PluginBench
MCP Server
Active

JFrog Remote MCP Server MCP Server

io.github.jfrog/jfrog-mcp-server

AI-powered access to JFrog artifact management, security scanning, and project resources.

What is the JFrog Remote MCP Server MCP server?

The JFrog Remote MCP Server integrates the JFrog platform with AI coding assistants and IDEs, enabling natural-language queries for artifact discovery, security monitoring, and resource management. It provides over 100 tools across Artifactory, Xray, and other JFrog services, automatically updated on the cloud-hosted remote server.

This MCP server connects your AI assistant to JFrog's artifact repository, security, and project management capabilities. Use it to discover packages and vulnerabilities, enforce approved dependencies, query OSS package information, track builds, and monitor security policies—all through conversational AI interactions.

How to install JFrog Remote MCP Server

Copy-paste configuration for popular MCP clients.

transport: http
Config generated by PluginBench — verify against the source before use.
~/.cursor/mcp.json
{
  "mcpServers": {
    "jfrog-mcp-server": {
      "url": "https://myPlatform.jfrog.github.io/mcp"
    }
  }
}

Tools & capabilities

Tools this server exposes to the agent.

  • Resource Management — Create and view projects, repositories, and other JFrog components.
  • Artifact & Build Discovery — Find packages and their versions, locate where artifacts are stored, and search builds using AQL.
  • Catalog and Curation — Access package information, versions, and vulnerabilities, and check curation status.
  • Security Monitoring — Get Xray security summaries and policy violations for artifacts, check scan/indexing status, and trace resources impacted by CVEs or packages.

Use cases

  • Ensure only approved packages are used by developers during coding
  • Query the JFrog Catalog about OSS package versions, vulnerabilities, and license requirements
  • Track and manage JFrog Projects and artifacts through natural language
  • Monitor security policies and CVE impacts across your artifact repositories
  • Discover package versions and their locations in your artifact storage

JFrog Remote MCP Server MCP server FAQ

What is the JFrog Remote MCP Server?

It's a cloud-hosted MCP server that connects AI assistants (Claude, Cursor, VS Code) to JFrog's artifact management, security scanning, and project management platform. It exposes over 100 tools for discovering packages, monitoring vulnerabilities, and managing resources.

Is it free?

The JFrog MCP Server is available to JFrog users with Cloud (SaaS) or Self-Managed subscriptions across all license types. Pricing depends on your JFrog subscription plan.

How do I install it in Cursor or Claude?

Add the server URL to your MCP client configuration (e.g., `https://<JFROG_PLATFORM_URL>/mcp` for Cursor), then restart your client. An OAuth window will open for authorization. See the README for VS Code and Cursor JSON config examples.

What authentication is required?

OAuth authentication is used. An Admin user must first enable the JFrog MCP Server on your JFrog platform, then you authorize your MCP client through an OAuth browser prompt.

Is this a remote or local server?

It's a remote server hosted on JFrog Cloud. You connect via HTTPS, and tools are automatically updated without requiring client-side upgrades.

What platforms are supported?

Supported on JFrog Cloud (SaaS) and Self-Managed platforms. The remote server is GA on SaaS; self-managed deployment is in Beta.

README (reference)

Source of truth, from the repository.

MCP Client

JFrog Remote MCP Server

The Model Context Protocol (MCP) connects AI systems with external tools, data, and services using a standardized, lightweight interface.

JFrog MCP Server empowers developers, bringing the advanced capabilities of the JFrog platform to the development environment. The JFrog MCP Server integrates with IDEs and AI coding assistants such as VS Code, Cursor, Claude, Kiro, and Codex to respond to natural-language AI queries with rich, actionable information from the JFrog platform.

Among the capabilities you can access with direct, friendly AI interactions:

  • Resource Management: Create and view projects, repositories, and other JFrog components.
  • Artifact & Build Discovery: Find packages and their versions, locate where artifacts are stored, and search builds using AQL.
  • Catalog and Curation: Access package information, versions, and vulnerabilities, and check curation status.
  • Security Monitoring: Get Xray security summaries and policy violations for artifacts, check an artifact's scan/indexing status, and trace every resource impacted by a specific CVE or package.

Use these resources and real-time information for various use cases. For example:

  • Ensure that only approved packages are used by developers during coding.
  • Query the JFrog Catalog about OSS package versions, changes in reported vulnerabilities, and license requirements.
  • Track and manage JFrog Projects and artifacts.

And much more. See the full tool reference for everything the server exposes.

Note: The JFrog MCP Server is now generally available (GA) on JFrog Cloud (SaaS). The self-managed server is in Beta. Individual tools marked Beta in the tool reference are experimental and must be enabled for your environment.

Remote Server Implementation

The JFrog MCP Server is hosted on JFrog Cloud, and the tools it provides to the client are continuously updated — you automatically get new features and improvements as they are released, with no installation or upgrade required on the client side.

You connect to the JFrog MCP Server using OAuth for authentication. This eliminates the need to manage API keys.

Note: Because this is a remote server, the tool set evolves on the server. The TOOLS.md reference reflects the current tool surface.

Set up the JFrog MCP Server

The JFrog Remote MCP Server is generally available (GA) to JFrog users with a Cloud (SaaS) subscription.

Subscription information: Supported on the Cloud (SaaS) and Self-Managed platforms for all licenses.

Self-Managed (Beta): A self-managed JFrog MCP Server is also available. See MCP Server Installation for Helm and Docker Compose deployment.

  1. An Admin user must enable the JFrog MCP Server on a JPD in the subscription.
  2. You can then add the JFrog MCP Server to an MCP client.
  3. Save the configuration file.
  4. Restart or refresh your MCP client. An OAuth window opens in your browser.
  5. Follow the prompts to authorize your MCP client to access the JFrog MCP Server.

In the examples below, replace <JFROG_PLATFORM_URL> with your JFrog platform URL (for example, https://mycompany.jfrog.io).

Visual Studio Code

{
  "mcp": {
    "servers": {
      "jfrog": {
        "url": "https://<JFROG_PLATFORM_URL>/mcp"
      }
    }
  }
}

Cursor

{
  "mcpServers": {
    "jfrog": {
      "url": "https://<JFROG_PLATFORM_URL>/mcp"
    }
  }
}

For more MCP clients (Kiro, Claude, Codex, and others), see Add the JFrog MCP Server to an MCP client.

Tools

The server exposes over 100 tools across Access, Artifactory, Security, Curation, Distribution, Grid, Workers, OneModel, Event, Evidence, and AppTrust.

See the full reference in TOOLS.md.

Documentation

Related MCP servers

Search the web and extract article text for LLMs.

2
C#
MIT
View repository →

Start with analyze_ev_site(address) for a free, source-backed EV charging opportunity screen.

0
HTML
View repository →

Discover, route, and hand off enterprise operations problems without exposing private records.

AI interview practice and career preparation with user-controlled guidance.

Capital-fit research and founder readiness with human-confirmed checkout.

Event discovery and promotion workflows with human-controlled publishing and commerce.