Skip to main content
Glama
grglzrv

Jenkins MCP Server

by grglzrv

jenkins_admin_request

Send a raw authenticated HTTP request to any Jenkins endpoint not covered by other tools. Requires admin opt-in; non-read methods can mutate or delete Jenkins state.

Instructions

Send an arbitrary authenticated request to a Jenkins path.

A powerful escape hatch for endpoints no other tool covers, disabled by default and requiring MCP_ALLOW_ADMIN_REQUEST. MCP_ALLOWED_JOBS still applies to job URLs. The Groovy console additionally requires MCP_ALLOW_SCRIPT_CONSOLE and remains blocked by Minibridge when its sensitive-pattern guardrail is active. Non-read methods can mutate or delete Jenkins state and are not gated by MCP_ALLOW_DESTRUCTIVE; confirm the exact method, path and body first. path must be Jenkins-relative and absolute, for example /api/json. Session and CSRF headers are withheld from the response. Unlike typed mutation tools, raw 3xx responses are returned for the caller to interpret. The encoded body must fit MCP_MAX_REQUEST_BYTES.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
bodyNo
pathYes
methodYes
content_typeNoapplication/json

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv2.10.10

TDQS

A4.8/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations present, the description carries the full burden and does so thoroughly: gate flags, that non-read methods mutate or delete state and are NOT gated by MCP_ALLOW_DESTRUCTIVE, that session/CSRF headers are withheld from responses, that raw 3xx responses are passed through unlike typed tools, and the MCP_MAX_REQUEST_BYTES limit.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with purpose and the escape-hatch framing, then the gating and safety notes. Dense and mostly economical, though the run of environment-variable clauses makes it slightly heavier than necessary.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a high-risk arbitrary-request tool with no annotations and no output schema, the description covers gating, mutation risk, header stripping, redirect behavior, and size limits. An agent has everything needed to invoke it safely and interpret the non-standard response handling.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 0%, so the description must compensate. It clarifies that path is Jenkins-relative and absolute with the example '/api/json', and that the encoded body must fit MCP_MAX_REQUEST_BYTES. Method semantics (allowed HTTP verbs) are only implied rather than spelled out, so it falls short of full compensation.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource: 'Send an arbitrary authenticated request to a Jenkins path.' It also positions itself against siblings by calling itself 'a powerful escape hatch for endpoints no other tool covers,' so an agent can distinguish it from the typed mutation tools without opening any schema.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicitly defines when to use it ('endpoints no other tool covers') and when it will not work: disabled by default, needs MCP_ALLOW_ADMIN_REQUEST, MCP_ALLOWED_JOBS applies to job URLs, and the Groovy console needs MCP_ALLOW_SCRIPT_CONSOLE. It also warns to confirm method/path/body before non-read calls.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.