Skip to main content
Glama
nice-winter

Nginx Proxy Manager MCP Server

by nice-winter

npm_update_access_list

Update an existing Nginx Proxy Manager access list to change Basic Auth users, IP allow/deny rules, and authentication settings without recreating it.

Instructions

Update an existing access list

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
nameNoName of the access list
itemsNoHTTP Basic Auth users
clientsNoIP whitelist/blacklist
list_idYesThe ID of the access list to update
pass_authNoPass authentication to upstream
satisfy_anyNoSatisfy any condition

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv2.0.0

TDQS

C2.7/5.0
Behavior1/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the entire behavioral burden, and it discloses nothing beyond the bare verb. It does not say whether omitted fields are preserved or cleared, whether items/clients replace or append to the existing list, whether password data is rewritten on every call, or what auth/permissions are required. For a destructive mutation of a security control (IP allow/deny plus Basic Auth credentials) this is a serious gap.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

A single front-loaded sentence with zero waste; nothing is padded or redundant. It is however terse to the point of underspecification for a six-parameter mutation tool, which caps this rather than lifting it to 5.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness2/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given six parameters, no annotations, no output schema, and nested credential/IP structures, a one-line description leaves the agent without the semantics it needs to update an access list safely. The schema supplies field names but the description should explain replacement vs merge behavior and the security implications.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so list_id, name, items, clients, pass_auth, and satisfy_any are all documented in the schema itself. The description adds no format or interaction semantics (e.g. how clients directives combine with satisfy_any) beyond that, so the baseline 3 applies.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb (Update) and resource (an existing access list), which cleanly separates it from the create/delete/list siblings. It stops short of describing what aspects of the access list are updatable or how this differs from npm_update_stream or npm_update_user, but the core purpose is unambiguous.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

No when-to-use guidance, no prerequisites (e.g. the list must already exist), and no mention of alternatives such as npm_create_access_list for new lists. The word 'existing' is the only hint about context, and it is left for the agent to infer.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.