Authenticated remote MCP server for managing MongoDB, running on Cloudflare Workers with WorkOS OAuth.
MongoDB MCP demonstrates solid fundamentals: all 7 tools have clear verb-noun naming (list*, find*, count, dbStats, collStats), descriptions present and actionable (avg ~80 chars), and input schemas with Zod validation. Tool annotations (readOnlyHint, destructiveHint, idempotentHint) are correctly applied. However, parameter descriptions for union-type fields (filter, projection, sort) are generic and lack format guidance for Extended JSON syntax. Output schemas are not documented, LLMs cannot predict response structure. Error handling includes permission hints but lacks recovery guidance for common failures. The 'find' tool caps results at 50 docs by default, addressing result limits, but pagination metadata (total count, next_cursor) is absent.
Return collStats for a collection (via $collStats aggregation).
Count documents matching a filter (countDocuments).
Return db.stats() for a database.
Run find() against a collection. Returns up to `limit` documents.
Return a single document.
List collections in a database.
List databases on the cluster with their size on disk.
Union-type parameters (filter, projection, sort) lack format guidance. Description states 'JSON object or JSON/Extended JSON string' but does not explain when to use each format or provide examples of $oid, $date syntax. LLMs will guess and pass invalid Extended JSON.
Output schemas are not documented. Tools return stringified Extended JSON via ok() helper, but LLMs cannot predict field names, types, or structure. Agents cannot plan downstream calls or extract specific fields reliably.
Error handling returns permission hints but lacks recovery guidance for non-auth errors (e.g., 'collection not found', 'invalid filter syntax'). Errors should suggest next steps: 'Try listCollections() to verify the collection exists.'
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | A | 82 | 2026-07-28+ | v2 |
Pagination metadata missing. 'find' tool accepts limit/skip but does not return total count or next_cursor. Large result sets cannot be iterated safely; LLMs cannot determine if more results exist.
Parameter descriptions do not specify constraints. 'limit' defaults to 50 but no min/max documented. 'skip' has no bounds. LLMs may pass absurd values (limit=999999, skip=-1) that break queries or cause timeouts.