RemnawaveSAFE
MCP Server for Remnawave Panel
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
English | Русский
MCP Server for Remnawave Panel
MCP server (Model Context Protocol) providing LLM clients (Claude Desktop, Cursor, Windsurf, etc.) with tools to manage a Remnawave VPN panel.
Version: 1.2.0 | Remnawave API: 2.7.4
Features
- 153 tools — full management of users, nodes, hosts, subscriptions, squads, HWID, config profiles, inbounds, API tokens, billing, snippets, external squads, settings, subscription page configs, node plugins, IP control, and metadata
- 3 resources — real-time panel stats, node status, health checks
- 5 prompts — guided workflows for common tasks
- Readonly mode — restrict to 69 read-only tools for safe monitoring
- Caddy support —
X-Api-Keyheader for panels behind Caddy with custom path - Type-safe — built on @remnawave/backend-contract for API route validation
- stdio transport — works with Claude Desktop, Cursor, Windsurf, and any MCP-compatible client
Requirements
- Node.js >= 22
- Remnawave panel with API token (Settings > API Tokens)
Installation
git clone https://github.com/TrackLine/mcp-remnawave.git cd mcp-remnawave npm install npm run build
Configuration
Create a .env file or pass environment variables:
REMNAWAVE_BASE_URL=https://vpn.example.com REMNAWAVE_API_TOKEN=your-api-token-here
Caddy with Custom Path
If your Remnawave panel is deployed behind [Caddy with a custom pa
0cf8b5727d46OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add remnawave-mcp --env CF_ACCESS_CLIENT_SECRET=${CF_ACCESS_CLIENT_SECRET} --env REMNAWAVE_API_KEY=${REMNAWAVE_API_KEY} --env REMNAWAVE_API_TOKEN=${REMNAWAVE_API_TOKEN} -- npx -y [email protected]{
"mcpServers": {
"remnawave-mcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"CF_ACCESS_CLIENT_SECRET": "${CF_ACCESS_CLIENT_SECRET}",
"REMNAWAVE_API_KEY": "${REMNAWAVE_API_KEY}",
"REMNAWAVE_API_TOKEN": "${REMNAWAVE_API_TOKEN}"
}
}
}
}Exposed tools (153)
78 read · 46 write · 29 destructive. Blast radius: 29 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
api_tokens_create | write | Create a new API token |
api_tokens_delete | destructive | Delete an API token |
api_tokens_list | read | List all API tokens |
auth_status | read | Check current authentication status with Remnawave panel |
billing_history_create | write | Create a billing history entry |
billing_history_delete | destructive | Delete a billing history entry |
billing_history_list | read | List billing history |
billing_node_create | write | Create a billing node |
billing_node_delete | destructive | Delete a billing node |
billing_node_update | write | Update a billing node |
billing_nodes_list | read | List all billing nodes |
billing_provider_create | write | Create a new billing provider |
billing_provider_delete | destructive | Delete a billing provider |
billing_provider_get | read | Get a billing provider by UUID |
billing_provider_update | write | Update a billing provider |
billing_providers_list | read | List all infrastructure billing providers |
config_profiles_create | write | Create a new config profile |
config_profiles_delete | destructive | Delete a config profile |
config_profiles_get | read | Get a config profile by UUID |
config_profiles_get_computed_config | read | Get computed configuration for a config profile |
config_profiles_get_inbounds | read | Get inbounds for a specific config profile |
config_profiles_list | read | List all config profiles |
config_profiles_reorder | read | Reorder config profiles |
config_profiles_update | write | Update a config profile |
external_squads_add_users | write | Add users to an external squad |
external_squads_create | write | Create a new external squad |
external_squads_delete | destructive | Delete an external squad |
external_squads_get | read | Get an external squad by UUID |
external_squads_list | read | List all external squads |
external_squads_remove_users | destructive | Remove users from an external squad |
external_squads_reorder | read | Reorder external squads |
external_squads_update | write | Update an external squad |
hosts_bulk_delete | destructive | Bulk delete selected hosts |
hosts_bulk_disable | write | Bulk disable selected hosts |
hosts_bulk_enable | write | Bulk enable selected hosts |
hosts_bulk_set_inbound | write | Bulk set inbound for selected hosts |
hosts_bulk_set_port | write | Bulk set port for selected hosts |
hosts_create | write | Create a new host in Remnawave |
hosts_delete | destructive | Delete a host from Remnawave |
hosts_get | read | Get a specific host by UUID |
hosts_list | read | List all Remnawave hosts |
hosts_tags_list | read | List all host tags |
hosts_update | write | Update an existing host |
hwid_device_create | write | Create a HWID device entry for a user |
hwid_device_delete | destructive | Delete a specific HWID device |
hwid_devices_delete_all | destructive | Delete all HWID devices for a user |
hwid_devices_list | read | List HWID devices for a specific user |
hwid_devices_list_all | read | List all HWID devices across all users |
hwid_stats | read | Get HWID device statistics |
hwid_top_users | read | Get users with most HWID devices |
inbounds_list | read | List all inbounds from all config profiles |
ip_control_drop_connections | destructive | Drop active connections by IP or user UUID on specific/all nodes |
ip_control_fetch_ips | read | Fetch active IPs for a user (async job) |
ip_control_fetch_users_ips | read | Fetch IPs for all users on a node (async job) |
ip_control_get_fetch_ips_result | read | Get result of an IP fetch job |
ip_control_get_fetch_users_ips_result | read | Get result of a users IP fetch job |
keygen_get | read | Generate a new SECRET_KEY for node configuration |
metadata_node_get | read | Get metadata for a specific node |
metadata_node_upsert | write | Create or update metadata for a node |
metadata_user_get | read | Get metadata for a specific user |
metadata_user_upsert | write | Create or update metadata for a user |
node_plugins_clone | read | Clone a node plugin |
node_plugins_create | write | Create a new node plugin |
node_plugins_delete | destructive | Delete a node plugin |
node_plugins_execute | write | Execute a node plugin with a command on target nodes |
node_plugins_get | read | Get a node plugin by UUID |
node_plugins_list | read | List all node plugins |
node_plugins_reorder | read | Reorder node plugins |
node_plugins_torrent_reports | read | Get torrent blocker reports |
node_plugins_torrent_stats | read | Get torrent blocker statistics |
node_plugins_torrent_truncate | destructive | Truncate all torrent blocker reports |
node_plugins_update | write | Update a node plugin |
nodes_bulk_actions | destructive | Bulk actions on selected nodes (enable/disable/restart/reset traffic) |
nodes_bulk_profile_modification | write | Bulk modify config profile for selected nodes |
nodes_bulk_update | write | Bulk update properties for selected nodes |
nodes_create | write | Create a new node in Remnawave |
nodes_delete | destructive | Delete a node from Remnawave |
nodes_disable | write | Disable a node |
nodes_enable | write | Enable a disabled node |
nodes_get | read | Get a specific node by UUID |
nodes_list | read | List all Remnawave nodes |
nodes_reorder | read | Reorder nodes by providing an ordered array of node positions |
nodes_reset_traffic | destructive | Reset traffic counter for a node |
nodes_restart | write | Restart a specific node |
nodes_restart_all | write | Restart all nodes |
nodes_tags_list | read | List all node tags |
nodes_update | write | Update an existing node |
settings_get | read | Get Remnawave panel settings |
settings_update | write | Update Remnawave panel settings |
snippets_create | write | Create a new configuration snippet |
snippets_delete | destructive | Delete a snippet by name |
snippets_list | read | List all configuration snippets |
snippets_update | write | Update an existing snippet |
squads_accessible_nodes | read | Get nodes accessible to a specific squad |
squads_add_users | write | Add users to an internal squad |
squads_create | write | Create a new internal squad |
squads_delete | destructive | Delete an internal squad |
squads_list | read | List all internal squads |
squads_remove_users | destructive | Remove users from an internal squad |
squads_update | write | Update an internal squad |
sub_page_configs_clone | read | Clone a subscription page configuration |
sub_page_configs_create | write | Create a subscription page configuration |
sub_page_configs_delete | destructive | Delete a subscription page configuration |
sub_page_configs_get | read | Get a subscription page config by UUID |
sub_page_configs_list | read | List all subscription page configurations |
sub_page_configs_reorder | read | Reorder subscription page configurations |
sub_page_configs_update | write | Update a subscription page configuration |
subscription_info | read | Get subscription info by short UUID (public endpoint) |
subscription_request_history_list | read | List subscription request history |
subscription_request_history_stats | read | Get subscription request history statistics |
subscriptions_get_by_short_uuid | read | Get subscription details by short UUID |
subscriptions_get_by_username | read | Get subscription details by username |
subscriptions_get_by_uuid | read | Get subscription details by UUID |
subscriptions_get_connection_keys | read | Get connection keys for a subscription |
subscriptions_get_raw_by_short_uuid | read | Get raw subscription config by short UUID |
subscriptions_get_subpage_config | read | Get subscription page configuration |
subscriptions_list | read | List all subscriptions with pagination |
system_bandwidth_stats | read | Get bandwidth statistics |
system_generate_x25519 | read | Generate X25519 key pair for VLESS Reality |
system_health | read | Check Remnawave panel health status |
system_metadata | read | Get Remnawave panel metadata and version information |
system_nodes_metrics | read | Get detailed node metrics |
system_nodes_statistics | read | Get node statistics |
system_srr_matcher | read | Test subscription request routing rules |
system_stats | read | Get overall Remnawave panel statistics (users, nodes, traffic, memory, CPU) |
system_stats_recap | read | Get system statistics recap |
users_bulk_all_extend_expiration | read | Extend expiration date for ALL users |
users_bulk_all_reset_traffic | destructive | Reset traffic counters for ALL users |
users_bulk_all_update | write | Update ALL users at once |
users_bulk_delete | destructive | Bulk delete selected users |
users_bulk_delete_by_status | destructive | Bulk delete users by status |
users_bulk_extend_expiration | read | Bulk extend expiration date for selected users |
users_bulk_reset_traffic | destructive | Bulk reset traffic for selected users |
users_bulk_revoke_subscription | destructive | Bulk revoke subscriptions for selected users |
users_bulk_update | write | Bulk update selected users |
users_bulk_update_squads | write | Bulk update squad assignments for selected users |
users_create | write | Create a new VPN user in Remnawave |
users_delete | destructive | Permanently delete a Remnawave user |
users_disable | write | Disable a Remnawave user (block VPN access) |
users_enable | write | Enable a disabled Remnawave user (restore VPN access) |
users_get | read | Get a specific Remnawave user by their UUID |
users_get_by_email | read | Get a Remnawave user by their email |
users_get_by_short_uuid | read | Get a Remnawave user by their short UUID |
users_get_by_subscription_uuid | read | Get a Remnawave user by subscription UUID |
users_get_by_tag | read | Get Remnawave users by tag |
users_get_by_telegram_id | read | Get a Remnawave user by their Telegram ID |
users_get_by_username | read | Get a Remnawave user by their username |
users_list | read | List all Remnawave VPN users with pagination |
users_reset_traffic | destructive | Reset traffic counter for a Remnawave user |
users_resolve | read | Search and resolve users by UUID, ID, short UUID, or username |
users_revoke_subscription | destructive | Revoke subscription for a Remnawave user (generates new subscription link) |
users_tags_list | read | List all user tags |
users_update | write | Update an existing Remnawave user |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (3)
api_tokens_delete, billing_history_delete, billing_node_delete, billing_provider_delete, config_profiles_delete, external_squads_delete, external_squads_remove_users, hosts_bulk_delete, hosts_delete,
@modelcontextprotocol/sdk, @remnawave/backend-contract, zod, @types/node, tsup, typescript
Gates applied: no_behavioural_pass, no_license.
0cf8b5727d46full audit observations/trust-audit/mcp-server/trackline__remnawave.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 0cf8b5727d46 | SAFE | B | 89 | first audit |
Questions
What is the Remnawave MCP server?
MCP Server for Remnawave Panel
What tools does Remnawave expose?
153 in total: 78 read-only, 46 that write, and 29 that can delete or overwrite (api_tokens_delete, billing_history_delete, billing_node_delete, billing_provider_delete, config_profiles_delete). Every one is listed on this page with its risk.
Is Remnawave safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 29 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Remnawave need?
It reads CF_ACCESS_CLIENT_SECRET, REMNAWAVE_API_KEY and REMNAWAVE_API_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Remnawave run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as remnawave-mcp at 1.2.0.
How current is this page?
The grade is for one exact copy of the source (0cf8b5727d46), read on 2026-10-07. The repository is watched and re-audited when it changes.