statamic-mcp
Health Warn
- No license — Repository has no license file
- Description — Repository has a description
- Active repo — Last push 0 days ago
- Community trust — 22 GitHub stars
Code Pass
- Code scan — Scanned 12 files during light audit, no dangerous patterns found
Permissions Pass
- Permissions — No dangerous permissions requested
This MCP server provides AI assistants with structured access to Statamic CMS capabilities, enabling seamless management of blueprints, entries, assets, and user roles directly through an AI client.
Security Assessment
The tool exposes a web endpoint by default for AI interactions, necessitating Bearer token authentication. It inherently accesses highly sensitive CMS data and can perform destructive administrative actions, such as executing bulk deletes, modifying user roles, and managing system caches. The light code scan found no hardcoded secrets, dangerous code patterns, or unauthorized network requests. Because it grants deep, write-level access to your CMS and relies on how securely you configure your application tokens, the overall risk is rated as Medium.
Quality Assessment
The project is actively maintained, with its most recent push occurring just today. It has garnered 22 GitHub stars, indicating a growing and present level of community trust. However, the repository currently lacks a designated open-source license. This is a notable oversight, as the absence of a formal license means the exact legal terms for using, modifying, and distributing the code are technically undefined.
Verdict
Use with caution — the code is actively maintained and safe from hidden vulnerabilities, but you should be aware of the missing software license and ensure strict access controls are applied to the default web endpoint.
AI-powered development tools for Statamic CMS. Provides 100+ MCP tools for blueprints, entries, collections, and more.
Statamic MCP Server
A comprehensive MCP (Model Context Protocol) server for Statamic CMS v6 that provides AI assistants with structured access to Statamic's content management capabilities through a modern router-based architecture.
Requirements
- PHP 8.3+
- Laravel 12+
- Statamic 6.6+
- Laravel MCP ^0.6
Installation
# Install via Composer
composer require cboxdk/statamic-mcp
# Run the installation command
php artisan mcp:statamic:install
Recommended: Laravel Boost Integration
We recommend installing Laravel Boost alongside this addon for the best experience:
composer require laravel/boost --dev
Laravel Boost provides Laravel-specific tools (Eloquent, database, debugging), while Statamic MCP Server provides Statamic-specific tools (blueprints, collections, entries, assets). Together they give your AI assistant complete coverage.
Web MCP Endpoint
The web MCP endpoint is enabled by default after installation. To customize the path:
STATAMIC_MCP_WEB_PATH="/mcp/statamic"
Create a token in the CP dashboard (Tools > MCP > Tokens), then configure your AI client:
{
"mcpServers": {
"statamic": {
"url": "https://your-site.test/mcp/statamic",
"headers": {
"Authorization": "Bearer <YOUR_TOKEN>"
}
}
}
}
See Getting Started for detailed setup or AI Client Setup for client-specific instructions (Claude, Cursor, ChatGPT, Windsurf).
Features
The MCP server organizes Statamic's capabilities into domain routers with action-based routing:
Blueprint Management — statamic-blueprints
Actions: list, get, create, update, delete, scan, generate, types, validate
List, inspect, create, and modify blueprints. Generate TypeScript/PHP types from field definitions. Validate blueprints for conflicts and structural integrity.
Entry Management — statamic-entries
Dedicated entry operations with filtering, search, pagination, status filtering, merge strategies, and bulk operations.
Term Management — statamic-terms
Taxonomy term operations with slug conflict prevention, dependency validation, and relationship mapping.
Global Management — statamic-globals
Global set structure and values management with multi-site support, change tracking, and field-level filtering.
Structure Management — statamic-structures
Collection, taxonomy, navigation, and site configuration management.
Asset Management — statamic-assets
Asset container and file operations: upload, move, copy, rename, delete with metadata management.
User Management — statamic-users
User CRUD, role assignment, group management with RBAC support.
System Management — statamic-system
System info, health checks, cache management (clear/warm), and configuration access.
Content Workflow Facade — statamic-content-facade
High-level workflow operations: content_audit and cross_reference.
Agent Education Tools
statamic-system-discover— Intent-based tool discoverystatamic-system-schema— Tool schema inspection
Architecture
Router-Based Design
- 11 domain routers instead of 140+ individual tools
- Action-based routing: Each router handles multiple related operations
- Better AI performance: Fewer tools to choose from, clearer purposes
- Single file per domain: Easy maintenance and testing
Security
- Scoped API tokens with 21 granular permissions
- OAuth 2.1 authorization server with PKCE and dynamic client registration
- Bearer token + Basic Auth authentication
- Rate limiting per token
- Audit logging for all operations
- Path traversal protection
- PHPStan Level 8 strict typing
CP Dashboard
Vue 3 dashboard in the Statamic CP (Tools > MCP) with:
- Connect — Endpoint URL, client config snippets for Claude/Cursor/ChatGPT/Windsurf
- Tokens — Create, list, and revoke API tokens with scope selection
- Activity — Audit log of MCP tool calls
- Settings — System stats, endpoint status, rate limiting
Configuration
php artisan vendor:publish --tag=statamic-mcp-config
Key settings in config/statamic/mcp.php:
- Web endpoint (enabled, path, HTTPS enforcement)
- Authentication (scoped tokens, token lifetime, audit logging)
- Security (force web mode, audit logging)
- Rate limiting (max attempts per minute)
- Per-domain tool enablement
Development
# Run tests
./vendor/bin/pest
composer test
# Code formatting
./vendor/bin/pint
composer pint
# Static analysis (Level 8)
./vendor/bin/phpstan analyse
composer stan
# Full quality check
composer quality
Quality Standards
- PHPStan Level 8 with zero errors
- Laravel Pint formatting
- Strict types on all PHP files
- Comprehensive test suite
Example Usage
"What version of Statamic is installed?"
"Show me all blueprints and generate TypeScript types"
"Create a new blog entry with title and content fields"
"List all global sets and their current values"
"Clear all caches and show me the status"
"Analyze this Antlers template for performance issues"
Contributing
- Fork the repository
- Install:
composer install - Test:
./vendor/bin/pest - Quality:
composer quality - Submit pull request
License
MIT License
Reviews (0)
Sign in to leave a review.
Leave a reviewNo results found