Download the PHP package sulu/mcp-bundle without Composer

On this page you can find all versions of the php package sulu/mcp-bundle. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.

FAQ

After the download, you have to make one include require_once('vendor/autoload.php');. After that you have to import the classes with use statements.

Example:
If you use only one package a project is not needed. But if you use more then one package, without a project it is not possible to import the classes with use statements.

In general, it is recommended to use always a project to download your libraries. In an application normally there is more than one library needed.
Some PHP packages are not free to download and because of that hosted in private repositories. In this case some credentials are needed to access such packages. Please use the auth.json textarea to insert credentials, if a package is coming from a private repository. You can look here for more information.

  • Some hosting areas are not accessible by a terminal or SSH. Then it is not possible to use Composer.
  • To use Composer is sometimes complicated. Especially for beginners.
  • Composer needs much resources. Sometimes they are not available on a simple webspace.
  • If you are using private repositories you don't need to share your credentials. You can set up everything on our site and then you provide a simple download link to your team member.
  • Simplify your Composer build process. Use our own command line tool to download the vendor folder as binary. This makes your build process faster and you don't need to expose your credentials for private repositories.
Please rate this library. Is it a good library?

Informations about the package mcp-bundle

SuluMcpBundle

Official Sulu Bundle Badge

GitHub license GitHub tag (latest SemVer) Test workflow status Sulu compatibility


The SuluMcpBundle turns a Sulu installation into a Model Context Protocol server. AI assistants connect over Streamable HTTP and create pages, edit articles, manage media and publish content through the same operations the administration interface uses. Every request runs as the authenticated Sulu user, so an operation that is denied in the administration interface is denied over MCP as well. There is no separate authentication layer and no privilege escalation.

🚀  Installation and Documentation

The first command enables the contrib recipes, where this bundle's Flex recipe lives. The recipe registers the bundles, writes the routes and the configuration, including the allowed hosts of the transport and the default OAuth scopes, and adds SULU_MCP_SERVER_URL to .env. The OAuth key pair, the league/oauth2-server-bundle grants, the migration and the security setup have no Flex configurator and stay manual.

The steps below spell out everything, both for installations without Flex and for reading back what the recipe put into your project. Start by registering the bundle in config/bundles.php, along with its two required dependencies. league/oauth2-server-bundle registers itself through its own recipe, while symfony/mcp-bundle has none and is registered by ours:

Import the routes in config/routes.yaml. The mcp entry registers the MCP transport endpoint provided by symfony/mcp-bundle. This bundle ships its OAuth endpoints in two files: the admin ones take the same prefix your project already uses for the rest of the Sulu admin, and the RFC 8414/9728 discovery documents stay unprefixed in the host's /.well-known/ namespace:

Generate the RSA key pair that league/oauth2-server-bundle signs its tokens with. Skipping this step leaves every MCP request failing with Invalid key supplied:

Both commands prompt for the passphrase, so it stays out of your shell history.

Keep both keys out of version control, for example by adding /config/jwt/*.pem to your .gitignore.

Set the public server URL and the OAuth secrets in your environment. The passphrase has to match the one used above, and the encryption key is any random string:

Configure league/oauth2-server-bundle in config/packages/league_oauth2_server.yaml. Its Flex recipe generates most of the file; make sure the authorization-code and refresh-token grants MCP uses are enabled and the password and implicit grants are explicitly off. scopes.default is required by league and comes from this bundle's recipe, which appends the MCP scopes to the ones the league recipe wrote; set it yourself when you install without Flex:

Name the public host on the MCP transport. The transport ships with DNS rebinding protection that accepts only localhost, so a server on its own domain rejects every client with Forbidden: Invalid Host header. once the OAuth handshake is through. This bundle's recipe writes the setting into config/packages/sulu_mcp.yaml; without Flex, put it in config/packages/mcp.yaml yourself:

Create the database tables. league/oauth2-server-bundle persists clients, authorization codes, access tokens and refresh tokens through Doctrine:

The MCP endpoint then answers at /admin/mcp. The docs/ directory documents the configuration reference, the required security setup, and per-client connection guides for Claude Code, Codex.

💡  Key Concepts

Permissions

The bundle adds no permission model of its own. Every tool declares the Sulu security context and permission type it requires, a compile-time map is built from those declarations, and a central gate checks it before any tool runs. Tools the current role cannot use are hidden from the tool listing, and calling one anyway returns a permission denial rather than a missing-tool error.

Dangerous tools

Tools with hard-to-reverse effects are disabled by default and enabled per category through the dangerous_tools configuration. When a category is disabled its tools are removed from the container at compile time, so they never appear to a client at all.

Available tools

40 tools spanning the core Sulu domains, plus 9 more when sulu/product-bundle is installed:

Domain Count Examples
Pages 7 sulu_page_create, sulu_page_get, sulu_page_list, sulu_page_move, sulu_page_reorder, sulu_page_tree, sulu_page_update
Blocks 5 sulu_block_add, sulu_block_update, sulu_block_reorder, sulu_block_list, sulu_block_remove
Articles 4 sulu_article_create, sulu_article_update, sulu_article_get, sulu_article_list
Snippets 4 sulu_snippet_create, sulu_snippet_update, sulu_snippet_get, sulu_snippet_list
Unified content 3 sulu_content_delete, sulu_content_publish, sulu_content_unpublish
Media 4 sulu_media_list, sulu_media_get, sulu_media_update, sulu_media_upload
Taxonomy 6 sulu_tag_*, sulu_category_*
Preview 2 sulu_preview_link_generate, sulu_preview_link_revoke
Navigation 1 sulu_navigation_get
Contact 1 sulu_contact_list
Products (optional) 9 sulu_product_create, sulu_product_update, sulu_product_get, sulu_product_list, sulu_product_variant_*, sulu_product_family_list, sulu_attribute_list — require sulu/product-bundle
Misc 3 sulu_content_search, sulu_get_context, sulu_ping

The block and unified content tools operate on pages, articles, snippets — and products, when sulu/product-bundle is installed — alike through a type parameter.

Products (optional)

The product tools appear only when sulu/product-bundle is installed and registered in bundles.php; without it they are hidden from tools/list. The bundle has no 3.x release yet, so it installs from its branch:

Products are modelled with a product family that decides which attributes apply, and support one level of variants: a product of type product_with_variants holds variant children. Variants cannot be nested. Because a variant inherits its parent's family and only carries the attributes the family marks variantSpecific, they are created with sulu_product_variant_create rather than sulu_product_create. Publishing the parent through sulu_content_publish cascades to all of its variants.

Authentication

Clients authenticate through OAuth 2.1 with Dynamic Client Registration, backed by league/oauth2-server-bundle. Sulu opens the administration login when needed and then shows an explicit consent screen naming the client and the requested scopes. Tokens are only issued once the user approves that screen.

For hosted clients, create an OAuth client up front:

❤️  Support and Contributions

The Sulu content management system is a community-driven open source project backed by various partner companies. We are committed to a fully transparent development process and highly appreciate any contributions.

Have a look at our contribution guidelines and the Sulu contribution documentation before opening a pull request. Security issues should be reported privately as described in SECURITY.md.

✅  Requirements

Have a look at the require section in the composer.json for an up-to-date list.

📘  License

The Sulu content management system is released under the terms of the MIT License.


All versions of mcp-bundle with dependencies

PHP Build Version
Package Version
Requires php Version ^8.2
composer-runtime-api Version ^2.0
symfony/doctrine-bridge Version ^7.3 || ^8.0
symfony/framework-bundle Version ^7.3 || ^8.0
symfony/http-client Version ^7.3 || ^8.0
symfony/mime Version ^7.3 || ^8.0
symfony/mcp-bundle Version ^0.13
mcp/sdk Version ^0.8.1
sulu/sulu Version ^3.0.9
league/oauth2-server-bundle Version ^1.2
nyholm/psr7 Version ^1.4
symfony/psr-http-message-bridge Version ^7.3 || ^8.0
symfony/password-hasher Version ^7.3 || ^8.0
Composer command for our command line client (download client) This client runs in each environment. You don't need a specific PHP version etc. The first 20 API calls are free. Standard composer command

The package sulu/mcp-bundle contains the following files

Loading the files please wait ...