mdrbx / nova-mcp
Expose Laravel Nova resources to MCP clients through Nova's existing permissions and OAuth.
Requires
- php: ^8.3
- ext-json: *
- ext-openssl: *
- illuminate/auth: ^12.41.1 || ^13.0
- illuminate/console: ^12.41.1 || ^13.0
- illuminate/database: ^12.41.1 || ^13.0
- illuminate/support: ^12.41.1 || ^13.0
- laravel/mcp: ^1.0.1
- laravel/nova: ^5.11
- laravel/passport: ^13.8
Requires (Dev)
- driftingly/rector-laravel: ^2.5
- larastan/larastan: ^3.12
- laravel/pint: ^1.29
- orchestra/testbench: ^10.8 || ^11.0
- phpstan/phpstan: ^2.2
- phpunit/phpunit: ^11.5 || ^12.0
- rector/rector: ^2.6
Suggests
None
Provides
None
Conflicts
None
Replaces
None
This package is auto-updated.
Last update: 2026-09-29 16:37:55 UTC
README
Nova MCP
Give your AI client access to the Laravel Nova resources you already use. β¨
Nova MCP exposes your resources through Laravel MCP, using Nova's existing policies, field visibility, validation and operations. Users connect with their Nova account over OAuth and manage access from MCP connections in Nova.
- π Start with your existing resources. Browse, search, edit, manage relationships and run synchronous actions through MCP tools.
- π Keep Nova in charge. Every operation respects the user's Nova permissions and the client's approved OAuth scopes.
- πͺΆ Keep setup light. Blade pages, no frontend build, worker or scheduler required.
π Quick start
Start in an application with PHP 8.3+, Laravel 12.41.1+ or 13.x, and Nova 5.11+. You'll need a valid Nova license. Composer installs Laravel MCP and Passport as dependencies. See full requirements.
1. Install
composer require mdrbx/nova-mcp php artisan nova-mcp:install
Review the published migrations, then run:
php artisan migrate
Using UUID or ULID user IDs? Adapt Passport's published
user_idcolumns before migrating. Existing Passport installations should keep their compatible schema. The installation guide covers the details.
2. Add the Nova Tool
Add new NovaMcp to your existing NovaServiceProvider::tools() return array:
use Mdrbx\NovaMcp\NovaMcp; public function tools(): array { return [ // Keep your other tools here. new NovaMcp, ]; }
Using a custom Nova::mainMenu? Add the tool's menu entry.
3. Connect your client
Set APP_URL to your public application URL. Open MCP connections in Nova,
copy the server URL, then add it to your MCP client with OAuth authentication.
Sign in, approve the permissions, and try: βWhich resources can I access?β
Cloud clients need a publicly reachable HTTPS endpoint. The connection guide explains scopes, consent and revocation.
ποΈ Make it yours
Writes require both Nova's permission and an approved nova:write scope.
To make the whole MCP read-only, set this in .env:
NOVA_MCP_READ_ONLY=true
You can also set the instructions sent to MCP clients:
NOVA_MCP_GUARDRAILS="Ask for confirmation before destructive changes. Never export personal data."
Read-only mode blocks writes even for existing tokens. Guardrails guide the AI client; they are not permission checks. Rebuild the configuration cache after changes if your deployment uses it. See all configuration options β
π Go a little further
| Guide | What's inside |
|---|---|
| Installation | Requirements, Passport keys and migrations, custom Nova menus. |
| Configuration | Resource selection, read-only mode, guardrails, URLs and token lifetimes. |
| Connecting clients | OAuth, consent, permissions, revocation and troubleshooting. |
| Operations | Available tools, forms, relationships, actions and compatibility limits. |
| Architecture | How the adapter reuses Nova and isolates OAuth from your application. |
π Help make it better
Found a bug or have a concrete use case to share? Open an issue, or have a look at the contributing guide to get started locally.
See the changelog for releases and security policy for reporting vulnerabilities privately.
Made by Matthieu Deroubaix. Released under the MIT license. Laravel Nova requires its own commercial license; Nova MCP is an independent community package.

