Docs / Connect your AI (MCP)

Connect your AI (MCP)

Keep working with the AI agent of your choice. Through the Saka MCP, the agent only uses the tools we provide, not a root shell that can do anything.

1. Create a token

  1. Open Pengaturan (Settings) in the panel, on the Sambungkan AI Anda (MCP) & token API (Connect your AI (MCP) & API tokens) card.
  2. Give the token a name, for example "Claude on my laptop", then press Buat token (Create token).
  3. Copy the token (it starts with saka_) now. It is shown only once.

The same token works for MCP and the REST API. The panel shows when it was last used, and a token can be revoked at any time; any AI using it loses access immediately.

2. Connect

Claude Code

Terminal
claude mcp add --transport http sakapanel https://app.saka.work/mcp --header "Authorization: Bearer <token>"

Other MCP clients

Coming soon

Sign-in with OAuth, so Saka can be added directly as a connector in claude.ai and ChatGPT without copying a token.

Once connected, try asking: "How are my servers doing?" The agent will call server_daftar.

Available MCP tools

ToolWhat it does
server_daftarLists servers with their latest status (connected, CPU, RAM, disk, apps).
server_statusLive status of one server, requested from the agent right then.
server_tambahCreates a one-line install command for a new VPS; you run it on the server yourself.
metrik_riwayatCPU, RAM, disk, and load history (stored on that server, 30 days).
resep_daftarCatalog of ready-to-install apps and the fields they need.
aplikasi_pasangInstalls an app from the catalog on a server (non-root container, local-only port).
aplikasi_logRecent app logs, read directly from the server (not stored by Saka).
aplikasi_mulai_ulangRestarts an app; data is not changed.
aplikasi_hapus_siapkanStep 1 of 2 for removing an app: a preview and a confirmation token (10 minutes).
aplikasi_hapusStep 2 of 2: removes the app with the token, only after you have approved the preview.
aplikasi_akses_daftarAccess requests (pairing) waiting for approval, for example a new person messaging the OpenClaw bot.
aplikasi_akses_setujuiApproves one access code, only after you recognize the sender.
server_perbaikiReadiness fixes: swap, firewall-cek (port list, read-only), and firewall.
database_daftarLists database clusters with their state and members.
database_buatCreates a multi-location database cluster (PostgreSQL or MariaDB, 2 data + 1 witness).
database_statusCluster state, members, replication lag, and connection string. No password.
database_sambungkan_aplikasiInstalls the Saka proxy on an app server so the app fails over automatically when a server goes down.
lb_daftarLists load balancers: balancers, targets, domains, state.
lb_buatCreates a load balancer with health checks and automatic HTTPS.
lb_statusHealth of each target server as seen from each balancer, and the HTTPS certificate for each domain.
situs_daftarLists sites (WordPress, PHP, static) across all servers, with their domains and state.
situs_buatCreates a WordPress, PHP, or static site with automatic HTTPS, a local or cluster database, or moves one from cPanel (from a backup file, or by signing in to the old cPanel; the cPanel password is only passed to your server). The agent must confirm the plan with you first.
situs_statusSite state: HTTPS and DNS for each domain, size, list of backups, SFTP account. No passwords.
situs_cadangkanMakes a site backup now (files + database), stored on the server.
situs_atur_phpChanges a site's PHP settings (like cPanel's MultiPHP INI Editor): upload limit, memory, execution time, max_input_vars, time zone, show errors. The site restarts for a few seconds.
situs_pindah_salinFirst step of moving to another server: copies the site straight to the target server (optionally with another PHP version and a WordPress update with automatic rollback). The old site keeps running.
situs_ubah_siapkanStep 1 of 2 for actions that replace a site's content: pulihkan (restore), hapus (delete), pindah_sekarang (move now: the old site shows a maintenance page briefly and the site goes live on the new server), pindah_selesai (finish: delete on the old server once DNS points to the new one), or pindah_batal (cancel the move). Returns a preview and a confirmation token (10 minutes).
situs_ubahStep 2 of 2: runs that action with the token, only after you have approved the preview.
fitur_usulkanSends a feature request to the Saka team when you need something Saka cannot do yet. The agent must show you the draft title and description, and send it only after you agree.
tugas_statusState of long-running tasks (for example an app install).
peringatan_aktifProblems happening right now across all servers (disconnected, disk full, app stopped).

Every error includes kode (code), arti (meaning), and langkah (next step), so the agent can fix things itself or explain to you what to do. MCP tool descriptions and responses are in Indonesian; your AI agent can still reply to you in your own language.

Security principles

AI directly on the server vs AI through Saka

Giving an AI agent root SSH access is fast, but one wrong command, or one web page that tricks the agent, can delete your data and expose your server.

AI directly on the server (root SSH)AI through Saka (MCP)
AccessRoot shell: can run anythingOnly the tools provided: status, install apps, sites, create databases, load balancers, fixes
Keys & passwordsSSH keys, database passwords, and AI keys are readable by the agentNever handed to the agent; you view them yourself in the panel
Dangerous actionsRun immediately, with no previewRemoving an app always takes two steps; the firewall must show the ports in use first
Tricked through chat or the webInjected commands run with root privilegesAt most it calls limited tools that still need your approval
Audit trailNot recorded anywhereEvery task on the server is recorded in the history with its result
Server dies suddenlyThe agent dies with it; nobody tells youSaka monitors from outside and sends a Telegram notification

AI costs are paid directly to your AI provider. Saka does not charge for MCP.