Jenkins MCP Server
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| JENKINS_URL | Yes | Jenkins server URL | |
| JENKINS_TOKEN | Yes | Jenkins API token | |
| MCP_READ_ONLY | No | When true, all write operations are disabled | false |
| JENKINS_USERNAME | Yes | Jenkins username | |
| MCP_ALLOWED_JOBS | No | Comma-separated list of allowed job path patterns (e.g. 'AI/*,Platform/*') | |
| JENKINS_CA_BUNDLE | No | Path to CA bundle for TLS verification | |
| JENKINS_VERIFY_TLS | No | Whether to verify TLS (true/false) | true |
| MCP_ALLOW_JOB_WRITE | No | Allow job create/update/copy/enable/disable | true |
| MCP_ALLOW_BUILD_STOP | No | Allow stop_build and cancel_queue_item | true |
| MCP_ALLOW_JOB_DELETE | No | Allow delete_job | false |
| MCP_ALLOW_JOB_UPDATE | No | Allow update_job_config | true |
| MCP_ALLOW_NODE_WRITE | No | Allow taking nodes offline/online | false |
| MCP_ALLOW_BUILD_WRITE | No | Allow triggering builds and scanning multibranch pipelines | true |
| MCP_ALLOW_DESTRUCTIVE | No | Master switch for destructive actions | true |
| MCP_ALLOW_ADMIN_REQUEST | No | Enable the generic jenkins_admin_request tool | false |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": false
} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| list_jobsA | List jobs visible to this server, optionally within a folder. Returns name, full path, URL and build colour. Pass a folder's full name, for example "Platform", to list its immediate children. Jobs outside MCP_ALLOWED_JOBS are omitted rather than reported as errors. Arbitrary plugin action/property payloads are not returned. |
| get_jobA | Get one job's current state: description, buildable flag, health and the most recent build references. Use get_job_config for its XML definition, or get_build_info for a specific build. Plugin actions and upstream/downstream job objects are not returned. |
| get_job_configA | Fetch a job's config.xml definition. Requires Job/ExtendedRead in Jenkins; Job/Read alone is not enough and fails with 403 while other tools keep working. |
| create_job_from_xmlA | Create a job from a raw config.xml. Fails if the name already exists. Prefer create_pipeline_job or create_multibranch_pipeline unless you need full control of the XML. Do not place plaintext credentials in the XML; reference Jenkins-managed credential IDs. The encoded body must fit MCP_MAX_REQUEST_BYTES. |
| update_job_configA | Replace a job's config.xml in full. Destructive: the previous definition is overwritten with no history kept by this server, and any setting absent from the XML you supply is lost. Read the current config first with get_job_config, and do not place plaintext credentials in the XML. Requires MCP_ALLOW_JOB_WRITE, MCP_ALLOW_DESTRUCTIVE and MCP_ALLOW_JOB_UPDATE. The encoded body must fit MCP_MAX_REQUEST_BYTES. |
| delete_jobA | Delete a job and all of its build history. Destructive and irreversible through this server: Jenkins core removes the job and its builds, so recovery requires an external backup. Disabled by default; requires MCP_ALLOW_JOB_WRITE, MCP_ALLOW_DESTRUCTIVE and MCP_ALLOW_JOB_DELETE. Confirm with get_job first. |
| copy_jobA | Copy an existing job's configuration to a new name. The target inherits the source's settings, including its enabled or disabled state; build history and workspaces are not copied. Both source and target must be inside MCP_ALLOWED_JOBS. Jenkins requires Job/ExtendedRead on the source and Job/Create on the target parent; it also requires source Job/Configure when extended-read redacts secrets. |
| enable_jobB | Enable a job so Jenkins will build it. Safe to call when already enabled. |
| disable_jobA | Disable a job so Jenkins stops building it. Queued builds are not cancelled; use cancel_queue_item for those. The job and its history are kept, so this is reversible with enable_job. |
| create_pipeline_jobA | Create a Pipeline job from an inline Jenkinsfile. The script runs in the Groovy sandbox. Requires workflow-job and workflow-cps, both included in the workflow-aggregator plugin. Reference Jenkins credential IDs; do not put plaintext secrets in the Jenkinsfile. The generated XML must fit MCP_MAX_REQUEST_BYTES. |
| create_multibranch_pipelineA | Create a multibranch Pipeline that discovers branches from a Git repository. Requires the workflow-multibranch, branch-api and git plugins. Run scan_multibranch_pipeline afterwards to populate branches immediately. repository_url must not contain embedded credentials, a query string, or a fragment. credentials_id names a credential already stored in Jenkins; never pass a token, password or private key in that field. script_path must be a canonical repository-relative path. The generated XML must fit MCP_MAX_REQUEST_BYTES. |
| scan_multibranch_pipelineA | Trigger a branch scan on a multibranch Pipeline so newly pushed branches are discovered without waiting for the next scheduled scan. |
| trigger_buildA | Queue a build. Returns a validated queue_id and a canonical queue_url built from configured JENKINS_URL, not a build number: the build has not started yet. Poll get_queue_item until its executable has a number, then use get_build_info. For a parameterised job pass parameters, using an empty object to accept every default; omitting it entirely makes Jenkins reject the trigger. Their encoded form must fit MCP_MAX_REQUEST_BYTES. |
| stop_buildA | Stop a running build. Destructive: the build is abandoned and marked ABORTED, and any work it had done is lost. mode escalates from stop to term and then kill. Freestyle builds support only stop; term and kill are Pipeline-only and require workflow-job. Requires MCP_ALLOW_BUILD_WRITE, MCP_ALLOW_DESTRUCTIVE and MCP_ALLOW_BUILD_STOP. |
| get_build_infoA | Get one build's result, timing, duration and parameters. build_number accepts a number or an alias such as lastBuild, lastSuccessfulBuild or lastFailedBuild. Secret-like parameter names and password/token/credential parameter classes have redacted values. Complex plugin parameter values and unrelated action/change-set payloads are not returned. |
| get_build_consoleA | Read a build's console output. Output is truncated to MCP_MAX_LOG_BYTES; pass the returned next_start back as start to continue reading, which is how a running build is followed. build_number accepts a number or an alias such as lastBuild. Invalid or incomplete Jenkins pagination metadata is refused rather than guessed. |
| list_running_buildsA | List builds currently executing across the controller, with their job and build number. Jobs outside MCP_ALLOWED_JOBS are omitted. Use get_build_console to follow one. Plugin-specific executor/action payloads are not returned. |
| get_queueA | List builds waiting to start, with why each is blocked. A queue item is not a build yet and has no build number; it gains one when an executor picks it up. Items outside MCP_ALLOWED_JOBS are omitted. Queue actions and build-parameter values are not returned. |
| get_queue_itemA | Follow one queued build from trigger to executor assignment. Pass queue_id from trigger_build. While waiting, the response explains why the item is blocked; once Jenkins starts it, executable contains the build number and URL needed by get_build_info. The owning job must match MCP_ALLOWED_JOBS. Jenkins retains completed queue records only briefly. |
| cancel_queue_itemA | Remove a queued item before it starts. Destructive: the request to build is discarded. Takes the queue item id from get_queue, which is not a build number. Use stop_build for a build that is already running. Requires MCP_ALLOW_BUILD_WRITE, MCP_ALLOW_DESTRUCTIVE and MCP_ALLOW_BUILD_STOP. |
| list_nodesA | List build nodes with their capacity, idle and offline state. Executor/current-build details are intentionally excluded; use list_running_builds for running jobs filtered through MCP_ALLOWED_JOBS. |
| get_nodeA | Get one node's capacity, idle state and offline reason. Current-build details are intentionally excluded; use list_running_builds for running jobs filtered through MCP_ALLOWED_JOBS. Node names are case sensitive and must not be empty. |
| set_node_offlineA | Take a node offline, or bring it back online. Taking a node offline is destructive: running builds keep going but no new work is scheduled there, which can stall a pipeline. Requires MCP_ALLOW_NODE_WRITE, and taking offline additionally requires MCP_ALLOW_DESTRUCTIVE. |
| jenkins_admin_requestA | Send an arbitrary authenticated request to a Jenkins path. A powerful escape hatch for endpoints no other tool covers, disabled by default and requiring MCP_ALLOW_ADMIN_REQUEST. MCP_ALLOWED_JOBS still applies to job URLs. The Groovy console additionally requires MCP_ALLOW_SCRIPT_CONSOLE and remains blocked by Minibridge when its sensitive-pattern guardrail is active. Non-read methods can mutate or delete Jenkins state and are not gated by MCP_ALLOW_DESTRUCTIVE; confirm the exact method, path and body first. path must be Jenkins-relative and absolute, for example /api/json. Session and CSRF headers are withheld from the response. Unlike typed mutation tools, raw 3xx responses are returned for the caller to interpret. The encoded body must fit MCP_MAX_REQUEST_BYTES. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 24 tools
Each tool targets a distinct resource+action, and where overlaps exist (create_job_from_xml vs create_pipeline_job vs create_multibranch_pipeline, get_queue vs get_queue_item, get_build_info vs get_build_console) the descriptions explicitly state when to use which. No two tools appear interchangeable.
Consistent snake_case verb_noun pattern throughout (list_jobs, get_job, delete_job, trigger_build, stop_build, get_queue_item, set_node_offline). The single jenkins_admin_request deviates slightly but remains readable and clearly scoped.
At 24 tools this is on the heavier side, but the Jenkins domain is broad (jobs, builds, queue, nodes, admin) and each tool covers a genuinely distinct operation, so nothing feels redundant. Slightly high for a single server, though every tool earns its place.
Strong lifecycle coverage: job CRUD/config, pipeline creation, build trigger/stop/info/console, queue inspection and cancellation, nodes, plus an admin escape hatch for anything else. Minor gaps remain (e.g. build artifacts, credential listing, views), but the admin tool largely backstops them.