AI AdminPanel Documentation

MCP Server

The AI Admin Panel includes a built-in MCP (Model Context Protocol) server. This lets AI assistants like Claude Code, Claude Desktop, Cursor, and Windsurf manage your panel programmatically.

The MCP server is served by the panel itself — it shares the panel's domain and TLS certificate, so there is no extra port, subdomain, or firewall rule to open.

Enabling the Admin MCP Server

The MCP server is disabled by default for security (its tools are admin-scoped). Enable it from the UI — no terminal or restart needed:

  1. Go to Settings → MCP Server.
  2. Toggle Enable MCP Server on.

The connection endpoints and ready-to-paste client configs appear once it's enabled. Disabling the toggle takes effect immediately.

Authentication

Admin MCP requests require an admin API key sent as a Bearer token:

  1. Create an admin API key under Settings → Security → API Keys.
  2. Use it as Authorization: Bearer <key> in your MCP client config.

Non-admin keys are rejected on the admin endpoints. Tenant connections use the separate endpoint and key type below.

Endpoints

The admin transports are served from your panel's domain:

TransportURLUse with
Streamable HTTPhttps://<your-panel>/mcpClaude Desktop, Claude Code, Cursor, modern clients
SSE compatibilityhttps://<your-panel>/sseExisting legacy clients only

The Settings → MCP Server tab shows the exact URLs for your deployment.

Connecting from Claude Code / Cursor

{
  "mcpServers": {
    "ai-admin-panel": {
      "url": "https://your-panel.example.com/mcp",
      "headers": {
        "Authorization": "Bearer YOUR_ADMIN_API_KEY"
      }
    }
  }
}

Connecting a remote client

Use a client that supports Streamable HTTP and a custom Authorization header. Set the server URL to https://your-panel.example.com/mcp and supply Bearer YOUR_ADMIN_API_KEY through the client's secret settings. The placeholder is not a usable key. This panel endpoint authenticates API keys, rather than providing an OAuth login flow. Client menus and connector availability vary by client version and plan; use the client's current connection instructions.

For browser-originated MCP HTTP requests, including the legacy SSE/message compatibility routes, the panel validates the exact normalized scheme, hostname, and effective port against PANEL_URL, or https://${PANEL_DOMAIN} when PANEL_URL is unset. It never trusts request Host or forwarding headers for this check. Native/cloud connector requests without an Origin header remain supported. Explicit protocol headers accept only the Streamable HTTP versions 2025-03-26, 2025-06-18, and 2025-11-25; duplicate or comma-combined version values are rejected as ambiguous.

Short demo and recovery

For a non-destructive demo, enable the connector for one conversation and ask Claude to list the panel's services. Confirm the returned names/statuses match the panel. Do not approve a write tool for this connection check.

If the connector does not load tools, verify the admin URL ends in /mcp, the transport is Streamable HTTP, and the request header contains the full Bearer value. Remove and re-add the custom connector if its settings cannot be edited. To stop access immediately, revoke the admin API key under Settings → Security → API Keys; disabling Settings → MCP Server stops all admin MCP requests without deleting the key.

Tenant MCP

Customers use https://your-panel.example.com/mcp/tenant with a customer-owned, organization-scoped key carrying the mcp scope, created through the customer portal's MCP page. The MCPTenant capability controls access. Admin keys and ordinary non-MCP keys are not substitutes. Tenant keys do not authenticate to the admin MCP server or the ordinary REST API.

Tenant SSE compatibility routes are /mcp/tenant/sse and /mcp/tenant/message. The admin Settings toggle controls admin MCP; tenant MCP uses its own capability check. Revoking a tenant key stops that key's access.

The tenant registry contains health, list_services, get_service_status, get_logs, start_service, stop_service, restart_service, redeploy_service, deploy_template, and get_usage. The authenticated key supplies the customer identity. Existing-service tools check ownership, and deployment uses the customer's configured per-template quota. A caller-supplied service ID does not select a different customer's resources.

Available Tools

The admin registry includes the common tools below. It also exposes health, delete_service, get_resource_usage, get_system_health, update_service_env, manage_domains, list_organizations, get_audit_log, analyze_repo, pull_model, and restart_all_services. Availability of the underlying operation depends on configured dependencies. An admin key can invoke broad and destructive operations; it is not a read-only assistant credential.

ToolDescription
list_servicesList all deployed services with status
get_service_statusGet detailed service info including containers
restart_serviceRestart a service
stop_serviceStop a running service
start_serviceStart a stopped service
list_templatesBrowse the template catalog
list_customersList customers with plans
get_dashboardGet dashboard metrics summary
deploy_templateDeploy a template with parameters
get_logsGet service container logs

Example Usage

Once connected, you can ask your AI assistant:

  • "List all running services on the panel"
  • "Restart the n8n service"
  • "What templates are available?"
  • "Show me the dashboard metrics"