Skip to main content
Glama
drmogie

Nginx Proxy Manager MCP

by drmogie

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault

No arguments

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": false
}
prompts
{
  "listChanged": false
}
resources
{
  "subscribe": false,
  "listChanged": false
}
experimental
{}

Tools

Functions exposed to the LLM to take actions

NameDescription
npm_statusA

Check that Nginx Proxy Manager is reachable and logged in.

Returns the NPM version and how many proxy hosts, redirection hosts, 404 hosts and streams exist. Read only. Good first call.

npm_hostsA

List, look at, add, change, delete, enable or disable NPM items.

kind: proxy-hosts, redirection-hosts, dead-hosts, streams, certificates, or access-lists. action: list, get, create, update, delete, enable, disable.

  • list and get are read only. list gives a short summary unless full=true.

  • create needs data. Only the main fields are needed. Sensible defaults fill the rest (for proxy-hosts: http, no certificate, block_exploits on). Proxy host example: {"domain_names": ["app.example.com"], "forward_host": "172.16.1.5", "forward_port": 8080, "allow_websocket_upgrade": true}

  • update needs id and data with ONLY the fields to change. The tool reads the current item and merges, so nothing else is lost.

  • create, update, enable and disable need confirm=true, after asking the user.

  • delete needs confirm=true and confirm_phrase='delete '. certificates and access-lists can only be listed, read, or deleted here. To make or change those, use npm_call. Tip: for a new outside address, use its own subdomain as a proxy host. Custom Locations under an existing domain have been unreliable on this NPM.

npm_callA

Call any NPM API path directly (the catch-all).

method: GET, POST, PUT, PATCH or DELETE. path: starts with /api/, for example /api/nginx/certificates. data: JSON body for POST and PUT. GET runs right away. POST and PUT need confirm=true after asking the user. DELETE, and anything under /api/users or /api/settings, also needs confirm_phrase set to ' ' exactly, for example 'DELETE /api/nginx/certificates/3'. Login and token paths are blocked. Use npm_hosts for normal hosts and streams. Use this for certificates (create, renew), access lists, users, settings, and the audit log.

npm_audit_logB

Show the newest changes made in NPM (who did what, and when). Read only.

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription

No resources

TDQS

A4.1/5.0

Scored across 4 tools

Disambiguation4/5

npm_status and npm_audit_log are clearly distinct, but npm_hosts and npm_call overlap for certificate and access-list operations. The descriptions provide clear guidance on when to use each, though npm_call as a catch-all could subsume other tools.

Naming Consistency4/5

All names use snake_case with an npm_ prefix, which is consistent. However, they mix nouns (npm_status, npm_hosts, npm_audit_log) with a verb (npm_call), deviating from a strict verb_noun pattern.

Tool Count5/5

Four tools cover the domain efficiently: a health check, a multi-resource manager, a raw API gateway, and an audit log. Each tool earns its place without redundancy or bloat.

Completeness5/5

The combination of npm_hosts (CRUD for hosts/streams) and npm_call (any API path) ensures full lifecycle coverage for all NPM resources. Minor convenience gaps (e.g., certificate creation only via npm_call) do not limit overall capability.

Maintenance

ActivityMaintained
ResponsivenessNo issues