Remote ChromaDB MCP server for Claude Desktop/Mobile/Code with authentication and REST API proxy.
7.0K
Remote MCP (Model Context Protocol) server that provides secure access to ChromaDB for AI assistants like Claude. Enables semantic search and vector database operations from mobile devices and remote locations.
One-command automated installation:
curl -fsSL https://raw.githubusercontent.com/meloncafe/chromadb-remote-mcp/release/scripts/install.sh | bash
The script will:
After installation:
cd chromadb-remote-mcp
docker compose up -d
Update:
docker compose pull
docker compose down
docker compose up -d
# Download configuration files
mkdir chromadb-remote-mcp && cd chromadb-remote-mcp
curl -O https://raw.githubusercontent.com/meloncafe/chromadb-remote-mcp/release/docker-compose.yml
curl -O https://raw.githubusercontent.com/meloncafe/chromadb-remote-mcp/release/.env.example
# Configure environment
cp .env.example .env
# Edit .env and set MCP_AUTH_TOKEN (see token generation below)
# Start services
docker compose up -d
# Check health
curl http://localhost:8080/health
# Method 1: Node.js (Recommended)
node -e "console.log(require('crypto').randomBytes(32).toString('base64url'))"
# Method 2: OpenSSL
openssl rand -base64 32 | tr '+/' '-_' | tr -d '='
Configure via environment variables in .env file:
| Variable | Description | Default |
|---|---|---|
PORT | External port (Caddy proxy) | 8080 |
MCP_AUTH_TOKEN | Authentication token (required for public access) | - |
CHROMA_DATA_PATH | ChromaDB data storage path (volume name, ./data, or absolute path) | chroma-data |
CHROMA_HOST | ChromaDB host (internal) | chromadb |
CHROMA_PORT | ChromaDB port (internal) | 8000 |
CHROMA_TENANT | ChromaDB tenant | default_tenant |
CHROMA_DATABASE | ChromaDB database | default_database |
CHROMA_AUTH_TOKEN | ChromaDB auth token (if ChromaDB requires auth) | - |
RATE_LIMIT_MAX | Max requests per IP per 15 minutes | 100 |
ALLOWED_ORIGINS | Comma-separated allowed origins (DNS rebinding protection) | - |
ALLOW_QUERY_AUTH | Enable authentication via query parameters | true |
IMPORTANT: For public internet access, you must set MCP_AUTH_TOKEN.
Supported authentication methods:
Authorization Header (Most Secure): Authorization: Bearer TOKEN
X-Chroma-Token Header: X-Chroma-Token: TOKEN
Query Parameter (Default Enabled): ?apiKey=TOKEN
ALLOW_QUERY_AUTH=true)ALLOW_QUERY_AUTH=false to disableChromaDB data can be stored in three ways:
Docker volume (default): CHROMA_DATA_PATH=chroma-data
Local directory: CHROMA_DATA_PATH=./data
Custom path: CHROMA_DATA_PATH=/path/to/data
Method 1: Custom Connector (Recommended - Pro/Team/Enterprise)
ChromaDBhttps://your-server.com/mcp?apiKey=YOUR_TOKENNote: Custom connector automatically syncs to the mobile app.
Method 2: mcp-remote Wrapper (Free/Pro Users)
Configuration file location:
~/Library/Application Support/Claude/claude_desktop_config.json%APPDATA%\Claude\claude_desktop_config.jsonAdd to configuration:
{
"mcpServers": {
"chromadb": {
"command": "npx",
"args": ["-y", "mcp-remote", "https://your-server.com/mcp?apiKey=YOUR_TOKEN"]
}
}
}
# With authentication (Query Parameter - Recommended)
claude mcp add --transport http chromadb https://your-server.com/mcp?apiKey=YOUR_TOKEN
# With authentication (Header)
claude mcp add --transport http chromadb https://your-server.com/mcp \
--header "Authorization: Bearer YOUR_TOKEN"
# Verify
claude mcp list
import chromadb
# HTTPS (Tailscale Funnel, public deployment)
client = chromadb.HttpClient(
host="your-server.com",
port=443,
ssl=True,
headers={
"X-Chroma-Token": "YOUR_TOKEN"
}
)
# Local development (HTTP)
client = chromadb.HttpClient(
host="localhost",
port=8080,
ssl=False,
headers={
"X-Chroma-Token": "YOUR_TOKEN"
}
)
# Usage
collection = client.create_collection("my_collection")
collection.add(
documents=["Document 1", "Document 2"],
ids=["id1", "id2"]
)
results = collection.query(query_texts=["query"], n_results=2)
/mcp - MCP Protocol endpoint/api/v2/* - ChromaDB REST API proxy/health - Health check (no auth required)/docs - Swagger UI documentation/openapi.json - OpenAPI specificationchroma_list_collections - List all collectionschroma_create_collection - Create new collectionchroma_delete_collection - Delete collectionchroma_get_collection_info - Get collection metadatachroma_get_collection_count - Get document countchroma_peek_collection - Preview collection itemschroma_add_documents - Add documents with embeddingschroma_query_documents - Semantic searchchroma_get_documents - Retrieve by IDchroma_update_documents - Update documentschroma_delete_documents - Delete documentsClaude Desktop/Mobile/Code
↓
MCP Server (this image)
├─ Authentication Gateway
├─ MCP Protocol Handler
└─ REST API Proxy
↓
ChromaDB (vector database)
services:
mcp-server:
image: devsaurus/chromadb-remote-mcp:latest
environment:
- MCP_AUTH_TOKEN=${MCP_AUTH_TOKEN}
- CHROMA_HOST=chromadb
depends_on:
- chromadb
networks:
- internal
caddy:
image: caddy:2-alpine
ports:
- "443:443"
volumes:
- ./Caddyfile:/etc/caddy/Caddyfile
networks:
- internal
chromadb:
image: chromadb/chroma:latest
volumes:
- chroma-data:/chroma/chroma
networks:
- internal
networks:
internal:
volumes:
chroma-data:
VPN-only access:
# Start services
docker compose up -d
# Enable Tailscale Serve (HTTPS with automatic certificates)
tailscale serve https / http://127.0.0.1:8080
# Check status
tailscale serve status
Public internet access:
# Enable Funnel (allows public internet access)
tailscale funnel 8080 on
tailscale serve https / http://127.0.0.1:8080
# Verify Funnel is active
tailscale serve status # Should show "Funnel on"
Warning: Public internet access requires
MCP_AUTH_TOKENto be set.
server {
listen 80;
server_name your-domain.com;
location / {
proxy_pass http://localhost:8080;
proxy_http_version 1.1;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
}
The container includes a built-in health check:
# Check service health
curl http://localhost:8080/health
# Docker health status
docker inspect --format='{{.State.Health.Status}}' mcp-server
# Health check
curl http://localhost:8080/health
# MCP tools list
curl -X POST http://localhost:8080/mcp \
-H "Content-Type: application/json" \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}'
# ChromaDB heartbeat
curl http://localhost:8080/api/v2/heartbeat
# MCP endpoint (Bearer token)
curl -X POST https://your-server.com/mcp \
-H "Content-Type: application/json" \
-H "Authorization: Bearer YOUR_TOKEN" \
-d '{"jsonrpc":"2.0","method":"tools/list","id":1}'
# MCP endpoint (Query parameter)
curl -X POST "https://your-server.com/mcp?apiKey=YOUR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"jsonrpc":"2.0","method":"tools/list","id":1}'
# ChromaDB REST API
curl https://your-server.com/api/v2/heartbeat \
-H "X-Chroma-Token: YOUR_TOKEN"
3000 (internal)8080 (configurable via PORT env var)MIT License - see LICENSE for details.
Content type
Image
Digest
sha256:9d4e3a5e0…
Size
774.7 MB
Last updated
18 days ago
docker pull devsaurus/chromadb-remote-mcp