RabbitMQ MCP Server for AI Assistants and Coding Agents
AceMQ's RabbitMQ MCP server lets AI assistants and coding agents read your broker through the RabbitMQ management API: queues, consumers, alarms, node health and policies. It runs inside your network, starts in read-only mode, logs every tool call, and only performs actions you have allowed and approved. It is commercially licensed and supported by the same engineers who run AceMQ's 24/7 RabbitMQ support, on its own or as part of a support or managed services contract.
The only partner with direct RabbitMQ core team access
15 min emergency SLA24 /7 follow-the-sun cover130 + enterprise customers26 + countries served
Trusted for Mission-Critical RabbitMQ by Teams in Finance, Healthcare, Defense, Telecom, and More
Named by the RabbitMQ Core Team
The Featured Authorized Partner for RabbitMQ — named by the engineers who build it
AceMQ is the Featured Authorized Partner for RabbitMQ, named by the RabbitMQ Core Engineering Team — the people who write and maintain the broker. That recognition covers RabbitMQ support, licensing and professional services, and it makes AceMQ the only RabbitMQ partner with a direct line to the core team. When an escalation needs an answer that is not in the documentation, it does not stop at a support tier.
You do not have to take our word for it — RabbitMQ lists AceMQ on its own site.
RabbitMQ partner with a direct line to the Core Engineering Team
Support · Licensing · Services
the full scope the partner status covers
Below 72 cores
the only provider globally licensing commercial RabbitMQ under Broadcom's minimum
Is This You?
You probably need this if…
Engineers already paste rabbitmqctl output and management UI screenshots into an AI assistant to ask what is wrong
Your developers work in Cursor, Claude Code or VS Code agent mode and want the agent to see the broker instead of guessing at it
On-call starts every incident by clicking through the management UI to find which queue is backing up and why
Security will not approve an MCP server that holds administrator credentials and keeps no record of what it did
You want AI help on the broker, but nothing that can purge a queue or change a policy without a person saying yes
Broker metadata and message rates have to stay inside your network
You want the integration covered by a support contract, with someone to call when it stops working
Outcomes
Where you are now, and where you end up
Concrete state changes, not deliverable counts. This is what actually differs about your RabbitMQ estate when the engagement closes.
Before
An assistant answers RabbitMQ questions from training data and whatever someone pasted into the chat.
After
The assistant reads live queue depth, consumer counts, rates, alarms and policies from your cluster before it answers.
Before
Finding the queue behind a memory alarm means several tabs of the management UI and a few rabbitmqctl commands.
After
An engineer asks why the alarm fired and gets the backlogged queues, their consumers and the likely cause, with the data behind it.
Before
The MCP setups on the table expect administrator credentials and can change the broker with no approval step.
After
Read-only by default, a least-privilege RabbitMQ user, and write actions that stay off until you allow them and approve each call.
Before
Nobody can say which agent looked at the broker, what it asked for or what it changed.
After
Every tool call is in an audit log: which client, which tool, which arguments, when, and what came back.
Before
An open-source integration works until it breaks, and then the question is who maintains it.
After
AceMQ licenses, maintains and supports the server, and the engineer who answers knows both the integration and RabbitMQ.
Scope
What's covered
Read-Only Broker Inspection
Tools that list virtual hosts, queues, exchanges, bindings, connections, channels and consumers, and read queue depth, message rates, unacknowledged counts, memory and disk alarms and node health. Policies and exported definitions are readable too, so an assistant can see how the cluster is configured, not just how it is behaving.
Diagnosis Built on RabbitMQ Experience
Tools that put the raw numbers in context: explain why a queue is backing up, trace a memory or disk alarm to the queues and connections behind it, and compare policies and configuration against RabbitMQ practice for queue types, delivery limits, dead-lettering and length limits. The checks reflect what AceMQ engineers look at first in support cases.
Guarded Write Actions
Purging a queue, moving messages with a shovel and changing policies are disabled by default. You enable them one action at a time through an allow-list, can limit them to named virtual hosts or queues, and each call needs explicit approval before it runs. Leave them off and the server stays read-only.
Runs Inside Your Network
You deploy the server in your own environment, next to the cluster. It talks to the management API over TLS as a dedicated RabbitMQ user with the monitoring tag and only the permissions it needs. AceMQ does not need access to your brokers or your data for it to work.
Audit Log of Every Tool Call
Each request is recorded with the client, the tool, its arguments, the time, the result and, for write actions, who approved it. Send the log to the system you already use for audit, so broker access by AI tools is reviewed the same way as access by people.
Supported by RabbitMQ Engineers
Installation help, upgrades and fixes come from AceMQ's RabbitMQ team, under the same 24/7 support model as the broker. Buy it on its own, or add it to an AceMQ support or managed services contract so one team covers the cluster and the integration.
The Engagement
How it actually runs
Every phase has a defined duration and a concrete artifact handed over at the end of it. You always know what stage you're in and what you've received.
Phase 11 call
Inquiry and Demo
Tell us which clusters you run, which AI tools your team uses and what you want them to do. We show the server working against a test broker, including the read-only tools, the approval step and the audit log.
You receive
Live demo against a test broker
Answers on fit for your clients and clusters
Outline of licensing and support options
Phase 2Days, by estate size
Scoping
We agree which clusters and virtual hosts the server can see, whether any write actions should be allowed and who approves them, where it runs, and where the audit log goes. Your security team gets the details it needs to review it.
You receive
Cluster and virtual host scope
Write-action allow-list, or confirmation of read-only
RabbitMQ user and permission plan
Quote for license and support
Phase 3Scoped with you
Deployment in Your Environment
Your team installs the server inside your network with an AceMQ engineer alongside. We create the least-privilege RabbitMQ user, configure TLS, connect your MCP clients and confirm the guardrails behave as agreed before anyone relies on it.
You receive
Server running inside your network
Least-privilege RabbitMQ user with the monitoring tag
MCP clients connected and tested
Audit log flowing to your chosen destination
Phase 4Ongoing
Supported Operation
Updates, fixes and questions go through AceMQ support. If an assistant surfaces a broker problem your team wants help with, the same support relationship covers the cluster, so there is no handoff between an integration vendor and a RabbitMQ vendor.
You receive
Updates and fixes to the server
Support for the integration and its configuration
Optional 24/7 RabbitMQ support or managed services for the cluster
What a RabbitMQ MCP server is
MCP, the Model Context Protocol, is an open standard for connecting AI applications to external systems. An AI application, the host, runs MCP clients that connect to MCP servers. Each server offers tools the model can call, resources it can read and prompts it can use. Servers run locally over standard input and output, or remotely over HTTP.
A RabbitMQ MCP server is one of those servers, with RabbitMQ on the other side. When an engineer asks an assistant why the orders queue is growing, the assistant calls the server's tools. The server queries the RabbitMQ management HTTP API, returns depth, consumers and rates, and the assistant answers from that data instead of from memory.
That puts the server in the path between an AI tool and a production broker, which is why AceMQ built it around what it will not do: it does not change anything unless you allow it, it holds no more RabbitMQ permissions than it needs, and it writes down every call it serves.
What it does, and what stays off unless you turn it on
On by default: inspection — Listing and reading queues, exchanges, bindings, connections, channels, consumers, policies and definitions, plus node health, alarms, queue depth and message rates.
On by default: diagnosis — Explaining a backlog or a memory alarm, and comparing configuration against RabbitMQ practice for queue types, dead-lettering, delivery limits and length limits.
Off by default: write actions — Purging a queue, moving messages with a shovel and changing policies. Each one is enabled separately through an allow-list, can be limited to named virtual hosts or queues, and needs explicit approval on every call.
Always on: the audit log — Every tool call, read or write, is recorded with its arguments, result and time.
Least privilege applies on the RabbitMQ side as well. The monitoring tag lets a user see node-level data, all virtual hosts and other users' connections without being able to manage users, virtual hosts or permissions. Queue permissions are a separate decision: in RabbitMQ, purging a queue needs only read permission on it, so we size the server's user to the actions you have actually allowed rather than relying on the tag alone.
Where your data goes
The server runs inside your network. What it returns goes to the AI client you connect, and from there to that client's model provider under your agreement with them. Choose clients, and decide which clusters each one may see, with that in mind.
Which AI assistants and coding agents can use it
Any MCP-compatible client can connect. The ones engineering teams ask about most are Claude Desktop and Claude Code, Cursor, and VS Code with GitHub Copilot. All of them can run MCP servers locally. Cursor asks for approval before it runs an MCP tool by default, and VS Code can ask you to confirm each tool call, which adds a client-side check on top of the server's own approval step.
ChatGPT connects to remote MCP servers added as custom connectors, which means publishing an HTTPS endpoint that OpenAI's service can reach. That is a different network decision from a server that never leaves your environment, and we work through it with you during scoping if ChatGPT is on your list.
Customer Success
Real RabbitMQ Results
See how enterprises trust AceMQ for their most critical RabbitMQ workloads.
It is a Model Context Protocol server that gives AI assistants and coding agents a set of tools for working with RabbitMQ. The assistant calls a tool, the server queries the RabbitMQ management HTTP API, and the answer comes back to the assistant as data. AceMQ's server covers inspection and diagnosis by default, keeps write actions behind an allow-list and an approval step, and logs every call.
No. It is commercially licensed and supported by AceMQ, and it is not published as a public repository or download. Community open-source MCP servers for RabbitMQ do exist. Teams usually come to us when they need least-privilege access, approval for anything that changes the broker, an audit trail, and a vendor that supports the integration and the cluster under one contract.
Not unless you decide it should. The server runs in read-only mode by default. Write actions such as purging a queue, moving messages or changing a policy are each disabled until you add them to an allow-list, can be limited to specific virtual hosts or queues, and need explicit approval every time they run. Every attempt, approved or not, is recorded in the audit log.
No. The server runs inside your network and talks to your brokers directly. AceMQ does not need access to your clusters or your data for it to work. What the server returns goes to the AI client you connect, and through that client to its model provider, so that is the data path to review with your security team.
Any MCP-compatible client. Teams most often use Claude Desktop, Claude Code, Cursor and VS Code with GitHub Copilot, all of which can run MCP servers locally. ChatGPT supports MCP through remote servers it reaches over the internet, so using it means exposing an endpoint, which we scope separately.
RabbitMQ versions with the management plugin enabled, since the server works through the management HTTP API. That covers open-source RabbitMQ and Tanzu RabbitMQ, including clusters on Kubernetes. If your estate runs older releases, tell us which ones during scoping and we will confirm coverage.
Contact AceMQ for a demo and a quote. The server is available on its own or bundled with AceMQ's 24/7 RabbitMQ support or managed services, and pricing depends on the clusters in scope and the support you want with it. We do not publish a price list.
AceMQ does. Questions, fixes and updates go through AceMQ support, handled by RabbitMQ engineers. If the server is part of a support or managed services contract, the same team also covers the broker, so a problem that starts in the integration and ends in the cluster stays with one team.
See the RabbitMQ MCP Server on a Test Broker
Tell us which clusters you run and which AI tools your team uses. We will set up a demo and come back with licensing and support options for your estate.
Get in Touch
Talk to a RabbitMQ Expert
Send us a message and we'll follow up within one business day — or book a free 30-min consultation directly.