Skip to content
appsgit

Shodan

Shodan is an MCP server that adds tools to AI assistants such as Claude Desktop, Claude Code and Cursor. MCP server for Shodan API — device search, IP lookup, DNS, and CVE/CPE queries. It has 174 GitHub stars, is released under the MIT license and runs locally with npx -y @burtthecoder/mcp-shodan.

github.com/w0h1v/mcp-shodan (opens in a new tab)

  • Needs API key
  • Other
  • MIT
  • Actively maintained

Install Shodan

Generated from the server's MCP registry entry. Replace your-value with your own values.

Claude Desktop

claude_desktop_config.json
{
  "mcpServers": {
    "shodan": {
      "command": "npx",
      "args": [
        "-y",
        "@burtthecoder/mcp-shodan"
      ],
      "env": {
        "SHODAN_API_KEY": "your-value"
      }
    }
  }
}

Settings > Developer > Edit Config. macOS: ~/Library/Application Support/Claude/, Windows: %APPDATA%\Claude\. Restart Claude Desktop afterwards.

Claude Code

claude mcp add --env SHODAN_API_KEY=your-value --transport stdio shodan -- npx -y @burtthecoder/mcp-shodan

Cursor

.cursor/mcp.json
{
  "mcpServers": {
    "shodan": {
      "type": "stdio",
      "command": "npx",
      "args": [
        "-y",
        "@burtthecoder/mcp-shodan"
      ],
      "env": {
        "SHODAN_API_KEY": "your-value"
      }
    }
  }
}

Project file; use ~/.cursor/mcp.json to enable it in every project.

VS Code

.vscode/mcp.json
{
  "inputs": [
    {
      "type": "promptString",
      "id": "shodan_api_key",
      "description": "SHODAN_API_KEY",
      "password": true
    }
  ],
  "servers": {
    "shodan": {
      "type": "stdio",
      "command": "npx",
      "args": [
        "-y",
        "@burtthecoder/mcp-shodan"
      ],
      "env": {
        "SHODAN_API_KEY": "${input:shodan_api_key}"
      }
    }
  }
}

Config formats checked against the official docs on Oct 7, 2026: modelcontextprotocol.io (opens in a new tab), code.claude.com (opens in a new tab), cursor.com (opens in a new tab), code.visualstudio.com (opens in a new tab).

Environment variables

Variables the server reads at startup.

NameRequiredDescription
SHODAN_API_KEYsecretYesYour Shodan API key

Tools (12)

Parsed from the Tools section of the README; check the repository for the current list.

  • query

    Shodan search query

  • max_results

    Number of results to return

  • hostnames

    Array of hostnames to resolve

  • product

    Name of the product to search for

  • count

    If true, returns only the count of matching CPEs

  • skip

    Number of CPEs to skip (for pagination)

  • limit

    Maximum number of CPEs to return

  • cpe23

    CPE 2.3 identifier (format: cpe:2.3:part:vendor:product:version)

  • is_kev

    If true, returns only CVEs with KEV flag set

  • sort_by_epss

    If true, sorts CVEs by EPSS score

  • start_date

    Start date for filtering CVEs (format: YYYY-MM-DDTHH:MM:SS)

  • end_date

    End date for filtering CVEs (format: YYYY-MM-DDTHH:MM:SS)

About Shodan

A Model Context Protocol (MCP) server for querying the Shodan API and Shodan CVEDB. This server provides comprehensive access to Shodan's network intelligence and security services, including IP reconnaissance, DNS operations, vulnerability tracking, and device discovery. All tools provide structured, formatted output for easy analysis and integration.

  • mcp
  • osint
  • reconnaissance
  • security
  • shodan
  • ai-tools
  • claude
  • cpe
  • cve
  • cybersecurity

FAQ

Shodan FAQ

Still curious? Email info@appsgit.com.

What is Shodan?

Shodan is an MCP server that adds tools to AI assistants such as Claude Desktop, Claude Code and Cursor. MCP server for Shodan API — device search, IP lookup, DNS, and CVE/CPE queries. It has 174 GitHub stars, is released under the MIT license and runs locally with npx -y @burtthecoder/mcp-shodan. The source code is at github.com/w0h1v/mcp-shodan.

How do I install the Shodan MCP server?

Add the command npx -y @burtthecoder/mcp-shodan to your MCP client: put it in claude_desktop_config.json for Claude Desktop, run claude mcp add for Claude Code, or add it to .cursor/mcp.json (Cursor) or .vscode/mcp.json (VS Code). The snippets on this page are ready to paste.

Is Shodan free?

The server is open source under the MIT license, so running it is free. It needs credentials (SHODAN_API_KEY) for the service it connects to, which may require a paid account.

Is Shodan actively maintained?

The most recent commit was on Sep 8, 2026. The latest release is v1.0.30, published Sep 8, 2026. appsgit only lists MCP servers with a commit in the last six months and re-checks every server daily.