portainer-mcp

MCP.Pizza Chef: portainer

Portainer is the web dashboard many teams use to run Docker and Kubernetes, and this official add-on lets an assistant list your environments, inspect what is running, read logs, work with deployment setups, and pass instructions through to Docker or Kubernetes directly. Straight out of the box it can change things rather than only look, though a read-only mode exists and stored secret values are hidden by default. You need your own Portainer install, an access token from it, and a matching version number.

Coding
Data
Other

Use This MCP server To

Ask which containers are unhealthy right now Read the logs of a service that just failed See what is running across all my environments Restart a container without opening the dashboard Get a plain-English explanation of a deployment problem Confirm nothing was left running after a test

README

Portainer MCP

Official MCP server for Portainer, generated from the Portainer OpenAPI spec via FastMCP.

Overview

This MCP server exposes the Portainer REST API as MCP tools: list and inspect environments, manage GitOps workflows, troubleshoot Docker and Kubernetes resources. It also supports proxying requests to the underlying Docker and K8s APIs of each environment.

Match the MCP server's minor version to your Portainer instance's minor — e.g. MCP server 2.44.x with Portainer 2.44.x. See Version compatibility for details.

Getting started

The MCP server supports different deployment scenarios:

  • execute it locally via uvx
  • install it as a MCP bundle
  • deploy it as a container

Use the uvx approach or the MCP bundle to explore the MCP capabilities locally and deploy it inside your infrastructure as a container for a team based deployment setup.

Note

Before using the MCP, make sure to generate an API key in Portainer under My Account → Access tokens first as both paths need it.

MCP bundle (one-click install)

The recommended way to test the MCP server locally. Your client must support MCP bundles:

  1. Fetch the self-contained .mcpb bundle for your platform from the latest release
  2. Double-click to install
  3. Enter your Portainer URL and API key.

Single user (stdio via uvx)

The other way to test the MCP server locally. Runs as a stdio process on your machine and connects directly to the Portainer instance.

Note

uv must be installed and available on PATH. See the uv install docs.

Set PORTAINER_TLS_VERIFY=0 if your Portainer instance uses self-signed TLS certificates.

Register with Claude Code:

portainer-mcp FAQ

Do I need my own Portainer?
Yes. It talks to a Portainer instance you already run. Create an access token inside it under My Account, then Access tokens.
Is there a version trap to watch for?
Yes, and it catches people out. The add-on's version must match your Portainer's version, so 2.44 with 2.44, or things will not line up.
Can I use this to restart a container?
Yes. By default it acts as well as reads, including passing instructions straight through to Docker and Kubernetes.
Can I make it look but never touch?
Yes. There is a read-only setting, and you can switch off the direct Docker and Kubernetes pass-through entirely.
Will it leak my secrets into the chat?
Stored environment values are redacted by default, so passwords kept there are not handed to the assistant unless you deliberately turn that off.
How hard is the setup?
The easy route is a downloadable bundle you double-click, then type in your Portainer address and token. Sharing it with a team means running a container and sorting out certificates.
Should I put this on the public internet?
No. Portainer explicitly advises against it. Keep it inside your own network, even when there is a secure proxy in front.