Back to Browse

Pihole MCP Server

Developer ToolsUse Caution4.0MCP RegistryLocal
Free

Server data from the Official MCP Registry

MCP server for Pi-hole v6 API — manage multiple instances: queries, lists, groups, stats

About

MCP server for Pi-hole v6 API — manage multiple instances: queries, lists, groups, stats

Security Report

4.0
Use Caution4.0High Risk

Valid MCP server (2 strong, 3 medium validity signals). 7 known CVEs in dependencies (0 critical, 5 high severity) Package registry verified. Imported from the Official MCP Registry.

8 files analyzed · 8 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

file_system

Check that this permission is expected for this type of plugin.

env_vars

Check that this permission is expected for this type of plugin.

What You'll Need

Set these up before or after installing:

Comma-separated list of Pi-hole instance names (e.g. 'pihole' or 'primary,secondary')Optional

Environment variable: PIHOLE_INSTANCES

Base URL of your first Pi-hole instance (e.g. 'http://192.168.1.100')Optional

Environment variable: PIHOLE_BASE_URL

API password for your first Pi-hole instanceRequired

Environment variable: PIHOLE_PASSWORD

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-ranklancer-pihole-mcp": {
      "env": {
        "PIHOLE_BASE_URL": "your-pihole-base-url-here",
        "PIHOLE_PASSWORD": "your-pihole-password-here",
        "PIHOLE_INSTANCES": "your-pihole-instances-here"
      },
      "args": [
        "-y",
        "@ranklancer/pihole-mcp"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

pihole-mcp

License: MIT Node.js Pi-hole v6 MCP

An MCP (Model Context Protocol) server that gives AI assistants like Claude full control over your Pi-hole v6 DNS ad-blocker - query logs, allow/deny lists, group management, gravity reload, and stats. Designed from day one for multi-instance deployments: manage one or many Pi-hole instances from a single MCP endpoint.

Why?

Pi-hole's admin API is powerful but cumbersome to script against. This MCP server turns every Pi-hole API action into a tool that any MCP-compatible AI assistant can call directly. Instead of clicking through the admin UI or writing curl commands, just ask your AI to check what's being blocked, allowlist a domain, or compare stats across instances.

Perfect for homelabbers running multiple Pi-holes (primary + secondary, or per-VLAN), network admins managing DNS filtering at scale, and anyone who wants AI-assisted DNS management.

Features

  • Multi-instance support - configure 1 to N Pi-hole instances via environment variables
  • Full Pi-hole v6 API coverage - query logs, allow/deny lists (full CRUD), group management, blocking control, local DNS (A + CNAME) records, gravity reload, stats
  • Smart regex detection - automatically routes domains to exact or regex lists based on metacharacter analysis
  • Regex landmine detector - finds deny-exact entries that look like they should be regex (miscategorized rules)
  • Docker-ready - multi-stage Dockerfile with non-root user, health checks, and security hardening
  • Streamable HTTP transport - works with any MCP client that supports HTTP-based MCP
  • Docker secrets support - passwords via env vars or /run/secrets/ files

Quick Start

Docker (recommended)

git clone https://github.com/ranklancer/pihole-mcp.git
cd pihole-mcp
cp .env.example .env
# Edit .env with your Pi-hole URL(s) and password(s)

mkdir -p secrets
echo "your-pihole-password" > secrets/pihole_password
chmod 600 secrets/pihole_password

cp docker-compose.example.yml docker-compose.yml
docker compose up -d

Node.js

npm install
npm run build
export PIHOLE_INSTANCES=pihole
export PIHOLE_BASE_URL=http://pihole.example.com
export PIHOLE_PASSWORD=your-password
npm start

Configuration

All configuration is via environment variables. See .env.example for the full reference.

Single Instance

PIHOLE_INSTANCES=pihole
PIHOLE_BASE_URL=http://192.0.2.100
PIHOLE_PASSWORD=your-password

Multiple Instances

PIHOLE_INSTANCES=primary,secondary
PRIMARY_BASE_URL=http://192.0.2.100
PRIMARY_PASSWORD=password1
SECONDARY_BASE_URL=https://198.51.100.101
SECONDARY_PASSWORD=password2
SECONDARY_INSECURE_TLS=true

For each instance name in PIHOLE_INSTANCES, provide:

VariableRequiredDescription
<NAME>_BASE_URLYesPi-hole base URL (e.g. http://pihole.local)
<NAME>_PASSWORDYesPi-hole API password (or use Docker secrets)
<NAME>_INSECURE_TLSNoSet true for self-signed certs (default: false)

Docker secrets are supported as a fallback: /run/secrets/<name>_password (lowercase).

Available MCP Tools

ToolDescription
pihole_query_logFetch query log with filters (limit, time range, client, domain, status)
pihole_allow_domainAdd to allowlist (auto-detects exact vs regex)
pihole_deny_domainAdd to denylist (auto-detects exact vs regex)
pihole_list_allowlistList all allowlist entries (exact + regex merged)
pihole_list_denylistList all denylist entries (exact + regex merged)
pihole_stats_summaryGet Pi-hole statistics summary
pihole_reload_listsTrigger gravity reload
pihole_group_managementCRUD operations on Pi-hole groups
pihole_check_regex_typesDetect miscategorized regex in deny-exact list
pihole_set_blockingEnable/disable blocking, with optional auto-revert timer
pihole_domain_managementUpdate or delete an allow/deny domain (completes CRUD)
pihole_local_dnsList/add/delete local DNS A records
pihole_local_cnameList/add/delete local CNAME records

Every tool accepts an optional instance parameter to target a specific Pi-hole. Defaults to the first configured instance.

Connecting to Your MCP Client

The server listens on http://HOST:PORT/mcp (default: http://localhost:3000/mcp).

Claude Desktop / Claude Code

Add to your MCP settings:

{
  "mcpServers": {
    "pihole": {
      "url": "http://localhost:3031/mcp"
    }
  }
}

Supergateway (stdio wrapper)

If your MCP client only supports stdio transport, use supergateway:

npx -y supergateway --streamableHttp http://localhost:3031/mcp

Health Check

curl http://localhost:3031/health
# {"ok":true,"service":"pihole-mcp","version":"0.3.0"}

Development

npm install
npm run dev     # Watch mode — recompiles on save
npm start       # Run the server

Requirements

  • Node.js >= 20
  • Pi-hole v6 with API access enabled
  • Network connectivity to your Pi-hole instance(s)

Related Projects

License

MIT

Reviews

No reviews yet

Be the first to review this server!