Back to Browse

Musicbrainz MCP Server

Developer ToolsModerate7.0Local
Free

MusicBrainz MCP — search/browse music metadata, cover art, and submit tags/ratings/collections

About

MusicBrainz MCP — search/browse music metadata, cover art, and submit tags/ratings/collections

Security Report

7.0
Moderate7.0Moderate Risk

This MusicBrainz MCP server is well-architected with proper authentication controls and no malicious patterns. OAuth credentials are correctly handled via environment variables, read operations are unauthenticated as intended, and write operations require explicit confirmation. Permissions align well with the server's purpose (music metadata queries and optional user submissions). Minor code quality observations around error handling and input validation do not significantly impact security. Supply chain analysis found 2 known vulnerabilities in dependencies (0 critical, 1 high severity). Package verification found 1 issue.

7 files analyzed · 7 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

What You'll Need

Set these up before or after installing:

Optional override for the User-Agent sent to MusicBrainz.Optional

Environment variable: MUSICBRAINZ_USER_AGENT

OAuth client ID (write tools only). Register at musicbrainz.org/account/applications.Required

Environment variable: MUSICBRAINZ_OAUTH_CLIENT_ID

OAuth client secret (write tools only).Required

Environment variable: MUSICBRAINZ_OAUTH_CLIENT_SECRET

OAuth refresh token with tag/rating/collection scopes (enables the write tools).Required

Environment variable: MUSICBRAINZ_OAUTH_REFRESH_TOKEN

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-chrischall-musicbrainz-mcp": {
      "env": {
        "MUSICBRAINZ_USER_AGENT": "your-musicbrainz-user-agent-here",
        "MUSICBRAINZ_OAUTH_CLIENT_ID": "your-musicbrainz-oauth-client-id-here",
        "MUSICBRAINZ_OAUTH_CLIENT_SECRET": "your-musicbrainz-oauth-client-secret-here",
        "MUSICBRAINZ_OAUTH_REFRESH_TOKEN": "your-musicbrainz-oauth-refresh-token-here"
      },
      "args": [
        "-y",
        "musicbrainz-mcp"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

musicbrainz-mcp

CI npm license

An MCP server for MusicBrainz, the open music encyclopedia. It gives Claude live access to MusicBrainz metadata — artists, releases, recordings, labels, works, and more — plus Cover Art Archive images, and (optionally) lets you submit your own tags, ratings, and collection edits.

Developed and maintained by AI (Claude Code). Use at your own discretion.

Tools

Read (no credentials required):

ToolWhat it does
musicbrainz_searchSearch any entity type with a Lucene query; returns ranked matches + MBIDs
musicbrainz_lookupLook up an entity by MBID, with inc subqueries for linked data
musicbrainz_browseList all entities linked to another (e.g. every release by an artist)
musicbrainz_cover_artCover Art Archive image URLs for a release / release-group
musicbrainz_resolveTurn a pasted musicbrainz.org URL into its entity
musicbrainz_healthcheckVerify connectivity and whether OAuth writes are configured

Write (OAuth, confirm-gated):

ToolWhat it does
musicbrainz_submit_tagsApply user tags to an entity on your account
musicbrainz_submit_ratingSet your 0–100 rating for an entity
musicbrainz_modify_collectionAdd/remove entities in one of your collections

Each write makes no network call without confirm: true; it returns a dry-run preview first.

Install

This is a Node MCP server (stdio). Point your MCP host at it:

{
  "mcpServers": {
    "musicbrainz": {
      "command": "npx",
      "args": ["-y", "musicbrainz-mcp"]
    }
  }
}

Reads work immediately. MusicBrainz asks clients to make at most one request per second — the server throttles itself to stay within that limit, so large browses are paced automatically.

Enabling the write tools (optional)

  1. Register an application at musicbrainz.org/account/applications (redirect URI urn:ietf:wg:oauth:2.0:oob).
  2. Complete the OAuth flow with the tag, rating, and collection scopes to obtain a refresh token.
  3. Provide these via your MCP host's env (or a local .env):
MUSICBRAINZ_OAUTH_CLIENT_ID=...
MUSICBRAINZ_OAUTH_CLIENT_SECRET=...
MUSICBRAINZ_OAUTH_REFRESH_TOKEN=...

Development

npm install
npm run build
npm test

See CLAUDE.md for architecture and docs/MUSICBRAINZ-API.md for the pinned API shapes.

License

MIT. Data from MusicBrainz, licensed under CC0 / CC BY-NC-SA.

Reviews

No reviews yet

Be the first to review this server!