MCP servers for legal & compliance

Legal teams mainly use MCP to give AI assistants access to contracts, matter files and legal research sources. E-signature platforms and document tools are furthest along; specialised legal research servers have grown rapidly since Anthropic's "Claude for Legal" launch (May 2026). The key question for every connection: which confidential documents may the model see, and does your duty of confidentiality remain intact?

16 servers · last verified 2026-07-06 · Official = built and maintained by the vendor itself

Box MCP Server

Official

by Box

Officially supported hosted MCP server connecting AI agents to enterprise content in Box with document access, search and analysis while preserving Box security policies; works with Claude, Copilot Studio, Azure API Center, Mistral Le Chat.

Capabilities: Search enterprise content · Document access and analysis · Security-policy-preserving agent access

Authentication
Box authentication (OAuth); enterprise security policies enforced
Use cases
Legal file and claims-dossier access for AI agents, Contract and matter document retrieval

⚠ Generic content platform; older community server (hmk/box-mcp) is superseded by the official hosted one.

Documentation / source →

CourtListener MCP Server

Official

by Free Law Project

Free official MCP server exposing CourtListener's US legal research platform: millions of federal/state opinions, PACER dockets, judge profiles, oral arguments, citation networks and real-time filing alerts.

Capabilities: Keyword and semantic case-law search · PACER docket data · Citation verification · Judge biographical data · Oral argument audio/transcripts

Authentication
OAuth 2.0 with Dynamic Client Registration; free CourtListener account; thin proxy that stores no credentials
Use cases
US case-law research, Citation checking to counter hallucinations, Docket monitoring for litigants, legal aid, journalists

⚠ US law only; completely free for basic use, elevated API access via membership.

Documentation / source →

Docusign MCP Server (Beta)

Official

by Docusign

Official Docusign MCP server (Open Beta) for natural-language interaction with Docusign IAM/eSignature APIs: generate access tokens, explore/test APIs and automate end-to-end agreement workflows; also available as a Claude connector.

Capabilities: Send and manage envelopes/agreement workflows · Generate access tokens and test APIs · Access agreement data (Navigator) · Automate end-to-end signing flows

Authentication
Docusign OAuth (developer and production accounts; no intake/approval required)
Use cases
E-signature automation for legal and insurance documents, Agreement status tracking, Developer exploration of Docusign APIs

⚠ Open Beta. Community alternatives exist: CData (read-only), Luther Systems (JWT server-to-server), This Dot Labs Navigator MCP.

Documentation / source →

Drata MCP Server

Official

by Drata

Drata-hosted (zero-setup) experimental MCP server bringing compliance, risk and monitoring data into AI workflows: summarize failed tests, generate real-time risk reports, automate evidence collection (SOC 2, HIPAA, ISO 27001).

Capabilities: Summarize failed compliance tests · Real-time risk reports · Automated evidence collection

Authentication
Drata account (hosted in hardened environment)
Use cases
Continuous compliance monitoring via AI, Risk reporting

⚠ Labeled experimental by Drata; hosted-only, no open-source code. Secureframe reportedly also ships an MCP server (lower-confidence secondary source).

Documentation / source →

Everlaw MCP Connector

Official

by Everlaw

Official Everlaw e-discovery MCP connector launched in the Claude for Legal wave (May 2026), making litigation review data queryable by AI agents. Relativity and Consilio launched comparable connectors in the same wave.

Capabilities: Query e-discovery/review data · Litigation document access for AI agents

Authentication
Everlaw user authentication
Use cases
Litigation review support, Case-fact synthesis across review sets

⚠ Limited public tool-level documentation; verify capabilities with vendor.

Documentation / source →

iManage MCP Connector

Official

by iManage

Official iManage MCP connector, launched as part of Anthropic's Claude for Legal (12 May 2026), giving AI agents permission-aware access to documents and matter context in iManage Work.

Capabilities: Search and retrieve documents from iManage Work · Matter-context access for AI agents

Authentication
iManage user authentication (permission-aware)
Use cases
Drafting with firm precedents, Matter research inside Claude

⚠ Detailed public tool documentation limited; part of the Claude for Legal connector wave.

Documentation / source →

Ironclad MCP Server

Official

by Ironclad

Official MCP server exposing Ironclad's Conversational Search: read-only natural-language search over the contract repository with semantic filters, returning only results the signed-in user may access.

Capabilities: Natural-language contract repository search · Semantic filters (e.g. NDAs under California law expiring within 12 months) · Permission-aware results

Authentication
Ironclad user sign-in (results scoped to user permissions)
Use cases
Contract portfolio questions, Renewal/expiry monitoring, CLM data inside AI assistants

⚠ Read-only: search only, no contract mutations via MCP.

Documentation / source →

LegalSearch (Roop's Law Assist)

Official

by Roop's Law Assist

Public Indian legal search MCP server (remote streamable-http at https://mcp.roopslaw.ai/mcp) for judgments, statutes and corpus grounding; listed in the official MCP registry.

Capabilities: Indian case-law search · Statute lookup · Corpus grounding for legal answers

Authentication
Optional Bearer token for authenticated access; public access available
Use cases
Indian legal research via AI assistants

⚠ India jurisdiction only; early version (0.1.0, May 2026).

Documentation / source →

LexisNexis (Lexis+ with Protégé) Claude integration

Official

by LexisNexis

LexisNexis integrated Anthropic's 12 Claude legal plugins into Lexis+ with Protégé (13 May 2026), grounded in 200 billion legal documents with 4 million added daily; LexisNexis is also listed among Claude MCP connectors.

Capabilities: Legal research grounded in LexisNexis corpus · 12 practice-area plugin workflows (Product, Employment, AI Governance, Litigation, etc.)

Authentication
Lexis+ subscription
Use cases
Legal research and drafting inside Protégé with Claude, Practice-area specific workflows

⚠ Lexis+ AI rebranded to 'Lexis+ with Protégé' on 24 Feb 2026. A third-party 'LexisNexis MCP server' (vinkius.com) also exists but is NOT official.

Documentation / source →

NetDocuments MCP Server

Official

by NetDocuments

Official NetDocuments MCP server (Claude for Legal wave) with a 'legal context graph' that gives agents workspace-level intelligence — matter summaries, key parties, important dates, recent activity — before opening a document.

Capabilities: Document search and fetch · Legal context graph: matter summaries, parties, key dates, recent activity

Authentication
NetDocuments user authentication
Use cases
Context-rich matter work in AI assistants, DMS-grounded drafting and review

⚠ Marketing claims ('first and only legal context graph') from vendor-side coverage; verify per deployment.

Documentation / source →

OneTrust Developer Portal MCP Server

Official

by OneTrust

Official OneTrust MCP server for the Developer Portal: lets AI editors (Cursor, Windsurf, Claude) interact with OneTrust APIs and documentation to ask questions, generate code and run tasks.

Capabilities: Query OneTrust API documentation · Generate integration code · Run developer-portal tasks

Authentication
OneTrust developer credentials
Use cases
Building privacy/GRC integrations against OneTrust APIs

⚠ Developer/API-docs MCP, NOT a privacy-operations MCP (no DSAR or consent management via MCP). No dedicated GDPR/privacy-ops MCP server exists from major privacy vendors as of mid-2026 — a notable market gap.

Documentation / source →

PandaDoc MCP

Official

by PandaDoc

Official PandaDoc MCP server letting AI agents drive complete agreement flows from natural language: template selection, variable merging, draft review, routing, status tracking and signature capture.

Capabilities: Create documents from templates with merged variables · Route for approval and signature · Track agreement status · End-to-end agreement workflows from one prompt

Authentication
PandaDoc API key/OAuth
Use cases
Proposal-to-signature automation, Sales and legal agreement workflows

⚠ Positioned against Docusign with outcome-based pricing; relatively new release.

Documentation / source →

Vanta MCP Server

Official

by Vanta

Official open-source (TypeScript, MIT) MCP server giving AI agents access to 1,200+ automated security/compliance tests across SOC 2, ISO 27001, HIPAA and GDPR frameworks.

Capabilities: Query automated compliance test results · Framework status across SOC 2 / ISO 27001 / HIPAA / GDPR · Evidence and control status

Authentication
Vanta API token
Use cases
Compliance status reporting via AI, Audit preparation, Failed-control triage

⚠ Security-compliance automation focus, not legal advice; described as the most complete open-source compliance MCP server.

Documentation / source →

Clio community MCP servers (Oktopeak e.a.)

Community

by Oktopeak / community (not Clio)

Open-source MCP connectors for Clio practice management: read live matters, contacts, documents, tasks, calendar and billing without pasting client data into chat. At least 4 community connectors exist (Oktopeak, LegalContext, lawquarter, LegalMCP).

Capabilities: Read matters, contacts, documents · Tasks and calendar · Billing data

Authentication
Clio API OAuth credentials
Use cases
Law-firm practice data inside Claude, Privilege-conscious AI workflows (ABA Opinion 512)

⚠ No official Clio MCP server exists; none of the community connectors is endorsed by Clio.

Documentation / source →

Last updated: