Claude Code CLI MCP Server
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| CLAUDE_MCP_MODE | No | Server access mode (safe or permissive). | safe |
| CLAUDE_MCP_MAX_RUNS | No | History size of completed tasks in the run store. | 50 |
| CLAUDE_MCP_FORCE_BARE | No | Pass --bare to disable local workspace profiles and hooks. | true |
| CLAUDE_MCP_CLAUDE_PATH | No | Path or command to invoke the claude CLI. | claude |
| CLAUDE_MCP_ALLOWED_ROOTS | No | JSON list of allowed workspace roots. | Current working directory |
| CLAUDE_MCP_LOGFIRE_TOKEN | No | Optional Logfire token for application telemetry. | None |
| CLAUDE_MCP_ALLOWED_MODELS | No | JSON set of permitted model names or aliases. | ["sonnet", "opus"] |
| CLAUDE_MCP_ALLOW_ENV_KEYS | No | JSON list of allowed env keys to pass in permissive mode. | [] |
| CLAUDE_MCP_ALLOW_EXTRA_ARGS | No | JSON list of allowed CLI arguments in permissive mode. | [] |
| CLAUDE_MCP_MAX_STDERR_BYTES | No | Maximum stderr bytes captured from the child process. | 200000 |
| CLAUDE_MCP_MAX_STDOUT_BYTES | No | Maximum stdout bytes captured from the child process. | 1000000 |
| CLAUDE_MCP_DEFAULT_TIMEOUT_S | No | Maximum allowed execution time for tasks in seconds. | 600 |
| CLAUDE_MCP_MAX_CONCURRENT_RUNS | No | Maximum concurrent background executions allowed. | 10 |
| CLAUDE_MCP_PERSISTENCE_ENABLED | No | Enables the persistent markdown memory layer. | true |
| CLAUDE_MCP_PERSISTENCE_BASE_DIR | No | Base directory for the persistence layer. | ~/.open-cli-router |
| CLAUDE_MCP_CLAUDE_PATH_FALLBACKS | No | Fallback absolute paths to search for the binary. | ["/usr/local/bin/claude", "/opt/homebrew/bin/claude", "~/.local/bin/claude"] |
| CLAUDE_MCP_DEFAULT_PERMISSION_MODE | No | Permission mode flag (default, acceptEdits, plan, dontAsk, bypassPermissions). | acceptEdits |
| CLAUDE_MCP_POLL_DEFAULT_WAIT_SECONDS | No | Default wait time between polling iterations. | 0.5 |
| CLAUDE_MCP_FORCE_SANDBOX_IN_SAFE_MODE | No | Enforce sandbox execution in safe mode. | true |
| CLAUDE_MCP_PERSISTENCE_MAX_FILE_BYTES | No | Maximum file size for persistence files before rejecting writes. | 1048576 |
| CLAUDE_MCP_PERSISTENCE_SEED_TEMPLATES | No | Seed default markdown files if missing on init. | true |
| CLAUDE_MCP_PERSISTENCE_BACKUP_ON_WRITE | No | Create a .bak backup copy of files before modification. | false |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
| logging | {} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
| extensions | {
"io.modelcontextprotocol/ui": {}
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| claude_healthA | Health check for the Claude Code CLI binary. Verifies the Optional fields: - expected_version (str): if set, returns ok=false on version mismatch Returns: - claude_path, claude_version, ok, auth_status, notes |
| claude_run_taskA | Run a single Claude task synchronously (bounded by FastMCP's 600s wrapper cap). Required: workspace_path, prompt. Common options: model (alias from Settings.claude_model_aliases), fallback_model, permission_mode, options.timeout_s (default 300, max 600), capture_changes. Estimated cost depends on For tasks that may exceed 600s (architecture, migration, large refactors),
use Returns: ClaudeRunTaskResponse with result, stdout/stderr, exit_code, timed_out, total_cost_usd, model_usage, and (if capture_changes=true) a unified git diff of workspace changes. |
| claude_start_taskA | Start a Claude Code CLI task asynchronously (up to 3600s). Returns immediately with a run_id. The subprocess continues running in
the background; use Required: workspace_path, prompt. Optional: model, fallback_model, permission_mode, options.timeout_s (default 300, max 3600 for async), capture_changes. Concurrent run limit: bounded by Settings.max_concurrent_runs. New calls beyond that limit return MAX_CONCURRENT_RUNS_EXCEEDED. |
| claude_poll_taskA | Poll an asynchronous task. Two polling modes: - drain=false (default): returns immediately with current state (new messages, stdout/stderr byte counts, elapsed time). Use for tight control loops with explicit backoff. - drain=true: blocks until status is no longer 'running' (fire-and-wait). Note: this is bounded by your MCP client's request timeout, not the async task's timeout_s. For long blocks, prefer async drain with orchestrator-level polling. Returns: ClaudePollTaskResponse with status (running|done|error|timeout|cancelled), new_messages, stdout_len/stderr_len, elapsed_seconds, and (once terminal) the full result with total_cost_usd, model_usage, and changes. |
| claude_cancel_taskA | Cancel a running task. Two escalation levels: - force=false (default): sends SIGTERM (graceful). The subprocess has ~5s to clean up before the OS escalates. Try this first. - force=true: sends SIGKILL (immediate). Use only if the subprocess doesn't respond to SIGTERM within ~5s. Returns: ClaudeCancelTaskResponse with canceled (bool) and status ("cancelled" if actively stopped, "already_done" if run finished naturally, "not_found" if run_id is unknown). |
| claude_list_runsA | List recent runs (active + recently completed). Returns ClaudeRunSummary entries ordered newest-first, with active
Use this for recovery after orchestrator restart: active async runs
survive across MCP client restarts and can be polled/cancelled via
|
| claude_init_persistenceA | Initialize the persistence directory and seed the three markdown files. Idempotent: re-running without force=true is a no-op if files already
exist. Creates the directory at the location resolved by
Optional fields: - force (bool): re-create files even if they exist - seed_templates (bool|None): whether to seed the default templates |
| claude_read_persistenceA | Read one of the three persistence files (agents | projects | memory). Optional fields: - file (str): which file to read (default: memory) - offset (int): start reading from line N (0-indexed) - limit (int|None): max lines to return (None = no limit) Large files are automatically truncated at
Settings.persistence_max_file_bytes; the response includes a
|
| claude_append_persistenceA | Append content to one of the persistence files. Required: file (agents|projects|memory), content. Optional: section_header (str|None) — if provided, the append is placed under a heading; otherwise content is appended at the end of the file. Safe-mode constraint: in Do not store secrets, credentials, or full file dumps — keep entries small and high-signal. |
| claude_update_persistenceA | Replace or append to a section in one of the persistence files. Required: file, section_anchor, new_content. Optional: mode (replace|append) — replace the entire section vs append inside it (default replace). Safe-mode constraint: in |
| claude_load_persistence_contextA | Load the persistence files as context for the current session. Returns head+tail excerpts of each file (head_ratio controlled by Settings.persistence_truncation_head_ratio). Use this at the start of each session to hydrate orchestrator memory before dispatching tasks. Optional fields: - include (list[str]|None): subset of files to load (agents|projects|memory). None = all three. - max_chars_per_file (int): per-file char cap (default from settings). |
| claude_self_testA | Inspect every registered tool's input schema and report robustness. This is a metadata-only check — no tools are actually invoked. Args shape:
The MCP client MUST pass arguments wrapped in a |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
| claude_sync_orchestration | Orchestration playbook for running a single synchronous task safely. |
| claude_async_orchestration | Orchestration playbook for running start_task + poll_task + cancel_task. |
| claude_model_selection_guidance | Guidance for model selection when using this MCP server. |
| claude_timeout_help | Decision matrix for picking the right timeout + sync/async per task. |
| claude_security_and_workspace_rules | Safety rules and workspace constraints for orchestrators. |
| claude_persistence_protocol | Instruct the orchestrator on how to maintain the persistence layer. |
| claude_quickstart | Cheatsheet for using this MCP server. Read this first if confused. Returns the canonical contract: args shape, required CLI binary, tool catalog, and common gotchas. Static, but kept in sync with `claude_self_test` results. |
| claude_contract | Full machine-readable JSON contract of every registered tool. Builds the catalog from mcp._local_provider._components so it stays in sync with the actual registered tool schemas. Read this before writing integrations. |
| claude_troubleshoot | Diagnose a specific error string and return the fix recipe. Pass the exact error message you received (e.g. "req: Missing required argument" or "workspace_path is outside allowed roots") and this prompt returns the canonical fix. |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 12 tools
The task lifecycle tools (run/start/poll/cancel/list) are clearly separated by sync vs async execution and state transitions, and the persistence tools have distinct read/append/update/load operations. The only mild ambiguity is between run_task and start_task, and between update_persistence and append_persistence, but the descriptions explicitly route usage.
All tools share a consistent claude_ prefix and snake_case style, with most following a verb_noun pattern like claude_run_task, claude_poll_task, and claude_read_persistence. claude_health is a noun-only outlier, and claude_load_persistence_context is less consistent with the shorter read/append/update names, but the overall pattern remains predictable.
Twelve tools is well-scoped for a server covering Claude Code CLI task execution and persistent memory files, with no redundant duplicates. Each tool addresses a distinct operational need within those two clear domains.
The surface covers the full task lifecycle: synchronous run, asynchronous start, poll, cancel, and list, plus health verification and self-test. Persistence is also complete with init, read, append, update, and load-context operations, leaving no obvious dead ends for the stated purpose.