Your AI can read your infrastructure. It should be able to run it.
coolify-mcp gives Claude, Cursor and any other MCP client a deliberate way to operate a live Coolify platform (deploy, diagnose, restart, roll back) and hands it only what it can take in.
“Why is checkout-web down?”
diagnose_applogslist_deployments
exited:unhealthy — OOM killed at 14:22. The deploy three hours ago raised the memory request, not the limit.
01 Install
One config block and an API token.
On your machine, in Claude Desktop, Claude Code, Cursor and anything else that speaks MCP. Or hosted inside your own Coolify, with OAuth for claude.ai and other remote clients. Locally the token stays on your machine; hosted, it stays in the container and clients get OAuth.
{
"mcpServers": {
"coolify": {
"command": "npx",
"args": ["-y", "@masonator/coolify-mcp"],
"env": {
"COOLIFY_BASE_URL": "https://coolify.example.com",
"COOLIFY_ACCESS_TOKEN": "your-api-token"
}
}
}
} - Remote
Run it as a container next to the Coolify it manages and connect claude.ai, Claude Desktop or Claude Code to
/mcp. Your token stays server-side; clients get OAuth 2.1. Five-minute setup. - Several Coolifys
Add
COOLIFY_INSTANCESand every tool takes an instance name. Fleet guide.
COOLIFY_BASE_URL="https://coolify.example.com" COOLIFY_ACCESS_TOKEN="your-api-token" \
npx @masonator/coolify-mcp doctor Whatever you configured, doctor checks it end to end and prints a one-line fix for each failure. It never prints a secret. What it checks.
02 What it can do
46 tools, covering the whole platform.
The full list lives in the tool reference, where it stays current. What matters here is the shape of it.
Work out what is wrong
Diagnose an app or a server in one call, read container logs, and scan the whole estate for problems.
Deploy and roll back
Trigger deploys by tag or uuid, watch them, cancel them, and start, stop or restart anything.
Create and destroy
Applications, databases, services, projects and environments: created, changed and removed.
Handle the configuration
Environment variables, volumes, scheduled tasks, backups and SSH keys. Secrets stay masked unless you ask.
Move across the whole estate
One key across many apps, a project redeployed, or everything stopped at once, each behind a human confirmation.
Run several Coolifys
Prod, staging and a per-region instance from one server. Every tool takes an instance; every confirmation names it.
03 Docs
The reference lives in the repo, next to the code.
One page here. The detail sits where contributors keep it honest, and it is all in /llms.txt for anything reading this on your behalf.
Tool reference
Every tool by category, how the surface is shaped, Coolify version compatibility and the upstream gotchas already handled.
Remote: HTTP mode
Run it as a container inside Coolify and connect claude.ai or Claude Code over OAuth 2.1. Five-minute install, every mistake we made.
Prompts and resources
Guided workflows you start as slash commands, and reads a client can attach. Why a prompt never fetches, and why a resource can never bypass masking.
Fleet
Several Coolify instances from one server: COOLIFY_INSTANCES, the instance argument, and why a fleet is one trust domain.
Doctor
npx @masonator/coolify-mcp doctor: what each check proves, exit codes, and what it deliberately does not guess.
Safety and security
Human confirmation on destructive operations, secrets masked at the API boundary, and how to report a vulnerability.
Changelog
Every release, what changed and why, with upgrade notes.
04 Why you can point it at production
It stops and asks a person before it does anything it cannot undo.
Not the model deciding it has permission. An actual human being asked “stop all 26 running applications?” in their own client, and having to answer.
It asks before it hurts
Destructive operations stop and put the question to a person, in their own client, before anything happens.
Secrets stay hidden
Environment variables come back masked. Revealing one is a separate, deliberate request.
It fits in the context window
Lists return summaries, not whole objects. Responses are 90–99% smaller than the raw API.
Tested against a real server
Every release runs against a live Coolify, not a mock. That is how the API quirks got found.
The tool choice is measured
A model reads these tools and has to pick the right one. An eval suite measures that it does — and red-teams whether a poisoned log can talk it into deleting anything or leaking a secret.
05 Work with me
Your clients want AI. You need someone who actually ships it.
I work out what is possible, what it costs to keep running, and where the data has to live. Then I build it, under your name if you are an agency. And when the honest answer is that a job does not need AI, I will say so before anyone has paid for anything.
An MCP server for your product
Give Claude, Cursor and every other AI client a proper way into your API, like this one.
Answers from your own stuff
AI that answers from your documents and data, with the receipts, instead of guessing.
Work that runs itself
A job on a schedule that sorts, checks or reports, with a person signing off before it goes out.
Building since 2006 · Folkestone, Kent · Agencies, SMEs and enterprise · Day rate, hourly, or priced by the job
06 Get in touch
Tell me what you are trying to build.
A rough paragraph is enough to start. You will get a straight answer from a person, usually the same day, including if I think you do not need me.
Or email [email protected]