A Model Context Protocol server that lets AI assistants create, read and edit Excel workbooks. It needs no Microsoft Excel installation.
- Read and write cells, formulas (with results calculated for you) and dates, with paging and streaming reads for large sheets, and search
- Format fonts, fills, borders, number formats, column widths and frozen panes; hide or group rows, columns and sheets; set up printing; protect sheets
- Structure sheets (order, view, workbook settings and protection), rows and columns (inserting or deleting updates every reference, as in Excel), merged cells, tables (totals row, calculated columns, banding, filter buttons, resizing), charts (column, bar, line, area, pie, doughnut, radar, scatter and bubble, with combos, secondary axes, trendlines and error bars; and the Excel 2016 waterfall, histogram, Pareto, box and whisker, treemap, sunburst and funnel), images, hyperlinks, PivotTables, and slicers and timelines that filter them and tables
- Data tools: paste special, fill series, remove duplicates, text to columns, find and replace, sheet and table filters with criteria
- Rules: conditional formatting (scales, data bars with borders, negative bars and axis, icon
sets with custom icons, top/bottom, duplicates, text, dates and more), sparklines (line, column,
win/loss) and data validation (dropdowns from cells, limits, input messages, alert styles),
cleared with
clear_range - Macros: read the VBA code in
.xlsmfiles, module by module (never run). Writing VBA is off unless you start the server with--allow-vba-write(see below) - Safe by design: optional folder confinement, a formula safety check, read-only mode, localhost-only HTTP by default, and atomic saves that never leave a half-written file
Works with .xlsx, .xlsm (macros are preserved), .xltx and .xltm files.
You need uv. Every client runs the
server with uvx excel-mcp-server stdio; replace /path/to/workbooks with the folder the
server may use.
Claude Desktop (Chat): download excel-mcp-server-<version>.mcpb from the
latest release and open it.
Claude asks which folder the server may use.
Claude Code (the CLI, and the Code tab in Claude Desktop):
claude mcp add excel --scope user -- uvx excel-mcp-server stdio --allow-dir /path/to/workbooksCursor (~/.cursor/mcp.json), and most clients that use an mcpServers config:
{
"mcpServers": {
"excel": {
"command": "uvx",
"args": ["excel-mcp-server", "stdio", "--allow-dir", "/path/to/workbooks"]
}
}
}VS Code with GitHub Copilot (.vscode/mcp.json, note the servers key):
{
"servers": {
"excel": {
"type": "stdio",
"command": "uvx",
"args": ["excel-mcp-server", "stdio", "--allow-dir", "${workspaceFolder}"]
}
}
}OpenAI Codex, Gemini CLI, Devin Desktop, and Claude Desktop without the bundle
OpenAI Codex (CLI, IDE extension and app):
codex mcp add excel -- uvx excel-mcp-server stdio --allow-dir /path/to/workbooksGemini CLI:
gemini mcp add -s user excel uvx excel-mcp-server stdio --allow-dir /path/to/workbooksDevin Desktop:
devin mcp add -s user excel -- uvx excel-mcp-server stdio --allow-dir /path/to/workbooksClaude Desktop, manual setup: open Settings, Developer, Edit Config, add the mcpServers
JSON above to claude_desktop_config.json, and restart Claude.
Desktop apps often cannot find uvx, because they do not see your shell's PATH (common
on macOS). Use its full path instead, which which uvx prints.
With --allow-dir DIR, the server only opens workbooks inside DIR (subfolders included)
and relative paths such as reports/q1.xlsx start there. Repeat the flag to allow several
folders, or set EXCEL_FILES_PATH (separate folders with : on macOS/Linux and ; on
Windows).
Without --allow-dir, any absolute path to an Excel file works. In every mode the server
only touches Excel files and never silently overwrites an existing workbook.
uvx excel-mcp-server streamable-http --allow-dir /srv/workbooksClients connect to http://127.0.0.1:8017/mcp. Workbooks live in the --allow-dir folder
(default ./excel_files), and export_workbook / import_workbook move files between the
server and the client.
The server listens on localhost only. To accept other machines, set a token and a host:
EXCEL_MCP_AUTH_TOKEN=change-me uvx excel-mcp-server streamable-http --host 0.0.0.0Clients then send Authorization: Bearer change-me. Put a TLS-terminating reverse proxy in
front of it for use across networks.
docker build -t excel-mcp-server .
docker run -p 8017:8017 -v "$PWD/workbooks:/data" -e EXCEL_MCP_AUTH_TOKEN=change-me excel-mcp-server| Flag | Environment variable | Default | Meaning |
|---|---|---|---|
--allow-dir DIR |
EXCEL_FILES_PATH |
none (stdio), ./excel_files (HTTP) |
Folders workbooks must be in |
--read-only |
EXCEL_MCP_READ_ONLY=1 |
off | Only offer tools that do not change files |
--allow-vba-write |
EXCEL_MCP_ALLOW_VBA_WRITE=1 |
off | Add tools that write VBA macros (see warning below); ignored with --read-only |
--max-file-mb N |
100 |
Largest workbook the server opens | |
--log-level LEVEL |
WARNING |
Logging on stderr | |
--host HOST |
EXCEL_MCP_HOST |
127.0.0.1 |
HTTP listen address |
--port PORT |
EXCEL_MCP_PORT |
8017 |
HTTP port |
EXCEL_MCP_AUTH_TOKEN |
none | Bearer token required on HTTP requests | |
--allow-unauthenticated |
off | Allow a non-local --host without a token |
| Area | Tools |
|---|---|
| Workbooks | create_workbook, describe_workbook, set_workbook_settings, list_workbooks, export_workbook, import_workbook |
| Sheets | describe_sheet, create_sheet, rename_sheet, copy_sheet, delete_sheet, insert_rows_or_columns, delete_rows_or_columns |
| Cells | read_range, write_range, clear_range, copy_range, sort_range, transform_range, find_cells, replace_cells |
| Formatting | format_range, merge_cells, set_sheet_layout, add_conditional_format, add_data_validation |
| Objects | create_table, edit_table, create_chart, delete_chart, create_pivot_table, delete_pivot_table, add_slicer, delete_slicer, insert_image, delete_image, add_sparklines, delete_sparklines |
| Names and notes | set_defined_name, delete_defined_name, set_note, delete_note |
| Macros | read_vba; with --allow-vba-write: write_vba_module, delete_vba_module |
Every parameter is documented in TOOLS.md.
With --allow-vba-write (or EXCEL_MCP_ALLOW_VBA_WRITE=1) the server can set the code of
standard, class, workbook and sheet modules in .xlsm and .xltm files, delete standard and
class modules, and create new .xlsm/.xltm workbooks. The server only stores the code; it
never runs it, and Excel asks before enabling macros. Digitally signed VBA projects are
refused, since any change would invalidate the signature.
Warning: macro code runs with your user's rights once you enable macros in Excel. A model that reads untrusted content could be tricked into writing harmful code. Enable this option only for trusted workflows, keep
--allow-dirnarrow, and read the code before you enable macros. The tools are never offered in--read-onlymode.
- Formulas are parsed before they are written. Functions that reach the network, other
programs or host information (
WEBSERVICE,HYPERLINK,IMAGE,RTD,CALL,INFO,INDIRECT, Google SheetsIMPORTXMLand others), DDE links and references to other workbooks are rejected. - Paths are resolved, including symlinks, before they are checked against the allowed folders.
- A single call processes at most 100,000 cells, and large reads are returned in pages.
- Cell contents are data from files. The server tells the model not to follow instructions found in them, but review what an assistant does with workbooks from untrusted sources.
Please report vulnerabilities privately; see SECURITY.md.
- Formulas are stored in the file, and Excel calculates them when it opens it. So that
read_rangeis useful before that,valuesmode calculates formulas that have no saved result with a built-in calculator (about 260 functions: math, statistics, financial and bond, dates, text, lookup, logical, LET, sorting and filtering). Results Excel saved are always preferred. A formula the calculator cannot reproduce exactly as Excel does (an unsupported function, a circular reference, or an Excel quirk it does not replicate) is returned as null and listed inuncalculatedwith the reason; it is never guessed. Ranges in a formula are reduced to the formula's own row or column where Excel's ordinary (not array-entered) formulas do the same, and volatile functions such asRANDare not calculated. The calculator is checked against more than 2,500 formulas recorded from real Excel (tests/fixtures/formula_golden.json). - Functions Excel added after 2007 (
IFS,XLOOKUP,STDEV.S,SORT, ...) are written with the_xlfn.prefix Excel expects, wherever formulas are stored (cells, copied and sorted cells, conditional formats, data validation, defined names). - Legacy
.xlsand.csvfiles are not supported. - PivotTables are created from a snapshot and can use text, number and date columns of up to
100,000 cells; Excel refreshes them from the live source data. They support number formats,
"show values as" (percent of total, row, column or parent, difference from, running total,
rank), sorting by label or value, date and number grouping, calculated fields, compact,
outline and tabular layouts, subtotals on or off, filters with chosen items and several
values fields as columns or rows. The figures written into the cells are the ones Excel shows
after a refresh, checked against about 200 PivotTables recorded from real Excel
(
tests/fixtures/pivot_golden.json). The exceptions: items that tie when sorted by value may swap places on refresh, andvalues_in: "rows"cannot be combined with rank figures or, with subtotals, other figures along a field, because Excel mixes the values fields up there. add_sliceradds slicers (Insert > Slicer) for tables and PivotTables, and timelines for date fields of PivotTables: field, caption, position and size, columns, style, sort, selected items (or a period) and "hide items with no data". Selecting items filters as clicking does: table rows are filtered and hidden; PivotTable items are hidden and the figures recalculated from the source, which Excel confirms on refresh (about 200 PivotTables are checked against Excel, and the slicer variants against Excel's own results). One slicer can filter several PivotTables that share a cache, such as those of copied sheets. Limits: a PivotTable made or refreshed by Excel keeps its figures in the cells (the hidden items and a refresh-on-open mark are stored, so Excel recalculates when it opens the file); fields grouped in a PivotTable take no slicer.- Inserting or deleting rows and columns, and renaming a sheet, update references like
Excel. Hyperlink targets and 3D references (
Sheet1:Sheet3!A1) are left alone (Excel does the same). An edit that cuts through an array formula, a PivotTable, a table header or two tables at once is refused. Inserted cells take the formatting, row height and column width of the line above or to the left (nothing at the first row or column), and calculated table columns are filled into rows inserted in a table. - Editing a workbook keeps what the tools cannot change: sparklines, extended conditional
formats and validation, slicers and timelines, newer charts (waterfall, histogram,
treemap and others), threaded comments, shapes, form controls, linked data types and
custom XML stay as Excel saved them and move with inserted or deleted rows and columns and
renamed sheets.
copy_sheetcopies sparklines, slicers and timelines (as Excel does), the Excel 2010 half of conditional formats (data bars, icon sets) and the Excel 2016 charts made bycreate_chart, but not the others. Deleting a sheet removes slicers that only it used; slicers that would be left without their PivotTable block the deletion, and deleting a table, or the column a table slicer filters, removes the slicer. Digital signatures are removed, as Excel does when a signed file changes. - Formulas that return several values (
FILTER,SORT,UNIQUE,SEQUENCE,A2:A9*2) are stored as dynamic array formulas, as Excel stores them, and spill into the cells next to them. A cell in the way blocks the spill (Excel shows#SPILL!), andwrite_rangereports it. Where the calculator cannot tell how large a result is, only the formula's cell is stored and Excel fills in the rest when it opens the file.
Version 1.0 renames and redesigns the tools, removes the SSE transport and requires Python 3.11 or newer. The changelog maps every old tool to its replacement.
Contributions are welcome. See CONTRIBUTING.md.
MIT. See LICENSE.
