Configuration and flags changeddocs/2026-07-28/tools/inspector/configuration
Nearest release: v2.1.221, published 22 hours after upstream edited the page. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.
Upstream edited this page at 2 Aug 2026 23:45 UTC, give or take a minute or two: the time comes from Anthropic’s own sitemap rather than from a commit. This site recorded the change at 28 Sep 2026 22:07 UTC.
Upstream edited
Recorded here
Lines+56added
Lines−56removed
From line
6
where the diff opens
First seen
14 Aug 2026
this site's first read of the page
Recorded edits2to this page, all time
The whole hunk
from line 6, old and new numbered
/
from line 6
66
77## The launcher owns exactly two things
88
9| Flag | Behavior |
10| --------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
9| Flag | Behavior |
10| - | - |
1111| `--web` / `--cli` / `--tui` | Selects the client, `--web` by default. Passing more than one fails with `Specify at most one of --web, --cli, or --tui.` Launcher flags must come first: parsing stops at the first argument the launcher does not own, and everything from that point on is forwarded to the client unchanged. |
12| `-h` / `--help` | With no mode flag, prints the launcher's own help and exits. With a mode flag it is forwarded, so `mcp-inspector --cli --help` prints the CLI's help. |
12| `-h` / `--help` | With no mode flag, prints the launcher's own help and exits. With a mode flag it is forwarded, so `mcp-inspector --cli --help` prints the CLI's help. |
1313
1414Everything below belongs to a client.
1515
from line 19
1919
2020All three clients resolve `--catalog` and `--config` through the same shared code, so each flag behaves the same in the web app, the CLI, and the TUI. Where the two differ from each other is the table below.
2121
22| | `--catalog <path>` | `--config <path>` |
23| --------------------------- | ---------------------------------------------------------------------------- | ------------------------------------------------------- |
24| **Writable?** | Yes, the Inspector's own server list. | No. Served as-is, never written, seeded, or migrated. |
25| **Missing file?** | Created and seeded (see below). | **Errors.** |
26| **Default** | `~/.mcp-inspector/mcp.json`, or the `MCP_CATALOG_PATH` environment variable. | None; you must pass it. |
27| **Editable in the web UI?** | Yes. | No. |
28| **Use it for** | Your own working set of servers. | A read-only session against someone else's config file. |
22| | `--catalog <path>` | `--config <path>` |
23| - | - | - |
24| **Writable?** | Yes, the Inspector's own server list. | No. Served as-is, never written, seeded, or migrated. |
25| **Missing file?** | Created and seeded (see below). | **Errors.** |
26| **Default** | `~/.mcp-inspector/mcp.json`, or the `MCP_CATALOG_PATH` environment variable. | None; you must pass it. |
27| **Editable in the web UI?** | Yes. | No. |
28| **Use it for** | Your own working set of servers. | A read-only session against someone else's config file. |
2929
3030The two are **mutually exclusive**, and neither combines with an ad-hoc target. Passing both is rejected identically by all three clients.
3131
from line 73
7373
7474Defined **separately by each of web, CLI, and TUI**, so they're available in all three, with the divergences noted:
7575
76| Flag | Meaning | Divergence |
77| ------------------------ | ----------------------------------------------------- | ----------------------------------------------------------------------------------------------- |
78| `--catalog <path>` | Writable catalog file. | None |
79| `--config <path>` | Read-only session file. | None |
80| `--server <name>` | Pick one named server out of the file. | **Web and CLI only.** The TUI loads every server in the file and lets you choose interactively. |
81| `--transport <type>` | `stdio`, `sse`, or `http`. | Ad-hoc targets only. |
82| `--server-url <url>` | Server URL for SSE/HTTP. | Ad-hoc targets only. |
83| `--cwd <path>` | Working directory for a stdio server process. | None |
84| `-e <KEY=VALUE>` | Environment variables for a stdio server. Repeatable. | None |
85| `--header "Name: Value"` | HTTP headers for an HTTP/SSE server. Repeatable. | Requires an ad-hoc HTTP/SSE server on the web client. |
86| `[target...]` | Positional command/URL for one ad-hoc server. | None |
76| Flag | Meaning | Divergence |
77| - | - | - |
78| `--catalog <path>` | Writable catalog file. | None |
79| `--config <path>` | Read-only session file. | None |
80| `--server <name>` | Pick one named server out of the file. | **Web and CLI only.** The TUI loads every server in the file and lets you choose interactively. |
81| `--transport <type>` | `stdio`, `sse`, or `http`. | Ad-hoc targets only. |
82| `--server-url <url>` | Server URL for SSE/HTTP. | Ad-hoc targets only. |
83| `--cwd <path>` | Working directory for a stdio server process. | None |
84| `-e <KEY=VALUE>` | Environment variables for a stdio server. Repeatable. | None |
85| `--header "Name: Value"` | HTTP headers for an HTTP/SSE server. Repeatable. | Requires an ad-hoc HTTP/SSE server on the web client. |
86| `[target...]` | Positional command/URL for one ad-hoc server. | None |
8787
8888### The `--` separator
8989
from line 97
9797
9898## Web-only flags
9999
100| Flag | Meaning |
101| ------- | ----------------------------------------------------------------------------------------------------- |
100| Flag | Meaning |
101| - | - |
102102| `--dev` | Run the Vite dev server instead of the pre-built bundle. Useful when working on the Inspector itself. |
103103
104104## CLI and TUI: OAuth client flags
from line 105
105105
106106These five are defined by the **CLI and TUI** only. The web client obtains the same settings through its Client Settings dialog.
107107
108| Flag | Environment variable | Meaning |
109| ----------------------------- | ------------------------ | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
110| `--client-config <path>` | `MCP_CLIENT_CONFIG_PATH` | Install-level client config. Default `~/.mcp-inspector/storage/client.json`. |
111| `--client-id <id>` | None | OAuth client ID for a static client. Overrides `client.json`. |
112| `--client-secret <secret>` | None | OAuth client secret for confidential clients. Overrides `client.json`. |
113| `--client-metadata-url <url>` | None | CIMD metadata URL. Overrides `client.json`. |
114| `--callback-url <url>` | `MCP_OAUTH_CALLBACK_URL` | The redirect URI sent to the authorization server. Default `http://127.0.0.1:6276/oauth/callback`. Must be a loopback host (`127.0.0.1` or `localhost`): the local callback listener receives the authorization code over plaintext `http`, so any other host is rejected and there is no flag to override this. |
108| Flag | Environment variable | Meaning |
109| - | - | - |
110| `--client-config <path>` | `MCP_CLIENT_CONFIG_PATH` | Install-level client config. Default `~/.mcp-inspector/storage/client.json`. |
111| `--client-id <id>` | None | OAuth client ID for a static client. Overrides `client.json`. |
112| `--client-secret <secret>` | None | OAuth client secret for confidential clients. Overrides `client.json`. |
113| `--client-metadata-url <url>` | None | CIMD metadata URL. Overrides `client.json`. |
114| `--callback-url <url>` | `MCP_OAUTH_CALLBACK_URL` | The redirect URI sent to the authorization server. Default `http://127.0.0.1:6276/oauth/callback`. Must be a loopback host (`127.0.0.1` or `localhost`): the local callback listener receives the authorization code over plaintext `http`, so any other host is rejected and there is no flag to override this. |
115115
116116## CLI-only flags
117117
118118The whole scripting surface belongs to the CLI. See [CLI client](/docs/2026-07-28/tools/inspector/cli) for usage.
119119
120| Group | Flags |
121| ------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------ |
120| Group | Flags |
121| - | - |
122122| **What to invoke** | `--method`, `--tool-name`, `--tool-arg`, `--tool-args-json`, `--uri`, `--prompt-name`, `--prompt-args`, `--log-level`, `--metadata`, `--tool-metadata` |
123| **How to run it** | `--connect-timeout`, `--format`, `--app-info` |
124| **Auth** | `--use-stored-auth`, `--stored-auth-only`, `--relogin`, `--wait-for-auth`, `--list-stored-auth`, `--print-handoff` |
123| **How to run it** | `--connect-timeout`, `--format`, `--app-info` |
124| **Auth** | `--use-stored-auth`, `--stored-auth-only`, `--relogin`, `--wait-for-auth`, `--list-stored-auth`, `--print-handoff` |
125125
126126## Environment variables
127127
from line 129
129129
130130### Read by the launcher
131131
132| Variable | Effect |
133| ----------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
134| `MCP_DEBUG` | Append the error stack to a top-level failure. Only when set to a meaningful value: `0`, `false`, and empty read as off. |
135| `DEBUG` | Same, with the same meaningful-value rule, so a stray `DEBUG=0` doesn't turn stack traces on and `DEBUG` still works as the npm `debug` package's namespace filter. |
132| Variable | Effect |
133| - | - |
134| `MCP_DEBUG` | Append the error stack to a top-level failure. Only when set to a meaningful value: `0`, `false`, and empty read as off. |
135| `DEBUG` | Same, with the same meaningful-value rule, so a stray `DEBUG=0` doesn't turn stack traces on and `DEBUG` still works as the npm `debug` package's namespace filter. |
136136
137137### CLI and TUI
138138
139| Variable | Effect |
140| -------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
141| `MCP_CATALOG_PATH` | Fallback for `--catalog`. Honored only when no ad-hoc target is given, so a shell that exports it can still run one-off ad-hoc invocations. |
142| `MCP_CLIENT_CONFIG_PATH` | Fallback for `--client-config`. |
143| `MCP_OAUTH_CALLBACK_URL` | Fallback for `--callback-url`. |
144| `MCP_STORAGE_DIR` | Directory for the OAuth state file (`<dir>/oauth.json`). |
145| `MCP_INSPECTOR_OAUTH_STATE_PATH` | Per-file override of the OAuth state path. Takes precedence over `MCP_STORAGE_DIR`. |
146| `MCP_AUTO_OPEN_ENABLED` | Controls browser auto-open and whether interactive OAuth may run without a TTY. `true` forces auto-open and allows OAuth prompts without a TTY, `false` never opens, and unset opens only on a TTY. |
139| Variable | Effect |
140| - | - |
141| `MCP_CATALOG_PATH` | Fallback for `--catalog`. Honored only when no ad-hoc target is given, so a shell that exports it can still run one-off ad-hoc invocations. |
142| `MCP_CLIENT_CONFIG_PATH` | Fallback for `--client-config`. |
143| `MCP_OAUTH_CALLBACK_URL` | Fallback for `--callback-url`. |
144| `MCP_STORAGE_DIR` | Directory for the OAuth state file (`<dir>/oauth.json`). |
145| `MCP_INSPECTOR_OAUTH_STATE_PATH` | Per-file override of the OAuth state path. Takes precedence over `MCP_STORAGE_DIR`. |
146| `MCP_AUTO_OPEN_ENABLED` | Controls browser auto-open and whether interactive OAuth may run without a TTY. `true` forces auto-open and allows OAuth prompts without a TTY, `false` never opens, and unset opens only on a TTY. |
147147
148148### Web backend environment variables
149149
150| Variable | Effect |
151| ----------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------ |
152| `MCP_INSPECTOR_API_TOKEN` | Pin the [session token](/docs/2026-07-28/tools/inspector/web#the-session-token) instead of generating a random one per launch. |
153| `DANGEROUSLY_OMIT_AUTH` | Disable the `/api/*` token check entirely. |
154| `HOST` | Bind host. Defaults to `localhost`. |
155| `CLIENT_PORT` | Web UI port. Defaults to `6274`. |
156| `DANGEROUSLY_BIND_ALL_INTERFACES` | Required opt-in to bind a wildcard host (`0.0.0.0`, `::`, or any equivalent spelling). |
157| `ALLOWED_ORIGINS` | Comma-separated origin allow-list. **Replaces** the default list rather than merging. |
158| `MCP_SANDBOX_PORT` | Pin the MCP Apps sandbox port, which is dynamic by default. |
159| `HTTPS_PROXY` / `HTTP_PROXY` / `NO_PROXY` | Standard proxy routing for outbound MCP connections. |
150| Variable | Effect |
151| - | - |
152| `MCP_INSPECTOR_API_TOKEN` | Pin the [session token](/docs/2026-07-28/tools/inspector/web#the-session-token) instead of generating a random one per launch. |
153| `DANGEROUSLY_OMIT_AUTH` | Disable the `/api/*` token check entirely. |
154| `HOST` | Bind host. Defaults to `localhost`. |
155| `CLIENT_PORT` | Web UI port. Defaults to `6274`. |
156| `DANGEROUSLY_BIND_ALL_INTERFACES` | Required opt-in to bind a wildcard host (`0.0.0.0`, `::`, or any equivalent spelling). |
157| `ALLOWED_ORIGINS` | Comma-separated origin allow-list. **Replaces** the default list rather than merging. |
158| `MCP_SANDBOX_PORT` | Pin the MCP Apps sandbox port, which is dynamic by default. |
159| `HTTPS_PROXY` / `HTTP_PROXY` / `NO_PROXY` | Standard proxy routing for outbound MCP connections. |
160160
161161<Warning>
162162 Never combine `DANGEROUSLY_OMIT_AUTH` and `DANGEROUSLY_BIND_ALL_INTERFACES`.
No line in this hunk matches that.