Skip to main content
Glama
nice-winter

Nginx Proxy Manager MCP Server

by nice-winter

npm_create_access_list

Create an access list with HTTP Basic Auth users and IP allow/deny rules to restrict access to Nginx Proxy Manager hosts.

Instructions

Create a new access list with HTTP Basic Auth and/or IP restrictions

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
nameYesName of the access list
itemsNoHTTP Basic Auth users
clientsNoIP whitelist/blacklist
pass_authNoPass authentication to upstream (default: false)
satisfy_anyNoSatisfy any condition (default: false)

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv2.0.0

TDQS

C2.9/5.0
Behavior2/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description carries the full behavioral burden, and it only implies mutation via 'Create'. It does not disclose whether names must be unique, what happens on duplicate name, required permissions, or what the response contains. For a write tool with zero annotation coverage this is a notable gap.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

A single front-loaded sentence with no wasted words; the verb and resource lead immediately. It is efficient, though arguably too terse to fully earn its place as the only prose an agent gets.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness2/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

This is a 5-parameter mutation tool with no annotations and no output schema, so the description should say more about return values, defaults (pass_auth, satisfy_any), and error conditions. With nested array-of-object parameters and no guidance beyond the schema, the definition is under-specified for its complexity.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so all five parameters are already documented, and the description merely restates that auth users and IP restrictions are the two content categories. Baseline 3 is appropriate since the schema does the heavy lifting.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description names a specific verb (Create) and resource (access list) and adds the scope of what the list can hold (HTTP Basic Auth users and/or IP restrictions), which maps directly to the `items` and `clients` parameters. It is clearly distinguishable from npm_list_access_lists, npm_update_access_list, and npm_delete_access_list, though it does not explicitly say so.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

There is no guidance on when to create a new access list versus updating an existing one, and no note about prerequisites such as needing an existing proxy host to attach it to. The agent must infer the entire usage context from the sibling list.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.