An MCP server for MarkLogic 12 that enables AI agents to interrogate, query, and manage MarkLogic databases using native capabilities including full-text search, Optic queries, SPARQL, bulk import/export, and TDE schema management.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
When Vitest UI server is listening, arbitrary file can be read and executed
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
process.env. You'll be asked to provide them before it can run.ANTHROPIC_API_KEY— Claude Desktop Built into the app (uses your Anthropic account)AWS_QUICKSIGHT_ACCOUNT_ID— _(none)_ QuickSight account IDAWS_REGION— _(none)_ AWS region for QuickSight integrationBUILD_TIMEFLUX_RUNNER_URL— _(none)_ Flux runner HTTP URL (e.g. http://localhost:8082)GIT_COMMITLOG_FORMAT— json json or prettyLOG_LEVEL— info debug, info, warn, errorMCP_API_KEY— ML_HOST=<host> ML_PASSWORD=<pass> =<secret> \MCP_CORS_ORIGIN— _(all)_ Restrict CORS to a single origin (default: allow all)MCP_HTTP_HOST— 0.0.0.0 Bind address for HTTP transportMCP_HTTP_PORT— MCP_TRANSPORT=http =3000 ML_HOST=your-host ML_USERNAME=admin ML_PASSWORD=pass \MCP_TRANSPORT— http MCP_HTTP_PORT=3000 ML_HOST=your-host ML_USERNAME=admin ML_PASSWORD=pass \MCP_TRUST_PROXYML_ALLOW_EVAL— Read-only by default — writes gated behind ML_READONLY=false, eval gated behind =trueML_AUTH_TYPE— "": "basic",ML_DATABASE— Documents Default databaseML_DHF_CLIENT_JAR— _(none)_ Absolute path to marklogic-data-hub-<version>-client.jarML_DHF_JOBS_PORT— _(ML_DHF_PORT+2)_ DHF jobs app server portML_DHF_PORT— _(ML_PORT)_ DHF staging app server portML_HOST— "": "your-marklogic-host",ML_MANAGEMENT_PORT— "": "8002",ML_MGMT_PORTML_OAUTH_TOKEN— _(none)_ Static Bearer token; required in stdio mode when ML_AUTH_TYPE=oauthML_PASSWORD— "": "your-password",ML_PORT— "": "8000",ML_READONLY— Read-only by default — writes gated behind =false, eval gated behind ML_ALLOW_EVAL=trueML_SSL— false Enable HTTPSML_SSL_REJECT_UNAUTHORIZED— true Reject self-signed SSL certificates (false for dev environments)ML_TIMEOUT_MS— 30000 HTTP request timeout for MarkLogic calls (milliseconds)ML_USERML_USERNAME— "": "admin",OPENAI_API_KEY— OpenAI-compatible agents Agent's own environment or config fileSEMAPHORE_HOST— ML_HOST=marklogic =semaphore ML_PASSWORD=admin \SEMAPHORE_KMM_PORT— 5080 Studio / KMM portSEMAPHORE_PASSWORD— _(none)_ KMM passwordSEMAPHORE_SCS_PORT— 5058 Classification Server portSEMAPHORE_SSLSEMAPHORE_TIMEOUT_MSSEMAPHORE_URL— _(none)_ Explicit CLS URL override (takes precedence over host:port)SEMAPHORE_USERNAME— _(none)_ KMM username[](https://m8ven.ai/mcp/tternquist-marklogic-mcp-1uk9hi)