Jupyter MCP Server
Coding · tested 2026-09-05 · re-test due 2026-12-04 · by the Hlido desk, not the vendor
In short: Well-documented open-source MCP server that lets an AI edit, document and execute Jupyter notebooks in real time — a clean, on-thesis agent-tooling bridge whose security and permission claims deserve verification before production use.
5 PASS · 0 FAIL of 5 public-surface claims
Quick answer
Jupyter MCP Server scores 74/100 (STEADY) on Hlido’s independent, hands-on test (reviewed 2026-09-05). STEADY (74): a well-scoped, well-documented open-source MCP server for a genuinely useful capability (agent-driven notebooks), with dual-transport support, an explicit security section, institutional backing and solid tr Pricing: Open source (free entry point documented).
This is a focused, legible piece of agent infrastructure: an MCP server that connects an AI client to Jupyter notebooks so it can view changes live, execute cells with output feedback, and reason over full notebook context. It supports both STDIO and Streamable HTTP transports, works with any Jupyter deployment (local, JupyterHub, or Datalayer-hosted), and is open source under BSD-3-Clause. The documentation is a real strength — dedicated sections for transports, code sandboxes, security, operations and architecture signal a project that has thought past the demo. Backing from Datalayer and 1.2k+ stars add credibility. For Hlido's audience this is precisely the kind of component agents actually consume, and the maintainers make some of the right noises about safety ('the agent receives a token scoped to what you approved', 'an agent can never reach a notebook you cannot'). Those permission and isolation claims are the ones that matter most and are exactly what a public-surface review cannot confirm — running arbitrary agent-authored code against your notebooks is high-trust, so the security posture is a claim to validate in a sandbox, not a checkbox to take on faith. Reviewed at the surface, it is a clean, credible bridge; verify the security model before you point an autonomous agent at production notebooks.
Why STEADY
STEADY (74): a well-scoped, well-documented open-source MCP server for a genuinely useful capability (agent-driven notebooks), with dual-transport support, an explicit security section, institutional backing and solid traction. Not higher because the load-bearing security/permission guarantees are unverified at Tier-1, and executing agent-authored code against notebooks is inherently high-risk until that model is validated.
Public-surface checklist
- PASS Homepage loads (required)
- PASS Primary value prop (required) — 'MCP server ... enables real-time interaction with Jupyter Notebooks'
- PASS Cta present (required) — 'Getting Started' docs
- PASS Pricing or access — Open-source server, free to self-host; hosted option via Datalayer
- PASS Evidence or demo — Feature list + architecture/security docs shown
What it does well
- Clean, single-purpose MCP bridge: agents can edit, document and execute notebooks live
- Dual transport (STDIO + Streamable HTTP); works with local, JupyterHub or hosted Jupyter
- Unusually thorough docs — transports, sandboxes, security, operations, architecture
- Open source (BSD-3-Clause) with institutional backing (Datalayer) and 1.2k+ stars
- Cell-output feedback lets the agent adjust when a run fails
What it fails at
- Security/permission claims ('scoped token', 'agent can't reach what you can't') are unverified at Tier-1
- Executing agent-authored code against notebooks is inherently high-trust — posture needs validation
- Real-world reliability under long agent sessions is untested from the surface
- Hosted vs. self-hosted operational differences are documented but not exercised here
Best for
- Data/ML teams that want an agent to drive notebooks (analysis, viz, execution)
- Builders wiring Jupyter into an MCP-capable agent client
- Orgs that can validate and sandbox the security model before production
- Anyone needing both STDIO and HTTP transport options
Not recommended for
- Teams unwilling to let an agent execute code until the permission model is independently verified
- Non-Jupyter data workflows
- Buyers wanting a fully managed product rather than a server to operate
Pricing & access
- ModelOpen source
- Free entry pointYes — a free tier or open-source edition is documented
- Pricing findable on the public surfacePASS Open-source server, free to self-host; hosted option via Datalayer (tested 2026-09-05)
Derived from Hlido-held evidence only (engine checklist + editorial text); quotes are verbatim from the scorecard; not vendor-supplied; re-derived daily. Verify current prices on the vendor's pricing page. Last verified 2026-09-05.
Compared to
-
jupytercad-mcp
general-notebook-control
JupyterCAD-MCP targets CAD-in-Jupyter workflows; this server is the general notebook execution/editing bridge. Choose by whether you need general notebook control or the CAD-specific surface.
Agent relevance
API MCP SDK Behavioral-testable
A native MCP server: any MCP-capable agent client connects over STDIO or HTTP to edit and execute Jupyter notebooks. Directly agent-drivable and behaviourally testable; security model should be validated first.
Agent-friendly score: 8/10
Score over time
The longitudinal record — every point is the score as published on that date. Raw series.
Evidence
- MCP server enabling real-time notebook edit/execute/document — source (2026-09-05) verified
- Supports STDIO and Streamable HTTP transports; any Jupyter deployment — source (2026-09-05) verified
- Open source under BSD-3-Clause — source (2026-09-05) verified
- Agent receives a scoped token; cannot reach notebooks the user cannot — source (2026-09-05)