“Give me a health check of the cluster.”
get_cluster_statusget_ceph_statuslist_node_updatesOpen source · MIT · Model Context Protocol
proxmox-mcp connects Claude and other AI assistants to Proxmox VE. Ask about VMs, containers, storage, backups and the cluster in plain English, and let the assistant make changes when you allow it.
docker pull ghcr.io/mattoddie/proxmox-mcplocal-zfs, which is 94% full, and three other busy guests share it.Ask anything
The assistant picks the right tools, runs them against the Proxmox API and explains what it found. No clicking through the web UI node by node.
“Give me a health check of the cluster.”
get_cluster_statusget_ceph_statuslist_node_updates“Which guests have no backup from this week? Back them up now.”
list_unbacked_guestsbackup_guests“Find snapshots older than 30 days and how much space they hold.”
list_all_snapshots“Clone the ubuntu-24 template as web-03 on pve3 and start it.”
clone_vmvm_power“Which storage fills up first, and do any disks have SMART warnings?”
list_storagelist_disks“Check free disk space inside the db VM.”
get_vmguest_execBroad coverage
Grouped into 19 toolsets you can switch on and off, so the assistant only sees what you need: 156 read, 107 write, 44 delete and 7 exec tools.
cluster15Cluster overview, nodes and guests at a glance, datacenter options, corosync config, metric servers and bulk guest actions.
nodes49Node status and statistics, services, network interfaces, DNS, time, updates and repositories, subscriptions, certificates and ACME, logs and node power.
vms20QEMU virtual machines: status, configuration, power, create, clone, disks, migration, templates, cloud-init and statistics.
containers16LXC containers: status, configuration, power, create, clone, volumes, migration, templates, interfaces and statistics.
agent13The QEMU guest agent: OS, network and filesystem information from inside VMs, filesystem freeze/trim, and (with exec enabled) running commands and reading/writing files.
snapshots7Snapshots of VMs and containers: list, create, roll back, describe and delete, plus a cluster-wide view of stale snapshots.
storage25Storage definitions and usage, volumes and content, ISO/template downloads, storage discovery, physical disks, SMART, ZFS and LVM.
backup16vzdump backup jobs, ad-hoc backups, backup listing and verification state, restores, pruning and guests without backups.
tasks5Proxmox tasks (UPIDs): list, inspect, read logs, wait for and stop them.
access33Users, groups, roles, ACLs, API tokens, authentication realms, effective permissions and two-factor authentication.
firewall21Firewall rules, options, aliases, IP sets and security groups at datacenter, node and guest level, plus the firewall log.
ha15High availability: status, HA resources, groups and rules, and HA-managed migration.
sdn18Software-defined networking: zones, VNets, subnets, controllers, IPAM and DNS, and applying pending SDN changes.
ceph27Ceph: health, OSDs, pools, monitors, managers, metadata servers, CephFS, flags and configuration.
pools5Resource pools and their members.
replication6Storage replication jobs, their status and logs.
notifications10Notification targets (sendmail, SMTP, Gotify, webhooks) and matchers.
hardware12PCI and USB devices, mediated devices, resource mappings, CPU models and QEMU capabilities.
raw1A raw API escape hatch for anything the other tools don't cover. It is limited to GET requests unless writes are enabled.
read write delete exec ·Full tool reference →
Safe by default
Tools that aren't allowed aren't registered at all. The assistant can't see them, so it can't call them or be talked into calling them.
156 tools, always on
list_guests · get_vm_stats · list_backups …107 tools with PROXMOX_ALLOW_WRITES=true
vm_power · clone_vm · migrate_vm · backup_guests …44 tools with PROXMOX_ALLOW_DELETES=true as well
delete_vm · delete_snapshot · delete_backup …7 tools with PROXMOX_ALLOW_EXEC=true as well
guest_exec · guest_write_file · vm_monitor_command …Works with your cluster
API token or username and password. Self-signed certificates work out of the box. Guests are found by VMID on whichever node they're on. Compatibility →
Works with your assistant
Run it once and share it, or start it per session with docker run -i. Long tasks are awaited and return their log. Client setup →
Quick start
In the Proxmox web UI, open Datacenter → Permissions → API Tokens → Add. Give the token's user the roles it needs, such as PVEAuditor for read-only.
curl -fsSLO https://raw.githubusercontent.com/mattoddie/proxmox-mcp/main/compose.yaml
curl -fsSL https://raw.githubusercontent.com/mattoddie/proxmox-mcp/main/example.env -o .env
# set PROXMOX_URL, PROXMOX_TOKEN_ID,
# PROXMOX_TOKEN_SECRET and MCP_AUTH_TOKEN in .env
docker compose up -dclaude mcp add --transport http proxmox \
http://<docker-host>:8080/mcp \
--header "Authorization: Bearer <token>"Then ask: “How's my cluster doing?”
Free, open source and MIT licensed. Contributions and compatibility reports are welcome.