Skip to main content

MCPyIDA

An MCP (Model Context Protocol) server that exposes IDA Pro reverse-engineering capabilities to LLM clients.

MCPyIDA exposes binary analysis capabilities via MCP: decompilation, disassembly, symbol lookup, cross-references, type inspection, structure recovery, binary patching, and scriptable analysis.

Related project: If you use Ghidra rather than IDA Pro, see MCPyGhidra for an equivalent MCP server for Ghidra.

Prerequisites

  • IDA Pro 9.x or later with idalib (tested with IDA Pro 9.2+; download)
  • Python 3.10–3.12

Note: IDA Pro is commercial software. A valid IDA Pro license is required. MCPyIDA does not bundle or distribute IDA Pro; you must supply your own installation.

Installation

1. Create a virtual environment (recommended)

python3 -m venv idavenv
source idavenv/bin/activate

2. Install MCPyIDA

pip install mcpyida

3. Register MCPyIDA as an IDA plugin

mcpyida_install

Alternative: IDA Plugin Manager (IDA Pro 9.0+)

If you run IDA Pro 9.0 or newer, you can install the GUI plugin via the Hex-Rays IDA Plugin Manager instead of steps 2–3:

hcli plugin install mcpyida

This pulls the mcpyida package from PyPI and registers the plugin loader automatically. Headless mode is not installed this way — use pip install mcpyida (see below) for headless/idalib usage.

4. Configure IDA to use your virtual environment

Point IDA's IDAPython at the same virtual environment. The exact steps depend on your IDA Pro version and OS; see the IDA Pro documentation for details on configuring IDAPython's Python interpreter.

Quick Start

GUI Mode (IDA Pro running interactively)

  1. Launch IDA Pro and open a binary.
  2. Go to Edit → Plugins → MCPyIDA (or the MCP menu added by the plugin).
  3. Start the MCP server.
  4. The server URL appears in the output window, e.g.: http://127.0.0.1:6050/sse/

Headless Mode

Launch the MCP server without the IDA GUI (requires idalib):

export IDADIR=/path/to/idapro
mcpyida-headless /path/to/firmware.elf

The server prints a JSON readiness signal to stdout:

{"status": "ready", "host": "127.0.0.1", "port": 6050, "binary": "/path/to/firmware.elf"}

Connecting an MCP Client

Point any MCP-compatible client (Claude Desktop, VS Code MCP extension, etc.) at the running server:

{
  "mcpServers": {
    "ida": {
      "type": "streamable-http",
      "url": "http://127.0.0.1:6050/mcp"
    }
  }
}

What's Exposed

MCPyIDA exposes tools organized into categories:

  • Listing & context: list entries, inspect binary metadata, resolve functions
  • Analysis: decompile, disassemble, cross-references, control-flow graphs
  • Types: type enumeration and detailed inspection
  • Modification: rename symbols, update variables, set comments, patch instructions
  • Scripting: Python code execution with back-to-client RPC callbacks
  • Search: binary pattern and instruction sequence matching

Troubleshooting

IDA does not load the plugin after mcpyida_install

Ensure your IDAPython interpreter is pointing at the virtual environment where mcpyida is installed. The mcpyida_install command copies the plugin loader into IDA's plugin directory; the loader itself must be able to import mcpyida at runtime.

mcpyida-headless exits immediately with an idalib error

Set IDADIR to the root of your IDA Pro installation (the directory containing idalib.so / idalib.dll). Verify the path is correct and that your IDA Pro license is valid and reachable.

Port 6050 is already in use

Pass --port <number> to mcpyida-headless, or configure the port in the plugin's settings panel when running in GUI mode.

MCP client reports connection refused

Confirm the server started successfully (look for the JSON readiness signal or check IDA's output window). The default transport is streamable-http on http://127.0.0.1:6050/mcp; older clients that only support SSE can connect to http://127.0.0.1:6050/sse/.

Development

Setup

git clone https://github.com/nightwing-us/mcpyida.git
cd mcpyida
pip install -e ".[dev]"

Testing

Unit tests (no IDA Pro required):

pytest tests/unit/ -v --tb=short

Integration and e2e tests require IDA Pro / idalib and are run in a CI environment with an IDA Pro license available.

Type Checking

mypy

Linting

ruff check src tests
ruff format src tests

Related Projects

MCPyIDA and MCPyGhidra are maintained in parallel as sister projects with intended feature parity — MCPyIDA targets IDA Pro and MCPyGhidra targets Ghidra.

  • MCPyGhidra — equivalent MCP server for Ghidra (free, open-source RE tool)
  • pyghidra-decaf — Python-native Ghidra plugin development framework (underpins MCPyGhidra)

License

Apache-2.0 — see LICENSE for details.

Copyright © 2026 Nightwing Group, LLC.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

mcpyida-0.8.0.tar.gz (216.6 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

mcpyida-0.8.0-py3-none-any.whl (102.7 kB view details)

Uploaded Python 3

File details

Details for the file mcpyida-0.8.0.tar.gz.

File metadata

  • Download URL: mcpyida-0.8.0.tar.gz
  • Upload date:
  • Size: 216.6 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for mcpyida-0.8.0.tar.gz
Algorithm Hash digest
SHA256 53a462edec911a050a9ec2d5b73cf04f8b7e43cbabe07b7a86d9bdb0af99055e
MD5 302ef050e7e631d2848ae95fc281a300
BLAKE2b-256 04370a05ca0f1c0108e81665d45f649adb06df4ad6e48c507720824d01458626

See more details on using hashes here.

Provenance

The following attestation bundles were made for mcpyida-0.8.0.tar.gz:

Publisher: release.yml on nightwing-us/mcpyida

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file mcpyida-0.8.0-py3-none-any.whl.

File metadata

  • Download URL: mcpyida-0.8.0-py3-none-any.whl
  • Upload date:
  • Size: 102.7 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for mcpyida-0.8.0-py3-none-any.whl
Algorithm Hash digest
SHA256 71926a781ba05c051b5fcb8c3696d7bf3e664b93f530fa07a332b4c1bd97b9ad
MD5 7d3804992e791f319552c68704276f53
BLAKE2b-256 17213e8668984cfb40dd3d567e80140acd1a554b4c6b274df8d72f2b1e67f54f

See more details on using hashes here.

Provenance

The following attestation bundles were made for mcpyida-0.8.0-py3-none-any.whl:

Publisher: release.yml on nightwing-us/mcpyida

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

This release

0.8.0 This release

2 files

0.7.3

2 files

0.7.2

2 files

0.7.1

2 files

0.7.0

2 files

0.6.0

2 files

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page