{
  "markdown": "# mcp-uptime-kuma\n\nA [Model Context Protocol (MCP)](https://modelcontextprotocol.io/) server for [Uptime Kuma](https://github.com/louislam/uptime-kuma) *version 2*. Supports stdio and streamable HTTP transports.\n\n![GitHub Stars](https://img.shields.io/github/stars/DavidFuchs/mcp-uptime-kuma?style=flat)\n![GitHub Last Commit](https://img.shields.io/github/last-commit/DavidFuchs/mcp-uptime-kuma?style=flat)\n![GitHub Repo Size](https://img.shields.io/github/repo-size/DavidFuchs/mcp-uptime-kuma?style=flat)\n\n![GitHub Actions - npmjs](https://img.shields.io/github/actions/workflow/status/DavidFuchs/mcp-uptime-kuma/publish-npm.yml?style=flat&label=npmjs%20build&link=https://www.npmjs.com/package/@davidfuchs/mcp-uptime-kuma)\n![npmjs Version](https://img.shields.io/npm/v/%40davidfuchs%2Fmcp-uptime-kuma?style=flat&label=npmjs%20package%20version)\n![npmjs Downloads](https://img.shields.io/npm/d18m/%40davidfuchs%2Fmcp-uptime-kuma?style=flat&label=npmjs%20downloads&color=blue)\n\n![GitHub Actions - DockerHub](https://img.shields.io/github/actions/workflow/status/DavidFuchs/mcp-uptime-kuma/publish-docker.yml?style=flat&label=docker%20build&link=https://www.npmjs.com/package/@davidfuchs/mcp-uptime-kuma)\n![Docker Version](https://img.shields.io/docker/v/davidfuchs/mcp-uptime-kuma?style=flat&label=docker%20image%20version)\n![Docker Pulls](https://img.shields.io/docker/pulls/davidfuchs/mcp-uptime-kuma?style=flat)\n\n## Features\n\n- **Real-time Monitoring**: Access monitors, heartbeats, uptime, and responsiveness metrics via Socket.IO with instant status change notifications.\n- **Context-Friendly**: Returns only essential data by default to avoid overwhelming LLM context windows.\n- **Multiple Transports**: Supports stdio (local) and streamable HTTP (remote) transports.\n\n## Quick Start\n\n### Using npx (stdio transport)\n\nAdd this to your MCP client configuration:\n\n```json\n{\n  \"mcpServers\": {\n    \"uptime-kuma\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@davidfuchs/mcp-uptime-kuma\"],\n      \"env\": {\n        \"UPTIME_KUMA_URL\": \"http://your-uptime-kuma-instance:3001\",\n        \"UPTIME_KUMA_USERNAME\": \"your_username\",\n        \"UPTIME_KUMA_PASSWORD\": \"your_password\"\n      }\n    }\n  }\n}\n```\n\n### Using Docker (streamable HTTP transport)\n\n**Option 1: Docker Run**\n\n```bash\ndocker run -d \\\n  --name mcp-uptime-kuma \\\n  -p 3000:3000 \\\n  -e UPTIME_KUMA_URL=http://your-uptime-kuma-instance:3001 \\\n  -e UPTIME_KUMA_USERNAME=your_username \\\n  -e UPTIME_KUMA_PASSWORD=your_password \\\n  davidfuchs/mcp-uptime-kuma:latest \\\n  -t streamable-http\n```\n\n**Option 2: Docker Compose**\n\nA [docker-compose.yml](docker-compose.yml) file is provided in the repository. Download it, configure your environment variables, and run:\n\n```bash\ndocker compose up -d\n```\n\nThen configure your MCP client to connect to the endpoint:\n\n```json\n{\n  \"mcpServers\": {\n    \"uptime-kuma\": {\n      \"url\": \"http://localhost:3000/mcp\"\n    }\n  }\n}\n```\n\nSee [Authentication Methods](#authentication-methods) for JWT token and anonymous authentication options.\n\n> **The endpoint above is unauthenticated.** Anyone who can reach port 3000 gets full\n> read/write control of your Uptime Kuma instance. See\n> [Securing the HTTP Endpoint](#securing-the-http-endpoint) before exposing it beyond localhost.\n\n## Example Conversation\n\n![MCP server answering questions about Uptime Kuma monitors](.github/images/screenshot-1.png)\n*Conversation in [LibreChat](https://github.com/danny-avila/LibreChat) where the `mcp-uptime-kuma` server is providing real-time information from Uptime Kuma.*\n\n## Available Tools\n\n### Monitors\n\n| Tool | Purpose |\n|------|---------|\n| `getMonitorSummary` | Get a quick overview of all monitors with their current status. Supports filtering. |\n| `listMonitors` | Get the full list of all monitors with configurations. Supports filtering. |\n| `listMonitorTypes` | Get all available monitor types supported by Uptime Kuma. |\n| `getMonitor` | Get detailed configuration for a specific monitor by ID. |\n| `createMonitor` | Create a new monitor (requires name and type at minimum). |\n| `updateMonitor` | Update an existing monitor's configuration. |\n| `deleteMonitor` | Permanently delete a monitor and all its heartbeat history. |\n| `pauseMonitor` | Pause a monitor to stop performing checks. |\n| `resumeMonitor` | Resume a paused monitor to restart checks. |\n\n### Heartbeats\n\n| Tool | Purpose |\n|------|---------|\n| `listHeartbeats` | Get status check history for all monitors. |\n| `getHeartbeats` | Get status check history for a specific monitor. |\n\n### Notifications\n\n| Tool | Purpose |\n|------|---------|\n| `listNotifications` | List all configured notification channels (Slack, Discord, email, webhooks, etc.). |\n| `addNotification` | Create a new notification channel. |\n| `updateNotification` | Update an existing notification channel. |\n| `deleteNotification` | Permanently delete a notification channel. |\n\n### Tags\n\n| Tool | Purpose |\n|------|---------|\n| `listTags` | List all tags defined in Uptime Kuma. |\n| `addTag` | Create a new tag that can be assigned to monitors. |\n| `deleteTag` | Permanently delete a tag (removes it from all monitors). |\n\n### Maintenance\n\n| Tool | Purpose |\n|------|---------|\n| `getMaintenanceWindows` | List all scheduled maintenance windows. |\n| `createMaintenance` | Schedule a new maintenance window. |\n\n### Status Pages & Settings\n\n| Tool | Purpose |\n|------|---------|\n| `listStatusPages` | List all configured status pages. |\n| `getSettings` | Get Uptime Kuma server settings. |\n\n### Filtering\n\n`getMonitorSummary` and `listMonitors` support filtering by:\n\n- **keywords**: Space-separated keywords for fuzzy matching against monitor pathNames\n- **type**: Monitor type(s), comma-separated (e.g., `\"http\"`, `\"http,ping,dns\"`)\n- **active**: Filter by active (`true`) or inactive (`false`) monitors\n- **maintenance**: Filter by maintenance mode status\n- **tags**: Tag name and optional value, comma-separated (e.g., `\"production\"`, `\"env=staging\"`)\n- **parentId**: Group monitor ID, returning that group's **direct** children. Pass `null` for top-level monitors (those with no parent). Not recursive — to walk deeper, use each child group's own `childrenIDs`.\n- **status** (getMonitorSummary only): Heartbeat status (`\"0\"`=DOWN, `\"1\"`=UP, `\"2\"`=PENDING, `\"3\"`=MAINTENANCE)\n\n**Examples:**\n```javascript\ngetMonitorSummary({ status: \"0\" })                     // All DOWN monitors\ngetMonitorSummary({ type: \"http\", maintenance: true }) // HTTP monitors in maintenance\ngetMonitorSummary({ parentId: 12, status: \"0\" })       // What's down inside group 12\nlistMonitors({ tags: \"production,region=us-east\" })    // Monitors with specific tags\nlistMonitors({ parentId: 12 })                         // Direct children of group 12\nlistMonitors({ parentId: null })                       // Top-level monitors only\n```\n\n## Authentication Methods\n\n### Anonymous Authentication\nIf authentication is disabled on your Uptime Kuma instance, only `UPTIME_KUMA_URL` is required.\n\n### Username/Password Authentication\n```\nUPTIME_KUMA_URL=http://your-instance:3001\nUPTIME_KUMA_USERNAME=your_username\nUPTIME_KUMA_PASSWORD=your_password\nUPTIME_KUMA_2FA_TOKEN=123456  # Optional, only if 2FA is enabled\n```\n\n### JWT Token Authentication\nRecommended for 2FA users. Takes precedence over username/password if both are provided.\n\n```\nUPTIME_KUMA_URL=http://your-instance:3001\nUPTIME_KUMA_JWT_TOKEN=your_jwt_token\n```\n\n#### Obtaining Your JWT Token\n\n**Using the CLI utility (recommended):**\n```bash\nnpx -p @davidfuchs/mcp-uptime-kuma mcp-uptime-kuma-get-jwt http://localhost:3001 admin mypassword\n```\n\n**Using Docker:**\n```bash\ndocker run --rm davidfuchs/mcp-uptime-kuma:latest get-jwt http://host.docker.internal:3001 admin mypassword\n```\n\n**From browser:** Open Developer Tools → Storage/Application → Local Storage → find `token` key.\n\n## Securing the HTTP Endpoint\n\nApplies to `-t streamable-http` only. The stdio transport has no listener to protect and\ntakes its credentials from the environment, as the MCP specification prescribes.\n\nAnyone who can reach `/mcp` has full read/write control of your Uptime Kuma instance,\nincluding deleting monitors. Two settings guard it, and both default to permissive so that\nupgrading cannot break an existing deployment - the server warns at startup in that state.\n\n| Variable | Default | Purpose |\n|----------|---------|---------|\n| `MCP_AUTH_TOKEN` | unset (no authentication) | Shared secret that callers must present as `Authorization: Bearer <token>`. Anything else gets `401`. |\n| `ALLOWED_ORIGIN` | `*` (no validation) | Comma-separated list of browser origins permitted to call `/mcp`. A request whose `Origin` is not listed gets `403`. Requests with no `Origin` header (every native MCP client) are always allowed. |\n| `HOST` | `0.0.0.0` | Address to bind. Set to `127.0.0.1` when running locally outside a container. |\n| `PORT` | `3000` | Port to listen on. |\n\n`/health` is deliberately left unauthenticated so container healthchecks and load balancer\nprobes keep working. It reports nothing but liveness.\n\n### Setting a token\n\nGenerate a high-entropy secret - this is a password, and it is compared in constant time,\nso length is the only thing protecting it:\n\n```bash\nopenssl rand -base64 32\n```\n\n```bash\ndocker run -d \\\n  --name mcp-uptime-kuma \\\n  -p 3000:3000 \\\n  -e UPTIME_KUMA_URL=http://your-uptime-kuma-instance:3001 \\\n  -e UPTIME_KUMA_JWT_TOKEN=your_jwt_token \\\n  -e MCP_AUTH_TOKEN=your_generated_secret \\\n  davidfuchs/mcp-uptime-kuma:latest \\\n  -t streamable-http\n```\n\nClients then send it as a header:\n\n```json\n{\n  \"mcpServers\": {\n    \"uptime-kuma\": {\n      \"url\": \"http://localhost:3000/mcp\",\n      \"headers\": {\n        \"Authorization\": \"Bearer your_generated_secret\"\n      }\n    }\n  }\n}\n```\n\n### Why `Origin` validation matters separately\n\nA shared secret stops anyone who cannot present it. It does not stop a website your browser\nalready trusts. Under a DNS rebinding attack a page on `evil.example` resolves its own\nhostname to `127.0.0.1`, so the browser treats requests to your local server as same-origin\n- no preflight happens and CORS never applies. The server comparing the `Origin` header it\nwas sent against a list of expected origins is the only check left standing, which is why\nthe MCP specification makes it a MUST rather than a SHOULD.\n\nIf you only use native clients, leaving `ALLOWED_ORIGIN` unset costs you nothing; those\nclients send no `Origin` header. If you use a browser-based client, list its origin:\n\n```\nALLOWED_ORIGIN=https://librechat.example.com,http://localhost:5173\n```\n\n## Credential Redaction\n\nRead tools return `***` in place of secrets rather than the values themselves.\n\nUptime Kuma's socket API returns configuration verbatim - its web UI masks credentials at\nrender time. That is fine for a browser and not fine for an MCP server, whose output lands\nin an LLM's context window and is then persisted in conversation transcripts, logs and\nsynced history. Asking \"what am I monitoring?\" should not write a live SMTP password or a\nthird-party API key into storage you may not control.\n\nWhat is withheld:\n\n| Tool | Withheld |\n|---|---|\n| `listNotifications` | everything in `config` except `type`/`name`/`isDefault`/`applyExisting`. The withheld field names are listed in `redactedConfigKeys` |\n| `listMonitors`, `getMonitor` | `pushToken`, `basic_auth_pass`, `bearer_token`, `oauth_client_secret`, `radiusPassword`, `radiusSecret`, `mqttPassword`, `rabbitmqPassword`, `tlsCert`/`tlsKey`/`tlsCa`, `databaseConnectionString`, `headers`, `grpcMetadata`, plus anything matching `/pass|secret|token|apikey|auth(oriz\\|entic)|bearer|credential|private.?key|jwt/i` |\n| `listDockerHosts` | `user:password@` inside a `dockerDaemon` URL |\n| `getHeartbeats`, `listHeartbeats` | any column Uptime Kuma returns beyond the declared heartbeat fields (e.g. `response`, which can carry a service's response body) is dropped, and `user:password@` inside a URL quoted in the status message is scrubbed |\n| `getSettings` | any secret-named field Uptime Kuma returns (e.g. `steamAPIKey`) |\n| `getMonitorSummary` | nothing - it returns no credentials to begin with |\n\n`hostname`, `port`, `url`, `authMethod`, `oauth_token_url`, `oauth_scopes` and usernames stay\nvisible: hiding useful configuration is how a redaction feature gets switched off.\n\nTo get the real values, either pass `includeSecrets: true` on the call:\n\n```\nlistNotifications({ includeSecrets: true })\n```\n\nor enable it globally:\n\n```\nUPTIME_KUMA_INCLUDE_SECRETS=true\n```\n\nThe per-call parameter wins over the environment variable in both directions, so a\npermissive deployment can still ask one call to redact.\n\n**Writing `***` back is safe.** `updateMonitor` and `updateNotification` restore the stored\nvalue when a field arrives as the marker, and report which fields they preserved. This\nmatters most for `updateNotification`: Uptime Kuma replaces the notification row rather than\nmerging it, so without this a read-edit-write round trip would replace a working password\nwith three asterisks. If there is no stored value to restore, the call fails rather than\nwriting a credential that looks set and cannot work.\n\n`updateDockerHost` gets the same protection for the credentials embedded in a `dockerDaemon`\nURL: a `http://***:***@host:2375` read back from `listDockerHosts` has its userinfo restored\nfrom the stored URL rather than persisted verbatim, so repointing a host without re-entering\nits credentials does not wipe them.\n\nThe MCP logging channel gets the same rule. The debug log for a live heartbeat reports the\nmonitored service's status message by length only (`msgLength=...`), never its content, since\nthat message can echo a target URL with an embedded `user:password@` or a slice of a response\nbody, and on the stdio transport those log notifications reach the client.\n\n## LibreChat Configuration\n\n**stdio transport:**\n```yaml\nmcpServers:\n  uptime-kuma:\n    command: npx\n    args: [\"-y\", \"@davidfuchs/mcp-uptime-kuma\"]\n    env:\n      UPTIME_KUMA_URL: \"http://your-instance:3001\"\n      UPTIME_KUMA_USERNAME: \"your_username\"\n      UPTIME_KUMA_PASSWORD: \"your_password\"\n    serverInstructions: true\n```\n\n**streamable HTTP transport:**\n\nUpdate the allowed domains to whatever domain you're using in the URL (e.g., `localhost` or `host.docker.internal` for Docker setups):\n\n```yaml\nmcpServers:\n  uptime-kuma:\n    type: streamable-http\n    url: \"http://mcp-uptime-kuma:3000/mcp\"\n    serverInstructions: true\n\nmcpSettings:\n  allowedDomains:\n    - 'mcp-uptime-kuma'\n```\n\n## Contributing\n\nFor development setup, building, testing, and project structure, see [CONTRIBUTING.md](CONTRIBUTING.md).\n\n## Learn More\n\n- [Uptime Kuma](https://github.com/louislam/uptime-kuma)\n- [Model Context Protocol Documentation](https://modelcontextprotocol.io/)\n- [MCP TypeScript SDK](https://www.npmjs.com/package/@modelcontextprotocol/sdk)\n- [MCP Specification](https://spec.modelcontextprotocol.io/)\n\n## Security\n\nTo report a vulnerability, please see [SECURITY.md](SECURITY.md).\n\n## Disclaimer\n\nThis is a personal, free, open-source side project provided \"as is\" under the\n[MIT License](LICENSE), without warranty of any kind. You install and run it\nyourself, and it connects to an Uptime Kuma instance that you control. The\nauthor is not responsible for any damage, data loss, downtime, or other\nconsequences arising from its use. Use at your own risk.\n\n## License\n\nLicensed under the [MIT License](LICENSE).\n",
  "bytes": 15446,
  "sha": "3adbb32ae73d3ae09c107c2892f23f601fcec19bd90fcc23635b57c5b04bd70d",
  "repo_slug": "davidfuchs/mcp-uptime-kuma",
  "fonte": "repo",
  "truncated": false,
  "api": "https://agentalog.com/api/listings/mcp_io_github_davidfuchs_mcp_uptime_kuma_269dd674/readme"
}