Environment Variables & Command Line Arguments
- reference
Reference for all environment variables and CLI arguments used to configure the Couchbase MCP Server, including authentication examples.
The MCP server can be configured using environment variables or command line arguments. If both are specified, command line arguments take priority over environment variables.
Configuration Reference
| Environment Variable | CLI Argument | Description | Default | |
|---|---|---|---|---|
|
|
Connection string to the Couchbase cluster. See Configuring Connection String. |
Required |
|
|
|
Username for basic authentication. See Configuring Authentication. |
Required (or mTLS) |
|
|
|
Password for basic authentication. See Configuring Authentication. |
Required (or mTLS) |
|
|
|
Path to client certificate for mTLS. See Configuring Authentication. |
Required if using mTLS |
|
|
|
Path to client key for mTLS. See Configuring Authentication. |
Required if using mTLS |
|
|
|
Path to server root certificate for TLS (self-signed / untrusted certs). Not required for Capella. |
||
|
|
Prevent all data modifications (KV and Query). See Read-Only Mode for details. |
|
|
|
|
Transport mode selection: |
|
|
|
|
Host for HTTP transport mode |
|
|
|
|
Port for HTTP transport mode |
|
|
|
|
Tools to disable. See Disabling Tools |
None |
|
|
|
Tools requiring user confirmation before execution. See Elicitation/Confirmation for Tool Calls |
None |
|
|
|
JWKS endpoint for verifying JWT signatures (Streamable HTTP only). See OAuth. |
None |
|
|
|
Expected JWT |
None |
|
|
|
Expected JWT |
None |
|
|
|
JWT signing algorithm. See OAuth. |
|
|
|
|
Public base URL of this server; enables Protected Resource Metadata / DCR discovery. See OAuth. |
None |
|
|
|
Custom label for the read scope, for IdPs using a different naming convention. See OAuth. |
|
|
|
|
Custom label for the write scope, for IdPs using a different naming convention. See OAuth. |
|
|
|
|
Minimum log level: |
|
|
|
|
Log output sinks: |
|
|
|
|
Base path for the per-level log files; used when the |
|
|
|
|
Deprecated — use |
|
|
|
|
Maximum size (MB) per log file before rotation, for all levels unless overridden per level. See Logging. |
|
|
|
|
Number of rotated backup files kept per level, in addition to the live file, for all levels unless overridden per level. See Logging. |
|
|
|
|
Rotation size in MB for the |
Inherits |
|
|
|
Rotation size in MB for the |
Inherits |
|
|
|
Rotation size in MB for the |
Inherits |
|
|
|
Rotation size in MB for the |
Inherits |
|
|
|
Rotated backups kept for the |
Inherits |
|
|
|
Rotated backups kept for the |
Inherits |
|
|
|
Rotated backups kept for the |
Inherits |
|
|
|
Rotated backups kept for the |
Inherits |
Both the rotation size and backup count can also be set per log level (error, warning, info, debug) — see Per-Level Overrides.
|
Configuring Authentication
For authentication, you need either:
-
Username and Password (basic authentication)
or
-
Client Certificate and Key paths (mTLS authentication)
If both are specified, mTLS takes priority.
Optionally, you can specify a CA root certificate path to validate server certificates (useful for self-signed certificates).
Example Configurations
All examples below use uvx to run the server.
These can be replaced with the corresponding docker run commands - see Streamable HTTP for the Docker HTTP configuration.
|
How to: Basic Auth
Provide a Couchbase database username and password. For Basic Authentication setup, see Manage Database Credentials (Capella) or Manage Users and Roles (self-managed).
{
"mcpServers": {
"couchbase": {
"command": "uvx",
"args": ["couchbase-mcp-server"],
"env": {
"CB_CONNECTION_STRING": "couchbases://your-connection-string",
"CB_USERNAME": "username",
"CB_PASSWORD": "password"
}
}
}
}
How to: Connect to Capella
-
Connection string: Use
couchbases://(withs) — TLS is always enabled. Find your connection string in the Capella UI under Cluster > Connect. -
TLS certificates: The bundled Capella root CA is used automatically. You do not need to set
CB_CA_CERT_PATH. -
IP allowlisting: Ensure the machine running the MCP server has its IP allowed in the Capella cluster settings. Required only when the server reaches Capella over the public Internet — not if it’s on a VPC or a private network connected to Capella.
{
"mcpServers": {
"couchbase": {
"command": "uvx",
"args": ["couchbase-mcp-server"],
"env": {
"CB_CONNECTION_STRING": "couchbases://cb.your-capella-endpoint.cloud.couchbase.com",
"CB_USERNAME": "username",
"CB_PASSWORD": "password"
}
}
}
}
How to: Connect to Self-Managed Server with Certificates
-
Connection string: Use
couchbase://for unencrypted connections orcouchbases://for TLS. -
TLS certificates: If using TLS with self-signed or untrusted certificates, set
CB_CA_CERT_PATHto your CA root certificate. -
mTLS: For certificate-based authentication, use
CB_CLIENT_CERT_PATHandCB_CLIENT_KEY_PATHinstead of username/password.
Basic auth with custom CA:
{
"mcpServers": {
"couchbase": {
"command": "uvx",
"args": ["couchbase-mcp-server"],
"env": {
"CB_CONNECTION_STRING": "couchbases://your-server-hostname",
"CB_USERNAME": "username",
"CB_PASSWORD": "password",
"CB_CA_CERT_PATH": "/path/to/ca-certificate.pem"
}
}
}
}
mTLS (no username/password):
{
"mcpServers": {
"couchbase": {
"command": "uvx",
"args": ["couchbase-mcp-server"],
"env": {
"CB_CONNECTION_STRING": "couchbases://your-server-hostname",
"CB_CLIENT_CERT_PATH": "/path/to/client-certificate.pem",
"CB_CLIENT_KEY_PATH": "/path/to/client.key",
"CB_CA_CERT_PATH": "/path/to/ca-certificate.pem"
}
}
}
}
How to: mTLS Based Auth
For environments requiring certificate-based authentication. For mTLS setup, see Configure Client Certificate Authentication.
{
"mcpServers": {
"couchbase": {
"command": "uvx",
"args": ["couchbase-mcp-server"],
"env": {
"CB_CONNECTION_STRING": "couchbases://your-connection-string",
"CB_CLIENT_CERT_PATH": "/path/to/client-certificate.pem",
"CB_CLIENT_KEY_PATH": "/path/to/client.key"
}
}
}
}