Skip to main content
Glama
sbezo
by sbezo

Palo Alto MCP + Open WebUI

This repository runs the Palo-MCP server for Palo Alto Networks PAN-OS firewalls behind an OpenAPI-compatible mcpo bridge, then connects it to Open WebUI through Docker Compose. Local LLM model is used.

Architecture:

Main files:

  • Dockerfile builds Palo-MCP and wraps it with mcpo.

  • docker-compose.yml starts Open WebUI and the Palo MCP proxy.

  • get_panos_api_key.py generates and refreshes PA_TOKEN in .env.

  • .env.example documents required local environment variables.

Environment naming:

  • Local .env uses PA_HOST, PA_USERNAME, PA_PASSWORD, and PA_TOKEN.

  • The Compose service maps PA_HOST and PA_TOKEN into the container as PANOS_HOST and PANOS_API_KEY, which Palo-MCP expects.

  • MCPO_API_KEY protects access to the OpenAPI proxy on port 8000.

Build Palo Alto MCP server docker image and wrap it to mcpo

MCP server 'https://github.com/apius-tech/Palo-MCP' uses stdio MCP client Open WebUI supports MCP Streamable HTTP or OpenAPI mcpo acts as a bridge

docker build -t pa-mcp -f Dockerfile .

Install requirements for python script (for obtaining API key)

pip install -r requirements.txt

PA setup

  • Create new Admin role on PA firewall Device > Admin Roles > Add; Enable XML API permissions needed for this integration

  • Create new API user Device > Administrators > Add; Assign the newly created API role

  • Add username, password and PA FW IP address to .env

Generate/Refresh PA_TOKEN from PA_HOST, PA_USERNAME, and PA_PASSWORD:

python3 ./get_panos_api_key.py

Generate random keys for OpenWebUI and MCP server and add them to .env

  • WEBUI_SECRET_KEY

  • MCPO_API_KEY

start Ollama server:

Open 2 terminals: First terminal:

ollama serve

Second terminal:

ollama run qwen3:4b
OLLAMA_BASE_URL=http://host.docker.internal:11434

Spin up Open WebUI and the Palo MCP:

docker compose up --build

Test the MCP OpenAPI proxy from the host:

set -a
. ./.env
set +a

curl http://localhost:8000/docs
curl -H "Authorization: Bearer $MCPO_API_KEY" http://localhost:8000/openapi.json

Test connectivity to the configured PA device:

curl -X POST http://localhost:8000/get_firewall_info \
  -H "Authorization: Bearer $MCPO_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{}'

Open and set up Open WebUI:

  • Open WebUI at: [[http://localhost:8080]]

  • Create account if needed (first time)

  • Add MCP: Settings > Admin Settings > Integrations > Add Connection

Type: OpenAPI
Name: PA MCP
URL: http://pa_mcp:8000
Auth: Bearer + MCPO_API_KEY
  • Verify connection

  • Save

Customize new chat

  • New Chat > Integrations > Tools > PA MCP enable

    • Upload Files > upload agent_instructions.md

  • start chat

Related MCP Connectors

Related MCP Servers