GetMCP 1.7.0 — Your Files as MCP Tools, a Launch Page for Every Server, and White Label
An AI client that can call your API still can’t see the files behind your site: the error log, the config that changed last night, the theme file someone edited. 1.7.0 connects that too. It also helps the people you build servers for actually install them, with a launch page for every server. And for agencies, GetMCP can now carry your brand instead of ours.
Your files, as MCP tools
Install File Server from Templates, open the server’s File server settings, and enter the login your host gave you. SFTP, FTPS and plain FTP all work, and presets for cPanel, Hostinger, SiteGround, WP Engine, Kinsta and seven more hosts fill in the protocol, port and login method, then tell you where that host shows the credentials. Click Test connection, and your AI client can look for itself.
Thirteen tools come with it. Six only read, and they are on from the start:
list_directory— a folder’s files and folders, with size, modified time and permissionsread_file— a text file, or just its first or last lines, which is how logs get readfind_files— search by name pattern, size, or how recently a file changedget_file_info,download_fileandchecksum_file— what a path is, the file itself, or a SHA-256, SHA-1 or MD5 of it
The seven that change files — write_file, edit_file, append_file, create_directory, move_path, delete_path and set_permissions — install switched off, and the connection itself starts read-only. That is two locks before anything on your server changes. Every path stays inside the root folder you set, such as /public_html; .. is refused, and so is any path that runs through a symbolic link.
When you do allow writes, they are careful ones. An edit names the exact text it replaces, and that text has to appear once; a dry run shows the result before anything is saved. A written file goes up under a temporary name and is moved into place, so a dropped connection never leaves half a file behind, and a file that is replaced keeps its permissions. FTPS verifies the server’s certificate, and SFTP can pin the host key so a changed server is refused. Your password or SSH key stays encrypted on your install; the client sees tools, never the login.
Cleaning up after a hack. When a site has been compromised, your AI client can do the tedious part. With only the read tools on, ask it which PHP files changed in the last few days when nothing was deployed, and to read them; injected code tends to stand out, often obfuscated behind eval or base64_decode. Keep the write tools off while it investigates, because a planted file can contain text written to mislead the AI reading it. Once you have a backup and agree on what goes, turn on edit_file or delete_path: each edit names the exact code it removes, and a dry run shows the result first. Then close the way in: update whatever was outdated, and change your FTP and admin passwords.
Launch Kit: a page that installs your server
A server is only useful once people connect to it, and “add this URL as a custom connector” loses most of them. Click Launch Kit on any server and you get a Server Page at /s/your-server-slug: visitors pick their AI app, and the setup steps for Claude, ChatGPT, Claude Code, Cursor, VS Code and Windsurf already contain your server’s address. The tool list, the getting-started steps and the install buttons fill themselves from your server and stay correct when you change it.
Then Share Studio has everything for telling people: ready-made posts for LinkedIn, X and Slack, a client email, a launch card image in three designs, a QR code, and an “Add to Claude” button for your own site or docs. The page starts private, and it can only go public once the server has authentication, so nobody finds an open server through it. Pro plans can remove its “Powered by” badge.
White Label: GetMCP under your name
If you build MCP servers for clients, they now see your product, not ours. The new White Label add-on unlocks a Branding screen in GetMCP: your name and tagline, logos for light and dark, an icon, accent colours, your company, website, support and docs links, and the footer credit. They appear everywhere GetMCP shows its own: across the admin, on the consent screen where an AI client asks for access, in GetMCP’s emails, and on the standalone app’s sign-in page. On WordPress it can also rename the plugin in the Plugins list.
Hide White Label goes one step further: Branding and the add-on disappear for everyone but you, and a private link brings them back in your browser. Your client sees your product, with no sign of the add-on behind it. White Label works on the WordPress plugin and the standalone app, on any plan including Solo, from $49 a year for one site, $99 for 25 sites, or $149 for unlimited sites.
It installs from the new Settings → Add-ons tab, which lists every GetMCP add-on with Install, Update, Activate and Connect licence on each row. Packages are checked against a published checksum before they install. On the standalone app you can also upload an add-on as a .zip or use php artisan getmcp:addon, and an add-on that fails to load is switched off with the reason shown, instead of taking the app down.
Manage GetMCP from outside the admin
1.7.0 lays the groundwork for managing many installs from one place. Under Settings → API & Remote, generate a connection key and copy the connection string that bundles it with your install’s address. A console or your own script can then call GET /info for a one-call summary of the install, and GET or POST /update to check for and apply updates. Logs → Remote lists every change made that way, with the time, route, result and IP address.
The connection key now works on the standalone app as well, and the whole getmcp/v1 API is described by an OpenAPI 3.1 document at /openapi.json, or wp getmcp openapi and php artisan getmcp openapi, so you can generate a client for it.
Three changes to know before you update
- Private and local addresses are allowed by default. Every kind of server now follows one setting, Settings → Security → Private Network Access, so an API on
localhostor a NAS on your LAN works out of the box. API tools used to refuse them. If people who don’t own your network can add servers to your install, switch it off. Cloud metadata and link-local addresses are always refused. - Browser pages on other domains need to be listed. The getmcp/v1 API now answers web pages only from the origins you list under Settings → API & Remote → Allowed origins, and those requests sign in with the connection key. Scripts, servers and AI clients are not affected.
- The WordPress plugin requires PHP 8.2, the version its code already needed. The standalone app still requires PHP 8.3.
Also in 1.7.0
- Installing the Mailbox, Database or File Server template now takes you straight to that connector’s section of the server’s Settings tab.
- Settings sent when creating or importing a server are now checked the same way as on update; creating one used to skip the PII redaction, icon and variable checks.
- The Authentication tab saves the server-stored credential with its own Save button when Client Authentication is OAuth without an identity provider, and Manage with AI no longer offers an OAuth setup that no client could sign in to.
- An HTTP tool whose hostname does not resolve now says so, instead of reporting a blocked address, and a refused licence connection shows the licence server’s own reason.
- Bundled libraries are updated for published advisories: jmespath.php and symfony/yaml in the WordPress plugin, league/commonmark and league/flysystem in the standalone app.
- Standalone app: files uploaded through the REST API, such as brand assets and add-ons, now reach the server.
Getting 1.7.0
If you’re on the WordPress plugin, the update is waiting in your dashboard. On the standalone app, System Status will offer it, or update from the command line:
curl -fsSL https://get.getmcp.com | bash -s -- --update --dir=/path/to/getmcp
Both builds are the same codebase, so the File Server connector, Launch Kit and White Label behave identically on either. To get started, read Connect a file server, Launch your MCP server with Launch Kit and GetMCP White Label. The full list of changes is on the changelog, and if you hit anything odd, support is the fastest way to reach us.
Ship an MCP server for your product this week.
Install GetMCP on any PHP host, import your API and share one URL. Your users can call your tools from Claude tonight.