0.7.2
September 27th, 2026
Agents can read what your forms collect.
Added
Form submissions. submissions_list returns a form's submissions newest first, each with its full data, so a week of contact requests is one call. search is the Control Panel's search: a substring match over the text, textarea, and integer fields, where % and _ are wildcards. since and before bound the date; a time without an offset is read in the app's timezone, and a date alone means midnight, so before: 2026-09-27 covers everything up to the end of the 26th. submissions_get returns one submission by form and id. submissions_delete removes one and, like the other delete tools, exists only when deletes is on. Nothing creates or edits a submission, as in the Control Panel.
Permissions follow Statamic's form policies. Reading takes view {form} form submissions and deleting takes delete {form} form submissions. configure forms grants both on every form, as it does in the Control Panel.
Forms in the overview and in blueprints_get. statamic_overview lists the forms you may read, with stores_submissions (false on a form that only sends email) and their submission count. blueprints_get takes type: form and returns the fields a submission's data is keyed by.
Worth knowing
A published config needs one line. The new resources.forms key defaults to true in the package config. A config/statamic/mcp.php you published before this release has no such key, and then no form is exposed until you add 'forms' => true under resources, the same rule navigations followed in 0.5.0.
Full changelog: https://github.com/danielgnh/statamic-mcp/compare/v0.7.1...v0.7.2
0.7.1
September 25th, 2026
Slugs follow the Control Panel's rules now, both where two entries share one and where a collection has none.
Fixed
A slug may repeat, as in the Control Panel. entries_create, entries_update, and entries_localize refused a slug that another entry of the collection already had in the site. The Control Panel only refuses a URL another entry has. So /products/overview and /services/overview can both exist, and a localization can sit under a parent with the same slug, as in /de/delivery/delivery. Agents worked around the old rule with slugs like overview-2, which then showed up in the page's URL. A taken URL is still refused, and a blueprint whose slug field sets unique_entry_value still keeps slugs unique.
entries_get no longer picks one of several entries. A lookup by collection and slug that matches several entries of the site is now an error. It lists each entry's id and URL, so the agent can pass the id of the one it means. Before, it returned whichever entry the Stache gave back first, and an agent could read, then edit, the wrong page.
Collections with slugs turned off. entries_localize failed on such a collection with "An internal server error occurred." entries_create made a slug from the title, so Statamic named the entry's file after it instead of after the entry's id, which the Control Panel never does. Both give the entry no slug now, and the three write tools refuse a slug for these entries, since the Control Panel has no field to set one. A blueprint with a slug field of its own keeps slugs.
Changed
Avatars on Connections. The User column on Tools → MCP → Connections shows each user the way the Users listing does, with their avatar or initials next to their email, and links to the user. A deleted user's rows still show the user ID.
Worth knowing
Entries that earlier versions created in a collection with slugs turned off keep the slug the tools made from their title. A save in the Control Panel clears it. entries_update refuses a slug there, so an agent can't.
Full changelog: https://github.com/danielgnh/statamic-mcp/compare/v0.7.0...v0.7.1
0.7.0
September 25th, 2026
Agents can translate entries on multilingual sites, and MCP gets its own place in the Control Panel.
Highlights
Translate an entry into another site. entries_localize adds an entry to another site of its collection, the way the Control Panel's Localize action does. The new entry is a draft localization. It inherits every field it doesn't override, data holds its own values such as a translated title and content, and slug defaults to the origin's. On a structured collection it joins the target site's tree under the localization of the origin's parent. It needs the edit permission for the origin entry and access to the target site, and it exists on multisite installs only.
Agents see what each site has. entries_get, entries_create, and entries_localize return localizations, the id and status of the entry in each site you can access, or null where it has none. On multisite, statamic_overview lists each collection's sites, propagate, and origin_behavior, and blueprints_get marks each field localizable or not, so an agent knows what it can translate before it writes. entries_update now refuses a localization's own value for a field that isn't localizable, as the Control Panel does, and names the origin entry to change instead.
Tools → MCP in the Control Panel. MCP has its own item under Tools, with Guidelines and Connections listed under it in the sidebar like the Utilities pages. Connections is the old MCP Access utility, with your tokens and OAuth connections. Guidelines holds the site's voice and tone and the rows on how a collection's entries are put together. Only super admins can open it.
Guidelines move out of Globals. The guidelines global set sat next to the site's content, so editors took it for website content, and any agent acting as a super admin could rewrite it through globals_update. Guidelines now live in Statamic's addon settings, in resources/addons/statamic-mcp.yaml or the database. Agents read them through statamic_overview and blueprints_get as before, a row switched off on the page no longer reaches them, and no tool writes them.
mcp:guidelines moves 0.6.0 guidelines. The command no longer creates a global set. It moves the old one to the Guidelines page, prints the page's URL, and lists the page builder blocks without instructions as before.
The Boost skill sends coding agents to the Guidelines page or its YAML file.
Breaking changes
- Guidelines no longer live in the
guidelinesglobal set. Agents read the set only untilphp please mcp:guidelinesmoves it, as described below. Theguidelinesconfig key is gone, and no tool writes guidelines any more. - The Guidelines page rejects
{{, Antlers and Blade component tags, and@props,@aware, and@cascade, because Statamic runs addon settings through Antlers every time it loads them. Describe such a tag in words. - The MCP Access utility and its permission are gone. Its page is Tools → MCP → Connections, which needs Access MCP, so a role with Access MCP alone can now issue its own tokens. OAuth mode already let those users connect themselves.
- Published copies of
utilities/mcp-tokens.blade.phpno longer apply. The page ismcp/connections.blade.php.
Upgrading from 0.6.0
- Update the package:
composer update danielgnh/statamic-mcp - Move the guidelines:
php please mcp:guidelines. Run it where the content lives, locally on a flat-file site or in production when globals live in a database. It copies the guidelines global set to Tools → MCP → Guidelines, then deletes the set and its blueprint. Until you run it, agents keep reading the set and the Guidelines page shows a notice. - On a flat-file site, commit
resources/addons/statamic-mcp.yamland the deleted set files. - If the command says the set stays, follow its message. It keeps the set when the Guidelines page already has guidelines, when the set's text holds template code, or when the set's other sites hold text, which 0.6.0 never read.
- Delete the
guidelineskey from a publishedconfig/statamic/mcp.php.
Full changelog: https://github.com/danielgnh/statamic-mcp/compare/v0.6.0...v0.7.0
0.6.0
September 24th, 2026
Guidelines for agents move where the people who run the site can edit them.
Highlights
Guidelines live in a global set. php please mcp:guidelines creates a guidelines global set once. Its Site field holds voice and tone, which statamic_overview returns to every agent. Its rows pick collections and taxonomies and say how their entries are put together, and blueprints_get returns the rows naming the requested resource with its blueprints. Admins edit the set in the Control Panel under Globals, with no deploy, and an agent whose user may edit the set can change it through globals_update.
Tab and section instructions reach agents. blueprints_get returns tabs: every tab whose own or whose sections' instructions exist, with the handles of the fields under them. A note about one blueprint, such as which existing entry to follow, goes in its first section, where editors see it too.
A readable block report. mcp:guidelines lists the blocks without instructions grouped under the blueprints that share them, one wrapped line per field, instead of a table wider than any terminal.
The Boost skill maps each kind of guidance to its one place and says never to restate a field in the global set.
Breaking changes
- The markdown files under
resources/mcp/guidelinesare no longer read, and theguidelines_pathconfig key is gone. The newguidelineskey names the set and defaults toguidelines. - Guidelines for one blueprint or for a global set have no file any more. Put them in a section's instructions.
Migrating from 0.5.0
- Update the package:
composer update danielgnh/statamic-mcp - Create the set:
php please mcp:guidelines - Paste
site.mdinto the set's Site field. - Paste each
collections/{handle}.mdinto a row that names its collection. Move anything that describes one field into that field'sinstructionsinstead. - Delete
resources/mcp/guidelines.
Full changelog: https://github.com/danielgnh/statamic-mcp/compare/v0.5.0...v0.6.0
0.5.0
September 24th, 2026
MCP now saves content the way the Control Panel does. Each value goes through its fieldtype's processing and validation, URLs have to be unique, and permission checks follow the CP's author and site rules. Publishing is its own pair of tools.
Agents also get new tools. They can preview drafts, edit navigation menus, nest and move pages, read the blocks of your page builder fields, and follow guidelines you write in markdown.
This release has breaking changes, and two of them are security fixes. A ^0.4 constraint never resolves to 0.5, so read the upgrade notes before you bump.
Security
Two permission gaps let MCP do more than the Control Panel allows. Every version before 0.5.0 has both.
- On a blueprint with an
authorfield, a role with a collection's edit, publish, or delete permission could do that to anyone's entry through MCP. The CP limits it to entries the user authored. The entry tools now check what Statamic'sEntryPolicychecks, and a denial names the missing permission.statamic_overviewtells agents which of these permissions they have. - On multisite, MCP never checked
access {site} sitefor the default site. A role with onlyaccess fr sitecould still read and write default-site content. MCP now gates the default site like every other site.
One more fix concerns OAuth mode. mcp:setup printed the private signing key during its key step, also in unattended runs. If you ran mcp:setup --oauth in a pipeline whose logs others can read, rotate the key: delete the row in statamic_mcp_oauth_keys and any storage/oauth-*.key files. The next request provisions a fresh pair, and every connected client reconnects through the OAuth flow.
Upgrading
composer require danielgnh/statamic-mcp:^0.5
Check these before you deploy.
- Statamic 6.31 or newer is required. Composer refuses earlier 6.x releases by default because of a security advisory, so most sites are there already. laravel/mcp 0.8 keeps working, and 0.9 and 1.x work too.
- Publishing has its own tools.
entries_createandentries_updateno longer acceptpublished. Agents publish withentries_publishand take entries offline withentries_unpublish, both behind the collection's publish permission. A client with a cached tool list gets an error that points toentries_publish. - Roles need the "other authors" permissions for entries they didn't write. Grant
edit other authors {collection} entries,publish other authors {collection} entries, ordelete other authors {collection} entriesto roles that should keep that access. Entries with no author count as someone else's. - The default site needs site access. On multisite, grant
access {site} sitefor the default site to every role that should keep reaching it. - New entries get an author. When the blueprint has an
authorfield anddatanames none,entries_createsets the acting user, as the CP does. Naming someone else, or changing the author withentries_update, needsedit other authors {collection} entries. - Published configs need the navigations key. If you published
config/statamic/mcp.php, add'navigations' => trueunderresources. Without it, the navigation tools see no menus. - Writes are validated like CP saves. Unknown set types, unknown keys inside sets, grid rows, and groups, asset paths missing from the field's container, and a URL another entry already has now fail with an error that names the problem. MCP used to save them.
- OAuth mode: run
php artisan migrate. The migration that widens Passport'suser_idcolumns ran too early on fresh installs and did nothing. It is renamed so it runs after Passport's own migrations. Sites it missed convert on the next migrate, and sites with converted columns see a no-op.
New
entries_publishandentries_unpublish. On revision-enabled collections they promote or apply the working copy and record a revision under the acting user, which only the CP could do before. Your MCP client asks for permission per tool, so allowingentries_updateno longer lets an agent publish.entries_previewreturns a Live Preview URL that renders a draft or working copy through your templates. Anyone with the URL can open it for an hour, so an agent can check its own work before anyone publishes. It changes no content, andread_onlykeeps it.navigations_getandnavigations_updateread and replace a navigation's tree.navigations_updatechecks the tree againstmax_depth, the root page rule, and the navigation's blueprint.entries_createandentries_updatetakeparentto nest or move an entry in a structured collection. Parallel tree edits take a lock per collection and site, so none of them drops another's placement.blueprints_getlists the sets of Replicator and Bard fields with their instructions. Passsetto get one set's fields and an example row. It also reports where asset, entry, term, and user fields point and how many items they take.- Guidelines for agents. Markdown files in
resources/mcp/guidelinesreach agents throughstatamic_overviewandblueprints_get.php please mcp:guidelinescreates the starter files without overwriting any and lists the blocks that have no instructions yet, blocks inside grids and groups included. Thestatamic-mcp-guidelinesBoost skill helps a coding agent write them. - Your own tools. Point the new
serverconfig key at a subclass ofDanielgnh\StatamicMcp\Server, then add, replace, or remove tools intools(). They run behind the same authentication andaccess mcpcheck as the built-in tools. - Scheduling.
statamic_overviewreports each dated collection'sdate_behaviorand the server timezone. When a date keeps a published entry hidden,entries_publishreports it as scheduled or expired.entries_gettakesworking_copy: true, andentries_listfilters bystatus: expired. - laravel/mcp 0.9 and 1.x work alongside 0.8. On 1.x, JSON-RPC errors come back as HTTP 400, 404, or 500 instead of 200, and clients on the 2026-07-28 protocol revision connect through
server/discover. If you run OAuth mode and have narrowedmcp.redirect_domains, move to laravel/mcp 0.9.6 or 1.0.1. Both fix the loopback redirect URI check in OAuth client registration, and 0.8 won't get that fix.
Fixed
- Writes store what the Control Panel stores. Each value goes through the fieldtype's
preProcess()andprocess(), so a single asset or relationship saves as a plain string, sets and grid rows get ids, dates use the field's save format, and HTML sent to a Bard field becomes ProseMirror. What the get tools return can be written back unchanged, also in collections with several blueprints:entries_getnow names the blueprint at the top level instead of insidedata. - Updating an entry, term, or global set no longer fails on a single-file asset, single-item relationship, or date that the CP saved, and a patch to a localization no longer fails on a required field it inherits from its origin.
- A new entry in a structured collection goes into the collection's tree. Its
urlused to come backnull. blueprints_getexamples match what the write tools accept.sluganddateare out of the example payload, option fields use the option's key, and relationship and date fields use the stored shape.entries_updateno longer reports "published" after a new date makes the entry scheduled or expired, and it reports the staged URL, not the live one, when it stages a working copy.entries_updaterefuses a date on a localization whose date field isn't localizable. Publishing used to drop that date without a word.mcp:keysprints only the keys on stdout, somcp:keys --json | jqandmcp:keys >> .envwork on the first run too. With only onePASSPORT_*key set, it reads each half the way Passport does.
Known caveats
entries_createalways uses the collection's default blueprint. It has noblueprintparameter, andblueprintinsidedatais refused as reserved.blueprints_getreports a set's group by name, without the group's instructions. Put instructions on the sets themselves.- Writes accept sets hidden from the CP's set picker.
blueprints_getmarks them"hidden": true.
The full list is in CHANGELOG.md.
Pull requests
- feat: add your own tools by naming a server subclass in config by @danielgnh in https://github.com/danielgnh/statamic-mcp/pull/18
- feat: publishing is its own tool pair (entries_publish / entries_unpublish) by @danielgnh in https://github.com/danielgnh/statamic-mcp/pull/19
- feat: tools() hook with a ToolRegistry to add, replace, and remove tools by @danielgnh in https://github.com/danielgnh/statamic-mcp/pull/21
- feat: make Statamic's own scheduling visible and honest to agents by @danielgnh in https://github.com/danielgnh/statamic-mcp/pull/22
- fix: writes store what the Control Panel stores by @danielgnh in https://github.com/danielgnh/statamic-mcp/pull/23
- fix: leave top-level parameters out of blueprints_get examples by @danielgnh in https://github.com/danielgnh/statamic-mcp/pull/24
- feat: page builder blocks and guidelines for agents by @danielgnh in https://github.com/danielgnh/statamic-mcp/pull/25
- feat: entries_preview returns a live-preview link for drafts by @danielgnh in https://github.com/danielgnh/statamic-mcp/pull/26
- feat: navigation tools and parent on entries_create by @danielgnh in https://github.com/danielgnh/statamic-mcp/pull/27
- fix!: match the Control Panel's author and site permissions by @danielgnh in https://github.com/danielgnh/statamic-mcp/pull/28
- feat: page builder sets as a short list, with a lookup per set by @danielgnh in https://github.com/danielgnh/statamic-mcp/pull/29
- feat: move entries in their tree with parent on entries_update by @danielgnh in https://github.com/danielgnh/statamic-mcp/pull/30
- feat: support laravel/mcp 0.9 and 1.x by @danielgnh in https://github.com/danielgnh/statamic-mcp/pull/31
- test: run the Passport-free tests in their own CI job by @danielgnh in https://github.com/danielgnh/statamic-mcp/pull/32
- fix: bugs found testing the unreleased changes end to end by @danielgnh in https://github.com/danielgnh/statamic-mcp/pull/33
0.4.2
July 20th, 2026
Full Changelog: https://github.com/danielgnh/statamic-mcp/compare/v0.4.1...v0.4.2
0.4.1
July 16th, 2026
What's Changed
- refactor(views): show only the active auth mode on the MCP Access page by @danielgnh in https://github.com/danielgnh/statamic-mcp/pull/17
Full Changelog: https://github.com/danielgnh/statamic-mcp/compare/v0.4.0...v0.4.1
0.4.0
July 15th, 2026
What's Changed
- feat: manage Passport's keys in the database — deploys need no key step by @danielgnh in https://github.com/danielgnh/statamic-mcp/pull/16
Full Changelog: https://github.com/danielgnh/statamic-mcp/compare/v0.3.2...v0.4.0