Syncthing MCP
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| SYNCTHING_URL | No | Single backend Syncthing URL. | |
| SYNCTHING_API_KEY | No | Single backend Syncthing API key; alternatively use SYNCTHING_MCP_API_KEY_FILE. | |
| SYNCTHING_MCP_HOST | No | HTTP host to bind. | 127.0.0.1 |
| SYNCTHING_MCP_PORT | No | HTTP port to bind. | 8080 |
| SYNCTHING_MCP_GROUPS | No | JSON array or comma-separated list of tool groups to enable; diagnostics excluded unless explicitly enabled. | |
| SYNCTHING_MCP_CA_FILE | No | Path to a CA bundle for upstream HTTPS; certificate validation cannot be disabled. | |
| SYNCTHING_MCP_PROFILE | No | Tool profile: full or core. | full |
| SYNCTHING_MCP_INSTANCES | No | JSON list of instances to connect to. Each instance is an object with name, url, and either api_key or api_key_file; optional allowed_paths and path_style. | |
| SYNCTHING_MCP_TRANSPORT | No | Transport to use: stdio or http. | stdio |
| SYNCTHING_MCP_AUTH_TOKEN | No | HTTP bearer token credential; supply only one of AUTH_TOKEN or AUTH_TOKEN_FILE. | |
| SYNCTHING_MCP_PATH_STYLE | No | Path style: posix or windows. | posix |
| SYNCTHING_MCP_ALLOW_ADMIN | No | Also requires writes; enables trust, sharing, security and global administration. | false |
| SYNCTHING_MCP_CONCURRENCY | No | Upstream calls and active HTTP request ceiling. | 8 |
| SYNCTHING_MCP_ALLOW_WRITES | No | Permit ordinary mutations. | false |
| SYNCTHING_MCP_API_KEY_FILE | No | Path to file containing the Syncthing API key; alternative to SYNCTHING_API_KEY. | |
| SYNCTHING_MCP_SCAN_TIMEOUT | No | Scan timeout in seconds. | 300 |
| SYNCTHING_MCP_ALLOWED_HOSTS | No | JSON array or comma-separated list of exact allowed HTTP Host values, including port when present. | |
| SYNCTHING_MCP_ALLOWED_PATHS | No | JSON array or comma-separated list of allowed destination roots for single-instance mode; empty denies destination changes. | |
| SYNCTHING_MCP_ENABLED_TOOLS | No | JSON array or comma-separated list of exact tool names to enable, replacing profile selection but never bypassing permissions. | |
| SYNCTHING_MCP_MAX_PAGE_SIZE | No | Ceiling for list operations. | 100 |
| SYNCTHING_MCP_DISABLED_TOOLS | No | JSON array or comma-separated list of exact tool names to disable; always wins. | |
| SYNCTHING_MCP_ALLOWED_ORIGINS | No | JSON array or comma-separated list of allowed Origin values; supplied Origin must match exactly, absent Origin is allowed. | |
| SYNCTHING_MCP_AUTH_TOKEN_FILE | No | File containing HTTP bearer token; supply only one of AUTH_TOKEN or AUTH_TOKEN_FILE. | |
| SYNCTHING_MCP_HTTP_RATE_LIMIT | No | Authenticated requests per minute, shared-principal token bucket. | 120 |
| SYNCTHING_MCP_REQUEST_TIMEOUT | No | Request timeout in seconds. | 30 |
| SYNCTHING_MCP_MAX_OUTPUT_BYTES | No | HTTP response and tool-result budget in bytes. | 262144 |
| SYNCTHING_MCP_ALLOW_DESTRUCTIVE | No | Also requires writes; destructive calls require confirm=true. | false |
| SYNCTHING_MCP_MAX_REQUEST_BYTES | No | HTTP body and tool argument budget in bytes. | 262144 |
| SYNCTHING_MCP_MAX_UPSTREAM_BYTES | No | Maximum streamed upstream response in bytes. | 4194304 |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": false
} |
Tools
Functions exposed to the LLM to take actions
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 40 tools
Many tools are terse nouns with overlapping scopes: config vs options, devices vs device_config/defaults/statistics, folder_status vs folder_completion/statistics/errors. An agent cannot reliably tell which tool to call for a given Syncthing operation without more description.
All tools consistently use snake_case with the syncthing_ prefix, which is predictable and readable. However, they are mostly noun phrases rather than verb_noun action patterns, so the convention is consistent but not action-oriented.
40 tools is excessive for a single MCP server, especially with many terse and overlapping endpoints. Although Syncthing has a broad API, this surface is heavy and difficult to navigate.
The tools cover many read/status/config areas such as devices, folders, events, connections, and statistics, but key lifecycle operations like adding/removing folders or devices, scanning, pausing, or resuming are not clearly represented. Some CRUD coverage may exist through config tools, but it is not evident from the surface.