group id owning the files in /config

  • TZ

    Timezone used for timestamps, e.g. Europe/Amsterdam

~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "arr-mcp": {
      "command": "docker",
      "args": [
        "run",
        "-i",
        "--rm",
        "ghcr.io/bardesss/arr-mcp:1.39.0",
        "-p",
        "6060:6060",
        "-v",
        "{config_dir}:/config"
      ],
      "env": {
        "PUID": "<YOUR_PUID>",
        "PGID": "<YOUR_PGID>",
        "TZ": "<YOUR_TZ>"
      }
    }
  }
}

Tools & capabilities

Tools this server exposes to the agent.

  • diagnose — Walks the entire chain from request through download to import to identify why content is missing or not available
  • list_movies — List movies from Radarr with pagination and filtering
  • list_series — List TV series from Sonarr with pagination and filtering
  • list_downloads — Show what is currently downloading across SABnzbd, Transmission, or qBittorrent
  • list_indexers — List indexers and their status, including any failures or errors
  • search_indexers — Search for releases across configured indexers
  • list_quality_profiles — Show quality profiles and their scoring rules
  • validate_profile — Check if a quality profile's arithmetic is achievable and identify conflicts
  • list_subtitles — List available subtitles from Bazarr
  • search_subtitles — Find and request subtitles for specific content
  • list_library — Show content in Jellyfin or Plex library
  • list_requests — Show pending requests in Seerr
  • request_content — Submit a request for new content via Seerr
  • pause_download_client — Pause SABnzbd, Transmission, or qBittorrent
  • resume_download_client — Resume a paused download client
  • list_seeding_rules — Show seeding rules and monitor active seeds
  • retry_failed_download — Retry a failed download or import
  • change_quality_profile — Reassign content to a different quality profile
  • unmonitor_content — Stop monitoring a series or movie (previewed before execution)
  • delete_files — Remove files from disk (previewed before execution)

Use cases

  • Diagnose why requested content is not appearing in your library and trace the issue across services
  • Search for and request new movies or TV shows, then monitor their download and import progress
  • Find highly-rated content from a specific year that you don't already own
  • Validate and fix quality profiles that are not behaving as intended
  • Manage downloads and seeding rules across SABnzbd, Transmission, or qBittorrent without switching tools

arr-mcp MCP server FAQ

What is arr-mcp?

arr-mcp is an MCP server that unifies control over your entire media stack—Radarr, Sonarr, Prowlarr, Bazarr, Jellyfin, Plex, Seerr, and download clients—into one conversation. It correlates data across services to answer questions no single service can answer alone.

Is arr-mcp free?

Yes, arr-mcp is open-source software licensed under MIT and free to use.

How do I install arr-mcp in Cursor or Claude?

Run arr-mcp as a Docker container (ghcr.io/bardesss/arr-mcp:latest) on your LAN, claim it via the browser UI at http://<host>:6060, add your services, then create an MCP token on the config page. Point your MCP client to http://<host>:6060/mcp with the token as a bearer header or URL parameter.

What authentication does arr-mcp require?

arr-mcp requires API keys or credentials for each service you configure (Radarr, Sonarr, etc.). For the MCP endpoint itself, you create an MCP token on the config page; it also accepts OAuth 2.1 access tokens if you run an identity provider.

Can I expose arr-mcp to the internet?

arr-mcp is not designed for internet exposure. It should run on your LAN only. If you must expose it, put it behind a reverse proxy with TLS and pin allowed_hosts in the config.

What services does arr-mcp support?

Radarr 4.0+, Sonarr 4.0+, Whisparr 2.x, Prowlarr 1.0+, Bazarr 1.4+, Jellyfin 10.9+, Plex Media Server 1.32+, Seerr 1.0+, SABnzbd 3.0+, Transmission 3.0+, qBittorrent 4.1+, and Profilarr 2.2.0+.

README (reference)

Source of truth, from the repository.

<div align="center"> <img src="assets/logo.svg" alt="" width="64" height="64">

arr-mcp

Talk to your entire media stack. One server, one endpoint, one conversation.

Radarr · Sonarr · Whisparr · Prowlarr · Bazarr · Jellyfin · Plex · Seerr · SABnzbd · Transmission · qBittorrent · Profilarr

Release CI Image Platforms Licence

<img src="screenshots/dashboard-dark.png" alt="The arr-mcp dashboard: every configured service tested live, with status, latency and version" width="880"> </div>

Everyone else ships one MCP server per service. This is one for the stack.

That difference is the whole point, because the interesting questions live between services:

"Why isn't the film I requested on Tuesday showing up in Jellyfin?"

No single service can answer that. It spans Seerr, Radarr, Prowlarr, SABnzbd and Jellyfin — five APIs, five sets of ids, five half-answers. arr-mcp correlates them and hands back the causal chain:

diagnose { query: "Blade" }

No file on disk yet. Trigger a search in Radarr or Sonarr — nothing is downloading and no indexer reported a failure.

One call. One answer. It even answers with a service down, and tells you which part it could not check rather than guessing across the hole.

Why people run it

🔍 diagnose answers what no single service canWalks the whole chain — requested, managed, monitored, downloaded, indexed, imported, scanned — and names the first thing that explains the absence.
🧮 Quality profiles that cannot do what they sayA minimum score nothing can reach, a language preferred but never required, a format scored where its wider twin sits at zero. The arithmetic ones are proved rather than guessed, and every fix names a change to make in Profilarr, which owns them.
🛡️ Indexer text is data, never instructionRelease names from public indexers are attacker-controllable and flow straight into model context. arr-mcp fences every one of them.
✋ Writes are opt-in, previewed, recordedOff until you turn them on, per service. Every write shows you exactly what it would do and waits for confirmation — and lands in an audit trail either way.
🖥️ A config page that diagnosesAdd services from a browser, see what is broken and what to do about it, read the logs and the write audit. No YAML required.
📚 Thirty-eight tools, one vocabularyEvery list pages the same way and answers readably whether or not your client reads structuredContent, every error names the config key that would fix it, every write takes ids rather than titles.

Nothing else in this space does the last five at all.

Quick start — about two minutes

Also in the repo as docker-compose.example.yml. On Unraid, use unraid/arr-mcp.xml instead — a Community Applications template with the appdata path and 99:100 ownership already set. It is not listed in CA yet, so for now drop it into /boot/config/plugins/dockerMan/templates-user/ and pick it from the template list under Add Container. Steps 1 to 3 below are the same once it starts.

On Proxmox VE, proxmox/ builds an unprivileged Debian LXC from source instead — no Docker anywhere. Run it on the host, not in a guest:

bash -c "$(curl -fsSL https://raw.githubusercontent.com/bardesss/arr-mcp/main/proxmox/ct/arr-mcp.sh)"

It defaults to 2 cores, 2 GB and 8 GB of disk — the memory is sized for the optional IMDb ingest, not for serving. config.yaml, the MCP tokens (hashed) and the databases live in /config, which an update does not touch; run update inside the container to rebuild it from the latest release. Re-running the command above on the host builds a second container instead. If it installs but never answers, journalctl -u arr-mcp is the log.

It follows the Community Scripts conventions but is not in their catalogue, and it has never been run on a real host — arm64 least of all, so the script asks rather than assuming. An install that worked is as useful to hear about as one that did not: #265. Steps 1 to 3 below are the same once it boots.

services:
  arr-mcp:
    image: ghcr.io/bardesss/arr-mcp:latest
    container_name: arr-mcp
    ports:
      - 6060:6060
    volumes:
      - ./config:/config
    environment:
      - PUID=1000
      - PGID=1000
      - TZ=Europe/Amsterdam
    restart: unless-stopped

1. Open http://<host>:6060 — the bare host, no path. Nothing to read out of the container log.

2. Claim it. The first page is a setup form rather than a sign-in: choose a username and a password of at least 12 characters.

[!IMPORTANT] Do this before exposing the port. Until it is claimed, whoever loads that page first owns the instance — and it holds every service's API key.

3. Add your services — Add a service, paste its URL and API key (or, for Transmission and qBittorrent, its username and password), save. It applies immediately; there is no restart. Configure only what you run. A config file that will not parse no longer takes the container down: arr-mcp serves a repair page with the error and an editor instead.

Your MCP client goes to http://<host>:6060/mcp with an MCP token. Create one on the config page; it is shown once, so copy it into your client straight away. Each token has its own tier and expiry, see MCP tokens. A client that can only be given a URL, not a header, can carry the token as ?token= instead — see allow_token_in_url. If you already run an identity provider, /mcp also accepts short-lived OAuth 2.1 access tokens, so each client gets its own credential and a scope that caps what it may do — read-only for one, writes for another, never more than config.yaml already permits. See auth.oauth. Everything the UI does is still just config.yaml, and editing that by hand remains supported. Clients that read the MCP Registry find it there as io.github.bardesss/arr-mcp.

Works with whatever you point at it. A client asking for Accept: application/json — or sending no Accept at all — gets one JSON object back with a Content-Length, rather than a refusal for not also naming text/event-stream. A client that does accept a stream still gets one. Even a refusal is JSON. So a plain curl works as-is, and so does a full MCP client.

Image tags are X.Y.Z, X.Y, X and latest, plus main for bleeding edge. Pin a minor — :1.6 — if you would rather approve each new tool surface yourself. Images are published for amd64 and arm64, so a Raspberry Pi or an ARM NAS runs the same build as everything else.

What you can ask it

Thirty-eight tools, but you never name them — you ask, and the model picks:

"What's downloading right now, and is anything stuck?" "What aired this week that I haven't watched?" "Which of my indexers are failing, and what did they say?" "Find me something highly rated from 1994 I don't already have." "Go and find Dutch subtitles for the film that just landed." "Not that release — grab the 1080p remux instead." "Why does this episode keep failing and never downloading?" "Pause SABnzbd, I need the bandwidth for an hour." "What are my seeding rules, and is anything still seeding past them?" "That download finished days ago and never got imported — sort it out." "Put this series on the 4K profile and only monitor future seasons." "This profile says it wants Dutch but keeps grabbing English — why?" "Has anything in Radarr drifted from what Profilarr set?" "Which of my shows have metadata that does not match the files?" "These episode titles are wrong for the files — fix them." "Unmonitor season 5 and delete its files." — previewed first, always.

Documentation

ToolsAll thirty-eight, what each answers, and the fields whose meaning is not obvious
WritesTurning them on, the two tiers, and the preview-and-confirm handshake
Configurationconfig.yaml, the seven services that take a list, Jellyfin's default_user
Config UIThe four pages, and what each does that is not obvious
Management APIJSON API for companion apps to see and manage services and tokens, with a key you generate on the config page
IMDb ratingsThe only way to get an IMDb score for a series, and what it costs
SecurityThe threat model, walked against the OWASP MCP Top 10, including what it does not solve
ContributingWhich services qualify, how to add an adapter, and the rules an AI agent tends to break

Requirements

  • At least one supported service, LAN-reachable: Radarr 4.0+, Sonarr 4.0+, Whisparr 2.x (V2 only, not Eros), Prowlarr 1.0+, Bazarr 1.4+, Jellyfin 10.9+, Plex Media Server 1.32+, Seerr 1.0+, SABnzbd 3.0+, Transmission 3.0+, qBittorrent 4.1+, Profilarr 2.2.0+
  • Docker, or Node 24+ to run from source
  • An MCP client speaking protocol revision 2026-07-28

Since 1.0 the tool surface is the public API: renaming or removing a tool, a parameter or a response field is a major, because that break is silent — a model stops finding a renamed tool rather than raising an error.

Contributing

Contributions are welcome, and new service adapters most of all — Lidarr, Emby and Deluge would all be accepted today, and the list says so in advance, along with the ones that would not be. An adapter is deliberately the most self-contained thing in the codebase. Two things to know first: not every service qualifies, and the bar is written down rather than decided per pull request — which services qualify. And I cannot test a service I do not run, so the second bar is that you tested it against your own live instance and the PR says what you tested and against which version.

One adapter remains unverified: qBittorrent. The maintainer runs neither Plex nor qBittorrent — testing means running a build against your own server and reporting what worked. Plex has since been verified against two live Plex Media Servers by two volunteer testers, its first write included, and its metadata repair ships off by default until it gets the same (#203); qBittorrent has shipped but still waits on the same kind of report. The design behind Plex, and what else is on the list.

AI-assisted contributions are welcome, held to the same bar and no other; arr-mcp is itself built with a coding agent. Point yours at CONTRIBUTING.md.

Missing a tool? Open an issue describing the question you could not get answered rather than the tool you think should exist. Often the answer is a new parameter on one that already exists — and when it genuinely needs a new tool, the question is what tells us so.

Security

arr-mcp is not designed to be exposed to the internet. The /mcp endpoint requires a bearer token because "LAN-only" is a network assumption rather than a security control — it fronts every service credential you configure and, once enabled, file deletion, and a home network contains guest phones and IoT devices. Put it behind a reverse proxy with TLS if it needs to leave the LAN, and pin allowed_hosts if you do.

Beyond the network: writes are off until you enable them, every write is previewed and confirmed before it acts, and everything a service returns is fenced as data rather than instruction. Security walks all of it against the OWASP MCP Top 10 — and is equally explicit about what it does not solve. Found something? SECURITY.md.

Thanks

arr-mcp is glue; the hard parts belong to other people. Every service it speaks to is free software maintained largely by volunteers — Radarr, Sonarr, Whisparr, Prowlarr, Bazarr, Jellyfin, Plex, Seerr, SABnzbd, Transmission, qBittorrent — as are the libraries it is built on: MCP TypeScript SDK, Hono, Zod, Pino, Vitest, yaml and TypeScript. If you find arr-mcp useful, consider supporting them first.

When you enable the IMDb dataset: information courtesy of IMDb, used with permission, for personal and non-commercial use.

Licence

MIT

Related MCP servers

Query normalized U.S. Congress STOCK Act trades with member, ticker, and performance data.

0
JavaScript
View repository →

Workflow timing analysis, configuration audit and billing insight for GitHub Actions.

3
TypeScript
MIT
View repository →

Correlates commits, PRs, issues and contributors between two git refs for release notes.

3
TypeScript
MIT
View repository →
TETest Intel logo

Coverage analysis, untested function detection and complexity scoring for TS and JS.

3
TypeScript
MIT
View repository →

AgencyAI's public MCP for service discovery and AI-readiness assessment.

View repository →
BABay Run logo

Bay Run

Active

Free OpenAI-compatible inference with signed provenance receipts and 3 focused MCP tools.

0
Python
View repository →