Jupyter MCP Server

Coding · tested 2026-09-05 · re-test due 2026-12-04 · by the Hlido desk, not the vendor

In short: Well-documented open-source MCP server that lets an AI edit, document and execute Jupyter notebooks in real time — a clean, on-thesis agent-tooling bridge whose security and permission claims deserve verification before production use.

5 PASS · 0 FAIL of 5 public-surface claims

Quick answer

Jupyter MCP Server scores 74/100 (STEADY) on Hlido’s independent, hands-on test (reviewed 2026-09-05). STEADY (74): a well-scoped, well-documented open-source MCP server for a genuinely useful capability (agent-driven notebooks), with dual-transport support, an explicit security section, institutional backing and solid tr Pricing: Open source (free entry point documented).

This is a focused, legible piece of agent infrastructure: an MCP server that connects an AI client to Jupyter notebooks so it can view changes live, execute cells with output feedback, and reason over full notebook context. It supports both STDIO and Streamable HTTP transports, works with any Jupyter deployment (local, JupyterHub, or Datalayer-hosted), and is open source under BSD-3-Clause. The documentation is a real strength — dedicated sections for transports, code sandboxes, security, operations and architecture signal a project that has thought past the demo. Backing from Datalayer and 1.2k+ stars add credibility. For Hlido's audience this is precisely the kind of component agents actually consume, and the maintainers make some of the right noises about safety ('the agent receives a token scoped to what you approved', 'an agent can never reach a notebook you cannot'). Those permission and isolation claims are the ones that matter most and are exactly what a public-surface review cannot confirm — running arbitrary agent-authored code against your notebooks is high-trust, so the security posture is a claim to validate in a sandbox, not a checkbox to take on faith. Reviewed at the surface, it is a clean, credible bridge; verify the security model before you point an autonomous agent at production notebooks.

Why STEADY

STEADY (74): a well-scoped, well-documented open-source MCP server for a genuinely useful capability (agent-driven notebooks), with dual-transport support, an explicit security section, institutional backing and solid traction. Not higher because the load-bearing security/permission guarantees are unverified at Tier-1, and executing agent-authored code against notebooks is inherently high-risk until that model is validated.

Public-surface checklist

What it does well

What it fails at

Best for

  • Data/ML teams that want an agent to drive notebooks (analysis, viz, execution)
  • Builders wiring Jupyter into an MCP-capable agent client
  • Orgs that can validate and sandbox the security model before production
  • Anyone needing both STDIO and HTTP transport options

Not recommended for

  • Teams unwilling to let an agent execute code until the permission model is independently verified
  • Non-Jupyter data workflows
  • Buyers wanting a fully managed product rather than a server to operate

Pricing & access

Derived from Hlido-held evidence only (engine checklist + editorial text); quotes are verbatim from the scorecard; not vendor-supplied; re-derived daily. Verify current prices on the vendor's pricing page. Last verified 2026-09-05.

Compared to

Agent relevance

API MCP SDK Behavioral-testable

A native MCP server: any MCP-capable agent client connects over STDIO or HTTP to edit and execute Jupyter notebooks. Directly agent-drivable and behaviourally testable; security model should be validated first.

Agent-friendly score: 8/10

Evidence

scorecard.json · registry · methodology

More: compare agents · best of · developer tools · incident registry

Verdict by Hlido Editor, our automated editorial system · Method: public-surface-tier-1+editorial-narrative-v2 · Methodology version 2026.05 · Next review due 2026-12-04

How this page was produced. The scores, claim verdicts and evidence come from automated hands-on testing of the product’s public surface. The written analysis is drafted by an AI system, and pages publish without a person reviewing each one. Hlido publishes this record and answers for it — tell us if anything here is wrong and we will correct it.

Embed this trust badge

Hlido trust score

Live, always-current independent score — free to embed on your site or README. No vendor pays for placement.

Markdown

[![Hlido trust score](https://hlido.eu/badge/datalayer-jupyter-mcp-server.svg)](https://hlido.eu/check/?agent=datalayer-jupyter-mcp-server)

HTML

<a href="https://hlido.eu/check/?agent=datalayer-jupyter-mcp-server"><img src="https://hlido.eu/badge/datalayer-jupyter-mcp-server.svg" alt="Hlido trust score"></a>