NixiHost cPanel MCP

A hosted MCP server that passes commands from your AI assistant to your own cPanel account. No account data or tokens are stored here: every request carries your credentials and forgets them when it ends.

1. Create a cPanel API token

  1. Sign in to cPanel (the link is in your NixiHost welcome email, or https://YOUR-DOMAIN:2083).
  2. Open Security → Manage API Tokens → Create. Give it a name such as "mcp". Leave the expiry off unless you want to rotate it. Copy the token: cPanel shows it only once.
  3. In your AI client, store your cPanel USERNAME and the TOKEN as secrets (Cursor/Grok Bot plugin variables, or Claude Code header values). Do not paste the token into chat.
  4. Set X-Cpanel-Host to your website domain. The server works out which NixiHost cPanel machine hosts it. You can also use the server hostname from the welcome email.
  5. Run the account_info tool. It should return your cPanel username and home directory. If it fails, run setup again and follow the message.
  6. To revoke access later, delete the token in cPanel → Security → Manage API Tokens. Nothing needs to change on this server.

2. Find your cPanel host

Enter your website domain. If it is hosted on a nixihost.com server, the matching cPanel hostname is shown. You can use either value in your client config.

Result appears here.

3. Connect your client

Claude Code (one command, then run /mcp):

claude mcp add --transport http nixihost https://mcp.nixihost.com/mcp --header "Authorization: cpanel YOUR_CPANEL_USERNAME:YOUR_API_TOKEN" --header "X-Cpanel-Host: your-domain.com"

Cursor, Grok Bot, or any client that takes JSON (set the three values as secrets in the client, not in a file you commit):

{
  "mcpServers": {
    "nixihost-cpanel": {
      "url": "https://mcp.nixihost.com/mcp",
      "headers": {
        "Authorization": "cpanel YOUR_CPANEL_USERNAME:YOUR_API_TOKEN",
        "X-Cpanel-Host": "your-domain.com"
      }
    }
  }
}

Endpoint: https://mcp.nixihost.com/mcp (Streamable HTTP). Health: /health. Host lookup API: GET /setup?domain=example.com.

What it can do

Any cPanel UAPI function, bounded by what your API token is allowed to do. Known read-only functions run immediately: Backup/list_backups, DNS/has_local_authority, DNS/parse_zone, DomainInfo/domains_data, DomainInfo/list_domains, DomainInfo/single_domain_data, Email/get_default_email, Email/get_main_account_disk_usage, Email/get_pop_quota, Email/list_auto_responders, Email/list_domain_forwarders, Email/list_filters, Email/list_forwarders, Email/list_lists, Email/list_mxs, Email/list_pops, Email/list_pops_with_disk, EmailAuth/validate_current_dkims, EmailAuth/validate_current_ptrs, EmailAuth/validate_current_spfs, Features/has_feature, Features/list_features, Fileman/get_file_content, Fileman/get_file_information, Fileman/list_files, Ftp/list_ftp, Ftp/list_ftp_sessions, LangPHP/php_get_installed_versions, LangPHP/php_get_vhost_versions, LangPHP/php_ini_get_user_basic_directives, Locale/get_attributes, Mime/list_handlers, Mime/list_hotlinks, Mime/list_mime, Mime/list_redirects, Mysql/get_server_information, Mysql/list_databases, Mysql/list_routines, Mysql/list_users, NVData/get, Notifications/get_notifications_count, PasswdStrength/get_required_strength, Postgresql/list_databases, Postgresql/list_users, Quota/get_quota_info, ResourceUsage/get_usages, SSL/fetch_cert_info, SSL/installed_hosts, SSL/list_certs, SSL/list_csrs, SSL/list_keys, StatsBar/get_stats, Themes/list, Variables/get_server_information, Variables/get_user_information.

Every other function is treated as a change and your assistant must ask you first. Examples: Backup/fullbackup_to_homedir, DNS/mass_edit_zone, Email/add_auto_responder, Email/add_forwarder, Email/add_pop, Email/delete_auto_responder, Email/delete_forwarder, Email/delete_pop, Email/edit_pop_quota, Email/passwd_pop, Email/set_default_address, EmailAuth/enable_dkim, EmailAuth/install_spf_records, Fileman/save_file_content, Fileman/upload_files, Ftp/add_ftp, Ftp/delete_ftp, LangPHP/php_set_vhost_versions, Mime/add_redirect, Mime/delete_redirect, Mysql/create_database, Mysql/create_user, Mysql/delete_database, Mysql/delete_user, Mysql/revoke_access_to_database, Mysql/set_privileges_on_database, SSL/install_ssl, SSL/start_autossl_check, SubDomain/addsubdomain.

Never proxied: Batch, ExternalAuthentication, Session, Tokens, TwoFactorAuth (manage tokens, sessions and two-factor in cPanel itself). WHM, billing and tickets are out of scope. File access is confined to your account's home directory. Revoke access at any time by deleting the token in cPanel.