Container Exec MCP Server
Enables management and interaction with Docker containers, including listing containers, executing commands inside containers, and inspecting container information and status.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Container Exec MCP Serverlist all running containers"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Container Exec MCP Server

A Model Context Protocol (MCP) server that provides Docker container automation capabilities. This server enables AI assistants like Claude/Cursor/ChatGPT to manage and interact with Docker containers, execute commands, and inspect container information.
This package minimizes the amount of tools to help AI Agents pick the right tool for a given prompt.
Features
🐳 Container Management - List and inspect Docker containers
🔧 Command Execution - Execute commands inside containers
📊 Detailed Information - Get comprehensive container details
🚀 Dual Transport - HTTP and stdio (for Claude Code/Cursor)
For detailed information about available tools, see tools.md.
Related MCP server: Docker MCP Server
Table of Contents
Getting Started
Prerequisites
Node.js 18 or higher
Docker installed and running
npm or yarn
Configuration
Environment Variables
Configure the server behavior using environment variables:
Variable | Description | Default | Options |
| HTTP server port |
| Any valid port number |
| Authentication token for HTTP server (optional) | None | Any string |
Cursor / Claude Code / Claude Desktop Configuration
To use this server with Cursor/Claude Code/Claude Desktop, add it to your MCP settings file.
Configuration:
{
"mcpServers": {
"container-exec": {
"command": "npx",
"args": [
"container-exec-mcp"
]
}
}
}Note: After updating the configuration, restart Claude Code/Desktop for changes to take effect.
Important: Ensure Docker is running and accessible on your system.
HTTP Transport (for n8n or other HTTP clients)
Start the HTTP server:
npm install
npm start
# or with custom port
PORT=4200 npm start
# With authentication (recommended)
MCP_AUTH_TOKEN=your-secret-token npm startThe server will listen on http://localhost:4200/mcp (or your custom port).
Authentication (Optional):
You can secure the HTTP server with token-based authentication by setting the MCP_AUTH_TOKEN environment variable. If set, all requests must include the token in the Authorization header.
Example HTTP Request (with authentication):
curl -X POST http://localhost:4200/mcp \
-H "Content-Type: application/json" \
-H "Authorization: Bearer your-secret-token" \
-d '{
"jsonrpc": "2.0",
"id": 1,
"method": "tools/call",
"params": {
"name": "list_containers",
"arguments": {
"all": true
}
}
}'Development
Development Scripts
npm install
# Start HTTP server with auto-reload
npm run dev
# Start stdio server with auto-reload
npm run dev:stdio
# Build TypeScript to JavaScript
npm run buildTroubleshooting
Common Issues
1. Docker not running
Error: connect ENOENT /var/run/docker.sockSolution: Start Docker Desktop or the Docker daemon.
2. Docker permission denied
Error: permission denied while trying to connect to the Docker daemon socketSolution: On Linux, add your user to the docker group: sudo usermod -aG docker $USER (then log out and back in).
3. Node.js version too old
Error: Node.js 18 or higher requiredSolution: Update Node.js to version 18 or higher.
4. Container not found
Error: No such container: xyzSolution: Verify the container ID or name with list_containers.
5. Port already in use (HTTP mode)
Error: listen EADDRINUSE: address already in use :::4200Solution: Change the port with PORT=3001 npm start
Debug Logging
For stdio mode, logs are written to stderr and appear in Claude Code logs:
macOS:
~/Library/Logs/Claude/mcp-server-container-exec-mcp.logLinux:
~/.config/Claude/logs/mcp-server-container-exec-mcp.log
For HTTP mode, logs appear in the terminal where you started the server.
Contributing
Contributions are welcome! Please:
Fork the repository
Create a feature branch
Make your changes
Run
npm run buildto ensure it compilesTest your changes
Submit a pull request
License
MIT
Acknowledgments
Built with:
Dockerode - Docker API client
Model Context Protocol SDK - MCP implementation
Zod - Schema validation
Express - HTTP server
Available Tools
3 toolsexecC
Execute a command in a Docker container
| Name | Required | Description | Default |
|---|---|---|---|
| container_id | Yes | Container ID or name | |
| command | Yes | Command to execute in the container | |
| stdin | No | Input to send to the command via stdin | |
| working_dir | No | Working directory for the command | /home/ubuntu/workspace |
| user | No | User to run the command as | |
| env | No | Environment variables (format: KEY=value) | |
| timeout | No | Command timeout in seconds |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries full burden for behavioral disclosure. It states the tool executes commands but doesn't mention critical behaviors: whether this is a read/write operation, what permissions are needed, if commands run as root by default, what happens on timeout, or how output/errors are returned. For a command execution tool with zero annotation coverage, this leaves significant gaps.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single, clear sentence with zero wasted words. It's appropriately sized for a tool with comprehensive schema documentation and gets straight to the point without unnecessary elaboration.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a command execution tool with 7 parameters, no annotations, and no output schema, the description is incomplete. It doesn't explain what the tool returns (stdout/stderr/exit code), error conditions, security implications, or interaction patterns. The combination of mutation capability and lack of behavioral context makes this inadequate.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so the schema already documents all 7 parameters thoroughly. The description adds no additional parameter semantics beyond what's in the schema. Baseline 3 is appropriate when the schema does the heavy lifting for parameter documentation.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the action ('Execute') and target resource ('a command in a Docker container'), providing a specific verb+resource combination. However, it doesn't explicitly distinguish this from sibling tools like get_container_info or list_containers, which are read-only operations versus this execution tool.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides no guidance on when to use this tool versus alternatives. It doesn't mention prerequisites (e.g., container must be running), when not to use it (e.g., for simple container inspection), or how it differs from sibling tools like get_container_info for container metadata.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
get_container_infoA
Get detailed information about a specific Docker container including state, network, mounts, environment, and resource configuration.
| Name | Required | Description | Default |
|---|---|---|---|
| container_id | Yes | Container ID or name |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the full burden of behavioral disclosure. While it indicates this is a read operation ('Get detailed information'), it doesn't specify whether it requires specific permissions, how it handles errors (e.g., invalid container IDs), latency, or output format. For a tool with zero annotation coverage, this leaves significant gaps in understanding its behavior beyond the basic purpose.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single, well-structured sentence that efficiently conveys the tool's purpose and scope. It front-loads the core action ('Get detailed information') and lists specific details without unnecessary elaboration, making it easy to parse and understand quickly.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's low complexity (1 parameter, no nested objects) and high schema coverage (100%), the description adequately covers the basic purpose. However, with no annotations and no output schema, it lacks details on behavioral aspects like permissions, error handling, and return values. For a read-only tool, this is a moderate gap, making it minimally viable but not fully comprehensive.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, with the single parameter 'container_id' documented as 'Container ID or name' in the schema. The description doesn't add any further meaning beyond this, such as examples or constraints (e.g., case sensitivity, partial matches). Since the schema does the heavy lifting, the baseline score of 3 is appropriate, as the description provides no additional parameter insights.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the specific action ('Get detailed information') and resource ('about a specific Docker container'), with explicit enumeration of the information types included (state, network, mounts, environment, resource configuration). It distinguishes from sibling tools like 'list_containers' (which likely lists containers rather than providing detailed info) and 'exec' (which executes commands).
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description implies usage context by specifying 'about a specific Docker container' and listing the detailed information returned, which suggests it's for inspecting a known container. However, it doesn't explicitly state when to use this tool versus alternatives like 'list_containers' (e.g., for overview vs. details) or 'exec' (e.g., for inspection vs. interaction), nor does it mention prerequisites or exclusions.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
list_containersA
List Docker containers. By default shows only running containers, use all=true to show all containers including stopped ones.
| Name | Required | Description | Default |
|---|---|---|---|
| all | No | Show all containers (default shows just running) |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the full burden of behavioral disclosure. It describes the default behavior (shows only running containers) and how to change it (use all=true), which adds useful context. However, it lacks details on output format, pagination, or error handling, leaving some behavioral aspects unclear for a tool with no annotations.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is front-loaded with the core purpose ('List Docker containers') and efficiently follows with usage details in a single, clear sentence. Every part of the description earns its place by providing essential information without any waste or unnecessary elaboration.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's low complexity (1 parameter, no output schema, no annotations), the description is reasonably complete for basic usage. It covers the purpose and key parameter behavior. However, without annotations or an output schema, it lacks details on return values or potential errors, which could be important for full contextual understanding.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The input schema has 100% description coverage, with the 'all' parameter fully documented in the schema. The description adds value by explaining the default behavior and the effect of setting 'all=true', but this is largely redundant with the schema's description. Since schema coverage is high, the baseline score of 3 is appropriate, as the description provides some reinforcement but no significant additional semantics.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the verb ('List') and resource ('Docker containers'), making the purpose specific and unambiguous. It distinguishes this tool from sibling tools like 'exec' and 'get_container_info' by focusing on listing rather than executing commands or getting detailed information about individual containers.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides explicit guidance on when to use this tool: 'By default shows only running containers, use all=true to show all containers including stopped ones.' This clearly defines the default behavior and how to modify it, offering practical usage instructions without needing to reference alternatives explicitly, as the context is straightforward.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
TDQS
Each tool has a clearly distinct purpose: exec for command execution, get_container_info for detailed container metadata, and list_containers for container enumeration. There is no overlap in functionality, making tool selection straightforward for an agent.
Two tools follow a consistent verb_noun pattern (get_container_info, list_containers), but exec uses a standalone verb without a noun. While the naming is readable and mostly consistent, the deviation from the pattern slightly reduces predictability.
Three tools are reasonable for a Docker container management server, covering core operations like listing, inspecting, and executing commands. However, the scope feels slightly thin, as common operations like starting/stopping containers or managing images are missing, though not critically so.
The toolset covers basic read and execute operations (list, get, exec) but lacks lifecycle management tools such as start, stop, create, or delete containers. This creates notable gaps that agents may need to work around, limiting full container management workflows.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Connectors
Operate Linux, macOS and Windows from your LLM. Every action runs through an auditable allowlist.
Develop, manage, and debug Railway projects, services, and deployments from within agents.
A registry of AI agent tools — MCP servers, APIs, CLIs, SDKs — kept current by automated ingestion.
Build, validate, deploy — HTTP APIs, cron jobs, webhooks and MCP tools — from your AI client.
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceEnables AI assistants like Claude to manage Docker containers, images, and Docker Compose deployments through the Model Context Protocol. Provides secure container lifecycle management, image operations, and multi-host Docker server connections.276MIT
- AlicenseNot gradedqualityNot gradedmaintenanceEnables AI assistants to interact with Docker containers through safe, permission-controlled access to inspect, manage, and diagnose containers, images, and compose services with built-in timeouts and AI-powered analysis.
- AlicenseNot gradedqualityDmaintenanceEnables AI assistants to manage Docker containers, images, networks, volumes, and Compose services through the Model Context Protocol. It supports system operations, command execution within containers, and integration with Docker Hub and GitHub Container Registry.1302MIT
- AlicenseNot gradedqualityDmaintenanceEnables AI assistants to manage Docker containers, images, networks, volumes, and Docker Compose services through the Model Context Protocol.186MIT
Appeared in Searches
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/davidkim9/container-exec-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server