MCP Directory

IDA Pro MCP Setup: A Safer Reverse-Engineering Workflow

IDA Pro MCP can connect an MCP client to IDA Pro for decompilation, disassembly, search, call-graph work, and carefully gated edits. Start with a disposable analysis copy, keep debugger and arbitrary-Python capabilities off the critical path, and verify read-only results before enabling annotations, rewrites, patches, or execution.

MCPtrove·September 22, 2026·6 min read
Vibrant green numbers on a computer screen, showcasing binary code and data streams.
Photo by Tibe De Kort on Pexels

IDA Pro MCP can connect an MCP client to IDA Pro for decompilation, disassembly, search, call-graph work, and carefully gated edits. Start with a disposable analysis copy, keep debugger and arbitrary-Python capabilities off the critical path, and verify read-only results before enabling annotations, rewrites, patches, or execution.

Table of contents

What IDA Pro MCP exposes

Use IDA Pro MCP as a controlled bridge between an MCP client and an IDA Pro analysis database. Begin with read-only decompilation and disassembly, then decide separately whether the agent may annotate, rename, rewrite, execute Python, or interact with the debugger.

The server can expose operations for:

  • Decompiling and disassembling functions
  • Reading and rewriting comments
  • Renaming variables and functions
  • Recovering and applying types and structures
  • Reading memory and inspecting stack frames
  • Searching for bytes, instructions, and strings
  • Building call graphs
  • Exporting functions
  • Running arbitrary Python inside IDA
  • Optionally driving the debugger

The GUI plugin exposes an HTTP/SSE endpoint on port 13337. Its documented authentication mode is none, so treat the endpoint as a boundary that should remain within an appropriately controlled analysis environment. Do not place an unreviewed client on the critical path to a production, sensitive, or irreplaceable database.

The IDA Pro MCP directory entry is a practical place to confirm the server’s scope before configuring a client. The project is also listed in the Hex-Rays plugin directory, while the MCP architecture documentation explains how clients, servers, and transports fit together. MCP architecture

Meet the IDA and Python prerequisites

Use Python 3.11 or higher and IDA Pro 8.3 or higher; IDA Pro 9 is recommended. Select the newest available Python with idapyswitch, and use a supported MCP client such as Claude, Claude Code, Cursor, VS Code, Windsurf, or Cline.

IDA Free is not supported. Before installing, verify:

  1. IDA Pro is installed and meets the version requirement.
  2. Python is version 3.11 or higher.
  3. idapyswitch selects the newest Python installation.
  4. A supported MCP client is available.
  5. For headless operation, idalib is activated globally with py-activate-idalib.py.
  6. For headless operation, uv is installed.

This dependency boundary matters because IDA Pro supplies the analysis environment, Python supplies the scripting runtime, and the MCP client supplies the conversational control surface. Keep those roles distinct while diagnosing failures. The IDAPython documentation is the supplied reference for the Python side of the environment.

Abstract green matrix code background with binary style.
Photo by Markus Spiske on Pexels

Install the plugin and connect a client

Install the project from its verified archive URL, then let the installer configure the supported client where applicable. The exact installation command is:

pip install https://github.com/mrexodia/ida-pro-mcp/archive/refs/heads/main.zip && ida-pro-mcp --install

For Claude Code, the documented path uses the author’s plugin marketplace. For other supported clients, use ida-pro-mcp --install or print the client configuration with:

ida-pro-mcp --config

The GUI path exposes the HTTP/SSE service from IDA Pro. Start IDA Pro with a disposable copy of the target database, allow the plugin to load, and then connect the MCP client using the generated or installed configuration.

A useful first check is whether the client can identify the server and request a harmless read-only operation. If the client expects a different transport, compare its configuration with the documented HTTP transport rather than changing the server command or inventing flags. The IDA Pro MCP repository remains the authoritative supplied source for installation and client setup.

Begin with read-only binary inspection

Start by asking the connected client for observations that do not change the database: function lists, decompiled output, disassembly, strings, byte patterns, memory reads, stack-frame details, or call-graph relationships. Confirm that the returned information matches what you can see in IDA Pro before permitting changes.

A cautious first sequence is:

  1. Open a disposable analysis copy.
  2. Request one known function’s decompilation.
  3. Compare the result with IDA Pro’s own view.
  4. Request disassembly, strings, or references for the same area.
  5. Record uncertainty instead of asking the agent to resolve it by editing.
  6. Repeat with a second function or search target.

This sequence tests the connection, database context, and basic analysis access without introducing edits. It also gives you a baseline for later annotations: if a rename or comment changes the database, you can compare it with the earlier read-only state.

MCP clients provide structured access to tools, but the client should not be treated as proof that an interpretation is correct. Ask for evidence from the binary—addresses, instructions, callers, callees, strings, or types—before accepting a conclusion. The MCP security guidance provides the relevant model for treating tool access as permissioned capability.

Gate renames, patches, Python, and debugger actions

Keep all database-changing and execution-capable actions behind an explicit approval step. Read-only inspection can establish context; it should not automatically authorize renames, comments, type application, patches, arbitrary Python, or debugger control.

Use a simple capability gate:

CapabilityInitial policyApproval condition
Decompile, disassemble, searchAllowOutput matches the intended database
Read memory and stack framesAllow with scopeTarget address and reason are clear
Comments, renames, types, structuresAsk firstProposed change and affected symbols are shown
Export functionsAsk firstDestination and exported scope are confirmed
Patches or rewritesRequire approvalOriginal location, replacement, and rollback copy are known
Arbitrary PythonKeep off the critical pathCode is reviewed and the disposable copy is active
Debugger actionsKeep off the critical pathTarget, state change, and observation goal are explicit

Do not combine a broad analysis request with permission to modify the database. Ask the agent to explain what it intends to change, where, and why. For Python, review the script as code rather than treating it as a harmless extension of a natural-language request. For debugger actions, require a clear target and expected observation.

The read/write files capability guide is a useful adjacent reference when a workflow includes exports or file changes. Keep file operations, IDA edits, Python execution, and debugger control as separate approvals.

Fix port, plugin, and headless-mode failures

Diagnose failures by checking the documented transport, port, client configuration, and prerequisites in that order. The MCP debugging guide recommends treating the client, server, transport, and tool call as separate layers rather than changing several variables at once.

SymptomCheck firstCorrective action
Client cannot connectHTTP transport and port 13337Confirm the GUI plugin is loaded and the client configuration points to the documented endpoint
Plugin does not loadIDA version and product editionUse IDA Pro 8.3 or higher; IDA Free is not supported
Python-related failurePython version and selectionUse Python 3.11 or higher and select the newest Python with idapyswitch
Manual client setup failsGenerated configurationRun ida-pro-mcp --config and transfer the printed configuration accurately
Headless mode failsidalib activation and uvConfirm global activation with py-activate-idalib.py and verify that uv is installed
Analysis reaches the wrong databaseIDA instance or database contextClose the connection, reopen the intended disposable copy, and repeat a read-only test

Headless operation uses the idalib-mcp supervisor with persistent per-database worker processes and can run over stdio or HTTP. If the GUI route is working, validate it first before adding headless components. If the failure remains unclear, consult the MCP debugging guide and use MCPtrove’s configuration doctor as the next practical diagnostic step.

FAQ

Is IDA Free supported?

No. IDA Pro MCP requires IDA Pro 8.3 or higher; IDA Pro 9 is recommended, and IDA Free is not supported.

What Python version does IDA Pro MCP require?

Use Python 3.11 or higher and select the newest Python with idapyswitch. Headless mode also requires globally activated idalib and uv.

What transport and port does the GUI plugin use?

The GUI plugin uses HTTP/SSE on port 13337, with no authentication documented for the transport. Keep the endpoint within a controlled analysis environment.

Should arbitrary Python or the debugger be enabled first?

No. Begin with read-only decompilation, disassembly, searches, and related inspection. Enable annotations or execution only after the database, request, and intended effect have been reviewed.

Put this into practice

Browse MCP servers by capability, or check your own setup's tool budget and security.

More in Security

Browse all security articles.