Skip to main content
Glama
heaventree

Heaventree WHMCS MCP

by heaventree

Heaventree WHMCS MCP

Original, MIT-licensed WHMCS addon exposing documented local API tools, operational BI reports and guarded administration over Model Context Protocol. Upload one addon folder to WHMCS; no Docker, remote database login or WHMCS remote API IP allowlist.

Release candidate 0.1.0. Local protocol/security tests are provided. Production WHMCS staging acceptance and Maxer provider verification are separate gates. Exact parity with the encrypted paid addon is not yet verified; see coverage. The existing commercial addon and JOSH bridges are not modified by this build.

Default access is read-only. Write execution requires a write-scoped token, the addon write switch, and a five-minute administrator-approved request bound to the exact tool, parameters and token. Approvals are single-use; unknown execution outcomes require independent verification, not automatic retries.

Business data remains on the WHMCS server until an authorized MCP client reads it. That client's model provider may receive returned data: self-hosting the addon does not guarantee data stays on-server when using a cloud AI client. Responses redact credential-like fields; token/audit tables do not store raw customer response bodies. Deployers must handle customer data lawfully and restrict access appropriately.

Development

PHP8.1+; no runtime Composer dependencies. Run php tests/run.php, node --test tests/bridge.test.mjs, and syntax-check every PHP file. Build an immutable ZIP with pwsh -NoProfile -File scripts/package.ps1. ZIP entries use / separators and include no secrets or vendor code.

Catalog regeneration: node scripts/generate-catalog.mjs /PATH/TO/OFFICIAL/WHMCS/developer-docs. The initial catalog uses documentation commit 2e75f454aa248b791948e14ad7b33fa9f0ded761. Regeneration is a reviewed build step, not runtime endpoint discovery; newly added operations default to write scope unless explicitly classified read-only.

Related MCP server: Clinical MCP Server

License and independence

Copyright2026 Heaventree. All original code and documentation in this repository are MIT-licensed. WHMCS is separately licensed and not included. API names and parameter types are interoperability facts from WHMCS's official documentation. No paid plugin source, ionCube decoder, license bypass, copied assets, production database or credential is distributed.

Related MCP Connectors

Related MCP Servers

  • A
    license
    Not graded
    quality
    D
    maintenance
    A read-only Model Context Protocol server that exposes over 60 AWS tools across services like EC2, S3, and IAM for AI agent interaction. It features multi-region support, resource caching, and audit logging to provide secure, AI-ready access to AWS infrastructure data.
    100 npm
    ISC
  • A
    license
    Not graded
    quality
    D
    maintenance
    A governed, audited Model Context Protocol server that provides AI agents with secure, read-only access to a clinical knowledge base through least-privilege tools, policy validation, and append-only audit logging.
    MIT
  • A
    license
    B
    quality
    C
    maintenance
    A guarded Model Context Protocol server that lets AI assistants inspect, edit, test, and validate explicitly approved local software projects, featuring 49 focused MCP tools for project discovery, safe editing, Git inspection, Laravel integration testing, and more.
    49
    1
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    A Model Context Protocol server that exposes a versioned brand package (tokens, rules, recipes, media rights, and audit gates) as resources, tools, and prompts for AI agents. It enables agents to plan and audit on-brand UI, image, motion, and video outputs while remaining read-only and credential-free.
    MIT