Hetzner CloudSAFE
A Model Context Protocol (MCP) server for interacting with the Hetzner Cloud API. This server allows language models to manage Hetzner Cloud resources through structured functions.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A Model Context Protocol (MCP) server for interacting with the Hetzner Cloud API. This server allows language models to manage Hetzner Cloud resources through structured functions.
Features
- List, create, and manage Hetzner Cloud servers
- Create, attach, detach, and resize volumes
- Manage firewall rules and apply them to servers
- Create and manage SSH keys for secure server access
- View available images, server types, and locations
- Power on/off and reboot servers
- Simple, structured API for language model interaction
- Claude Code integration for managing Hetzner resources directly from Claude
Requirements
- Python 3.11+
- Hetzner Cloud API token
Installation
Method 1: Direct Installation
- Clone this repository:
git clone https://github.com/dkruyt/mcp-hetzner.git cd mcp-hetzner
- Install dependencies:
pip install -e .
- Create a
.envfile and add your Hetzner Cloud API token:
HCLOUD_TOKEN=your_hetzner_cloud_api_token_here
Method 2: Install as a Package
# Install directly from the repository pip install git+https://github.com/dkruyt/mcp-hetzner.git
After installing as a package, create a .env file in your working directory with your Hetzner Cloud API token.
Usage
Starting the Server
Option 1: Run the installed package:
# Using default stdio transport mcp-hetzner # Using SSE transport mcp-hetzner --transport sse # Setting a custom port mcp-hetzner --transport sse --port 8000
Option 2: Run as a module:
python -m mcp_hetzner # or python -m mcp_hetzner.server
The server supports two transport modes:
stdio(default): Standard I/O transport, typically used with Claude Codesse: Server-Sent Events transport, suitable for HTTP clients
By default, the server runs on localhost:8080. You can customize the host and port by:
- Setting the
MCP_HOSTandMCP_PORTenv
8d5571cea9c8OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-hetzner --env HCLOUD_TOKEN=${HCLOUD_TOKEN} -- uvx mcp-hetzner{
"mcpServers": {
"mcp-hetzner": {
"command": "uvx",
"args": [
"mcp-hetzner"
],
"env": {
"HCLOUD_TOKEN": "${HCLOUD_TOKEN}"
}
}
}
}Exposed tools (30)
17 read · 8 write · 5 destructive. Blast radius: 5 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
apply_firewall_to_resources | write | |
attach_volume | read | |
create_firewall | write | |
create_server | write | |
create_ssh_key | write | |
create_volume | write | |
delete_firewall | destructive | |
delete_server | destructive | |
delete_ssh_key | destructive | |
delete_volume | destructive | |
detach_volume | read | |
get_firewall | read | |
get_server | read | |
get_ssh_key | read | |
get_volume | read | |
list_firewalls | read | |
list_images | read | |
list_locations | read | |
list_server_types | read | |
list_servers | read | |
list_ssh_keys | read | |
list_volumes | read | |
power_off | read | |
power_on | read | |
reboot | read | |
remove_firewall_from_resources | destructive | |
resize_volume | read | |
set_firewall_rules | write | |
update_firewall | write | |
update_ssh_key | write |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (2)
delete_firewall, delete_server, delete_ssh_key, delete_volume, remove_firewall_from_resources
media/mcp-hetzner.gif
Gates applied: no_behavioural_pass.
8d5571cea9c8full audit observations/trust-audit/mcp-server/dkruyt__hetzner-cloud.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 8d5571cea9c8 | SAFE | B | 89 | first audit |
Questions
What is the Hetzner Cloud MCP server?
A Model Context Protocol (MCP) server for interacting with the Hetzner Cloud API. This server allows language models to manage Hetzner Cloud resources through structured functions.
What tools does Hetzner Cloud expose?
30 in total: 17 read-only, 8 that write, and 5 that can delete or overwrite (delete_firewall, delete_server, delete_ssh_key, delete_volume, remove_firewall_from_resources). Every one is listed on this page with its risk.
Is Hetzner Cloud safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 5 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Hetzner Cloud need?
It reads HCLOUD_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Hetzner Cloud run?
It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as mcp-hetzner.
How current is this page?
The grade is for one exact copy of the source (8d5571cea9c8), read on 2026-10-07. The repository is watched and re-audited when it changes.