
Shodan MCP Server
by burtthecoderio.github.BurtTheCoder/shodanv1.0.22
Query the Shodan API and Shodan CVEDB: IP lookups, device searches, DNS lookups, vulnerability queries and CPE lookups.
context tax
queued
security
queued
cold start
queued
freshness
Active31d ago
Install Shodan MCP server
Install in Claude Code
claude mcp add shodan -e SHODAN_API_KEY='<shodan-api-key>' -- npx -y @burtthecoder/mcp-shodanInstall in Cursor
{
"mcpServers": {
"shodan": {
"command": "npx",
"args": [
"-y",
"@burtthecoder/mcp-shodan"
],
"env": {
"SHODAN_API_KEY": "<shodan-api-key>"
}
}
}
}Add to ~/.cursor/mcp.json (global) or .cursor/mcp.json (project).
Install in Claude Desktop
{
"mcpServers": {
"shodan": {
"command": "npx",
"args": [
"-y",
"@burtthecoder/mcp-shodan"
],
"env": {
"SHODAN_API_KEY": "<shodan-api-key>"
}
}
}
}Settings → Developer → Edit Config (claude_desktop_config.json), then restart.
Install in VS Code
{
"servers": {
"shodan": {
"type": "stdio",
"command": "npx",
"args": [
"-y",
"@burtthecoder/mcp-shodan"
],
"env": {
"SHODAN_API_KEY": "<shodan-api-key>"
}
}
}
}Add to .vscode/mcp.json in your workspace.
Install in Windsurf
{
"mcpServers": {
"shodan": {
"command": "npx",
"args": [
"-y",
"@burtthecoder/mcp-shodan"
],
"env": {
"SHODAN_API_KEY": "<shodan-api-key>"
}
}
}
}Add to ~/.codeium/windsurf/mcp_config.json.
Configuration
| Variable | Required | Secret | Description |
|---|---|---|---|
| SHODAN_API_KEY | yes | yes | Your Shodan API key |
Freshness
Active — last maintenance signal 31d ago. The newest of the signals below sets the band.
Last commit (default branch)
2026-09-08 · 31d ago · GitHub
Latest release
2026-09-08 · 31d ago · GitHub · v1.0.30
Package published
no data · npm/PyPI
Registry entry updated
2026-03-03 · 7mo ago · official registry · v1.0.22
FAQ
›How do I install the Shodan MCP server in Claude Code?
Run: claude mcp add shodan -e SHODAN_API_KEY='<shodan-api-key>' -- npx -y @burtthecoder/mcp-shodan. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.
›Does Shodan require an API key?
Yes. It expects SHODAN_API_KEY, of which 1 is a secret.
›Can I use Shodan as a remote (hosted) MCP server?
No hosted endpoint is published; it runs locally over stdio.
›Is Shodan in the official MCP registry?
Yes, as io.github.BurtTheCoder/shodan.
Alternatives to Shodan
Other security MCP servers.