Extend IaC Code with MCP

Updated at:

IaC Code acts as a Model Context Protocol (MCP) client that connects to external tools, services, and data sources. This topic walks you through adding, verifying, and invoking MCP servers, and covers remote servers, configuration scopes, and security requirements.

Prerequisites

  • You have completed the operations in Install and configure IaC Code.

  • You are in the project directory where you want to use the MCP server.

  • Node.js and npx are installed if you plan to run the Stdio example in this topic.

  • The MCP Server’s source, startup command, dependency versions, and required permissions have been reviewed.

Supported connection methods

IaC Code supports MCP Servers of the Stdio, HTTP, SSE, and URL-only WebSocket types, and can discover their tools, resources, and prompts. An MCP Server can be launched as a local subprocess or accessed as a remote service.

Add and verify a local MCP server

The following example uses the official Filesystem MCP Server with access restricted to the current project directory.

Run the following command in the project root directory:

iac-code mcp add filesystem \
  --scope local \
  -- npx -y @modelcontextprotocol/server-filesystem "$PWD"

IaC Code writes the filesystem server to the local MCP configuration of the current project. Verify the configuration and run a health check:

iac-code mcp list
iac-code mcp get filesystem --scope local --check

The list shows the server name, the local scope, and the stdio transport type. In the health check output, connection_state is connected and the number of discovered tools appears. The Filesystem MCP Server does not provide resource or prompt interfaces, so the corresponding capability probes may return Method not found. This does not affect the tools that are already discovered. The health check connects only briefly and exits automatically after it finishes.

Invoke MCP tools

Use the REPL

  1. Run iac-code in the same project directory.

  2. Enter /mcp, select filesystem, and review its connection state and tool list.

  3. Enter the following request:

    Use the filesystem MCP Server to list the entries in the root directory of the current project. Read only, and do not modify any files.
  4. Review the tool name, parameters, and accessible directory, and then approve the read-only call.

    IaC Code calls the directory read tool that filesystem provides and returns the entries in the current project. After you finish the verification, remove the configuration if you no longer need it:

iac-code mcp remove filesystem --scope local

Manage and invoke MCP in the web version

Open a web session that uses the same project, and then go to Settings > Plugins > MCP. The web version supports the following management operations:

  • Add or edit Stdio, HTTP, SSE, and WebSocket servers.

  • View the scope, connection state, authentication state, error messages, and the discovered tools, resources, and prompts.

  • Enable, disable, or delete a configuration. Approve or reject a project-level server. Run a connection check.

  • Start a sign-in, re-authenticate, or clear authentication for remote servers that support OAuth.

After confirming that filesystem shows as connected, return to the session and submit the same directory read request as in the REPL. The Web version will display the MCP Server, tool parameters, and results in tool cards; after reviewing them, approve the read-only call. You can also add the above Filesystem configuration directly in the MCP panel without first running the CLI management command.

Connect to a remote MCP server

After you obtain the URL from the service provider, add the remote server with the HTTP transport:

iac-code mcp add --transport http <server-name> <https-mcp-server-url>

Verify the connection:

iac-code mcp get <server-name> --check

The health check reports connection_state as connected and lists the tools, resources, and prompts that the remote server provides.

If the service uses OAuth, authenticate and then verify:

iac-code mcp auth <server-name>
iac-code mcp get <server-name> --check

IaC Code opens or prints the authorization URL and receives the callback on the local loopback address. If the service requires a preassigned Client ID, Client Secret, or specific OAuth metadata, follow the GitHub MCP configuration documentation.

MCP configuration scopes

Scope

Default file

Description

user

~/.iac-code/settings.yml

Available to all projects of the current user.

local

<project>/.iac-code/settings.local.yml

Used only by the current checkout. Suitable for private configurations on the local machine.

project

<project>/.mcp.json

Can be shared by the project, but each server requires local trust approval.

session

Passed in when ACP creates a session

Takes effect only while the corresponding ACP session runs.

The .mcp.json file in a project can start a local process, so it is not trusted automatically. The interactive REPL prompts you to approve each server. Headless, ACP, and A2A modes do not prompt for approval. Project servers that are not yet approved are skipped with a warning.

Permissions and security

  • Server review — Connect only to trusted MCP servers. Before you use a server, review its source code, startup command, dependency versions, tool descriptions, and requested permissions.

  • Dependency management — Pin dependency versions for Stdio servers.

  • Network security — For remote servers, use HTTPS, trusted certificates, and authentication. Restrict the allowed domain names.

  • Secrets management — For secrets in MCP headers and environment variables, use ${VAR} references or OAuth secure storage. Do not write secrets into .mcp.json or a repository.

  • Permission control — MCP tools remain subject to the IaC Code permission framework. Apply least privilege to file writes, command execution, external network access, and write operations on the cloud. Check the parameters of every call.

  • Approval invalidation — Modifying the project MCP configuration invalidates existing approvals. Do not turn off security checks to remove approval prompts.

FAQ

The MCP server fails to start

Run iac-code mcp get <name> --config-only to check the redacted configuration, and then run iac-code mcp get <name> --check to view the bounded diagnostics. For a Stdio server, also confirm that the command exists, the dependencies are installed, and the working directory is correct. On Windows, a Node.js server usually must be started through cmd /c npx.

MCP tools are not visible

In /mcp in the REPL, or in Settings > Plugins > MCP in the web version, check whether the server is disabled, waiting for project approval, requires OAuth, or failed to connect. Reconnect after you change the configuration. On the command line, you can run iac-code mcp reconnect <name>.

You are still prompted as unauthenticated after OAuth completes

Confirm that the browser callback reaches the local machine that runs IaC Code, and then run the health check again. If you need to authorize again, first run iac-code mcp reset-auth <name> to clear the stored authentication state of the server, and then run iac-code mcp auth <name>.

References