LumisCloud cPanel MCP
A hosted MCP server that passes commands from your AI assistant to your own cPanel account. No account data or tokens are stored here: every request carries your credentials and forgets them when it ends.
1. Create a cPanel API token
- Sign in to cPanel (the link is in your LumisCloud welcome email, or https://YOUR-DOMAIN:2083). Your cPanel USERNAME is shown at the top right of cPanel; you will need it in a moment.
- Open Security → Manage API Tokens → Create (or use the direct link from the setup tool / landing page). Name it after the AI client, e.g. "claude".
- Scope the token before saving. Recommended: tick "Read-only" if the AI only needs to look things up; otherwise choose "Restricted" and tick only the features it should touch (Email, DNS, File Manager, MySQL, PHP...). Whitelist the IP 169.128.191.54 so the token only works through this MCP service. Set an expiry (90 days is sensible) and rotate it later.
- Copy the token: cPanel shows it only once. Store USERNAME and TOKEN as secrets in your AI client (Cursor/Grok Bot plugin variables, Claude Code header values, Codex env_http_headers or a keychain helper). Never paste the token into chat. The config generator on https://mcp.lumiscloud.com/ builds the exact config in your browser.
- Set X-Cpanel-Host to your website domain. The server works out which LumisCloud cPanel machine hosts it. The server hostname from the welcome email also works.
- Run the account_info tool. It returns your cPanel username, home directory and the scope of the tokens on the account. If it fails, run setup again and follow the message.
- To revoke access later, delete the token in cPanel → Security → Manage API Tokens. Nothing needs to change on this server.
2. Check your host and build your config
Enter your website domain, cPanel username and the token. Nothing leaves your browser when you build a config. Test connection sends the values to this server once, checks them against cPanel, reports the result, and forgets them.
Result appears here.
Claude Code (one command, then run /mcp):
Cursor: Add to Cursor VS Code: Add to VS Code
Cursor / Grok Bot / generic JSON:
Codex CLI (~/.codex/config.toml plus two environment variables in your shell profile):
Claude Desktop (claude_desktop_config.json, via the mcp-remote bridge):
Paste, save, restart the client, then ask it to run account_info. Reload this page to clear the fields.
3. Templates (if you prefer to fill in by hand)
Claude Code:
claude mcp add --transport http lumiscloud https://mcp.lumiscloud.com/mcp --header "Authorization: cpanel YOUR_CPANEL_USERNAME:YOUR_API_TOKEN" --header "X-Cpanel-Host: your-domain.com"
Cursor, Grok Bot, or any client that takes JSON:
{
"mcpServers": {
"lumiscloud-cpanel": {
"url": "https://mcp.lumiscloud.com/mcp",
"headers": {
"Authorization": "cpanel YOUR_CPANEL_USERNAME:YOUR_API_TOKEN",
"X-Cpanel-Host": "your-domain.com"
}
}
}
}
Codex CLI:
[mcp_servers.lumiscloud]
url = "https://mcp.lumiscloud.com/mcp"
# Header values come from environment variables, so the token never sits in config.toml.
# export LUMISCLOUD_AUTH="cpanel YOUR_CPANEL_USERNAME:YOUR_API_TOKEN" (put this in your shell profile or a secrets manager)
# export LUMISCLOUD_CPANEL_HOST="your-domain.com"
env_http_headers = { "Authorization" = "LUMISCLOUD_AUTH", "X-Cpanel-Host" = "LUMISCLOUD_CPANEL_HOST" }
# Alternative: http_headers_helper = "/path/to/script" that prints {"Authorization": "...", "X-Cpanel-Host": "..."} (for example from the macOS Keychain).
Endpoint: https://mcp.lumiscloud.com/mcp (Streamable HTTP). Health: /health. Host lookup API: GET /setup?domain=example.com. This service's IP for token whitelisting: 169.128.191.54.
What it can do
Any cPanel UAPI function, bounded by what your API token is allowed to do. Known read-only functions run immediately: Backup/list_backups, DNS/has_local_authority, DNS/parse_zone, DomainInfo/domains_data, DomainInfo/list_domains, DomainInfo/single_domain_data, Email/get_default_email, Email/get_main_account_disk_usage, Email/get_pop_quota, Email/list_auto_responders, Email/list_domain_forwarders, Email/list_filters, Email/list_forwarders, Email/list_lists, Email/list_mxs, Email/list_pops, Email/list_pops_with_disk, EmailAuth/validate_current_dkims, EmailAuth/validate_current_ptrs, EmailAuth/validate_current_spfs, Features/has_feature, Features/list_features, Fileman/get_file_content, Fileman/get_file_information, Fileman/list_files, Ftp/list_ftp, Ftp/list_ftp_sessions, LangPHP/php_get_installed_versions, LangPHP/php_get_vhost_versions, LangPHP/php_ini_get_user_basic_directives, Locale/get_attributes, Mime/list_handlers, Mime/list_hotlinks, Mime/list_mime, Mime/list_redirects, Mysql/get_server_information, Mysql/list_databases, Mysql/list_routines, Mysql/list_users, NVData/get, Notifications/get_notifications_count, PasswdStrength/get_required_strength, Postgresql/list_databases, Postgresql/list_users, Quota/get_quota_info, ResourceUsage/get_usages, SSL/fetch_cert_info, SSL/installed_hosts, SSL/list_certs, SSL/list_csrs, SSL/list_keys, StatsBar/get_stats, Themes/list, Variables/get_server_information, Variables/get_user_information.
Every other function is treated as a change and your assistant must ask you first. Examples: Backup/fullbackup_to_homedir, DNS/mass_edit_zone, Email/add_auto_responder, Email/add_forwarder, Email/add_pop, Email/delete_auto_responder, Email/delete_forwarder, Email/delete_pop, Email/edit_pop_quota, Email/passwd_pop, Email/set_default_address, EmailAuth/enable_dkim, EmailAuth/install_spf_records, Fileman/save_file_content, Fileman/upload_files, Ftp/add_ftp, Ftp/delete_ftp, LangPHP/php_set_vhost_versions, Mime/add_redirect, Mime/delete_redirect, Mysql/create_database, Mysql/create_user, Mysql/delete_database, Mysql/delete_user, Mysql/revoke_access_to_database, Mysql/set_privileges_on_database, SSL/install_ssl, SSL/start_autossl_check, SubDomain/addsubdomain.
Never proxied: Batch, ExternalAuthentication, Session, Tokens, TwoFactorAuth (manage tokens, sessions and two-factor in cPanel itself). WHM, billing and tickets are out of scope. File access is confined to your account's home directory. Revoke access at any time by deleting the token in cPanel.