Skip to main content

streamlit-mcp

Serve any Streamlit app as an MCP server. Agents introspect your app's widgets, set values, click buttons, and read the rendered output and session_state — natively, over MCP, with no browser automation.

📖 Documentation: https://dkedar7.github.io/streamlit-mcp/

pip install streamlit-mcp          # or run with no install via: uvx streamlit-mcp ...

# serve an app over MCP (stdio for local clients)
streamlit-mcp serve app.py
# ...or HTTP/SSE on loopback for local networked agents
streamlit-mcp serve app.py --transport http --port 8000

# drive it yourself from the terminal (same engine the agent uses)
streamlit-mcp inspect app.py
streamlit-mcp call app.py --set "Name=agent" --click "Save" --read

Streamlit has no callback graph — it reruns the whole script per interaction — so streamlit-mcp drives the app headlessly through Streamlit's own test runtime (streamlit.testing.v1.AppTest) and returns the semantic element tree, not pixels. Gradio and Dash already shipped native app-as-MCP; this fills the Streamlit gap.

Demo

A normal Streamlit app (what a human opens in a browser) and what an agent does with the same app over MCP — inspect the widgets, call to set values / click / read the result. No browser:

A Streamlit signup form in a browser The streamlit-mcp CLI introspecting and driving the app
The app a human runs What the agent sees over MCP

A human can also watch the agent work live in their browser — no refresh, no browser automation — by opting in with one with block (from streamlit_mcp.live import live). See the live / human-in-the-loop guide.

Use it with an MCP client

Claude Desktop / Cursor — add to your MCP config (claude_desktop_config.json or .cursor/mcp.json):

{
  "mcpServers": {
    "streamlit-mcp": {
      "command": "uvx",
      "args": ["streamlit-mcp", "serve", "/absolute/path/to/your/app.py"]
    }
  }
}

Claude Code:

claude mcp add streamlit-mcp -- uvx streamlit-mcp serve /absolute/path/to/your/app.py

uvx runs the published package with no prior install. stdio (the default) is the right transport for local clients.

Tools exposed to agents

Tool What it does
list_widgets / get_layout introspect widgets (kind, label, value, constraints)
set_widget(identifier, value) set a widget and rerun
click(identifier) click a button and rerun
read_output() the rendered element tree, agent-readable
get_state() the app's session_state

Supported widgets: text_input, number_input, text_area, slider, select_slider, selectbox, multiselect, checkbox, toggle, radio, button, date_input, time_input, color_picker — including their two-handle range forms (st.slider("Price", 0, 100, (20, 80)), st.date_input("Dates", (start, end))), which advertise a 2-element array schema and take [low, high]. An st.form is driven the way a human drives it: set the fields, then click the form's submit button.

Input widgets streamlit-mcp can't drive (file_uploader, camera_input, chat_input, pills, segmented_control, feedback, …) are reported explicitly on every surface (text --layout, --json, MCP get_layout), never silently dropped — wherever they're placed, including st.sidebar.file_uploader(...) and inside columns, tabs and containers.

Custom semantic tools

Beyond the per-widget tools, expose a higher-level named action by decorating a function with @mcp_tool in your app file:

import streamlit as st
from streamlit_mcp import mcp_tool

@mcp_tool
def reset_all():
    """Reset everything to defaults."""
    return {"ok": True}

st.text_input("Name")

streamlit-mcp serve app.py loads the app and exposes reset_all over MCP alongside the widget tools. The decorated function is called directly (it isn't a widget), so keep it self-contained. It's reachable from the CLI too (human ↔ agent parity): streamlit-mcp inspect app.py lists it and streamlit-mcp call app.py --tool reset_all invokes it.

Human ↔ agent parity

Everything an agent can do over MCP, a human can do via the CLI — both call the same engine. The read-only mode and widget allow-list guardrails apply identically to both surfaces.

Security / trust model

  • app_path is executed as trusted code in the server process (that's how AppTest runs it). Only serve apps you trust.
  • get_state / read_output expose the app's session_state to the caller — do not put secrets there.
  • HTTP/SSE bearer auth is enforced. Pass --bearer-token <T> and every HTTP/SSE request must send Authorization: Bearer <T> — a missing or wrong token gets 401 before any tool runs. A non-loopback host is allowed only with a token set; without one, serve binds 127.0.0.1 only and refuses a non-loopback host (fail closed). stdio is local and unauthenticated.

Known limitations

  • Sessions are not disposed. Per-client isolation works, but there is no session-close hook, so a long-running HTTP server accumulates one runtime per client. stdio and single-client use are unaffected.
  • No concurrency locking. Concurrent requests sharing one session are not serialized, and AppTest is not known to be re-entrant — use one in-flight request per session for now.
  • Output capture covers headings / markdown / caption / text; st.write, st.error, and similar are a planned coverage expansion.

License

MIT

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

streamlit_mcp-0.4.0.tar.gz (480.0 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

streamlit_mcp-0.4.0-py3-none-any.whl (33.5 kB view details)

Uploaded Python 3

File details

Details for the file streamlit_mcp-0.4.0.tar.gz.

File metadata

  • Download URL: streamlit_mcp-0.4.0.tar.gz
  • Upload date:
  • Size: 480.0 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: uv/0.11.28 {"installer":{"name":"uv","version":"0.11.28","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

File hashes

Hashes for streamlit_mcp-0.4.0.tar.gz
Algorithm Hash digest
SHA256 510c4baab28b8403460b29df6fa9bf750552a4062258636a46bab602727fdb72
MD5 7426d13b7c598b8e876f86169197941f
BLAKE2b-256 c2543ba4209c564563e567d0ee06627ccc0496b577c5ed40290b313d901f7669

See more details on using hashes here.

File details

Details for the file streamlit_mcp-0.4.0-py3-none-any.whl.

File metadata

  • Download URL: streamlit_mcp-0.4.0-py3-none-any.whl
  • Upload date:
  • Size: 33.5 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: uv/0.11.28 {"installer":{"name":"uv","version":"0.11.28","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

File hashes

Hashes for streamlit_mcp-0.4.0-py3-none-any.whl
Algorithm Hash digest
SHA256 f93f9b273f132fbeb6409c05ddcf89fd42e35d6ec7b91e3281bf569ae02f9273
MD5 a86a14b80477d1c5d8bd53295ee98312
BLAKE2b-256 1fb8752dc1f6de7b681a3338fce9b072979582180a1fb3fe14fcac44f0734610

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page