OPA MCP
About
Author, validate, debug, and explain OPA Rego policies through any MCP-compatible client.
Use this server
Add it to your MCP client. The catalogue lists this config verbatim from its source — it does not run, download, or vouch for the server. Review the command before you run it.
Transportstdio (runs a local command)
Env vars
OPA_URL OPA_TOKEN OPA_BINARY REGAL_BINARY CONFTEST_BINARY OPA_MCP_ALLOWED_PATHS GITHUB_TOKENClaude Code
claude mcp add --env OPA_URL= --env OPA_TOKEN= --env OPA_BINARY= --env REGAL_BINARY= --env CONFTEST_BINARY= --env OPA_MCP_ALLOWED_PATHS= --env GITHUB_TOKEN= opa-mcp -- npx @orygn/opa-mcp
Cursor
If the button doesn't open Cursor, use the JSON below — Cursor accepts the same mcpServers config.
VS Code
code --add-mcp '{"name":"opa-mcp","command":"npx","args":["@orygn/opa-mcp"],"env":{"OPA_URL":"","OPA_TOKEN":"","OPA_BINARY":"","REGAL_BINARY":"","CONFTEST_BINARY":"","OPA_MCP_ALLOWED_PATHS":"","GITHUB_TOKEN":""}}'
JSON
{
"mcpServers": {
"opa-mcp": {
"command": "npx",
"args": [
"@orygn/opa-mcp"
],
"env": {
"OPA_URL": "",
"OPA_TOKEN": "",
"OPA_BINARY": "",
"REGAL_BINARY": "",
"CONFTEST_BINARY": "",
"OPA_MCP_ALLOWED_PATHS": "",
"GITHUB_TOKEN": ""
}
}
}
}
Environment variables are listed by name only — fill in your own values. Entries never carry secrets.