Skip to main content

Hex-Rays IDA MCP

⚠️ Experimental prerelease ⚠️

Official Hex-Rays IDA MCP Server.

Installation

Requirements

  • Installed in your PATH
  • IDA 9.4 or higher with idalib and Python 3.11+
  • Other IDA MCP servers must be disabled to reduce agent confusion

IDA GUI Plugin

To support IDA GUI instances when using Hex-Rays IDA MCP, install the plugin:

uvx ida-hcli plugin install https://github.com/HexRaysSA/ida-mcp
# or if you have hcli installed:
hcli plugin install https://github.com/HexRaysSA/ida-mcp

Note: Without the GUI plugin, IDA MCP will only work headlessly.

Claude Code

# Add Hex-Rays marketplace
claude plugin marketplace add HexRaysSA/claude-marketplace
# Install plugin
claude plugin install ida-mcp@HexRaysSA
# Update to latest version
claude plugin update ida-mcp@HexRaysSA

Codex CLI

# Add Hex-Rays marketplace
codex plugin marketplace add HexRaysSA/codex-marketplace
# Install plugin
codex plugin add ida-mcp@HexRaysSA

GitHub Copilot CLI

# Add Hex-Rays marketplace
copilot plugin marketplace add HexRaysSA/copilot-marketplace
# Install plugin
copilot plugin install ida-mcp@HexRaysSA
# Update to latest version
copilot plugin update ida-mcp

Pi

# Install extension
pi install git:github.com/HexRaysSA/ida-mcp@latest
# Update to latest version
pi update --extensions

oh-my-pi

# Install extension
omp plugin install github:HexRaysSA/ida-mcp#latest
# Update to latest version
omp plugin upgrade

Other agents

Configure a regular stdio MCP server in your MCP JSON configuration:

{
  "mcpServers": {
    "ida": {
      "command": "uvx",
      "args": [
        "--exclude-newer=1s",
        "ida-mcp",
        "stdio",
        "--agent=my-agent"
      ]
    }
  }
}

uvx resolves the latest stable ida-mcp release from PyPI, so this configuration does not need to be updated for each release.

--agent=my-agent is a human-chosen label (like claude-code, cursor, my-custom-agent, etc.) used to differentiate sessions in the dashboard.

Commands

Every invocation requires a subcommand:

# MCP server over standard input/output
uvx ida-mcp stdio --agent=my-agent

# MCP server over Streamable HTTP
uvx ida-mcp http --host 127.0.0.1 --port 8737

# Inspect semantic MCP sessions
uvx ida-mcp dashboard --open

# Export sessions, linked agent transcripts, and Nexus worker logs
uvx ida-mcp logs

# Agent integrations use these as pre-tool hooks
uvx ida-mcp hook claude
uvx ida-mcp hook codex
uvx ida-mcp hook copilot

Semantic session files remain in the shared IDA Nexus state directory under sessions/, including when IDA_NEXUS_STATE_DIR overrides that directory.

Embedding

The server API is available from ida_mcp.mcp for applications that need to add tools or host Streamable HTTP themselves:

from ida_mcp.mcp import serve_http, stop_http_server, tool


@tool
def application_status() -> str:
    """Return the embedding application's status."""
    return "ready"


serve_http("127.0.0.1", 8737, path_prefix="/hex-rays")
# Later, during application shutdown:
stop_http_server()

serve_http() also accepts a DatabaseManager subclass and constructor arguments for hosts that provide custom database resolution. See the architecture documentation for lifecycle, tracing, and archive details.

We tested the following clients, but any MCP client should work similarly:

Example Usage

Start your agent harness and ask it something like:

Reverse /path/to/sample.elf for me

To test the GUI integration, open something in IDA and ask your harness:

What do I have open in the IDA GUI?

Developers: IDA Nexus

The IDA MCP project is built on IDA Nexus, which allows multiple clients to seamlessly share and operate on IDA databases.

You can build your own tools on top of the ida-nexus library, see the documentation for more information.

Release files for ida-mcp 20260918.0.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for ida-mcp 20260918.0.1
File Size Uploaded
ida_mcp-20260918.0.1.tar.gz 112.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for ida-mcp 20260918.0.1
File Interpreter ABI Platform
ida_mcp-20260918.0.1-py3-none-any.whl Python 3 none any Details

Total release size: 160.0 kB

Release files / ida_mcp-20260918.0.1.tar.gz

Download URL ida_mcp-20260918.0.1.tar.gz
Size 112.4 kB
Tags Source
SHA-256 checksum
How to use checksums
84eb177b0847484907f93212b68cce6ef33bccfca5b98e7a1091e74626662d85
BLAKE2b-256 checksum
How to use checksums
f792e60d16a6bec680ba626b3f99c0e5133978599316885df033d5f84c375bbd
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.10.6 {"installer":{"name":"uv","version":"0.10.6","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 18, 2026.

Transparency log

Release files / ida_mcp-20260918.0.1-py3-none-any.whl

Download URL ida_mcp-20260918.0.1-py3-none-any.whl
Size 47.7 kB
Tags Python 3
SHA-256 checksum
How to use checksums
dbb901fbf719d888f53eefe6b000a12ec5dd21e1992a93a25aed3757424557cc
BLAKE2b-256 checksum
How to use checksums
57cce3886310fcdbf787dc9bc7a6dd99ab2cdf5983a9c0907a545475ad25c359
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.10.6 {"installer":{"name":"uv","version":"0.10.6","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 18, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

20260918.0.1 This release

2 release files

3.0.3

2 release files

3.0.2

2 release files

3.0.1

2 release files

3.0.0

2 release files

2.2.2

2 release files

2.2.1

2 release files

2.2.0

2 release files

2.1.0

2 release files

2.0.4

2 release files

2.0.3

2 release files

2.0.2

2 release files

2.0.1

2 release files

2.0.0

2 release files

1.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page