proxmox-mcp
Provides tools for managing Proxmox VE virtual environments, including inventory, VM/container lifecycle, creation, configuration, storage management, and protected destructive actions like deletion and force-stop.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@proxmox-mcplist all VMs on node pve1"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
proxmox-mcp
proxmox-mcp is a safety-gated, local stdio Model Context Protocol server for the Proxmox VE API. It is launched as a process by an MCP host; it is not an HTTP service and does not expose an HTTP endpoint.
Status — current release: v0.1.1. The canonical distribution is the GitHub Release archive and its SHA-256 checksum. No npm package is provided or published.
Install the released Proxmox MCP
For a local stdio installation, use the checksum-verified GitHub Release archive:
There is no npm package. The LobeHub Marketplace listing describes capabilities; it is not the local installation source. ClawHub is not currently published because a publicly installable OpenClaw wrapper/listing is not available.
Related MCP server: mcp-server-proxmox
Quick install
Download the v0.1.1 archive and checksum from GitHub Releases, verify them, and extract the archive. Do this on the machine where the MCP host will run.
curl -fLO https://github.com/Theorvane/proxmox-mcp/releases/download/v0.1.1/proxmox-mcp-0.1.1.tar.gz
curl -fLO https://github.com/Theorvane/proxmox-mcp/releases/download/v0.1.1/proxmox-mcp-0.1.1.tar.gz.sha256
shasum -a 256 -c proxmox-mcp-0.1.1.tar.gz.sha256
tar -xzf proxmox-mcp-0.1.1.tar.gz
cd proxmox-mcp-0.1.1The archive requires Node.js >=22. Supply credentials through the environment; the values below are placeholders, not working credentials.
export PROXMOX_BASE_URL='https://proxmox.example:8006'
export PROXMOX_TOKEN_ID='user@realm!token-name'
: "${PROXMOX_TOKEN_SECRET:?set PROXMOX_TOKEN_SECRET in the environment}"
./proxmox-mcp./proxmox-mcp is a stdio process. Register or configure that command, its working directory, and the three environment variables in your MCP host; starting it in a terminal alone does not make it available to a client. For the archive layout and installation details, see the GitHub Release installation guide.
Configuration
Only these environment variables are used:
Variable | Required | Meaning |
| Yes | HTTPS origin for the Proxmox VE API, for example |
| Yes | Proxmox API token identifier. |
| Yes | Proxmox API token secret; provide it only through the local process environment. |
TLS certificate verification is always enabled. PROXMOX_TLS_VERIFY=false is rejected at startup; do not use it. If the Proxmox endpoint uses a private CA, trust that CA in the host trust store. See configuration for the full policy.
Capabilities
The server provides a focused set of Proxmox VE operations. MCP hosts discover the exact schemas and tool descriptions at connection time.
Area | Implemented capabilities |
Inventory | Cluster version and resources; node status; node storage; QEMU and LXC inventory; task inventory and task status. |
QEMU and LXC lifecycle | Start, graceful shutdown, stop, and reboot QEMU VMs and LXC containers. |
Creation and configuration | Create and configure QEMU VMs and LXC containers. |
Storage | Resize a QEMU disk. |
Protected actions | Delete a QEMU VM or LXC container, delete an unused QEMU disk, and force-stop a QEMU VM. |
Tool names, inputs, outputs, and node-name validation rules are documented in the tool contract.
Safety model
Control | Behavior |
Destructive-action gate |
|
Target validation | Node names are constrained to a supported Proxmox hostname label, and dynamic API path segments are encoded. |
Authorization | Proxmox RBAC remains authoritative. This server does not grant permissions beyond the API token. |
TLS | HTTPS is required and certificate verification cannot be disabled. |
Deletion, unused-disk removal, and force-stop can be non-recoverable. Review targets carefully and give the token only the Proxmox permissions it needs. See the complete safety guidance.
OpenClaw local skill
The merged dev codebase contains an OpenClaw skill at skills/proxmox-mcp-openclaw/. It is a local skill, not a generic OpenClaw plugin. Use its local SKILL.md instructions.
Choose a new absolute target directory—the target must not already exist. First inspect the credential-free plan:
node skills/proxmox-mcp-openclaw/scripts/install.mjs --dry-run /absolute/path/to/proxmox-mcpWith the three configuration variables exported in the shell, install and register it:
node skills/proxmox-mcp-openclaw/scripts/install.mjs /absolute/path/to/proxmox-mcpThe installer verifies the immutable v0.1.1 release and its checksum, then invokes the supported openclaw mcp add command only after preflight succeeds. It does not log or store credentials.
Operational boundaries
This is a local stdio MCP integration, not a hosted service or a replacement for Proxmox access controls.
The server does not make a Proxmox request until an MCP client calls a tool. Installation and documentation examples do not call a real Proxmox API.
Keep credentials out of repositories, shell history where practical, and shared configuration files. Use a least-privilege Proxmox API token.
Obtain releases only from Theorvane/proxmox-mcp GitHub Releases and verify the published SHA-256 checksum before running the archive.
Documentation
Verification and contributing
Contributors work from an issue-numbered branch based on dev, open pull requests to dev, and promote only reviewed dev to main. GitHub Release archives are the only distribution channel. See CONTRIBUTING.md.
Maintainers can run the same local verification commands used by the project:
npm ci
npm run lint
npm run typecheck
npm test
npm run build
npm run release:archive
npm run verify:release-archive
npm run validate:docs
npm run validate:governance
npm run validate:release
npm audit --omit=dev --audit-level=high
git diff --checkLicense
This project is licensed under the terms in LICENSE.
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseAqualityCmaintenanceMCP server for managing Proxmox VE clusters — provision VMs and containers, manage snapshots and backups, execute commands, browse storage, and monitor resources through natural language2513MIT
- Alicense-qualityDmaintenanceA Model Context Protocol (MCP) server for Proxmox Virtual Environment that enables AI assistants to manage virtual machines, containers, nodes, and resources through natural language interactions.3MIT
- Flicense-qualityCmaintenanceMCP server for Proxmox VE that enables AI assistants to inspect and manage LXC containers, VMs, snapshots, and resource pools via the Proxmox API.
- AlicenseAqualityCmaintenanceMCP server for managing Proxmox VE resources, VM/CT lifecycle, snapshots, backups, and clones via natural language.23MIT
Related MCP Connectors
Personal assistant MCP server with search, execute, packages, jobs, secrets, and integrations.
MCP server for generating rough-draft project plans from natural-language prompts.
A comprehensive Model Context Protocol (MCP) server that enables AI assistants to interact with yo…
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/Theorvane/proxmox-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server