Joomla MCP Server
Provides tools for managing Joomla content including articles, categories, tags, modules, menus, media, languages, templates, extensions, and multilingual associations via Joomla's Web Services API.
MCP Server for Joomla
A Joomla 4, 5 and 6 component that exposes a Model Context Protocol (MCP) server over HTTP JSON-RPC. It lets MCP clients such as Claude Desktop and Cursor work with Joomla content through the site's own Joomla Web Services API.
Version: 1.8.0 · Requires: Joomla 4, 5 or 6 · PHP 8.1+ · Licence: GPL-2.0-or-later
Features
Administrator dashboard with request summary (totals, error rate and auth failures), a requests-per-day chart, top tools and methods, and a requests log — restricted to the viewer's own requests unless they are a Super User
One-click Claude Desktop extension (
.mcpb), generated on demand from the administrator or attached to every releaseSecurity with bearer token authentication, optional IP allow-listing and CORS origin control
Configurable fixed-window rate limiting
Response caching through Joomla's cache layer
JSON Schema validation for MCP tool inputs
Health endpoint for monitoring
MCP Resources (recent published articles as
joomla://article/{id}) and guided Prompts (draft, SEO audit, translate)Joomla update server metadata for official releases
Related MCP server: WordPress MCP Python
MCP Tools
The component exposes 71 tools grouped by Joomla domain. List tools include a pagination object (total_count, count, offset, has_more, next_offset) so agents can page through large result sets. Write tools use Joomla's Web Services API where possible; a small number of behaviours not exposed cleanly through Web Services (custom module HTML writes, multilingual associations, template file editing) are handled through Joomla's database or filesystem APIs.
Articles
Tool | Description |
| Retrieve a Joomla article by ID |
| Search Joomla articles |
| Create a new Joomla article |
| Update an existing Joomla article |
| Delete a Joomla article (trashes it first when needed, then deletes permanently) |
Categories
Tool | Description |
| List Joomla content categories (use to discover valid |
| Retrieve a Joomla content category by ID |
| Create a new Joomla content category |
| Update an existing Joomla content category |
| Delete a Joomla content category (trashes first, then deletes; the category must be empty) |
Tags
Tool | Description |
| List Joomla tags |
| Retrieve a Joomla tag by ID |
| Create a new Joomla tag |
| Update an existing Joomla tag |
| Delete a Joomla tag (trashes first, then deletes) |
Article versions
Tool | Description |
| List saved versions (content history) for a Joomla article |
| Retrieve a single article version from content history |
| Compare two saved article versions (unified diff for introtext/fulltext) |
| Toggle the "keep forever" flag on an article version |
| Delete a single article version from content history |
| Restore a Joomla article to a previous saved version |
Article versioning tools require Joomla article versioning to be enabled.
Custom modules
Tool | Description |
| Create a new Joomla "Custom" ( |
| List all Joomla "Custom" ( |
| Retrieve a Joomla "Custom" module by ID |
| Update the content of a Joomla "Custom" module |
Modules
Tool | Description |
| List all Joomla modules |
| Retrieve a Joomla module by ID |
| Create a new module of any installed type (type-specific settings via |
| Update any Joomla module (all types); merges type-specific params and sets the menu (page) assignment |
| Delete a Joomla module and its page assignments |
Menus and menu items
Tool | Description |
| List all Joomla menus (menu types) |
| Create a new Joomla menu (menu type) |
| List menu items, optionally filtered by menu type |
| Retrieve a Joomla menu item by ID |
| Create a new Joomla menu item |
| Update an existing Joomla menu item |
| Delete a Joomla menu item (trashes first, then deletes) |
Media
Tool | Description |
| List Joomla media files and folders |
| Retrieve a single Joomla media file or folder by path |
| Upload a new Joomla media file |
| Create a new folder in the Joomla media library |
| Rename, move or replace an existing media file or folder |
| Delete a Joomla media file or folder by path |
Content languages
Tool | Description |
| List Joomla content languages (tags assignable to articles, menu items, etc.) |
| Retrieve a Joomla content language by ID |
| Create a new Joomla content language |
| Update an existing Joomla content language |
| Delete a Joomla content language by ID |
Installed languages
Tool | Description |
| List languages installed on the Joomla site (site and administrator clients) |
Template styles
Tool | Description |
| List Joomla template styles for the chosen client |
| Retrieve a Joomla template style by ID |
| Create a new template style for an already-installed template |
| Update an existing Joomla template style |
| Delete a Joomla template style |
Installed templates
Tool | Description |
| List templates installed on the Joomla site (site and administrator clients) |
Template files
Tool | Description |
| List editable source files of an installed template (Joomla's "Customise" view) |
| Read the source of a single template file |
| Write the source of a template file, creating it if its parent directory exists |
| Create a template override by copying a core view, module, plugin or layout into the template |
Extensions
Tool | Description |
| List installed extensions (components, modules, plugins, templates, languages, …) |
| Enable or disable an installed extension (e.g. activate a plugin after installing it) |
| Install a Joomla extension from a base64 zip or a download URL (arbitrary code execution — restrict to trusted callers) |
| Uninstall an extension by |
install_extension, uninstall_extension and update_template_file are disabled by default because they allow code execution on the server. Remove them from the Disabled Tools list in the component options to opt in.
Multilingual associations
Tool | Description |
| List cross-language associations for a Joomla article |
| Set cross-language associations for a Joomla article |
| List cross-language associations for a Joomla site menu item |
| Set cross-language associations for a Joomla site menu item |
Maintenance
Tool | Description |
| Clear Joomla's system cache so recent changes become visible on the site (all groups, or a single group such as |
Site diagnostics
Tool | Description |
| Fetch the HTML a guest visitor sees for an article or menu item (anonymous request, 512 KB cap, 30 s timeout) |
| Audit published articles for missing titles, missing/short/long metadesc, and duplicate aliases in the same category |
| Resolve article hyperlinks offline against published/unpublished articles and menu paths; external links are never probed |
get_rendered_page fetches the public site as an anonymous visitor so the result matches what a guest actually sees after the template and content plugins run. check_internal_links never issues HTTP requests for external URLs. seo_audit_articles does not inspect metakey — Joomla stopped using keyword meta tags in 2009.
Not covered (by design)
User management, Joomla global configuration, custom fields (com_fields), contacts, banners and redirects are deliberately not exposed as tools. User accounts and global configuration in particular would widen the blast radius of a leaked bearer token well beyond content management. If your workflow needs one of these domains, open an issue — they are candidates for opt-in tools in a future release.
MCP Resources
When Enable Resources is on (the default), MCP clients can attach published articles as context without a tool call.
resources/listreturns up to 50 recent published articles, newest first, asjoomla://article/{id}.resources/templates/listadvertises the templatejoomla://article/{id}.resources/readreturns the article HTML (introtext+fulltext,mimeTypetext/html).
Turning the option off omits the resources capability, returns empty lists, and answers resources/read with method-not-found.
MCP Prompts
When Enable Prompts is on (the default), MCP clients can pick guided workflows from a menu:
Prompt | Arguments | Purpose |
|
| Draft a new article matching the tone of recent published articles, for |
|
| Audit an article for SEO and suggest |
|
| Translate an article, then |
Turning the option off omits the prompts capability, returns an empty list, and answers prompts/get with method-not-found.
Installation
Download the latest com_mcpserver-<version>.zip package from the GitHub releases page, then install it in Joomla Administrator via System → Install → Extensions.
For a local development build:
./build.shThe build creates com_mcpserver-<version>.zip at the repository root. The version is read from mcpserver.xml.
Configuration
Open Administrator → Components → MCP Server, then click Options in the toolbar.
Key settings:
Server Name: identifier returned in MCP server information.Base URL: base URL of the Joomla site. Leave empty to use the current site.API Token: Joomla Web Services API token used for outbound REST calls.Verify SSL: verifies SSL certificates for outbound requests.Resolve Host To IP: optional. Pins the Base URL hostname to a specific IP (e.g.127.0.0.1) for the component's outbound REST calls only. Use when the server cannot reach its own public hostname (NAT hairpinning); the Host header and TLS validation still use the real hostname, soVerify SSLcan stay on.Cache TTL: response cache lifetime in seconds.Require Auth: requires MCP clients to send a bearer token.MCP Bearer Token: token clients must send inAuthorization: Bearer.IP Allow List: comma-separated client IP allow list.Allowed Origins: comma-separated CORS origin allow list.Trusted Proxies: comma-separated proxy IPs trusted forX-Forwarded-For.Read-Only Mode: when enabled, only read-only tools may run; every tool that writes, deletes or installs anything is blocked.Disabled Tools: comma- or newline-separated MCP tool names to block (e.g.delete_article). Defaults to the code-execution tools (install_extension,uninstall_extension,update_template_file); remove them to opt in, or enternoneto allow all tools (an emptied field reverts to the defaults when saved).Enable Resources: when enabled (the default), MCP clients can list and read recent published articles asjoomla://article/{id}resources.Enable Prompts: when enabled (the default), MCP clients can use the draft, SEO audit and translate article prompts.Rate Limit RequestsandRate Limit Window: fixed-window rate limit settings.
Configuring the API Token
The API Token setting holds a Joomla Web Services API token. The component uses it to make outbound REST calls to your site's own Joomla Web Services API, which is how most MCP tools read and write content. Without a valid token, those tools will fail.
Enable the Web Services API. In the Joomla administrator, go to System → Global Configuration → Server and ensure the Web Services components are available. The relevant plugins live under System → Plugins; enable Web Services - Content (and any other
Web Services -plugins for the data you want to access). The API plugin System - Joomla API Authentication must also be enabled — it is by default.Create a token for a user. Tokens are tied to a Joomla user account, and API calls run with that user's permissions, so use an account that has the access the MCP tools need (for full functionality, a Super User or an account with the equivalent component permissions).
Go to Users → Manage, edit the chosen user, and open the Joomla API Token tab.
Set Token Enabled to Yes, click Save, then copy the generated token. (If the tab is missing, enable the User - Joomla API Token plugin under System → Plugins.)
Paste the token into the component options. Back in Components → MCP Server, click Options in the toolbar, paste the value into API Token and click Save.
Verify the API is reachable. The component calls your site's own API under
/api/, so the web server must route that path to Joomla's API application. On Apache this works out of the box — Joomla's core.htaccessrewrites/api/requests toapi/index.php. On nginx there is no equivalent by default, so every tool fails whilehealth.pingstill reportsok(that endpoint only checks the component itself, not the outbound API layer). Check with:curl -i "https://example.com/api/index.php/v1/content/articles?page[limit]=1" \ -H "X-Joomla-Token: <API_TOKEN>" -H "Accept: application/vnd.api+json"The status code alone is not enough — the response format tells you where the problem lies:
Response from
/api/…Actual cause
HTML page
The request never reached the API application → web server routing (see the nginx note below)
JSON
404The relevant
Web Services - *plugin is disabledJSON
401/403The API token is invalid, or its user lacks sufficient permissions
On nginx, add this block before the general
location /block, then runnginx -tand reload:location /api { try_files $uri $uri/ /api/index.php$is_args$args; }
Security note: treat the API token like a password. It grants the token user's level of access to your site. Store it only in trusted configuration, and regenerate it (by toggling Token Enabled off and on) if it may have been exposed.
Governed Mode (per-client credentials)
By default the component authenticates every MCP client with the single shared MCP Bearer Token and makes outbound Joomla API calls with the Legacy Shared API Token in Basic Settings. Governed Mode ignores that Basic Settings token and replaces it with individually issued, revocable credentials: each MCP client authenticates with its own bearer token, and every request is made using the Joomla API token encrypted inside that client's credential. Successful mutating tool calls made under a governed credential are additionally attributed to the credential's Joomla user in both the component's own request log and, when available, Joomla's core Action Logs.
Prerequisite: API tokens for every user who needs a credential
Claiming a governed credential requires the user's own Joomla Web Services API token, so each of them must be able to create one. Joomla's User - Joomla API Token plugin controls this, and its Allowed User Groups setting defaults to Super Users only — so on a stock site nobody else has an API Tokens tab on their account, the claim field cannot be filled in, and the claim fails.
Before cutover, for every group that will hold a credential:
Go to System → Plugins → User - Joomla API Token and make sure it is enabled.
Add those user groups to Allowed User Groups, and save.
Each user opens their account (User Menu → Edit Account, or Users → Manage → [their account]), goes to the API Tokens tab, sets Token Enabled to Yes, and copies the token shown.
That token is what they paste when claiming. The component verifies it belongs to them, stores it encrypted, and never displays it again.
You do not have to work this out in advance: if a requester's group has no route to an API token, the Pending credential requests queue says so on that request, names the groups to add, and distinguishes a group restriction from the plugin being disabled outright. A request flagged this way can be approved, but never claimed, until the plugin setting is changed.
Prerequisite: Joomla Action Logs
Governed Mode attributes successful mutating tool calls (create/update/delete-type calls, not read-only ones) to the issuing user in Joomla's core System - Action Logs plugin, in addition to the component's own audit trail. Before cutover, enable it under System → Plugins → System - Action Logs. If the plugin (or com_actionlogs itself) is not installed or enabled, the Action Log write is silently skipped — the MCP response and the component's own audit trail (#__mcpserver_request_log) are unaffected — so governed mode still functions, but per-user actions will not appear in Users → Action Logs. Enable it first if you need that attribution for compliance or review.
Setup
Setup requires Governed Mode to be enabled first — see Migrating clients off the shared token below, and note the downtime warning there. While Governed Mode is off, Manage Credentials is hidden and every task on it is refused.
The credential salt — a random value stored in the component's own configuration, not in mcpserver.xml or any file — is generated automatically when the component is installed or updated, so there is nothing to provision by hand. Combined with the Joomla application secret, it derives the key that encrypts every stored credential's underlying Joomla API token, so back it up as part of your normal Joomla database backups; see Recovery below.
Go to Administrator → Components → MCP Server → Client Configuration and click Manage Credentials in the Governed Mode panel. (There is no menu entry for it: the panel, and therefore the page, only appear while Governed Mode is on.) Any user granted Manage Own Credentials (
mcpserver.credential.self) orcore.manageoncom_mcpservercan open this page — that is what the request step below relies on. Approving, rejecting, deleting a credential and pruning the audit trail each additionally require a Super User (globalcore.admin).Confirm the Governed Mode Setup panel reports the salt as provisioned, and record the recovery key fingerprint (a one-way hash, never the salt or secret itself) shown beside it. After a database restore or migration, compare it against the fingerprint shown post-restore to confirm the credential salt was preserved intact, before assuming existing credentials will still decrypt.
If the panel instead shows a Provision credential salt button, automatic provisioning did not run (or the stored salt is unreadable). Pressing it — a Super User action — generates a salt only while no credential exists. If credentials are already stored, do not treat this as a fix: their salt has been lost, a new one cannot decrypt them, and the button will refuse. Restore the salt from backup instead, or reissue every credential.
Migrating clients off the shared token
Governed Mode is a single site-wide toggle (Governed Mode in Options → Security Settings), not a per-client switch, and it is the master switch for the whole credential workflow: while it is off, Manage Credentials is hidden from the administrator menu and no credential can be requested, approved or claimed.
Plan for downtime. Enabling Governed Mode stops the shared
MCP Bearer Tokenfrom being accepted immediately, but credentials can only be requested after it is enabled. Every MCP client is therefore refused from the moment you switch it on until its user has claimed a credential. Do the cutover in a maintenance window, and have each user ready to claim.
Enable Governed Mode in Options → Security Settings. Manage Credentials appears in the component menu. From this point the shared
API TokenandMCP Bearer Tokenare no longer consulted, and existing clients will be refused until they are migrated.Open Manage Credentials and check the Setup panel above: the credential salt is generated automatically on install/update, so this is normally a confirmation rather than an action.
Each eligible user opens Manage Credentials and requests access with the client name. A different Super User reviews the pending request, approves it, and chooses that request's expiry. A Super User cannot approve or reject their own request.
The request owner then opens their approved request, enters their own current Joomla API token, and claims the credential. The component validates the token's ownership only at this step. The one-time bearer token shown must be copied immediately — it is never displayed again — and configured in the client the same way the shared bearer token was (
Authorization: Bearer <token>, orHTTP_AUTH_BEARERfor the bundled bridge).Once every client has claimed and configured its credential, service is restored: each client now authenticates and acts as its own issued credential and its own Joomla user.
To roll back, switch Governed Mode off: the shared bearer token is accepted again immediately, issued credentials stop working, and Manage Credentials disappears from the menu. Nothing is deleted, so switching it back on restores the previously issued credentials.
Rollback
Disabling Governed Mode in Options → Security Settings is the rollback: it does not delete the credential salt, any issued credential, or the audit trail — it only stops governed authentication being used, so requests fall back to the shared MCP Bearer Token and shared API Token immediately. Re-enabling later resumes governed authentication with the same salt and the same still-active credentials, without needing to re-run Setup or reissue credentials (unless they have since expired or been revoked).
Recovery
Lost or revoked a credential: submit and claim a new request from Manage Credentials for the same user; the old credential's bearer token cannot be recovered (it is never stored), only revoked.
Restoring the site from a database backup: because encrypted credential tokens are keyed on the credential salt (
#__extensions.params.credential_saltforcom_mcpserver) together with the Joomla application secret, restore both from the same backup as the#__mcpserver_credentialtable. Compare the recovery key fingerprint shown on Manage Credentials before and after the restore to confirm the salt was preserved; a changed fingerprint means every existing credential must be reissued.Joomla application secret rotated independently of a restore: this also invalidates every existing credential's stored ciphertext, since the encryption key is derived from both the secret and the salt. Reissue credentials for every affected client after rotating the secret.
Endpoints
Method | Path | Description |
|
| MCP JSON-RPC endpoint in the site application |
|
| Server-Sent Events stream used by the stdio bridge |
|
| Site health endpoint |
|
| MCP JSON-RPC endpoint in the administrator application |
|
| Administrator health endpoint |
Claude Desktop Extension (.mcpb)
For Claude Desktop the easiest client setup is the bundled extension: a .mcpb file (a zip in the MCPB format) that installs with a double-click. It contains the component's own zero-dependency HTTP bridge, so there is no Node.js install, no npm package and no hand-edited JSON — Claude Desktop supplies the Node runtime itself, and the connector appears as MCP Server for Joomla with the project logo.
Download it from your own site (recommended). In Administrator → Components → MCP Server, click Download Claude Desktop extension in the MCP Client Configuration card. The component generates a personalised bundle on the fly: the endpoint URL is pre-filled and the connector is named after the site, which keeps several Joomla sites clearly distinguishable in Claude Desktop.
Or download the generic bundle. Every GitHub release also publishes com_mcpserver.mcpb alongside the component zip.
To install:
Double-click the downloaded
.mcpbfile (requires Claude Desktop).Enter the MCP endpoint URL — pre-filled when the bundle was downloaded from your site; otherwise copy the RPC Endpoint shown under Components → MCP Server.
Enter the MCP Bearer Token from Components → MCP Server, under Options in the toolbar.
The bearer token is never embedded in the downloaded file: it remains a one-time paste into Claude Desktop's settings, so no live credential lands in your downloads folder, backups or sync folders.
Desktop Client Bridge
Claude Desktop users: prefer the .mcpb extension above — it needs no Node.js or manual configuration. The bridge below remains for other stdio clients and custom setups.
For MCP clients that use stdio transport, run the included Node.js bridge. After installation it is located at components/com_mcpserver/mcp-http-bridge.js in your Joomla site root. When working from a repository checkout or extracted release zip, use site/mcp-http-bridge.js instead.
node components/com_mcpserver/mcp-http-bridge.js <endpoint-url> [bearer-token]Example:
node components/com_mcpserver/mcp-http-bridge.js "https://example.com/index.php?option=com_mcpserver&task=rpc.handle" "$MCP_BEARER_TOKEN"MCP client configuration
For your agent (e.g. Codex, Cursor, Claude, Hermes, OpenClaw), point your MCP client configuration file at the bundled bridge:
{
"mcpServers": {
"joomla": {
"command": "node",
"args": [
"/path/to/joomla/components/com_mcpserver/mcp-http-bridge.js",
"https://example.com/index.php?option=com_mcpserver&task=rpc.handle"
],
"env": {
"HTTP_AUTH_BEARER": "your-mcp-bearer-token"
}
}
}
}The bridge speaks plain HTTP POST with no SSE or transport negotiation, so connection failures surface their real cause.
Windows / Claude Desktop
Claude Desktop on Windows spawns MCP servers with a truncated PATH that excludes the Node.js directory, so "command": "npx" (or a bare "node") fails with spawn npx ENOENT. Any cmd.exe layer — npx, npx.cmd or cmd /c — must also be avoided: cmd.exe treats & as a command separator and splits the endpoint URL at &task=, which the site answers with an HTML 404. Use the absolute path to node.exe and invoke the bridge directly. Copy mcp-http-bridge.js to the Windows machine first (from components/com_mcpserver/ in the Joomla site root, or from the release zip):
{
"mcpServers": {
"joomla": {
"command": "C:\\Program Files\\nodejs\\node.exe",
"args": [
"C:\\path\\to\\mcp-http-bridge.js",
"https://example.com/index.php?option=com_mcpserver&task=rpc.handle"
],
"env": {
"HTTP_AUTH_BEARER": "your-mcp-bearer-token"
}
}
}
}Fully quit Claude Desktop from the tray after editing the configuration — closing the window is not enough.
The bearer token can also be supplied through HTTP_AUTH_BEARER. Set MCP_IGNORE_SSL=1 only for local development with self-signed certificates.
Release Build
composer validate --working-dir=admin --no-check-publish
./build.shLicence
MCP Server for Joomla is free software released under GPL-2.0-or-later.
This server cannot be deployed
Maintenance
Related MCP Connectors
Remote MCP server for supportsheep: run AI interviews and manage support content for your blog.
A MCP server built for developers enabling Git based project management with project and personal…
An MCP server that let you interact with Cycloid.io Internal Development Portal and Platform
An MCP server that provides an API to LLMs to manage their JumpCloud resources.
Related MCP Servers
- FlicenseBqualityDmaintenanceAn MCP server that enables users to execute arbitrary shell commands on their local machine and receive the output. It provides a terminal tool for running system commands through MCP-compatible clients using the Python SDK.1-
- AlicenseCqualityDmaintenanceA lightweight MCP server that connects to WordPress via REST API, enabling content management (posts, pages, categories, etc.) and site configuration through natural language commands.49Apache 2.0
- FlicenseNot gradedqualityDmaintenanceA secure, controlled terminal MCP server that enables executing whitelisted shell commands safely with multiple security layers.-
- AlicenseNot gradedqualityCmaintenanceSSH-based MCP server that enables remote execution of SSH commands, file transfers, and secure server management via the MCP protocol.ISC