1Panel

by 1panel-dev

156 stars
417 downloads
Not rated
GitHub Website

About

Enables server administrators to manage websites, databases, SSL certificates, and applications through 1Panel's server management capabilities without switching contexts.

Details

Author
1panel-dev
GitHub stars
156
Downloads
417
Categories
Cloud Service, Other, Infrastructure, Design, Developer Tools, AI, Database
Tags
#web

- Supports stdio, sse, and streamable-http transports
- Provides tools for system, website, SSL, application, and database management
- Configurable via environment variables or command-line flags
- Includes MCP authentication token and Origin allowlist for HTTP transports
- Local loopback only by default; remote access requires explicit flags and TLS

Setting up with Highlight

This MCP is not yet compatible with Highlight’s one-click setup. However, you can still use it with Highlight by following these steps:

  1. Download and install Highlight from highlightai.com/download
  2. Navigate to the plugins tab and select "Add Custom Plugin"
  3. Configure the plugin with the settings below
    Plugin Name 1Panel
    Command (node, npx, python, etc.)

    Please refer to the README for specific instructions on how to obtain API keys or other required environment variables.

  4. Enable "Start Automatically" if you want the plugin to start when Highlight launches

From the repository

Install Go 1.25+ and have an existing 1Panel instance. Build from source (make build) or install via go install github.com/1Panel-dev/mcp-1panel@latest. Configure the mcp-1panel command in your MCP client (e.g., Cursor, Windsurf) with PANEL_HOST and PANEL_ACCESS_TOKEN environment variables. Use stdio transport for local desktop clients or sse/streamable-http for remote setups.

The server provides various tools for interacting with 1Panel:

| Tool | Category | Minimum access | Description |
|-----------------------------|----------|----------------|------------------------|
| get_dashboard_info | System | readonly | List dashboard status |
| get_system_info | System | readonly | Get system information |
| list_websites | Website | readonly | List all websites |
| create_website | Website | readwrite | Create a website |
| list_ssls | Certificate | readonly | List all certificates |
| create_ssl | Certificate | readwrite | Create a certificate |
| list_installed_apps | Application | readonly | List all installed applications |
| install_openresty | Application | full | Install OpenResty |
| install_mysql | Application | full | Install MySQL |
| list_databases | Database | readonly | List all databases |
| create_database | Database | readwrite | Create a database |

Claude Desktop / Cursor

Paste into your MCP client config file to install this server.

{
    "mcpServers": {
        "1panel": {
            "mcp-1panel": {
                "command": "mcp-1panel",
                "env": {
                    "PANEL_ACCESS_TOKEN": "<your 1Panel access token>",
                    "PANEL_HOST": "such as http://localhost:8080"
                }
            }
        }
    }
}

McpServers

{
    "mcp-1panel": {
        "command": "mcp-1panel",
        "env": {
            "PANEL_ACCESS_TOKEN": "<your 1Panel access token>",
            "PANEL_HOST": "such as http://localhost:8080"
        }
    }
}

1Panel MCP Server is an implementation of the Model Context Protocol (MCP) server for 1Panel.

git clone https://github.com/1Panel-dev/mcp-1panel.git cd mcp-1panel

Move./build/mcp-1panelto the system environment path.

go install github.com/1Panel-dev/mcp-1panel@latest

CursorandWindsurfconfiguration example:

{ "mcpServers": { "mcp-1panel": { "command": "mcp-1panel", "env": { "PANEL_ACCESS_TOKEN": "<your 1Panel access token>", "PANEL_HOST": "such as http://localhost:8080" } } } }

mcp-1panelcan create and persist its own local CA and HTTPS server certificate. It does not depend on 1Panel certificate management.

MCP_AUTH_TOKEN=<strong random MCP token> \ PANEL_HOST=<your 1Panel access address> \ PANEL_ACCESS_TOKEN=<your 1Panel access token> \ mcp-1panel \ -transport streamable-http \ -addr "https://127.0.0.1:8000/mcp" \ -tls-hosts "localhost,127.0.0.1"

On first startup, the server writes the CA path and SHA-256 fingerprint to stderr. Configure the MCP client to trust the generatedca.crt; do not disable certificate verification. The CA is reused while the server certificate is renewed automatically.

HTTP transports require an MCP authentication token by default. Clients must send it on every request asAuthorization: Bearer <token>; the privateX-MCP-Tokenheader is not accepted. This is a pre-shared token mode intended for a single-user/private deployment, not the MCP OAuth authorization flow. Put the server behind an OAuth-capable gateway when standards-based multi-user authorization is required.

Use stdio for local desktop clients when possible. Non-loopback listeners require anhttps://address,-allow-remote-http, a token, explicit certificate SANs, and an appropriate Origin allowlist.

The server defaults toreadonly. Tool permissions are enforced when tools are registered, so disallowed tools are not returned bytools/listand cannot be called directly.

Set the level with-access-levelorMCP_ACCESS_LEVEL. Command-line configuration takes precedence.

- -token: 1Panel access token; preferPANEL_ACCESS_TOKENto avoid exposing secrets in process lists
- -host: 1Panel access address; preferPANEL_HOSTfor environment-based configuration
- -transport: Transport type (stdio or streamable-http; default: stdio)
- -addr: Base URL for HTTP transports (default:http://127.0.0.1:8000)
- -mcp-token: Pre-shared Bearer token for HTTP transports
- -allowed-origins: Comma-separated Origin allowlist for HTTP transports
- -allow-insecure-http: Allow unauthenticated HTTP transports; only use for local development
- -allow-remote-http: Allow HTTPS transports to listen on non-loopback addresses
- -access-level: Tool access level (readonly,readwrite, orfull; default:readonly)
- -tls-dir: Directory for the local CA and HTTPS server certificate
- -tls-hosts: Comma-separated DNS names and IP addresses for the HTTPS server certificate

You can also configure the server using environment variables:

- PANEL_HOST: 1Panel access address
- PANEL_ACCESS_TOKEN: 1Panel access token
- MCP_AUTH_TOKEN: Pre-shared Bearer token forstreamable-http
- MCP_ACCESS_LEVEL: Tool access level (readonly,readwrite, orfull)

The server provides various tools for interacting with 1Panel:

Core AWS MCP server providing prompt understanding and server management capabilities.

DevOps MCP — Secure MCP Server for Linux Server Automation

A three-tier access control MCP server that allows AI assistants (Claude Code, Cursor, Windsurf) to safely scan, plan, and operate Linux servers via SSH without full write access. Includes an out-of-band human consent token gate, automated port-conflict scanning, and a completely read-only default safe mode to eliminate accidental destructive commands on production environments.

An AI-powered interface for managing the Dokploy infrastructure platform.

An AI-powered interface for managing the Dokploy infrastructure platform.

Integrate with Foreman to manage hosts and other infrastructure resources.

The official Impreza Host connector for offshore server management

Manage LetsCloud infrastructure through natural language conversations. Supports both English and Portuguese.

MCP (Model Context Protocol) server for managing VPS servers via the mikr.us API and remote Linux servers over SSH. Built in Python, runs anywhere — locally, in Docker, or as a Claude Desktop integration.

Manage your Plesk hosting server using AI assistants.

Manage Railway infrastructure through natural language using the Railway API.

No reviews yet — be the first

Sign in to leave a review

Use Google, GitHub, or an email account so ratings stay tied to real people.

Email sign in

No reviews posted yet.