FBI Crime Data Explorer — UCR estimates, NIBRS breakdowns, hate crimes, arrests, and agency data.
Exposes the FBI Crime Data Explorer API — UCR crime estimates, NIBRS incident breakdowns, hate crimes, arrests, human trafficking, and agency participation data via MCP. STDIO or Streamable HTTP.
FBI Crime Data Explorer (CDE) data — monthly UCR offense rates and counts by national, state, or agency scope, plus Law Enforcement Officers Killed and Assaulted (LEOKA) statistics. Query crime trends and officer-safety data from any MCP client; the CDE's legacy UCR endpoints (agency search, NIBRS breakdowns, hate crimes, arrests, human trafficking, participation) have been decommissioned by the FBI, and their tools and resources return an error. Runs as a stdio process or a local Streamable HTTP server.
| Tool | Description |
|---|---|
fbi_get_crime_estimates | Monthly UCR offense rates and counts by national, state, or agency scope, from the CDE summarized endpoint |
fbi_get_agency_offenses | Same CDE summarized endpoint, scoped to a single agency, state, or the national level |
fbi_get_leoka | Officer fatality, weapon, and circumstance data (LEOKA) by month or year-to-date |
fbi_get_arson | [UNAVAILABLE] Redirects to fbi_get_crime_estimates with offense="arson" |
fbi_search_agencies | [UNAVAILABLE] UCR agency search backend decommissioned |
fbi_get_agency | [UNAVAILABLE] UCR agency profile backend decommissioned |
fbi_get_arrests | [UNAVAILABLE] UCR arrests backend decommissioned |
fbi_get_hate_crimes | [UNAVAILABLE] UCR hate crimes backend decommissioned |
fbi_get_human_trafficking | [UNAVAILABLE] UCR human trafficking backend decommissioned |
fbi_get_nibrs_breakdown | [UNAVAILABLE] UCR NIBRS breakdown backend decommissioned |
fbi_get_participation | [UNAVAILABLE] UCR and CDE participation backends decommissioned |
fbi_list_code_table | [UNAVAILABLE] UCR code table backend decommissioned |
| Resource | Description |
|---|---|
fbi://agency/{ori} | [UNAVAILABLE] Agency profile by ORI; UCR backend decommissioned |
fbi://state/{state_abbr} | [UNAVAILABLE] State participation overview; CDE backend decommissioned |
fbi_get_crime_estimates toolscope: national, state (requires state_abbr, 2 letters), or agency (requires ori, 9 characters)offense: one of violent-crime, property-crime, robbery, burglary, larceny, motor-vehicle-theft, arson, aggravated-assault, rape, homicidefrom_year/from_month (default January) and to_year/to_month (default December), years 2000–2030data_last_updated when the CDE reports a refresh datescope_param_missing (missing state_abbr/ori for the chosen scope), no_datafbi_get_agency_offenses toolfbi_get_crime_estimates, scoped by scope: national, state (state_abbr), or agency (ori)offense enum and from_year/from_month/to_year/to_month range (years 2000–2030)scope_param_missing, no_datafbi_get_leoka toolperiod: ytd (year-to-date) or monthly (requires month, 1–12); year is required (2000–2030)deaths_by_year and deaths_by_region are keyed by Felonious/Accidentalmonth_required (monthly period without month), no_datafbi_get_arson toolServiceUnavailable — the dedicated UCR arson endpoint is decommissionedfbi_get_crime_estimates with offense="arson", which serves arson data via the CDE summarized endpointscope, state_abbr, since_year, until_year) are accepted but unusedfbi_search_agencies toolServiceUnavailable — the UCR agency search backend (crime-data-api.fr.cloud.gov) is decommissionedstate_abbr, agency_type, city, population_group, page, per_page) are accepted but unusedfbi_get_agency toolServiceUnavailable — the UCR agency profile backend is decommissioned, with no CDE replacement identifiedori input is accepted but unusedfbi_get_arrests toolServiceUnavailable — the UCR arrests backend is decommissionedsince_year/until_year inputs are accepted but unusedfbi_get_hate_crimes toolServiceUnavailable — the UCR hate crimes backend is decommissionedscope, state_abbr, since_year, until_year, cross_offense) are accepted but unusedfbi_get_human_trafficking toolServiceUnavailable — the UCR human trafficking backend is decommissionedscope, state_abbr, ori, since_year, until_year) are accepted but unusedfbi_get_nibrs_breakdown toolServiceUnavailable — the UCR NIBRS breakdown backend is decommissioneddimension, variable, scope, state_abbr, offense_name, since_year, until_year) are accepted but unusedfbi_get_participation toolServiceUnavailable — both the UCR legacy backend and the CDE /LATEST/participation/ path are decommissioned (404)scope, state_abbr, year, nibrs_only, page, per_page) are accepted but unusedfbi_list_code_table toolServiceUnavailable — the UCR code table backend is decommissionedtable input (one of 10 code-table names) is accepted but unusedfbi://agency/{ori} resourceServiceUnavailable on read — the UCR agency profile backend is decommissionedori is the 9-character ORI (Originating Agency Identifier) codefbi://state/{state_abbr} resourceServiceUnavailable on read — the CDE /LATEST/participation/state/ path returns 404state_abbr is the two-letter US state abbreviationBuilt on @cyanheads/mcp-ts-core: stdio and Streamable HTTP transports, pluggable auth (none / jwt / oauth), swappable storage (in-memory, filesystem, Supabase, Cloudflare KV/R2/D1), structured logging with optional OpenTelemetry tracing.
FBI CDE-specific:
/cde/summarized/) for national, state, and per-agency offense rates and counts across 10 offense types/cde/leoka/) for officer fatality, weapon, and circumstance data by month or year-to-dateDEMO_KEY works without registration (shared, rate-limited pool); a registered api.data.gov key raises throughputServiceUnavailable error — the legacy UCR backend (crime-data-api.fr.cloud.gov) was decommissioned; fbi_get_arson redirects callers to fbi_get_crime_estimatesAgent-friendly output:
scope_param_missing, no_data, month_required, endpoint_decommissioned) each carry a recovery hint naming the next step or the cde.ucr.cjis.gov replacementnull rather than fabricated zeros, on the rate, clearance, and count fields of fbi_get_crime_estimates and fbi_get_agency_offensesdata_last_updated echoes the CDE's own refresh timestamp so agents can reason about freshnessAdd the following to your MCP client configuration file. See the FBI CDE API key registration to obtain a key — DEMO_KEY works for exploration but is rate-limited.
{
"mcpServers": {
"fbi-crime-mcp-server": {
"type": "stdio",
"command": "bunx",
"args": ["@cyanheads/fbi-crime-mcp-server@latest"],
"env": {
"MCP_TRANSPORT_TYPE": "stdio",
"MCP_LOG_LEVEL": "info",
"FBI_API_KEY": "your-api-key"
}
}
}
}
Or with npx (no Bun required):
{
"mcpServers": {
"fbi-crime-mcp-server": {
"type": "stdio",
"command": "npx",
"args": ["-y", "@cyanheads/fbi-crime-mcp-server@latest"],
"env": {
"MCP_TRANSPORT_TYPE": "stdio",
"MCP_LOG_LEVEL": "info",
"FBI_API_KEY": "your-api-key"
}
}
}
}
Or with Docker:
{
"mcpServers": {
"fbi-crime-mcp-server": {
"type": "stdio",
"command": "docker",
"args": [
"run", "-i", "--rm",
"-e", "MCP_TRANSPORT_TYPE=stdio",
"-e", "FBI_API_KEY=your-api-key",
"ghcr.io/cyanheads/fbi-crime-mcp-server:latest"
]
}
}
}
For Streamable HTTP, set the transport and start the server:
MCP_TRANSPORT_TYPE=http MCP_HTTP_PORT=3010 FBI_API_KEY=... bun run start:http
# Server listens at http://localhost:3010/mcp
DEMO_KEY works for testing but is rate-limited to ~1,000 req/hr from a shared pool.git clone https://github.com/cyanheads/fbi-crime-mcp-server.git
cd fbi-crime-mcp-server
bun install
cp .env.example .env
# edit .env and set FBI_API_KEY
All configuration is validated at startup via Zod schemas in src/config/server-config.ts. Key environment variables:
| Variable | Description | Default |
|---|---|---|
FBI_API_KEY | Required. api.data.gov API key for the FBI CDE API. Use DEMO_KEY for limited testing. | — |
FBI_API_BASE_UCR | Override UCR base URL. | https://api.usa.gov/crime/fbi/ucr |
FBI_API_BASE_CDE | Override CDE base URL. | https://api.usa.gov/crime/fbi/cde |
FBI_REQUEST_TIMEOUT_MS | Per-request timeout in milliseconds. | 15000 |
MCP_TRANSPORT_TYPE | Transport: stdio or http. | stdio |
MCP_HTTP_PORT | Port for HTTP server. | 3010 |
MCP_HTTP_ENDPOINT_PATH | HTTP endpoint path. | /mcp |
MCP_SESSION_MODE | HTTP session mode: stateless, stateful, or auto (resolves to stateful). The server declares stateless in code; set this to override it. | stateless |
MCP_PUBLIC_URL | Public origin override for TLS-terminating reverse-proxy deployments. | none |
MCP_AUTH_MODE | Auth mode: none, jwt, or oauth. | none |
MCP_LOG_LEVEL | Log level (RFC 5424). | info |
MCP_GC_PRESSURE_INTERVAL_MS | Opt-in Bun-only forced-GC pressure interval (ms). Try 60000 if RSS grows under sustained HTTP load. | 0 |
LOGS_DIR | Directory for log files (Node.js only). | <project-root>/logs |
STORAGE_PROVIDER_TYPE | Storage backend: in-memory, filesystem, supabase, cloudflare-kv/r2/d1. | in-memory |
OTEL_ENABLED | Enable OpenTelemetry instrumentation. | false |
See .env.example for the full list of optional overrides.
Build and run:
# One-time build
bun run rebuild
# Run the built server
bun run start:stdio
# or
bun run start:http
Run checks and tests:
bun run devcheck # Lint, format, typecheck, security
bun run test # Vitest test suite
bun run lint:mcp # Validate MCP definitions against spec
docker build -t fbi-crime-mcp-server .
docker run --rm -e FBI_API_KEY=your-key -p 3010:3010 fbi-crime-mcp-server
The Dockerfile defaults to HTTP transport, stateless session mode, and logs to /var/log/fbi-crime-mcp-server. OpenTelemetry peer dependencies are installed by default — build with --build-arg OTEL_ENABLED=false to omit them.
| Directory | Purpose |
|---|---|
src/index.ts | createApp() entry point — registers tools, resources, and inits services. |
src/config | Server-specific environment variable parsing and validation with Zod. |
src/mcp-server/tools | Tool definitions (*.tool.ts). 12 tools — 3 active via CDE API, 9 decommissioned. |
src/mcp-server/resources | Resource definitions (*.resource.ts). Agency and state overview resources. |
src/services | FBI API service layer — UCR and CDE clients with shared retry/timeout logic. |
tests/ | Unit and integration tests mirroring src/. |
See CLAUDE.md for development guidelines and architectural rules. The short version:
try/catch in tool logicctx.log for request-scoped logging, ctx.state for tenant-scoped storagesrc/mcp-server/*/definitions/index.ts/cde/summarized/, /cde/leoka/); decommissioned tools throw serviceUnavailable with a recovery hintIssues are welcome. Run checks and tests before submitting:
bun run devcheck
bun run test
Apache-2.0 — see LICENSE for details.
Source-derived launch command. Check the maintainer’s required arguments and credentials before running:
npx -y @cyanheads/fbi-crime-mcp-serverMerge this template into ~/Library/Application Support/Claude/claude_desktop_config.json. Keep existing servers. Add any arguments, credentials, and permissions required by the maintainer; this template has not been install-tested.
{
"mcpServers": {
"io-github-cyanheads-fbi-crime-mcp-server": {
"command": "npx",
"args": [
"-y",
"@cyanheads/fbi-crime-mcp-server"
]
}
}
}Restart Claude Desktop completely for changes to take effect. Confirm the server appears connected in the client’s tool list, then try a read-only example from its documentation.
Claude Desktop setup referenceio.github.cyanheads/fbi-crime-mcp-server works with any MCP-compatible client. Copy the config snippet from the Configuration section above and add it to the file shown for your client, then restart the application.
~/Library/Application Support/Claude/claude_desktop_config.jsonRestart Claude Desktop completely for changes to take effect.~/.cursor/mcp.jsonRestart Cursor for changes to take effect..vscode/mcp.jsonReload VS Code window for changes to take effect.~/.codeium/windsurf/mcp_config.jsonRestart Windsurf for changes to take effect..mcp.jsonSave at the project root, then start Claude Code in that project and review the MCP server approval prompt. Keep real credentials out of shared files.