mongodb-mcp-setup
Guide users through configuring key MongoDB MCP server options. Use this skill when a user has the MongoDB MCP server installed but hasn't configured the required environment variables, or when they ask about connecting to MongoDB/Atlas and don't have the credentials set up.
What this skill does
# MongoDB MCP Server Setup This skill guides users through configuring the MongoDB MCP server for use with an agentic client. ## Overview The MongoDB MCP server requires authentication. Users have three options: 1. **Connection String** (Option A): Direct connection to a specific cluster - Quick setup for single cluster - Requires `MDB_MCP_CONNECTION_STRING` environment variable 2. **Service Account Credentials** (Option B): MongoDB Atlas Admin API access - **Recommended for Atlas users** - simplifies authentication and data access - Access to Atlas Admin API and dynamic cluster connection via `atlas-connect-cluster` - No manual DB user credential management - Requires `MDB_MCP_API_CLIENT_ID` and `MDB_MCP_API_CLIENT_SECRET` environment variables 3. **Atlas Local** (Option C): Local development with Docker - **Best for local testing** - zero configuration required - Runs Atlas locally in Docker, requires Docker installed - No credentials or cloud cluster access This is an interactive step-by-step guide. The agent detects the user's environment and provides tailored instructions, but **never asks for or handles credentials** — users add those directly to their shell profile or agentic client config in Step 5. Make this clear to the user whenever credentials come up in Steps 3a and 3b. ## Step 0: Detect Client Before anything else, determine which agentic client the user is running. This controls how credentials are configured in Step 1 and Step 5. Run: ```bash env | grep "^CODEX_" ``` - **If no `CODEX_*` variables are present** → the user is running a **shell-based client** (Claude, Cursor, Gemini CLI, Copilot CLI, etc.). Credentials are configured via shell profile environment variables. - **If any `CODEX_*` variables are present** → the user is running **Codex**. Credentials are stored in `~/.codex/config.toml` (macOS/Linux) or `%USERPROFILE%\.codex\config.toml` (Windows), not in shell environment variables. The desktop app does not inherit shell env vars when launched from Finder, Launchpad, or the Windows Start menu. Carry this **client type** (Codex vs. shell-based) forward through every subsequent step. ## Step 1: Check Existing Configuration Check whether credentials are already configured. **For shell-based clients** — check the current environment: ```bash env | grep "^MDB_MCP" | sed '/^MDB_MCP_READ_ONLY=/!s/=.*/=[set]/' ``` **For Codex** — search `~/.codex/config.toml` (macOS/Linux) or `%USERPROFILE%\.codex\config.toml` (Windows): ```bash grep -E 'MDB_MCP_(CONNECTION_STRING|API_CLIENT_ID|API_CLIENT_SECRET|READ_ONLY)' ~/.codex/config.toml 2>/dev/null | sed '/MDB_MCP_READ_ONLY/!s/[[:space:]]*=[[:space:]].*/ = "[set]"/' ``` **Interpretation (both):** - If `MDB_MCP_CONNECTION_STRING` appears → connection string auth is configured - If both `MDB_MCP_API_CLIENT_ID` and `MDB_MCP_API_CLIENT_SECRET` appear → service account auth is configured. If only one is present, treat it as incomplete. - If `MDB_MCP_READ_ONLY` appears → read-only mode is enabled **Partial Configuration Handling:** - User wants to add read-only to existing setup (has auth, no read-only flag) → skip to Step 4 - User wants to switch authentication methods → explain they should remove the old credentials first (from `config.toml` for Codex, from their shell profile for shell-based clients), then proceed with Steps 2–5 - User wants to update credentials → skip to Step 5 **Important**: If the user wants an Atlas Admin API action (managing clusters, creating users, performance advisor) but only has `MDB_MCP_CONNECTION_STRING`, explain they need service account credentials and offer to walk through setup. ## Step 2: Present Configuration Options If no valid configuration exists, present the options: **Connection String (Option A)** — Best for: - Single cluster access - Existing database credentials - Self-hosted MongoDB or no Atlas Admin API needs **Service Account Credentials (Option B)** — Best for: - MongoDB Atlas users (recommended) - Multi-cluster switching - Atlas Admin API access (cluster management, user creation, performance monitoring) **Atlas Local (Option C)** — Best for: - Local development/testing without cloud setup - Fastest setup with Docker, no credentials required Ask the user which option they'd like to proceed with. ## Step 3a: Connection String Setup If the user chooses Option A: ### 3a.1: Explain How to Find the Connection String Explain where and how to obtain their connection string: **For MongoDB Atlas:** 1. Go to [cloud.mongodb.com](https://cloud.mongodb.com) 2. Select your cluster → click **Connect** 3. Choose **Drivers** or **Shell** → copy the connection string 4. Replace `<username>` and `<password>` with your database user credentials **For self-hosted MongoDB:** - The connection string is typically configured by your DBA or in your application config - Format: `mongodb://username:password@host:port/database` **Expected formats:** - `mongodb://username:password@host:port/database` - `mongodb+srv://username:[email protected]/database` - `mongodb://host:port` (local, no auth) Proceed to Step 4 (Determine Read-Only Access). ## Step 3b: Service Account Setup If the user chooses Option B: ### 3b.1: Guide Through Atlas Service Account Creation Direct the user to create a MongoDB Atlas Service Account: **Full documentation**: https://www.mongodb.com/docs/mcp-server/prerequisites/ Walk them through the key steps: 1. **Navigate to MongoDB Atlas** — [cloud.mongodb.com](https://cloud.mongodb.com) 2. **Select your organization** from the ORGANIZATION section near the top of the page 3. **Go to "Project Identity and Access"** on the left sidebar → **Applications** → **Create Service Account** 4. **Set Permissions** — Grant Organization Member or Project Owner (see docs for exact permission mappings) 5. **Generate Credentials** — Create Client ID and Secret - ⚠️ The **Client Secret is shown only once** — save it immediately before leaving the page 5. **Note both values** — you'll need Client ID and Client Secret for Step 5 ### 3b.2: API Access List Configuration ⚠️ **CRITICAL**: The user MUST add their IP address to the service account's API Access List, or all Atlas Admin API operations will fail. Steps: 1. On the service account details page, find **API Access List** 2. Click **Add Access List Entry** 3. Add your current IP address. Use a specific IP or CIDR range whenever possible. - ⚠️ **`0.0.0.0/0` allows access from any IP — this is a significant security risk.** Only use it as a last resort for temporary testing and remove it immediately afterward. It should never be used in production. 4. Save changes This is more secure than global Network Access settings as it only affects API access, not database connections. Proceed to Step 4 (Determine Read-Only Access). ## Step 3c: Atlas Local Setup If the user chooses Option C: ### 3c.1: Check Docker Installation Verify Docker is installed: ```bash docker info ``` If not installed, direct them to: https://www.docker.com/get-started ### 3c.2: Confirm Setup Complete Atlas Local requires no credentials — the user is ready to go: - Create deployments: `atlas-local-create-deployment` - List deployments: `atlas-local-list-deployments` - All operations work out of the box with Docker **Skip Steps 4 and 5** (no configuration needed) and proceed to Step 6 (Next Steps). ## Step 4: Determine Read-Only vs Read-Write Access **Only applies to Options A and B. Skip to Step 6 for Option C.** Ask whether they want read-only or read-write access: - **Read-Write** (default): Full data access, modifications allowed - Best for: Development, testing, administrative tasks - **Read-Only**: Data reads only, no modifications - Best for: Production data safety, reporting, compliance **If read-only**: include the read-only flag in the credential snippet in Step 5. **If read-write**: omit it (defaults to read-write). Proceed to
Related in AI Agents
skill-development
IncludedComprehensive meta-skill for creating, managing, validating, auditing, and distributing Claude Code skills and slash commands (unified in v2.1.3+). Provides skill templates, creation workflows, validation patterns, audit checklists, naming conventions, YAML frontmatter guidance, progressive disclosure examples, and best practices lookup. Use when creating new skills, validating existing skills, auditing skill quality, understanding skill architecture, needing skill templates, learning about YAML frontmatter requirements, progressive disclosure patterns, tool restrictions (allowed-tools), skill composition, skill naming conventions, troubleshooting skill activation issues, creating custom slash commands, configuring command frontmatter, using command arguments ($ARGUMENTS, $1, $2), bash execution in commands, file references in commands, command namespacing, plugin commands, MCP slash commands, Skill tool configuration, or deciding between skills vs slash commands. Delegates to docs-management skill for official documentation.
reprompter
IncludedTransform messy prompts into well-structured, effective prompts — single or multi-agent. Use when: "reprompt", "reprompt this", "clean up this prompt", "structure my prompt", rough text needing XML tags and best practices, "reprompter teams", "repromptception", "run with quality", "smart run", "smart agents", multi-agent tasks, audits, parallel work, anything going to agent teams. Don't use when: simple Q&A, pure chat, immediate execution-only tasks. See "Don't Use When" section for details. Outputs: Structured XML/Markdown prompt, quality score (before/after), optional team brief + per-agent sub-prompts, agent team output files. Success criteria: Single mode quality score ≥ 7/10; Repromptception per-agent prompt quality score 8+/10; all required sections present, actionable and specific.
adaptive-compaction
IncludedAdaptive add-on policy and recovery layer that decides WHEN to compact, prune, snapshot, or fork -- replacing fixed-percent auto-compaction across Claude Code, Codex, and MCP-capable hosts. Trigger on auto-compact timing or damage: "when should I compact", "is it safe to compact now or start a fresh session", "auto-compact fires too early/mid-task", "switching to an unrelated task but the window still has space", "context rot", "answers get worse the longer the session runs", "the agent forgot the plan or my decisions after it summarized", "add a layer on top that manages context without changing the agent", raising autoCompactWindow to give the policy room, or installing/tuning a cross-tool compaction policy or PreCompact hook -- even when "compaction" is never said but the problem is context-window pressure or post-summarization memory loss. Do NOT use to summarize a conversation, build RAG, write a summarization prompt (decides WHEN not HOW), or answer max-context-length trivia.
agent-skill-creator
IncludedCreate cross-platform agent skills from workflow descriptions. Activates when users ask to create an agent, automate a repetitive workflow, create a custom skill, or need advanced agent creation. Triggers on phrases like create agent for, automate workflow, create skill for, every day I have to, daily I need to, turn process into agent, need to automate, create a cross-platform skill, validate this skill, export this skill, migrate this skill. Supports single skills, multi-agent suites, transcript processing, template-based creation, interactive configuration, cross-platform export, and spec validation.
llm-wiki
IncludedUse when building or maintaining a persistent personal knowledge base (second brain) in Obsidian where an LLM incrementally ingests sources, updates entity/concept pages, maintains cross-references, and keeps a synthesis current. Triggers include "second brain", "Obsidian wiki", "personal knowledge management", "ingest this paper/article/book", "build a research wiki", "compound knowledge", "Memex", or whenever the user wants knowledge to accumulate across sessions instead of being re-derived by RAG on every query.
skill-master
IncludedAgent Skills authoring, evaluation, and optimization. Create, edit, validate, benchmark, and improve skills following the agentskills.io specification. Use when designing SKILL.md files, structuring skill folders (references, scripts, assets), ingesting external documentation into skills, running trigger evals, benchmarking skill quality, optimizing descriptions, or performing blind A/B comparisons. Keywords: agentskills.io, SKILL.md, skill authoring, eval, benchmark, trigger optimization.