What is the Proxmox VE MCP server?
Manage Proxmox VE nodes, VMs, containers, storage and snapshots. Read-only by default.
How to install Proxmox VE
Copy-paste configuration for popular MCP clients.
PROXMOX_HOSTrequiredProxmox host IP or hostname.
PROXMOX_PORTProxmox API port.
PROXMOX_VERIFY_SSLVerify the TLS certificate. Proxmox self-signs by default.
PROXMOX_TIMEOUTSeconds to wait for each Proxmox API request.
PROXMOX_USERAPI user, including the realm.
PROXMOX_TOKEN_NAMEAPI token name. Use this plus PROXMOX_TOKEN_VALUE, or PROXMOX_PASSWORD.
PROXMOX_TOKEN_VALUEsecretAPI token secret.
PROXMOX_PASSWORDsecretPassword, used only when no API token is set.
PROXMOX_RISK_LEVELWhich tools exist: read-only, plus lifecycle, or everything.
PROXMOX_TOOLS_ALLOWComma-separated tool names to register, intersected with the risk level. Unset = all of them.
PROXMOX_REDACT_SECRETSMask cipassword and sshkeys in every response.
PROXMOX_MCP_TRANSPORTstdio (default) or streamable-http.
PROXMOX_MCP_HOSTHTTP bind address. Anything but loopback also needs PROXMOX_MCP_ALLOWED_HOSTS.
PROXMOX_MCP_PORTHTTP port.
PROXMOX_MCP_PATHStreamable HTTP endpoint path.
PROXMOX_MCP_JSON_RESPONSEAnswer with JSON instead of an SSE stream.
PROXMOX_MCP_ALLOWED_HOSTSComma-separated Host headers to accept over HTTP; '*' disables the check.
PROXMOX_MCP_ALLOWED_ORIGINSComma-separated browser origins allowed to call the endpoint. Empty = same-origin only.
SENTRY_DSNsecretOptional: report tool traces and errors to Sentry. Unset disables it.
Related MCP servers

Android Security Analyzer
MCP server for static security analysis of Android source code

MCP gateway/proxy: multiplexes tool calls across upstream MCP servers into one catalog.
App Store Connect for MCP clients: PPP pricing, subscriptions, TestFlight, reviews, reports & more

CiteNexus
Search scholarly sources, verify references, and export citations with traceable evidence.

ZulipChat MCP Server
Connect Claude, Cursor, and other AI assistants to Zulip with 60+ messaging, search, and analytics tools.
Open-source security layer for AI agents accessing clinical data: PHI redaction, audit trails, step-up auth, and tenant isolation.

