Manage Servers and Databases via Natural Language
1Panel MCP Server gives an AI assistant scoped access to manage a 1Panel server's websites, certificates, apps, and databases.
1.0.0Add to Favorites
Why it matters
Leverage natural language to manage your Linux servers, websites, databases, and applications through the 1Panel web interface. Automate system tasks and gain insights into your infrastructure.
Outcomes
What it gets done
Manage websites and SSL certificates
Create and list databases
Install and manage applications
Monitor system information and dashboard status
Source
Get it from source
Spark does not host a copy of it.
Open sourceReports
Agent outcome reports
No reports yet
Capabilities
Tools your agent gets
Get dashboard status
Get system information
List all websites
Create a website
List all certificates
Create a certificate
List installed applications
Install OpenResty
Overview
1Panel MCP Server
1Panel MCP Server is an MCP server for the 1Panel self-hosted management panel, giving an AI assistant tools to read system status and manage websites, SSL certificates, applications, and databases. Tool access is scoped to readonly, readwrite, or full levels enforced at registration. Use it when an AI assistant needs to inspect or manage a real 1Panel server. Requires an existing 1Panel instance and access token, and defaults to read-only access until explicitly escalated.
What it does
1Panel MCP Server is an MCP server implementation for 1Panel, the self-hosted server management panel, giving an AI assistant tools to inspect and manage a 1Panel-administered server - dashboard and system info, websites, SSL certificates, installed applications, and databases.
When to use - and when NOT to
Use it when an AI assistant needs to check or manage a real 1Panel server: reading dashboard and system status, listing or creating websites and certificates, installing applications like OpenResty or MySQL, or managing databases. It requires an existing 1Panel instance and its access token - it's a control layer on top of 1Panel, not a replacement for it. By default it's locked to readonly tools; a permission model enforced at tool registration means disallowed tools are neither listed nor callable, so escalating to readwrite (website, certificate, and database creation) or full (application installation) is an explicit opt-in, not a default.
Capabilities
Tools are grouped by category with a required minimum access level: System (get_dashboard_info, get_system_info, readonly), Website (list_websites readonly, create_website readwrite), Certificate (list_ssls readonly, create_ssl readwrite), Application (list_installed_apps readonly, install_openresty/install_mysql requiring full), and Database (list_databases readonly, create_database readwrite). The HTTP transport can generate and persist its own local CA and HTTPS certificate independent of 1Panel's own certificate management, auto-renewing the server cert while reusing the CA; clients should trust the generated ca.crt rather than disabling certificate verification.
How to install
Build from source with git clone and make build, or install directly with go install github.com/1Panel-dev/mcp-1panel@latest. Configure it in Cursor, Windsurf, or another MCP client over stdio:
{
"mcpServers": {
"mcp-1panel": {
"command": "mcp-1panel",
"env": {
"PANEL_ACCESS_TOKEN": "<your 1Panel access token>",
"PANEL_HOST": "such as http://localhost:8080"
}
}
}
}
For remote access, run it with -transport streamable-http behind a pre-shared Authorization: Bearer token - this is single-user, private-deployment auth, not the MCP OAuth flow, so put it behind an OAuth-capable gateway if you need standards-based multi-user authorization. Requires Go 1.25.0+ to build. The project recommends stdio for local desktop clients; a non-loopback HTTP listener additionally requires -allow-remote-http, an explicit certificate SAN list, and an Origin allowlist. Prefer the PANEL_ACCESS_TOKEN and PANEL_HOST environment variables over their equivalent CLI flags, since a flag value is visible in the system's process list.
Who it's for
Server administrators running 1Panel who want an AI assistant to inspect and manage sites, certificates, databases, and installed applications, with tool access scoped to exactly the risk level they're comfortable granting.
Source README
1Panel MCP Server
1Panel MCP Server is an implementation of the Model Context Protocol (MCP) server for 1Panel.
Installation
Prerequisites
- Go 1.25.0 or higher
- Existing 1Panel
Build from Source
Clone the repository:
git clone https://github.com/1Panel-dev/mcp-1panel.git cd mcp-1panelBuild the project:
make buildMove
./build/mcp-1panelto the system environment path.
Install using go install
go install github.com/1Panel-dev/mcp-1panel@latest
Usage
Cursor and Windsurf configuration example:
stdio mode
{
"mcpServers": {
"mcp-1panel": {
"command": "mcp-1panel",
"env": {
"PANEL_ACCESS_TOKEN": "<your 1Panel access token>",
"PANEL_HOST": "such as http://localhost:8080"
}
}
}
}
Streamable HTTP with standalone TLS
mcp-1panel can create and persist its own local CA and HTTPS server certificate. It does not depend on 1Panel certificate management.
MCP_AUTH_TOKEN=<strong random MCP token> \
PANEL_HOST=<your 1Panel access address> \
PANEL_ACCESS_TOKEN=<your 1Panel access token> \
mcp-1panel \
-transport streamable-http \
-addr "https://127.0.0.1:8000/mcp" \
-tls-hosts "localhost,127.0.0.1"
On first startup, the server writes the CA path and SHA-256 fingerprint to stderr. Configure the MCP client to trust the generated ca.crt; do not disable certificate verification. The CA is reused while the server certificate is renewed automatically.
HTTP transports require an MCP authentication token by default. Clients must send it on every request as Authorization: Bearer <token>; the private X-MCP-Token header is not accepted. This is a pre-shared token mode intended for a single-user/private deployment, not the MCP OAuth authorization flow. Put the server behind an OAuth-capable gateway when standards-based multi-user authorization is required.
Use stdio for local desktop clients when possible. Non-loopback listeners require an https:// address, -allow-remote-http, a token, explicit certificate SANs, and an appropriate Origin allowlist.
Access levels
The server defaults to readonly. Tool permissions are enforced when tools are registered, so disallowed tools are not returned by tools/list and cannot be called directly.
| Level | Tools |
|---|---|
readonly |
Queries, lists, and status reads |
readwrite |
readonly plus existing website, certificate, and database creation tools |
full |
readwrite plus existing application installation tools |
Set the level with -access-level or MCP_ACCESS_LEVEL. Command-line configuration takes precedence.
Command Line Options
-token: 1Panel access token; preferPANEL_ACCESS_TOKENto avoid exposing secrets in process lists-host: 1Panel access address; preferPANEL_HOSTfor environment-based configuration-transport: Transport type (stdio or streamable-http; default: stdio)-addr: Base URL for HTTP transports (default:http://127.0.0.1:8000)-mcp-token: Pre-shared Bearer token for HTTP transports-allowed-origins: Comma-separated Origin allowlist for HTTP transports-allow-insecure-http: Allow unauthenticated HTTP transports; only use for local development-allow-remote-http: Allow HTTPS transports to listen on non-loopback addresses-access-level: Tool access level (readonly,readwrite, orfull; default:readonly)-tls-dir: Directory for the local CA and HTTPS server certificate-tls-hosts: Comma-separated DNS names and IP addresses for the HTTPS server certificate
Environment Variables
You can also configure the server using environment variables:
PANEL_HOST: 1Panel access addressPANEL_ACCESS_TOKEN: 1Panel access tokenMCP_AUTH_TOKEN: Pre-shared Bearer token forstreamable-httpMCP_ACCESS_LEVEL: Tool access level (readonly,readwrite, orfull)
Available Tools
The server provides various tools for interacting with 1Panel:
| Tool | Category | Minimum access | Description |
|---|---|---|---|
| get_dashboard_info | System | readonly |
List dashboard status |
| get_system_info | System | readonly |
Get system information |
| list_websites | Website | readonly |
List all websites |
| create_website | Website | readwrite |
Create a website |
| list_ssls | Certificate | readonly |
List all certificates |
| create_ssl | Certificate | readwrite |
Create a certificate |
| list_installed_apps | Application | readonly |
List all installed applications |
| install_openresty | Application | full |
Install OpenResty |
| install_mysql | Application | full |
Install MySQL |
| list_databases | Database | readonly |
List all databases |
| create_database | Database | readwrite |
Create a database |
FAQ
Common questions
Discussion
Questions & comments · 0
Sign In Sign in to leave a comment.