OPA MCP Server
by orygnscodeio.github.OrygnsCode/opa-mcpv0.9.0
OPA and Rego policy toolkit wrapping the OPA CLI and Regal: format, lint, evaluate, test and benchmark policies, manage the OPA REST API and explain decisions.
context tax
queued
security
queued
cold start
queued
freshness
Active3d ago
Install OPA MCP server
Install in Claude Code
claude mcp add opa -e OPA_TOKEN='<opa-token>' -e GITHUB_TOKEN='<github-token>' -- npx -y @orygn/opa-mcpInstall in Cursor
{
"mcpServers": {
"opa": {
"command": "npx",
"args": [
"-y",
"@orygn/opa-mcp"
],
"env": {
"OPA_TOKEN": "<opa-token>",
"GITHUB_TOKEN": "<github-token>"
}
}
}
}Add to ~/.cursor/mcp.json (global) or .cursor/mcp.json (project).
Install in Claude Desktop
{
"mcpServers": {
"opa": {
"command": "npx",
"args": [
"-y",
"@orygn/opa-mcp"
],
"env": {
"OPA_TOKEN": "<opa-token>",
"GITHUB_TOKEN": "<github-token>"
}
}
}
}Settings → Developer → Edit Config (claude_desktop_config.json), then restart.
Install in VS Code
{
"servers": {
"opa": {
"type": "stdio",
"command": "npx",
"args": [
"-y",
"@orygn/opa-mcp"
],
"env": {
"OPA_TOKEN": "<opa-token>",
"GITHUB_TOKEN": "<github-token>"
}
}
}
}Add to .vscode/mcp.json in your workspace.
Install in Windsurf
{
"mcpServers": {
"opa": {
"command": "npx",
"args": [
"-y",
"@orygn/opa-mcp"
],
"env": {
"OPA_TOKEN": "<opa-token>",
"GITHUB_TOKEN": "<github-token>"
}
}
}
}Add to ~/.codeium/windsurf/mcp_config.json.
Configuration
| Variable | Required | Secret | Description |
|---|---|---|---|
| OPA_URL | — | — | Base URL of a running OPA server. Required only for opa_* runtime tools, not for rego_* language tools. |
| OPA_TOKEN | — | yes | Bearer token for OPA running with --authentication=token. |
| OPA_BINARY | — | — | Path to the opa binary. Defaults to 'opa' on PATH. |
| REGAL_BINARY | — | — | Path to the regal binary (optional; used by rego_lint, rego_security_audit and rego_fix). Defaults to 'regal' on PATH. |
| CONFTEST_BINARY | — | — | Path to the conftest binary (optional, used by conftest_* tools). Defaults to 'conftest' on PATH. |
| OPA_MCP_ALLOWED_PATHS | — | — | Comma-separated list of root directories tools may read/write. When unset, file-based tools refuse to access the disk. |
| GITHUB_TOKEN | — | yes | GitHub personal access token with the "gist" scope. Required only for rego_playground_share. |
Freshness
Active — last maintenance signal 3d ago. The newest of the signals below sets the band.
Last commit (default branch)
2026-10-06 · 4d ago · GitHub
Latest release
2026-10-06 · 3d ago · GitHub · v0.9.0
Package published
no data · npm/PyPI
Registry entry updated
2026-10-06 · 3d ago · official registry · v0.9.0
FAQ
›How do I install the OPA MCP server in Claude Code?
Run: claude mcp add opa -e OPA_TOKEN='<opa-token>' -e GITHUB_TOKEN='<github-token>' -- npx -y @orygn/opa-mcp. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.
›Does OPA require an API key?
Yes. It expects OPA_TOKEN, GITHUB_TOKEN, of which 2 are secrets.
›Can I use OPA as a remote (hosted) MCP server?
No hosted endpoint is published; it runs locally over stdio.
›Is OPA in the official MCP registry?
Yes, as io.github.OrygnsCode/opa-mcp.
Alternatives to OPA
Other security MCP servers.