Skip to main content

streamlit-mcp

Serve any Streamlit app as an MCP server. Agents introspect your app's widgets, set values, click buttons, and read the rendered output and session_state — natively, over MCP, with no browser automation.

📖 Documentation: https://dkedar7.github.io/streamlit-mcp/

pip install streamlit-mcp          # or run with no install via: uvx streamlit-mcp ...

# serve an app over MCP (stdio for local clients)
streamlit-mcp serve app.py
# ...or HTTP/SSE on loopback for local networked agents
streamlit-mcp serve app.py --transport http --port 8000

# drive it yourself from the terminal (same engine the agent uses)
streamlit-mcp inspect app.py
streamlit-mcp call app.py --set "Name=agent" --click "Save" --read

Streamlit has no callback graph — it reruns the whole script per interaction — so streamlit-mcp drives the app headlessly through Streamlit's own test runtime (streamlit.testing.v1.AppTest) and returns the semantic element tree, not pixels. Gradio and Dash already shipped native app-as-MCP; this fills the Streamlit gap.

Demo

A normal Streamlit app (what a human opens in a browser) and what an agent does with the same app over MCP — inspect the widgets, call to set values / click / read the result. No browser:

A Streamlit signup form in a browser The streamlit-mcp CLI introspecting and driving the app
The app a human runs What the agent sees over MCP

A human can also watch the agent work live in their browser — no refresh, no browser automation — by opting in with one with block (from streamlit_mcp.live import live). See the live / human-in-the-loop guide.

Use it with an MCP client

Claude Desktop / Cursor — add to your MCP config (claude_desktop_config.json or .cursor/mcp.json):

{
  "mcpServers": {
    "streamlit-mcp": {
      "command": "uvx",
      "args": ["streamlit-mcp", "serve", "/absolute/path/to/your/app.py"]
    }
  }
}

Claude Code:

claude mcp add streamlit-mcp -- uvx streamlit-mcp serve /absolute/path/to/your/app.py

uvx runs the published package with no prior install. stdio (the default) is the right transport for local clients.

Tools exposed to agents

Tool What it does
list_widgets / get_layout introspect widgets (kind, label, value, constraints)
set_widget(identifier, value) set a widget and rerun
click(identifier) click a button and rerun
read_output() the rendered element tree, agent-readable
get_state() the app's session_state

Supported widgets: text_input, number_input, text_area, slider, select_slider, selectbox, multiselect, checkbox, toggle, radio, button, date_input, time_input, color_picker, pills, segmented_control, feedback — including their two-handle range forms (st.slider("Price", 0, 100, (20, 80)), st.date_input("Dates", (start, end))), which advertise a 2-element array schema and take [low, high]. An st.form is driven the way a human drives it: set the fields, then click the form's submit button.

Input widgets streamlit-mcp can't drive (file_uploader, camera_input, audio_input, chat_input, data_editor, …) are reported explicitly on every surface (text --layout, --json, MCP get_layout), never silently dropped — wherever they're placed, including st.sidebar.file_uploader(...) and inside columns, tabs and containers.

Custom semantic tools

Beyond the per-widget tools, expose a higher-level named action by decorating a function with @mcp_tool in your app file:

import streamlit as st
from streamlit_mcp import mcp_tool

@mcp_tool
def reset_all():
    """Reset everything to defaults."""
    return {"ok": True}

st.text_input("Name")

streamlit-mcp serve app.py loads the app and exposes reset_all over MCP alongside the widget tools. The decorated function is called directly (it isn't a widget), so keep it self-contained. It's reachable from the CLI too (human ↔ agent parity): streamlit-mcp inspect app.py lists it and streamlit-mcp call app.py --tool reset_all invokes it.

Human ↔ agent parity

Everything an agent can do over MCP, a human can do via the CLI — both call the same engine. The read-only mode and widget allow-list guardrails apply identically to both surfaces. If the served app raises, the exception is reported on every surface — --json, MCP read_output/get_layout, and the text CLI — and call/inspect --strict exit non-zero on an app exception (for CI/scripts).

Security / trust model

  • app_path is executed as trusted code in the server process (that's how AppTest runs it). Only serve apps you trust.
  • get_state / read_output expose the app's session_state to the caller — do not put secrets there.
  • HTTP/SSE bearer auth is enforced. Pass --bearer-token <T> and every HTTP/SSE request must send Authorization: Bearer <T> — a missing or wrong token gets 401 before any tool runs. A non-loopback host is allowed only with a token set; without one, serve binds 127.0.0.1 only and refuses a non-loopback host (fail closed). stdio is local and unauthenticated.

Known limitations

  • Sessions are not disposed. Per-client isolation works, but there is no session-close hook, so a long-running HTTP server accumulates one runtime per client. stdio and single-client use are unaffected.
  • No concurrency locking. Concurrent requests sharing one session are not serialized, and AppTest is not known to be re-entrant — use one in-flight request per session for now.
  • Output capture covers headings / markdown / caption / text; st.write, st.error, and similar are a planned coverage expansion.

License

MIT

Metadata

Release files for streamlit-mcp 0.7.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for streamlit-mcp 0.7.1
File Size Uploaded
streamlit_mcp-0.7.1.tar.gz 506.9 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for streamlit-mcp 0.7.1
File Interpreter ABI Platform
streamlit_mcp-0.7.1-py3-none-any.whl Python 3 none any Details

Total release size: 548.9 kB

Release files / streamlit_mcp-0.7.1.tar.gz

Download URL streamlit_mcp-0.7.1.tar.gz
Size 506.9 kB
Tags Source
SHA-256 checksum
How to use checksums
b5f2420de729d58ad61b9dc5191d6671a9a23b272311ed0f085dcb8670722888
BLAKE2b-256 checksum
How to use checksums
0c2aa0f9a403234d639afd00ccc5fbbe096a635b27718fc62e10397d5736ef74
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.11.29 {"installer":{"name":"uv","version":"0.11.29","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release files / streamlit_mcp-0.7.1-py3-none-any.whl

Download URL streamlit_mcp-0.7.1-py3-none-any.whl
Size 41.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
c96410d6249cc3f7ea2aedf019964c095cbdb176994685ca8907a43ca4048fec
BLAKE2b-256 checksum
How to use checksums
e4658a07288bc23aec13e2f145c3421809d90a83bb1191ef32ce515ac9e78938
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.11.29 {"installer":{"name":"uv","version":"0.11.29","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release history Release notifications | RSS feed

This release

0.7.1 This release

2 release files

0.7.0

2 release files

0.6.0

2 release files

0.5.0

2 release files

0.4.0

2 release files

0.3.9

2 release files

0.3.8

2 release files

0.3.7

2 release files

0.3.6

2 release files

0.3.5

2 release files

0.3.4

2 release files

0.3.3

2 release files

0.3.2

2 release files

0.3.1

2 release files

0.3.0

2 release files

0.2.3

2 release files

0.2.2

2 release files

0.2.1

2 release files

0.2.0

2 release files

0.1.2

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page