mcp-jumpserver
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| JUMPSERVER_URL | Yes | The URL of the JumpServer instance, e.g. https://jumpserver.example.com | |
| JUMPSERVER_ORG_ID | No | The organization UUID in JumpServer, if required. Optional. | |
| JUMPSERVER_PASSWORD | Yes | The password for the JumpServer service account. | |
| JUMPSERVER_USERNAME | Yes | The username for a dedicated JumpServer service account with minimal permissions. | |
| JUMPSERVER_VERIFY_SSL | No | Whether to verify SSL certificates. Defaults to 'true'. Set to 'false' to disable verification. | true |
| JUMPSERVER_DATABASE_ASSETS | No | A JSON array of database asset names (e.g. '["DB-正式mysql-A", "DB-正式mysql-B"]') used by get_jumpserver_configured_database_credentials. Optional if you only use the single-asset tool. |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": false
} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| test_jumpserver_loginA | Verify URL and username/password authentication without returning the API token. |
| list_jumpserver_databasesA | List JumpServer database assets. Optionally filter by name or address. |
| list_jumpserver_database_accountsA | List non-secret accounts for an exact database asset name, address, or UUID. |
| get_jumpserver_temporary_database_credentialA | Create temporary database proxy credentials like JumpServer's DB Guide page. The asset must be an exact name, address, or UUID. If multiple stored-secret accounts or database protocols are permitted, pass the account username/UUID and protocol explicitly. The returned connection.username and connection.password are short-lived plaintext credentials for the JumpServer database proxy, not the underlying database account secret. |
| get_jumpserver_configured_database_credentialsA | Create temporary proxy credentials for every configured database asset. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 5 tools
Each tool has a distinct purpose: testing login, listing databases, listing accounts, and two credential-generation tools. The two credential tools differ by scope (single asset vs. all configured assets), which is clear from their descriptions, though they could still be confused at a glance.
All tool names follow a consistent verb_jumpserver_noun pattern using snake_case (test, list, list, get, get). The pattern is predictable and readable, with no mixing of conventions or vague verbs.
With 5 tools, the server is well-scoped for its purpose of managing and retrieving JumpServer database credentials. Each tool fills a clear role without excess or deficiency.
The set covers authentication verification, asset listing, account listing, and credential retrieval for single and bulk scenarios. Missing CRUD operations for databases or accounts are not central to the stated purpose, but a create/delete tool would round out the surface.