Ctfd MCP Server

Model Context Protocol (MCP) server for interacting with CTFd instances - authenticate, retrieve challenges, submit flags

Local serverstdioTypeScript

What is the Ctfd MCP server?

Ctfd MCP server is a locally run integration for AI assistants that speak the Model Context Protocol. Model Context Protocol (MCP) server for interacting with CTFd instances - authenticate, retrieve challenges, submit flags.

What you get

A lightweight and extensible Model Context Protocol (MCP) server for interacting with any CTFd instance. This project enables AI tools and automation to authenticate, retrieve challenges, and submit flags through MCP tools.

This project acts as a bridge between CTFd and AI-driven systems by providing a unified interface. It supports multiple authentication modes, dynamic base URL control, and direct MCP tool integration.

  • Dynamic BASE_URL configuration
  • Token and cookie authentication
  • Username/password login
  • List challenges with optional filtering
  • Submit flags programmatically
  • Compatible with MCP-based AI tools (Claude, Codex, Amp, Gemini)

Configuration and credentials

You will need 2 environment variables: BASE_URL, CTFD_TOKEN. The server will not start without them, which is usually why the tools fail to appear on a first run. Keep credentials in your client's env block or a secrets manager rather than in a file you might commit.

Setting it up

ctfd-mcp-server on npm is all you need. Most clients run it directly, so configuration is a few lines and a restart.

Choosing this one

Among the developer tooling options, the useful question is rarely "what can it do" but "what does it cost you to run" — permissions, credentials, and how much of your context its toolset consumes. It is maintained by tomek7667; worth a glance at recent repository activity before you build anything load-bearing on it.

SyncDev reviews every entry in this directory against the project's own documentation before publishing, and revisits them as servers change.

Before you rely on it

  • It runs with your machine's permissions. That is convenient and also the reason to think about what you point it at before you approve a tool call.
  • Missing credentials fail quietly in some clients — if no tools show up, check the environment block first.
  • MCP clients confirm each tool call by default. Leave that on until you have watched what the ctfd mcp server does with a few real requests.

How to install the Ctfd MCP server

{
	"mcpServers": {
		"ctfd": {
			"command": "npx",
			"args": ["-y", "ctfd-mcp-server"],
			"env": {
				"BASE_URL": "https://demo.ctfd.io",
				"CTFD_TOKEN": "<your ctfd api token>"
			}
		}
	}
}

Configuration as documented by the project. Restart the client after saving.

Configuration

VariableDescriptionRequired
BASE_URLEndpoint or connection string the server talks to.Yes
CTFD_TOKENCredential the server authenticates with.Yes

Frequently asked questions

It connects Ctfd to MCP-compatible AI assistants such as Claude and Cursor. Instead of copying data back and forth by hand, the assistant works with Ctfd directly.