Atlas / MCP servers / trackline / Remnawave

RemnawaveSAFE

mcp/trackline/remnawave

MCP Server for Remnawave Panel

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
153 78r · 46w · 29d
Transport
stdio
License
—
Stars
98
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

English | Русский

MCP Server for Remnawave Panel

MCP server (Model Context Protocol) providing LLM clients (Claude Desktop, Cursor, Windsurf, etc.) with tools to manage a Remnawave VPN panel.

Version: 1.2.0 | Remnawave API: 2.7.4

Features

  • 153 tools — full management of users, nodes, hosts, subscriptions, squads, HWID, config profiles, inbounds, API tokens, billing, snippets, external squads, settings, subscription page configs, node plugins, IP control, and metadata
  • 3 resources — real-time panel stats, node status, health checks
  • 5 prompts — guided workflows for common tasks
  • Readonly mode — restrict to 69 read-only tools for safe monitoring
  • Caddy support — X-Api-Key header for panels behind Caddy with custom path
  • Type-safe — built on @remnawave/backend-contract for API route validation
  • stdio transport — works with Claude Desktop, Cursor, Windsurf, and any MCP-compatible client

Requirements

  • Node.js >= 22
  • Remnawave panel with API token (Settings > API Tokens)

Installation

git clone https://github.com/TrackLine/mcp-remnawave.git
cd mcp-remnawave
npm install
npm run build

Configuration

Create a .env file or pass environment variables:

REMNAWAVE_BASE_URL=https://vpn.example.com
REMNAWAVE_API_TOKEN=your-api-token-here

Caddy with Custom Path

If your Remnawave panel is deployed behind [Caddy with a custom pa

Read from source at commit 0cf8b5727d46OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add remnawave-mcp --env CF_ACCESS_CLIENT_SECRET=${CF_ACCESS_CLIENT_SECRET} --env REMNAWAVE_API_KEY=${REMNAWAVE_API_KEY} --env REMNAWAVE_API_TOKEN=${REMNAWAVE_API_TOKEN} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "remnawave-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "CF_ACCESS_CLIENT_SECRET": "${CF_ACCESS_CLIENT_SECRET}",
        "REMNAWAVE_API_KEY": "${REMNAWAVE_API_KEY}",
        "REMNAWAVE_API_TOKEN": "${REMNAWAVE_API_TOKEN}"
      }
    }
  }
}
03

Exposed tools (153)

78 read · 46 write · 29 destructive. Blast radius: 29 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
api_tokens_createwriteCreate a new API token
api_tokens_deletedestructiveDelete an API token
api_tokens_listreadList all API tokens
auth_statusreadCheck current authentication status with Remnawave panel
billing_history_createwriteCreate a billing history entry
billing_history_deletedestructiveDelete a billing history entry
billing_history_listreadList billing history
billing_node_createwriteCreate a billing node
billing_node_deletedestructiveDelete a billing node
billing_node_updatewriteUpdate a billing node
billing_nodes_listreadList all billing nodes
billing_provider_createwriteCreate a new billing provider
billing_provider_deletedestructiveDelete a billing provider
billing_provider_getreadGet a billing provider by UUID
billing_provider_updatewriteUpdate a billing provider
billing_providers_listreadList all infrastructure billing providers
config_profiles_createwriteCreate a new config profile
config_profiles_deletedestructiveDelete a config profile
config_profiles_getreadGet a config profile by UUID
config_profiles_get_computed_configreadGet computed configuration for a config profile
config_profiles_get_inboundsreadGet inbounds for a specific config profile
config_profiles_listreadList all config profiles
config_profiles_reorderreadReorder config profiles
config_profiles_updatewriteUpdate a config profile
external_squads_add_userswriteAdd users to an external squad
external_squads_createwriteCreate a new external squad
external_squads_deletedestructiveDelete an external squad
external_squads_getreadGet an external squad by UUID
external_squads_listreadList all external squads
external_squads_remove_usersdestructiveRemove users from an external squad
external_squads_reorderreadReorder external squads
external_squads_updatewriteUpdate an external squad
hosts_bulk_deletedestructiveBulk delete selected hosts
hosts_bulk_disablewriteBulk disable selected hosts
hosts_bulk_enablewriteBulk enable selected hosts
hosts_bulk_set_inboundwriteBulk set inbound for selected hosts
hosts_bulk_set_portwriteBulk set port for selected hosts
hosts_createwriteCreate a new host in Remnawave
hosts_deletedestructiveDelete a host from Remnawave
hosts_getreadGet a specific host by UUID
hosts_listreadList all Remnawave hosts
hosts_tags_listreadList all host tags
hosts_updatewriteUpdate an existing host
hwid_device_createwriteCreate a HWID device entry for a user
hwid_device_deletedestructiveDelete a specific HWID device
hwid_devices_delete_alldestructiveDelete all HWID devices for a user
hwid_devices_listreadList HWID devices for a specific user
hwid_devices_list_allreadList all HWID devices across all users
hwid_statsreadGet HWID device statistics
hwid_top_usersreadGet users with most HWID devices
inbounds_listreadList all inbounds from all config profiles
ip_control_drop_connectionsdestructiveDrop active connections by IP or user UUID on specific/all nodes
ip_control_fetch_ipsreadFetch active IPs for a user (async job)
ip_control_fetch_users_ipsreadFetch IPs for all users on a node (async job)
ip_control_get_fetch_ips_resultreadGet result of an IP fetch job
ip_control_get_fetch_users_ips_resultreadGet result of a users IP fetch job
keygen_getreadGenerate a new SECRET_KEY for node configuration
metadata_node_getreadGet metadata for a specific node
metadata_node_upsertwriteCreate or update metadata for a node
metadata_user_getreadGet metadata for a specific user
metadata_user_upsertwriteCreate or update metadata for a user
node_plugins_clonereadClone a node plugin
node_plugins_createwriteCreate a new node plugin
node_plugins_deletedestructiveDelete a node plugin
node_plugins_executewriteExecute a node plugin with a command on target nodes
node_plugins_getreadGet a node plugin by UUID
node_plugins_listreadList all node plugins
node_plugins_reorderreadReorder node plugins
node_plugins_torrent_reportsreadGet torrent blocker reports
node_plugins_torrent_statsreadGet torrent blocker statistics
node_plugins_torrent_truncatedestructiveTruncate all torrent blocker reports
node_plugins_updatewriteUpdate a node plugin
nodes_bulk_actionsdestructiveBulk actions on selected nodes (enable/disable/restart/reset traffic)
nodes_bulk_profile_modificationwriteBulk modify config profile for selected nodes
nodes_bulk_updatewriteBulk update properties for selected nodes
nodes_createwriteCreate a new node in Remnawave
nodes_deletedestructiveDelete a node from Remnawave
nodes_disablewriteDisable a node
nodes_enablewriteEnable a disabled node
nodes_getreadGet a specific node by UUID
nodes_listreadList all Remnawave nodes
nodes_reorderreadReorder nodes by providing an ordered array of node positions
nodes_reset_trafficdestructiveReset traffic counter for a node
nodes_restartwriteRestart a specific node
nodes_restart_allwriteRestart all nodes
nodes_tags_listreadList all node tags
nodes_updatewriteUpdate an existing node
settings_getreadGet Remnawave panel settings
settings_updatewriteUpdate Remnawave panel settings
snippets_createwriteCreate a new configuration snippet
snippets_deletedestructiveDelete a snippet by name
snippets_listreadList all configuration snippets
snippets_updatewriteUpdate an existing snippet
squads_accessible_nodesreadGet nodes accessible to a specific squad
squads_add_userswriteAdd users to an internal squad
squads_createwriteCreate a new internal squad
squads_deletedestructiveDelete an internal squad
squads_listreadList all internal squads
squads_remove_usersdestructiveRemove users from an internal squad
squads_updatewriteUpdate an internal squad
sub_page_configs_clonereadClone a subscription page configuration
sub_page_configs_createwriteCreate a subscription page configuration
sub_page_configs_deletedestructiveDelete a subscription page configuration
sub_page_configs_getreadGet a subscription page config by UUID
sub_page_configs_listreadList all subscription page configurations
sub_page_configs_reorderreadReorder subscription page configurations
sub_page_configs_updatewriteUpdate a subscription page configuration
subscription_inforeadGet subscription info by short UUID (public endpoint)
subscription_request_history_listreadList subscription request history
subscription_request_history_statsreadGet subscription request history statistics
subscriptions_get_by_short_uuidreadGet subscription details by short UUID
subscriptions_get_by_usernamereadGet subscription details by username
subscriptions_get_by_uuidreadGet subscription details by UUID
subscriptions_get_connection_keysreadGet connection keys for a subscription
subscriptions_get_raw_by_short_uuidreadGet raw subscription config by short UUID
subscriptions_get_subpage_configreadGet subscription page configuration
subscriptions_listreadList all subscriptions with pagination
system_bandwidth_statsreadGet bandwidth statistics
system_generate_x25519readGenerate X25519 key pair for VLESS Reality
system_healthreadCheck Remnawave panel health status
system_metadatareadGet Remnawave panel metadata and version information
system_nodes_metricsreadGet detailed node metrics
system_nodes_statisticsreadGet node statistics
system_srr_matcherreadTest subscription request routing rules
system_statsreadGet overall Remnawave panel statistics (users, nodes, traffic, memory, CPU)
system_stats_recapreadGet system statistics recap
users_bulk_all_extend_expirationreadExtend expiration date for ALL users
users_bulk_all_reset_trafficdestructiveReset traffic counters for ALL users
users_bulk_all_updatewriteUpdate ALL users at once
users_bulk_deletedestructiveBulk delete selected users
users_bulk_delete_by_statusdestructiveBulk delete users by status
users_bulk_extend_expirationreadBulk extend expiration date for selected users
users_bulk_reset_trafficdestructiveBulk reset traffic for selected users
users_bulk_revoke_subscriptiondestructiveBulk revoke subscriptions for selected users
users_bulk_updatewriteBulk update selected users
users_bulk_update_squadswriteBulk update squad assignments for selected users
users_createwriteCreate a new VPN user in Remnawave
users_deletedestructivePermanently delete a Remnawave user
users_disablewriteDisable a Remnawave user (block VPN access)
users_enablewriteEnable a disabled Remnawave user (restore VPN access)
users_getreadGet a specific Remnawave user by their UUID
users_get_by_emailreadGet a Remnawave user by their email
users_get_by_short_uuidreadGet a Remnawave user by their short UUID
users_get_by_subscription_uuidreadGet a Remnawave user by subscription UUID
users_get_by_tagreadGet Remnawave users by tag
users_get_by_telegram_idreadGet a Remnawave user by their Telegram ID
users_get_by_usernamereadGet a Remnawave user by their username
users_listreadList all Remnawave VPN users with pagination
users_reset_trafficdestructiveReset traffic counter for a Remnawave user
users_resolvereadSearch and resolve users by UUID, ID, short UUID, or username
users_revoke_subscriptiondestructiveRevoke subscription for a Remnawave user (generates new subscription link)
users_tags_listreadList all user tags
users_updatewriteUpdate an existing Remnawave user
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (1 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (3)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
api_tokens_delete, billing_history_delete, billing_node_delete, billing_provider_delete, config_profiles_delete, external_squads_delete, external_squads_remove_users, hosts_bulk_delete, hosts_delete,
Why it matters. 29 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, @remnawave/backend-contract, zod, @types/node, tsup, typescript
Why it matters. 6 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-07 · audit v0.4.1 · source sha 0cf8b5727d46full audit observations/trust-audit/mcp-server/trackline__remnawave.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-070cf8b5727d46SAFEB89first audit
06

Questions

What is the Remnawave MCP server?

MCP Server for Remnawave Panel

What tools does Remnawave expose?

153 in total: 78 read-only, 46 that write, and 29 that can delete or overwrite (api_tokens_delete, billing_history_delete, billing_node_delete, billing_provider_delete, config_profiles_delete). Every one is listed on this page with its risk.

Is Remnawave safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 29 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Remnawave need?

It reads CF_ACCESS_CLIENT_SECRET, REMNAWAVE_API_KEY and REMNAWAVE_API_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Remnawave run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as remnawave-mcp at 1.2.0.

How current is this page?

The grade is for one exact copy of the source (0cf8b5727d46), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement