IDA Pro MCP Setup: A Safer Reverse-Engineering Workflow
IDA Pro MCP can connect an MCP client to IDA Pro for decompilation, disassembly, search, call-graph work, and carefully gated edits. Start with a disposable analysis copy, keep debugger and arbitrary-Python capabilities off the critical path, and verify read-only results before enabling annotations, rewrites, patches, or execution.

IDA Pro MCP can connect an MCP client to IDA Pro for decompilation, disassembly, search, call-graph work, and carefully gated edits. Start with a disposable analysis copy, keep debugger and arbitrary-Python capabilities off the critical path, and verify read-only results before enabling annotations, rewrites, patches, or execution.
Table of contents
- What IDA Pro MCP exposes
- Meet the IDA and Python prerequisites
- Install the plugin and connect a client
- Begin with read-only binary inspection
- Gate renames, patches, Python, and debugger actions
- Fix port, plugin, and headless-mode failures
- FAQ
What IDA Pro MCP exposes
Use IDA Pro MCP as a controlled bridge between an MCP client and an IDA Pro analysis database. Begin with read-only decompilation and disassembly, then decide separately whether the agent may annotate, rename, rewrite, execute Python, or interact with the debugger.
The server can expose operations for:
- Decompiling and disassembling functions
- Reading and rewriting comments
- Renaming variables and functions
- Recovering and applying types and structures
- Reading memory and inspecting stack frames
- Searching for bytes, instructions, and strings
- Building call graphs
- Exporting functions
- Running arbitrary Python inside IDA
- Optionally driving the debugger
The GUI plugin exposes an HTTP/SSE endpoint on port 13337. Its documented authentication mode is none, so treat the endpoint as a boundary that should remain within an appropriately controlled analysis environment. Do not place an unreviewed client on the critical path to a production, sensitive, or irreplaceable database.
The IDA Pro MCP directory entry is a practical place to confirm the server’s scope before configuring a client. The project is also listed in the Hex-Rays plugin directory, while the MCP architecture documentation explains how clients, servers, and transports fit together. MCP architecture
Meet the IDA and Python prerequisites
Use Python 3.11 or higher and IDA Pro 8.3 or higher; IDA Pro 9 is recommended. Select the newest available Python with idapyswitch, and use a supported MCP client such as Claude, Claude Code, Cursor, VS Code, Windsurf, or Cline.
IDA Free is not supported. Before installing, verify:
- IDA Pro is installed and meets the version requirement.
- Python is version 3.11 or higher.
idapyswitchselects the newest Python installation.- A supported MCP client is available.
- For headless operation, idalib is activated globally with
py-activate-idalib.py. - For headless operation,
uvis installed.
This dependency boundary matters because IDA Pro supplies the analysis environment, Python supplies the scripting runtime, and the MCP client supplies the conversational control surface. Keep those roles distinct while diagnosing failures. The IDAPython documentation is the supplied reference for the Python side of the environment.

Install the plugin and connect a client
Install the project from its verified archive URL, then let the installer configure the supported client where applicable. The exact installation command is:
pip install https://github.com/mrexodia/ida-pro-mcp/archive/refs/heads/main.zip && ida-pro-mcp --install
For Claude Code, the documented path uses the author’s plugin marketplace. For other supported clients, use ida-pro-mcp --install or print the client configuration with:
ida-pro-mcp --config
The GUI path exposes the HTTP/SSE service from IDA Pro. Start IDA Pro with a disposable copy of the target database, allow the plugin to load, and then connect the MCP client using the generated or installed configuration.
A useful first check is whether the client can identify the server and request a harmless read-only operation. If the client expects a different transport, compare its configuration with the documented HTTP transport rather than changing the server command or inventing flags. The IDA Pro MCP repository remains the authoritative supplied source for installation and client setup.
Begin with read-only binary inspection
Start by asking the connected client for observations that do not change the database: function lists, decompiled output, disassembly, strings, byte patterns, memory reads, stack-frame details, or call-graph relationships. Confirm that the returned information matches what you can see in IDA Pro before permitting changes.
A cautious first sequence is:
- Open a disposable analysis copy.
- Request one known function’s decompilation.
- Compare the result with IDA Pro’s own view.
- Request disassembly, strings, or references for the same area.
- Record uncertainty instead of asking the agent to resolve it by editing.
- Repeat with a second function or search target.
This sequence tests the connection, database context, and basic analysis access without introducing edits. It also gives you a baseline for later annotations: if a rename or comment changes the database, you can compare it with the earlier read-only state.
MCP clients provide structured access to tools, but the client should not be treated as proof that an interpretation is correct. Ask for evidence from the binary—addresses, instructions, callers, callees, strings, or types—before accepting a conclusion. The MCP security guidance provides the relevant model for treating tool access as permissioned capability.
Gate renames, patches, Python, and debugger actions
Keep all database-changing and execution-capable actions behind an explicit approval step. Read-only inspection can establish context; it should not automatically authorize renames, comments, type application, patches, arbitrary Python, or debugger control.
Use a simple capability gate:
| Capability | Initial policy | Approval condition |
|---|---|---|
| Decompile, disassemble, search | Allow | Output matches the intended database |
| Read memory and stack frames | Allow with scope | Target address and reason are clear |
| Comments, renames, types, structures | Ask first | Proposed change and affected symbols are shown |
| Export functions | Ask first | Destination and exported scope are confirmed |
| Patches or rewrites | Require approval | Original location, replacement, and rollback copy are known |
| Arbitrary Python | Keep off the critical path | Code is reviewed and the disposable copy is active |
| Debugger actions | Keep off the critical path | Target, state change, and observation goal are explicit |
Do not combine a broad analysis request with permission to modify the database. Ask the agent to explain what it intends to change, where, and why. For Python, review the script as code rather than treating it as a harmless extension of a natural-language request. For debugger actions, require a clear target and expected observation.
The read/write files capability guide is a useful adjacent reference when a workflow includes exports or file changes. Keep file operations, IDA edits, Python execution, and debugger control as separate approvals.
Fix port, plugin, and headless-mode failures
Diagnose failures by checking the documented transport, port, client configuration, and prerequisites in that order. The MCP debugging guide recommends treating the client, server, transport, and tool call as separate layers rather than changing several variables at once.
| Symptom | Check first | Corrective action |
|---|---|---|
| Client cannot connect | HTTP transport and port 13337 | Confirm the GUI plugin is loaded and the client configuration points to the documented endpoint |
| Plugin does not load | IDA version and product edition | Use IDA Pro 8.3 or higher; IDA Free is not supported |
| Python-related failure | Python version and selection | Use Python 3.11 or higher and select the newest Python with idapyswitch |
| Manual client setup fails | Generated configuration | Run ida-pro-mcp --config and transfer the printed configuration accurately |
| Headless mode fails | idalib activation and uv | Confirm global activation with py-activate-idalib.py and verify that uv is installed |
| Analysis reaches the wrong database | IDA instance or database context | Close the connection, reopen the intended disposable copy, and repeat a read-only test |
Headless operation uses the idalib-mcp supervisor with persistent per-database worker processes and can run over stdio or HTTP. If the GUI route is working, validate it first before adding headless components. If the failure remains unclear, consult the MCP debugging guide and use MCPtrove’s configuration doctor as the next practical diagnostic step.