Install
$ agentstack add mcp-atom2ueki-mcp-server-synology β scanned Β· β verified β works with Claude Code, Cursor, and more.
Security review
β PassedNo issues found. Passed automated security review. Β· v0.1.0 How review works β
- β Prompt-injection patterns
- β Secret / credential exfiltration
- β Dangerous shell & filesystem operations
- β Untrusted network calls
- β Known-malicious package signatures
What it can access
- β Network access Used
- β Filesystem access No
- β Shell / process execution No
- β Environment & secrets Used
- β Dynamic code execution No
From automated source analysis of v0.1.0. βUsedβ means the capability is present in the source β more access means more to trust, not that itβs unsafe.
About
πΎ Synology MCP Server
A Model Context Protocol (MCP) server for Synology NAS devices. Enables AI assistants to manage files and downloads through secure authentication and session management.
π NEW: Unified server supports both Claude/Cursor (stdio) and Xiaozhi (WebSocket) simultaneously!
π Quick Start with Docker
1οΈβ£ Setup Environment
# Clone repository
git clone https://github.com/atom2ueki/mcp-server-synology.git
cd mcp-server-synology
# Create environment file
cp env.example .env
2οΈβ£ Configure .env File
Basic Configuration (Claude/Cursor only):
# Required: Synology NAS connection
SYNOLOGY_URL=http://192.168.1.100:5000
SYNOLOGY_USERNAME=your_username
SYNOLOGY_PASSWORD=your_password
# Optional: Auto-login on startup
AUTO_LOGIN=true
VERIFY_SSL=false
Extended Configuration (Both Claude/Cursor + Xiaozhi):
# Required: Synology NAS connection
SYNOLOGY_URL=http://192.168.1.100:5000
SYNOLOGY_USERNAME=your_username
SYNOLOGY_PASSWORD=your_password
# Optional: Auto-login on startup
AUTO_LOGIN=true
VERIFY_SSL=false
# Enable Xiaozhi support
ENABLE_XIAOZHI=true
XIAOZHI_TOKEN=your_xiaozhi_token_here
XIAOZHI_MCP_ENDPOINT=wss://api.xiaozhi.me/mcp/
3οΈβ£ Run with Docker
One simple command supports both modes:
# Claude/Cursor only mode (default if ENABLE_XIAOZHI not set)
docker-compose up -d
# Both Claude/Cursor + Xiaozhi mode (if ENABLE_XIAOZHI=true in .env)
docker-compose up -d
# Build and run
docker-compose up -d --build
4οΈβ£ Alternative: Local Python
# Install dependencies
pip install -r requirements.txt
# Run with environment control
python main.py
π Client Setup
π€ Claude Desktop
Add to your Claude Desktop configuration file:
macOS: ~/Library/Application Support/Claude/claude_desktop_config.json Windows: %APPDATA%\Claude\claude_desktop_config.json
{
"mcpServers": {
"synology": {
"command": "docker-compose",
"args": [
"-f", "/path/to/your/mcp-server-synology/docker-compose.yml",
"run", "--rm", "synology-mcp"
],
"cwd": "/path/to/your/mcp-server-synology"
}
}
}
βοΈ Cursor
Add to your Cursor MCP settings:
{
"mcpServers": {
"synology": {
"command": "docker-compose",
"args": [
"-f", "/path/to/your/mcp-server-synology/docker-compose.yml",
"run", "--rm", "synology-mcp"
],
"cwd": "/path/to/your/mcp-server-synology"
}
}
}
π Continue (VS Code Extension)
Add to your Continue configuration (.continue/config.json):
{
"mcpServers": {
"synology": {
"command": "docker-compose",
"args": [
"-f", "/path/to/your/mcp-server-synology/docker-compose.yml",
"run", "--rm", "synology-mcp"
],
"cwd": "/path/to/your/mcp-server-synology"
}
}
}
π» Codeium
For Codeium's MCP support:
{
"mcpServers": {
"synology": {
"command": "docker-compose",
"args": [
"-f", "/path/to/your/mcp-server-synology/docker-compose.yml",
"run", "--rm", "synology-mcp"
],
"cwd": "/path/to/your/mcp-server-synology"
}
}
}
π Alternative: Direct Python Execution
If you prefer not to use Docker:
{
"mcpServers": {
"synology": {
"command": "python",
"args": ["main.py"],
"cwd": "/path/to/your/mcp-server-synology",
"env": {
"SYNOLOGY_URL": "http://192.168.1.100:5000",
"SYNOLOGY_USERNAME": "your_username",
"SYNOLOGY_PASSWORD": "your_password",
"AUTO_LOGIN": "true",
"ENABLE_XIAOZHI": "false"
}
}
}
}
π Remote HTTP/SSE Deployment (NEW)
By default the server speaks stdio, which means the MCP client has to spawn the process locally (or via a bridge such as SSH/docker exec). For setups where the NAS is remote (different machine from where Claude/Cursor runs), you can expose the MCP server over HTTP/SSE using mcp-proxy. This makes it consumable by any MCP client that supports URL-based connectors β exactly like ha-mcp or other "remote" MCP servers.
Architecture
[Claude Desktop / Cursor / ...]
β
β HTTPS (URL connector)
βΌ
[Reverse proxy: DSM / Nginx / Traefik / Caddy]
β (TLS termination + auth)
β HTTP localhost:8765
βΌ
[Docker container]
ββ mcp-proxy
ββ python main.py (stdio)
Deploy
mcp-proxyis installed automatically when you build the HTTP image β it
lives in requirements-http.txt and the provided compose file sets the INSTALL_HTTP=true build arg (it is not in the default stdio/Xiaozhi image).
- Use the provided
docker-compose.http.yml:
# Edit credentials in docker-compose.http.yml first
docker compose -f docker-compose.http.yml up -d --build
docker logs -f synology-mcp-http
You should see mcp-proxy report Uvicorn running on http://0.0.0.0:8765 and the auto-login succeed.
Reverse proxy
Most MCP clients require HTTPS, so the HTTP endpoint must be fronted by a TLS-terminating reverse proxy. For DSM users, the built-in Login Portal β Reverse Proxy does the job:
- Source:
HTTPS, hostnamesynology-mcp.example.com, port443 - Destination:
HTTP,localhost, port8765 - Custom Headers: click Create β WebSocket (adds the headers needed for SSE/long-lived connections)
For Nginx, the equivalent is:
location / {
proxy_pass http://localhost:8765;
proxy_http_version 1.1;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
# SSE-specific
proxy_buffering off;
proxy_cache off;
proxy_read_timeout 24h;
}
Client configuration
In Claude Desktop (or any MCP client that supports remote connectors), add a custom connector pointing at:
https://synology-mcp.example.com/sse
No command, no args, no local Python β just a URL.
Security
mcp-proxy does not provide server-side authentication. Anything that can reach the HTTP endpoint can call every tool. Mitigations:
- Keep it on a private network or behind a VPN
- Use the reverse proxy to enforce an IP allow-list
- Add Basic Auth / mTLS / OAuth2 proxy at the reverse proxy layer
- Use a dedicated low-privilege DSM user (already recommended in the security warning above)
π Xiaozhi Integration
New unified architecture supports both clients simultaneously!
How It Works
- ENABLE_XIAOZHI=false (default): Standard MCP server for Claude/Cursor via stdio
- ENABLE_XIAOZHI=true: Multi-client bridge supporting both:
- π‘ Xiaozhi: WebSocket connection
- π» Claude/Cursor: stdio connection
Setup Steps
- Add to your .env file:
ENABLE_XIAOZHI=true
XIAOZHI_TOKEN=your_xiaozhi_token_here
- Run normally:
# Same command, different behavior based on environment
python main.py
# OR
docker-compose up
Key Features
- β Zero Configuration Conflicts: One server, multiple clients
- β Parallel Operation: Both clients can work simultaneously
- β All Tools Available: Xiaozhi gets access to all Synology MCP tools
- β Backward Compatible: Existing setups work unchanged
- β Auto-Reconnection: Handles WebSocket connection drops
- β Environment Controlled: Simple boolean flag to enable/disable
Startup Messages
Claude/Cursor only mode:
π Synology MCP Server
==============================
π Claude/Cursor only mode (ENABLE_XIAOZHI=false)
Both clients mode:
π Synology MCP Server with Xiaozhi Bridge
==================================================
π Supports BOTH Xiaozhi and Claude/Cursor simultaneously!
π οΈ Available MCP Tools
π Authentication
synology_status- Check authentication status and active sessionssynology_list_nas- List all configured NAS units from settings.jsonsynology_login- Authenticate with Synology NAS (conditional)synology_logout- Logout from session (conditional)
π File System Operations
list_shares- List all available NAS shareslist_directory- List directory contents with metadatapath(required): Directory path starting with/get_file_info- Get detailed file/directory informationpath(required): File path starting with/search_files- Search files matching patternpath(required): Search directorypattern(required): Search pattern (e.g.,*.pdf)create_file- Create new files with contentpath(required): Full file path starting with/content(optional): File content (default: empty string)overwrite(optional): Overwrite existing files (default: false)create_directory- Create new directoriesfolder_path(required): Parent directory path starting with/name(required): New directory nameforce_parent(optional): Create parent directories if needed (default: false)delete- Delete files or directories (auto-detects type)path(required): File/directory path starting with/rename_file- Rename files or directoriespath(required): Current file pathnew_name(required): New filenamemove_file- Move files to new locationsource_path(required): Source file pathdestination_path(required): Destination pathoverwrite(optional): Overwrite existing files
π₯ Download Station Management
ds_get_info- Get Download Station informationds_list_tasks- List all download tasks with statusoffset(optional): Pagination offsetlimit(optional): Max tasks to returnds_create_task- Create new download taskuri(required): Download URL or magnet linkdestination(optional): Download folder pathds_pause_tasks- Pause download taskstask_ids(required): Array of task IDsds_resume_tasks- Resume paused taskstask_ids(required): Array of task IDsds_delete_tasks- Delete download taskstask_ids(required): Array of task IDsforce_complete(optional): Force delete completedds_get_statistics- Get download/upload statistics
π₯ Health Monitoring
synology_system_info- Get system model, serial, DSM version, uptime, temperaturesynology_utilization- Get real-time CPU, memory, swap, and disk I/O utilizationsynology_disk_health- List all physical disks with SMART status, model, temp, sizesynology_disk_smart- Get detailed SMART attributes for a specific disksynology_volume_status- List all volumes with status, size, usage, filesystem typesynology_storage_pool- List RAID/storage pools with level, status, member diskssynology_network- Get network interface status and transfer ratessynology_ups- Get UPS status, battery level, power readingssynology_services- List installed packages and their running statussynology_system_log- Get recent system log entriessynology_health_summary- Aggregate system info, utilization, disk health, and volume status
π³ Container Manager
synology_container_list- List Container Manager containersoffset(optional): Pagination offsetlimit(optional): Maximum containers to returncontainer_type(optional): Container filter (default:all)synology_container_get- Get a Container Manager containername(required): Container namesynology_container_start- Start a Container Manager containername(required): Container namesynology_container_stop- Stop a Container Manager containername(required): Container namesynology_container_restart- Restart a Container Manager containername(required): Container namesynology_container_delete- Delete a Container Manager containername(required): Container nameforce(optional): Force deletion (default: false)preserve_profile(optional): Preserve Synology container profile (default: true)synology_container_logs- Get Container Manager container logsname(required): Container namesince(optional): Log start time/filteroffset(optional): Pagination offset (default: 0)limit(optional): Maximum log lines to return (default: 1000)synology_container_resource- Get real-time resource usage for a Container Manager containername(required): Container namesynology_container_project_list- List Container Manager projectssynology_container_project_get- Get a Container Manager projectname(required): Project namesynology_container_project_create- Create a Container Manager projectname(required): Project nameshare_path(required): Project folder path on the NAScontent(required): Docker Compose YAML contentenable_service_portal(optional): Enable Synology service portal (default: false)service_portal_name(optional): Service portal nameservice_portal_port(optional): Service portal portservice_portal_protocol(optional): Service portal protocol (default:http)synology_container_project_update- Update a Container Manager projectname(required): Project namecontent(required): Docker Compose YAML contentenable_service_portal(optional): Enable Synology service portalservice_portal_name(optional): Service portal nameservice_portal_port(optional): Service portal portservice_portal_protocol(optional): Service portal protocolsynology_container_project_start- Start a Container Manager projectname(required): Project namesynology_container_project_stop- Stop a Container Manager projectname(required): Project namesynology_container_project_restart- Restart a Container Manager projectname(required): Project namesynology_container_project_build- Build a Container Manager projectname(required): Project namesynology_container_project_clean- Clean a Container Manager projectname(required): Project namesynology_container_project_delete- Delete a Container Manager projectname(required): Project namesynology_container_image_list- List Container Manager imagesoffset(optional): Pagination offsetlimit(optional): Maximum images to returnshow_dsm(optional): Include DSM images (default: false)synology_container_image_get- Get a Container Manager imagename(required): Image repository nametag(optional): Image tag (default:latest)synology_container_image_delete- Delete a Container Manager imagename(required): Image repository nametag(optional): Image tag (default:latest)synology_container_image_pull- Pull a Container Manager imagerepository(required): Image repository nametag(optional): Image tag (default:latest)synology_container_registry_list- List Container Manager registriessynology_container_registry_search- Search Container Manager registriesquery(required): Image search queryoffset(optional): Pagination offsetlimit(optional): Maximum results to returnsynology_container_registry_tags- List tags for a registry imagerepository(required): Image repository nameoffset(optional): Pagination offsetlimit(optional): Maximum tags to returnsynology_container_registry_download- Download a registry imagerepository(required): Image repository nametag(optional): Image tag (default:latest)- **`synologycontainernetwork_li
β¦
Source & license
This open-source MCP server is cataloged on AgentStack and links to its original source β we do not rehost the code.
- Author: atom2ueki
- Source: atom2ueki/mcp-server-synology
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet β be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.