django-admin-mcp
Provides tools to interact with Django admin models via MCP, enabling CRUD operations, admin actions, model history, and more on Django models exposed through the admin interface.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@django-admin-mcplist the latest articles"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
django-admin-mcp
Add a mixin to your ModelAdmin and MCP clients get CRUD, admin actions and relationship traversal, inside Django's existing permissions. Only Django and Pydantic as dependencies.
Why not just give the agent database access?
A database connection hands the agent raw tables. The Django admin is where your project already encodes who may touch what, how records are validated, and what the sanctioned bulk operations are. This package puts the agent behind that layer instead of around it:
Permissions — every call goes through
ModelAdmin.has_*_permission(). A token can only do what its linked user can do, and starts with no access until you grant it.Validation — writes run
full_clean()and yoursave_model()/save_related()hooks, so the agent cannot save a record the admin form would reject.Audit history — every create, update, delete and action is written to Django's
LogEntryunder the token's user. You can see what the agent changed, and the agent can read the history too.Admin actions — "publish", "refund", "export CSV" and your other registered actions become tools, including two-step confirmation flows. The agent uses the operations you designed rather than inventing SQL.
Scoped exposure —
mcp_fields/mcp_exclude_fieldskeep password hashes and secrets out of the agent's view;get_queryset()still limits which rows it can see.
Related MCP server: drf-mcp-docs
How it compares
A generic Django MCP server or a hand-rolled FastMCP wrapper asks you to define tools, schemas and permission checks yourself, one function at a time. This package reads the ModelAdmin classes you already maintain and generates the tools from them, so field choices, querysets, validation, actions and permissions stay in one place and the agent inherits every change you make to the admin. It also ships as a plain Django app with no MCP SDK or extra HTTP stack.
Installation
pip install django-admin-mcp# settings.py
INSTALLED_APPS = [
'django_admin_mcp',
# ...
]
# urls.py
urlpatterns = [
path('mcp/', include('django_admin_mcp.urls')),
# ...
]python manage.py migrate django_admin_mcpQuick start
1. Expose a model. Set mcp_expose = True to generate tools for it. Models with the mixin but without the flag are discoverable through find_models only.
from django.contrib import admin
from django_admin_mcp import MCPAdminMixin
from .models import Article, Author
@admin.register(Article)
class ArticleAdmin(MCPAdminMixin, admin.ModelAdmin):
mcp_expose = True # list_article, get_article, create_article, ...
mcp_exclude_fields = ['internal_notes']
list_display = ['title', 'author', 'published']
@admin.register(Author)
class AuthorAdmin(MCPAdminMixin, admin.ModelAdmin):
pass # discoverable, no direct tools2. Create a token in the admin at /admin/django_admin_mcp/mcptoken/. Grant it exactly the permissions and groups the agent needs. The linked user caps what the token can do and is the identity its changes are logged under.
3. Point your MCP client at it, for example in a .mcp.json for Claude Code:
{
"mcpServers": {
"django-admin": {
"type": "http",
"url": "http://localhost:8000/mcp/",
"headers": { "Authorization": "Bearer YOUR_TOKEN" }
}
}
}4. Ask the agent.
User: Show me the latest 10 articles
Agent: [calls list_article with limit=10]
User: Mark articles 1, 2 and 3 as published
Agent: [calls action_article with action="mark_as_published", ids=[1, 2, 3]]
User: What changed on article 42?
Agent: [calls history_article with id=42]Tools
For each exposed model (here Article) the server generates:
Tool | Does |
| Read with pagination and filtering (needs view) |
| Write single records (needs add / change / delete) |
| Create, update or delete many records at once |
| List and run registered admin actions, including file-returning exports |
| Field definitions, types and constraints |
| Follow foreign keys and reverse relations |
| Django admin change history |
| Search suggestions for foreign-key fields |
Plus find_models to discover everything exposed, MCP prompts for common workflows, and read-only resources at models:// and data:// URIs. The endpoint speaks JSON-RPC 2.0 over HTTP with GET /mcp/health/ for health checks. Full reference in the docs.
Security in brief
Tokens look like
mcp_<key>.<secret>; only a salted hash of the secret is stored.Each token carries its own permissions and groups, intersected with its user's permissions. Deactivating the user disables its tokens.
Expiry is configurable; revoke a token by deactivating or deleting it in the admin.
Sensitive values are redacted from log messages, and large action downloads are capped by
MCP_ACTION_MAX_FILE_BYTES(default 5 MiB).
See Permissions and Token Management for details.
Requirements
Python 3.10+, Django 3.2 to 5.0, Pydantic 2. Tested against every Django release in that range.
Support the project
If this saved you time, a star on GitHub helps others find it. Issues and PRs are welcome; see the contributing guide.
License
MIT
This server cannot be deployed
Maintenance
Related MCP Connectors
Your DRF API as MCP tools — 1,800 endpoints become 16 dispatchers, permissioned by Django.
Build multi-tenant apps over MCP. Schemas, CRUD, deploys — access control enforced server-side.
Query, browse, and automate OmegaAI workspaces from any MCP client. Streamable HTTP with OAuth 2.0.
- GentkeyOAuthcom.gentkey
One MCP URL for all your connectors — scoped writes, enforced constraints, and a full audit trail.
Related MCP Servers
- AlicenseNot gradedqualityBmaintenanceExposes Django admin's ModelAdmin as MCP tools, with identical permissions, form validation, and session authentication.5MIT
- AlicenseNot gradedqualityCmaintenanceExposes Django REST Framework API documentation via MCP for AI coding agents to read, understand, and write frontend integration code.16MIT
- AlicenseNot gradedqualityDmaintenanceTurns Django models into MCP tools and a REST API from a single class, and can generate a Django project from a MySQL or Postgres schema.2MIT
- AlicenseNot gradedqualityCmaintenanceExposes Django REST Framework APIs as MCP tools for AI agents via the Model Context Protocol, with automatic discovery and security.1MIT