ghidra-bridge
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@ghidra-bridgelist the functions in the loaded binary"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Ghidra Bridge
Ghidra Bridge gives network access to an active Ghidra program.
The runtime runs on Java 21 and supports Ghidra 12.1.
It exposes two transports: WebSocket JSON-RPC 2.0 and MCP Streamable HTTP 2026-07-28.
The runtime JAR has zero third-party dependencies.
Key Features
Dual Transports: Access Ghidra through WebSocket JSON-RPC 2.0 or MCP Streamable HTTP.
Unified Catalog: One typed registry defines 53 public dotted methods. WebSocket exposes all 53. MCP exposes 52 of them;
interface.getis WebSocket only.Bounded Scans: Address-ordered listings support cooperative cancellation and cursor pagination.
Atomic Transactions: Execute batch operations with automatic rollback on error.
Headless Mode: Run the bridge in Ghidra headless scripts without GUI interaction.
Related MCP server: re-angr
Build the Scripts
Set GHIDRA_INSTALL_DIR to your Ghidra installation path.
Then build the scripts with the Gradle wrapper:
./gradlew buildGhidraScriptThe build task creates three files in build/ghidra-script/:
Bridge.java
GhidraMcp.java
ghidra-bridge.jarKeep these three files in the same directory.
The loader scripts locate ghidra-bridge.jar relative to their file path.
Start the Bridge
Run in the Ghidra GUI
Open a binary in the Ghidra CodeBrowser tool.
Open the Script Manager window.
Add
build/ghidra-script/to your script directories.Run
Bridge.javafor WebSocket orGhidraMcp.javafor MCP.Enter configuration arguments in the prompt window.
Run in Ghidra Headless Mode
You can run GhidraMcp.java or Bridge.java as a post-script in headless mode.
Create a project directory, then import and analyze the target binary.
Do not use project paths with dot-prefixed directory names like .cache.
mkdir -p /path/to/projects
"$GHIDRA_INSTALL_DIR/support/analyzeHeadless" /path/to/projects demo \
-import /path/to/target_binary \
-scriptPath "$PWD/build/ghidra-script" \
-postScript GhidraMcp.java host=127.0.0.1 port=8766 path=/mcp session_id=demoThe post-script serves requests until you stop the process.
To open an existing project file without re-analysis, use -process with -noanalysis:
"$GHIDRA_INSTALL_DIR/support/analyzeHeadless" /path/to/projects demo \
-process target_binary -noanalysis \
-scriptPath "$PWD/build/ghidra-script" \
-postScript GhidraMcp.java host=127.0.0.1 port=8766 path=/mcp session_id=demoConfiguration Arguments
Configure the bridge with strict key=value pairs.
The launcher rejects unknown arguments, duplicate arguments, and camelCase keys.
# Embedded WebSocket server
host=127.0.0.1 port=8765 path=/ws/agent session_id=demo
# Outbound WebSocket client
ws_url=ws://127.0.0.1:8765/ws/agent session_id=demo token=secret
# MCP HTTP server
host=127.0.0.1 port=8766 path=/mcp session_id=demo token=secret
# Second MCP HTTP server with its own tool names
host=127.0.0.1 port=8767 path=/mcp session_id=other tool_prefix=otherParameter Reference
Parameter | Default | Description |
|
| Local network interface address to listen on. |
|
| TCP port number for the HTTP or WebSocket server. WebSocket uses the default only when |
|
| URL path endpoint for request dispatch. |
| Program name | Unique identifier string for this active session. |
| (none) | Shared secret token for bearer authentication. |
| (none) | Remote WebSocket URL when operating as an outbound client. |
|
| MCP only. First part of every tool name, such as |
| (auto) | Path to |
Security Rules
The bridge enforces strict security boundaries:
Loopback Default: Listeners bind to
127.0.0.1by default.Mandatory Token: A listener bound to a non-loopback interface requires
token.Bearer Header: Inbound requests must send
Authorization: Bearer <token>.Query Tokens Rejected: The server rejects tokens in URL query strings with HTTP 400.
Log Privacy: Secret tokens are never written to log files or consoles.
API and Transports
The public API has 53 dotted methods, from interface.get to batch.execute.
WebSocket JSON-RPC 2.0
WebSocket sends strict JSON-RPC 2.0 requests with dotted method names:
{"jsonrpc":"2.0","id":"r1","method":"program.get","params":{}}Call interface.get to discover all supported methods and schemas.
Model Context Protocol (MCP)
MCP exposes the same operations, except interface.get, through 15 tools over Streamable HTTP:
ghidra.help: Discover domains, list operations, or view schemas.14 Domain Tools:
ghidra.program,ghidra.memory,ghidra.function,ghidra.listing, etc.
Call an operation with its operation name in the domain tool and its parameters.
For example, the program.get method is the get operation of ghidra.program:
{
"name": "ghidra.program",
"arguments": {
"operation": "get",
"params": {}
}
}Each MCP request must also send MCP metadata and headers. See Protocol Specification.
The MCP tool schema is also available at ghidra-bridge://contracts/mcp-tools.
Documentation Index
Overview: System concepts, concurrency model, and query patterns.
Architecture: Module boundaries and dependency graph.
Protocol Specification: JSON-RPC envelopes, MCP endpoints, and error formats.
Batch and Transactions: Atomic execution and transaction boundaries.
Development Guide: Environment setup, workflows, and quality gates.
Method Reference: Full 53-method catalog and schemas.
AsyncAPI Contract: Formal WebSocket contract.
MCP Tools Contract: Formal MCP tool definitions.
Verify the Build
Run the full verification suite before committing changes:
./gradlew --no-daemon clean verifyThe verify task checks:
Architecture boundary rules.
Generated API contract drift.
Generated script build and compilation.
The MCP test suite in tests/ runs every MCP tool against Ghidra in headless mode.
This server cannot be deployed
Maintenance
Related MCP Connectors
Governed data discovery, exact queries, decisions, simulations, and runtime utilities over MCP.
Repository knowledge graph MCP server for codebase understanding and debugging.
Hosted MCP memory and agent control plane for durable conversations, jobs, and operations.
MCP server for mandates, delegation, policy-gated execution, credential grants, and audit.
Related MCP Servers
- AlicenseNot gradedqualityBmaintenanceExposes Ghidra reverse engineering capabilities via MCP, enabling LLMs and agents to analyze binaries, decompile, search, and edit programs headlessly or with GUI integration.426Apache 2.0
- AlicenseAqualityCmaintenanceMCP server for angr — symbolic execution + CFG + reaching-definitions.4MIT
- AlicenseNot gradedqualityCmaintenanceMCP server exposing the rizin CLI for static binary analysis of executables.MIT
- AlicenseBqualityBmaintenanceEnables AI agents and automation to perform Ghidra reverse-engineering tasks through MCP, including decompilation, live debugging, P-code emulation, data-flow analysis, and headless script execution, with specialized AArch64-aware emulation.8Apache 2.0