piherder-mcp
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@piherder-mcpshow me the current server inventory"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
PiHerder MCP
stdio process that lets Cursor, Claude, Codex, Windsurf, Continue, Goose, and other MCP clients call a PiHerder instance through the existing bearer API.
It runs on the computer that runs the agent. It is not part of the PiHerder image, and the herder does not open an MCP port. The public demo is not a target.
Adapter 0.1.1 talks to the token API that shipped with PiHerder 1.6.0. The contract for this cut is the v1.7 train. MCP registry name: io.github.bjorngluck/piherder-mcp (see server.json).
Install
Full steps and scope notes: Agents (MCP).
export PIHERDER_URL='https://piherder.example.com'
export PIHERDER_TOKEN='ph_…'
uvx piherder-mcpRequires uv (uvx). The package is on PyPI (piherder-mcp 0.1.1).
Git fallback (pin a branch or commit):
uvx --from git+https://github.com/bjorngluck/piherder-mcp.git piherder-mcpAuth and tokens
In PiHerder: Settings → API management (mint a token). Prefer an MCP preset when that lands on the token page. Details: API tokens.
readis required.jobs,edit, andfilesadd the write tools. A token withoutreadexits on stderr.Set
PIHERDER_URLandPIHERDER_TOKENfor the MCP process.
${PIHERDER_TOKEN} often does not expand inside client JSON env blocks. Many clients pass that string literally. Prefer one of:
Export
PIHERDER_TOKENin the host environment and omit it from the clientenvobject (if the client inherits the parent env), orUse the client's secret / env UI when it has one, or
Paste the token once into the client config and keep that file out of git.
Samples in clients/ use a ph_… placeholder — replace it, or remove the key and rely on the host env. Do not commit real tokens.
Related MCP server: Puppet Enterprise MCP Server
Clients
Samples: clients/ (Cursor, Claude Desktop, Codex, Grok, Windsurf, Continue, Goose, Windows cmd /c). Path notes: clients/README.md.
Claude Desktop config locations:
macOS:
~/Library/Application Support/Claude/claude_desktop_config.jsonWindows:
%APPDATA%\Claude\claude_desktop_config.json
Minimal Cursor / Claude-shaped entry:
{
"mcpServers": {
"piherder": {
"command": "uvx",
"args": ["piherder-mcp"],
"env": {
"PIHERDER_URL": "https://piherder.example.com",
"PIHERDER_TOKEN": "ph_…"
}
}
}
}The same operating note is in skills/piherder/SKILL.md (Grok), clients/cursor/piherder.mdc (Cursor), CLAUDE.md, and AGENTS.md.
Tools
Tool | Scope |
|
|
|
|
|
|
|
|
trigger_job accepts backup, retention, os_patch, container_patch, os_update_check, and container_update_check. A 409 is the job already running. Poll get_job. File bodies are capped at 256 KiB.
SSH, the console, Move, undo, compose stack actions, and token admin are not tools.
Wiki
Topic | Page |
Install, clients, scopes | |
Token scopes and allowlist | |
Jobs the token can start | |
Fleet-jail files | |
Train contract |
Do not vendor this tree inside the PiHerder Docker image.
Publishing (maintainers)
piherder-mcp 0.1.1 is the first PyPI release. The PyPI badge links to that project page. The Release badge links to the v0.1.1 GitHub Release.
Trusted Publisher is already set: GitHub Environment pypi, workflow release.yml, owner bjorngluck, repository piherder-mcp. Later versions reuse it. github-release and publish-pypi still run independently after the build, so a green GitHub Release is not proof the package is on PyPI.
Package version is
piherder_mcp.__version__.pyproject.tomlreads it. CI checksserver.json, the Continue sample, the changelog heading, and the README adapter line.Tag the release commit and push the tag:
git tag -a vX.Y.Z <sha> -m "piherder-mcp X.Y.Z" && git push origin vX.Y.Z.Confirm the Release has wheel and sdist assets and the
publish-pypijob succeeded, then check pypi.org/project/piherder-mcp.Optional: publish
server.jsonto the MCP registry; keep the README<!-- mcp-name: … -->marker in sync withserver.jsonname(the version test checks the marker).Suggested GitHub topics:
mcp,model-context-protocol,piherder,python,stdio,uvx.
See CHANGELOG.md. Workflow comments in .github/workflows/release.yml repeat the Trusted Publisher fields.
Tests
pip install -e ".[dev]"
pytest -qTests mock HTTP. They do not call a live herder. CI runs Python 3.10–3.12.
Support
Optional. Nothing here is required to install the adapter.
github.com/sponsors/bjorngluck · buymeacoffee.com/bjorngluck · Support the project
This server cannot be deployed
Maintenance
Related MCP Connectors
Build, validate, deploy — HTTP APIs, cron jobs, webhooks and MCP tools — from your AI client. Air Pipe MCP token as a bearer credential, e.g. 'Authorization: Bearer <token>'. Create one at https://app.airpipe.io/
Deploy and manage Jade Hosting projects from AI clients. Jade account and OAuth required.
Your apps, skills, MCP servers and keys from ahel.ai, served to Claude, ChatGPT, Cursor and Codex.
MCP server that lets AI assistants use all OneSchema features exposed via the public API.
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceEnables LLMs to manage and monitor Hetzner Cloud infrastructure, including servers, firewalls, networks, and snapshots, while keeping the API token local and secure.MIT
- FlicenseNot gradedqualityDmaintenanceExposes the full Puppet Enterprise API to AI assistants, enabling management of Puppet infrastructure through natural language.-
- AlicenseBqualityAmaintenanceGives AI assistants read (and optionally write) access to a NetBox instance, covering DCIM, IPAM, circuits, virtualization, tenancy, and more.10039 npmMIT
- AlicenseNot gradedqualityAmaintenanceTurns any Linux server into an AI-agent-accessible machine over HTTPS, allowing MCP clients like ChatGPT, Claude, and Grok to securely control files, run shell commands, inspect system state, query SQLite, and work with git behind a bearer token.402 npm4MIT