marzban-mcp

MCPattesté
v0.3.0io.github.Ilmar7786UnknownMis à jour il y a 28 jnpmGitHub

Manage Marzban panels through the Model Context Protocol.

Fonctionne dans
ClaudeCursorCopilotGemini

Déduit des transports déclarés par cette annonce (stdio). Un client absent de cette liste n’est pas écarté pour autant — c’est simplement quelque chose que Forge ne peut pas confirmer.

Build attesté
Une attestation de provenance vérifiée lie cet artefact au dépôt indiqué. Personne n’a encore revendiqué l’annonce — cela prouve où le code a été construit, pas qui le soutient.
il y a 28 jDernière mise à jour
Nécessite 1 identifiant avant de pouvoir fonctionner
  • MARZBAN_PASSWORDClé d’APIobligatoire

    Marzban administrator password.

Déclaré par l’auteur dans le registre MCP officiel. Forge does not store, broker, or ever see these values — the config below is scaffolded with placeholders you fill in locally.

Paquet
Auteurio.github.Ilmar7786
LicenceUnknown
Version0.3.0
Sourcenpm+mcp-registry
Statut de confiance
A
85/100Fiable
✓Listé dans l’index Forge+10/10
✓Identité vérifiée · build attesté+20/20
—Signature de publication Ed25519+0/5
→ Incluse automatiquement quand l’éditeur exécute `forge publish`
—Vérification de domaine+0/5
→ Éditeur : hébergez /.well-known/forge.json sur la page d’accueil du paquet avec { "publisher": "<github-login>" }
✓npm Trusted Publishing (Sigstore)+5/5
—Correspondance de mainteneur npm+0/5
→ Éditeur : ajoutez le login GitHub vérifié aux mainteneurs du paquet npm (npm owner add <login>)
✓Analyse CVE · propre+30/30
✓Analyse statique · propre+20/20
Collez-le dans Claude Code, Cursor ou tout assistant d’IA pour combler toutes les lacunes
StatutIdentité vérifiée
ÉditeurNon vérifié
SignatureNon signé
Domaine—
Provenance✓ Vérifié par Sigstore · fa0f7da
Dépendances✓ 20 résolues+ · aucune vulnérable
Surface d’outils24 outils · 1 privilégiés
Analyse de sécurité✓ Proprev0.3.0 · il y a 4 jQuelle est l’efficacité de cette analyse ?
ÉvaluationsAucune
Indexé1 sept. 2026

La vérification confirme l’identité de l’éditeur (la propriété du dépôt), pas la sûreté du code. L’analyse de sécurité couvre les CVE connues et les scripts d’installation suspects.

Outils

24 outils · 1 privilégiés
Extrait statiquement du paquet publiév0.3.0 · 4d ago

Lu dans le code que npm livre réellement, au moment de l’analyse. Le paquet n’a jamais été exécuté. Les outils enregistrés dynamiquement à l’exécution, ou cachés dans du code empaqueté ou minifié, peuvent passer inaperçus — c’est donc un plancher de la surface d’outils, pas un recensement complet.

marzban_config_getReads the Xray core configuration. Defaults to a structural summary (inbound/outbound tags, ports, protocols, routing rule count) — the full config can be tens of KB and this is usually all that's needed. Pass `section` (e.g. "inbounds") for one key's raw JSON, or `section: "raw"` for the entire co…

Reads the Xray core configuration. Defaults to a structural summary (inbound/outbound tags, ports, protocols, routing rule count) — the full config can be tens of KB and this is usually all that's needed. Pass `section` (e.g. "inbounds") for one key's raw JSON, or `section: "raw"` for the entire co…

Aucun schéma d’entrée n’a été publié pour cet outil.

marzban_config_updateOverwrites the entire Xray core configuration and restarts the core — this is the single most disruptive operation on the whole panel, dropping every active connection while it restarts. Replaces the config wholesale, not a patch. Set `dryRun: true` first to preview the diff against the current con…

Overwrites the entire Xray core configuration and restarts the core — this is the single most disruptive operation on the whole panel, dropping every active connection while it restarts. Replaces the config wholesale, not a patch. Set `dryRun: true` first to preview the diff against the current con…

Aucun schéma d’entrée n’a été publié pour cet outil.

marzban_core_restartRestarts the Xray core and every connected node, dropping all active connections. Use marzban_config_update instead if the goal is to apply a config change — it restarts the core as part of applying, so a separate restart is rarely needed. Requires confirmation.

Restarts the Xray core and every connected node, dropping all active connections. Use marzban_config_update instead if the goal is to apply a config change — it restarts the core as part of applying, so a separate restart is rarely needed. Requires confirmation.

Aucun schéma d’entrée n’a été publié pour cet outil.

marzban_hosts_getLists proxy host settings grouped by inbound tag. Flags host fields (remark/address/host/sni/path) that reference an unknown `{VARIABLE}` template token — almost always a typo, since Marzban leaves unknown tokens un-substituted rather than erroring.

Lists proxy host settings grouped by inbound tag. Flags host fields (remark/address/host/sni/path) that reference an unknown `{VARIABLE}` template token — almost always a typo, since Marzban leaves unknown tokens un-substituted rather than erroring.

Aucun schéma d’entrée n’a été publié pour cet outil.

marzban_hosts_updateOverwrites the entire proxy host configuration (all inbound tags at once) — this replaces the whole map, not a per-tag patch, so include every tag you want to keep. May change subscription links/configs for affected users. Requires confirmation.

Overwrites the entire proxy host configuration (all inbound tags at once) — this replaces the whole map, not a per-tag patch, so include every tag you want to keep. May change subscription links/configs for affected users. Requires confirmation.

Aucun schéma d’entrée n’a été publié pour cet outil.

marzban_nodes_listLists all connected nodes with their status and Xray version, plus bandwidth usage (uplink/downlink) over the given period. `start`/`end` (ISO datetimes) narrow the usage window; omit both for all-time.

Lists all connected nodes with their status and Xray version, plus bandwidth usage (uplink/downlink) over the given period. `start`/`end` (ISO datetimes) narrow the usage window; omit both for all-time.

Aucun schéma d’entrée n’a été publié pour cet outil.

marzban_subscription_infoReads subscription status/usage/expiry using the token from a subscription URL (the same public, unauthenticated endpoint client apps use) — for diagnosing a broken subscription link without needing the username. For an admin-side lookup by username, use marzban_users_get instead.

Reads subscription status/usage/expiry using the token from a subscription URL (the same public, unauthenticated endpoint client apps use) — for diagnosing a broken subscription link without needing the username. For an admin-side lookup by username, use marzban_users_get instead.

Aucun schéma d’entrée n’a été publié pour cet outil.

marzban_users_revoke_subscriptionIssues a new subscription link for a user and invalidates the old one. Use when a link has leaked or needs rotating — not for routine renewals (use marzban_users_extend for those). Requires confirmation.

Issues a new subscription link for a user and invalidates the old one. Use when a link has leaked or needs rotating — not for routine renewals (use marzban_users_extend for those). Requires confirmation.

Aucun schéma d’entrée n’a été publié pour cet outil.

marzban_system_statsReports panel-wide stats: CPU/memory usage, user counts by status, and bandwidth totals/speeds, plus the Xray core version and whether it is currently running.

Reports panel-wide stats: CPU/memory usage, user counts by status, and bandwidth totals/speeds, plus the Xray core version and whether it is currently running.

Aucun schéma d’entrée n’a été publié pour cet outil.

marzban_system_inboundsLists configured inbound proxies grouped by protocol, with tag, network, TLS mode, and port for each. For the raw Xray inbound JSON (routing, stream settings, etc.) use marzban_config_get with section: "inbounds" instead.

Lists configured inbound proxies grouped by protocol, with tag, network, TLS mode, and port for each. For the raw Xray inbound JSON (routing, stream settings, etc.) use marzban_config_get with section: "inbounds" instead.

Aucun schéma d’entrée n’a été publié pour cet outil.

marzban_users_listLists users, optionally filtered by status or a search term (matches username/note). Paginated — default 25, max 100 per call; prefer `search` over paging through everyone. For one known username, use marzban_users_get instead.

Lists users, optionally filtered by status or a search term (matches username/note). Paginated — default 25, max 100 per call; prefer `search` over paging through everyone. For one known username, use marzban_users_get instead.

Aucun schéma d’entrée n’a été publié pour cet outil.

marzban_users_getFetches one user by username, with a computed summary: data left, days left, usage percent, and whether they are effectively expired (covers the case where status has not caught up with an already-past expire yet).

Fetches one user by username, with a computed summary: data left, days left, usage percent, and whether they are effectively expired (covers the case where status has not caught up with an already-past expire yet).

Aucun schéma d’entrée n’a été publié pour cet outil.

marzban_users_createCreates a new user. `dataLimit` accepts a human size ("10GB"), `expire` a relative duration ("30d") or absolute date — both default to unlimited when omitted. `templateId` fills dataLimit/inbounds/expire from a user template; any field also given explicitly overrides the template value.

Creates a new user. `dataLimit` accepts a human size ("10GB"), `expire` a relative duration ("30d") or absolute date — both default to unlimited when omitted. `templateId` fills dataLimit/inbounds/expire from a user template; any field also given explicitly overrides the template value.

Aucun schéma d’entrée n’a été publié pour cet outil.

marzban_users_updatePartially updates a user — only fields you provide are changed, everything else is left as-is. For status changes prefer marzban_users_activate/deactivate/hold (clearer intent, no need to know the raw status enum). For renewing an expiring/expired user prefer marzban_users_extend.

Partially updates a user — only fields you provide are changed, everything else is left as-is. For status changes prefer marzban_users_activate/deactivate/hold (clearer intent, no need to know the raw status enum). For renewing an expiring/expired user prefer marzban_users_extend.

Aucun schéma d’entrée n’a été publié pour cet outil.

marzban_users_activateSets a user's status to active.

Sets a user's status to active.

Aucun schéma d’entrée n’a été publié pour cet outil.

marzban_users_deactivateSets a user's status to disabled, immediately blocking their access without deleting them.

Sets a user's status to disabled, immediately blocking their access without deleting them.

Aucun schéma d’entrée n’a été publié pour cet outil.

marzban_users_holdSets a user's status to on_hold — inactive until their first connection, at which point the on-hold timer starts. Useful for provisioning an account ahead of time without starting its clock.

Sets a user's status to on_hold — inactive until their first connection, at which point the on-hold timer starts. Useful for provisioning an account ahead of time without starting its clock.

Aucun schéma d’entrée n’a été publié pour cet outil.

marzban_users_extendRenews a user: adds addDuration to their current expiration (or to now, if they have none or it already passed) and/or addData on top of their current data limit. If the user was expired or limited, status is moved back to active. Use this instead of marzban_users_update for renewals — it reads the…

Renews a user: adds addDuration to their current expiration (or to now, if they have none or it already passed) and/or addData on top of their current data limit. If the user was expired or limited, status is moved back to active. Use this instead of marzban_users_update for renewals — it reads the…

Aucun schéma d’entrée n’a été publié pour cet outil.

marzban_users_usageReports how much data a user has used: total, lifetime total, their current limit, and a breakdown by node. `start`/`end` (ISO datetimes) narrow the per-node breakdown to a period; omit both for all-time.

Reports how much data a user has used: total, lifetime total, their current limit, and a breakdown by node. `start`/`end` (ISO datetimes) narrow the per-node breakdown to a period; omit both for all-time.

Aucun schéma d’entrée n’a été publié pour cet outil.

marzban_users_deleteprivilégiéPermanently deletes a user, along with their subscription link and traffic history. Irreversible — requires confirmation. Prefer marzban_users_deactivate if you only need to block access without losing their data.

Permanently deletes a user, along with their subscription link and traffic history. Irreversible — requires confirmation. Prefer marzban_users_deactivate if you only need to block access without losing their data.

Aucun schéma d’entrée n’a été publié pour cet outil.

marzban_users_reset_trafficResets used traffic back to zero for one user, or for every user at once when `all: true`. Does not change data_limit or expire. Irreversible — requires confirmation; `all: true` affects every user on the panel in one call.

Resets used traffic back to zero for one user, or for every user at once when `all: true`. Does not change data_limit or expire. Irreversible — requires confirmation; `all: true` affects every user on the panel in one call.

Aucun schéma d’entrée n’a été publié pour cet outil.

expiring_users_auditFinds users whose subscription is expiring soon (or already expired/limited) and suggests next steps for each.

Finds users whose subscription is expiring soon (or already expired/limited) and suggests next steps for each.

Aucun schéma d’entrée n’a été publié pour cet outil.

node_diagnosticsInvestigates why a node might be unhealthy: connection status, Xray version, and recent bandwidth.

Investigates why a node might be unhealthy: connection status, Xray version, and recent bandwidth.

Aucun schéma d’entrée n’a été publié pour cet outil.

traffic_reportSummarizes bandwidth usage across the panel, nodes, and top users for a given period.

Summarizes bandwidth usage across the panel, nodes, and top users for a given period.

Aucun schéma d’entrée n’a été publié pour cet outil.

24 outils sur 24 ont publié une description.

Les noms et descriptions d’outils sont écrits par l’éditeur et affichés tels quels, comme du texte inerte. Ce sont les chaînes qu’un client MCP transmet à un modèle, alors Forge y recherche des motifs d’injection de prompt — tout constat apparaît avec l’analyse de sécurité ci-dessus. « Privilégié » est une correspondance de mot-clé sur le nom de l’outil, pas un audit de ce qu’il fait : un nom anodin peut tout de même tout faire.

À propos

Manage Marzban panels through the Model Context Protocol.

Mots-clés
mcp
Alternatives
Comparaison des surfaces d’outils…

Arbre de dépendances

Ce qu'une analyse Forge a résolu à partir des métadonnées npm le 2026-10-01 — résolution observée, et non une déclaration de l'éditeur.

20 paquets résolus · 3 directs · aucun porteur d'avis de sécurité La résolution s'arrête à la profondeur 4 et à 60 paquets.

L'exploration s'est arrêtée à la limite de profondeur 4. Tout ce qui se trouve en dessous n'a jamais été résolu.

Déclarées mais non résolues

9 dépendances déclarées ne sont jamais arrivées dans l'arbre. Elles manquent à la résolution de Forge, pas au paquet.

Non suivies : peerDependencies. Cet arbre ne couvre que les dépendances d'exécution ; ce qu'elles entraînent n'a jamais été résolu.