MCP Connector

Manage Servers and Databases via Natural Language

1Panel MCP Server gives an AI assistant scoped access to manage a 1Panel server's websites, certificates, apps, and databases.

Works with 1paneldockergithub

79
Spark score
out of 100
Updated last month
Source checked Sep 15, 2026
Version 1.0.0
Models
universal

Add to Favorites

Why it matters

Leverage natural language to manage your Linux servers, websites, databases, and applications through the 1Panel web interface. Automate system tasks and gain insights into your infrastructure.

Outcomes

What it gets done

01

Manage websites and SSL certificates

02

Create and list databases

03

Install and manage applications

04

Monitor system information and dashboard status

Source

Get it from source

Spark does not host a copy of it.

Open source

Reports

Agent outcome reports

No reports yet

Capabilities

Tools your agent gets

get_dashboard_info

Get dashboard status

get_system_info

Get system information

list_websites

List all websites

create_website

Create a website

list_ssls

List all certificates

create_ssl

Create a certificate

list_installed_apps

List installed applications

install_openresty

Install OpenResty

+3 tools

Overview

1Panel MCP Server

1Panel MCP Server is an MCP server for the 1Panel self-hosted management panel, giving an AI assistant tools to read system status and manage websites, SSL certificates, applications, and databases. Tool access is scoped to readonly, readwrite, or full levels enforced at registration. Use it when an AI assistant needs to inspect or manage a real 1Panel server. Requires an existing 1Panel instance and access token, and defaults to read-only access until explicitly escalated.

What it does

1Panel MCP Server is an MCP server implementation for 1Panel, the self-hosted server management panel, giving an AI assistant tools to inspect and manage a 1Panel-administered server - dashboard and system info, websites, SSL certificates, installed applications, and databases.

When to use - and when NOT to

Use it when an AI assistant needs to check or manage a real 1Panel server: reading dashboard and system status, listing or creating websites and certificates, installing applications like OpenResty or MySQL, or managing databases. It requires an existing 1Panel instance and its access token - it's a control layer on top of 1Panel, not a replacement for it. By default it's locked to readonly tools; a permission model enforced at tool registration means disallowed tools are neither listed nor callable, so escalating to readwrite (website, certificate, and database creation) or full (application installation) is an explicit opt-in, not a default.

Capabilities

Tools are grouped by category with a required minimum access level: System (get_dashboard_info, get_system_info, readonly), Website (list_websites readonly, create_website readwrite), Certificate (list_ssls readonly, create_ssl readwrite), Application (list_installed_apps readonly, install_openresty/install_mysql requiring full), and Database (list_databases readonly, create_database readwrite). The HTTP transport can generate and persist its own local CA and HTTPS certificate independent of 1Panel's own certificate management, auto-renewing the server cert while reusing the CA; clients should trust the generated ca.crt rather than disabling certificate verification.

How to install

Build from source with git clone and make build, or install directly with go install github.com/1Panel-dev/mcp-1panel@latest. Configure it in Cursor, Windsurf, or another MCP client over stdio:

{
  "mcpServers": {
    "mcp-1panel": {
      "command": "mcp-1panel",
      "env": {
        "PANEL_ACCESS_TOKEN": "<your 1Panel access token>",
        "PANEL_HOST": "such as http://localhost:8080"
      }
    }
  }
}

For remote access, run it with -transport streamable-http behind a pre-shared Authorization: Bearer token - this is single-user, private-deployment auth, not the MCP OAuth flow, so put it behind an OAuth-capable gateway if you need standards-based multi-user authorization. Requires Go 1.25.0+ to build. The project recommends stdio for local desktop clients; a non-loopback HTTP listener additionally requires -allow-remote-http, an explicit certificate SAN list, and an Origin allowlist. Prefer the PANEL_ACCESS_TOKEN and PANEL_HOST environment variables over their equivalent CLI flags, since a flag value is visible in the system's process list.

Who it's for

Server administrators running 1Panel who want an AI assistant to inspect and manage sites, certificates, databases, and installed applications, with tool access scoped to exactly the risk level they're comfortable granting.

Source README

1Panel MCP Server

1Panel MCP Server is an implementation of the Model Context Protocol (MCP) server for 1Panel.

Installation

Prerequisites

  • Go 1.25.0 or higher
  • Existing 1Panel

Build from Source

  1. Clone the repository:

    git clone https://github.com/1Panel-dev/mcp-1panel.git
    cd mcp-1panel
    
  2. Build the project:

    make build
    

    Move ./build/mcp-1panel to the system environment path.

Install using go install

go install github.com/1Panel-dev/mcp-1panel@latest

Usage

Cursor and Windsurf configuration example:

stdio mode

{
  "mcpServers": {
    "mcp-1panel": {
      "command": "mcp-1panel",
      "env": {
        "PANEL_ACCESS_TOKEN": "<your 1Panel access token>",
        "PANEL_HOST": "such as http://localhost:8080"
      }
    }
  }
}

Streamable HTTP with standalone TLS

mcp-1panel can create and persist its own local CA and HTTPS server certificate. It does not depend on 1Panel certificate management.

MCP_AUTH_TOKEN=<strong random MCP token> \
PANEL_HOST=<your 1Panel access address> \
PANEL_ACCESS_TOKEN=<your 1Panel access token> \
mcp-1panel \
  -transport streamable-http \
  -addr "https://127.0.0.1:8000/mcp" \
  -tls-hosts "localhost,127.0.0.1"

On first startup, the server writes the CA path and SHA-256 fingerprint to stderr. Configure the MCP client to trust the generated ca.crt; do not disable certificate verification. The CA is reused while the server certificate is renewed automatically.

HTTP transports require an MCP authentication token by default. Clients must send it on every request as Authorization: Bearer <token>; the private X-MCP-Token header is not accepted. This is a pre-shared token mode intended for a single-user/private deployment, not the MCP OAuth authorization flow. Put the server behind an OAuth-capable gateway when standards-based multi-user authorization is required.

Use stdio for local desktop clients when possible. Non-loopback listeners require an https:// address, -allow-remote-http, a token, explicit certificate SANs, and an appropriate Origin allowlist.

Access levels

The server defaults to readonly. Tool permissions are enforced when tools are registered, so disallowed tools are not returned by tools/list and cannot be called directly.

Level Tools
readonly Queries, lists, and status reads
readwrite readonly plus existing website, certificate, and database creation tools
full readwrite plus existing application installation tools

Set the level with -access-level or MCP_ACCESS_LEVEL. Command-line configuration takes precedence.

Command Line Options

  • -token: 1Panel access token; prefer PANEL_ACCESS_TOKEN to avoid exposing secrets in process lists
  • -host: 1Panel access address; prefer PANEL_HOST for environment-based configuration
  • -transport: Transport type (stdio or streamable-http; default: stdio)
  • -addr: Base URL for HTTP transports (default: http://127.0.0.1:8000)
  • -mcp-token: Pre-shared Bearer token for HTTP transports
  • -allowed-origins: Comma-separated Origin allowlist for HTTP transports
  • -allow-insecure-http: Allow unauthenticated HTTP transports; only use for local development
  • -allow-remote-http: Allow HTTPS transports to listen on non-loopback addresses
  • -access-level: Tool access level (readonly, readwrite, or full; default: readonly)
  • -tls-dir: Directory for the local CA and HTTPS server certificate
  • -tls-hosts: Comma-separated DNS names and IP addresses for the HTTPS server certificate

Environment Variables

You can also configure the server using environment variables:

  • PANEL_HOST: 1Panel access address
  • PANEL_ACCESS_TOKEN: 1Panel access token
  • MCP_AUTH_TOKEN: Pre-shared Bearer token for streamable-http
  • MCP_ACCESS_LEVEL: Tool access level (readonly, readwrite, or full)

Available Tools

The server provides various tools for interacting with 1Panel:

Tool Category Minimum access Description
get_dashboard_info System readonly List dashboard status
get_system_info System readonly Get system information
list_websites Website readonly List all websites
create_website Website readwrite Create a website
list_ssls Certificate readonly List all certificates
create_ssl Certificate readwrite Create a certificate
list_installed_apps Application readonly List all installed applications
install_openresty Application full Install OpenResty
install_mysql Application full Install MySQL
list_databases Database readonly List all databases
create_database Database readwrite Create a database

FAQ

Common questions

Discussion

Questions & comments · 0

Sign In Sign in to leave a comment.