WHMCS MCP Server
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@WHMCS MCP Serverfind client by email and show their unpaid invoices"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
whmcs-bridge-mcp
An MCP (Model Context Protocol) server for the WHMCS External API — built for safe production use, not just convenience.
Read-only by default. Write actions are opt-in per domain. Billing and destructive actions require a two-step confirmation. Secrets, card data, and PII are redacted before results ever reach the model. The server detects your WHMCS version at startup and warns on unsupported installs.
Tested against the WHMCS 8.12.x and 9.0.x External API contract (action names and parameters are unchanged across that range).
Install
npm install -g whmcs-bridge-mcp
# or run without installing:
npx whmcs-bridge-mcpClaude Desktop / Claude Code
{
"mcpServers": {
"whmcs": {
"command": "npx",
"args": ["-y", "whmcs-bridge-mcp"],
"env": {
"WHMCS_API_URL": "https://your-whmcs-install.example.com/includes/api.php",
"WHMCS_API_IDENTIFIER": "your-api-identifier",
"WHMCS_API_SECRET": "your-api-secret",
"WHMCS_MCP_MODE": "readonly"
}
}
}
}From source
git clone https://github.com/peguesj/whmcs-mcp.git
cd whmcs-mcp
npm install
npm run build
cp .env.example .env # fill in your own values — never commit real credentials
node dist/index.jsRelated MCP server: whm-mcp-server
Quickstart
In WHMCS admin, create a dedicated API Credential (Setup → Staff Management → Manage API Credentials, or the legacy API user under System Settings) and, if your WHMCS version supports it, an API Role scoped to only the actions you intend to expose. Least-privilege first — see
SECURITY.mdfor a recommended role recipe.Set
WHMCS_API_URL,WHMCS_API_IDENTIFIER, andWHMCS_API_SECRET(see.env.example).Leave
WHMCS_MCP_MODEunset orreadonlyfor your first run. Confirm the server starts andsystem_get_detailsreports your WHMCS version.Add domains you need with
WHMCS_MCP_ENABLE_DOMAINS(defaults to all domains, filtered by mode/tier).Only set
WHMCS_MCP_MODE=writeorfullonce you have reviewed Safety model below and understand what each mode exposes.
Safety model
Every tool has a tier:
Tier | Meaning | Example |
| No side effects. Always advertised. |
|
| Mutates non-billing state (tickets, contacts, DNS, service metadata). |
|
| Mutates invoices, payments, credits, orders, or domain registration/transfer/renewal. Confirmation-gated and off unless |
|
| Irreversible or hard-to-reverse (delete, merge, terminate, cancel, mark fraud). Always confirmation-gated. |
|
And every deployment has a mode, set via WHMCS_MCP_MODE:
Mode |
|
|
|
|
| advertised | hidden | hidden | hidden |
| advertised | advertised | hidden | advertised (confirm required) |
| advertised | advertised | advertised (confirm required) | advertised (confirm required) |
WHMCS_MCP_ENABLE_DOMAINS (comma-separated: tickets,clients,products,invoices,domains,orders,system) further narrows which domains' tools are registered at all, independent of mode.
flowchart LR
subgraph Tiers
R[read]
W[write]
B[billing]
D[destructive]
end
subgraph Modes
RO[readonly<br/>default]
WM[write]
FM[full]
end
RO -->|advertises| R
WM -->|advertises| R
WM -->|advertises| W
WM -->|advertises, confirm required| D
FM -->|advertises| R
FM -->|advertises| W
FM -->|advertises, confirm required| B
FM -->|advertises, confirm required| DTwo-step confirmation (billing and destructive tiers): the first call to a gated tool returns a human-readable preview plus a short-lived, single-use confirmToken (HMAC-signed, 5-minute TTL, bound to the tool name and a hash of its arguments). The caller must repeat the call with that exact token to execute. Every mutating tool also accepts dryRun: true, which returns the same preview and makes no network call at all — no token needed, no state changed.
Redaction runs on every response and on error messages before they leave the process: API secrets, session/access keys, stored passwords, full card and bank account numbers, CVV, and EPP transfer codes are always stripped. Email, phone, and address fields are redacted when WHMCS_MCP_REDACT_PII=true (the recommended default for any shared or logged transcript).
Operator policy note: this project ships with the invoice-mutating tools (billing_create_invoice, billing_update_invoice, billing_add_payment, billing_apply_credit, billing_capture_payment) in the billing tier specifically so an operator can enforce "no agent writes to WHMCS invoices" by simply never setting WHMCS_MCP_MODE=full. Do not enable full mode in a deployment where invoice mutation must stay human-only.
See SECURITY.md for the full threat model and the recommended least-privilege WHMCS API role.
Example: a billing/destructive call through an agent harness
The sequence below shows a harness-driven agent (any orchestrator that spawns subagents against this
MCP server — the example uses an ecc-style agent config) walking a billing-tier tool through the
confirm-token flow. The agent never mutates state on the first call; it only mutates after echoing back
the exact confirmToken it was handed.
sequenceDiagram
participant Agent as Harness agent (ecc)
participant MCP as whmcs-bridge-mcp
participant WHMCS as WHMCS External API
Agent->>MCP: billing_apply_credit(clientid, amount, description)
Note over MCP: tier=billing, no confirmToken present
MCP-->>Agent: preview + confirmToken (5m TTL, single-use)
Agent->>Agent: surface preview to operator / policy check
Agent->>MCP: billing_apply_credit(..., confirmToken)
Note over MCP: token verified, matches tool+args hash
MCP->>WHMCS: AddCredit
WHMCS-->>MCP: result=success
MCP-->>Agent: structuredContent (redacted)Registering the server under an ecc-family harness config looks the same as any other MCP client —
add it once per project or globally, then reference its tools by name from an agent definition:
// .claude/settings.json (or wherever your harness reads MCP server config)
{
"mcpServers": {
"whmcs": {
"command": "npx",
"args": ["-y", "whmcs-bridge-mcp"],
"env": {
"WHMCS_API_URL": "https://your-whmcs-install.example.com/includes/api.php",
"WHMCS_API_IDENTIFIER": "your-api-identifier",
"WHMCS_API_SECRET": "your-api-secret",
"WHMCS_MCP_MODE": "readonly"
}
}
}
}<!-- an ecc-style agent definition scoping which tools it may call -->
---
name: whmcs-ticket-triage
description: Read-only ticket triage. Never enables write/billing/destructive tools.
tools: mcp__whmcs__tickets_list, mcp__whmcs__tickets_get, mcp__whmcs__tickets_get_predefined_replies
model: haiku
---Keep write/billing/destructive tools out of a read-only agent's tools: allowlist even when the
server itself is running in a more permissive mode elsewhere — the mode/domain gates above are the
server's own defense-in-depth, not a substitute for scoping what each agent can reach.
Configuration
Env var | Required | Default | Purpose |
| yes | — | Full URL to |
| yes | — | API credential identifier. |
| yes | — | API credential secret. Never logged. |
| no | — | Optional |
| no |
|
|
| no | all domains | Comma-separated domain filter: |
| no |
| Redact email/phone/address in tool output in addition to the always-on secret/card redaction. |
| no |
| Per-request timeout to the WHMCS API. |
| no |
| Token-bucket rate limit applied to outgoing WHMCS API calls. |
| no |
| Allows |
Full details, including per-tool minimum API-role permissions: docs/configuration.md. WHMCS 8.x/9.x compatibility notes: docs/version-compatibility.md.
Tools
The full generated tool reference — every tool, its tier, its WHMCS action, and its parameters — lives in docs/tools.md (regenerated from the zod schemas via npm run gen:docs, also published as site/data/tools.json for the marketing site's tool catalog).
At a glance, tools are grouped by domain, mirroring src/tools/:
system—system_get_details(version discovery),system_get_stats,system_get_activity_log,system_get_admin_details,system_get_todo_items,system_get_email_templates,system_send_email,system_get_payment_methods,system_get_currencies,system_log_activity, plus thewhmcs_raw_callescape hatch (full mode only, allowlisted actions, confirm-gated).tickets— list/get/create/reply/update/note/merge/delete tickets, attachments, counts, departments, statuses, predefined replies.clients— list/get/create/update/close clients, contacts, client emails, client groups.products— product/promotion lookups, client services and addons, service and addon updates, module lifecycle (create/suspend/unsuspend/terminate/change-package), product/config-option upgrades.invoices— invoice list/get/create/update, payments, credits, transactions, billable items, saved pay methods, and quotes (list/create/update/send).domains— client domain list, WHOIS lookup and availability, nameservers, locking, renew/register/transfer, TLD pricing.orders— order list/create/accept/pending/cancel/fraud/delete, order statuses.
Example call (MCP tool invocation shown as JSON-RPC-style params):
{
"name": "tickets_list",
"arguments": { "status": "Open", "limitnum": 25 }
}Example of a confirm-gated mutation:
// 1. First call — preview only, no network mutation
{ "name": "tickets_delete", "arguments": { "ticketid": 4821 } }
// -> { "preview": "Delete ticket #4821 (subject: ...) — irreversible", "confirmToken": "eyJ..." }
// 2. Second call — echoes the token to execute
{ "name": "tickets_delete", "arguments": { "ticketid": 4821, "confirmToken": "eyJ..." } }Versioning
This repo tags atomically: every commit (via a post-commit git hook in .githooks/) bumps
package.json's MINOR version and creates an annotated vX.Y.0 tag on the resulting version-bump
commit. Hooks wire themselves up automatically on npm install (via the prepare script setting
git config core.hooksPath .githooks); no manual setup is needed after cloning.
Development
npm install
npm run typecheck # tsc --noEmit
npm run lint
npm test # vitest against an in-process mock WHMCS server (test/mock-whmcs-server.ts)
npm run gen:docs # regenerate docs/tools.md and site/data/tools.json from the tool registry
npm run screenshots # Playwright captures against MCP Inspector + the mock server, for site/assets/screenshots
npm run pack:check # npm pack --dry-runThe mock WHMCS server serves synthetic fixture data only (test/fixtures/) — screenshots and tests never touch a real WHMCS instance or real client data.
Docker
docker build -t whmcs-mcp .
docker run --rm -i \
-e WHMCS_API_URL -e WHMCS_API_IDENTIFIER -e WHMCS_API_SECRET \
-e WHMCS_MCP_MODE=readonly \
whmcs-mcpThe image is a multi-stage build onto a distroless Node runtime, running as a non-root user, with stdio as the default transport.
Security
See SECURITY.md for the threat model, the recommended least-privilege WHMCS API role, the billing-tier policy, and how to report a vulnerability.
Acknowledgments
Several WHMCS MCP servers already existed before this one; each contributed an idea worth borrowing:
Project | License | Language | Notes |
AGPL-3.0 | Go | Closest in spirit — read-only default, confirmation-gated mutations, redacted output, ~15-25 tools advertised per profile out of 162 documented actions. We borrowed the "small advertised tool list" idea. | |
Commercial | TypeScript | 98 tools, | |
| MIT | TypeScript | 34 tools, no tiered safety model. Holds the unscoped npm name, which is why we publish as |
| ISC | TypeScript | 60+ tools, last published 2026-04. Holds the |
MIT | — | Most-starred of the group; ships CI, a GHCR Docker image, and a generated |
This project differentiates on safety posture (tiered mode matrix, confirm-token flow, deep redaction), license (MIT, no paid tier), typed schemas (one zod schema per WHMCS action, not a generic dispatcher), version awareness (runtime WhmcsDetails check), and an extensible custom-action layer for operator-defined tools outside the built-in domain set.
License
MIT © Jeremiah Pegues
This server cannot be deployed
Maintenance
Related MCP Connectors
- PlixanaOAuthcom.plixana
Operate the Plixana CRM from any AI: contacts, deals, quotes, WhatsApp and metrics.
- mcp-serverOAuthcom.make
Give your AI agents the tools to build, manage, and run automation workflows.
Malaysian SME accounting, e-Invoice and payroll for your AI. 64 tools; writes are approved drafts.
Hosted MCP with 91 agent tools: X, domains, SEO, Maps, Trends, Search, YouTube, TikTok, and more.
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceEnables AI agents to manage Plesk hosting environments through a set of standardized tools for security, health monitoring, DNS, email, backups, and service management.MIT
- FlicenseNot gradedqualityCmaintenanceEnables AI assistants to manage WHM hosting accounts and server administration tasks including account management, server stats, updates, SSL, backups, and email through a secure API.10-
- AlicenseNot gradedqualityCmaintenanceEnables AI agents to administrate WHMCS installations through the External API, providing ~50 tools for clients, billing, orders, services, domains, support, and aggregators with safety features and governance.26 npm2ISC
- FlicenseNot gradedqualityCmaintenanceEnables AI assistants to manage cPanel hosting accounts including DNS, email, databases, SSL, files, security, and more through natural language using cPanel's UAPI and API2.-