🎩 You're Invited:Meet the Socket team at Black Hat in Las Vegas, August 3-6.RSVP
Sign In

obambu-cpanel-mcp

Package Overview
Dependencies
Maintainers
1
Versions
2
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

obambu-cpanel-mcp

MCP server exposing cPanel UAPI (domains, DNS, email, MySQL, files) as tools for AI assistants

latest
Source
npmnpm
Version
0.1.2
Version published
Maintainers
1
Created
Source

obambu-cpanel-mcp

A Model Context Protocol (MCP) server that lets an AI assistant (Claude, etc.) manage a cPanel hosting account through the cPanel UAPI.

It exposes tools for domains, DNS zones, email accounts, MySQL databases, and file listing, plus a generic escape hatch to call any other UAPI module/function.

Requirements

  • Node.js 18+
  • A cPanel account with API token access (Security → Manage API Tokens in cPanel)

Setup

git clone https://github.com/<your-username>/obambu-cpanel-mcp.git
cd obambu-cpanel-mcp
npm install
cp .env.example .env

Edit .env with your cPanel details:

CPANEL_HOST=your-server-hostname-or-ip
CPANEL_PORT=2083
CPANEL_USERNAME=your-cpanel-username
CPANEL_API_TOKEN=paste-your-api-token-here

Build and run:

npm run build
npm start

For local development without building first:

npm run dev

Using it with an MCP client

Add it to your MCP client config (e.g. Claude Desktop / Claude Code), pointing at the built entrypoint:

{
  "mcpServers": {
    "obambu-cpanel": {
      "command": "node",
      "args": ["/absolute/path/to/obambu-cpanel-mcp/dist/index.js"],
      "env": {
        "CPANEL_HOST": "your-server-hostname-or-ip",
        "CPANEL_PORT": "2083",
        "CPANEL_USERNAME": "your-cpanel-username",
        "CPANEL_API_TOKEN": "your-api-token"
      }
    }
  }
}

Available tools

ToolDescription
get_account_summaryDisk/bandwidth quota usage and general stats
list_domainsDomains, subdomains, addon domains and parked domains
list_dns_recordsRead a domain's DNS zone
add_dns_recordAdd a DNS record
edit_dns_recordEdit an existing DNS record
remove_dns_recordRemove a DNS record
list_emailsList email accounts
create_emailCreate an email account
delete_emailDelete an email account
list_filesList files/directories under the account home directory
list_databasesList MySQL databases
list_database_usersList MySQL database users
create_databaseCreate a MySQL database
create_database_userCreate a MySQL database user
grant_database_privilegesGrant a user privileges on a database
cpanel_uapi_callCall any UAPI module/function directly for anything not covered above

Usage examples

Once connected, just talk to your assistant in plain language — it picks the right tool:

  • "Test the connection to my cPanel account"get_account_summary
  • "What domains and subdomains are on this hosting account?"list_domains
  • "Show me the DNS records for example.com"list_dns_records
  • "Add an A record for shop.example.com pointing to 1.2.3.4"add_dns_record
  • "Create a mailbox contact@example.com"create_email
  • "Create a MySQL database and user for my new app, then grant privileges"create_database + create_database_user + grant_database_privileges
  • "List the files in public_html"list_files
  • "Read config/filesystems.php and fix this path"cpanel_uapi_call with module: "Fileman", function: "get_file_content" / save_file_content

Because tool calls map directly to UAPI modules, this is also useful for real migration/deployment workflows — e.g. moving a site to a new cPanel account, provisioning a database for a fresh app, or auditing DNS before a domain cutover.

Notes on Fileman

Only list_files (backed by Fileman::list_files) and, through the cpanel_uapi_call escape hatch, get_file_content / save_file_content are known to work reliably for reading and writing individual files. Bulk filesystem operations (extract_files, rename, mkdir, fileop, delete_files, ...) are not guaranteed to be available depending on your cPanel version/provider — test before relying on them, and prefer cPanel's File Manager UI for bulk moves, extraction, and deletion.

Security

  • Never commit your .env file (it's git-ignored by default).
  • Scope your cPanel API token as narrowly as your provider allows.
  • The cpanel_uapi_call tool can call any UAPI function available to your account — treat it with the same care as direct API/token access.

License

MIT

Keywords

mcp

FAQs

Package last updated on 24 Jul 2026

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts