Skip to content
Advertisement

Best MCP Servers for Home Lab and Self-Hosting

SumitSumit··11 min read
Home Assistant, Proxmox and Docker logos above the words MCP servers for your home lab

An AI agent that can see your home lab is genuinely useful. "Why is the NAS slow?" becomes a question it can answer by reading Grafana. "Snapshot every VM before I update Proxmox" becomes one sentence instead of ten clicks. MCP (Model Context Protocol) servers are what make that possible: each one gives Claude, Codex, opencode or any other agent a set of tools for one app.

It is also the riskiest place to give an agent access. A bad command on a coding project breaks a branch. A bad command on your hypervisor or firewall takes the house offline. So this list comes with the maintenance status of every server (checked on GitHub on September 26, 2026), whether it is official, and how to keep it read-only.

Quick picks
  • Safest start: Home Assistant's built-in MCP server and Grafana's official server. Both are official and can be limited to read or exposed-only access.
  • Containers: Portainer's official server or Docker's MCP Gateway. Anything with the Docker socket is effectively root on that host.
  • Proxmox has no official server. ProxmoxMCP-Plus is the best maintained community option, with read-only and approval policies.
  • TrueNAS has an official server, but it is labelled a research preview.
  • Skip Uptime Kuma for now: every MCP server for it is tiny or abandoned.
Rules before you connect anything
  • Start every server in read-only mode. Turn on write access one server at a time, only when you need it.
  • Create a dedicated API token per server with the smallest permissions the app allows. Never use your admin password.
  • Keep MCP servers on your LAN or behind Tailscale. Do not expose them to the internet.
  • Remember prompt injection: a log line, a container name or a web page can contain text that tries to steer the agent. Read-only access limits the damage.
  • Keep backups you can restore without the agent.

How to connect a home lab server

Most of these run locally with uvx (Python) or npx (Node), or as a Docker container, and talk to your app's API. In Claude Code:

claude mcp add grafana -e GRAFANA_URL=http://grafana.lan:3000 \
  -e GRAFANA_SERVICE_ACCOUNT_TOKEN=glsa_xxx -- uvx mcp-grafana --disable-write

The same command and environment variables go into Codex, Gemini CLI, opencode or Cursor config. See how to add MCP servers to Cursor, Codex, Gemini CLI and opencode for each client's format. New to self-hosting? Start with our list of home lab apps.

Smart home

01 / SMART HOME

Home Assistant (built-in MCP Server)

Official

Home Assistant ships an MCP server as a normal integration. Add "Model Context Protocol Server" in Settings, and your instance serves MCP at /api/mcp, with OAuth or a long-lived token. The agent can only see and control entities you have exposed to Assist, and it cannot change your Home Assistant configuration. That makes it the safest server on this list.

For Claude Code, Home Assistant's docs give an add-json command with OAuth. Claude Desktop needs a public URL or mcp-proxy for a LAN-only instance.

Replaces
Opening the app for quick checks
Runs on
Home Assistant 2025.2+
Difficulty
Easy
Licence
Apache-2.0 (open)
Skip if
You want the agent to edit automations
02 / SMART HOME

ha-mcp

Community

The power-user option: 87 tools covering automations, scripts, dashboards and configuration, far beyond the official integration. Very active (release 8.5.0 on September 16, 2026, about 4.9k stars) but unofficial. It has a read-only HTTP mode. Use that until you trust your setup, because the full mode can rewrite automations. If you are building voice control, also see our guide to Google Home with MCP and AI agents.

Replaces
Editing automations by hand
Runs on
Home Assistant
Difficulty
Medium
Licence
MIT (open)
Skip if
You only need to control devices (use the official one)

Virtualisation and containers

03 / HYPERVISOR

ProxmoxMCP-Plus

Community

There is no official Proxmox MCP server. This fork is the best maintained (release 0.5.22 on September 26, 2026) and adds what matters for safety: a read-only policy and approval for high-risk actions like stopping or deleting a VM. It covers VMs, LXC containers, backups and snapshots. Run it with uvx proxmox-mcp-plus or Docker.

Create a Proxmox API token with a limited role (PVEAuditor for read-only) rather than using root. The original canvrno/ProxmoxMCP has not been updated since February 2025. Our Proxmox VE guide covers setting up roles and tokens.

Replaces
Clicking through the Proxmox UI
Runs on
Proxmox VE, Python (uv)
Difficulty
Medium
Licence
MIT (open)
Skip if
You are not comfortable with an agent near your VMs
04 / CONTAINERS

Portainer MCP

Official

Portainer's own server (release 2.45.1, September 2, 2026) with a read-only mode. It goes through Portainer's API and permissions instead of the raw Docker socket, which is the safer design. One catch: the server's minor version must match your Portainer version.

Replaces
The Portainer UI for routine checks
Runs on
Portainer
Difficulty
Easy
Licence
MIT (open)
Skip if
You do not run Portainer
05 / CONTAINERS

Docker MCP Gateway

Official

Two uses here. First, it runs other MCP servers each in their own container, with managed secrets, which is a tidy way to host all the servers on this list on your home server. Second, its catalogue includes Docker management servers. For direct container control, the community mcp-server-docker (GPL-3.0) manages containers and compose stacks.

Be clear about the risk: access to the Docker socket is effectively root on that machine.

Replaces
Installing each MCP server by hand
Runs on
Docker Desktop or Engine
Difficulty
Medium
Licence
MIT (open)
Skip if
You run only one or two servers
06 / KUBERNETES

Kubernetes MCP Server

Red Hat / containers

For k3s and Talos home clusters. Supports read_only = true, selectable toolsets, Helm and KubeVirt. An alternative is mcp-server-kubernetes (MIT, with a non-destructive mode): claude mcp add kubernetes -- npx mcp-server-kubernetes. Use a kubeconfig for a limited service account.

Replaces
kubectl for everyday questions
Runs on
A cluster (k3s works)
Difficulty
Medium
Licence
Apache-2.0 (open)
Skip if
You do not run Kubernetes

Monitoring

07 / DASHBOARDS

Grafana MCP

Official

The most useful monitoring server. The agent can search dashboards, run Prometheus and Loki queries through Grafana, and read alerts, which is exactly what you need for "why was the NAS slow last night?" Official and very active (1.6.0 on September 25, 2026). Run with uvx mcp-grafana, a Grafana service account token with Viewer role, and --disable-write.

Replaces
Hunting through dashboards
Runs on
Grafana
Difficulty
Easy
Licence
Apache-2.0 (open)
Skip if
You do not run Grafana
08 / METRICS

Prometheus MCP

Prometheus org

Now hosted under the Prometheus organisation. Query metrics directly, with destructive admin tools switched off unless you opt in. Handy if you run Prometheus without Grafana, or want the agent to explore metrics you have not built dashboards for.

Replaces
Writing PromQL by hand
Runs on
Prometheus
Difficulty
Easy
Licence
Apache-2.0 (open)
Skip if
Grafana MCP already covers you

Storage

09 / NAS

TrueNAS MCP

Official preview

From iXsystems itself, which is good, but labelled a research preview and "not recommended for production" (0.0.6, July 2026). Fine for reading pool health and dataset usage on a home NAS. Do not let it touch pools or shares yet.

claude mcp add truenas -- truenas-mcp --truenas-url 192.168.1.10 --api-key YOUR_KEY
Replaces
Checking pools and datasets in the UI
Runs on
TrueNAS SCALE
Difficulty
Medium
Licence
GPL-3.0 (open)
Skip if
You want a stable, finished tool
10 / NAS

Unraid MCP

Community

There is no official Unraid server yet. This one (formerly jmagar/unraid-mcp) uses Unraid's GraphQL API and is actively maintained, but its README says plainly that it is not read-only. Use an API key with limited permissions.

Replaces
The Unraid dashboard
Runs on
Unraid with the API
Difficulty
Medium
Licence
MIT (open)
Skip if
You need read-only (it is not)

Media

11 / MEDIA

Jellyfin MCP

Community

31 tools for searching the library, checking what is playing and managing items, with --read-only and --disable-destructive flags and confirmation prompts. Updated September 2026. More on the server itself in our self-hosted media servers comparison.

Replaces
Browsing the library to find things
Runs on
Jellyfin
Difficulty
Easy
Licence
MIT (open)
Skip if
You use Plex
12 / MEDIA

Plex MCP (with Sonarr and Radarr)

Community

Covers Plex plus Sonarr, Radarr and Trakt in one server: 46 tools, 58 with writes enabled. "Add the new season of this show and tell me when it is ready" works. Keep writes off unless you want the agent adding downloads. Standalone *arr MCP servers exist but are all very small projects; treat them as unvetted.

Replaces
Jumping between Plex and the *arr apps
Runs on
Plex, optional Sonarr/Radarr
Difficulty
Medium
Licence
MIT (open)
Skip if
You use Jellyfin

Automation and network

13 / AUTOMATION

n8n (built-in MCP)

Official

n8n has an instance-level MCP server at /mcp-server/http. You opt workflows in one by one, and since 2.13 the agent can also build and edit workflows. This turns your existing automations into tools: "run the backup workflow" or "build a workflow that pings me when the NAS is full". Turn it off entirely with N8N_DISABLED_MODULES=mcp. New to it? Read what is n8n and how to self-host n8n.

Replaces
Opening n8n to trigger or edit workflows
Runs on
n8n 2.13+
Difficulty
Easy
Licence
Fair-code
Skip if
You do not run n8n
14 / FIREWALL

OPNsense and pfSense MCP

Community

The highest-risk category. For OPNsense, OPNSenseMCP hides write tools with OPNSENSE_READ_ONLY=true. For pfSense, pfsense-mcp-server wraps the REST API package in 332 tools with confirmation for destructive actions, which is a lot of context for most agents. We would only use either in read-only mode, for questions like "what blocked this device last night?"

Replaces
Reading firewall logs by hand
Runs on
OPNsense or pfSense with API
Difficulty
Hard
Licence
MIT (open)
Skip if
You cannot get to the console if you lock yourself out
15 / REMOTE ACCESS

Tailscale and Cloudflare

Mixed

Tailscale has no official MCP server, though its Aperture product can proxy other MCP servers across your tailnet. Community servers can list devices and manage ACLs; keep them read-only, since an ACL change can cut off access. Cloudflare's official server (https://mcp.cloudflare.com/mcp) handles DNS, Tunnels and Workers well if you expose services through Cloudflare Tunnel.

Replaces
Admin consoles for DNS and devices
Runs on
Tailscale or Cloudflare account
Difficulty
Medium
Licence
Various
Skip if
You do not use either

What is missing

  • Uptime Kuma: every MCP server we found has under ten stars or has not been updated since mid 2025. Skip for now, or query it through Grafana or n8n.
  • Official Proxmox, Unraid and Tailscale servers: none yet. Community options above.
  • Pi-hole and AdGuard Home: we did not find a well-maintained server for either. Their web APIs are simple enough that an n8n workflow exposed through MCP is often the safer route.

A safe starter setup

  1. Home Assistant's built-in server, with only a few devices exposed.
  2. Grafana MCP with a Viewer token and --disable-write.
  3. Portainer MCP in read-only mode.
  4. Everything running on your LAN, reached over Tailscale when you are away.
  • Each server has its own limited API token
  • Read-only mode on by default
  • No MCP port forwarded to the internet
  • Backups tested without the agent
  • Write access enabled one server at a time, and removed when done

This setup answers most "what is going on at home?" questions with almost no risk. Add write access later, one server at a time. For the wider MCP picture, see our best MCP servers for Claude.

Is there an MCP server for Home Assistant?
Yes. Home Assistant has a built-in Model Context Protocol Server integration since version 2025.2. It serves MCP at /api/mcp, supports OAuth, and only exposes entities you have shared with Assist. The community ha-mcp server adds automation and configuration editing.
Is there an official Proxmox MCP server?
No. Proxmox has not released one. ProxmoxMCP-Plus is the best maintained community server, with read-only and approval policies. Use a Proxmox API token with a limited role rather than root.
Is it safe to give an AI agent access to my home lab?
It can be, if you start read-only, use a separate limited API token per server, keep servers off the internet, and keep backups you can restore yourself. Write access to hypervisors, Docker or firewalls carries real risk of outages.
Can I use these MCP servers with a local model?
Yes. MCP servers work with any agent that supports MCP, including opencode, Goose and Claude Code pointed at a local or free model. Smaller local models are less reliable at tool calling, so read-only mode matters even more.
Which MCP server is best for monitoring a home lab?
Grafana's official MCP server. It can query Prometheus and Loki through Grafana, search dashboards and read alerts, and supports a --disable-write flag.
SSumit

Sumit

Contributor

Hi, I'm Sumit, Being an introvert I have always been obsessed with technology-computers and reading dozens of posts to learn, find answers out of my curiosity. I love to write as I explore more.

106 articles writtenView all posts by Sumit →

Related articles

See all