marzban-mcp

MCPattested
v0.3.0io.github.Ilmar7786UnknownUpdated 29d agonpmGitHub

Manage Marzban panels through the Model Context Protocol.

Works in
ClaudeCursorCopilotGemini

Inferred from the transports this listing declares (stdio). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.

Attested build
A verified provenance attestation binds this artifact to the listed repository. Nobody has claimed the listing yet — this proves where the code was built, not who stands behind it.
29d agoLast update
Needs 1 credential before it runs
  • MARZBAN_PASSWORDAPI keyrequired

    Marzban administrator password.

Declared by the author in the official MCP registry. Forge does not store, broker, or ever see these values — the config below is scaffolded with placeholders you fill in locally.

Package
Authorio.github.Ilmar7786
LicenseUnknown
Version0.3.0
Sourcenpm+mcp-registry
Trust Status
A
85/100Trusted
✓Listed in Forge index+10/10
✓Identity verified · attested build+20/20
—Ed25519 publish signature+0/5
→ Included automatically when the publisher runs `forge publish`
—Domain verification+0/5
→ Publisher: host /.well-known/forge.json on the package homepage with { "publisher": "<github-login>" }
✓npm Trusted Publishing (Sigstore)+5/5
—npm maintainer match+0/5
→ Publisher: add the verified GitHub login to the npm package's maintainers (npm owner add <login>)
✓CVE scan · clean+30/30
✓Static analysis · clean+20/20
Paste into Claude Code, Cursor, or any AI assistant to fix all gaps
StatusIdentity verified
PublisherUnverified
SignatureUnsigned
Domain—
Provenance✓ Sigstore-verified · fa0f7da
Dependencies✓ 20 resolved+ · none vulnerable
Tool surface24 tools · 1 privileged
Security scan✓ Cleanv0.3.0 · 4d agoHow well does this scan work?
EvalsNone
IndexedSep 1, 2026

Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.

Tools

24 tools · 1 privileged
Statically extracted from the published packagev0.3.0 · 4d ago

Read out of the source npm actually ships, at scan time. The package was never executed. Tools registered dynamically at runtime, or hidden inside bundled or minified code, can be missed — so this is a floor on the tool surface, not a complete census of it.

marzban_config_getReads the Xray core configuration. Defaults to a structural summary (inbound/outbound tags, ports, protocols, routing rule count) — the full config can be tens of KB and this is usually all that's needed. Pass `section` (e.g. "inbounds") for one key's raw JSON, or `section: "raw"` for the entire co…

Reads the Xray core configuration. Defaults to a structural summary (inbound/outbound tags, ports, protocols, routing rule count) — the full config can be tens of KB and this is usually all that's needed. Pass `section` (e.g. "inbounds") for one key's raw JSON, or `section: "raw"` for the entire co…

No input schema was published for this tool.

marzban_config_updateOverwrites the entire Xray core configuration and restarts the core — this is the single most disruptive operation on the whole panel, dropping every active connection while it restarts. Replaces the config wholesale, not a patch. Set `dryRun: true` first to preview the diff against the current con…

Overwrites the entire Xray core configuration and restarts the core — this is the single most disruptive operation on the whole panel, dropping every active connection while it restarts. Replaces the config wholesale, not a patch. Set `dryRun: true` first to preview the diff against the current con…

No input schema was published for this tool.

marzban_core_restartRestarts the Xray core and every connected node, dropping all active connections. Use marzban_config_update instead if the goal is to apply a config change — it restarts the core as part of applying, so a separate restart is rarely needed. Requires confirmation.

Restarts the Xray core and every connected node, dropping all active connections. Use marzban_config_update instead if the goal is to apply a config change — it restarts the core as part of applying, so a separate restart is rarely needed. Requires confirmation.

No input schema was published for this tool.

marzban_hosts_getLists proxy host settings grouped by inbound tag. Flags host fields (remark/address/host/sni/path) that reference an unknown `{VARIABLE}` template token — almost always a typo, since Marzban leaves unknown tokens un-substituted rather than erroring.

Lists proxy host settings grouped by inbound tag. Flags host fields (remark/address/host/sni/path) that reference an unknown `{VARIABLE}` template token — almost always a typo, since Marzban leaves unknown tokens un-substituted rather than erroring.

No input schema was published for this tool.

marzban_hosts_updateOverwrites the entire proxy host configuration (all inbound tags at once) — this replaces the whole map, not a per-tag patch, so include every tag you want to keep. May change subscription links/configs for affected users. Requires confirmation.

Overwrites the entire proxy host configuration (all inbound tags at once) — this replaces the whole map, not a per-tag patch, so include every tag you want to keep. May change subscription links/configs for affected users. Requires confirmation.

No input schema was published for this tool.

marzban_nodes_listLists all connected nodes with their status and Xray version, plus bandwidth usage (uplink/downlink) over the given period. `start`/`end` (ISO datetimes) narrow the usage window; omit both for all-time.

Lists all connected nodes with their status and Xray version, plus bandwidth usage (uplink/downlink) over the given period. `start`/`end` (ISO datetimes) narrow the usage window; omit both for all-time.

No input schema was published for this tool.

marzban_subscription_infoReads subscription status/usage/expiry using the token from a subscription URL (the same public, unauthenticated endpoint client apps use) — for diagnosing a broken subscription link without needing the username. For an admin-side lookup by username, use marzban_users_get instead.

Reads subscription status/usage/expiry using the token from a subscription URL (the same public, unauthenticated endpoint client apps use) — for diagnosing a broken subscription link without needing the username. For an admin-side lookup by username, use marzban_users_get instead.

No input schema was published for this tool.

marzban_users_revoke_subscriptionIssues a new subscription link for a user and invalidates the old one. Use when a link has leaked or needs rotating — not for routine renewals (use marzban_users_extend for those). Requires confirmation.

Issues a new subscription link for a user and invalidates the old one. Use when a link has leaked or needs rotating — not for routine renewals (use marzban_users_extend for those). Requires confirmation.

No input schema was published for this tool.

marzban_system_statsReports panel-wide stats: CPU/memory usage, user counts by status, and bandwidth totals/speeds, plus the Xray core version and whether it is currently running.

Reports panel-wide stats: CPU/memory usage, user counts by status, and bandwidth totals/speeds, plus the Xray core version and whether it is currently running.

No input schema was published for this tool.

marzban_system_inboundsLists configured inbound proxies grouped by protocol, with tag, network, TLS mode, and port for each. For the raw Xray inbound JSON (routing, stream settings, etc.) use marzban_config_get with section: "inbounds" instead.

Lists configured inbound proxies grouped by protocol, with tag, network, TLS mode, and port for each. For the raw Xray inbound JSON (routing, stream settings, etc.) use marzban_config_get with section: "inbounds" instead.

No input schema was published for this tool.

marzban_users_listLists users, optionally filtered by status or a search term (matches username/note). Paginated — default 25, max 100 per call; prefer `search` over paging through everyone. For one known username, use marzban_users_get instead.

Lists users, optionally filtered by status or a search term (matches username/note). Paginated — default 25, max 100 per call; prefer `search` over paging through everyone. For one known username, use marzban_users_get instead.

No input schema was published for this tool.

marzban_users_getFetches one user by username, with a computed summary: data left, days left, usage percent, and whether they are effectively expired (covers the case where status has not caught up with an already-past expire yet).

Fetches one user by username, with a computed summary: data left, days left, usage percent, and whether they are effectively expired (covers the case where status has not caught up with an already-past expire yet).

No input schema was published for this tool.

marzban_users_createCreates a new user. `dataLimit` accepts a human size ("10GB"), `expire` a relative duration ("30d") or absolute date — both default to unlimited when omitted. `templateId` fills dataLimit/inbounds/expire from a user template; any field also given explicitly overrides the template value.

Creates a new user. `dataLimit` accepts a human size ("10GB"), `expire` a relative duration ("30d") or absolute date — both default to unlimited when omitted. `templateId` fills dataLimit/inbounds/expire from a user template; any field also given explicitly overrides the template value.

No input schema was published for this tool.

marzban_users_updatePartially updates a user — only fields you provide are changed, everything else is left as-is. For status changes prefer marzban_users_activate/deactivate/hold (clearer intent, no need to know the raw status enum). For renewing an expiring/expired user prefer marzban_users_extend.

Partially updates a user — only fields you provide are changed, everything else is left as-is. For status changes prefer marzban_users_activate/deactivate/hold (clearer intent, no need to know the raw status enum). For renewing an expiring/expired user prefer marzban_users_extend.

No input schema was published for this tool.

marzban_users_activateSets a user's status to active.

Sets a user's status to active.

No input schema was published for this tool.

marzban_users_deactivateSets a user's status to disabled, immediately blocking their access without deleting them.

Sets a user's status to disabled, immediately blocking their access without deleting them.

No input schema was published for this tool.

marzban_users_holdSets a user's status to on_hold — inactive until their first connection, at which point the on-hold timer starts. Useful for provisioning an account ahead of time without starting its clock.

Sets a user's status to on_hold — inactive until their first connection, at which point the on-hold timer starts. Useful for provisioning an account ahead of time without starting its clock.

No input schema was published for this tool.

marzban_users_extendRenews a user: adds addDuration to their current expiration (or to now, if they have none or it already passed) and/or addData on top of their current data limit. If the user was expired or limited, status is moved back to active. Use this instead of marzban_users_update for renewals — it reads the…

Renews a user: adds addDuration to their current expiration (or to now, if they have none or it already passed) and/or addData on top of their current data limit. If the user was expired or limited, status is moved back to active. Use this instead of marzban_users_update for renewals — it reads the…

No input schema was published for this tool.

marzban_users_usageReports how much data a user has used: total, lifetime total, their current limit, and a breakdown by node. `start`/`end` (ISO datetimes) narrow the per-node breakdown to a period; omit both for all-time.

Reports how much data a user has used: total, lifetime total, their current limit, and a breakdown by node. `start`/`end` (ISO datetimes) narrow the per-node breakdown to a period; omit both for all-time.

No input schema was published for this tool.

marzban_users_deleteprivilegedPermanently deletes a user, along with their subscription link and traffic history. Irreversible — requires confirmation. Prefer marzban_users_deactivate if you only need to block access without losing their data.

Permanently deletes a user, along with their subscription link and traffic history. Irreversible — requires confirmation. Prefer marzban_users_deactivate if you only need to block access without losing their data.

No input schema was published for this tool.

marzban_users_reset_trafficResets used traffic back to zero for one user, or for every user at once when `all: true`. Does not change data_limit or expire. Irreversible — requires confirmation; `all: true` affects every user on the panel in one call.

Resets used traffic back to zero for one user, or for every user at once when `all: true`. Does not change data_limit or expire. Irreversible — requires confirmation; `all: true` affects every user on the panel in one call.

No input schema was published for this tool.

expiring_users_auditFinds users whose subscription is expiring soon (or already expired/limited) and suggests next steps for each.

Finds users whose subscription is expiring soon (or already expired/limited) and suggests next steps for each.

No input schema was published for this tool.

node_diagnosticsInvestigates why a node might be unhealthy: connection status, Xray version, and recent bandwidth.

Investigates why a node might be unhealthy: connection status, Xray version, and recent bandwidth.

No input schema was published for this tool.

traffic_reportSummarizes bandwidth usage across the panel, nodes, and top users for a given period.

Summarizes bandwidth usage across the panel, nodes, and top users for a given period.

No input schema was published for this tool.

24 of 24 tools published a description.

Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.

About

Manage Marzban panels through the Model Context Protocol.

Keywords
mcp
Alternatives
Comparing tool surfaces…

Dependency tree

What one Forge scan resolved from npm metadata on 2026-10-01 — observed resolution, not a publisher declaration.

20 packages resolved · 3 direct · none carrying advisories Resolution stops at depth 4 and 60 packages.

The crawl stopped at the depth-4 limit. Anything below that level was never resolved.

Declared but not resolved

9 declared dependencies never landed in the tree. They are missing from Forge's resolution, not from the package.

Not followed: peerDependencies. This tree covers runtime dependencies only, so anything those pull in was never resolved.