{"id":28504222,"url":"https://github.com/professionalwiki/mediawiki-mcp-server","last_synced_at":"2026-08-27T15:45:16.765Z","repository":{"id":297840007,"uuid":"982324225","full_name":"ProfessionalWiki/MediaWiki-MCP-Server","owner":"ProfessionalWiki","description":"Model Context Protocol (MCP) Server to connect your AI with any MediaWiki","archived":false,"fork":false,"pushed_at":"2026-08-20T12:37:37.000Z","size":2800,"stargazers_count":123,"open_issues_count":13,"forks_count":32,"subscribers_count":5,"default_branch":"master","last_synced_at":"2026-08-21T21:40:02.080Z","etag":null,"topics":["agents","ai","ai-agent-tools","gemini-cli-extension","llms","mcp","mcp-server","mediawiki","model-context-protocol","model-context-protocol-servers","modelcontextprotocol"],"latest_commit_sha":null,"homepage":"https://professional.wiki/en/mediawiki-mcp-server","language":"TypeScript","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/ProfessionalWiki.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"SECURITY.md","support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":"AGENTS.md","dco":null,"cla":null,"disclosure":null}},"created_at":"2025-05-12T17:55:22.000Z","updated_at":"2026-08-21T09:24:17.000Z","dependencies_parsed_at":"2025-12-08T10:06:03.823Z","dependency_job_id":"73ecaf11-b371-41a2-b890-ecc5402f2896","html_url":"https://github.com/ProfessionalWiki/MediaWiki-MCP-Server","commit_stats":null,"previous_names":["professionalwiki/mediawiki-mcp-server"],"tags_count":28,"template":false,"template_full_name":null,"purl":"pkg:github/ProfessionalWiki/MediaWiki-MCP-Server","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ProfessionalWiki%2FMediaWiki-MCP-Server","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ProfessionalWiki%2FMediaWiki-MCP-Server/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ProfessionalWiki%2FMediaWiki-MCP-Server/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ProfessionalWiki%2FMediaWiki-MCP-Server/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/ProfessionalWiki","download_url":"https://codeload.github.com/ProfessionalWiki/MediaWiki-MCP-Server/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ProfessionalWiki%2FMediaWiki-MCP-Server/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":36944061,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-08-22T15:14:58.755Z","status":"online","status_checked_at":"2026-08-27T02:00:07.166Z","response_time":96,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["agents","ai","ai-agent-tools","gemini-cli-extension","llms","mcp","mcp-server","mediawiki","model-context-protocol","model-context-protocol-servers","modelcontextprotocol"],"created_at":"2025-06-08T18:00:38.447Z","updated_at":"2026-08-27T15:45:16.751Z","avatar_url":"https://github.com/ProfessionalWiki.png","language":"TypeScript","funding_links":[],"categories":["Knowledge \u0026 Memory"],"sub_categories":["How to Submit"],"readme":"# MediaWiki MCP Server\n[![NPM Version](https://img.shields.io/npm/v/%40professional-wiki%2Fmediawiki-mcp-server?color=red)](https://www.npmjs.com/package/@professional-wiki/mediawiki-mcp-server) [![MIT licensed](https://img.shields.io/npm/l/%40professional-wiki%2Fmediawiki-mcp-server)](./LICENSE)\n\nAn MCP (Model Context Protocol) server that enables Large Language Model (LLM) clients to interact with any MediaWiki wiki.\n\n## Features\n\n### Tools\n\nEvery tool that operates on a wiki accepts an optional `wiki` argument naming the wiki to act on (the wiki-management and OAuth tools do not) — pass a wiki key (e.g. `en.wikipedia.org`) or the full `mcp://wikis/{wikiKey}` URI. Omit it to use the configured default wiki (see [Configuration](#configuration)). Each tool response reports the wiki the call ran against.\n\n#### Page reads\n\n| Name | Description |\n|---|---|\n| `compare-pages` | Diff two versions of a wiki page by revision, title, or supplied wikitext. |\n| `get-category-members` | List members of a category (up to 500 per call, paginated via `continueFrom`). |\n| `get-file` | Fetch a file page. |\n| `get-file-data` | Fetch a file's image bytes inline (base64) for visual analysis — for clients that can't reach the wiki host. Returns a scaled rendition (set `width`); non-renderable types (audio, video, binaries) error. For metadata or a download URL, use `get-file`. |\n| `get-links-here` | List pages that reference a wiki page — pages that link to it, embed it as a template, or display it as a file (select via `type`), including pages that reach it through a redirect. Up to 500 per call, paginated via `continueFrom`. |\n| `get-page` | Fetch a wiki page. |\n| `get-page-history` | List recent revisions of a wiki page. |\n| `get-pages` | Fetch multiple wiki pages in one call (up to 50). |\n| `get-recent-changes` | List recent change events across the wiki, filterable by timestamp, namespace, user, tag, type, and hide flags (up to 50 per call, paginated via `continue`). |\n| `get-revision` | Fetch a specific revision of a page. |\n| `get-site-info` | Get a wiki's key settings: MediaWiki version, content language, title-case rules, namespaces, installed extensions, license, and (optionally) statistics. |\n| `list-wikis` | List every configured wiki — its key, sitename, server, whether it is read-only or the default, whether it is reachable, which extension-gated tools work on it, and, for an OAuth-configured wiki, its authorization server. Disabled when fewer than two wikis are configured. |\n| `parse-wikitext` | Render wikitext to HTML without saving. Returns parse warnings, wikilinks, templates, and external URLs. |\n| `search-page` | Search wiki page titles and contents. |\n| `search-page-by-prefix` | Search page titles by prefix. |\n| `whoami` | Report the identity the current session is authenticated as on the targeted wiki — username, whether it is anonymous, and group memberships (optionally user rights). |\n\n#### Page writes\n\n| Name | Description | Permissions |\n|---|---|---|\n| `create-page` 🔐 | Create a new wiki page. | `Create, edit, and move pages` |\n| `delete-page` 🔐 | Delete a wiki page. | `Delete pages, revisions, and log entries` |\n| `move-page` 🔐 | Move (rename) a wiki page. | `Create, edit, and move pages` |\n| `undelete-page` 🔐 | Undelete a wiki page. | `Delete pages, revisions, and log entries` |\n| `update-file` 🔐 | Upload a new revision of an existing file from local disk. | `Upload, replace, and move files` |\n| `update-file-from-url` 🔐 | Upload a new revision of an existing file from a URL. | `Upload, replace, and move files` |\n| `update-page` 🔐 | Update an existing wiki page. | `Edit existing pages` |\n| `upload-file` 🔐 | Upload a file to the wiki from local disk. | `Upload new files` |\n| `upload-file-from-url` 🔐 | Upload a file to the wiki from a URL. | `Upload, replace, and move files` |\n\n#### Wiki management\n\n| Name | Description |\n|---|---|\n| `add-wiki` | Add a wiki as an MCP resource from its URL. Disabled when `allowWikiManagement` is `false`. |\n| `remove-wiki` | Remove a wiki resource. Disabled when `allowWikiManagement` is `false` or fewer than two wikis are configured. |\n\n#### OAuth\n\n| Name | Description |\n|---|---|\n| `oauth-logout` | Remove stored OAuth tokens. Stdio only. |\n| `oauth-status` | List stored OAuth tokens with scopes and expiry (no token values). Stdio only. |\n\n#### Extension packs\n\nEach pack's tools register only on wikis where its extension is installed.\n\n**[NeoWiki](https://neowiki.ai/)**\n\n| Name | Description |\n|---|---|\n| `neowiki-list-schemas` | List schemas (entity types) and their property counts. |\n| `neowiki-get-schema` | Get one schema's property definitions, relations, and select options. |\n| `neowiki-cypher-query` | Run a read-only Cypher query against the knowledge graph. |\n| `neowiki-search-subjects` | Find subject IDs by label within a schema. |\n| `neowiki-get-subject` | Fetch one subject's structured data by ID. |\n| `neowiki-get-page-subjects` | List the subjects attached to a wiki page. |\n| `neowiki-create-subject` | Create a subject (child or main) on a page. Requires the `edit` right. |\n| `neowiki-update-subject` | Replace a subject's label and statements. Requires the `edit` right. |\n| `neowiki-delete-subject` | Delete a subject by ID. Requires the `edit` right. |\n| `neowiki-set-main-subject` | Set or clear a page's main subject. Requires the `edit` right. |\n| `neowiki-validate-subject` | Dry-run validate a proposed subject and return violations. |\n\n**[Semantic MediaWiki](https://www.mediawiki.org/wiki/Extension:Semantic_MediaWiki)**\n\n| Name | Description |\n|---|---|\n| `smw-list-properties` | List Semantic MediaWiki properties with copy-paste templates for `smw-query`. |\n| `smw-query` | Run a Semantic MediaWiki `#ask` query. |\n\n**[Bucket](https://github.com/weirdgloop/mediawiki-extensions-Bucket)**\n\n| Name | Description |\n|---|---|\n| `bucket-query` | Run a Bucket Lua query. |\n\n**[Cargo](https://www.mediawiki.org/wiki/Extension:Cargo)**\n\n| Name | Description |\n|---|---|\n| `cargo-list-tables` | List Cargo tables defined on the wiki. |\n| `cargo-describe-table` | List a Cargo table's fields with their types and list-flags. |\n| `cargo-query` | Run a Cargo SQL-style query. |\n\n**[Wikibase](https://www.mediawiki.org/wiki/Extension:Wikibase_Repository)**\n\n| Name | Description |\n|---|---|\n| `wikibase-search-entities` | Find items and properties by label or alias. |\n| `wikibase-get-entity` | Read one entity's terms and statements, with referenced IDs resolved to labels. |\n| `wikibase-query` | Run a SPARQL query against the wiki's query service. Offered only for a repository whose siteinfo publishes one. |\n| `wikibase-edit-entity` | Create or change an entity from Wikibase entity JSON. Requires the `edit` right. |\n| `wikibase-add-statement` | Add one statement with an item, string, external-id or url value. Requires the `edit` right. |\n\n### Resources\n\n**`mcp://wikis/{wikiKey}`** — per-wiki resource exposing `sitename`, `server` (the wiki's public address), `articlepath`, `scriptpath`, and the `private` and `readOnly` flags.\n\n- Those fields are the whole of it: the resource publishes a fixed list, so credentials and server-side settings in your configuration file are never exposed in resource content.\n- After `add-wiki` or `remove-wiki`, the server sends `notifications/resources/list_changed` so clients refresh.\n\n\u003cdetails\u003e\u003csummary\u003eExample read result\u003c/summary\u003e\n\n```json\n{\n  \"contents\": [\n    {\n      \"uri\": \"mcp://wikis/en.wikipedia.org\",\n      \"mimeType\": \"application/json\",\n      \"text\": \"{ \\\"sitename\\\":\\\"Wikipedia\\\",\\\"server\\\":\\\"https://en.wikipedia.org\\\",\\\"articlepath\\\":\\\"/wiki\\\",\\\"scriptpath\\\":\\\"/w\\\",\\\"private\\\":false }\"\n    }\n  ]\n}\n```\n\u003c/details\u003e\n\n### Environment variables\n\nThe variables below are relevant to any setup. Variables that only apply when self-hosting the HTTP transport (ports, timeouts, Host/Origin and SSRF guards) or running the hosted OAuth proxy are in [docs/deployment.md — environment variables](docs/deployment.md#environment-variables). Config-file substitution and upload-directory variables are in [docs/configuration.md](docs/configuration.md).\n\n| Name | Description | Default |\n|---|---|---|\n| `CONFIG` | Path to your configuration file | `config.json` |\n| `MCP_TRANSPORT` | Type of MCP server transport (`stdio` or `http`) | `stdio` |\n| `MCP_LOG_LEVEL` | Minimum severity for logger output. One of `debug`, `info`, `notice`, `warning`, `error`, `critical`, `alert`, `emergency`, or `silent`. | `debug` |\n| `MCP_CONTENT_MAX_BYTES` | Byte cap for the content bodies and result blocks tools return (wikitext, rendered HTML, diffs, statement and row listings). Tune to the target LLM client's tool-response budget. | `50000` |\n| `MCP_FILE_DATA_MAX_BYTES` | Hard cap on the base64-encoded size of a `get-file-data` response. A transport/safety backstop; tune the actual size per call with the tool's `width`. Over-cap calls error rather than truncate. | `1000000` |\n| `MCP_UPLOAD_MAX_BYTES` | Memory cap on the server-side fetch used by `upload-file-from-url` / `update-file-from-url`. Files larger than this are handed to the wiki's own copy-upload instead of being buffered by the server. Guards this server's memory, not the wiki's `$wgMaxUploadSize`. | `104857600` |\n| `MCP_OAUTH_CREDENTIALS_FILE` | Override the default credentials store path. Default: `~/.config/mediawiki-mcp/credentials.json` (Linux/macOS) or `%APPDATA%\\mediawiki-mcp\\credentials.json` (Windows). | `unset` |\n| `MCP_OAUTH_NO_BROWSER` | Set to `1` to skip launching a browser during the OAuth flow; the auth URL is logged to stderr instead. Useful in headless environments. | `unset` |\n\n## Configuration\n\n\u003e [!NOTE]\n\u003e Config is only required when interacting with a private wiki or using authenticated tools.\n\nCreate a `config.json` file to configure wiki connections. Use the `config.example.json` as a starting point.\n\n```json\n{\n  \"defaultWiki\": \"en.wikipedia.org\",\n  \"wikis\": {\n    \"en.wikipedia.org\": {\n      \"sitename\": \"Wikipedia\",\n      \"server\": \"https://en.wikipedia.org\",\n      \"articlepath\": \"/wiki\",\n      \"scriptpath\": \"/w\"\n    }\n  }\n}\n```\n\n**Internal vs public address.** The `server` you configure may be an internal hostname (e.g. `http://mediawiki` in Docker); URLs handed back to the caller are built from the wiki's public address, so internal hostnames don't leak into links. See [docs/configuration.md — per-wiki fields](docs/configuration.md#per-wiki-fields).\n\nFor the full field reference, env-var substitution, secret sources, change tags, upload directories, and authentication options, see [docs/configuration.md](docs/configuration.md).\n\n## Authentication\n\nTools marked 🔐 require authentication. Write tools (including extension-pack writes) are hidden from `tools/list` when the configured default wiki has `readOnly: true` — see [Deployment](#deployment).\n\n- **Browser-based OAuth (recommended).** Sign in through a browser tab the first time a tool needs auth. Set `oauth2ClientId` and `oauth2CallbackPort` per wiki — see [docs/configuration.md — OAuth (browser-based)](docs/configuration.md#oauth-browser-based).\n- **Per-request bearer token (HTTP), deprecated.** Each request carries `Authorization: Bearer \u003ctoken\u003e` and the server forwards it to MediaWiki. Off by default, because an MCP server must not accept tokens that were not issued for it. See [docs/deployment.md — per-request bearer token](docs/deployment.md#per-request-bearer-token-http-transport-deprecated).\n- **Hosted OAuth proxy (HTTP).** The server fronts one MediaWiki consumer as an OAuth 2.1 Authorization Server, so an OAuth-aware client signs each user in — no manual tokens. Point it at `https://\u003cwiki\u003e/mcp`; anonymous read still works. See [docs/deployment.md — hosted OAuth sign-in](docs/deployment.md#hosted-oauth-sign-in).\n- **Manual OAuth2 access token.** Paste a long-lived token into `config.json`. See [docs/configuration.md — manual OAuth2 access token](docs/configuration.md#manual-oauth2-access-token).\n- **Bot password.** Fallback when Extension:OAuth isn't installed. See [docs/configuration.md — bot password](docs/configuration.md#bot-password).\n\nThe Cargo tools (`cargo-query`, `cargo-list-tables`, `cargo-describe-table`) call API actions gated by the `runcargoqueries` user right. Most wikis grant this to all users by default; wikis that restrict it require the **`Create, query and delete data through the Cargo extension`** grant on the bot password or OAuth consumer. The Cargo extension is also detected on wiki.gg-hosted wikis (Helldivers, Terraria, Ark, etc.), where it ships under the rebranded name `LIBRARIAN`.\n\n## Installation\n\nPick your client below, or use the [standard configuration](#standard-configuration) if it is not listed. `CONFIG` is optional; without it the server targets English Wikipedia. To point it at your own wiki and set up authentication for writes, see [docs/configuration.md](docs/configuration.md).\n\n### Claude Code\n\nAdd this repository as a plugin marketplace, then install the bundled server:\n\n```\n/plugin marketplace add ProfessionalWiki/MediaWiki-MCP-Server\n/plugin install mediawiki-mcp-server@professional-wiki\n```\n\nThe plugin takes an optional configuration file, which points the server at your own wiki. Set it from the prompt when enabling the plugin, or at any time with `/plugin configure mediawiki-mcp-server@professional-wiki`. A command-line install takes the same value via `claude plugin install mediawiki-mcp-server@professional-wiki --config configPath=path/to/config.json`.\n\nWhen installed as a plugin, the tools are namespaced `mcp__plugin_mediawiki-mcp-server_mediawiki__\u003ctool\u003e`; update any tool allowlists or hooks accordingly.\n\nTo configure the server directly instead, see the [Claude Code MCP docs](https://docs.anthropic.com/en/docs/claude-code/mcp). The short version:\n\n```bash\nclaude mcp add mediawiki-mcp-server -- npx -y @professional-wiki/mediawiki-mcp-server@latest\n# Environment variables go before the `--`:\nclaude mcp add mediawiki-mcp-server -e CONFIG=path/to/config.json -- npx -y @professional-wiki/mediawiki-mcp-server@latest\n```\n\n### Codex\n\nAdd this repository as a plugin marketplace, then install the bundled server:\n\n```bash\ncodex plugin marketplace add ProfessionalWiki/MediaWiki-MCP-Server\ncodex plugin add mediawiki-mcp-server@professional-wiki\n```\n\nTo point the plugin at your own wiki, set `CONFIG` in the shell you launch Codex from, for example `export CONFIG=path/to/config.json`. Codex has no per-plugin configuration; if you would rather not set an environment variable, `codex mcp add mediawiki --env CONFIG=path/to/config.json -- npx -y @professional-wiki/mediawiki-mcp-server@latest` registers the server directly and takes precedence over the plugin's copy.\n\nSee the [Codex plugins documentation](https://developers.openai.com/codex/plugins) for how to list, update, or remove plugins.\n\n### Claude Desktop\n\nDownload [MediaWiki-MCP-Server.mcpb](https://github.com/ProfessionalWiki/MediaWiki-MCP-Server/releases/latest/download/MediaWiki-MCP-Server.mcpb) and double-click it to install the extension, which prompts for a configuration file path so you can point it at your own wiki instead of English Wikipedia.\n\n### VS Code and Cursor\n\n[![Install in VS Code](https://img.shields.io/badge/Add%20to-VS%20Code-blue?style=for-the-badge\u0026labelColor=%230e1116\u0026color=%234076b5)](https://insiders.vscode.dev/redirect/mcp/install?name=mediawiki-mcp-server\u0026config=%7B%22command%22%3A%22npx%22%2C%22args%22%3A%5B%22-y%22%2C%22%40professional-wiki%2Fmediawiki-mcp-server%40latest%22%5D%7D)\n[![Install in VS Code Insiders](https://img.shields.io/badge/Add%20to-VS%20Code%20Insiders-blue?style=for-the-badge\u0026labelColor=%230e1116\u0026color=%234f967e)](https://insiders.vscode.dev/redirect/mcp/install?name=mediawiki-mcp-server\u0026config=%7B%22command%22%3A%22npx%22%2C%22args%22%3A%5B%22-y%22%2C%22%40professional-wiki%2Fmediawiki-mcp-server%40latest%22%5D%7D\u0026quality=insiders)\n[![Install in Cursor](https://cursor.com/deeplink/mcp-install-dark.svg)](https://cursor.com/install-mcp?name=mediawiki-mcp-server\u0026config=eyJjb21tYW5kIjoibnB4IiwiYXJncyI6WyIteSIsIkBwcm9mZXNzaW9uYWwtd2lraS9tZWRpYXdpa2ktbWNwLXNlcnZlckBsYXRlc3QiXX0%3D)\n\nOr add the [standard configuration](#standard-configuration) by hand.\n\n### Antigravity\n\nAdd the [standard configuration](#standard-configuration) to Antigravity's MCP config, either globally in `~/.gemini/config/mcp_config.json` or per-workspace in `.agents/mcp_config.json`.\n\nIf you previously installed the Gemini CLI extension, Antigravity's setup wizard offers to import your existing Gemini CLI configuration.\n\n### OpenCode\n\nOpenCode uses its own configuration shape rather than `mcpServers`; add this to `opencode.json` in your project root, or `~/.config/opencode/opencode.json` for a global install.\n\n```json\n{\n  \"$schema\": \"https://opencode.ai/config.json\",\n  \"mcp\": {\n    \"mediawiki-mcp-server\": {\n      \"type\": \"local\",\n      \"command\": [\"npx\", \"-y\", \"@professional-wiki/mediawiki-mcp-server@latest\"],\n      \"environment\": {\n        \"CONFIG\": \"path/to/config.json\"\n      }\n    }\n  }\n}\n```\n\n### Standard configuration\n\nMost clients read the same server block. Paste it into the file listed for your client, replacing `mcpServers` with that client's root key:\n\n| Client | Configuration file | Root key |\n| --- | --- | --- |\n| Cursor | `~/.cursor/mcp.json`, or `.cursor/mcp.json` per project | `mcpServers` |\n| VS Code | `.vscode/mcp.json` per workspace, or the **MCP: Open User Configuration** command | `servers` |\n| Devin Desktop (formerly Windsurf) | `~/.codeium/windsurf/mcp_config.json` | `mcpServers` |\n| Zed | `~/.config/zed/settings.json` | `context_servers` |\n| LM Studio | `~/.lmstudio/mcp.json` | `mcpServers` |\n\n```json\n{\n  \"mcpServers\": {\n    \"mediawiki-mcp-server\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@professional-wiki/mediawiki-mcp-server@latest\"],\n      \"env\": {\n        \"CONFIG\": \"path/to/config.json\"\n      }\n    }\n  }\n}\n```\n\nFor any other client, `npx add-mcp @professional-wiki/mediawiki-mcp-server` may work: [add-mcp](https://github.com/neon-solutions/add-mcp) is a community CLI that writes your client's configuration file for you. It sets the launch command only; add `CONFIG` yourself to point at your own wiki.\n\n## Deployment\n\nRunning the server as a remote HTTP endpoint for other users has its own configuration requirements — see [docs/deployment.md](docs/deployment.md). A pre-built image is published at `ghcr.io/professionalwiki/mediawiki-mcp-server`. For day-2 operations (logs, `/health`/`/ready`, metrics, graceful shutdown), see [docs/operations.md](docs/operations.md).\n\n## Security\n\nDefaults are safe for single-user use. Before exposing the HTTP transport to others, lock down three things:\n\n- **Terminate TLS at your reverse proxy.** Don't expose the MCP port directly on an untrusted network. See [docs/deployment.md — security checklist](docs/deployment.md#security-checklist).\n- **Pair `MCP_BIND` with `MCP_ALLOWED_HOSTS` and `MCP_ALLOWED_ORIGINS`.** The HTTP transport binds to `127.0.0.1` by default. When you open it up with `MCP_BIND=0.0.0.0`, set `MCP_ALLOWED_HOSTS` to the hostnames your proxy forwards and `MCP_ALLOWED_ORIGINS` to the browser origins allowed to call the server — these block DNS-rebinding and cross-origin attacks respectively.\n- **Uploads are opt-in.** `upload-file` is disabled until you list allowed directories in `uploadDirs` or `MCP_UPLOAD_DIRS`. See [docs/configuration.md — upload directories](docs/configuration.md#upload-directories).\n- **Internal destinations need `MCP_TRUSTED_HOSTS`.** Outbound fetches are SSRF-guarded: a destination resolving to a private or loopback address (e.g. a Docker-network alias like `mediawiki.svc`) is refused until you list its host in `MCP_TRUSTED_HOSTS`. See [docs/deployment.md — outbound SSRF guard](docs/deployment.md#outbound-ssrf-guard).\n\nReport a vulnerability via GitHub's [security advisory form](https://github.com/ProfessionalWiki/MediaWiki-MCP-Server/security/advisories/new) — full policy in [SECURITY.md](SECURITY.md).\n\n## Contributing\n\nContributions are welcome — pull requests and issues (bugs, feature requests, suggestions) both work.\n\n- **Working on tool code?** Start from [AGENTS.md](AGENTS.md) for repo layout, commands, and testing patterns.\n- **Adding or modifying a tool?** Read [docs/tool-conventions.md](docs/tool-conventions.md) — it covers description voice, parameter docs, annotation hints, and MediaWiki terminology conventions.\n- **Running a release?** See [docs/releasing.md](docs/releasing.md).\n\n## License\n\nThis project is licensed under the MIT License. See the [LICENSE](LICENSE) file for details.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fprofessionalwiki%2Fmediawiki-mcp-server","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fprofessionalwiki%2Fmediawiki-mcp-server","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fprofessionalwiki%2Fmediawiki-mcp-server/lists"}