re-mcp-ida
IDA Pro backend for RE-MCP — a headless IDA Pro MCP server using idalib. Exposes IDA's full analysis capabilities over the Model Context Protocol, letting LLMs drive reverse engineering directly.
This is a standalone server, not an IDA plugin. It uses idalib to run IDA's analysis engine without a GUI.
Requirements
- Python 3.12+
- IDA Pro 9+ with a valid license
- macOS, Windows, or Linux
Installation
uv tool install re-mcp-ida
Or with pip:
pip install re-mcp-ida
Finding IDA Pro
The server looks for your IDA Pro installation in the following order:
IDADIRenvironment variable — set this if IDA is in a non-standard location.- IDA's config file —
Paths.ida-install-dirin~/.idapro/ida-config.json(macOS/Linux) or%APPDATA%\Hex-Rays\IDA Pro\ida-config.json(Windows). - Platform-specific default paths (e.g.
/Applications/IDA Professional *.app/Contents/MacOSon macOS).
See the main documentation for the full list of default search paths per platform.
Usage
# Run the server (direct stdio mode)
re-mcp-ida
# Or with uvx (no install needed)
uvx re-mcp-ida
MCP client configuration
{
"mcpServers": {
"ida": {
"command": "uvx",
"args": ["re-mcp-ida"]
}
}
}
CLI subcommands
| Command | Description |
|---|---|
re-mcp-ida (or re-mcp-ida stdio) |
Direct stdio mode — single-session, workers die on disconnect (default) |
re-mcp-ida proxy |
Stdio proxy that auto-spawns a persistent HTTP daemon |
re-mcp-ida serve |
Start the HTTP daemon directly |
re-mcp-ida stop |
Gracefully shut down a running daemon |
re-mcp-ida backends |
List installed backends |
Environment variables
| Variable | Default | Description |
|---|---|---|
IDADIR |
(auto-detected) | Path to IDA Pro installation directory |
IDA_MCP_MAX_WORKERS |
(unlimited) | Maximum simultaneous databases (1-8) |
IDA_MCP_LOG_LEVEL |
WARNING |
Logging level |
IDA_MCP_LOG_DIR |
(unset) | Directory for per-run log files |
IDA_MCP_IDLE_TIMEOUT |
300 |
Auto-shutdown timeout in seconds (0 to disable) |
IDA_MCP_ALLOW_SCRIPTS |
(unset) | Set to 1, true, or yes to enable run_script for arbitrary IDAPython |
Features
- Full decompilation and disassembly
- Function, type, and structure management
- Cross-reference and call graph analysis
- String and byte pattern search
- Binary patching and instruction assembly
- FLIRT signature and type library support
- MCP prompts for guided workflows (binary triage, function analysis, crypto detection, etc.)
- Multi-database support with concurrent analysis
- MCP resources for structured read-only access
See the main documentation for the full tool catalog, multi-database workflows, and detailed usage.
License
Dual-licensed under MIT and Apache-2.0.
Metadata
Release files for re-mcp-ida 3.0.3
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| re_mcp_ida-3.0.3.tar.gz | 102.8 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| re_mcp_ida-3.0.3-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 248.8 kB
Release files / re_mcp_ida-3.0.3.tar.gz
| Download URL | re_mcp_ida-3.0.3.tar.gz |
|---|---|
| Size | 102.8 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
875a2d417010b722bf51246532652ed19c2b7afca01ecb8a035a1083cd12af90
|
|
BLAKE2b-256 checksum How to use checksums |
0862f9bcec6d81e22dbeb79348e667e8993f753ecc3507f04b72686b6644a107
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jun 15, 2026.
Transparency logRelease files / re_mcp_ida-3.0.3-py3-none-any.whl
| Download URL | re_mcp_ida-3.0.3-py3-none-any.whl |
|---|---|
| Size | 146.0 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
cf7c20274708fa393d38c66f95f9380aeb12105250c07e7bb8b08dff99574a9f
|
|
BLAKE2b-256 checksum How to use checksums |
9a7eb073621e0f6dc56df80f0bd579fd427e779ca78ef88cb3d99d42c689fdf0
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jun 15, 2026.
Transparency log