aapanel-mcp
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| AAPANEL_CONFIG | No | Override the config file location. | |
| AAPANEL_API_KEY | Yes | API key for the aaPanel API interface. Required. | |
| AAPANEL_PANEL_URL | No | Panel URL. Must include the port. | http://127.0.0.1:8888 |
| AAPANEL_READ_ONLY | No | Refuses every state-changing tool. | true |
| AAPANEL_TIMEOUT_MS | No | Per-request timeout in milliseconds. | 60000 |
| AAPANEL_ALLOW_DANGEROUS | No | Unlocks root credentials and raw file access. | false |
| AAPANEL_ALLOW_SELF_SIGNED | No | Accept an unverifiable panel certificate. | false |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
| resources | {
"listChanged": true
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| panel_system_totalA | Panel version, OS, CPU cores, CPU usage and physical memory totals. Use this first to confirm connectivity and see what the box looks like. |
| panel_disk_infoA | Capacity and inode usage for every mounted partition. Use before any operation that writes large files, uploads a certificate, or imports a database dump. |
| panel_network_statusB | Realtime CPU, memory, load average and cumulative network traffic counters. |
| panel_install_task_countA | Number of install/compile tasks still running. Poll this after asking the panel to install software instead of guessing when a long operation finished. |
| panel_check_updateC | Report whether a newer panel release is available. Read-only when called without force. |
| panel_mysql_statusA | Installed MySQL version and whether the service is running. |
| site_listA | All PHP sites with id, domain, root path, remark, expiry and backup count. This is the entry point for any site operation, since most actions need a numeric site id. |
| site_getA | Fetch a single site record by id. Cheaper and more reliable than paging the whole list when the id is already known. |
| site_typesB | Available site groups/classification ids, with id 0 being the default group. |
| site_list_domainsA | Every domain bound to a site, including the port each one answers on. |
| site_get_rootB | Absolute root directory of a site, without listing every site. |
| site_php_versionsA | Every PHP version installed on the panel, with the "00" pseudo-version meaning pure static. Pass one of these versions when creating a site. |
| site_php_versionB | Which PHP version a specific site currently runs. |
| site_rewrite_templatesB | Named rewrite rule templates shipped with the panel (wordpress, laravel5, thinkphp, ...). |
| site_get_rewriteA | Contents of one rewrite template, so a rule can be reviewed before it is applied to a live site. |
| site_get_configB | Raw nginx or apache vhost file for a site. Useful for debugging a 502 or a rewrite that is not taking effect. |
| site_get_sslB | Whether SSL is deployed for a site, plus certificate subject and expiry when present. |
| site_dir_useriniC | The .user.ini anti-cross-site protection flag, access-log flag and the current run directory of a site. |
| site_delete_checkA | What a site deletion would take with it: associated domains, databases, FTP accounts and root directory. Always call this before site_delete so the user can see the blast radius. |
| ssl_listA | All SSL certificates uploaded to the panel, with the hash needed to deploy one to a site. |
| db_listB | All MySQL databases known to the panel, with user, access host and size. |
| db_tablesA | Table names, engines, row counts and total size for a database. Use this to confirm a schema landed before pointing an app at it. |
| db_access_getC | Hosts a database user is allowed to connect from, plus its SSL mode. |
| db_backupsC | Backup files recorded for a database, newest first. |
| db_recycle_binA | Databases that were deleted and can still be restored. Use db_delete_check first: the panel keeps them recoverable. |
| db_delete_checkC | The record the panel would remove, so a deletion can be confirmed against the right database. |
| site_createA | Create a PHP site, optionally with an FTP account and a MySQL database in one call. The panel generates passwords; the response returns them once, so capture them for the user rather than logging them. |
| site_deleteA | Delete a site. Run site_delete_check first and show the user what would be lost. The panel keeps a recycle bin for some resources, but do not rely on it. |
| site_startA | Bring a stopped site back online. |
| site_stopB | Take a site offline without deleting it. |
| site_add_domainA | Bind an extra domain to an existing site. Newline-separated values add several at once. The site name must also be added to DNS. |
| site_remove_domainA | Unbind one domain from a site, leaving the site itself intact. |
| site_set_php_versionA | Switch a site to another installed PHP version. Extensions available in one version may be missing in another, so verify afterwards. |
| site_set_run_pathA | Change the directory nginx resolves requests against, for apps whose entry point lives in a subdirectory such as /public. The directory must already exist inside the site root. |
| site_set_dir_useriniC | Toggle the .user.ini cross-site protection for a site. |
| site_set_rewriteA | Write the rewrite config for a site and reload nginx. Overwrites the current rule, so read the existing one first when changing something live. |
| site_set_indexB | Change which filenames nginx treats as directory indexes, comma separated. |
| site_backupA | Start a site backup. Poll panel_install_task_count or site_backups to see when it finishes. |
| site_list_backupsB | Backup records for a site, newest first. |
| db_createB | Create a MySQL database and user. Pass 127.0.0.1 as the access host unless the app connects from another machine, in which case pass that machine ip or % for any host. |
| db_set_passwordA | Set a new password for an existing database user. Update the application config in the same change, or the app will lose the database. |
| db_set_accessC | Change which hosts a database user may connect from. |
| db_backupB | Start a database backup. The result lands in the panel backup directory. |
| db_deleteA | Delete a database. The panel moves it to the recycle bin rather than dropping it immediately, but treat it as destructive and confirm with db_delete_check first. |
| db_optimize_tableC | Run OPTIMIZE TABLE on one or more tables of a database. |
| db_repair_tableA | Run REPAIR TABLE on one or more tables of a database, for recovering from a crash. |
| db_sync_from_serverA | Pull databases that exist in MySQL but are not tracked by the panel into the panel inventory. Safe and non-destructive to existing records. |
| db_restoreA | Restore a deleted database using the rname shown by db_recycle_bin. |
| db_import_sqlA | Import a .sql file that already exists on the panel host into a database. The file must be on the panel machine, not uploaded by this server. |
| ssl_uploadA | Store a PEM certificate and private key in the panel. Returns the hash used by ssl_deploy. |
| ssl_deployA | Bind a stored certificate to one or more sites, replacing their current SSL configuration. |
| ssl_disableB | Remove the SSL configuration from a site, returning it to plain HTTP. |
| danger_mysql_root_passwordA | Read the MySQL root password, or set a new one when password is supplied. This is the highest-privilege credential on the box: the server refuses to expose it unless AAPANEL_ALLOW_DANGEROUS is set. |
| danger_mysql_reset_root_passwordA | Set a new MySQL root password. Every existing root login, cron job and monitoring agent that used the old password will stop working. |
| danger_write_fileA | Write any file the panel user can write, including vhost and nginx configs. This bypasses every validation in the site tools, so the server refuses it unless AAPANEL_ALLOW_DANGEROUS is set. |
| danger_read_fileA | Read any file readable by the panel user, including /www/server/panel/config.json and database files. Refused unless AAPANEL_ALLOW_DANGEROUS is set. |
| danger_update_panelA | Install a panel update. Refused unless AAPANEL_ALLOW_DANGEROUS is set. |
| aapanel_statusA | Report the panel address, whether the connection works, the panel version, and which modes are active (read-only, dangerous operations). Safe to call at any time; it reveals no secrets. |
| aapanel_capabilitiesA | Every operation this server exposes, with its risk level. Use it to discover what is possible and which operations are currently blocked by the server mode. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
| panel-overview | Server health snapshot: OS, panel version, CPU, memory, disks and load. |
| databases | All MySQL databases tracked by the panel. |
| Site list unavailable | Could not reach the aaPanel at http://127.0.0.1:8888: connect ECONNREFUSED 127.0.0.1:8888. Verify AAPANEL_PANEL_URL and that the panel port is open. |
TDQS
Scored across 59 tools
Most tools target clearly distinct resources and actions across sites, databases, SSL, panel status, and dangerous operations. However, danger_mysql_root_password and danger_mysql_reset_root_password overlap in setting the MySQL root password, and aapanel_status partially overlaps panel_system_total and panel_check_update, creating minor ambiguity.
Tool names consistently use snake_case with predictable domain prefixes such as site_, db_, ssl_, panel_, danger_, and aapanel_. The few prefix choices are intentional and readable, so an agent can reliably infer the tool family from the name.
59 tools is far above the practical range for an MCP server and exceeds the 25+ threshold for being too many. Although aaPanel is a broad administration surface, many granular read-only status tools could be consolidated without losing functionality.
The surface covers most core lifecycle operations for sites, databases, SSL, panel status, and dangerous operations, including delete checks, backups, restores, and imports. Some adjacent aaPanel areas are missing, such as standalone FTP account management, cron jobs, firewall, DNS management, and a generic site update operation.