Uptime KumaCAUTION
A Model Context Protocol (MCP) server for Uptime Kuma version 2.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A Model Context Protocol (MCP) server for Uptime Kuma version 2. Supports stdio and streamable HTTP transports.
Features
- Real-time Monitoring: Access monitors, heartbeats, uptime, and responsiveness metrics via Socket.IO with instant status change notifications.
- Context-Friendly: Returns only essential data by default to avoid overwhelming LLM context windows.
- Multiple Transports: Supports stdio (local) and streamable HTTP (remote) transports.
Quick Start
Using npx (stdio transport)
Add this to your MCP client configuration:
{
"mcpServers": {
"uptime-kuma": {
"command": "npx",
"args": ["-y", "@davidfuchs/mcp-uptime-kuma@latest"],8eb97520463aOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-uptime-kuma --env UPTIME_KUMA_PASSWORD=${UPTIME_KUMA_PASSWORD} --env UPTIME_KUMA_2FA_TOKEN=${UPTIME_KUMA_2FA_TOKEN} --env UPTIME_KUMA_JWT_TOKEN=${UPTIME_KUMA_JWT_TOKEN} --env UPTIME_KUMA_HEADERS=${UPTIME_KUMA_HEADERS} -- npx -y @davidfuchs/[email protected]Exposed tools (31)
31 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
addDockerHost | read | |
addNotification | read | |
addTag | read | |
createMaintenance | read | |
createMonitor | read | |
createStatusPage | read | |
deleteDockerHost | read | |
deleteMonitor | read | |
deleteNotification | read | |
deleteStatusPage | read | |
deleteTag | read | |
getHeartbeats | read | |
getMaintenanceWindows | read | |
getMonitor | read | |
getMonitorSummary | read | |
getSettings | read | |
getStatusPage | read | |
listDockerHosts | read | |
listHeartbeats | read | |
listMonitorTypes | read | |
listMonitors | read | |
listNotifications | read | |
listStatusPages | read | |
listTags | read | |
pauseMonitor | read | |
resumeMonitor | read | |
testDockerHost | read | |
updateDockerHost | read | |
updateMonitor | read | |
updateNotification | read | |
updateStatusPage | read |
Trust audit
CAUTIONgrade B · trust 85/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (2 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (13)
console.log(`Usage: mcp-uptime-kuma-get-jwt <url> <username> <password> [2fa-token]
const API_KEY = 'zz-integration-header-key';
const TOKEN = 'correct-horse-battery-staple';
.env.test.example
const serverPath = join(__dirname, '../../src/index.ts');
import { normalizeAdvertisedSchema } from '../../src/server.js';import { UptimeKumaClient } from '../../src/uptime-kuma-client.js';import { UptimeKumaClient } from '../../src/uptime-kuma-client.js';import { UptimeKumaClient } from '../../src/uptime-kuma-client.js';return { url: `http://127.0.0.1:${port}`, firstRequest };['mcp-uptime-kuma-get-jwt', 'src/get-jwt.ts', ['http://127.0.0.1:1', 'admin', 'password']],
UPTIME_KUMA_URL: 'http://127.0.0.1:1',
@modelcontextprotocol/sdk, @types/cors, cors, dotenv, express, express-rate-limit, fuzzysort, node-cache
Gates applied: no_behavioural_pass.
8eb97520463afull audit observations/trust-audit/mcp-server/davidfuchs__uptime-kuma.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 8eb97520463a | CAUTION | B | 85 | first audit |
Questions
What is the Uptime Kuma MCP server?
A Model Context Protocol (MCP) server for Uptime Kuma version 2.
What tools does Uptime Kuma expose?
31 in total: 31 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Uptime Kuma safe to connect to an agent?
With care. The audit graded it B (85/100) and found 13 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Uptime Kuma need?
It reads MCP_AUTH_TOKEN, UPTIME_KUMA_2FA_TOKEN, UPTIME_KUMA_HEADERS, UPTIME_KUMA_INCLUDE_SECRETS, UPTIME_KUMA_JWT_TOKEN and UPTIME_KUMA_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Uptime Kuma run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @davidfuchs/mcp-uptime-kuma at 0.0.0-dev.
How current is this page?
The grade is for one exact copy of the source (8eb97520463a), read on 2026-10-08. The repository is watched and re-audited when it changes.