Skip to main content
Glama
drmogie

Nginx Proxy Manager MCP

by drmogie
README.md
# Nginx Proxy Manager MCP

![Version](https://img.shields.io/badge/version-2026.09.28.01-blue)
![License](https://img.shields.io/badge/license-MIT-green)

A small tool that lets Claude read and change
[Nginx Proxy Manager](https://nginxproxymanager.com/) through its API.

It runs on your own computer. Your password stays on your computer.

## What Claude can do with it

- Check that NPM is up (npm_status).
- List, look at, add, change, turn on, turn off, and delete:
  proxy hosts, redirection hosts, 404 hosts, and streams (npm_hosts).
- List and delete certificates. List access lists (npm_hosts).
- See the newest changes made in NPM (npm_audit_log).
- Anything else in the NPM API, such as making or renewing a
  certificate, access lists, users, and settings (npm_call).

When Claude changes a host, the tool reads the current one first and merges
your change. Nothing else on that host is lost.

## Safety

Every call has a safety level.

- **read**: runs right away.
- **change**: adding, editing, turning on or off. It does not run until
  Claude asks you and sets `confirm`. Claude shows you what will be sent first.
- **destructive**: deleting anything, and any change to users or settings.
  It also needs an exact phrase typed back, like `delete proxy-hosts 5`.

Other protections:

- Login and token calls are blocked. The tool logs in by itself.
- The password and the login token are never printed.
  They are removed from error messages.
- Paths must start with `/api/`. The tool cannot be pointed at another site.

## Set up

### 1. Make a user for Claude

1. Open the NPM web page (port 81).
2. Go to Users, then Add User.
3. Use a separate user just for this, like `claude@example.com`.
   Then you can turn it off on its own later.
4. Turn OFF two-step login for this user. The tool cannot do the code step.
5. Give it Administrator, or pick the permissions you want it to have.

**Do not paste the password in a chat.** Put it only in the config file below.

### 2. Add the tool to Claude

Open the Claude desktop app settings and find the MCP servers config file.
Add the block from `claude_desktop_config.example.json`.
Change the address, email, and password.

- `NPM_URL`: your NPM admin address, like `http://172.16.90.75:81`
- `NPM_EMAIL`: the login email of the user you made
- `NPM_PASSWORD`: that user's password

That file now holds a secret. Do not share it. Do not put it on GitHub.

The example uses `uvx`. If you do not have it, use Python instead:

```
pip install D:\GitHub-Projects\nginx-proxy-manager-mcp
```

Then use `"command": "nginx-proxy-manager-mcp"` and no args.

Restart the Claude desktop app.

### 3. Try it

Ask Claude: "Show my Nginx Proxy Manager proxy hosts."

## Other settings

- `NPM_VERIFY_TLS=false`: for an https address with a self-signed certificate.

## Good to know

- For a new outside address, use its own subdomain as a proxy host.
  Custom Locations under an existing domain were unreliable on this NPM.
- The NPM API is not officially documented. This tool follows the
  schema in the NPM GitHub repo. If a new NPM version changes it, use
  `npm_call` and tell me what broke.
- Not tested against a real NPM when first built. It was tested against a
  fake server.

TDQS

A4.1/5.0

Scored across 4 tools

Disambiguation4/5

npm_status and npm_audit_log are clearly distinct, but npm_hosts and npm_call overlap for certificate and access-list operations. The descriptions provide clear guidance on when to use each, though npm_call as a catch-all could subsume other tools.

Naming Consistency4/5

All names use snake_case with an npm_ prefix, which is consistent. However, they mix nouns (npm_status, npm_hosts, npm_audit_log) with a verb (npm_call), deviating from a strict verb_noun pattern.

Tool Count5/5

Four tools cover the domain efficiently: a health check, a multi-resource manager, a raw API gateway, and an audit log. Each tool earns its place without redundancy or bloat.

Completeness5/5

The combination of npm_hosts (CRUD for hosts/streams) and npm_call (any API path) ensures full lifecycle coverage for all NPM resources. Minor convenience gaps (e.g., certificate creation only via npm_call) do not limit overall capability.

Maintenance

ActivityMaintained
ResponsivenessNo issues