# cPanel MCP AI Agent Access (v138): Secure Setup and Audit

Source: https://srvscripts.com/guides/cpanel-mcp-ai-agent-access-138/
Updated: 2026-10-03
Publisher: srvScripts (https://srvscripts.com/)

The Model Context Protocol, MCP, is the interface that AI assistants such as desktop chat clients and coding agents use to call tools on external systems. cPanel & WHM 138, released in July 2026, added an MCP server to cPanel so that an authorised AI client can query and act on an account: list domains, read error logs, create email accounts, change PHP versions, and so on, within limits the administrator sets. For a hosting provider this is both a support opportunity and a new privileged interface that needs the same care as an API token. This guide covers turning it on, authorising a client, restricting its scope and auditing what it does.

In short: Enable MCP in WHM → Tweak Settings (AI section, 138 and later), add it to a dedicated feature list, then authorise the client from WHM → AI → MCP Clients or the matching cPanel widget, choosing a read-only permission set and an expiry.

**Short answer:** Enable MCP in WHM → Tweak Settings (AI section, 138 and later), add it to a dedicated feature list, then authorise the client from WHM → AI → MCP Clients or the matching cPanel widget, choosing a read-only permission set and an expiry. The client receives an account-scoped token, and every call it makes is written to `/usr/local/cpanel/logs/api_log` once API logging is on. Treat the authorisation exactly like an API token: name it, review it weekly and revoke it when unused.

## What the MCP integration exposes

The cPanel MCP server runs as part of cpsrvd and speaks MCP over HTTPS on the normal cPanel port. An AI client that has been authorised presents a token and receives a list of tools it may call. The tool set mirrors a subset of the UAPI: read-only functions such as listing domains, mail accounts, databases and SSL status; and a set of write actions that map to common tasks. Each write action can be allowed or denied per authorisation, and the client cannot escalate beyond the account it was authorised for.

This is account-scoped, not server-scoped. There is no MCP path to WHM functions in 138, and a client authorised for one account cannot see another. Given the run of cross-account vulnerabilities in 2026, that boundary is the one to watch; keep the server on a build that includes the September fixes before exposing any new interface.

## Enable the feature

MCP support is off by default. Enable it server-wide in WHM → Server Configuration → Tweak Settings, in the AI section introduced in 138, and then grant it through the feature list for the accounts that may use it. Confirm the option names on your build:

```
whmapi1 get_tweaksetting --output=json | grep -i mcp
whmapi1 get_featurelist_data featurelist=default | grep -i mcp
whmapi1 update_featurelist featurelist=ai-pilot mcp=1
```

As with Ask AI, use a dedicated feature list for early adopters rather than enabling the default list. The [Meridian and Ask AI guide](/guides/cpanel-meridian-ask-ai-nova/) covers the feature list mechanics.

## Authorise a client

WHM → AI → MCP Clients on 138 provides the widget for authorising an AI client on behalf of an account, and the same widget is in cPanel for account holders who have the feature. Authorising a client generates a token bound to that account and to a chosen permission set. The interface shows a connection string or configuration snippet that the user pastes into their AI client’s MCP settings; it includes the server URL, the account and the token.

Two choices matter at this step. First, the permission set: choose read-only for anything that is only meant to answer questions or diagnose problems, and add write actions individually only when there is a concrete need. Second, the expiry: set one. A token that never expires will still be valid after the customer has forgotten they created it.

From the shell, tokens are listed and revoked through the account’s API token functions, which the MCP integration builds on:

```
uapi --user=customer Tokens list --output=json
uapi --user=customer Tokens revoke name='mcp-desktop-client'
```

Token names are shown in the widget; use a naming convention that identifies the client and the person, so that revocation is unambiguous later.

## Audit what the agent does

Every MCP call is logged. The account-level record is in the cPanel session log for that user, and the server-level record is in `/usr/local/cpanel/logs/session_log` and `/usr/local/cpanel/logs/api_log` when API logging is enabled. Turn API logging on if it is not already:

```
whmapi1 set_tweaksetting key=api_log_enabled value=1
grep -i 'mcp' /usr/local/cpanel/logs/api_log | tail -n 20
```

Entries show the account, the tool name, the parameters and the result. Review them weekly for the pilot accounts, looking for write actions you did not expect and for high call volumes that suggest an automated loop rather than a person asking questions. WHM → AI → MCP Clients also shows last-used timestamps per token, which is the quickest way to find dormant authorisations to revoke.

Combine this with the ordinary controls: Host Access Control does not apply to MCP because it comes over the cPanel port, but cPHulk brute-force protection does, and two-factor authentication on the account is still required to create or modify authorisations.

## Restrict and revoke

To take a client’s write access away without breaking it, edit the authorisation in the widget and remove the write actions; the token remains valid for reads. To remove it entirely, revoke the token. To disable MCP for a group of customers, remove the feature from their feature list, which invalidates the tool listing on the next call. To disable it for the whole server, turn off the Tweak Setting; existing tokens stop working immediately.

## Verify

After authorising a test client, make a read call and a denied write call from the AI client, then confirm both appear in the log:

```
tail -n 50 /usr/local/cpanel/logs/api_log | grep -i mcp
uapi --user=customer Tokens list
```

The denied write should be logged with a permission error, which proves the scope is enforced. Then revoke the token and confirm the client can no longer connect.

## Common pitfall

The mistake to avoid is treating an MCP authorisation as less sensitive than an API token because it was created through a friendly widget. It is an API token. A customer who pastes the configuration into a shared or compromised AI client has handed over their account, and a client with write actions enabled can delete mail accounts or change PHP versions on instruction from whatever prompt it receives. Default to read-only, set expiries, name tokens clearly, and review the log. Keep MCP restricted to accounts whose owners understand what they are connecting.

## CPanel MCP AI agent at a glance

**Official documentation:** [cPanel & WHM documentation](https://docs.cpanel.net/), [Linux man pages](https://man7.org/linux/man-pages/).

**Related guides:** [Fix Imunify360 missing from the WHM interface (enable-plugin and other causes)](https://srvscripts.com/guides/fix-imunify360-missing-from-whm/) · [Locking down WHM: 2FA, cPHulk, Host Access Control and scoped API tokens](https://srvscripts.com/guides/lock-down-whm-2fa-cphulk-api-tokens/) · [Fix WordPress “cURL error 28: Failed to connect” caused by Imunify360 or CSF](https://srvscripts.com/guides/wordpress-curl-error-28-imunify360-csf/).

## Frequently asked questions

### Does cPanel MCP give an AI agent access to WHM or other accounts?

No. In version 138 the MCP server is account-scoped only: a client authorised for one cPanel account sees that account’s tools and nothing else, and there is no MCP path to WHM functions.

### How long should an MCP token for an AI client stay valid?

Set an expiry every time; a few weeks for a support engagement or a pilot is sensible, and the last-used timestamps in WHM → AI → MCP Clients show which tokens can be revoked early.

### Can I revoke an AI client’s write access without cutting it off completely?

Yes. Edit the authorisation in the MCP Clients widget and remove the write actions; the token stays valid for read-only tools, and revoking it entirely with `uapi Tokens revoke` remains available if needed.
