MeshCentral MCP Server
Provides integration with Intel Active Management Technology (AMT) for scanning and managing AMT-enabled devices through the MeshCentral panel.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@MeshCentral MCP Serverlist all devices in the lab group and show their power state"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
MeshCentral MCP Server
A Model Context Protocol (MCP) server that lets AI assistants control your MeshCentral panel.
Features
List, search, and manage devices (nodes)
List and manage device groups (meshes)
Run remote commands on devices (CMD, PowerShell, Linux shell, Agent console)
Power actions (sleep, reset, poweroff, wake-on-LAN)
Send toast notifications to devices
Manage users (list, create, delete)
View events and audit logs
Device notes management
Move devices between groups
Intel AMT device scanning
Login token authentication (avoids storing real passwords)
Local file jail (prevents agent from reading .env or escaping designated directory)
Confirmation tokens for destructive operations
Connection health check (ping/pong)
Output sanitization (ANSI stripping, truncation, prompt injection prevention)
Related MCP server: TeamViewer MCP Server
Setup
1. Install dependencies
cd meshcentral-mcp
npm install2. Configure MeshCentral credentials
Copy .env.example to .env and fill in your server details:
cp .env.example .envLogin tokens (preferred over a password)
Create a login token in the MeshCentral web UI under My Account → Login tokens. MeshCentral returns a pair: a token username (always prefixed ~t:) and a token password. Both are required — a token password on its own cannot authenticate.
MESH_TOKEN_USER=~t:xxxxxxxxxxxxxxxx
MESH_TOKEN_PASS=xxxxxxxxxxxxxxxxxxxxOr supply both in one variable, comma-separated:
MESH_TOKEN=~t:xxxxxxxxxxxxxxxx,xxxxxxxxxxxxxxxxxxxxTokens can be given an expiry and revoked without changing the account password, so they are the right credential for a service account.
Username/password fallback
MESH_SERVER_URL=https://mesh.yourdomain.com
MESH_USERNAME=admin
MESH_PASSWORD=yourpassword3. MCP Client Configuration
Add to your MCP client config (e.g. Claude Desktop claude_desktop_config.json):
{
"mcpServers": {
"meshcentral": {
"command": "node",
"args": ["path/to/meshcentral-mcp/src/index.js"],
"env": {
"MESH_SERVER_URL": "https://mesh.yourdomain.com",
"MESH_TOKEN_USER": "~t:xxxxxxxxxxxxxxxx",
"MESH_TOKEN_PASS": "xxxxxxxxxxxxxxxxxxxx"
}
}
}
}For opencode, add to your opencode.json:
{
"mcpServers": {
"meshcentral": {
"command": "node",
"args": ["path/to/meshcentral-mcp/src/index.js"],
"env": {
"MESH_SERVER_URL": "https://mesh.yourdomain.com",
"MESH_TOKEN_USER": "~t:xxxxxxxxxxxxxxxx",
"MESH_TOKEN_PASS": "xxxxxxxxxxxxxxxxxxxx"
}
}
}
}Available Tools (58 total)
Inventory & Monitoring
Tool | Description |
| Get server info and stats (cached from connect) |
| List all devices, optionally by group |
| Get device details |
| List device groups |
| List users |
| List user groups |
| Get audit events |
| Device notes |
| Last connection times for all devices |
| Device power state history |
| Full hardware info (CPU, RAM, disks, BIOS, Defender) |
| Network interfaces (MACs, IPs, DNS, WiFi) |
| Remote clipboard access |
File Operations (remote device filesystem, via secure tunnels)
Tool | Description |
| List a directory on a remote device |
| Read file content (text or base64) |
| Download remote file to local disk (confined to local file root) |
| Write text/base64 content to remote file |
| Upload local file to remote device (confined to local file root) |
| Delete files/folders — requires confirmation token |
| Create directory |
| Rename/move file or folder |
| Copy/move between directories |
| Search files by filter |
Remote Execution & Control
Tool | Description |
| Shell commands: CMD (1), PowerShell (2), Linux (3), agent console (4) |
| Raw agent console (JS) access |
| Process management |
| Installed software |
| Agent-reported system summary |
| Sleep, reset, poweroff, flash, vibrate (requires confirmation) |
| Wake-on-LAN |
| Device notifications |
Device & Group Management
Tool | Description |
| Edit device name, host, tags, ports, consent |
| Remove a device |
| Move device between groups |
| Device group management |
| Group permissions |
| Per-device user permissions |
| User accounts |
| User group management |
Agent Management
Tool | Description |
| Uninstall agent from device (requires confirmation) |
| Agent installation invite URLs |
| Push agent cores (default/recovery/tiny/clear) |
| Request agent update |
| Intel AMT network scan |
Server Administration
Tool | Description |
| Run server console commands (e.g. "help", "dbstats") |
| Server statistics |
| Server error log |
| Version info |
Security Notes
Store credentials in environment variables, never in code
Use
MESH_INSECURE_TLS=trueonly for self-signed certificates in dev/lab environmentsUse login tokens (
MESH_TOKEN_USER/MESH_TOKEN_PASS) rather than an account password — set an expiry on themLocal file access is confined to
MESH_LOCAL_FILE_ROOT(default./mcp-files); the agent cannot read.envor escape the directory. SetMESH_LOCAL_FILE_ROOT=*to disable (not recommended)Confirmation tokens are required for destructive operations (
mesh_power_action,mesh_file_delete,mesh_uninstall_agent) — the tool returns a token on first call that must be re-submitted to proceedOutput sanitization strips ANSI escapes and control characters from all device-sourced output, truncated at 100KB to prevent prompt injection
Connection health check sends periodic pings to detect dead sockets within 30 seconds
Serverinfo is cached from the connect handshake —
mesh_server_inforeturns instantly without a second requestThe MCP server acts with the full permissions of the account you give it — use a dedicated, non-admin service account scoped to the device groups you need
What's New
Login Token Authentication
Instead of storing your real MeshCentral password, use login tokens. Create one in the web UI under My Account → Login tokens. Tokens are a user/password pair that can be expired and revoked without changing your account password.
MESH_TOKEN_USER=~t:xxxxxxxxxxxxxxxx
MESH_TOKEN_PASS=xxxxxxxxxxxxxxxxxxxxOr combined: MESH_TOKEN=~t:xxxxxxxxxxxxxxxx,xxxxxxxxxxxxxxxxxxxx
Local File Jail (MESH_LOCAL_FILE_ROOT)
mesh_file_download and mesh_file_upload are now confined to a local directory (./mcp-files by default). The agent cannot read your .env, SSH keys, or escape the directory via .. or symlinks. Set MESH_LOCAL_FILE_ROOT=* to disable (not recommended).
Confirmation Tokens for Destructive Tools
Tools that can cause irreversible damage now require a two-step confirmation:
mesh_power_action(sleep/reset/poweroff)mesh_file_delete(delete files/folders)mesh_uninstall_agent(remove agent from device)
On first call, the tool returns a confirmation token. Re-invoke with confirm_token: "<token>" to proceed. Tokens expire after 120 seconds.
Connection Health Check
A ping/pong is sent every 30 seconds to detect dead sockets early, instead of waiting for the next command to fail.
Output Sanitization
All device-sourced output is now sanitized:
ANSI escape sequences stripped
Control characters removed (except tab/newline/CR)
Truncated at 100KB to prevent prompt injection from compromised devices
Serverinfo Fix
mesh_server_info now uses cached data from the connect handshake. No more timeout — returns instantly.
Serverstats Fix
mesh_server_stats push subscription cleanup now uses a finally block to guarantee the timer is stopped, even on errors.
Recommendations and future updates
I will be thankful if you suggest any new feature.
This server cannot be deployed
Maintenance
Related MCP Connectors
Connect any AI agent to 1,000+ apps and 27,000+ actions through one remote MCP server (OAuth).
- mytesla.ioOAuthio.mytesla
Control your Tesla from your AI assistant - climate, charging, access, and security.
Zero-setup MCP gateway securely connecting AI to your tools with authentication and workflows
Connect any AI assistant to Syncro: manage tickets, invoices, customers, assets, and more.
Related MCP Servers
- AlicenseAqualityCmaintenanceEnables AI assistants to manage remote servers via SSH with agentless command execution, file operations, and service management.9MIT
- FlicenseNot gradedqualityBmaintenanceExposes the TeamViewer Web API as MCP tools, enabling AI assistants to manage devices, users, groups, sessions, and more via natural language.-
- AlicenseNot gradedqualityFmaintenanceEnables AI assistants to control and communicate with MeshCore mesh network devices via HTTP, providing tools for sending messages, managing contacts, and syncing device clocks.GPL 3.0
- AlicenseNot gradedqualityBmaintenanceEnables MCP-capable AI assistants to control a Windows computer through GUI automation, file and process operations, PowerShell commands, durable background jobs, and binary file transfer with downloadable exports.MIT