mcp-shodan

MCP.Pizza Chef: w0h1v

Seven look-only tools cover ground security folk usually cover by hand: what services an address is running, who owns it, forward and reverse name lookups, the full story on a numbered vulnerability, and which known flaws affect a given product. Nothing here changes or scans anything on your behalf. It refuses to start without a Shodan account key, even though three of the seven need no key at all, and filtered searches spend Shodan query credits that free accounts have very few of.

Data
Web/Research

Use This MCP server To

Check what services an address is exposing to the internet Look up the details of a specific vulnerability by its number Find which known flaws affect software we already run Resolve a list of domain names to their addresses See which company owns an address that showed up in our logs Find out whether a flaw is being actively exploited

README

Shodan MCP Server

smithery badge MCP Registry

A Model Context Protocol (MCP) server for querying the Shodan API and Shodan CVEDB. This server provides comprehensive access to Shodan's network intelligence and security services, including IP reconnaissance, DNS operations, vulnerability tracking, and device discovery. All tools provide structured, formatted output for easy analysis and integration.

Quick Start (Recommended)

Installing via Claude Code

claude mcp add --transport stdio --env SHODAN_API_KEY=your-shodan-api-key shodan -- npx -y @burtthecoder/mcp-shodan

Installing via Codex CLI

codex mcp add shodan --env SHODAN_API_KEY=your-shodan-api-key -- npx -y @burtthecoder/mcp-shodan

Installing via Gemini CLI

gemini mcp add -e SHODAN_API_KEY=your-shodan-api-key shodan npx -y @burtthecoder/mcp-shodan

Installing via Smithery

mcp-shodan FAQ

Do I need a paid Shodan account?
You need a Shodan account key at minimum, and the program will not even start without one. Searches that use filters spend query credits, and a free account has very few, so anything beyond occasional use realistically means paying Shodan for a membership or credits.
Does the setting for how many results I want actually work?
No. It is handed to Shodan under a name Shodan does not recognise, and the results are never trimmed afterwards, so a search can come back with up to a hundred entries no matter what number you ask for.
Can it change or scan anything?
No. All seven tools only read what Shodan already knows. It never launches a scan, never touches the machines you ask about, and cannot alter anything anywhere.
Can I use this to check whether one of our own servers is exposed?
Yes. Give it the address and it reports the open ports, the services and versions behind them, the certificate details, and any known weaknesses Shodan has recorded.
Which apps does it work in?
Claude Code, Codex, Gemini CLI, and Claude Desktop all have one-line install commands in the instructions, and there is a Smithery installer. Any app that accepts a pasted server entry works too.
How hard is setup?
Easy. One command installs it, and you paste your Shodan key alongside. There is no building or container work unless you want to run it from source.
Do the vulnerability lookups need the key?
In practice yes, because the program will not start without one, but three of them — vulnerability detail, product lookups, and flaws by product — actually query a free public database that needs no key.
Is it still maintained?
The code was last changed in March 2026, so it is quiet but current, and it carries a permissive MIT licence that is fine for workplace use.