Skip to main content

re-mcp-ida

IDA Pro backend for RE-MCP — a headless IDA Pro MCP server using idalib. Exposes IDA's full analysis capabilities over the Model Context Protocol, letting LLMs drive reverse engineering directly.

This is a standalone server, not an IDA plugin. It uses idalib to run IDA's analysis engine without a GUI.

Requirements

  • Python 3.12+
  • IDA Pro 9+ with a valid license
  • macOS, Windows, or Linux

Installation

uv tool install re-mcp-ida

Or with pip:

pip install re-mcp-ida

Finding IDA Pro

The server looks for your IDA Pro installation in the following order:

  1. IDADIR environment variable — set this if IDA is in a non-standard location.
  2. IDA's config file — Paths.ida-install-dir in ~/.idapro/ida-config.json (macOS/Linux) or %APPDATA%\Hex-Rays\IDA Pro\ida-config.json (Windows).
  3. Platform-specific default paths (e.g. /Applications/IDA Professional *.app/Contents/MacOS on macOS).

See the main documentation for the full list of default search paths per platform.

Usage

# Run the server (direct stdio mode)
re-mcp-ida

# Or with uvx (no install needed)
uvx re-mcp-ida

MCP client configuration

{
  "mcpServers": {
    "ida": {
      "command": "uvx",
      "args": ["re-mcp-ida"]
    }
  }
}

CLI subcommands

Command Description
re-mcp-ida (or re-mcp-ida stdio) Direct stdio mode — single-session, workers die on disconnect (default)
re-mcp-ida proxy Stdio proxy that auto-spawns a persistent HTTP daemon
re-mcp-ida serve Start the HTTP daemon directly
re-mcp-ida stop Gracefully shut down a running daemon
re-mcp-ida backends List installed backends

Environment variables

Variable Default Description
IDADIR (auto-detected) Path to IDA Pro installation directory
IDA_MCP_MAX_WORKERS (unlimited) Maximum simultaneous databases (1-8)
IDA_MCP_LOG_LEVEL WARNING Logging level
IDA_MCP_LOG_DIR (unset) Directory for per-run log files
IDA_MCP_IDLE_TIMEOUT 300 Auto-shutdown timeout in seconds (0 to disable)
IDA_MCP_ALLOW_SCRIPTS (unset) Set to 1, true, or yes to enable run_script for arbitrary IDAPython

Features

  • Full decompilation and disassembly
  • Function, type, and structure management
  • Cross-reference and call graph analysis
  • String and byte pattern search
  • Binary patching and instruction assembly
  • FLIRT signature and type library support
  • MCP prompts for guided workflows (binary triage, function analysis, crypto detection, etc.)
  • Multi-database support with concurrent analysis
  • MCP resources for structured read-only access

See the main documentation for the full tool catalog, multi-database workflows, and detailed usage.

License

Dual-licensed under MIT and Apache-2.0.

Metadata

Release files for re-mcp-ida 3.0.3

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for re-mcp-ida 3.0.3
File Size Uploaded
re_mcp_ida-3.0.3.tar.gz 102.8 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for re-mcp-ida 3.0.3
File Interpreter ABI Platform
re_mcp_ida-3.0.3-py3-none-any.whl Python 3 none any Details

Total release size: 248.8 kB

Release files / re_mcp_ida-3.0.3.tar.gz

Download URL re_mcp_ida-3.0.3.tar.gz
Size 102.8 kB
Tags Source
SHA-256 checksum
How to use checksums
875a2d417010b722bf51246532652ed19c2b7afca01ecb8a035a1083cd12af90
BLAKE2b-256 checksum
How to use checksums
0862f9bcec6d81e22dbeb79348e667e8993f753ecc3507f04b72686b6644a107
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.12

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jun 15, 2026.

Transparency log

Release files / re_mcp_ida-3.0.3-py3-none-any.whl

Download URL re_mcp_ida-3.0.3-py3-none-any.whl
Size 146.0 kB
Tags Python 3
SHA-256 checksum
How to use checksums
cf7c20274708fa393d38c66f95f9380aeb12105250c07e7bb8b08dff99574a9f
BLAKE2b-256 checksum
How to use checksums
9a7eb073621e0f6dc56df80f0bd579fd427e779ca78ef88cb3d99d42c689fdf0
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.12

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jun 15, 2026.

Transparency log
Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page