ProxmoxMCP-Plus
MCP server for Proxmox VE: manage VMs, LXC, snapshots and backups from an agent with permission control and command approval
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- Manages live virtualization: VMs, LXC, snapshots, backups
- Requires a Proxmox API token with mutating permissions
- Native MCP over HTTP can be exposed without auth if misconfigured
Install
In your terminal, with SkillFoxx CLI
npx skillfoxx add mcp/proxmoxmcp-plusDetects the agents on your machine, checks the risk and pins the version.
Other ways to install
This entry is high risk, so there is no one-click install. Review the code and add the config by hand.
Run in a terminal
claude mcp add --transport stdio --env 'PROXMOX_HOST=<PROXMOX_HOST value>' --env 'PROXMOX_USER=<PROXMOX_USER value>' --env 'PROXMOX_TOKEN_NAME=<PROXMOX_TOKEN_NAME value>' --env 'PROXMOX_TOKEN_VALUE=<your PROXMOX_TOKEN_VALUE>' proxmox-mcp-plus -- uvx proxmox-mcp-plus==0.5.20Or add to the file .mcp.json, in the project
{
"mcpServers": {
"proxmox-mcp-plus": {
"command": "uvx",
"args": [
"proxmox-mcp-plus==0.5.20"
],
"env": {
"PROXMOX_HOST": "<PROXMOX_HOST value>",
"PROXMOX_USER": "<PROXMOX_USER value>",
"PROXMOX_TOKEN_NAME": "<PROXMOX_TOKEN_NAME value>",
"PROXMOX_TOKEN_VALUE": "<your PROXMOX_TOKEN_VALUE>"
}
}
}
}If the file already exists, add the server inside the mcpServers key.
Keys and settings
PROXMOX_MCP_CONFIGoptional- Optional path to a JSON config file. If set, file config is used before environment variable fallback.
PROXMOX_HOSTrequired- Hostname or IP address of the Proxmox VE API endpoint.
PROXMOX_USERrequired- Proxmox username with realm, for example root@pam.
PROXMOX_TOKEN_NAMErequired- Name of the Proxmox API token.
PROXMOX_TOKEN_VALUEsecret, required- Secret value of the Proxmox API token.
PROXMOX_PORToptional- Proxmox API port. Defaults to 8006.
PROXMOX_VERIFY_SSLoptional- Set to true to verify TLS certificates, or false for self-signed lab environments.
PROXMOX_DEV_MODEoptional- Set to true when using verify_ssl=false in a self-signed lab environment.
PROXMOX_SERVICEoptional- Proxmox service type. Defaults to PVE.
MCP_TOOL_ALLOWLISToptional- Optional comma-separated exact tool names to expose. Do not set together with MCP_TOOL_DENYLIST.
MCP_TOOL_DENYLISToptional- Optional comma-separated exact tool names to hide. Do not set together with MCP_TOOL_ALLOWLIST.
LOG_LEVELoptional- Server log verbosity. Defaults to INFO.
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file ~/.cursor/mcp.json, for all projects
{
"mcpServers": {
"proxmox-mcp-plus": {
"command": "uvx",
"args": [
"proxmox-mcp-plus==0.5.20"
],
"env": {
"PROXMOX_HOST": "<PROXMOX_HOST value>",
"PROXMOX_USER": "<PROXMOX_USER value>",
"PROXMOX_TOKEN_NAME": "<PROXMOX_TOKEN_NAME value>",
"PROXMOX_TOKEN_VALUE": "<your PROXMOX_TOKEN_VALUE>"
}
}
}
}If the file already exists, add the server inside the mcpServers key. For a single project, put the same block into .cursor/mcp.json.
Keys and settings
PROXMOX_MCP_CONFIGoptional- Optional path to a JSON config file. If set, file config is used before environment variable fallback.
PROXMOX_HOSTrequired- Hostname or IP address of the Proxmox VE API endpoint.
PROXMOX_USERrequired- Proxmox username with realm, for example root@pam.
PROXMOX_TOKEN_NAMErequired- Name of the Proxmox API token.
PROXMOX_TOKEN_VALUEsecret, required- Secret value of the Proxmox API token.
PROXMOX_PORToptional- Proxmox API port. Defaults to 8006.
PROXMOX_VERIFY_SSLoptional- Set to true to verify TLS certificates, or false for self-signed lab environments.
PROXMOX_DEV_MODEoptional- Set to true when using verify_ssl=false in a self-signed lab environment.
PROXMOX_SERVICEoptional- Proxmox service type. Defaults to PVE.
MCP_TOOL_ALLOWLISToptional- Optional comma-separated exact tool names to expose. Do not set together with MCP_TOOL_DENYLIST.
MCP_TOOL_DENYLISToptional- Optional comma-separated exact tool names to hide. Do not set together with MCP_TOOL_ALLOWLIST.
LOG_LEVELoptional- Server log verbosity. Defaults to INFO.
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Run in a terminal
code --add-mcp '{"name":"proxmox-mcp-plus","type":"stdio","command":"uvx","args":["proxmox-mcp-plus==0.5.20"],"env":{"PROXMOX_HOST":"<PROXMOX_HOST value>","PROXMOX_USER":"<PROXMOX_USER value>","PROXMOX_TOKEN_NAME":"<PROXMOX_TOKEN_NAME value>","PROXMOX_TOKEN_VALUE":"<your PROXMOX_TOKEN_VALUE>"}}'Or add to the file .vscode/mcp.json, in the project
{
"servers": {
"proxmox-mcp-plus": {
"type": "stdio",
"command": "uvx",
"args": [
"proxmox-mcp-plus==0.5.20"
],
"env": {
"PROXMOX_HOST": "<PROXMOX_HOST value>",
"PROXMOX_USER": "<PROXMOX_USER value>",
"PROXMOX_TOKEN_NAME": "<PROXMOX_TOKEN_NAME value>",
"PROXMOX_TOKEN_VALUE": "<your PROXMOX_TOKEN_VALUE>"
}
}
}
}If the file already exists, add the server inside the servers key.
Keys and settings
PROXMOX_MCP_CONFIGoptional- Optional path to a JSON config file. If set, file config is used before environment variable fallback.
PROXMOX_HOSTrequired- Hostname or IP address of the Proxmox VE API endpoint.
PROXMOX_USERrequired- Proxmox username with realm, for example root@pam.
PROXMOX_TOKEN_NAMErequired- Name of the Proxmox API token.
PROXMOX_TOKEN_VALUEsecret, required- Secret value of the Proxmox API token.
PROXMOX_PORToptional- Proxmox API port. Defaults to 8006.
PROXMOX_VERIFY_SSLoptional- Set to true to verify TLS certificates, or false for self-signed lab environments.
PROXMOX_DEV_MODEoptional- Set to true when using verify_ssl=false in a self-signed lab environment.
PROXMOX_SERVICEoptional- Proxmox service type. Defaults to PVE.
MCP_TOOL_ALLOWLISToptional- Optional comma-separated exact tool names to expose. Do not set together with MCP_TOOL_DENYLIST.
MCP_TOOL_DENYLISToptional- Optional comma-separated exact tool names to hide. Do not set together with MCP_TOOL_ALLOWLIST.
LOG_LEVELoptional- Server log verbosity. Defaults to INFO.
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Run in a terminal
codex mcp add proxmox-mcp-plus --env 'PROXMOX_HOST=<PROXMOX_HOST value>' --env 'PROXMOX_USER=<PROXMOX_USER value>' --env 'PROXMOX_TOKEN_NAME=<PROXMOX_TOKEN_NAME value>' --env 'PROXMOX_TOKEN_VALUE=<your PROXMOX_TOKEN_VALUE>' -- uvx proxmox-mcp-plus==0.5.20Or add to the file ~/.codex/config.toml, for all projects
[mcp_servers.proxmox-mcp-plus]
command = "uvx"
args = ["proxmox-mcp-plus==0.5.20"]
env = { PROXMOX_HOST = "<PROXMOX_HOST value>", PROXMOX_USER = "<PROXMOX_USER value>", PROXMOX_TOKEN_NAME = "<PROXMOX_TOKEN_NAME value>", PROXMOX_TOKEN_VALUE = "<your PROXMOX_TOKEN_VALUE>" }If the file already exists, append the block to the end.
Keys and settings
PROXMOX_MCP_CONFIGoptional- Optional path to a JSON config file. If set, file config is used before environment variable fallback.
PROXMOX_HOSTrequired- Hostname or IP address of the Proxmox VE API endpoint.
PROXMOX_USERrequired- Proxmox username with realm, for example root@pam.
PROXMOX_TOKEN_NAMErequired- Name of the Proxmox API token.
PROXMOX_TOKEN_VALUEsecret, required- Secret value of the Proxmox API token.
PROXMOX_PORToptional- Proxmox API port. Defaults to 8006.
PROXMOX_VERIFY_SSLoptional- Set to true to verify TLS certificates, or false for self-signed lab environments.
PROXMOX_DEV_MODEoptional- Set to true when using verify_ssl=false in a self-signed lab environment.
PROXMOX_SERVICEoptional- Proxmox service type. Defaults to PVE.
MCP_TOOL_ALLOWLISToptional- Optional comma-separated exact tool names to expose. Do not set together with MCP_TOOL_DENYLIST.
MCP_TOOL_DENYLISToptional- Optional comma-separated exact tool names to hide. Do not set together with MCP_TOOL_ALLOWLIST.
LOG_LEVELoptional- Server log verbosity. Defaults to INFO.
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Run in a terminal
gemini mcp add -s user -e 'PROXMOX_HOST=<PROXMOX_HOST value>' -e 'PROXMOX_USER=<PROXMOX_USER value>' -e 'PROXMOX_TOKEN_NAME=<PROXMOX_TOKEN_NAME value>' -e 'PROXMOX_TOKEN_VALUE=<your PROXMOX_TOKEN_VALUE>' proxmox-mcp-plus uvx proxmox-mcp-plus==0.5.20Or add to the file ~/.gemini/settings.json, for all projects
{
"mcpServers": {
"proxmox-mcp-plus": {
"command": "uvx",
"args": [
"proxmox-mcp-plus==0.5.20"
],
"env": {
"PROXMOX_HOST": "<PROXMOX_HOST value>",
"PROXMOX_USER": "<PROXMOX_USER value>",
"PROXMOX_TOKEN_NAME": "<PROXMOX_TOKEN_NAME value>",
"PROXMOX_TOKEN_VALUE": "<your PROXMOX_TOKEN_VALUE>"
}
}
}
}If the file already exists, add the server inside the mcpServers key.
Keys and settings
PROXMOX_MCP_CONFIGoptional- Optional path to a JSON config file. If set, file config is used before environment variable fallback.
PROXMOX_HOSTrequired- Hostname or IP address of the Proxmox VE API endpoint.
PROXMOX_USERrequired- Proxmox username with realm, for example root@pam.
PROXMOX_TOKEN_NAMErequired- Name of the Proxmox API token.
PROXMOX_TOKEN_VALUEsecret, required- Secret value of the Proxmox API token.
PROXMOX_PORToptional- Proxmox API port. Defaults to 8006.
PROXMOX_VERIFY_SSLoptional- Set to true to verify TLS certificates, or false for self-signed lab environments.
PROXMOX_DEV_MODEoptional- Set to true when using verify_ssl=false in a self-signed lab environment.
PROXMOX_SERVICEoptional- Proxmox service type. Defaults to PVE.
MCP_TOOL_ALLOWLISToptional- Optional comma-separated exact tool names to expose. Do not set together with MCP_TOOL_DENYLIST.
MCP_TOOL_DENYLISToptional- Optional comma-separated exact tool names to hide. Do not set together with MCP_TOOL_ALLOWLIST.
LOG_LEVELoptional- Server log verbosity. Defaults to INFO.
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file ~/.config/devin/mcp_config.json, for all projects
{
"mcpServers": {
"proxmox-mcp-plus": {
"command": "uvx",
"args": [
"proxmox-mcp-plus==0.5.20"
],
"env": {
"PROXMOX_HOST": "<PROXMOX_HOST value>",
"PROXMOX_USER": "<PROXMOX_USER value>",
"PROXMOX_TOKEN_NAME": "<PROXMOX_TOKEN_NAME value>",
"PROXMOX_TOKEN_VALUE": "<your PROXMOX_TOKEN_VALUE>"
}
}
}
}If the file already exists, add the server inside the mcpServers key. Legacy Cascade keeps the MCP config in ~/.codeium/windsurf/mcp_config.json.
Keys and settings
PROXMOX_MCP_CONFIGoptional- Optional path to a JSON config file. If set, file config is used before environment variable fallback.
PROXMOX_HOSTrequired- Hostname or IP address of the Proxmox VE API endpoint.
PROXMOX_USERrequired- Proxmox username with realm, for example root@pam.
PROXMOX_TOKEN_NAMErequired- Name of the Proxmox API token.
PROXMOX_TOKEN_VALUEsecret, required- Secret value of the Proxmox API token.
PROXMOX_PORToptional- Proxmox API port. Defaults to 8006.
PROXMOX_VERIFY_SSLoptional- Set to true to verify TLS certificates, or false for self-signed lab environments.
PROXMOX_DEV_MODEoptional- Set to true when using verify_ssl=false in a self-signed lab environment.
PROXMOX_SERVICEoptional- Proxmox service type. Defaults to PVE.
MCP_TOOL_ALLOWLISToptional- Optional comma-separated exact tool names to expose. Do not set together with MCP_TOOL_DENYLIST.
MCP_TOOL_DENYLISToptional- Optional comma-separated exact tool names to hide. Do not set together with MCP_TOOL_ALLOWLIST.
LOG_LEVELoptional- Server log verbosity. Defaults to INFO.
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Formerly Windsurf.
Add to the file cline_mcp_settings.json, for all projects
{
"mcpServers": {
"proxmox-mcp-plus": {
"command": "uvx",
"args": [
"proxmox-mcp-plus==0.5.20"
],
"env": {
"PROXMOX_HOST": "<PROXMOX_HOST value>",
"PROXMOX_USER": "<PROXMOX_USER value>",
"PROXMOX_TOKEN_NAME": "<PROXMOX_TOKEN_NAME value>",
"PROXMOX_TOKEN_VALUE": "<your PROXMOX_TOKEN_VALUE>"
}
}
}
}If the file already exists, add the server inside the mcpServers key. Open the settings file in Cline: MCP Servers tab, Configure MCP Servers.
Keys and settings
PROXMOX_MCP_CONFIGoptional- Optional path to a JSON config file. If set, file config is used before environment variable fallback.
PROXMOX_HOSTrequired- Hostname or IP address of the Proxmox VE API endpoint.
PROXMOX_USERrequired- Proxmox username with realm, for example root@pam.
PROXMOX_TOKEN_NAMErequired- Name of the Proxmox API token.
PROXMOX_TOKEN_VALUEsecret, required- Secret value of the Proxmox API token.
PROXMOX_PORToptional- Proxmox API port. Defaults to 8006.
PROXMOX_VERIFY_SSLoptional- Set to true to verify TLS certificates, or false for self-signed lab environments.
PROXMOX_DEV_MODEoptional- Set to true when using verify_ssl=false in a self-signed lab environment.
PROXMOX_SERVICEoptional- Proxmox service type. Defaults to PVE.
MCP_TOOL_ALLOWLISToptional- Optional comma-separated exact tool names to expose. Do not set together with MCP_TOOL_DENYLIST.
MCP_TOOL_DENYLISToptional- Optional comma-separated exact tool names to hide. Do not set together with MCP_TOOL_ALLOWLIST.
LOG_LEVELoptional- Server log verbosity. Defaults to INFO.
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file .roo/mcp.json, in the project
{
"mcpServers": {
"proxmox-mcp-plus": {
"command": "uvx",
"args": [
"proxmox-mcp-plus==0.5.20"
],
"env": {
"PROXMOX_HOST": "<PROXMOX_HOST value>",
"PROXMOX_USER": "<PROXMOX_USER value>",
"PROXMOX_TOKEN_NAME": "<PROXMOX_TOKEN_NAME value>",
"PROXMOX_TOKEN_VALUE": "<your PROXMOX_TOKEN_VALUE>"
}
}
}
}If the file already exists, add the server inside the mcpServers key.
Keys and settings
PROXMOX_MCP_CONFIGoptional- Optional path to a JSON config file. If set, file config is used before environment variable fallback.
PROXMOX_HOSTrequired- Hostname or IP address of the Proxmox VE API endpoint.
PROXMOX_USERrequired- Proxmox username with realm, for example root@pam.
PROXMOX_TOKEN_NAMErequired- Name of the Proxmox API token.
PROXMOX_TOKEN_VALUEsecret, required- Secret value of the Proxmox API token.
PROXMOX_PORToptional- Proxmox API port. Defaults to 8006.
PROXMOX_VERIFY_SSLoptional- Set to true to verify TLS certificates, or false for self-signed lab environments.
PROXMOX_DEV_MODEoptional- Set to true when using verify_ssl=false in a self-signed lab environment.
PROXMOX_SERVICEoptional- Proxmox service type. Defaults to PVE.
MCP_TOOL_ALLOWLISToptional- Optional comma-separated exact tool names to expose. Do not set together with MCP_TOOL_DENYLIST.
MCP_TOOL_DENYLISToptional- Optional comma-separated exact tool names to hide. Do not set together with MCP_TOOL_ALLOWLIST.
LOG_LEVELoptional- Server log verbosity. Defaults to INFO.
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
A fork of Roo Code, same .roo folders.
Add to the file opencode.json, in the project
{
"mcp": {
"proxmox-mcp-plus": {
"type": "local",
"command": [
"uvx",
"proxmox-mcp-plus==0.5.20"
],
"environment": {
"PROXMOX_HOST": "<PROXMOX_HOST value>",
"PROXMOX_USER": "<PROXMOX_USER value>",
"PROXMOX_TOKEN_NAME": "<PROXMOX_TOKEN_NAME value>",
"PROXMOX_TOKEN_VALUE": "<your PROXMOX_TOKEN_VALUE>"
}
}
}
}If the file already exists, add the server inside the mcp key.
Keys and settings
PROXMOX_MCP_CONFIGoptional- Optional path to a JSON config file. If set, file config is used before environment variable fallback.
PROXMOX_HOSTrequired- Hostname or IP address of the Proxmox VE API endpoint.
PROXMOX_USERrequired- Proxmox username with realm, for example root@pam.
PROXMOX_TOKEN_NAMErequired- Name of the Proxmox API token.
PROXMOX_TOKEN_VALUEsecret, required- Secret value of the Proxmox API token.
PROXMOX_PORToptional- Proxmox API port. Defaults to 8006.
PROXMOX_VERIFY_SSLoptional- Set to true to verify TLS certificates, or false for self-signed lab environments.
PROXMOX_DEV_MODEoptional- Set to true when using verify_ssl=false in a self-signed lab environment.
PROXMOX_SERVICEoptional- Proxmox service type. Defaults to PVE.
MCP_TOOL_ALLOWLISToptional- Optional comma-separated exact tool names to expose. Do not set together with MCP_TOOL_DENYLIST.
MCP_TOOL_DENYLISToptional- Optional comma-separated exact tool names to hide. Do not set together with MCP_TOOL_ALLOWLIST.
LOG_LEVELoptional- Server log verbosity. Defaults to INFO.
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file ~/.config/zed/settings.json, for all projects
{
"context_servers": {
"proxmox-mcp-plus": {
"command": "uvx",
"args": [
"proxmox-mcp-plus==0.5.20"
],
"env": {
"PROXMOX_HOST": "<PROXMOX_HOST value>",
"PROXMOX_USER": "<PROXMOX_USER value>",
"PROXMOX_TOKEN_NAME": "<PROXMOX_TOKEN_NAME value>",
"PROXMOX_TOKEN_VALUE": "<your PROXMOX_TOKEN_VALUE>"
}
}
}
}If the file already exists, add the server inside the context_servers key.
Keys and settings
PROXMOX_MCP_CONFIGoptional- Optional path to a JSON config file. If set, file config is used before environment variable fallback.
PROXMOX_HOSTrequired- Hostname or IP address of the Proxmox VE API endpoint.
PROXMOX_USERrequired- Proxmox username with realm, for example root@pam.
PROXMOX_TOKEN_NAMErequired- Name of the Proxmox API token.
PROXMOX_TOKEN_VALUEsecret, required- Secret value of the Proxmox API token.
PROXMOX_PORToptional- Proxmox API port. Defaults to 8006.
PROXMOX_VERIFY_SSLoptional- Set to true to verify TLS certificates, or false for self-signed lab environments.
PROXMOX_DEV_MODEoptional- Set to true when using verify_ssl=false in a self-signed lab environment.
PROXMOX_SERVICEoptional- Proxmox service type. Defaults to PVE.
MCP_TOOL_ALLOWLISToptional- Optional comma-separated exact tool names to expose. Do not set together with MCP_TOOL_DENYLIST.
MCP_TOOL_DENYLISToptional- Optional comma-separated exact tool names to hide. Do not set together with MCP_TOOL_ALLOWLIST.
LOG_LEVELoptional- Server log verbosity. Defaults to INFO.
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file .codeassistant/mcp.json, in the project
{
"mcpServers": {
"proxmox-mcp-plus": {
"command": "uvx",
"args": [
"proxmox-mcp-plus==0.5.20"
],
"env": {
"PROXMOX_HOST": "<PROXMOX_HOST value>",
"PROXMOX_USER": "<PROXMOX_USER value>",
"PROXMOX_TOKEN_NAME": "<PROXMOX_TOKEN_NAME value>",
"PROXMOX_TOKEN_VALUE": "<your PROXMOX_TOKEN_VALUE>"
}
}
}
}If the file already exists, add the server inside the mcpServers key.
Keys and settings
PROXMOX_MCP_CONFIGoptional- Optional path to a JSON config file. If set, file config is used before environment variable fallback.
PROXMOX_HOSTrequired- Hostname or IP address of the Proxmox VE API endpoint.
PROXMOX_USERrequired- Proxmox username with realm, for example root@pam.
PROXMOX_TOKEN_NAMErequired- Name of the Proxmox API token.
PROXMOX_TOKEN_VALUEsecret, required- Secret value of the Proxmox API token.
PROXMOX_PORToptional- Proxmox API port. Defaults to 8006.
PROXMOX_VERIFY_SSLoptional- Set to true to verify TLS certificates, or false for self-signed lab environments.
PROXMOX_DEV_MODEoptional- Set to true when using verify_ssl=false in a self-signed lab environment.
PROXMOX_SERVICEoptional- Proxmox service type. Defaults to PVE.
MCP_TOOL_ALLOWLISToptional- Optional comma-separated exact tool names to expose. Do not set together with MCP_TOOL_DENYLIST.
MCP_TOOL_DENYLISToptional- Optional comma-separated exact tool names to hide. Do not set together with MCP_TOOL_ALLOWLIST.
LOG_LEVELoptional- Server log verbosity. Defaults to INFO.
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Install uvx proxmox-mcp-plus and add the server to your MCP client config. First copy proxmox-config/config.example.json to config.json and set the node address and Proxmox API token.
Other ways from the author
uvx proxmox-mcp-plusRun MCP stdio from PyPI without a system install. Requires uv.
This is third-party code. Review the repository files before installing.
What it does
The server connects Proxmox VE to agents and HTTP tooling through one control layer. It covers day-two operations: virtual machines and LXC, snapshots, backups, ISOs, storage and cluster node queries. Long-running tasks are tracked by stable job_ids tied to the Proxmox UPID, with status polling, retry, cancel and history. Two paths are available: native MCP for agents and an OpenAPI bridge for dashboards and no-code flows. It installs via uvx or pip from PyPI, or runs in docker.
Who it is for. For devops engineers and homelab owners who run virtualization on Proxmox VE.
Good fit when
- You want to manage VMs and LXC on Proxmox from an agent
- You need snapshots, backups and storage operations on demand
- You need to track long-running Proxmox tasks with retry and cancel
Not a fit when
- You have no Proxmox API token with the right permissions
- You do not want to give an agent access to live virtualization
- You need read-only viewing without the risk of mutating operations
Example request
Show Proxmox nodes and VMs and take a snapshot of vm 101 before the updateLimitations
You need access to Proxmox VE and an API token; the token's permissions define what the server can do. Configuration lives in proxmox-config/config.json with the node address and token. Native MCP over HTTP needs a separate MCP_API_KEY and an Authorization header on every request, otherwise access must be opened explicitly with an unsafe option. The server performs mutating operations against infrastructure.
How to disable. Remove the server entry from your MCP client config, stop the docker container if running, and revoke the Proxmox API token.
MCP
- Transport
- stdio, http, sse
- Authentication
- API key
| Environment variables | |
|---|---|
| MCP_API_KEY secret | Key for native MCP over HTTP, sent in the Authorization header and independent of Proxmox credentials |
| PROXMOX_MCP_MODE | Server run mode, for example mcp-http for native MCP over HTTP |
Security check
- Manages live virtualization: VMs, LXC, snapshots, backups
- Requires a Proxmox API token with mutating permissions
- Native MCP over HTTP can be exposed without auth if misconfigured
README in short
The README covers driving Proxmox VE from MCP clients, agents and OpenAPI tools with a security focus: Proxmox API tokens, OpenAPI bearer auth, command policy, approval tokens and TLS validation. It shows three run paths: MCP stdio via uvx proxmox-mcp-plus, native MCP over HTTP via docker compose, and the OpenAPI bridge. Long-running operations are tracked by job_id and Proxmox UPID. A code execution mode with three tools in an isolated sandbox is documented separately. MIT licensed.
FAQ
How does native MCP differ from OpenAPI?
Native MCP is for agents. The OpenAPI bridge exposes the same operations over HTTP for dashboards, scripts and no-code tools.
How is Proxmox access configured?
Through proxmox-config/config.json, where you set the node address, port and an API token with the needed permissions.
Related
An MCP server built into the Netdata agent: metrics, logs, alerts and live process, service and container data for an AI assistant
GitHub's official MCP server: code, issues, pull requests, Actions and security alerts straight from the agent
Agent Skills for Google products
Agent Skills for Google products and technologies
Official Google skill collection for working with Google Cloud, BigQuery, GKE, ads and analytics from an agent
AWS's official MCP server suite: docs, IaC, containers, serverless, databases, cost and monitoring