Codanna
A local MCP server and CLI for agents: semantic code search, call graphs and change-impact analysis
Medium risk
We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.
Why this level
- Reads and indexes the project's source code
- Runs a local server; with optional remote embeddings data goes to an external API
Install
Manual install
curl -fsSL --proto '=https' --tlsv1.2 https://install.codanna.sh | shInstall for macOS, Linux and WSL.
This is third-party code. Review the repository files before installing.
What it does
Codanna indexes a repository on disk and returns a correlated view of the code in one call: symbol context, signature, callees, callers and the blast radius of a change. It fuses symbol search, semantic search, call graphs, dependency tracking and document RAG, collapsing the grep-and-read loop into a single response. You can run it as a persistent MCP server for a long session or as one-shot CLI commands for slash-commands, hooks and CI. The index and embedding model stay local, and by default no source leaves the machine. It supports Claude Code, Cursor, Windsurf, Codex, Gemini and other MCP clients across fifteen languages.
Who it is for. For developers who want the agent to understand code structure rather than match strings.
Good fit when
- You need to see where a function is called and what breaks if you change it
- You want semantic search by meaning, not by name
- You want fast code answers in slash-commands and CI without a daemon
Not a fit when
- You need a language outside the supported fifteen
- You are on Windows and not ready for its experimental status
Example request
Find where errors are handled and show what breaks if I change this functionLimitations
The embedding model needs about 150 MB and downloads on first use. Building from source requires Rust 1.85 and, on Linux, pkg-config and libssl-dev. Windows support is experimental. Remote OpenAI-compatible embeddings are opt-in, and then data goes to an external API with the key kept in the environment only.
How to disable. Remove the codanna entry from the MCP configuration, and optionally remove the package and the project's .codanna index folder.
MCP
- Transport
- stdio, http
- Authentication
- not required
| Environment variables | |
|---|---|
| CODANNA_EMBED_API_KEY secret | Key for remote embeddings via an OpenAI-compatible endpoint, needed only for the optional remote mode |
Security check
- Reads and indexes the project's source code
- Runs a local server; with optional remote embeddings data goes to an external API
README in short
The README describes Codanna as a local code intelligence server and CLI for agents, written in Rust. One call returns the symbol, docs, signature, two-way calls and impact analysis rather than plain string matches. The tools are reachable as a persistent MCP server over stdio, HTTP and HTTPS or as one-shot CLI commands. It installs via an install script, Homebrew, Nix or Cargo, and there is a Claude Code plugin with x-ray and graph visualizations. It supports fifteen languages and runs locally. Apache 2.0 licensed.
FAQ
Does code leave the machine?
By default no. The index and embedding model run locally; remote embeddings via an external API are opt-in.
Is a persistent server required?
No. The same tools are available as one-shot codanna mcp commands without a daemon, handy for slash-commands, hooks and CI.
Related
A skills library that gives coding agents a development process: brainstorming, planning, TDD, subagents and code review
Skills for real engineers by Matt Pocock
Skills For Real Engineers
Small composable skills for engineering with agents: plan grilling, TDD, bug diagnosis, code review and architecture
GitHub toolkit for spec-driven development: the specify CLI adds agent commands and skills to a project, from principles to implementation
Reference MCP servers
Model Context Protocol servers
Official reference MCP servers: Filesystem, Fetch, Git, Memory, Sequential Thinking, Time and Everything