Extend IaC Code with MCP
IaC Code acts as a Model Context Protocol (MCP) client that connects to external tools, services, and data sources. This topic walks you through adding, verifying, and invoking MCP servers, and covers remote servers, configuration scopes, and security requirements.
Prerequisites
You have completed the operations in Install and configure IaC Code.
You are in the project directory where you want to use the MCP server.
Node.js and
npxare installed if you plan to run the Stdio example in this topic.The MCP Server’s source, startup command, dependency versions, and required permissions have been reviewed.
Supported connection methods
IaC Code supports MCP Servers of the Stdio, HTTP, SSE, and URL-only WebSocket types, and can discover their tools, resources, and prompts. An MCP Server can be launched as a local subprocess or accessed as a remote service.
Add and verify a local MCP server
The following example uses the official Filesystem MCP Server with access restricted to the current project directory.
Run the following command in the project root directory:
iac-code mcp add filesystem \
--scope local \
-- npx -y @modelcontextprotocol/server-filesystem "$PWD"IaC Code writes the filesystem server to the local MCP configuration of the current project. Verify the configuration and run a health check:
iac-code mcp list
iac-code mcp get filesystem --scope local --checkThe list shows the server name, the local scope, and the stdio transport type. In the health check output, connection_state is connected and the number of discovered tools appears. The Filesystem MCP Server does not provide resource or prompt interfaces, so the corresponding capability probes may return Method not found. This does not affect the tools that are already discovered. The health check connects only briefly and exits automatically after it finishes.
Invoke MCP tools
Use the REPL
Run
iac-codein the same project directory.Enter
/mcp, selectfilesystem, and review its connection state and tool list.Enter the following request:
Use the filesystem MCP Server to list the entries in the root directory of the current project. Read only, and do not modify any files.Review the tool name, parameters, and accessible directory, and then approve the read-only call.
IaC Code calls the directory read tool that
filesystemprovides and returns the entries in the current project. After you finish the verification, remove the configuration if you no longer need it:
iac-code mcp remove filesystem --scope localManage and invoke MCP in the web version
Open a web session that uses the same project, and then go to Settings > Plugins > MCP. The web version supports the following management operations:
Add or edit
Stdio,HTTP,SSE, andWebSocketservers.View the scope, connection state, authentication state, error messages, and the discovered tools, resources, and prompts.
Enable, disable, or delete a configuration. Approve or reject a project-level server. Run a connection check.
Start a sign-in, re-authenticate, or clear authentication for remote servers that support
OAuth.
After confirming that filesystem shows as connected, return to the session and submit the same directory read request as in the REPL. The Web version will display the MCP Server, tool parameters, and results in tool cards; after reviewing them, approve the read-only call. You can also add the above Filesystem configuration directly in the MCP panel without first running the CLI management command.
Connect to a remote MCP server
After you obtain the URL from the service provider, add the remote server with the HTTP transport:
iac-code mcp add --transport http <server-name> <https-mcp-server-url>Verify the connection:
iac-code mcp get <server-name> --checkThe health check reports connection_state as connected and lists the tools, resources, and prompts that the remote server provides.
If the service uses OAuth, authenticate and then verify:
iac-code mcp auth <server-name>
iac-code mcp get <server-name> --checkIaC Code opens or prints the authorization URL and receives the callback on the local loopback address. If the service requires a preassigned Client ID, Client Secret, or specific OAuth metadata, follow the GitHub MCP configuration documentation.
MCP configuration scopes
Scope | Default file | Description |
|
| Available to all projects of the current user. |
|
| Used only by the current checkout. Suitable for private configurations on the local machine. |
|
| Can be shared by the project, but each server requires local trust approval. |
| Passed in when ACP creates a session | Takes effect only while the corresponding ACP session runs. |
The .mcp.json file in a project can start a local process, so it is not trusted automatically. The interactive REPL prompts you to approve each server. Headless, ACP, and A2A modes do not prompt for approval. Project servers that are not yet approved are skipped with a warning.
Permissions and security
Server review — Connect only to trusted MCP servers. Before you use a server, review its source code, startup command, dependency versions, tool descriptions, and requested permissions.
Dependency management — Pin dependency versions for Stdio servers.
Network security — For remote servers, use HTTPS, trusted certificates, and authentication. Restrict the allowed domain names.
Secrets management — For secrets in MCP headers and environment variables, use
${VAR}references orOAuthsecure storage. Do not write secrets into.mcp.jsonor a repository.Permission control — MCP tools remain subject to the IaC Code permission framework. Apply least privilege to file writes, command execution, external network access, and write operations on the cloud. Check the parameters of every call.
Approval invalidation — Modifying the project MCP configuration invalidates existing approvals. Do not turn off security checks to remove approval prompts.
FAQ
The MCP server fails to start
Run iac-code mcp get <name> --config-only to check the redacted configuration, and then run iac-code mcp get <name> --check to view the bounded diagnostics. For a Stdio server, also confirm that the command exists, the dependencies are installed, and the working directory is correct. On Windows, a Node.js server usually must be started through cmd /c npx.
MCP tools are not visible
In /mcp in the REPL, or in Settings > Plugins > MCP in the web version, check whether the server is disabled, waiting for project approval, requires OAuth, or failed to connect. Reconnect after you change the configuration. On the command line, you can run iac-code mcp reconnect <name>.
You are still prompted as unauthenticated after OAuth completes
Confirm that the browser callback reaches the local machine that runs IaC Code, and then run the health check again. If you need to authorize again, first run iac-code mcp reset-auth <name> to clear the stored authentication state of the server, and then run iac-code mcp auth <name>.